Privacy Policy

Last Updated: 29 December 2025

Website: shmowebsites.com

Business email: [email protected]

Business phone: +44 7508 199860

This Privacy Policy explains how Shmo Websites ("we", "us", "our") collects, uses, shares, stores, and protects personal information when you visit shmowebsites.com, contact us, request a consultation/meeting, or use our website design, development, redesign, management, maintenance, and related services.

We primarily operate under UK law but also serve customers in the EU/EEA and the United States. This policy is written to align with the UK GDPR and Data Protection Act 2018, the EU GDPR where it applies, and relevant US privacy requirements where applicable.

1. Who We Are

For most personal data described in this policy, Shmo Websites is the data controller (we decide how and why your personal data is processed).

How to contact us (email-only contact):

We do not publish a business address on our website. If a regulator or lawful process requires a service address, we will provide it through appropriate channels.

2. Key Points (Plain-English Summary)

We collect full names, phone numbers, emails, and meeting/project details so we can manually arrange a consultation and provide web services.

We do not use third-party automated booking tools; meetings are arranged via email/phone.

We do not sell your personal data.

We share data only with service providers who help us run our business (e.g., email, hosting, security, invoicing), and only as needed.

You have rights over your data (access, deletion, correction, objection, etc.), which you can exercise by emailing us.

3. What We Collect (Extremely Detailed)

We collect information in three ways: (A) you give it to us, (B) we collect it automatically, and (C) we get it from third parties (limited).

A) Information You Provide (especially to set up a meeting)

Because we arrange consultations manually, we may request and process:

Identity & Contact (Meeting Setup Essentials)

  • • Full name (first and last name)
  • • Email address
  • • Phone number
  • • Company/business name (if applicable)
  • • Job title/role (optional)
  • • Preferred contact method (e.g., email/phone) and contact time preferences (optional)

Scheduling & Consultation Details (Manual Booking)

  • • Preferred days/times and availability windows
  • • Time zone
  • • Preferred meeting format (phone/video/in-person) if you specify
  • • Any constraints you share (e.g., "evenings only")
  • • Any accessibility needs you choose to disclose (optional)

"Other Information" You May Share (Project Discovery)

This may include any details you provide to help us understand and quote your project, such as:

  • • Current website URL(s) and platform/CMS
  • • Desired domain(s) (if you ask for domain help)
  • • Business/brand overview, products/services, target audience
  • • Project goals (e.g., lead generation, ecommerce, bookings, portfolio)
  • • Required pages/features (forms, ecommerce, memberships, portals, blogs, integrations)
  • • Design preferences, brand guidelines, logo files, fonts, color palettes
  • • Content you provide (text, images, videos, PDFs)
  • • Competitor/inspiration websites and links
  • • Budget range and timeline (if you choose to share)
  • • Any messages, notes, or attachments you send

B) Communications Data

When you communicate with us by email, phone, website form, or social media:

  • • Message content and attachments
  • • Communication timestamps and metadata (e.g., subject line, sender/recipient)
  • • Our internal notes and summaries to manage your request
  • • Call notes

Call recording: We will only record calls if we clearly inform you (where lawful) and explain why.

C) Client / Contract / Delivery Data (if you become a customer)

If you engage us for services, we may process:

  • • Contract/statement of work details, change requests, approvals
  • • Project management records (tasks, milestones, feedback)
  • • Deliverables and revisions history
  • • Support and maintenance requests and outcomes
  • • Client communications history

D) Billing & Payment Data (if applicable)

If you purchase services, we may collect:

  • • Billing name and (if required) billing address (not displayed publicly)
  • • Invoice data, payment status, tax/VAT details if applicable
  • • Transaction references

Card details: typically handled by payment processors; we do not intentionally store full card details on our own systems.

E) Credentials & Access Data (client systems)

To build/manage a website, you may provide credentials or grant access to:

  • • Hosting accounts, control panels, SFTP/SSH
  • • Domain registrar and DNS settings
  • • CMS/admin accounts (e.g., WordPress admin)
  • • Plugin/theme licenses and dashboards
  • • Analytics and advertising accounts (if used)
  • • Email/SMTP services
  • • Third-party integrations and APIs (e.g., CRM, ecommerce, booking systems you choose)

Credential handling principles

  • We request the minimum access necessary.
  • We limit access internally on a need-to-know basis.
  • We recommend you use unique credentials, enable MFA, and revoke access when work ends.

