Skip to content
Legal · UK GDPR & DPA 2018

Privacy Policy

This Privacy Policy explains what personal data Quinnsite collects when you use quinnsite.co.uk and the calculator suite, why we collect it, how long we keep it, who we share it with, and your rights under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

Effective date: 28 June 2026 Version: 1.1 Last reviewed: 2026-07-07

1. Data controller

The data controller for the personal data described in this policy is Quinnsite Ltd (trading as Quinnsite), a company registered in England and Wales under company number 17325930, with its registered office at 27 Old Gloucester Street, London WC1N 3AX, United Kingdom. Our entry on the public register can be verified at Companies House.

As an organisation that processes personal data, we are registered with the UK Information Commissioner's Office (ICO). Our registration can be verified on the ICO's public register at ico.org.uk, and our registration reference is available on request.

The Service is operated by Quinnsite Ltd and hosted on Netlify (Netlify, Inc., 44 Montgomery Street, Suite 300, San Francisco, CA 94104, United States; see Section 7).

2. Scope

This policy covers all personal data we collect when you:

  • Visit any page on quinnsite.co.uk;
  • Use any of the Quinnsite calculators or knowledge-base pages;
  • Generate, export, download or share a PDF report using our tools;
  • Interact with the click-through disclaimer modal or any acknowledgement we record;
  • Contact us by email or any future contact form.

It does not cover websites we link to. Once you click through to a third-party site, that site's privacy policy applies.

3. What we collect

Quinnsite is designed to collect as little personal data as possible. You can use the calculators and knowledge base without an account: the tools are calculation engines and your SuDS designs stay on your device. If you choose to create an account (needed only to hold a subscription and to upload a company logo for report branding), we process the limited account and billing data described in Section 3.4. We never store your drainage designs on our servers: only your account, subscription and (for Pro) your company logo.

3.1 Data stored on your device

WhatStorageWhyPersonal?
Disclaimer acknowledgement (catchment_ack_v1)localStorageRecords that you have read and accepted the Terms and the professional-use disclaimer, so we do not re-prompt you on every page.No. Contains only a timestamp, a Terms version string and your browser's user-agent string.
Session identifier (suds_session_id_v1)sessionStorageA randomly-generated UUID v4 that ties together calculation events within a single browser session, so the audit trail of a PDF report is coherent.No. Randomly generated; not linked to you outside the session.
Calculation IO-log (suds_iolog_v1)localStorage (rolling buffer of last 50 events)Allows you to export the inputs/outputs/methodology version applied for evidential and quality-assurance purposes. See Section 4 on lawful basis.Potentially, if you choose to enter your name, project reference or any identifying string into a calculator input field, that string is stored locally. We do not require you to enter such information.

This data lives in your browser. It does not leave your device unless you actively choose to export, share or transmit a PDF report.

3.2 Data we receive at the server

The Service is hosted on Netlify. When your browser fetches a page, Netlify automatically receives standard server-log information:

  • Your IP address;
  • The page you requested and the timestamp;
  • Your browser's user-agent string;
  • The referring page (if any).

This is standard web-server behaviour. We use Netlify's default log retention. For aggregate usage analytics we use Netlify Web Analytics, which is measured server-side from these logs: it sets no cookies, records no personal identifiers, and performs no cross-site tracking or advertising profiling. We do not use Google Analytics or any tracking pixel.

Our hosting provider, Netlify, acts as a data processor on our behalf and processes hosting, request and aggregate-analytics data under its Data Processing Addendum, which is aligned with the UK GDPR and incorporates the UK International Data Transfer Addendum for any transfer of data outside the UK.

3.3 Phase 2 server-side endpoints (planned)

We are preparing two Netlify Functions endpoints (/api/ack-log and /api/iolog) that will, when enabled, record:

  • The fact that an acknowledgement was made (Terms version + disclaimer version + acknowledgement timestamp + session UUID + server-derived IP);
  • The methodology version applied to each calculation event.

These endpoints are not yet live. When they go live we will update this policy and the disclaimer modal accordingly, and re-prompt for acknowledgement.

