Legal

Privacy Policy

Last updated: 22 July 2026

This policy explains what personal information Weblia collects, why we collect it, how long we keep it, and what rights you have over it. It applies to our website and to the services we provide.

We’ve tried to write it in plain English rather than legal boilerplate. If anything here is unclear, open a support ticket and ask — we’d rather explain it than have you guess.

1. Who we are

Weblia builds websites for small businesses. For the information we hold about you as a customer or enquirer, Weblia is the data controller — meaning we decide what is collected and why.

We’re based in the United Kingdom and handle personal data in line with the UK GDPR and the Data Protection Act 2018.

2. What we collect

Only what we need to run the service. In practice that’s:

WhenWhat we collect
Creating an accountYour name, email address, a securely hashed password, and the date you signed up
Placing an orderName, email, business name (if given), and your project brief — what you want on the site, pages, colours, style, whether you have a logo or content, example sites you like, your domain and preferred launch date
Contacting supportYour name, email, subject and the full contents of your chat thread
Any of the aboveYour IP address and the time of the request, recorded for security and abuse prevention
Resetting a passwordA single-use, time-limited token (we never store the reset link itself in a usable form)
We don’t collect card details Payment information is entered directly into Stripe’s secure form and never passes through or is stored on our servers. We only ever see the outcome — whether a payment succeeded, and the amount.

We don’t buy personal data from third parties, and we don’t use tracking pixels or advertising cookies.

3. Why we collect it, and our lawful basis

UK data protection law requires us to have a valid reason for processing your data. Ours are:

PurposeLawful basis
Delivering the website you’ve orderedPerformance of a contract
Taking payment and issuing receiptsPerformance of a contract
Answering support messagesPerformance of a contract, or legitimate interests
Keeping accounts and tax recordsLegal obligation
Preventing spam, fraud and abuseLegitimate interests
Keeping our own service secureLegitimate interests

Where we rely on legitimate interests, we’ve considered whether it’s fair to you. Logging IP addresses to stop someone flooding our contact form is a good example: minimal data, clear benefit, no real intrusion.

We don’t send marketing emails. If that ever changes, we’ll ask for your consent first and you’ll be able to withdraw it at any time.

4. Payments

Payments are processed by Stripe Payments Europe, Ltd. When you pay, your card details go directly to Stripe. We receive confirmation of the payment, the amount, and a reference — never the card number.

Stripe acts as an independent data controller for payment data and processes it under its own privacy policy, available at stripe.com. Stripe may transfer data outside the UK; it uses approved safeguards for those transfers.

For monthly plans, Stripe securely stores your payment method so the subscription can renew. You can ask us to cancel a subscription at any time by opening a support ticket.

5. Who we share it with

We don’t sell your data, and we don’t share it for advertising. We do use a small number of service providers to operate:

WhoWhat they see, and why
StripeYour name, email and payment details, in order to take payment
Google FontsServes the typefaces used on our site. Your browser requests these from Google, which involves your IP address

We may also disclose information where we’re legally required to — for example to a court, HMRC, or a regulator.

6. How long we keep it

DataKept for
Order records and invoices7 years, as required for UK tax purposes
Account detailsWhile your account is open, then deleted within 30 days of closure
Support conversations2 years from the last message
Enquiries that don’t become orders12 months
Password reset tokens1 hour, then automatically discarded
IP addresses in security logs12 months

When a retention period ends, we delete the data or anonymise it so it can no longer identify you.

7. How we protect it

No system is perfectly secure. If a breach ever occurred that risked your rights or freedoms, we’d report it to the ICO within 72 hours and tell affected customers without undue delay.

8. Cookies

We use one cookie: a session cookie that keeps you signed in as you move between pages. It’s strictly necessary for the site to work, so it doesn’t require consent under the cookie rules.

It lasts up to 30 days if you stay signed in, and is removed when you log out. We don’t use analytics, advertising or tracking cookies. If we add analytics in future, we’ll ask for your consent first.

9. Your rights

Under UK data protection law you have the following rights, free of charge:

Access

Ask for a copy of the personal data we hold about you.

Correction

Have inaccurate or incomplete information put right.

Erasure

Ask us to delete your data, where we don’t need to keep it by law.

Restriction

Ask us to pause processing while a concern is resolved.

Portability

Receive your data in a common, machine-readable format.

Objection

Object to processing we carry out under legitimate interests.

To use any of these, open a support ticket and tell us what you’d like. We’ll respond within one month. We may need to verify who you are first, so that we don’t hand your data to someone else.

Note that we can’t delete records we’re legally required to retain — invoices, for instance, must be kept for seven years. We’ll tell you if that applies.

10. Data on the websites we build

If we build a site for you that collects personal data — a contact form, bookings, an enquiry list — then for that data you are the controller and we are the processor. It’s your data; we handle it on your instructions.

That means you’re responsible for having your own privacy policy and a lawful basis for collecting it. We’ll act on your reasonable instructions, keep it secure, and return or delete it when our work ends.

If you need a formal data processing agreement, open a ticket and we’ll provide one.

11. Children

Our services are aimed at businesses and aren’t intended for children. We don’t knowingly collect data from anyone under 16. If you believe a child has given us personal data, tell us and we’ll delete it.

12. Changes to this policy

We may update this policy as the service changes. The version published here is the one that applies. If we make a significant change to how we use your data, we’ll tell existing customers directly.

13. Contact & complaints

The quickest way to reach us about anything in this policy — including a request to access or delete your data — is to open a support ticket.

Open a support ticket Start a conversation from our contact section, or from your account dashboard if you have an account. You’ll get a reference and a live chat thread you can return to.

If you’re unhappy with how we’ve handled your data, please tell us first so we can put it right. You also have the right to complain to the Information Commissioner’s Office (ICO), the UK’s data protection regulator, at ico.org.uk or on 0303 123 1113.