Privacy Policy
What Jarvis Studios collects when you use this site, why, who else processes it, and how to have it deleted.
Last updated
This policy covers jarvisstudios.net. It is written to be read rather than skimmed past, so it is specific about what actually happens instead of reserving every right a lawyer could think of.
The short version: the only information we ask for is what you type into the contact form. We do not sell it, we do not advertise to you, we do not build a profile of you, and we set no cookies.
Who is responsible for your data
Jarvis Studios is the data controller for the information described here. You can reach us about anything in this policy at jarvisstudios12@gmail.com, and we will respond to any request about your own data within 30 days.
What we collect
When you submit the contact form, we receive and store exactly the fields on it:
- Your name
- Your email address
- Your company name, if you choose to give one (the field is optional)
- The project type you select, if you select one (also optional)
- The message you write
What we collect automatically
Two things, neither of which identifies you by name.
Your IP address is used to rate-limit the contact form, so that one source cannot flood it. It is held briefly by our rate-limiting provider as part of a counter and expires automatically within the hour. It is not stored alongside your enquiry and we never look at it.
We also run privacy-preserving analytics on page views and page performance. These are cookieless and aggregated: they tell us that a page was viewed, roughly from where, and how quickly it loaded. They do not track you between sites, and they do not build a profile.
Why we are allowed to hold it
Under the GDPR, and as a matter of plain fairness wherever you happen to be, the reasons are:
- Your enquiry: because you asked us to contact you about working together, which is a step taken at your request before entering a contract.
- Your IP address for rate limiting: our legitimate interest in keeping a public form from being abused. There is no way to run an open contact form safely without it.
- Analytics: our legitimate interest in knowing which pages are useful. We use a cookieless, non-profiling tool specifically so this stays proportionate.
Who else processes it
We are a small studio and we do not run our own infrastructure. Your enquiry passes through these providers, and no others:
- Vercel: hosts the site and provides the cookieless analytics described above.
- Supabase: the database your enquiry is stored in.
- Upstash: the rate-limiting store that briefly holds the IP counter.
- Resend: delivers the notification email containing your enquiry to us.
- Slack: receives a notification message containing your enquiry.
A copy reaches our inbox
Worth stating plainly, because most policies leave it implied: the notification email and Slack message contain what you wrote. That means a copy of your enquiry lives in our email and our Slack workspace as well as in the database, and it stays there under those services' own retention until we delete it. When you ask us to erase your data, we delete those copies too, not just the database row.
How long we keep it
We keep enquiries for 24 months from our last contact with you, then delete them. A project conversation can restart a year later, which is why the window is not shorter; there is no reason for it to be longer.
Rate-limiting records expire automatically within an hour. Analytics data is aggregated and holds nothing that identifies you.
Your rights
We extend these to every visitor, not only those in a jurisdiction that mandates them. You can ask us to:
- Give you a copy of what we hold about you
- Correct anything that is wrong
- Delete it entirely
- Restrict what we do with it, or object to us holding it at all
- Send it to you in a portable, machine-readable format
How to exercise them
Email jarvisstudios12@gmail.com. We do not require a form, an account, or a reason. If you are in the UK or EU and you think we have handled your data badly, you are also entitled to complain to your national data protection authority, and you do not need to raise it with us first.
Where your data goes
The providers listed above may process data on servers outside your country, including in the United States. Where that involves personal data leaving the UK or EEA, it is covered by the transfer safeguards those providers maintain, such as Standard Contractual Clauses.
What we do not do
We do not sell or rent your information. We do not share it with advertisers. We do not use it to train machine-learning models. We do not make automated decisions about you, and we do not profile you. If any of that changes, it changes here first.
Security
Enquiries are stored in a database with no public read or write access. Every access goes through our server, never your browser. The site is served over HTTPS only. Input is validated and escaped on the server before it is stored or included in any notification.
No system is perfect, and we would rather say that than claim otherwise. If you find a security problem with this site, please tell us at the address above.
Children
This is a business-to-business site and it is not directed at children. We do not knowingly collect information from anyone under 16. If you believe a child has sent us something, contact us and we will delete it.
Changes to this policy
If we change what we collect, who processes it, or how long we keep it, we update this page and the date at the top of it. Material changes are not applied retroactively to data already collected under an earlier version.