Skip to content

Privacy Policy for Stagebit

Last updated: 29 May 2026

This Privacy Policy explains how Stagebit (“Stagebit”, “we”, “us” or “our”) collects, uses, stores, shares and protects personal data when you visit stagebit.com (the “Website”), contact us, or engage our services.

We are committed to protecting your privacy and handling your personal data in compliance with the General Data Protection Regulation (GDPR), the UK GDPR, the California Consumer Privacy Act (CCPA), the Australian Privacy Act 1988, and all other applicable data protection laws.

Please read this policy carefully. If you have any questions, contact us at [email protected] before using our Website.

1. Who We Are

Stagebit is an eCommerce development agency specialising in Magento 2, Adobe Commerce, Hyvä themes, Shopware, WooCommerce, Shopify and PWA development. We provide development, migration, maintenance and related technical services to clients worldwide.

For the purposes of data protection law, Stagebit is the data controller in respect of the personal data collected through this Website.

Contact details:
Email: [email protected]
Website: https://stagebit.com

2. What Personal Data We Collect

We collect the following categories of personal data:

2.1 Data you provide directly

  • Contact and enquiry data: Your name, work email address, company name, phone number, website URL and the content of messages submitted through our contact forms, chat tools or email correspondence.
  • Project and brief data: Information you provide when requesting a quote or scoping a project, including technical requirements, existing platform details, budget ranges and any attachments or files shared with us.
  • Client account data: Name, job title, billing address and payment contact details if you become a client of Stagebit.
  • Communication data: Records of email, Slack or other correspondence between you and our team during the course of an enquiry or engagement.

2.2 Data collected automatically

  • Usage and technical data: IP address, browser type and version, operating system, referral source, pages visited, time spent on pages, links clicked and device identifiers. This data is collected via server log files and analytics tools.
  • Cookie data: Information stored in cookies placed on your device. See Section 7 (Cookies) for full details.

2.3 Data from third-party sources

  • Review platforms: If you leave a review of our services on Clutch, Google or Upwork, we may reference publicly available information from those platforms.
  • Referrals: If another party refers you to us, we may receive your name and contact details from them.

We do not collect any special categories of personal data (such as health, racial or ethnic origin, religious beliefs, or biometric data) and we do not process financial payment data directly — payments are handled by third-party processors named in Section 5.

3. Legal Basis for Processing (GDPR)

Under GDPR and UK GDPR, we are required to identify a lawful basis before processing your personal data. We rely on the following bases:

PurposeLegal Basis
Responding to your enquiry or contact form submissionLegitimate interests (Article 6(1)(f)) — responding to business enquiries is a legitimate interest of ours and you have a reasonable expectation of a response
Providing services under a signed contract or statement of workPerformance of a contract (Article 6(1)(b))
Sending marketing communications to existing clientsLegitimate interests (Article 6(1)(f)) — you can opt out at any time
Sending marketing communications to non-clients who have opted inConsent (Article 6(1)(a))
Analytics and website performance monitoringLegitimate interests (Article 6(1)(f)) — improving our website and services
Complying with legal obligations (tax, accounting, legal claims)Legal obligation (Article 6(1)(c))
Fraud prevention and securityLegitimate interests (Article 6(1)(f))

Where we rely on legitimate interests, we have carried out a balancing test and concluded that our interests are not overridden by your rights and interests. You may request details of this assessment by contacting us at [email protected].

4. How We Use Your Personal Data

We use personal data for the following purposes:

  • To respond to enquiries, requests for proposals and contact form submissions.
  • To scope, deliver and manage eCommerce development projects and related services.
  • To issue invoices, process payments and maintain financial records.
  • To send project updates, technical reports and communications relevant to your engagement.
  • To send marketing communications about our services where you have consented or where we have a legitimate interest to do so (existing clients). You can opt out at any time.
  • To analyse how our Website is used and improve its content, structure and performance.
  • To detect, investigate and prevent fraudulent activity or misuse of our services.
  • To comply with legal and regulatory obligations including tax, accounting and applicable laws.
  • To defend or pursue legal claims where necessary.

We do not use personal data for automated decision-making or profiling that produces legal or similarly significant effects.

5. Data Sharing and Third-Party Processors

We do not sell, rent or trade your personal data to third parties for their own marketing purposes. We share personal data only as described below.

5.1 Service providers and sub-processors

We engage the following categories of third-party service providers who process personal data on our behalf. All processors are bound by data processing agreements and are required to implement appropriate security measures.

