Privacy Policy
Mateusz Podeszwa, sole trader operating as podeszwa.dev (the “Studio”, “we”, or “us”), is committed to protecting your personal data. This Privacy Policy explains what information we collect, why we collect it, and your rights under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
Who we are. Mateusz Podeszwa, a sole trader trading as podeszwa.dev, established in England and Wales, is the data controller for the personal data described below. Our full contact details, trading address, telephone number and registration details are in the “Who you are contracting with” panel at the foot of this page.
There is no requirement for us to appoint a Data Protection Officer, and we have not appointed one. Questions about this policy go to the email address in that panel.
1. Data we collect
We collect and process the following categories of personal data:
- Account data — your name, email address, company name (optional), and a hashed password, provided when you create an account via the /hire form or by invitation.
- Gig data — project briefs, messages exchanged through the client portal, milestone notes, and invoice records relating to your engagement with the Studio.
- Payment data — billing references (Stripe Customer ID, Payment Intent identifiers) sufficient to process invoices and refunds. We do not store card numbers or full payment credentials; those remain solely with our payment processor.
- Patreon membership data — only if you choose to link your Patreon account to claim a member discount: your Patreon user identifier and an encrypted authorisation token (held so we can re-check your membership), together with your membership tier and status for our campaign. We never receive your Patreon password or payment details. You can disconnect at any time from your account settings, which deletes these tokens immediately.
- Newsletter data — your email address and subscription status, collected only if you opt in to the Studio’s newsletter.
- File uploads — files you attach to a hire request or that the Studio uploads as project deliverables. These are stored in an encrypted object-storage bucket and are subject to automatic deletion after the retention periods set out in clause 3 below.
- Security and sign-in data — a record of each successful sign-in to your account (time, approximate IP address, and browser/device string), kept so that you can spot a sign-in you don’t recognise, and so we can alert you when your account is used from a device it hasn’t used recently. If you enable two-factor authentication we also store the settings needed to operate it. We do not record failed sign-in attempts.
- Signature data — only if we send you an agreement to sign: your name, email address, signature, IP address, and the signing audit trail, held as evidence that the document was executed.
- Usage data — page views, referrer, and coarse device and country signals, collected by our self-hosted Umami analytics instance. Umami sets no advertising or cross-site tracking cookies, does not build a profile of you, and the data is not linked to your account.
2. Legal bases for processing
| Data category | Legal basis |
|---|---|
| Account & gig data | Contract — Art. 6(1)(b) UK GDPR. Necessary to deliver the services you requested. |
| Financial & tax records | Legal obligation — Art. 6(1)(c). UK tax law requires retention of financial records for six years. |
| Newsletter | Consent — Art. 6(1)(a). You may withdraw at any time via the unsubscribe link in any newsletter email. |
| Patreon membership | Consent — Art. 6(1)(a). Processed only if you link Patreon to obtain a member discount; withdraw at any time by disconnecting. |
| File uploads | Contract — Art. 6(1)(b). Necessary to review your brief and deliver project files. Files are automatically purged after the applicable retention period. Uploads are scanned for malware before they are stored, which we do under legitimate interest — Art. 6(1)(f), in keeping the platform and its other users safe. |
| Payment and billing references | Contract — Art. 6(1)(b) to take payment for what you ordered, and legal obligation — Art. 6(1)(c) for the tax and accounting record of it. |
| Security and sign-in data | Legitimate interest — Art. 6(1)(f), in keeping your account secure and letting you spot a sign-in you do not recognise. We have weighed this against your interests and consider it something you would reasonably expect of any account you hold; you may object at any time under clause 5. |
| Signature and signing audit trail | Contract — Art. 6(1)(b) to execute the agreement, and legitimate interest — Art. 6(1)(f), in being able to prove afterwards that it was signed, by whom, and when. This is evidence of a contract, so it is not deleted on an erasure request while the agreement or the period for a claim under it is still running (see clause 3). |
| Usage analytics | Legitimate interest — Art. 6(1)(f), in understanding which pages are read. Counts are coarse and are not linked to your account or used to profile you. No cookie is set, and we rely on the statistical purposes exception described at clause 6, which you can switch off at any time using the button at the foot of this page. |
3. Retention periods
- Account data — retained for the duration of the account and deleted within 30 days of a written deletion request (see clause 5), unless a legal obligation requires longer retention.
