Privacy Policy
Last updated: 31 August 2026
Who we are and what this policy covers
Mintygo (mintygo.com) builds fixed-price websites for small businesses. This policy explains what personal data we collect when you visit mintygo.com or use one of the forms on the site, why we collect it, how long we keep it, who we share it with, and the rights you have over it. It applies to mintygo.com and the two lead forms currently on the site: the quote form and the free audit form.
If you have any questions about this policy or want to exercise any of the rights described below, contact us at hello@mintygo.com.
What personal data we collect, and why
We collect personal data in a small number of specific ways. We don't have user accounts, we don't run a checkout on the site, and we don't run any analytics or advertising tracking. Here's everything that actually happens.
The quote form
When you request a quote, we ask for your name, email address, your current website URL (optional), the package you're interested in, and a free-text message describing what you need. We use this to respond to your enquiry and put together a quote.
Legal basis: legitimate interest (Article 6(1)(f) UK/EU GDPR). Responding to a direct request you've made for a commercial quote is a normal part of running the business, and processing your contact details for that single purpose is what you'd reasonably expect. Where we go on to form a contract with you, later processing is based on taking steps prior to entering a contract (Article 6(1)(b)).
The audit form
When you request a free website audit (a PageSpeed/SEO report), we ask for the URL of the website you want audited and your email address so we can send you the report.
Legal basis: legitimate interest (Article 6(1)(f)). You're asking us for something specific, and giving us your email is necessary to deliver it. We only use the email address to send you the report and any related follow-up about it, not for unrelated marketing, unless you separately opt in to that later.
How both forms reach us
Both forms post to a single backend endpoint (/api/lead), which formats the submission into a message and posts it to a private Slack channel via a Slack incoming webhook. There is currently no database. Slack is the only place your submission is stored after that point, and it's retained according to our Slack workspace's own settings and Slack's retention policies. We don't keep a separate copy anywhere else.
Both forms also include a hidden honeypot field used purely for spam filtering. It isn't personal data, nothing you enter goes into it, and if a bot fills it in, the submission is discarded rather than processed.
Server and hosting logs
The site is hosted on Vercel. Like any web host, Vercel's infrastructure incidentally processes technical data about each request to load the site, including your IP address, browser type, and request timestamps, as part of running the servers and edge network that serve you the page. We don't access or use this data ourselves for tracking or profiling; it's a normal function of web hosting, handled by Vercel as our hosting provider.
Legal basis: legitimate interest (Article 6(1)(f)), keeping the site running, secure, and available.
Fonts
The typefaces on this site are hosted on our own servers rather than loaded from Google Fonts or any other third party. Your browser never contacts an external font provider when a page loads, so no data about you passes to one for this purpose.
Future: sending you the audit report by email
We don't currently send emails from the site. The audit report request only reaches us via Slack today, and a person on our team follows up. We expect to add a transactional email service soon so the audit report can be sent to your inbox automatically. When we do, that provider will process your email address as a processor on our behalf, purely to deliver the message you asked for. We'll update this policy to name the provider once one is chosen, and, where required, obtain any additional consent needed for that specific processing.
What we don't collect
We don't use cookies, analytics, or advertising/tracking scripts of any kind on mintygo.com today: no Google Analytics, no Meta Pixel, no Plausible, nothing. We don't run a checkout or take payments on the site (our pricing is invoiced separately, half up front and half on launch, entirely off-site, so we never see or store payment card details). We don't have user accounts or logins.
How long we keep your data
- Quote and audit form submissions: retained in Slack for as long as our Slack workspace retains messages under our plan's settings, or until we manually delete the message, whichever is sooner. We don't keep a separate copy elsewhere.
- Server and hosting logs: retained by Vercel according to its own standard log-retention periods as our hosting provider, not set by us on a per-visitor basis.
- Font requests: not retained by us at all. This is a live request made by your browser to Google each time a page loads, not something we store.
We don't currently have a database, so we're not keeping a running record of every enquiry beyond what sits in Slack. If that changes, for example if we add a CRM or database to track leads properly, we'll update this policy to describe the new retention period.
Who we share your data with, and why
We use a small number of third-party services to run the site and handle enquiries. Each one only receives the data it needs to do its job:
- Slack (Salesforce, Inc.): receives the contents of both lead forms via a webhook, so our team can see and respond to enquiries. Slack acts as a data processor for this purpose.
- Vercel Inc.: hosts the site and its API route, and incidentally processes visitor IP addresses and request logs as part of serving pages and running the backend.
- Sanity.io: powers the CMS behind our blog. Sanity stores and serves our editorial content (blog posts, images we've chosen to publish), not visitor personal data. Its CDN serves requests for that content as part of normal site infrastructure, the same way Vercel does.
- A future transactional email provider: not yet in use. See the section above. We'll update this policy before or as soon as this goes live.
We may add further sub-processors as the site develops, for instance if we introduce a proper CRM or database instead of relying on Slack alone. We'll keep this policy updated to reflect who's actually processing your data at any given time. We don't sell your personal data, and we don't share it with third parties for their own marketing purposes.