CategoryPurposeExample providersData location
Website hostingHosting and serving the WebsiteWordPress hosting providerEU / USA
AnalyticsWebsite usage analysis and performance monitoringGoogle Analytics 4USA (SCCs applied)
Email marketingSending marketing and transactional emailsEmail service providerEU / USA
CRM softwareManaging client relationships and enquiriesCRM platformEU / USA
Project managementDelivering client projectsProject management toolsEU / USA
Payment processingProcessing invoices and paymentsStripe, PayPalUSA (SCCs applied)
Cloud storageStoring project files and documentationCloud storage providerEU / USA
Communication toolsClient communication during projectsSlack, emailUSA (SCCs applied)

“SCCs” means Standard Contractual Clauses approved by the European Commission for international data transfers, as described in Section 6.

5.2 Other disclosure circumstances

We may also share personal data:

  • With professional advisers (lawyers, accountants, auditors) bound by professional confidentiality.
  • With regulatory authorities, law enforcement or courts where required by law or to protect our legal rights.
  • With a successor entity in the event of a business acquisition, merger or restructuring, in which case we will notify you in advance where required by law.

6. International Data Transfers

Stagebit operates globally and serves clients in the USA, UK, EU and Australia. Some of our service providers process data outside the European Economic Area (EEA) and the UK.

Where we transfer personal data outside the EEA or UK, we ensure that appropriate safeguards are in place. These safeguards may include:

  • Adequacy decisions: Transfers to countries recognised by the European Commission or the UK ICO as providing adequate data protection.
  • Standard Contractual Clauses (SCCs): The European Commission’s approved contractual clauses between data exporters and importers, incorporated into our agreements with relevant processors.
  • UK International Data Transfer Agreements (IDTAs): For transfers from the UK to third countries not covered by an adequacy regulation.

You may request a copy of the relevant transfer mechanisms by contacting us at [email protected].

7. Cookies

7.1 What cookies are

Cookies are small text files placed on your device when you visit a website. They allow the website to recognise your device and remember certain information about your visit.

7.2 Types of cookies we use

CategoryPurposeExamplesDuration
Strictly necessaryEssential for the Website to function. Cannot be disabled.Session management, security tokens, CSRF protectionSession or up to 1 year
Analytics and performanceMeasure how visitors interact with the Website to help us improve it.Google Analytics 4 (_ga, _gid)Up to 2 years
FunctionalRemember your preferences and improve your experience.Language preference, form field memoryUp to 1 year
Marketing / targeting Used only if you have given explicit consent. Track visits across websites to deliver relevant advertising. Remarketing pixelsUp to 90 days

7.3 Managing cookies

When you first visit our Website, you will be presented with a cookie consent banner. You can accept or reject non-essential cookies at that point. You may also change your preferences at any time by clearing cookies in your browser settings. Note that disabling certain cookies may affect the functionality of the Website.

For information on managing cookies in specific browsers, visit: aboutcookies.org.

7.4 Google Analytics

We use Google Analytics 4 to understand how visitors use our Website. Google Analytics may transfer data to the USA. We have enabled IP anonymisation, entered into Google’s Data Processing Addendum and applied Standard Contractual Clauses. You can opt out of Google Analytics across all websites by installing the Google Analytics Opt-out Browser Add-on.

8. Data Retention

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by law. Our retention periods are as follows:

Category of dataRetention periodReason
Enquiry and contact form data (no contract entered)24 months from last contactLegitimate interest in managing business relationships
Client project data and correspondence7 years from end of engagementLegal obligation (tax, accounting, potential claims)
Invoices and financial records7 years (UK/EU) / 7 years (USA IRS) / 5 years (AU ATO)Statutory accounting and tax requirements
Marketing consent recordsUntil consent is withdrawn plus 3 yearsEvidence of lawful processing
Website analytics data26 months (GA4 default)Website improvement and performance analysis
Server log files90 daysSecurity and fraud prevention

When personal data is no longer required, it is securely deleted or anonymised so that it can no longer be associated with an individual.

9. Data Security

We implement appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. These measures include:

  • TLS/HTTPS encryption for all data transmitted via the Website.
  • Access controls ensuring that only authorised personnel can access personal data.
  • Role-based access management with least-privilege principles.
  • Regular security patching of Website infrastructure and third-party software.
  • Encrypted backups with offsite storage.
  • Secure disposal of data when retention periods expire.
  • Staff awareness of data protection obligations.

No method of transmission over the internet or electronic storage is 100% secure. While we implement robust security practices, we cannot guarantee absolute security. In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware and will notify affected individuals without undue delay where required.