- Financial records — retained for six years from the end of the relevant tax year, as required by HMRC.
- Newsletter subscriptions — retained until you unsubscribe. Removed from our systems within 90 days of unsubscription.
- Patreon authorisation — the encrypted Patreon token and identifier are kept only while your account is linked, and are deleted the moment you disconnect Patreon or delete your account.
- Security and sign-in records — retained for 12 months from the sign-in, then deleted. They exist so that you (and we) can spot account misuse; older entries stop being useful for that.
- Signature and signing audit trail — retained for six years from the end of the agreement it evidences, which is the period during which a claim can be brought on a contract under the Limitation Act 1980. Because it is the evidence that the contract exists, it is one of the few things we will decline to erase on request while that period is running; the rest of your account can still be deleted around it.
- Contact and enquiry messages — retained for 24 months from the last message in the thread, then deleted, unless the enquiry became an engagement (in which case it is kept with the engagement record).
- Usage analytics — coarse page-view records are retained for up to 24 months and then deleted.
- Hire-request file attachments — files uploaded during a hire request are retained for 30 days from upload. If the inquiry moves to Reviewing the window shortens to 3 days from that transition; files uploaded for a request that is cancelled or declined are deleted within 15 minutes.
- Milestone deliverables — files attached to project milestones are retained while the engagement is active. Once the engagement is marked Completed, deliverable files are automatically deleted 14 days after completion. Files attached to archived engagements are deleted within 1 hour of archiving.
- Final delivery files — the retention window is set by the Studio on a per-engagement basis (per-download expiry, a fixed number of days, or no expiry). Cancelled or declined engagements result in automatic deletion within 15 minutes.
All file deletions described above are permanent and irreversible. You may request early deletion of your uploaded files at any time by contacting us (see clause 11). Requests will be acted on within 72 hours under Article 17 of the UK GDPR.
4. Who else is involved, and in what role
Two different relationships sit behind this site, and the difference decides who you go to about what.
4.1 Companies that decide for themselves (independent controllers)
These are not our processors and do not act on our instructions. They have their own legal duties, their own privacy notice, and their own reasons for holding your data. We disclose data to them; what they then do with it is governed by their notice, not ours.
- Stripe, Inc. (payments) — Stripe is an independent controller for the payment itself, because it is a regulated payment institution with its own obligations for fraud prevention, anti-money-laundering and licensing. Card details go straight to Stripe and never reach this site; we hold only billing references. Stripe is certified to PCI-DSS Level 1. See stripe.com/gb/privacy.
- Patreon, Inc. (membership verification) — only if you choose to link your account. This is a disclosure between two independent controllers, not us instructing Patreon: we exchange an OAuth authorisation to read your membership tier for our campaign, solely to apply a member discount. We never receive your Patreon password or payment details. Data is processed in the USA. See privacy.patreon.com.
4.2 Companies that act only on our instructions (processors)
Each of these is bound by a written data-processing agreement meeting Article 28 of the UK GDPR, may not use your data for its own purposes, and may not engage anyone else without telling us:
- Resend, Inc. (transactional email and newsletter) — delivers account-critical and notification emails on our behalf, and stores newsletter subscriber email addresses and subscription status. Data processed in the USA under Standard Contractual Clauses. See resend.com/legal/privacy-policy.
- Cloudflare, Inc. (bot check and script delivery) — the Turnstile bot check on our public forms sends your IP address and browser signals to Cloudflare so it can tell a person from a script. Separately, some of the code this site runs in your browser is served from Cloudflare’s public cdnjs network, which means your IP address reaches Cloudflare when a page loads. Data is processed in the USA under the UK Addendum to the EU Standard Contractual Clauses. See cloudflare.com/privacypolicy.
