Privacy policy
Last updated: 4 May 2026
1. Who we are
Highstreet Sites (“we”, “us”, “our”) is a sole-trader business operated from the United Kingdom. We design, build, host, and maintain landing pages for local businesses.
For the purposes of UK GDPR and the Data Protection Act 2018, we are the data controller for the personal information you provide through this website.
Contact for data-protection enquiries: hello@highstreetsites.co.uk
2. What information we collect
We collect the following information when you interact with this site:
- Contact form submissions: your name, email address, business name, the plan you are interested in, and the message you write to us.
- Server access logs: your IP address, browser type, and the pages you visit. These are kept for security and abuse prevention only.
- Analytics: aggregated, anonymised information about how visitors use the site (pages viewed, country, referrer). We use Plausible Analytics, which does not set cookies and does not collect personal data.
We do not collect any special-category data (health, biometric, political opinion, etc.). We do not knowingly collect data from children under 13.
3. Why we use your information (lawful basis)
We process your personal data on the following lawful bases under UK GDPR:
- Legitimate interest (Article 6(1)(f)): to respond to your enquiry and provide a quote when you submit our contact form. Replying to people who reach out to us is a fundamental business activity.
- Contract (Article 6(1)(b)): if you become a client, we use your contact details to deliver the service, send invoices, and provide support.
- Legal obligation (Article 6(1)(c)): we keep invoice and tax records for the period required by HMRC (currently six years).
4. Who we share your information with
We do not sell your data. We share it only with the service providers necessary to operate the site and respond to your enquiry. These providers are bound by their own data-protection obligations:
- Vercel Inc. — website hosting and contact-form processing. Servers located in the EU/EEA where possible.
- Resend — transactional email delivery for contact form submissions and replies.
- Plausible Insights OÜ — privacy-focused analytics, hosted in the EU.
- Stripe Payments Europe Ltd. — payment processing, only if you become a paying client.
- Cloudflare Inc. — DNS and content-delivery network for performance and security.
Some providers (e.g. Stripe, Cloudflare) may transfer data outside the UK or EEA. These transfers are protected by the UK International Data Transfer Agreement or the EU Standard Contractual Clauses with UK addendum.
5. How long we keep your information
- Contact form enquiries that do not become clients: deleted within 12 months.
- Client records (active and former clients): kept for the duration of our working relationship plus six years for HMRC tax purposes.
- Server logs: retained for 30 days, then deleted.
- Analytics: aggregated and not tied to any individual; retained indefinitely.
6. Your rights under UK GDPR
You have the following rights regarding your personal data:
- Right of access — ask for a copy of the data we hold about you.
- Right to rectification — ask us to correct inaccurate or incomplete data.
- Right to erasure ("right to be forgotten") — ask us to delete your data, subject to legal retention requirements.
- Right to restrict processing — ask us to stop using your data while a query is resolved.
- Right to data portability — receive your data in a portable format.
- Right to object — object to processing based on legitimate interest.
- Right to withdraw consent — where we rely on consent, withdraw it at any time.
To exercise any of these rights, email hello@highstreetsites.co.uk. We will respond within 30 days.
7. Cookies
This website does not use tracking cookies. We use Plausible Analytics, which is cookieless by design. We may set strictly necessary cookies for security (e.g. CSRF protection on the contact form) — these are essential and do not track you.
8. Security
We protect your personal data using HTTPS encryption, access-controlled hosting, and reputable third-party processors with their own security certifications (Vercel, Resend, Cloudflare, Stripe). However, no system is perfectly secure. If you believe your data has been compromised, please contact us immediately.
9. Complaints
If you are unhappy with how we have handled your personal data, please contact us first so we can try to resolve the issue. You also have the right to complain to the UK’s Information Commissioner’s Office (ICO) at any time:
ico.org.uk/make-a-complaint · Helpline: 0303 123 1113
10. Changes to this policy
We may update this policy from time to time. The date at the top of the page reflects the most recent revision. Material changes that affect your rights will be communicated by email to clients and posted prominently on this page.
Have a question about this policy or your data? Email us at hello@highstreetsites.co.uk or return to the home page.