F) Automatically Collected Technical Data (website usage)

When you visit our website, we may automatically collect:

IP address, device type and identifiers

Browser type/version, operating system

Approximate location (city/region from IP)

Pages visited, time spent, clicks, referrals

Date/time stamps

Security and server logs (including error logs)

G) Cookies and Similar Technologies

We may use cookies and similar technologies to make the site work and (if enabled) for analytics/marketing. See Section 11.

H) Sensitive Data (Special Category Data)

We do not intentionally collect sensitive data (e.g., health, religion, biometrics). Please avoid sending it unless we explicitly request it and a lawful basis applies.

I) Children's Data

Our services are not aimed at children, and we do not knowingly collect children's personal data.

4. Why We Use Your Data (Purposes)

We process personal data for the following purposes:

Enquiries and Meeting Setup (Core)

To respond to your enquiry, confirm your identity/contact details, manually arrange and confirm a consultation/meeting, and send meeting-related communications and reasonable follow-ups.

Quotes and Pre-Contract Steps

To understand requirements, prepare estimates and proposals, and assess feasibility, timelines, and scope.

Service Delivery (Clients)

To design, develop, redesign, manage, host (if offered), maintain, and support websites. To implement requested features, integrations, and content updates, and provide troubleshooting and support.

Business Operations

To manage records, workflow, quality control, training, and internal reporting. To protect our business from fraud, abuse, and security risks.

Marketing (Only Where Allowed)

To send updates or offers where permitted by law (and where you can opt out). To measure interest in our services (where appropriate).

Legal and Compliance

To meet legal obligations (accounting/tax), enforce agreements, and defend legal claims.

5. Lawful Bases (UK GDPR / EU GDPR)

We rely on one or more of the following legal bases depending on the situation:

  • Contract: to provide services or take steps you request before entering a contract (e.g., quote, consultation).
  • Legitimate interests: to run our business, respond to enquiries, keep communications, improve services, and keep systems secure—balanced against your rights.
  • Consent: where required (e.g., non-essential cookies; some marketing). You can withdraw consent at any time.
  • Legal obligation: where we must comply with laws (tax/accounting/regulatory).

6. If You Don't Provide Required Information

If you do not provide the information needed to contact you (typically full name, email address, and phone number) and enough context to schedule a meeting, we may be unable to:

  • • arrange your consultation,
  • • provide a meaningful response or quote,
  • • or deliver certain services.

7. Where Your Data Comes From (Sources)

  • • Directly from you via forms, emails, calls, messages, and files
  • • Automatically via website logs/cookies
  • • From your organisation (if a colleague provides your details)
  • • From public sources (limited), e.g., a company website you ask us to review

We do not buy bulk personal data lists for outreach.

8. Who We Share Data With (and Why)

We do not sell your personal data.

We share data only when necessary and typically with:

A) Email and Communications Provider

We use Outlook for business email. This means messages you send us and our replies may be processed and stored in Microsoft's email infrastructure, subject to their security and data handling practices.

B) Hosting, Infrastructure, and IT Providers (as needed)

To operate our website and deliver services, we may use providers such as:

  • • Website hosting and servers
  • • Domain/DNS providers
  • • Security services (firewalls, anti-spam, anti-abuse)
  • • Cloud storage/backups (if used)
  • • Development tools and repositories (if used)

C) Payment and Accounting Providers (if used)

If you pay for services, payments may be processed by a third-party payment provider; invoicing/accounting may involve third-party systems.

D) Professional Advisers

Accountants, solicitors, insurers, consultants (only as needed).

E) Legal / Regulatory / Safety

We may disclose information if required by law, court order, or to protect rights, safety, and security.

F) Business Transfer

If we merge, sell, or restructure, data may be transferred as part of the transaction with appropriate safeguards.

Vendor standards: Where required, we use contracts and confidentiality obligations to protect personal data and restrict processing to our instructions.

9. International Data Transfers (UK, EU, US)

Because we serve EU/US customers and may use providers with global infrastructure, your data may be transferred and stored internationally.

