Privacy policy
Last updated 10 October 2026
- We only collect what people type in, plus what we need to keep the service secure.
- We use one cookie, to keep you signed in. Business websites built with us use none.
- No advertising, no tracking and no analytics scripts. We never sell personal data.
Who we are
My Business Suite helps UK small businesses build and run their website, handle the enquiries and bookings it brings in, and send quotes and invoices.
The service is run by My Business Suite. For anything about your data, email privacy@mybusinesssuite.co.uk.
Two kinds of people, two roles
If you run a business on My Business Suite, we decide how your account data is used, so we are its controller.
If you visited, contacted or booked with a business that uses My Business Suite, that business decides what happens to your details and is the controller. We store and process them on the business’s behalf, as its processor, and only to run the service it uses. For questions about your enquiry, booking or invoice, contact the business first. We’ll help it answer you.
What we collect, and why
When you create and use an account
- Your name, email address and business name. We need these to create your account. There is no password: to sign in, we email you a link and a 6-digit code that work once, for 15 minutes. We keep a scrambled (hashed) copy of the link and code, with the email address it was sent to, for a day. Lawful basis: our contract with you.
- What you put into your website and the app, such as text, photos, services, prices, opening hours and notes. We store it to build and show your website. Lawful basis: contract.
- Your invoice details, if you send invoices: your legal business name, company and VAT numbers if you have them, and the bank details you want customers to pay into. We store them to print them on your invoices. Lawful basis: contract.
- Card payments, if you set them up: you sign up on Stripe’s own pages, and Stripe collects your identity and bank details for its legal checks as a separate controller, under Stripe’s privacy policy. We keep only your Stripe account’s id and what Stripe tells us about it (whether it can take payments and pay out, and what it still needs). Lawful basis: contract.
- AI requests. When you ask the AI to draft your website or a reply, we send the text it needs (your answers, or the enquiry you’re replying to) to our AI provider to write the draft. Nothing is published or sent to anyone until you approve it. Lawful basis: contract.
- Your daily summary. When you open Home, our AI may write a two or three sentence summary of your new messages and today’s bookings. It reads only what you can see in the app, and the customers’ first names, messages, services and times it needs go to our AI provider. We keep the summary for you alone, until the end of that day, and delete it within 48 hours. It writes nothing else and sends nothing. Lawful basis: contract.
- Emails we must send you, such as sign-in links and new booking notices. These are service messages, not marketing. Lawful basis: contract.
When you contact or book with a business through its website
- Contact form: your name, email address, phone number (optional), your message, and the wording of the consent box you ticked. The business uses these to reply to you.
- Online booking: your name, email address, phone number (optional), any note you add, and the service and time you chose. The business uses these to provide your appointment, and you’ll get a confirmation email. If the business cancels it, we also keep when it was cancelled, who at the business cancelled it, and any message the business wrote to you, which is included in the email telling you.
- The business can see these details in its account, and may use our AI to help draft a reply to you, or to summarise its new messages and bookings for itself. A person at the business always reviews a reply before it is sent.
- The business can also keep its own records about you in its account: notes, and sales notes about work it is discussing with you, such as a short description, its estimated value, the next step and whether it went ahead. The business decides what to record and is the controller for it.
When a business sends you a quote or an invoice
- Quotes: your name, email address, the address the business adds (optional), and what you were quoted for and how much. If you accept or decline the quote from its link, we record your answer, when you gave it and the note you add (optional), and email them to the business. Lawful basis: steps you ask for before a contract.
- Invoices: your name, email address, the billing address the business adds (optional), what you were invoiced for and how much, and the payments the business records against it. The business uses these to bill you and to keep the financial records the law requires.
- Reminders and follow-ups: if the business chases an invoice or follows up a quote, we store the message it sent you (who it went to, the subject, the text and when) and email it to you with the link. The business can have an AI help write the message from the invoice or quote details; the business reads and edits it before it is sent. Lawful basis: the business’s legitimate interest in being paid and in hearing back.
- When you open a quote or invoice link: the business can see the date you first opened it, so it knows it reached you. We record only that time, not your IP address, and set no cookie. Lawful basis: the business’s legitimate interest in knowing its quote or invoice arrived.
- Paying an invoice by card: if the business takes card payments, you pay on Stripe’s own page. Your card details go to Stripe and never reach us, and Stripe handles them under its own privacy policy. We keep the amount, the time, Stripe’s ids for the payment, our fee on it, and any refund or dispute and its status, not your card number, brand or last four digits. No Stripe script or cookie is used on our pages. Lawful basis: contract.
