Privacy policy
Last updated: 6 October 2026
This policy explains what information Webbricks handles, why, and the choices you have. Webbricks is in early access, so this policy will be updated as the service grows.
1. Who is responsible for the service?
Webbricks is operated by Matthew Short, 8 Chevin Avenue, Menston, West Yorkshire, LS29 6PR.
You can contact us about privacy at hello@webbricks.co.uk.
In this policy, “Webbricks”, “we”, “us” and “our” mean the operator of the Webbricks mobile app, the service behind it and the websites it hosts.
2. What this policy covers
This policy covers the Webbricks mobile app, the Webbricks service, the public business websites hosted at addresses ending webbricks.co.uk (or on a business's own domain name), contact forms on those sites, and push notifications generated by the service.
It covers both:
- people who create or manage a Webbricks account; and
- people who visit a Webbricks-hosted business site or submit its contact form.
If a business uses Webbricks to collect enquiries, that business may also have its own responsibilities to provide a privacy notice to its customers. That is for the business to provide.
3. Information we handle
Account and sign-in information
When you create or use an account, we handle:
- email address;
- a password hash and salt, rather than the password itself;
- hashed bearer-session tokens and session timestamps;
- hashed single-use password reset tokens, kept until they expire or are used and then removed by a daily cleanup; and
- account and session expiry information.
The app stores the active bearer session token in local device storage so the user does not need to sign in on every launch. The raw password is not returned to the app, and raw session tokens are not stored in our database.
Business website information
The app can send and the service can store:
- business name, service area, headline and about text;
- phone number and email address intended for public display;
- service descriptions, colour choice, website slug and publication status;
- customer reviews (a name and quote the business enters), frequently asked questions, opening hours, a closure notice and a Google Business Profile link;
- trust badges the business selects, with any registration or membership number it enters;
- photos the business uploads for its gallery and photo albums, with their titles and album descriptions;
- creation, update and publication timestamps; and
- the resulting published pages on the business's Webbricks address.
Photos are resized on the phone before upload, which also removes embedded metadata such as the location a photo was taken. Uploaded photos are stored in Cloudflare R2 in the EU jurisdiction. Only photos the business saves into a published gallery or album are public.
The customer chooses what to put on a public site and should not add sensitive or confidential information to site content.
Contact enquiries and quote requests
A visitor can submit a name, optional phone number, optional email address and message through a published site's contact form. The service stores the enquiry, timestamp and read status in our database and displays it to the business in the app's enquiry inbox. The business, rather than Webbricks, normally decides how to respond to and otherwise use that enquiry.
If the business has switched on its quote request form, the visitor can also say what they need, give a postcode and how soon they need it, and attach up to three photos. The visitor's browser resizes photos before sending them. These photos are stored privately in Cloudflare R2 (EU jurisdiction) and can only be viewed by the business in the app; they are never published on the website.
Replies to enquiries
A business can reply to an enquiry that included an email address from inside the app. The reply is sent as an email to the visitor from replies@mail.webbricks.co.uk through our email provider, Resend, with the business's email address set as the reply-to address, so the visitor's answer goes directly to the business rather than to Webbricks. We store the reply text, the address it was sent to and when it was sent with the enquiry so the business can see the conversation. The email includes the visitor's original message for context.
The service does not store the visitor's IP address in the application database. Cloudflare may process request metadata, including IP information, for delivery, security, abuse prevention and rate limiting.
Usage and device information
Each website records one aggregate view count per site and calendar day. It also keeps anonymous daily counts for each site broken down by:
- the page viewed (the home page or a photo album page);
- a broad traffic source worked out from the referring website, such as "Google", "Facebook", "Direct" or "Other websites"; and
- a broad device class ("Mobile", "Tablet" or "Desktop") worked out from the browser's user-agent string.
We do not store visitors' IP addresses, user-agent strings, full referring URLs or search terms for these statistics, and requests that identify themselves as search engines or bots are not counted. The counts are shown to the business in the app. The service does not build an advertising profile or cross-site analytics profile.
For notifications, the app can request permission and register an Expo push token. The service stores the token, associated account and last-seen time so that it can send a new-enquiry notification to the user's device.
The new-enquiry notification includes a short title, the sender's name (limited in length), and internal site/lead identifiers. A weekly summary notification includes the account's total visits and enquiries for the past week and is only sent when there was activity. Push delivery is handled by Expo's push service and the device's notification infrastructure.
If the app crashes or hits an error, it sends a crash report to our error monitoring provider, Sentry, so that we can find and fix the problem. A report contains the error and where in the app it happened, the app version, whether it is the test or live app, and device details such as the model and operating system version. We do not attach the account's email address, website content or customer enquiries to crash reports. Sentry may process the device's IP address in order to receive the report. Crash reports are stored in the EU and are deleted automatically after a limited period set by our Sentry plan.
