Legal

    Privacy Policy

    What we do with your personal data, why, and the rights you have over it under UK data protection law.

    Last updated: 18 August 2026

    1. Who is responsible for your data

    This Agency ("we", "us", "our") is the data controller for the personal data described here. Contact us about anything in this policy at [email protected].

    We handle personal data in line with the UK GDPR and the Data Protection Act 2018.

    2. The Hatch browser extension

    Hatch is also available as a browser extension, used to export your site from its builder as a ZIP file. The extension is separate from the account and Service described in the rest of this policy, and it collects no personal data.

    • It reads project files only from the builder tab you have open, and only when you press the button.
    • All processing happens in your browser, on your own machine.
    • The result is saved to your own computer as a ZIP file.
    • Nothing is transmitted to Hatch, This Agency, or any third party, and there is no server of ours involved at any point. The only requests the extension makes are to the builder you are already signed in to, to read your own project files.
    • It requires no account and no sign-in.
    • There is no analytics or telemetry of any kind.
    • Permission to access additional domains is requested at the moment it is needed, per domain, and can be revoked at any time in your browser's settings.

    The rest of this policy describes the Hatch web application and account. It does not describe the extension, which is separate and operates entirely locally.

    3. The data we collect

    • Account data — your name and email address, and your password in encrypted form.
    • Billing data — your plan, billing history and country. Card details are handled by our payment provider, not by us.
    • Usage data — records of deploys you run, the site names you choose, and errors the Service reports.
    • Support data — the messages you send us and our replies.
    • Technical data — IP address, browser type and similar information collected when you use the Service.

    4. What we do not collect or keep

    We do not store your exported website files on our servers. They travel from your browser to your own GitHub and Cloudflare accounts. We do not store the passwords of those accounts, and access tokens are used to carry out the actions you ask for.

    We never sell your personal data, and we do not use it to train AI models.

    5. Why we use it, and our lawful basis

    • To provide the Service and carry out our contract with you — performance of a contract.
    • To take payment and keep accounting records — contract and legal obligation.
    • To give support and answer your questions — contract and legitimate interests.
    • To keep the Service secure, prevent abuse and fix faults — legitimate interests.
    • To send marketing email, where you have asked for it — consent, which you can withdraw at any time.

    6. Cookies

    We use cookies that are strictly necessary to keep you signed in and to keep the Service secure; these do not need your consent. Any analytics or non-essential cookies are only set if you agree, and you can change your mind at any time. You can also control cookies in your browser settings.

    7. Who we share it with

    We share personal data only with providers who help us run the Service — for example hosting, email delivery, payment processing and customer support tools. They act on our instructions and may not use your data for their own purposes.

    We may also disclose data where the law requires it, or to establish or defend legal claims. If our business is transferred, data may pass to the buyer under the same protections.

    8. Sending data outside the UK

    Some of our providers are based outside the UK. Where personal data is transferred abroad we rely on UK adequacy regulations, or on the International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, so that your data keeps an equivalent level of protection.

    9. How long we keep it

    We keep account and usage data for as long as your account is open, and for a reasonable period afterwards in case you return or a dispute arises. Billing records are kept for six years to meet UK tax and accounting requirements. Support messages are kept for up to two years.

    10. Keeping it secure

    We use appropriate technical and organisational measures, including encryption in transit, restricted access and regular review. No online service is completely secure, but we take this seriously and will tell you and the ICO about a personal data breach where the law requires it.

    11. Your rights

    Under UK data protection law you have the right to:

    • ask for a copy of the personal data we hold about you;
    • have inaccurate data corrected;
    • ask us to delete data, in certain circumstances;
    • ask us to restrict how we use it, or object to our use of it;
    • receive data you gave us in a portable format; and
    • withdraw consent at any time, where we rely on consent.

    Email [email protected] to exercise any of these. We will respond within one month. Using these rights is free.

    12. Children

    Hatch is not intended for children. We do not knowingly collect personal data from anyone under 18. If you believe a child has given us their data, contact us and we will delete it.

    13. Changes to this policy

    We may update this policy. The date at the top shows when it last changed, and we will tell you directly if a change materially affects how we use your data.

    14. How to complain

    Please come to us first at [email protected] so we can put things right.

    You also have the right to complain to the Information Commissioner's Office, the UK supervisory authority, at ico.org.uk or on 0303 123 1113.

    Share this page
    Hatch by GHL47Hatch.

    Get your site off the platform and live on your own hosting. In. Out. Live.

    © 2026 This Agency. Hatch is a product of This Agency.

    Projects that use a database need their own security keys. We never handle or store them.

    Lovable, Bolt, Vercel, Manus, GoHighLevel, GitHub and Cloudflare are trademarks of their respective owners. Their marks are used here to show what Hatch works with, and do not imply any endorsement, sponsorship or affiliation.