Where laws restrict transfers (e.g., UK/EU personal data going outside the UK/EEA), we use appropriate safeguards such as:

  • • contractual protections (e.g., Standard Contractual Clauses or UK transfer mechanisms),
  • • security measures (encryption, access controls),
  • • and vendor due diligence.

10. How Long We Keep Data (Retention)

We keep personal data only as long as needed for the purposes described, then delete or anonymise it.

Typical retention periods:

  • Enquiries / meeting requests (non-clients): up to 24 months from last interaction (to manage follow-ups and maintain business records).
  • Client project records: generally up to 6 years after completion (for legal, contractual, and accounting reasons).
  • Invoices and financial records: generally up to 6 years (or longer if legally required).
  • Security logs: typically 30–180 days, unless needed longer for investigations.
  • Marketing opt-out records: kept as long as needed to ensure we respect your preferences.

If a dispute arises, we may retain relevant information for longer while the matter is ongoing.

11. Cookies and Tracking

Our website uses cookies and similar tracking technologies. A cookie is a small text file stored on your device that helps us provide and improve our services.

Cookie Consent: When you first visit our website, you'll see a cookie banner asking for your consent. We will not use non-essential cookies unless you accept them. You can change your preferences at any time by clicking the "Cookie Settings" button in our website footer, which allows you to review and update your cookie choices.

Types of Cookies We Use:

Strictly Necessary Cookies (Always Active)

These cookies are essential for the website to function properly. They enable core functionality such as security, network management, and accessibility. You cannot opt-out of these cookies.

Examples: Session management, security tokens, cookie consent preferences, abuse prevention.

Analytics Cookies (Optional - Requires Consent)

These cookies help us understand how visitors interact with our website by collecting and reporting information anonymously. This helps us improve our website and services.

Examples: Google Analytics, visitor statistics, page views, traffic sources, user behaviour patterns.

Duration: Up to 24 months

Marketing/Advertising Cookies (Optional - Requires Consent)

These cookies track your online activity to help advertisers deliver more relevant advertising or to limit how many times you see an ad. We may share this information with third parties.

Examples: Facebook Pixel, Google Ads, retargeting cookies, conversion tracking.

Duration: Up to 12 months

Functional Cookies (Optional - Requires Consent)

These cookies enable enhanced functionality and personalization, such as remembering your preferences, language settings, or previous interactions.

Examples: Language preferences, accessibility settings, saved form data.

Duration: Up to 12 months

Third-Party Cookies

Some cookies may be set by third-party services that appear on our pages. We do not control these cookies. You should check the third-party websites for more information about these cookies.

Third parties we may use:

  • Google Analytics: Website traffic and user behaviour analysis
  • Google Ads: Advertising and conversion tracking (if used)
  • Facebook Pixel: Social media advertising and tracking (if used)
  • LinkedIn Insight Tag: Professional network advertising (if used)

How to Manage Cookies

You have several options to manage or disable cookies:

Cookie Banner

Accept or reject non-essential cookies when you first visit our site. You can change your preferences at any time by clicking the "Cookie Settings" link in our website footer.

Browser Settings

Most browsers allow you to control cookies through their settings:

  • Chrome: Settings → Privacy and security → Cookies and other site data
  • Firefox: Settings → Privacy & Security → Cookies and Site Data
  • Safari: Preferences → Privacy → Cookies and website data
  • Edge: Settings → Cookies and site permissions → Cookies

Opt-Out Tools

You can opt out of interest-based advertising via:

Please note: Disabling all cookies may affect your ability to use certain features of our website. Strictly necessary cookies will still be used to ensure the site functions properly.

12. Security Measures

We use reasonable technical and organisational measures to protect personal data, which may include:

HTTPS/TLS Encryption

Secure data transmission for our website

Access Controls

Least-privilege permissions

Multi-factor Authentication

Where available for added security

Secure Backups

If used for data protection

Malware Monitoring

Abuse and threat detection

Staff Obligations

Confidentiality requirements

No method of transmission/storage is completely secure, but we work to protect your information.

12.1 Data Breach Notification

In the unlikely event of a data breach that poses a risk to your rights and freedoms, we will:

Notify Supervisory Authorities

Report the breach to the ICO (Information Commissioner's Office) within 72 hours of becoming aware of it, as required by UK GDPR and EU GDPR.