4. Why we use the information
We use information to:
- create accounts and authenticate users;
- create, update, publish and route business websites;
- display customer enquiries, quote details and attached photos in the correct business account;
- send a business's replies to the visitors who contacted it;
- show aggregate and anonymous visitor statistics and enquiry counts;
- register devices and send new-enquiry notifications;
- protect public forms from spam and excessive submissions;
- operate, fix, secure and improve the service; and
- comply with applicable legal obligations where required.
Our legal bases for this under UK data protection law are:
- contract: to provide the account, websites and features you ask for;
- legitimate interests: to keep the service secure, prevent abuse, fix problems and understand in aggregate how sites are used; and
- legal obligation: where the law requires us to keep or disclose information.
Notifications are only sent if you allow them on your device, and you can turn them off in your device settings at any time.
5. Public websites and visitor choices
When a business publishes a site, the business information it entered may be publicly visible at that site's Webbricks address. A visitor can choose whether to submit the optional phone number or email address on the contact form.
The website does not intentionally set an application cookie or use an advertising cookie. The public site uses ordinary HTTPS requests and a contact form. Cloudflare may still process technical request data as part of its hosting, network, security and abuse-prevention services.
If Turnstile is enabled for a site, Cloudflare processes the challenge and verification data under its own terms and privacy information. Turnstile is optional and may be switched on for spam prevention.
6. Who receives information
We do not currently sell personal information or use it for targeted advertising. Information may be processed by:
- Cloudflare, which provides Workers, our database database hosting, R2 photo storage (EU jurisdiction), DNS, TLS, caching/network delivery, rate limiting and optional Turnstile protection;
- Expo, which receives push notification requests and tokens when Android notifications are configured;
- Resend, which delivers enquiry replies by email and therefore processes the visitor's email address, the reply text, the visitor's original message and the business's name and reply-to address;
- Sentry, which receives crash and error reports from the mobile app (stored in the EU); and
- service providers or professional advisers where reasonably necessary to operate the service, investigate abuse or comply with law.
Cloudflare, Expo, Resend and Sentry may process information outside the UK. Where they do, the transfer is covered by the safeguards those providers put in place, such as UK adequacy regulations or the UK International Data Transfer Addendum. Contact us if you would like more detail.
7. How long information is kept
We keep information as follows:
- account data, site content, photos, enquiries, quote photos and replies are kept while the account is in use, then deleted when the account owner uses the in-app Delete account control or asks us to delete it;
- when an owner deletes a single website, it is hidden immediately and held for 7 days so it can be recovered; after that the site, its photos, enquiries, quote photos, replies and statistics are permanently deleted;
- photos uploaded to the gallery but never saved, or later removed from it, are deleted after 24 hours;
- registered Expo device tokens are deleted with the account and are not kept for a former account;
- bearer sessions expire after 30 days, and expired sessions are removed after a further 30-day cleanup grace period; and
- visitor statistics contain only aggregate per-site/per-day counts (the daily total and the anonymous page, source and device breakdown). A daily scheduled job removes statistics older than 395 days (approximately 13 months).
Account deletion removes the account, all its sites, published content, photos, enquiries, quote photos, replies, device registrations, sessions, password reset tokens and visitor statistics. This is permanent and there is no self-service export or recovery promise. Cloudflare, Expo, Resend and Sentry may retain technical or delivery records under their own terms and retention controls; Webbricks does not claim to delete those provider-side records through the app.
8. Security
The service uses HTTPS, access controls around account-owned resources, hashed passwords, hashed session tokens, database constraints and basic public-form abuse controls. No online service can guarantee absolute security. Users must keep their account credentials and devices secure and should report suspected unauthorised access to the contact address at the end of this policy.
9. Your rights and choices
Depending on the applicable law and our role for the particular information, an individual may have rights to request access, correction, deletion, restriction, objection or portability, and to withdraw consent where consent is the basis. A person may also complain to the relevant data-protection supervisory authority.
The account owner can exercise deletion for their Webbricks account directly in the app by opening Account, entering the account email exactly, and confirming Delete account permanently. This requires a valid authenticated session and deletes all account-owned data described above. If the app cannot be used, email us from the address on the account and we will delete it for you.
For an enquiry submitted to a business site, the business may be the relevant controller and should be contacted through that business where appropriate. If you sent an enquiry through a Webbricks site and want it deleted, you can also contact us; we will check which site and enquiry it relates to before acting.
In the UK, the supervisory authority is the Information Commissioner's Office (ICO), at ico.org.uk.
10. Children
Webbricks is designed for business owners and is not directed at children. Do not knowingly create an account for a child or ask children to submit personal information through a business contact form.
11. Changes to this policy
We may update this policy when the service or its use of information changes. The date at the top shows when it was last updated, and we will tell account holders about significant changes.
12. Contact
Email hello@webbricks.co.uk, or write to Matthew Short, 8 Chevin Avenue, Menston, West Yorkshire, LS29 6PR.