Plain-language summary
We collect three things: contact information you give us when you reach out (name, email, business details), aggregate analytics about how the site is used, and project files clients hand over during the build. We use that information only to deliver work, communicate with you about the work, and improve the site. We don't sell your data, ever. We share it with a handful of named processors (hosting, email, analytics) listed below. You can ask us what we hold, request deletion, or opt out at any time.
The rest of this page is the long version of those four sentences.
Scope of this policy
This Privacy Policy applies to upcomingbrand.com and all sub-domains, plus any direct interaction with Upcoming Brand by email, phone, video call, or messaging platform during a discovery, project, or care-plan engagement. It does not cover third-party sites we link to, even when those sites are operated by partners we recommend (hosts, plugins, payment processors).
"Upcoming Brand," "we," "us," and "our" refer to the studio operating at upcomingbrand.com. "You" refers to anyone visiting the site, contacting us, or engaged with us as a client.
Information we collect
We collect information in three ways:
Information you give us directly
- Name, email, phone (optional), company name, and project details submitted through the contact or discovery forms
- Anything you send via email or chat during discovery and engagement
- Files, copy, brand assets, and credentials you provide for project work
- Billing details (handled by Stripe — we never see card numbers)
Information collected automatically
- Aggregate analytics about page visits, time on site, referral sources, and device type
- Server logs (IP address, browser, timestamps) retained for security and debugging — typically 30-90 days
- Cookie and similar identifiers — see the Cookies section below
Information from third parties
- Public profile data when you mention or link a LinkedIn, Upwork, or social profile
- Analytics aggregates from Google, Plausible, or similar services we use
How we use information
We use the information we collect to:
- Respond to inquiries and schedule discovery calls
- Deliver project work — design, development, schema, hosting setup, and care-plan support
- Issue invoices, process payments through Stripe, and maintain financial records
- Send transactional emails (project status, staging URLs, launch confirmations, care-plan reports)
- Improve the site, identify usability issues, and prioritise content based on aggregate analytics
- Comply with legal obligations including tax records, contractor agreements, and security investigations
We do not use your information to train AI models, build advertising profiles, or sell to third parties. We do not run retargeting ads.
Third-party services
We use a small set of vetted third-party processors. Each one is listed here so you know exactly where your data may be stored.
| Processor | Purpose | Data handled | Region |
|---|---|---|---|
| Vercel | Site hosting and CDN | Server logs, page requests | USA / global edge |
| Netlify Forms | Contact form processing | Form submissions | USA |
| Stripe | Invoice and payment processing | Billing details, card data (we never see card numbers) | USA / EU |
| Google Workspace | Email hosting | Email content with you | USA |
| Google Analytics 4 | Aggregate site analytics | Anonymised page-view data | USA |
| Zoom / Google Meet | Discovery and design calls | Call audio (recorded only with consent) | USA |
Data retention
We hold information only as long as we have a legitimate reason to:
- Discovery inquiries that don't proceed: 12 months, then deleted
- Project files and communications: duration of the engagement plus 7 years for tax and legal records
- Server logs: 30-90 days, depending on the system
- Analytics aggregates: up to 26 months in Google Analytics 4, configurable
- Care plan client data: duration of the active care plan plus 1 year after cancellation
You can request earlier deletion at any time — see Your Rights below.
Your rights (GDPR / CCPA)
Depending on where you live, you have rights over the information we hold about you. We honour all of these regardless of jurisdiction:
- Access — request a copy of the information we hold about you
- Correction — fix anything that's inaccurate
- Deletion — request we delete information we no longer need to keep
- Portability — receive your data in a portable format
- Restriction — limit how we process your data
- Objection — object to specific uses (e.g., analytics)
- Withdraw consent — withdraw consent at any time, without affecting prior processing
To exercise any of these rights, email hello@upcomingbrand.com. We respond within 30 days. There's no fee unless the request is excessive or repeated.
For California residents (CCPA / CPRA)
You have the right to know what we collect, how we use it, and the right to non-discrimination for exercising any privacy right. We don't sell or share personal information for cross-context behavioural advertising.
Security
We use reasonable, current security practices to protect information in our control: TLS encryption in transit, encrypted storage where possible, two-factor authentication on every account that touches client data, principle-of-least-privilege access, and regular security review of our processors.
No system is fully secure. If we discover a breach affecting your information, we'll notify you and the appropriate authorities within 72 hours where required by law.
International transfers
Upcoming Brand operates from the United States. Most of our processors are also US-based. If you're located outside the US, your information may be transferred to and processed in countries with different data protection laws than your own — but always under safeguards including Standard Contractual Clauses where applicable.
Children's privacy
Upcoming Brand is a B2B service. We don't knowingly collect information from anyone under 16. If we discover we've collected information from a minor, we delete it. If you believe we have, contact us immediately.
Changes to this policy
We may update this Privacy Policy as our practices, services, or applicable laws change. The "Last updated" date at the top reflects the most recent revision. For material changes, we'll notify active clients by email at least 30 days before the change takes effect.
Past versions are archived and available on request — we don't quietly replace policies and pretend the older version never existed.
Contact us
Privacy questions, data requests, or concerns about how we handle your information — reach out and we'll respond within 4 business hours during business days.