Last updated: October 8, 2026
Singlehand is a one-person studio. This page explains what personal data I collect through singlehand.studio and through my services, why I collect it, how long I keep it, and what you can ask me to do with it.
The short version: I collect as little as I can, I don’t sell it, and this site has no analytics or advertising trackers.
Who is responsible for your data
Singlehand is run by one person, a sole trader. I decide how your data is used, which makes me the “controller” under data protection laws such as the GDPR. My legal name appears on every invoice, and I’ll tell you on request.
Email: [email protected]
What I collect, and why
You don’t have to give me any personal data. But I can’t reply, send the newsletter or do an audit without your email address and, for an audit, your store’s web address.
When you request an audit
The form asks for your store’s web address, your email and, if you like, a note about what worries you. It also records the page you sent it from. I use this to reply, to check whether your store is a fit, and to do the audit if you go ahead.
Legal basis: steps you ask me to take before we have a contract, and then the contract itself.
When you subscribe to the newsletter
I collect your email address and send you one email asking you to confirm. Nothing else arrives until you click the link in it. When you confirm, the newsletter tool records the time and your IP address as proof that you agreed.
My newsletter emails contain a small tracking image, and their links pass through my site first, so I can see whether an email was opened and which links were clicked. Each open or click is stored with the time and the IP address it came from. This tells me which topics are useful. Blocking images in your email app stops open tracking; unsubscribing stops both.
Legal basis: your consent. You can withdraw it at any time with the unsubscribe link at the bottom of every newsletter email.
When you become a client
To deliver an audit or a Fix project, I keep:
- your name, your business name and your email;
- billing details for the invoice, such as your business address;
- payment records. Payments go through Payoneer, so I never see your full card or bank details;
- our emails;
- what I see through the access you give me to your store and Search Console, and the report I write.
I ask for the narrowest access the work needs. I don’t ask for access to your customer or order records, and I don’t copy your customers’ personal data into reports or notes.
Legal basis: our contract and, for invoices and payment records, my legal obligations.
When you email me
I keep your message and my reply so I can help you and keep track of our conversation. Legal basis: my legitimate interest in answering you.
To keep this site safe
To stop spam, the forms count how many times one connection sends them. For this check your IP address is turned into a scrambled code (a hash), and the code expires after 10 minutes. Cloudflare, which protects the site, sees each visitor’s IP address so it can block attacks and bots. My hosting provider also keeps standard server logs, such as IP address, browser type, the page requested and the time, for security and troubleshooting.
Legal basis: my legitimate interest in keeping the site secure.
What I don’t do
- I don’t sell or rent your personal data, and I don’t share it for advertising. In California’s terms, I don’t “sell” or “share” personal information.
- I don’t use analytics or advertising trackers on this site.
- Fonts are hosted on this site. Nothing is loaded from Google Fonts or similar services.
- I don’t make decisions about you by automated means.
Cookies
Reading this site doesn’t set any cookies from me. A few can appear in specific situations:
- fc_hash_secure (90 days): set by the newsletter tool when you confirm your subscription, open the unsubscribe page or click a link in one of my emails. It lets the tool recognize you as a subscriber.
- fc_cid (28 days): set by the newsletter tool when you click a link in one of my emails, to record which email the click came from.
- Cloudflare security cookies, such as __cf_bm: Cloudflare, which protects this site, may set one to filter out bots. It doesn’t track you across websites.
- WordPress login cookies: set only when I log in to manage the site.
None of these cookies is used for advertising. Because I don’t track you across other websites, there’s nothing for Do Not Track or Global Privacy Control signals to switch off.
Who helps me run this
These providers process data only to provide their service to me:
- Spaceship: web hosting, and the mailbox and mail server for [email protected].
- Cloudflare: domain name system (DNS) and site security.
Payoneer handles payment requests and payments, and processes your payment details under its own privacy policy.
The newsletter tool (FluentCRM) and the email plugin (GoSMTP) run on my site’s hosting, not on their makers’ servers. Emails from the site are sent through my mailbox at Spaceship.
I also use a few everyday tools to do the work, such as a note-taking app, document tools and AI writing assistants. I use them only for the work you asked for, and I don’t put your customers’ personal data into them.
When you give me access to your Shopify store or Google Search Console, the data stays in your accounts, under your control. I copy into the report only what it needs as evidence, such as URLs, screenshots and Search Console figures. You can remove my access at any time.
Where your data is processed
I’m based in Vietnam, and my providers run servers in several countries, including the United States. Vietnam has no EU or UK adequacy decision, so if you’re in the EU or the UK, your data leaves the area those laws cover. I process it there because I need it to answer you, send the newsletter you asked for and do the work you hire me for. My providers protect it under their own data protection terms.
How long I keep it
- Audit requests, and emails with people who don’t become clients: 24 months after our last email, then deleted.
- The site’s log of form submissions: 24 months. Entries that look like spam are deleted every month.
- Newsletter sign-ups that are never confirmed: deleted within 60 days.
- Newsletter: until you unsubscribe. After that, I keep your contact record marked as unsubscribed, so I never email you again by mistake. Ask me and I’ll delete it completely.
- Client work (reports, notes and emails): 24 months after the last delivery, so I can answer follow-up questions. Then it’s deleted, or sooner if you ask.
- Invoices and payment records: as long as tax and accounting law requires.
- Spam-check codes: 10 minutes.
- Copies of emails the site sends, kept for troubleshooting: cleared at least every 30 days.
- Server logs: kept by my hosting provider under its own retention settings.
Your rights
Depending on where you live, you can ask me to:
- give you a copy of your personal data;
- correct it;
- delete it;
- limit how I use it, or object to how I use it;
- send it to you or to someone else in a common format;
- withdraw your consent, for example by unsubscribing.
Email [email protected]. It’s free, and I’ll reply within 30 days. If you’re in the EU or the UK and you’re not happy with my answer, you can complain to your local data protection authority.
Children
My services are for businesses. This site isn’t meant for anyone under 16, and I don’t knowingly collect their data.
Security
The site uses HTTPS. I protect my accounts with strong, unique passwords and turn on two-factor authentication wherever it’s available. Apart from the providers and tools listed above, only I have access to your data, unless the law requires otherwise. No system is perfectly secure; if a breach puts your data at risk, I’ll tell you without undue delay.
Changes to this policy
When I change this policy, I’ll update the date at the top. If a change affects how I use your data, I’ll tell newsletter subscribers and clients by email.