- jsDelivr (script delivery) — a public code-delivery network used for a small number of browser libraries. As with any such network, your IP address and browser string reach it when a page that uses one of those libraries loads. No account data is sent. See jsdelivr.com/terms/privacy-policy.
- Railway Corporation (hosting and database) — all application data, including account and gig data, is stored on Railway’s infrastructure in the United States. Transfers are covered by Standard Contractual Clauses. See railway.com/legal/privacy.
- Self-hosted components running on Railway — three parts of this platform are open-source software we run ourselves on the Railway infrastructure named above, rather than services operated by anyone else. No separate company receives your data through them, and they are covered by the Railway entry rather than being sub-processors in their own right:
- MinIO — the object store holding uploaded files and project deliverables, encrypted at rest with AES-256.
- Umami — the analytics instance recording page views, referrer, and coarse device and country signals. It sets no cookies, builds no visitor profile, and is not linked to your account.
- ClamAV — the malware scanner every uploaded file passes through before it is stored.
- Calendly LLC (call scheduling) — only if you book a call: your name, email address, chosen time, and any answers you give on the booking form are processed by Calendly to create and manage the appointment. Data is processed in the USA. See calendly.com/legal/privacy-notice.
- eSignatures.com (electronic signature) — only if we send you a contract to sign: your name, email address, signature, IP address, and the signing audit trail are processed to execute and evidence the document.
We keep this list current. Where a transfer outside the UK is involved, it is made under one of: a UK adequacy determination; the UK Extension to the EU-US Data Privacy Framework, where the recipient is certified to that Extension specifically and its certification is live and covers the data in question; the ICO’s International Data Transfer Agreement; or the UK Addendum to the EU Standard Contractual Clauses. In each case we first carry out a transfer risk assessment against the data protection test introduced by the Data (Use and Access) Act 2025, which asks whether protection in the destination is not materially lower than under UK law. You can ask us which mechanism covers a particular recipient and we will tell you.
We do not sell, rent, or share your personal data with any third party for their own marketing or commercial purposes.
4a. When we handle data on a client’s behalf
This policy describes data for which the Studio is the controller — that is, data about you as a visitor, enquirer, or account holder.
Separately, where the Studio hosts, maintains, or supports a system belonging to a business client, it processes that client’s own customer data as a processor acting on that client’s instructions. That relationship is governed by a Data Processing Agreement between the Studio and the client, not by this policy, and the client — not the Studio — is the controller of that data. If you have been in contact with a business whose website the Studio hosts, that business is the right party to contact about your data.
5. Your rights under UK GDPR
You have the following rights in relation to your personal data. Requests should be submitted via the contact form or email to hello@podeszwa.dev. We will respond within one calendar month.
- Right of access — obtain a copy of the personal data we hold about you.
- Right to rectification — correct inaccurate or incomplete data.
- Right to erasure — request deletion of your data where there is no overriding legal obligation to retain it.
- Right to restrict processing — pause processing while a dispute is resolved.
- Right to data portability — receive your account data in a structured, machine-readable format.
- Right to object — object to processing carried out on the basis of legitimate interest.
- Right to withdraw consent — for any processing based on consent (newsletter, Patreon linking), exercisable at any time without affecting the lawfulness of prior processing.
- Right to complain — to us, or directly to the Information Commissioner’s Office, as set out in clause 9.
Do you have to give us this data? Only the parts marked as required on each form. Your name and email address are needed to create an account and to run an engagement, and without them we cannot enter into or perform the contract. Everything else is optional, and leaving it out costs you nothing beyond the feature it powers.
Two limits worth stating plainly. Erasure is not absolute: where the law requires us to keep something (tax records) or where the data is the evidence that a contract exists (the signing audit trail), we will keep that specific item for the period given in clause 3 and delete the rest. We will always tell you which parts we are keeping and why.