3.4 Accounts & billing (when you create an account)

When you sign up we collect your email address and, unless you sign in with Google or Microsoft, a password which is stored only in hashed form (we never see it). You may optionally provide your name, company, job role and sector. If you subscribe, we hold your subscription status (plan, status and renewal date) and a payment-processor customer reference. If you are a Pro subscriber and upload a company logo for report branding, that image is stored in our private cloud storage so it is available across your devices.

We never upload your SuDS projects, calculations or designs; those remain on your device (Section 3.1). Card and payment details are handled entirely by our payment processor, Stripe, and are never seen or stored by us. The processors involved in accounts and billing are listed in Section 6, and the lawful bases in Section 4.

4. Lawful basis

Our lawful bases under Article 6 UK GDPR are:

  • Legitimate interests (Article 6(1)(f)): for storing the disclaimer acknowledgement and the calculation IO-log. The legitimate interests are: (a) operating an evidentially-defensible engineering tool whose outputs can be traced to a methodology version; (b) demonstrating that users have read and accepted the professional-use disclaimer before relying on outputs. We have balanced this against your rights and consider the impact minimal because the data is stored locally on your device and is not used for advertising or profiling.
  • Legal obligation (Article 6(1)(c)): where retention is necessary to demonstrate compliance with our duty of care or in response to a regulatory enquiry.
  • Consent (Article 6(1)(a)): where you actively click through the disclaimer modal. You can withdraw consent at any time by clearing your browser storage (see Section 10).
  • Contract (Article 6(1)(b)): for creating and operating your account, authenticating you, and managing any subscription you take out. This processing is necessary to provide the service you have asked for.
  • Consent (Article 6(1)(a)): for sending you marketing or product-update emails, only where you have ticked the separate, unticked-by-default marketing box at sign-up. This is distinct from accepting our Terms. You can withdraw it at any time via the unsubscribe link in any such email or in your account settings.

5. Retention

On-device data: until you clear your browser storage, or until the underlying schema version is bumped, whichever is sooner. The IO-log is a rolling buffer of the last 50 events; older events are evicted automatically.

Netlify server logs: per Netlify's standard retention policy (currently approximately 30 days for access logs; see Netlify's privacy policy for the current period).

Phase 2 server-side logs (once live): retained for 7 years, aligning with the expected limitation period for engineering professional-indemnity claims in England and Wales.

Account data: retained for as long as your account is active. If you delete your account (see Section 9) we delete your profile, login and stored company logo.

Billing & invoice records: we and our payment processor, Stripe, are required by UK tax and accounting law to retain invoice and payment records for approximately six years. Deleting your account therefore does not erase those financial records, which are held for the duration of that legal obligation.

6. Sharing & processors

We do not sell your personal data. We do not share it with third parties for advertising or marketing purposes. We use the following processors:

  • Netlify, Inc.: hosting and CDN. Netlify processes server-log data on our behalf under a Data Processing Addendum.
  • Google Fonts: the site's web fonts are loaded from fonts.googleapis.com. When you load a page, your browser makes a request to Google's servers. We are migrating to self-hosted fonts to remove this dependency.
  • Cloudflare cdnjs: JavaScript libraries (jsPDF, jspdf-autotable, html2pdf, Chart.js, axios where used) are loaded from cdnjs.cloudflare.com. Same caveat as above.

When you create an account or subscribe, we additionally use the following processors:

  • Supabase (Supabase Inc.): authentication, account database and private company-logo storage. Your account data is hosted in the London / EU region.
  • Stripe (Stripe Payments Europe, Ltd.): subscription payments, billing and invoicing. We never see or store your card details; Stripe processes them under its PCI-DSS obligations.
  • Resend: sending transactional account email (address verification, password reset, the welcome message).
  • Cloudflare Turnstile: privacy-preserving bot protection on our sign-in and sign-up forms.
  • Netlify: in addition to hosting, we use Netlify Web Analytics, which is measured server-side, sets no cookies and collects no personal identifiers (see our Cookie Policy).

