Legal
Privacy Policy
This policy explains how One Webpage ("we", "us", "our") collects, uses, and protects personal information when you use https://onewebpage.co.uk or our website services.
Last updated: 25 July 2026
1. Who we are
The data controller is One Webpage, based in Belfast, Northern Ireland.
For privacy requests or questions, email hello@onewebpage.co.uk.
2. Scope
This policy covers personal data we process when you:
- Visit or use our marketing website
- Submit an enquiry or start a subscription
- Complete our post-payment content form
- Email or otherwise contact us
- Become a customer of our one-page website service
3. Information we collect
Depending on how you use our services, we may collect:
- Identity and contact details - name, email address, phone number, and business name
- Business and project details - services you offer, current website or social links, address, opening hours, about copy, company number, notes, photos, and other content you submit for your site
- Account and order data - subscription status, Stripe customer or session identifiers, and related billing metadata needed to provide the service
- Payment information - processed by Stripe. We do not store full card numbers on our servers
- Technical and usage data - IP address, browser and device information, and basic server logs generated when you visit our site
- Communications - emails and messages you send us, and our replies
We only ask for information we need to respond to you, deliver your website, or run the service.
4. How we use your information
We use personal information to:
- Respond to enquiries and provide customer support
- Create checkout sessions and manage subscriptions
- Collect website content, build, host, and maintain your one-page site
- Set up included services such as domain and business email
- Send service emails (for example payment confirmation and content form links)
- Improve and secure our website and systems
- Meet legal, tax, and accounting obligations
- Establish, exercise, or defend legal claims where necessary
We do not sell your personal information, and we do not use it for unrelated third-party marketing.
5. Legal bases (UK GDPR)
Where UK GDPR applies, we rely on one or more of the following:
- Contract - to take steps at your request before a contract, and to provide the paid website service
- Legitimate interests - to operate, secure, and improve our business and website in ways that do not override your rights
- Consent - for non-essential cookies or similar technologies where required (see our Cookie Policy)
- Legal obligation - where we must keep records for tax, accounting, or other legal reasons
6. Who we share information with
We share personal data with trusted service providers only where needed to run the service. They process data on our instructions (or as independent controllers where that is how their service works), and only for the purposes described in this policy.
- Stripe - payment processing and subscription billing
- Google Firebase - authentication, database, and file storage for content and site operations
- Resend - transactional email delivery
- Hosting / infrastructure providers - to serve and secure our website and applications
We may also disclose information if required by law, regulation, court order, or to protect our rights, customers, or the public.
7. International transfers
Some providers (including Stripe, Google, and Resend) may process data outside the United Kingdom. Where that happens, we use providers that offer appropriate safeguards recognised under UK data protection law, such as the UK International Data Transfer Agreement / Addendum or Standard Contractual Clauses, together with any additional measures those providers apply.
8. How long we keep information
We keep personal data only as long as needed for the purpose it was collected, including:
- Enquiries - typically up to 12 months after the last meaningful contact, unless you become a customer
- Customer and website content - for the life of your subscription and a reasonable period afterwards to wind down the service, resolve issues, or meet legal duties
- Billing and transaction records - usually up to 6 years where needed for tax and accounting
- Server and security logs - for a short period needed for security, troubleshooting, and abuse prevention
When data is no longer needed, we delete or anonymise it where practical.
9. Security
We use appropriate technical and organisational measures to protect personal data, including HTTPS, access controls, and reputable third- party processors for payments, hosting, and storage. No method of transmission or storage is completely secure, but we take reasonable steps to reduce risk.
10. Cookies
We use cookies and similar technologies as explained in our Cookie Policy.
11. Your rights
Under UK data protection law, you may have the right to:
- Access your personal data
- Correct inaccurate or incomplete data
- Request deletion of your data
- Restrict or object to certain processing
- Receive a copy of data you provided in a portable format
- Withdraw consent where we rely on consent
To exercise these rights, email hello@onewebpage.co.uk. We aim to respond within one month. You may need to verify your identity before we can action a request.
You also have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk.
12. Children
Our services are aimed at businesses and adults. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it where appropriate.
13. Updates
We may update this policy from time to time. The "Last updated" date at the top will change when we do. The latest version will always be published on this page.
14. Contact
Privacy questions: hello@onewebpage.co.uk
Location: Belfast, Northern Ireland
