Sitebound.app
← Back to Sitebound
Draft — not yet reviewed. This notice is complete in substance but the marked fields are unfilled and it has not been through legal review. It must be finished before the form on the home page is connected, because the form cannot lawfully collect an address without a published notice behind it. While this banner is here the page also carries <meta name="robots" content="noindex">; both come off together.

Effective DATE · version 2026-09-07

Privacy notice

Sitebound has no product yet, so there is very little to tell you. This notice covers the only personal data that exists today: what you type into the form on the home page, and anything you choose to write back to me afterwards.

Who is responsible

The controller is LEGAL OR TRADING NAME, an individual sole trader established in the United Kingdom, at ADDRESS. UK GDPR and the Data Protection Act 2018 apply to everything described here, regardless of where you are. ICO registration number: ICO NUMBER.

Questions, corrections and deletion requests: CONTACT EMAIL.

What is collected, and why

DataWhyRequired
Email addressTo confirm your signup and tell you when there is something to see.Yes
Your consent to be emailedThe lawful basis for sending you anything at all.Yes
What a finished set of drawings would have been worth to youThe reason the form exists. It is the only guide to what the paid version should cost.No
United States, or somewhere elseThe first version is US-only. This stops you being emailed about a product that cannot serve you.No
Anything you write in a reply to the confirmation emailFree text you choose to send me — usually what you would draw first. It aims the build, and I may email you back about it.No
Consent version and signup timeProof of what you agreed to and when, as UK GDPR requires.Automatic
Confirmation and unsubscribe recordsThe one-time secret inside each link, whether you clicked it and when, and how many times a confirmation was sent. It is what makes double opt-in and one-click unsubscribe work, and it is the evidence that you asked to be here.Automatic
Which page the signup came fromRecorded as the single word landing. Confirmations per source is the only demand signal that stays comparable over time; a bare total measures how far a link traveled, not what anyone wanted. It carries nothing about you.Automatic
Coarse anti-abuse data: your network rather than your address, and a one-word browser familyYour IP address is cut down before it is stored — to the first three parts of an IPv4 address, or the first 48 bits of an IPv6 one — and your browser is reduced to one of seven fixed words such as chrome or other. Two cut-down networks are kept: the one the entry was made from, and the one that most recently caused a confirmation email to be sent to it, which are not always the same person and are the only way to stop somebody using this form to mail an address over and over. None of it is ever used to locate, contact or profile anyone, and all of it is erased 30 days after signup.Automatic

Nothing else. The page runs no analytics, sets no cookies of its own, loads no third-party fonts, and does not build a profile of you. Your full IP address is never stored. The web host and Cloudflare's anti-bot check see it in passing, as they do for any website you visit; what reaches the database is the cut-down networks in the last row above, and the database will not accept a whole address even if something tries to write one.

Lawful basis

Consent, given by ticking the box on the form, evidenced by the double opt-in email. You can withdraw it at any time — the one-click unsubscribe in every message, or an email to the address above — and withdrawing it is as easy as giving it. Withdrawal does not affect anything done before you withdrew.

Three of the automatic items sit outside that consent, because they are not used to email you. The cut-down networks and the browser family exist to stop the form being abused, and the source label exists to tell whether a link brought anyone: legitimate interests. The balancing test is short — none of it identifies you, none of it is shared with anyone, and all of it is erased at 30 days. You can object to it, and the honest answer if you do is that the only way to remove it is to delete your entry, which I will do on request.

How long it is kept

If you unsubscribe, your address is kept on a suppression list rather than deleted, so that it stays off the list even if it is typed into the form again. Ask for it to be erased outright instead and it will be, with the consequence that nothing then stops it being re-added by someone who types it in.

Who else touches it

Processors, each under a data processing agreement:

ProcessorWhat forWhere
SupabaseThe database the list lives inEU/UK REGION
ResendSends the confirmation and any later updateREGION
CloudflareTurnstile, the anti-bot check on the formGlobal
HOSTServes this pageREGION
EMAIL PROVIDERReceives and stores replies you send to the confirmation email, in the mailbox I read them inREGION

Your data is never sold, never shared for anyone else's marketing, and never passed to an advertising network. Where a processor operates outside the UK, transfers rely on the UK International Data Transfer Addendum or an adequacy decision.

Your rights

Under UK GDPR you can ask for a copy of what is held about you, ask for it to be corrected or erased, object to it being processed, ask for processing to be restricted, and receive it in a portable form. Email the address above; there is one person reading, and the statutory deadline is one month. If you are unhappy with the response you can complain to the Information Commissioner's Office at ico.org.uk.

Changes

If this notice changes materially, everyone on the list is emailed before the change takes effect. The version string at the top is stored against your signup so it is always clear which wording you agreed to.