Loading fonts and JavaScript libraries from third-party servers (Google Fonts and Cloudflare cdnjs) causes your browser to send your IP address to those providers, which can constitute processing of personal data under the UK GDPR and access to information stored on your device under the Privacy and Electronic Communications Regulations (PECR). We use these providers only to deliver essential page presentation and functionality, never for advertising or cross-site tracking, and we disclose them here. We are migrating these dependencies to self-hosted copies to remove the transfer entirely.

7. International transfers

Netlify is a US-based provider with a UK GDPR-aligned Data Processing Addendum incorporating the EU Standard Contractual Clauses and the UK Addendum. Google and Cloudflare may also process data in the United States or other countries outside the United Kingdom. Where this happens, transfers are made under appropriate safeguards (SCCs + UK Addendum).

For accounts and billing: your Supabase account data is held in the London / EU region, so it is not transferred outside the UK/EU for ordinary account operations. Stripe, Resend and Cloudflare Turnstile may process limited data (such as your email or IP address) in the United States or elsewhere; where they do, transfers are covered by the Standard Contractual Clauses and the UK International Data Transfer Addendum (IDTA).

8. Security

The Service is served exclusively over HTTPS. We use Netlify's automatic TLS provisioning. Local-storage data on your device is protected by your browser's same-origin policy and the security boundaries of your operating system.

Account security. Account data in Supabase is protected by row-level security so that you can only access your own records; all traffic is encrypted in transit (HTTPS/TLS); payment card data is handled solely by Stripe under PCI-DSS; and our secret keys are held server-side only and are never exposed to the browser.

If a security incident occurred that affected personal data, we would notify the Information Commissioner's Office (ICO) within 72 hours where required by Article 33 UK GDPR, and would notify affected individuals directly where required by Article 34.

9. Your rights

Under UK GDPR you have the following rights in relation to personal data we hold about you:

  • Right of access (Article 15): request a copy of your personal data.
  • Right to rectification (Article 16): request correction of inaccurate data.
  • Right to erasure (Article 17): the "right to be forgotten", subject to limited exceptions. If you have an account, you can exercise this directly using the Delete account action in your account settings, which cancels any subscription and deletes your login, profile and stored company logo. As noted in Section 5, invoice and payment records are retained for the legally-required period.
  • Right to restrict processing (Article 18).
  • Right to data portability (Article 20): for on-device data, this is implemented by the "Export session log" function in the IO-log helper.
  • Right to object (Article 21): to processing based on legitimate interests.
  • Right to withdraw consent (Article 7(3)).
  • Right to lodge a complaint with the ICO (see Section 13).

To exercise any of these rights, contact us at the address in Section 13. We will respond within one calendar month.

10. Cookies & local storage

Quinnsite does not set any advertising or tracking cookies, and our analytics (Netlify Web Analytics) is cookieless, so no cookie-consent banner is required. We use the browser's localStorage and sessionStorage APIs to record the disclaimer acknowledgement, session UUID, IO-log buffer and (per calculator) any auto-saved input values you have started entering, strictly necessary for the calculator to remember your work between page reloads. If you sign in, your authentication session is also kept in localStorage by our authentication provider (Supabase) so you stay logged in; this is strictly necessary for the account to function. See our Cookie Policy for the full breakdown.

To clear all Quinnsite local-storage data, open your browser's developer console on any Quinnsite page and run:

  • localStorage.clear(); sessionStorage.clear();

or use your browser's "Clear site data" tool for quinnsite.co.uk. The full inventory of storage keys we use is listed in the Cookie Policy.

11. Children

The Service is aimed at professional engineers, planners, contractors, architects, developers and local-authority staff. It is not directed at children under 13. We do not knowingly collect personal data from children. If you become aware that a child has provided personal data to us, please contact us so we can remove it.

12. Changes to this policy

We will publish any material change here, update the "Effective date" and the disclaimer-version string in the click-through modal, and re-prompt you for acknowledgement on your next visit.

13. Contact & complaints

Privacy queries, data-subject requests and complaints can be sent to: hello@quinnsite.co.uk.

If we cannot resolve your complaint, you have the right to complain to the Information Commissioner's Office:

  • Website: ico.org.uk
  • Helpline: 0303 123 1113
  • Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF