Privacy Policy
Last updated: 21 July 2026 · Studio Mare, Ireland
1. Who we are
Studio Mare builds and hosts one-page websites for small businesses in Ireland. For the information you share with us — in the concierge chat, at checkout and in your account — we are the data controller under the GDPR and the Irish Data Protection Act 2018. For any privacy question or request, contact contact@dunaai.dev.
One special case: enquiries that visitors submit on our clients' published websites. For those, the business that owns the website decides why the data is collected — we store and forward it on their behalf, acting as their processor (see section 8).
2. What we collect
- Briefing details you share in the concierge chat: business name and type, your name, email, phone, service area, opening hours, WhatsApp number, social media pages, domain preference, and the chat transcript itself.
- Files you upload for your website: a logo and work photos.
- Account details: email and password (password held by our authentication provider — we never see it).
- Billing details: name and billing address, collected by Stripe at checkout — needed for billing and, if you ask us to register a domain, for the domain registrant record. We never see or store your full card number.
- Enquiries submitted through your published site's contact form (name, contact details and message of the person enquiring — passed to you).
- Operational logs needed to run and secure the service: IP addresses, timestamps and request metadata, kept briefly for rate-limiting, abuse prevention and debugging.
3. Why we can use it (legal bases)
- Contract — building, publishing, hosting and supporting your website; taking payment; sending service messages.
- Legitimate interests — securing the service (rate limiting, abuse and bot prevention, logs), improving it, and defending legal claims.
- Legal obligation — tax and accounting records, and responding to lawful requests.
- Consent — anything optional we ask for separately (for example, showing your site in our portfolio). You can withdraw consent at any time.
We don't use your data for advertising, we don't sell it, and we don't make automated decisions about you that have legal effects. AI is used to draft your website copy from the details you give us — you review the result before paying.
4. Processors we use
To provide the service we share the minimum necessary data with these providers, each bound by a data-processing agreement:
- Supabase — database, authentication and file storage.
- Vercel — hosting and content delivery; and, where you ask us to register a domain, domain registration services.
- Stripe — payments, billing and invoicing.
- OpenAI — powers the concierge chat and drafts your website copy from the details you provide. API data is not used by OpenAI to train models.
- Resend — transactional email (confirmations, your site-is-live email, enquiry notifications).
- Cloudflare — bot protection on our forms (Turnstile), when enabled.
- UptimeRobot — availability monitoring of published sites (pings public pages; processes no personal data).
If we add or replace a provider we'll update this page. Some providers process data outside the EU under appropriate safeguards — EU Standard Contractual Clauses or an adequacy decision such as the EU–US Data Privacy Framework.
5. Domain registration data
If we register a domain for you, ICANN and registry rules require passing your registrant details (name, address, email, phone) to the registrar and registry. Depending on the extension, some of this may appear in public WHOIS/RDAP records, usually behind the registrar's privacy service where available. This is inherent to owning a domain in your own name — which is the point: it's yours.
6. Cookies & local storage
We keep this boutique-simple: no advertising cookies, no third-party analytics, no tracking. What we do use:
- Essential storage — your login session, and your chat progress saved in your own browser (localStorage) so a refresh doesn't lose your briefing.
- Stripe — sets cookies during checkout for payment security and fraud prevention.
- Cloudflare Turnstile — when enabled, sets a cookie solely to tell humans from bots on our forms.
Because everything above is strictly necessary to provide what you asked for, there's no cookie banner to click — there's nothing optional to consent to.
7. How long we keep things (retention)
- Your site, briefing and account — for as long as your website is live with us, plus a reasonable offboarding period (at least 30 days) so you can export or reactivate.
- Billing records — up to 7 years, as Irish tax law requires.
- Operational logs — days to a few weeks, unless needed for an ongoing security investigation.
- Abandoned briefings (chat started, never purchased) — deleted or anonymised after a reasonable period.
8. Enquiries on client websites
When someone fills in the contact form on a website we host for a client, that enquiry (name, contact details, message) belongs to the client's business: they are the controller, and we process it for them — storing it and emailing it to the business owner. If you enquired on one of our clients' sites and want your enquiry corrected or deleted, contact that business directly, or email us and we'll pass the request on and assist.
9. Security
Traffic is encrypted in transit (HTTPS everywhere, including client sites). Data is stored with providers offering encryption at rest. Access to production systems is limited to what the service needs, service credentials are scoped and rotated, and payments never touch our servers — they go straight to Stripe. No system is perfectly secure, but if a breach ever affects your personal data we'll notify you and the Data Protection Commission as the GDPR requires (within 72 hours where feasible).
10. Your rights
Under the GDPR you can ask for access to, correction of, deletion of, or a portable copy of your personal data; you can object to or restrict certain processing; and you can withdraw any consent you've given. Email contact@dunaai.dev and we'll respond within a month. You also have the right to complain to the Irish Data Protection Commission (dataprotection.ie).
11. Children
Our service is for businesses and isn't directed at children; we don't knowingly collect children's data.
12. Changes to this policy
We'll post updates here with a new "last updated" date. If a change meaningfully reduces your rights, we'll give active customers notice by email first.