For everyone: keeping the service secure
- Your IP address is used to stop spam and repeated sign-in guessing. We never store it as it is: it’s turned into a scrambled code using a key that changes every day, and that code is deleted within a day or two. Lawful basis: our legitimate interest in protecting the service and the businesses on it.
- Request logs. Our hosting provider keeps short-lived technical logs of requests to our servers, which include IP addresses, to run and protect the service. Lawful basis: legitimate interest.
Cookies and browser storage
When you change Appearance in the app, we remember your choice of Light, Dark or System for six months. This preference cookie contains no identifier and is not used for tracking.
We don’t use advertising or analytics cookies, and business websites built with My Business Suite store nothing on visitors’ devices. Everything on our pages, including fonts and images, comes from our own servers, so your browser doesn’t contact any other company when you visit.
This is everything we store in your browser. Each item is strictly necessary for something you asked for, so the law doesn’t require us to ask permission first, and we don’t show a cookie banner.
| Name | Type | Where | What it’s for | How long |
|---|---|---|---|---|
mbs_appearance | Cookie | The My Business Suite app, when you change Appearance | Remembers the Light, Dark or System appearance you chose. It contains no identifier and is not used for tracking. | Six months, renewed when you change Appearance |
mbs_session | Cookie | The My Business Suite app, after you sign in | Keeps you signed in. It holds a random id, nothing else. | 30 days, or until you log out |
mbs:website-intake:… | Browser storage | The app's "Generate my website" form | Saves your answers as you type, so a refresh doesn't lose them. | Until your website is generated |
Who we share data with
We never sell personal data or share it for advertising. We use these providers to run the service. Each one only processes data on our instructions, under a contract that requires them to protect it.
- Cloudflare: Hosts the app and business websites, stores uploaded photos, makes resized copies of them for websites, and keeps short-lived request logs. It also manages our web addresses and the certificates for businesses' own domains.
- Neon: Runs our database, where accounts, websites, enquiries, bookings, quotes and invoices are stored.
- Anthropic: Provides the AI that writes website drafts, reply drafts, payment reminders, quote follow-ups, suggested invoice lines and the daily summary on Home. It receives only the text needed for that draft or summary.
- Stripe: Lets a business take card payments, once it sets them up. Stripe collects the business owner's identity and bank details, and the customer's card details on its own payment page, under its own privacy policy. We keep the Stripe account's id and whether it can take payments, and for each card payment the amount, time, Stripe's ids and our fee, never card details.
- Resend: Sends our emails, including sign-in links and codes, booking notices and invoices, from servers in Ireland.
Some of these providers are based in, or use staff and systems in, the United States. When personal data leaves the UK, we only use providers covered by UK adequacy regulations (such as the UK–US data bridge) or by the International Data Transfer Addendum approved by the Information Commissioner.
We will also share data if the law requires it, for example a valid request from the police or a court.
How long we keep it
- Account and website data: while your account is open. When you close it, we delete it after a short grace period, so you can change your mind.
- Enquiries, bookings and a business’s notes about you: for as long as the business keeps its account, unless the business deletes them sooner or you ask it to.
- Invoices and payments: at least six years after the invoice is sent, because UK businesses must keep their financial records that long. If you ask for your details to be erased, the invoice stays only as the record the law requires and is no longer linked to your contact record.
- AI daily summaries: until the end of the day they were written for, and deleted within 48 hours.
- Sign-in sessions: 30 days at most.
- Sign-in emails’ scrambled link and code, and the address they went to: a day.
- Scrambled IP codes used against spam: a day or two.
- Backups: up to 30 days, after which deleted data is gone from them too.
Your rights
Under UK data protection law you can ask to:
- see the personal data we hold about you and get a copy;
- correct anything that’s wrong;
- have it deleted;
- limit how we use it, or object to us using it;
- receive it in a format you can take to another service.
To use any of these rights, contact us at privacy@mybusinesssuite.co.uk. If your details were collected by a business’s website, you can also ask the business directly. We’ll answer within one month, and it’s free.
If you’re unhappy with how we’ve handled your data, you can complain to the Information Commissioner’s Office at ico.org.uk or on 0303 123 1113. We’d appreciate the chance to put it right first.
Keeping data safe
Everything is sent over encrypted connections. Each business’s data is kept separate from every other business’s at the database level. We don’t use passwords, sign-in links and codes are stored only in scrambled form, and access to data inside our team is limited and logged.
Changes to this policy
When we change what we collect or how we use it, we update this page and the date at the top. If a change matters to you, we’ll tell you in the app or by email before it takes effect.