10. Your Rights

10.1 Rights under GDPR and UK GDPR (EU and UK residents)

If you are in the EU or UK, you have the following rights:

  • Right of access (Article 15): You have the right to obtain a copy of the personal data we hold about you and information about how we process it.
  • Right to rectification (Article 16): You have the right to request correction of inaccurate or incomplete personal data.
  • Right to erasure (Article 17): You have the right to request deletion of your personal data where there is no compelling reason for its continued processing, subject to certain exceptions (e.g. legal obligations).
  • Right to restrict processing (Article 18): You have the right to request that we limit how we use your data in certain circumstances.
  • Right to data portability (Article 20): Where processing is based on consent or contract and carried out by automated means, you may request a copy of your data in a machine-readable format.
  • Right to object (Article 21): You have the right to object to processing based on legitimate interests or for direct marketing purposes. Where you object to direct marketing, we will stop immediately.
  • Right to withdraw consent: Where processing is based on consent, you may withdraw that consent at any time without affecting the lawfulness of processing before withdrawal.
  • Right not to be subject to automated decision-making: We do not use automated decision-making that produces legal or similarly significant effects on you.

To exercise any of these rights, contact us at [email protected]. We will respond within one month of receiving a verifiable request. We may need to verify your identity before processing the request.

If you are unhappy with how we have handled your data, you have the right to lodge a complaint with your national supervisory authority:

  • EU residents: Your national Data Protection Authority (DPA). A list is available at edpb.europa.eu.
  • UK residents: The Information Commissioner’s Office (ICO) at ico.org.uk.

10.2 Rights under the CCPA (California residents)

If you are a California resident, the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA) provides you with the following rights:

  • Right to know: You may request disclosure of the categories and specific pieces of personal information we have collected about you, the sources of that information, the business or commercial purposes for collecting it, and the categories of third parties with whom we share it.
  • Right to delete: You may request deletion of personal information we have collected from you, subject to certain exceptions.
  • Right to correct: You may request correction of inaccurate personal information we hold about you.
  • Right to opt out of sale or sharing: We do not sell or share personal information as defined under the CCPA. No opt-out action is required.
  • Right to limit use of sensitive personal information: We do not use or disclose sensitive personal information for purposes beyond those permitted under the CPRA.
  • Right to non-discrimination: We will not discriminate against you for exercising any of your CCPA rights.

To exercise CCPA rights, submit a verifiable consumer request to [email protected]. We will respond within 45 days. We may extend this period by a further 45 days where reasonably necessary and will notify you of the extension.

10.3 Rights under the Australian Privacy Act (Australian residents)

If you are in Australia, you have rights under the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), including:

  • Access: You may request access to personal information we hold about you. We will respond within 30 days.
  • Correction: You may request correction of personal information that is inaccurate, out of date, incomplete, irrelevant or misleading.
  • Complaint: If you are unhappy with our handling of your personal information, you may make a complaint to us first. If unresolved, you may complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.

11. Direct Marketing

We may send marketing communications about our services to existing clients on the basis of legitimate interests, or to other individuals who have explicitly consented to receive them.

You can opt out of marketing communications at any time by:

  • Clicking the “unsubscribe” link in any marketing email we send.
  • Emailing us at [email protected].

Opting out of marketing does not affect communications necessary to deliver services you have requested (e.g. project updates, invoices).

12. Children’s Privacy

Our Website and services are directed at businesses and professionals. We do not knowingly collect personal data from:

  • Children under the age of 13 (USA — COPPA).
  • Children under the age of 16 (EU — GDPR, unless a lower age has been set by the applicable EU member state).
  • Children under the age of 13 (Australia — Privacy Act).

If you believe a child has submitted personal data through our Website, please contact us at [email protected] immediately and we will take prompt steps to delete that information.

13. Links to Third-Party Websites

Our Website may contain links to third-party websites including Clutch, Upwork, Adobe and other platforms. Clicking these links will take you to sites that we do not control. We are not responsible for the privacy practices of those websites and encourage you to review their privacy policies before providing any personal data.

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our data practices, legal requirements or the services we offer. When we make material changes, we will:

  • Update the “Last updated” date at the top of this page.
  • Post a notice on the Website where appropriate.
  • Where required by law, notify you directly by email.

We encourage you to review this page periodically. Your continued use of the Website after any changes constitutes acceptance of the updated policy to the extent permitted by law.

15. Contact Us

If you have any questions, concerns or requests regarding this Privacy Policy or our data practices, please contact us:

Privacy enquiries:
Email: [email protected]

General enquiries:
Email: [email protected]
Website: stagebit.com/contact-us

We aim to respond to all privacy-related requests within 30 days. For complex requests, we may extend this period by up to two months and will inform you of the extension.

If you are located in the EU or UK and are not satisfied with our response to a complaint, you have the right to escalate your complaint to the relevant supervisory authority as described in Section 10.