Privacy policy
Last updated: 6 October 2026
RevUp Online Ltd, registered in England and Wales, company number 14084762. Registered office: 86 St Benedicts Street, Norwich, Norfolk, NR2 4AB. VAT number GB412102959.
Who we are
My Webby is a product of RevUp Online Ltd, company number 14084762, and we are the data controller for the personal data described in this policy. Our registered office is shown at the top of this page. We are on the Information Commissioner's register under number ZB406127.
To ask about your data or to make a request, email us at hello@mywebby.co.uk or use our contact page. We answer within one month, and it costs you nothing.
Our website and customer data are hosted in the EU, by Netcup. Some of the companies we use to run the service are based in the United States, so some data may be processed there. Each one, and how that data is protected, is listed below.
When we act for a business
Businesses that use My Webby collect personal data from their own customers through the websites we build and the customer hub: enquiries, bookings, quotes and jobs, client records, review requests and reviews, and the email in their business mailboxes. For that data, the business is the data controller and we are its data processor. We only use it to run those features for the business, under the data processing schedule in our terms and conditions.
If you contacted or booked with a business that uses My Webby, that business decides what happens to your details. Ask the business first. If you cannot reach them, contact us and we will pass your request on.
What data we collect and why
For customers and their team:
| Data | Legal basis | How long we keep it |
|---|---|---|
| Name, email, password hash | Contract | Until you ask us to delete your account, then up to 30 days |
| Business name, address, phone | Contract | Until you ask us to delete your account, then up to 30 days |
| Payment card details | Contract | Never stored by us, Stripe only |
| Billing history, invoices | Legal obligation (tax) | 7 years |
| Subscription status and plan | Contract | Your subscription, then 7 years |
| IP address, sign-in times | Legitimate interest (security) | 90 days |
| Uploaded files (logo, images) | Contract | Until you ask us to delete your account, then up to 30 days |
| Your website brief and change requests | Contract | Until you ask us to delete your account, then up to 30 days |
| Emails about your account, your plan and your website | Contract | Our record of each email sent, 90 days |
| Support messages | Legitimate interest | 2 years |
| A login made at signup that was never paid for | Legitimate interest (letting you finish signing up) | 90 days |
| Your details while you pay at checkout | Contract | Up to 4 days after the checkout closes |
| A copy of your data you asked to download | Legal obligation (your right of access) | 7 days, then the link stops working |
Before you sign up:
| What | Data | Legal basis | How long we keep it |
|---|---|---|---|
| Asking for a website design | Name, email, phone, business details and your answers | Legitimate interest (building the design you asked for) | 90 days if you do not sign up |
| Half-finished answers | Your email and the answers you had given so far | Legitimate interest (letting you pick up where you left off) | 30 days after your last visit |
| Reminder emails about half-finished answers | Your email address | Legitimate interest. Every email has a link to stop them | Up to four emails, then none |
| A message from the contact page | Name, email, phone if given, business details if given, your message | Legitimate interest (answering you) | 90 days if you do not sign up |
| Booking a meeting | Name, email, phone, business name if given, your notes, the time | Legitimate interest (holding the call you booked) | Kept for the call you booked. Ask us and we delete it |
| Seeing what is happening on our site while you are on it | The page you are on, the step you are on, where you came from and your kind of device. No cookie is added for it | Legitimate interest (helping you while you are here) | 1 day |
| Measuring our adverts when you ask for a website or sign up | The click id if you came from an advert, and a scrambled (hashed) copy of your email and phone | Legitimate interest (knowing which adverts work) | Our record of what we sent, 90 days. The advertising network keeps its copy under its own terms |
When you ask for a website or sign up, we tell our advertising networks (Google, Microsoft and Meta) so we know which adverts work. We send the click id if you came from one of our adverts and, for Google and Meta, a scrambled (hashed) copy of your email address and phone number, which they can only match against accounts they already hold. This is sent from our server, not through cookies, whatever you choose in cookie settings. The advertising cookies on this site are separate, and you can turn them off in cookie settings. You can object to this measurement at any time by emailing us.
For the businesses we work for, we keep their customers' enquiries, bookings and other records for as long as the business keeps them in its customer hub. The business can delete them at any time. Anything marked as spam is deleted after 30 days. When a business's account is deleted, all of it goes within 30 days.
Copies of data in our backups are removed as the backups roll over, so they last a little longer than the periods above.
How we use AI
Webby, the AI that does the groundwork on your design and words, is provided to us by Anthropic. When you ask for a design, the answers you give us (your business name, trade, town, services, the phone and email you want on the website, and your existing website if you have one) are sent to Anthropic so it can write the first draft. We also use it to help write the SEO content and Google Business Profile posts we do for customers. We use Anthropic under its commercial terms, which say it does not train its models on what we send it.
If we switch on Google's image tool for your design, Google gets your business name, your trade and a description of each picture so it can draw your logo or the pictures on your page.
Our website specialists check everything before your website goes live.
Decisions made automatically
Enquiries sent through the websites we build are checked by an automatic spam filter on our own servers. It uses no AI. An enquiry it thinks is spam is kept in the business's spam folder, where the business can still read it and mark it as not spam, and is deleted after 30 days. Requests for a free design are limited per email address and per connection, and throwaway email addresses are refused. None of this has a legal effect on you or anything of similar weight. If you think a decision was wrong, tell us and a person will look at it.
Your rights
Under UK GDPR you have the right to access, erase, move, correct, object to and restrict the use of your personal data.
- Access: download all your data from your portal under Account settings. We email you a link when it is ready, and the link works for 7 days.
- Erasure: ask to delete your account under Account settings in your portal, or email hello@mywebby.co.uk and we close it for you. Personal data is deleted within 30 days of the request. Your account is not deleted just because your plan ends, so you can come back to it. Ask us to delete it whenever you like. Billing records are anonymised instead of deleted, because tax rules require us to keep them for 7 years.
- Portability: export your enquiries and bookings as CSV at any time, and your site content as part of the full data download.
- Correction: edit your name, email, phone and business details in the portal at any time.
- Object and restrict: stop any email we send from the link in it, turn analytics or advertising cookies off in cookie settings, or ask us to stop or pause anything else.
For anything from before you signed up (a design, a message, a meeting), or anything the portal does not cover, email hello@mywebby.co.uk. We may ask you to confirm who you are first, so we do not hand your details to somebody else.
Who we share data with
We use these companies to run the service. Each works under a data processing agreement and only uses the data to do the job for us. When we act for a business, the same companies are the sub-processors for its customers' data.
| Company | What for | Data shared | Whose data | Where |
|---|---|---|---|---|
| Netcup | Hosting our website, the websites we build, our own mail server and all of the data | All data | Everyone in this policy | EU |
| ServerAvatar | Managing our servers | Access to the servers that hold the data | Everyone in this policy | EU/UK |
| Cloudflare | Network and DNS, and the "are you a person" check on our forms | IP addresses and request details | Everyone in this policy | Worldwide, US company |
| Cloudflare (R2 storage) | File storage and backups | Uploaded files, data downloads, backup copies | Everyone in this policy | EU/UK |
| Stripe | Taking payments | Name, email, card and billing details, subscription status | Customers | US and Ireland |
| Anthropic | Webby, our AI: design groundwork and SEO writing | Your answers, your website brief, business details | People asking for a design, customers | US |
| Google (Gemini) | Drawing logos and pictures for a design, only when we switch it on | Business name, trade, a description of the picture | People asking for a design, customers | US |
| OpenAI, xAI | Stand-in AI if Anthropic is down, only when we switch one on | The same as Anthropic | People asking for a design, customers | US |
| Postmark | Sending emails, including the ones a business sends its own customers (enquiry replies, booking reminders, quotes, review requests) | Email address, name and the email | Everyone in this policy | US |
| MXroute | Business email for some customers | Email addresses, mailbox passwords and the email in the mailbox | Customers and the people who email them | EU/UK |
| Namecheap | Registering your domain | Your domain name. We are the registered owner, so none of your own details are sent | Customers | US |
| GitHub | Storing and publishing the websites we build | Everything on your website: business name, the contact details you publish, words and photos. Never enquiries | Customers | US |
| Sentry | Telling us when something breaks | Technical details of the error, with personal data switched off and form contents removed | Everyone in this policy | EU/UK |
| Slack | Alerts to our team | Business name, trade, town and website address, and the start of a change request you send. Never your name, email or phone | People asking for a design, customers | US |
| Plausible (run by us) | Counting visits to this site and the websites we build | Visit counts only, no cookies | Visitors | Our own servers (EU) |
| Google (Analytics and Ads) | Measuring our site and our adverts: cookies you can turn off, and the measurement described above when you ask for a website or sign up | Cookie ids, pages visited, hashed email and phone | Visitors, people asking for a design, customers | US |
| Google (Business Profile) | Bringing a business's Google reviews into its portal, and its posts onto Google | Reviewer names and reviews, the business's posts | Customers and the people who review them | US |
| Microsoft Advertising | Measuring our adverts: cookies you can turn off, and the measurement described above when you ask for a website or sign up | Cookie ids, pages visited, click ids | Visitors, people asking for a design, customers | US |
| Meta (Facebook and Instagram) | Measuring our adverts: cookies you can turn off, and the measurement described above when you ask for a website or sign up | Cookie ids, pages visited, hashed email and phone | Visitors, people asking for a design, customers | US and Ireland |
When a business connects its own Google, Microsoft or Meta advertising account, the websites we build tell that account about each enquiry, with a scrambled (hashed) copy of the email and phone given. That is done for the business, on its instructions, and the business is responsible for telling its own customers.
Data sent outside the UK and EU
The companies marked US above may process data in the United States. Where they do, the data is protected by UK-approved safeguards, such as the UK's adequacy regulations for the US (the UK-US data bridge, also called the UK Extension to the EU-US Data Privacy Framework) where the company is certified under it, or otherwise the ICO's International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses. Data sent to the EU is covered by the UK's adequacy regulations for the EU. Ask us through the contact page if you would like to know which applies to a particular company.
Children
My Webby is a service for businesses and is not aimed at children. We do not knowingly collect children's data.
Cookies
We use essential, analytics and advertising cookies. You can turn the analytics and advertising ones off at any time. See our cookie policy for the full list and how to change your mind.
Complaints
If you have a concern about how we handle your data, please tell us first and we will try to put it right. You also have the right to complain to the Information Commissioner's Office (ICO), the UK data protection regulator, at ico.org.uk/make-a-complaint or on 0303 123 1113.
Changes to this policy
We may update this policy from time to time. The latest version is always on this page, with the date it last changed at the top.