International data transfers
Slack and Vercel are both US-based companies, and processing your data through them can involve transferring it outside the UK and EU. Where that happens, we rely on the safeguards those providers have in place rather than assuming a transfer is automatically fine:
- Slack offers a Data Processing Addendum incorporating the EU Standard Contractual Clauses (SCCs) approved by the European Commission, covering transfers to the US and other countries.
- Vercel signs the 2021 EU Standard Contractual Clauses (Commission decision 2021/914) under Article 46(2)(c) GDPR, plus the UK International Data Transfer Addendum for UK transfers, and applies supplementary technical measures such as encryption in transit and at rest.
These clauses are the standard, legally recognised mechanism under GDPR Chapter V for transferring personal data to a country, like the US, that doesn't have a UK/EU adequacy decision. We haven't independently audited each provider's implementation, but each is an established company that publishes its transfer mechanism, and we choose providers on that basis.
Your rights under UK and EU GDPR
If you're in the UK or the EU, data protection law gives you the following rights over your personal data:
- Right of access: ask us what personal data we hold about you and get a copy of it.
- Right to rectification: ask us to correct data that's inaccurate or incomplete.
- Right to erasure: ask us to delete your personal data, subject to certain exceptions (for example, if we need to keep something for legal reasons).
- Right to restrict processing: ask us to pause processing your data in certain circumstances, without necessarily deleting it.
- Right to data portability: ask for the personal data you've given us in a structured, commonly used, machine-readable format, where we're processing it based on consent or a contract and by automated means.
- Right to object: object to us processing your data based on legitimate interest, including anything resembling direct marketing.
- Rights related to automated decision-making: we don't carry out automated decision-making or profiling that has legal or similarly significant effects on you, so this doesn't currently apply to how we use your data.
To exercise any of these, email hello@mintygo.com. We'll respond within one month, as required by law.
If you're not satisfied with how we've handled your data, you have the right to complain to a supervisory authority. In the UK, that's the Information Commissioner's Office. If you're in the EU, you can complain to your local data protection authority (for example, the CNIL in France or the Datenschutzbehörde in Austria); a full list is available via the European Data Protection Board.
We don't have a dedicated Data Protection Officer. Under UK and EU GDPR, a DPO is only legally required for public authorities, or businesses whose core activity involves large-scale, regular and systematic monitoring of individuals, or large-scale processing of special category data, none of which describes Mintygo. hello@mintygo.com is the right contact point for any data protection query in the meantime.
Your rights under US state privacy laws
California (CCPA/CPRA)
California residents have the right to know what personal information a business collects, to delete it, to correct inaccurate information, to opt out of the sale or sharing of personal information, to limit use of sensitive personal information, and not to be discriminated against for exercising these rights. In practice, the CCPA's obligations only apply to businesses that meet at least one of three thresholds: annual gross revenue above roughly $26.6 million (a figure adjusted for inflation periodically), buying, selling, or sharing the personal information of 100,000 or more California consumers or households a year, or deriving 50% or more of annual revenue from selling or sharing personal information. Mintygo doesn't meet any of these thresholds, so the CCPA's obligations most likely don't legally apply to us at this scale. We're including these rights here anyway as good practice: if you're a California resident and want to know what we hold about you or want it deleted, email hello@mintygo.com and we'll handle it the same way we would any other request under this policy.
Other US states
A number of other states, including Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Oregon (OCPA), Montana (MCDPA), and Texas (TDPSA), have their own comprehensive privacy laws. Most set applicability thresholds based on the number of residents' data a business processes each year, commonly 25,000 to 100,000 or more, rather than revenue; Montana's threshold is lower, at 50,000. Texas's law is unusual in that it exempts businesses that qualify as a "small business" under the federal Small Business Act, regardless of how many Texans' data they process. Given the volume of data Mintygo currently processes, through two lead forms with no analytics or ad tracking, we don't believe we meet the applicability thresholds under any of these laws today. As with California, we'll honor requests to know, correct, or delete your personal data regardless of which state you're in: email hello@mintygo.com.
If our data practices grow, for example if we add analytics, advertising, or a larger customer database, we'll reassess which of these laws apply to us and update this policy accordingly.
Cookies and similar technologies
We don't currently set any cookies on mintygo.com, and we don't use analytics or advertising technologies of any kind. If that changes, for example if we add website analytics down the line, we'll update this policy with a proper breakdown of what's set, why, and how you can control it, and we'll ask for consent first wherever the law requires it.
Children's privacy
Mintygo is a business-to-business service aimed at small business owners and isn't directed at, or intended for use by, children. We don't knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us at hello@mintygo.com and we'll delete it.
Changes to this policy
We may update this policy as the site and our data practices change, for example when we add an email provider for audit reports or introduce analytics. We'll update the "last updated" date at the top of this page when we do. If a change is significant, we'll make a reasonable effort to flag it prominently on the site.
How to contact us
For anything relating to this policy or your personal data, email hello@mintygo.com. That's where a request to access, correct, delete, or otherwise exercise your rights should go.