Privacy

What we collect, and what we don't.

Last updated 26 August 2026. Short version: we collect what you type into the contact form, we do not use cookies, we do not run ad trackers, and we never sell anything to anybody.

Who this covers

This policy covers hyphr.net and the pages on it. Our products, MATCH and ANSWR, are separate applications with their own terms and their own privacy notices. If you are a client, the agreement we signed with you governs the data inside the system we built for you, and that data belongs to you, not to us.

What we collect

Information you send us

When you fill in the "Start a project" form, we receive what you typed: your name, your company (if you enter one), your email address, the project type you selected, and your description of the work. That is the whole list. There are no hidden fields collecting anything else.

If you email us directly, we obviously have that email and whatever is in it.

Information collected automatically

  • Server logs. Our host records standard request data — IP address, approximate location, browser and device type, the page requested and the time. This is normal web-server operation and is used to keep the site up and to spot abuse.
  • Aggregate analytics. We use Vercel Analytics and Vercel Speed Insights to see which pages get visited and how fast they load. These are cookieless and do not build a profile of you across sites. We see counts and page-load timings, not individuals.

What we do not collect

  • No cookies are set by this website. That is why you were not shown a cookie banner.
  • No advertising or social-media tracking pixels. No Meta pixel, no Google Ads tag, no LinkedIn Insight tag.
  • No fonts, scripts or images loaded from third-party servers. Everything this page needs is served from hyphr.net, so no outside company sees your visit.
  • No payment details. We invoice clients separately and never take card numbers on this site.
  • Nothing at all from anyone under 16, knowingly.

Why we use it

We use what you send us for exactly one purpose: to reply to you and to scope the work you asked about. If you become a client, we keep it as part of the project record. If you don't, it sits in our enquiry list unless you ask us to remove it.

We do not add you to a marketing list. We do not send drip campaigns. We do not sell, rent, trade or share your information with anyone for their own marketing, and we never will.

Where it is stored, and who can see it

Your enquiry is stored in a private database and a copy is emailed to us. We use a small number of service providers to do that, and only that:

  • Vercel — hosting, serverless functions and analytics for this website.
  • Supabase — the database that holds enquiries.
  • Resend — sends the notification email so we actually see your message.

Each of these processes the data on our instructions only. Access on our side is limited to the people at HYPHR who need it to reply to you. These providers operate infrastructure in the United States and elsewhere, so your information may be processed outside your own country.

How long we keep it

Enquiries that don't turn into projects are kept for up to 24 months so we have context if you come back, then deleted. Client project records are kept for as long as we work together and for up to 7 years afterwards, because tax and contract records have to be retained. Server logs roll off on our host's normal schedule, within about 30 days.

You can shorten any of this by asking. See below.

Your rights

Wherever you live, we will honour these requests. Email hello@hyphr.net and we will action it within 30 days, at no charge:

  • See it. Ask for a copy of everything we hold about you.
  • Fix it. Have anything inaccurate corrected.
  • Delete it. Have it erased, except records we are legally required to keep.
  • Take it. Get it exported in a usable format.
  • Stop it. Object to how we are using it, or withdraw consent.

If you are in the UK or the EU, our lawful basis is legitimate interest (replying to a business enquiry you initiated) and, where a contract exists, performance of that contract. If you are in California, note again that we do not sell or share personal information, so there is nothing to opt out of, and we will not discriminate against you for exercising any right.

Security

The whole site is served over HTTPS, and every response carries a strict-transport policy instructing browsers to refuse plain HTTP for two years. Enquiries travel over an encrypted connection into a private database that is not publicly readable. Credentials for our providers are held as server-side environment variables and never appear in the pages you download. No system is perfect, and we will not pretend otherwise — but if a breach ever affects your information, we will tell you, and we will tell you quickly rather than quietly.

This site links out to MATCH, ANSWR and to clients' sites. Once you follow a link, you are on someone else's property and their privacy policy applies, not this one.

Changes

If we change this policy we will change the "last updated" date at the top. Material changes get a note on the homepage rather than a silent edit.

Contact

Questions, requests, or complaints about anything on this page go to hello@hyphr.net. A person reads it.