Notify Affected Individuals

Contact you directly without undue delay if the breach is likely to result in a high risk to your rights and freedoms. We'll use the email address or phone number you've provided.

Provide Full Details

Explain what happened, what data was affected, the potential consequences, and the measures we've taken or plan to take to address the breach and minimize harm.

Recommend Protective Actions

Advise you on steps you can take to protect yourself, such as changing passwords, monitoring accounts, or being alert for phishing attempts.

Our Commitment: We take data security seriously and maintain incident response procedures to handle any potential breaches swiftly and transparently. You will be kept informed throughout the process.

13. Your Rights (UK/EU)

Depending on your location and applicable law, you may have rights to:

Access your personal data

Request a copy of data we hold

Correct inaccurate data

Update or fix incorrect information

Delete data (where applicable)

Request erasure in certain circumstances

Restrict processing

Limit how we use your data

Object to processing

Especially marketing and some legitimate interests

Data portability

Receive data in portable format (where applicable)

Withdraw consent

Where processing is based on consent

How to exercise your rights:

Email [email protected] with "Privacy Request" and describe what you want. We may ask for verification to protect your data.

Complaints

  • UK users: you can complain to the UK data protection regulator (the Information Commissioner's Office).
  • EU/EEA users: you can complain to your local supervisory authority.

We encourage you to contact us first so we can try to resolve concerns quickly.

14. US Privacy Notice (State Laws)

If you are a resident of certain US states (e.g., California, Colorado, Connecticut, Virginia, Utah, etc.), you may have additional rights depending on whether the law applies to our business based on legal thresholds.

What we typically collect (categories)

  • Identifiers: name, email, phone
  • Commercial information: services requested/purchased
  • Internet/network activity: IP, device/browser info, website interactions
  • Professional info: company name/role (if provided)

Selling or Sharing

We do not sell personal information. If we ever engage in "sharing" for cross-context behavioural advertising, we will provide an opt-out mechanism where required.

To make a privacy request (US):

Email [email protected] with "US Privacy Request".

15. Automated Decision-Making and Profiling

Human Review Only: We do not use automated decision-making or profiling that produces legal or similarly significant effects. All quotes, consultations, and business decisions are made manually by our team members.

When you submit an enquiry or request a quote:

  • A real person reviews your enquiry and responds personally
  • All quotes are prepared manually based on your specific requirements
  • Meeting arrangements are coordinated directly with you by a team member
  • No algorithms or automated systems make decisions about your project or pricing

This ensures personalized service and gives you the opportunity to discuss your needs directly with our team.

16. Children's Privacy

Age Restriction: Our services are intended for business use and individuals aged 16 or older (13 or older in some jurisdictions). We do not knowingly collect personal information from children under these age limits.

If you believe we have inadvertently collected information from a child:

Please Contact Us Immediately

Email us at [email protected] with the subject line "Child Privacy Concern" and we will:

  • • Investigate the matter promptly
  • • Delete the information from our systems
  • • Take steps to prevent future collection
  • • Confirm the deletion with you

Parents and Guardians: If you believe your child has provided us with personal information without your consent, please contact us as outlined above.

17. Third-Party Links

Our website may link to third-party websites (e.g., client sites, tools). Their privacy practices are their own. Review their policies before submitting personal data to them.

18. Client Websites We Build / Manage (Very Important)

When we build or manage a website for a client:

  • • The client is typically responsible for their own website's privacy policy and cookie compliance (unless your contract with us states otherwise).
  • • If we process personal data on behalf of a client (e.g., troubleshooting their form submissions), we do so as a processor under their instructions and contract terms.

19. Changes to This Policy

We may update this policy to reflect legal, operational, or technology changes. Updates will be posted on this page with a new "Last updated" date.

19. Contact

If you have any questions, concerns, or requests regarding this Privacy Policy, please contact us:

Company Name

Shmo Websites

We aim to respond to all privacy-related inquiries within 30 days. For urgent matters, please call us directly.

Supervisory Authority

If you are located in the UK or EEA and have concerns about how we process your personal data, you have the right to lodge a complaint with your local data protection authority:

UK: Information Commissioner's Office (ICO)

Website: ico.org.uk
Phone: 0303 123 1113

Thank you for taking the time to read our Privacy Policy. Your privacy and trust are important to us.