Privacy Policy
This policy explains what personal data Rune Sites collects, why we collect it, who we share it with and what control you have over it. It covers this website and the applications we operate under the Rune Sites name.
Last updated: 27 August 2026
1. Who we are
Rune Sites (“we”, “us”) designs, builds and looks after websites and social media content for small businesses. We operate the website at runewebsites.com and are based in the United Kingdom.
For the personal data described in this policy, Rune Sites is the data controller under the UK GDPR and the Data Protection Act 2018. You can reach us at willweatherhead636@gmail.com, and we will provide a postal address on request.
2. What we collect
We only collect data you give us, plus the minimum our hosting needs to run.
Information you give us
- Quote and enquiry forms. Your name, email address, business name, and optionally your phone number, together with the details of the project itself — the type of website you want, your business type, the features and package you select, colour and style preferences, example sites you like, and any notes you write.
- Custom requests. Your name, email address and the message you send us.
- Direct correspondence. Anything you send us by email, along with your email address.
Information collected automatically
- Server and security logs. Our hosting provider records standard request data such as IP address, browser user-agent, the page requested and the time of the request. This is used to keep the site running and to protect it from abuse.
- Your browser’s local storage. Your basket and any part-completed quote form are saved in your own browser so you don’t lose your progress. This stays on your device and is not sent to us until you submit the form.
We do not run advertising or analytics trackers on this website, we do not use tracking cookies, we do not sell or rent personal data to anyone, and we do not build advertising profiles. We do not take payment card details on this site.
3. Why we use it, and our legal basis
Under the UK GDPR we must have a lawful basis for using your data. Ours are:
| What we do | Legal basis |
|---|---|
| Reply to your enquiry and prepare a quote or proposal | Steps taken at your request before entering a contract |
| Deliver, support and invoice for work you have commissioned | Performance of a contract |
| Send you a confirmation email when you submit a form | Steps taken at your request / legitimate interests |
| Keep the site secure, prevent spam and fix faults | Legitimate interests in running a safe, working service |
| Keep records for tax and accounting | Legal obligation |
We do not send marketing emails to people who have only requested a quote. If we ever introduce a mailing list, it will be opt-in and every message will carry an unsubscribe link.
6. Connected platform APIs (Pinterest, Instagram, Etsy)
Rune Sites operates internal tools that connect to third-party platform APIs — including the Pinterest API, and where enabled the Instagram and Etsy APIs — in order to publish and manage our own marketing content and that of clients who have asked us to manage their accounts.
What we access and why
- Access is granted only through the platform’s own OAuth flow, by the owner of the account, after they have reviewed and approved the permissions requested.
- We request the narrowest set of permissions needed to do the job: reading the boards or profiles the account holder has authorised, creating and updating posts or pins on those boards, and reading the resulting performance statistics.
- We use that access solely to schedule, publish and report on content for the account that granted it. We do not use platform data for advertising, for training machine-learning models, for building profiles of other people, or for any purpose the account holder has not asked us to perform.
- We do not access, collect or store the personal data of a platform’s wider users — for example other people’s Pins, boards, followers or private messages — beyond the aggregate engagement figures the platform returns about the connected account’s own content.
How we store and protect it
- Access tokens and account identifiers are held as encrypted server-side credentials, never in the browser and never in our public source code.
- Access to these tools is restricted to authenticated Rune Sites operators, and every action that writes to an external platform requires a person to approve it.
- Content and statistics retrieved from a platform are kept only as long as the connection is active, and are deleted when it ends.
Revoking access and deletion
An account holder can disconnect us at any time from within their platform’s own settings — for Pinterest, under Settings › Security and permissions › Apps. Revoking access immediately stops all further use. To have the associated tokens and stored content deleted from our systems as well, email willweatherhead636@gmail.com and we will delete them within 30 days.
Our use of these APIs is also subject to each platform’s own developer terms and privacy policy. Their handling of your data on their own services is governed by their policies, not this one.
7. How long we keep it
- Enquiries that do not become projects — kept for up to 24 months, then deleted.
- Client project records — kept for the life of the working relationship and for 6 years afterwards, which is the period UK tax and accounting rules require.
- Server and security logs — kept for a short period by our hosting provider under their retention schedule.
- Platform API tokens — deleted when the connection is revoked or the relationship ends.
You can ask us to delete your data sooner — see your rights below.
8. International transfers
Some of our providers are based outside the UK, principally in the United States. Where personal data is transferred outside the UK, it is protected by an adequacy decision or by the International Data Transfer Agreement or Addendum (the UK’s Standard Contractual Clauses), which places contractual obligations on the provider to protect your data to UK standards.
9. Security
The site is served over HTTPS. Form submissions are validated on the server, and database and email credentials are held as server-side environment variables, never exposed to the browser. Access to stored enquiries is limited to people who need it to do the work.
No system can be guaranteed completely secure. If a breach affecting your rights occurs, we will notify the Information Commissioner’s Office and, where required, you, without undue delay.
10. Your rights
Under UK data protection law you have the right to:
- Ask what personal data we hold about you, and get a copy of it
- Have inaccurate data corrected
- Ask us to delete your data, where we have no overriding reason to keep it
- Ask us to restrict how we use it, or object to our using it
- Receive the data you gave us in a portable, machine-readable format
- Withdraw consent at any time, where we relied on consent
To exercise any of these, email willweatherhead636@gmail.com. We will respond within one month, and it is free. If you are unhappy with how we have handled your data, you can complain to the Information Commissioner’s Office at ico.org.uk or on 0303 123 1113 — though we would appreciate the chance to put it right first.
11. Children
Our services are aimed at businesses. We do not knowingly collect personal data from anyone under 16. If you believe a child has given us their data, contact us and we will delete it.
12. Changes to this policy
We may update this policy as our services change. The date at the top always shows the current version, and material changes will be highlighted on this page.
13. Contact us
Questions about this policy, or about the data we hold on you:
Rune Sites · United Kingdom · runewebsites.com