Privacy Policy
What personal data MVP Ninja collects through this website and the project brief, why, who receives it and your rights.
- Draft — pending legal review
This page is a draft and will be reviewed by a lawyer before launch.
This policy explains what personal data MVP Ninja collects through this website and the project brief form, why we collect it, and what you can do about it.
Personal data we handle while delivering a project is covered by the project agreement, not by this policy.
Who we are
This website is run by MVP Ninja Labs (“MVP Ninja”, “we”, “us”), [REGISTERED ADDRESS]. We are the controller of the personal data described in this policy.
For any question about this policy or your data, email [CONTACT EMAIL FOR PRIVACY].
What we collect
When you send a project brief, we receive:
- Your answers: what you want to build, what it should help people do, who will use it, where you are now, your preferred timeline, the tools it should connect to and a budget range.
- The package you picked, if you started the brief from our pricing pages.
- Your name and email address, and your company name and phone number if you add them.
- A reference number and the time the brief was sent.
- How you found us: the first page you opened on our site, the name of the website that linked you (not the full address) and any campaign tags in that link, such as utm_source. Your browser keeps this in memory while you browse and sends it only with a brief or quick note.
To stop spam and abuse of the brief form, we also process:
- Your IP address. Our server turns it into a one-way hash (a scrambled code) and uses that code to count how many briefs come from the same connection. Our application does not store the IP address itself.
- The time you started the brief, to spot submissions made faster than a person could answer.
- A hidden form field that people can't see. If it's filled in, we treat the submission as automated and discard it.
When you visit any page, our hosting provider, Hostinger, processes the technical data needed to deliver it, such as your IP address, browser type, the page requested and the time. This may be kept in server logs.
If you contact us on WhatsApp or LinkedIn, we receive what you send us there and the profile details that service shows us.
Please don't include sensitive personal data, such as health information, or other people's personal details in your brief. We don't need them to reply.
Where it comes from
Almost everything comes from you: what you type into the brief or send us directly. Technical data comes from your browser when it connects to the site.
We don't buy personal data or collect it from data brokers.
How we use it and why we're allowed to
We use personal data for these purposes, each with a lawful basis under UK and EU data protection law:
- To read your brief, reply, ask questions and prepare a scope and price. Lawful basis: taking steps at your request before entering into a contract. If you contact us for a company, our legitimate interest in responding to business enquiries.
- To prevent spam, abuse and automated submissions, using the hashed IP address, the timing check and the hidden field. Lawful basis: our legitimate interest in keeping the site and our inbox secure.
- To recover a brief if email delivery fails. If the email can't be sent, the full brief is written to our server log so it isn't lost, and the form asks you to try again. Lawful basis: our legitimate interest in not losing your enquiry.
- To run and secure the website through server logs. Lawful basis: our legitimate interest in operating a secure, working website.
- To count visits and see which parts of the site and the brief people use, only if we turn on analytics. Lawful basis: our legitimate interest in understanding how the site is used.
- To learn which pages, websites and campaigns bring enquiries, using how you found us. Lawful basis: our legitimate interest in knowing which of our work reaches people.
- To meet legal obligations, for example responding to a lawful request from an authority. Lawful basis: legal obligation.
Where we rely on legitimate interests, we have weighed them against your rights, and you can object at any time.
We only email you about your brief. We don't add you to a mailing list, use your data for advertising, or make decisions about you by purely automated means.
Who receives it
We use a small number of service providers that handle data on our instructions:
- Resend, an email delivery service based in the United States, delivers your brief to our inbox. Your email address is set as the reply-to address so we can answer you directly.
- Microsoft (Outlook), which hosts the inbox where briefs arrive and our replies are sent from.
- Hostinger, which hosts the website, runs the brief form's server code and keeps server logs.
- Upstash, only if we enable it, stores the hashed code of your IP address and a counter for up to 15 minutes so the rate limit works across servers. Without Upstash, that counter exists only in the server's memory.
- Umami (or Plausible), only if we enable it, counts page visits, where visitors came from and a few named actions without cookies. It never receives your brief answers, name, email or phone number. See the Cookie Policy.
We may also disclose data where the law requires it, to protect our legal rights, or to a buyer or successor if the business is sold or restructured.
WhatsApp and LinkedIn are separate companies. Our links to them are ordinary links: we don't embed their content or use their tracking pixels. If you contact us through them, their own privacy policies apply to what you send.
We don't sell personal data.
International transfers
Resend is based in the United States, and our other providers may also process data outside the UK and the European Economic Area. Where that happens, we protect your data with [TRANSFER MECHANISM], for example the European Commission's Standard Contractual Clauses with the UK Addendum, or an adequacy decision where one applies.
You can ask us for details of these safeguards.
How long we keep it
- Briefs and the emails about them: [RETENTION PERIOD] after our last contact, unless you become a client. Then the project agreement applies.
- Rate-limit counters: up to 15 minutes.
- Server logs, including any undelivered brief written to them: [LOG RETENTION PERIOD].
- Answers saved in your browser while you fill in the brief: until you close the tab or your brief is sent. They stay on your device.
You can ask us to delete your brief sooner at any time.
Your rights
If you're in the UK or the European Economic Area, you have the right to:
- Get a copy of the personal data we hold about you.
- Have inaccurate data corrected.
- Have your data deleted.
- Ask us to restrict how we use your data.
- Object to our use of your data where we rely on legitimate interests.
- Receive data you gave us in a portable format, where the law provides for it.
We don't rely on consent for anything described in this policy.
To use any of these rights, email [CONTACT EMAIL FOR PRIVACY]. We'll reply within one month and may ask you to confirm your identity first. It's free unless a request is clearly unfounded or excessive.
If you live elsewhere, including the GCC, local law may give you similar rights. Contact us in the same way.
US residents
Some US states, including California, Colorado, Connecticut and Virginia, give residents rights over their personal information. You can ask us what personal information we hold about you, and ask us to correct or delete it, using the contact details on this page.
The categories we collect are described in “What we collect”: identifiers (such as name, email address, phone number and IP address), professional information (your company) and commercial information (the project and budget you describe). We use them only for the purposes in this policy.
We don't sell personal information or share it for cross-context behavioural advertising. We won't treat you differently for using your rights. You can make a request through an authorised agent; we may need to verify it.
Complaints
If you're unhappy with how we've handled your data, please tell us first so we can try to put it right.
You also have the right to complain to a data protection regulator. In the UK, that's the Information Commissioner's Office (ICO). In the European Economic Area, it's the supervisory authority in the country where you live or work, or where you believe the problem happened.
Children
This website and our services are for businesses and adults. We don't knowingly collect personal data from anyone under 18. If you believe a child has sent us a brief, contact us and we'll delete it.
Security
The site is served over HTTPS, and browsers are told to always use a secure connection. The brief form checks where each request comes from, limits its size and how often it can be sent, and validates every answer on the server. Briefs are sent only to MVP Ninja's own inbox.
No way of sending or storing data online is completely secure, but we take reasonable steps to protect what you share with us.
Changes to this policy
We'll update this page when what we do with personal data changes, for example if we add a service provider. The date at the top shows when it last changed.
Contact
- MVP Ninja Labs
- Email: [CONTACT EMAIL FOR PRIVACY]
- Post: [REGISTERED ADDRESS]