6. Cookies
No advertising or cross-site tracking cookies are set on this site, and none of the cookies below are used to profile you. Every one of them is strictly necessary for a feature you asked for, which is why you are not asked to consent to them:
- Sign-in — keeps you logged in, and remembers a device you have chosen to trust for two-factor authentication.
- Anti-CSRF token — protects every form on the site from being submitted by another website on your behalf.
- Language — remembers the language you picked, if you changed it.
- Shop basket and wishlist — remembers what you put in your basket and saved for later, so it survives a refresh.
- Discount code — remembers a promotional code you entered so the price you were shown is the price you are charged.
- Patreon linking — a short-lived security value used only while you are connecting your Patreon account, to protect that connection from being hijacked.
- Cloudflare Turnstile — the bot check on the contact form may set a short-lived cookie; it is cleared when your browser session ends.
Analytics, and how to switch it off
Our analytics (Umami, clause 4) sets no cookies at all. It does read a little about your browser, such as the size of your screen, which is enough to bring it within the rules on storage and access technologies even without a cookie. We are not going to pretend otherwise.
We rely on the statistical purposes exception in Schedule A1 of the Privacy and Electronic Communications Regulations 2003. That exception is available to us because all four of its conditions hold, and we will keep them holding:
- the only purpose is counting how the site is used so we can improve it. It is never used for advertising, for retargeting, for tracking you across other sites, or for building a profile of you;
- the data is not shared with anyone. Umami is open-source software we run on our own infrastructure, so no analytics company receives it;
- this clause is the clear and comprehensive information the exception requires; and
- you have a simple, free way to object, and if you do, we stop.
To switch analytics off, use the button at the bottom of this page. It takes effect immediately, costs nothing, and is remembered in your browser. Because that exception works on objection rather than permission, counting starts unless and until you say no, which is why there is no consent banner to click through on arrival.
If we ever add a cookie or a tracking technology that is not strictly necessary and not covered by that exception, we will ask for your consent first, and it will be a real question with a real "no".
7. Security
We implement appropriate technical and organisational measures to protect your personal data, including HTTPS-only transport, encrypted database storage, hashed password storage (never readable in plain text), and access controls restricting data to authorised systems and personnel.
8. Automated decision-making
We do not make decisions about you using solely automated means that produce legal or similarly significant effects.
9. Complaints
If you are unhappy with how we have handled your personal data, please tell us first — email hello@podeszwa.dev with “Data complaint” in the subject line, or use the contact form. You do not need to use any particular wording.
We operate the complaints procedure required by section 164A of the Data Protection Act 2018:
- we will acknowledge your complaint within 30 days of receiving it;
- we will take appropriate steps to investigate it, which may include asking you for more detail; and
- we will tell you the outcome without undue delay.
You can complain to the Information Commissioner’s Office at any time, whether or not you have raised it with us first — at ico.org.uk or by telephone on 0303 123 1113. The ICO may ask whether you have contacted us, so raising it with us first is usually the quicker route.
10. Changes to this policy
We may update this Privacy Policy from time to time. When we publish a change, every registered account is emailed a notice saying what changed and when it takes effect — you do not have to watch this page. The date at the top of the page is only ever moved by a published change. Continued use of the service after the effective date constitutes acceptance of the revised policy.
11. Contact
Mateusz Podeszwa (data controller), sole trader trading as podeszwa.dev. Trading address, email and telephone number are in the “Who you are contracting with” panel at the foot of this page. You can also use the contact form.
Who you are contracting with
- Legal status
- Mateusz Podeszwa, an individual trading as podeszwa.dev, established in England and Wales
- hello@podeszwa.dev
Turn off usage analytics
This site counts page views so I can see which work is worth writing more of. It sets no cookies, builds no profile of you, and the data never leaves my own server. If you would still rather not be counted, switch it off here. The choice is stored in this browser only, it is free, and it takes effect immediately.