Privacy policy.
What we do with data — the little this site collects, and the client data we handle building stores, apps and measurement infrastructure.
Contents
1. Three different kinds of data
Worth separating, because they are governed differently:
- Website data. Information about people who visit monochrome.digital or email us. Monochrome decides how this is handled and is the controller of it.
- Client data. Advertising, analytics, store and business data that we access and process on behalf of a client, under that client’s instructions and with access that client has granted. Monochrome acts as a processor here; the client remains the controller.
- Product data. Data processed by applications Monochrome publishes and operates. Each application we publish — Inner Circle and Provenance — has its own privacy policy describing exactly what that application does with data: Inner Circle and Provenance. This policy covers the studio, not the individual products.
2. This website
monochrome.digital is a set of static pages. It sets no cookies, runs no analytics or advertising tags, has no tracking pixels, and does not fingerprint or profile visitors. There is nothing to consent to, which is why there is no consent banner.
The typeface is served from our own domain rather than a font CDN, so simply reading these pages does not tell any third party that you visited. Two things are worth disclosing anyway:
- The contact form’s spam check. The form on our contact page — and only that page — runs Cloudflare Turnstile, which decides whether a submission came from a person or a bot. It runs a script from Cloudflare and passes them your IP address and some signals about your browser for that check. Turnstile is used because it does not profile visitors, set advertising cookies or track you across sites, which the common alternatives do. It runs in invisible mode, so there is nothing to click and most people will never know it ran; Cloudflare’s handling of what it collects is described in the Turnstile Privacy Addendum. If you would rather not run it, email us directly instead; it reaches exactly the same place.
- Server logs. Our hosting provider keeps standard access logs — IP address, timestamp, requested page, user agent — for security and operational purposes. We do not use these logs for marketing and do not attempt to identify individuals from them.
3. If you contact us
There are three ways to reach us, and they are handled slightly differently.
- Email. When you write to hello@monochrome.digital we hold your message, your address and anything you choose to put in it, so we can reply and keep a record of the conversation.
- The contact form. The form on our contact page posts to our own server, which turns your submission into a single email and discards it. The form sets no cookies, runs no JavaScript in your browser, and does not profile or track you. Delivery of that email is handled by our transactional email provider, who processes it on our instruction and is not permitted to use it for their own purposes.
- Booking a call. Our scheduling link is hosted by Cal.com. If you book through it, the details you give are processed by Cal.com under their own privacy policy as well as ours. If you would rather not use them, email us and we will arrange a time by hand.
We use what you send for replying and for the resulting work. We do not add correspondents to a mailing list, and we do not sell or share contact details.
Enquiries that do not become work are deleted within 12 months. Correspondence relating to an engagement is kept for the duration of that engagement and for as long afterwards as we are required to keep business records.
4. Advertising-platform and analytics data
This is a substantial part of our work, so it is set out in detail.
What we connect to
With a client’s authorisation we connect to platforms including Google Ads (via the Google Ads API), Google Analytics 4 (via the Google Analytics Data API), Google Search Console (via the Search Console API) and Meta Ads (via the Meta Marketing API), together with the client’s own systems such as Shopify, a CRM or a billing system.
Access is read-only
Our connections to advertising platforms are used to read reporting data only. We retrieve campaign, cost, delivery, conversion and performance data for reporting and analysis. We do not create, edit, pause or delete campaigns, change budgets or bids, upload audiences, or spend money through these connections. Where a platform offers both read and write scopes, we request the read scopes.
Whose instruction we act on
We access a client’s platform data only where that client has granted access through the platform’s own permission system, and only for the purposes agreed with that client. Access can be revoked by the client at any time, directly in the platform, without our involvement.
What we do not do with it
- We do not sell client data, advertising data or any data derived from it. There is no circumstance in which we would.
- We do not share it with third parties except the infrastructure providers described in section 8, who process it on our instruction, and where a law or court order requires disclosure.
- We do not combine one client’s data with another’s. Each engagement is kept in a separate, isolated environment.
- We do not use client data to build benchmarks, market reports, resold datasets or training data for machine-learning models.
- We do not use it to target advertising, our own or anybody else’s.
- We do not transfer platform data to any advertising network, data broker or credit agency.
Google API Services
Monochrome’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Data obtained through the Google Ads API is used solely to provide reporting and analysis to the client whose account it belongs to, in accordance with the Google Ads API Terms and Conditions and the Google Ads Platform Terms.
Personal data within platform data
Most of what we handle is aggregate reporting data: impressions, clicks, cost, sessions, queries, conversions by campaign and date. Some engagements also involve identifiers from a client’s own records, such as an order reference or a hashed customer identifier, used to join a conversion to the activity that preceded it. Where we can do the work with pseudonymous or aggregate data, we do; we ask for identifying fields only when the analysis genuinely requires them, and we do not request raw payment details, passwords or special-category data.
5. Store and application development
Building or maintaining a client’s Shopify store or application means having access to a live system that contains real customer and order records. How we handle that:
- Named accounts, scoped permissions. We work through our own named staff or collaborator accounts on the client’s store, with the narrowest permissions the work allows, protected by multi-factor authentication. We do not use shared logins and we do not ask clients to send us passwords.
- Access ends with the engagement. When work finishes we ask the client to remove our accounts, and we confirm removal. Access is theirs to grant and theirs to revoke.
- We do not export customer lists. Customer, order and payment records are viewed in place, in the client’s admin, for the purpose of doing the work. We do not download customer databases, and we do not copy them into our own systems. Where a data export is genuinely necessary — a migration, for instance — it is agreed in writing in advance, limited to the fields required, and deleted once the work is complete.
- Test data where possible. Development and staging work uses sample or anonymised data rather than live customer records wherever that is workable.
- No payment details. We do not have access to, and do not ask for, cardholder data. Payment processing is handled by the client’s payment provider and never passes through us.
- Apps we build for clients request the narrowest API scopes that make the app work, implement the platform’s mandatory data-request and data-erasure webhooks, and are owned by the client on handover.
6. Applications we publish
Monochrome publishes and operates Inner Circle and Provenance for Shopify. Each application has its own privacy policy setting out precisely what data that application accesses, why, where it is stored and how long it is kept. Those policies — Inner Circle, Provenance, with a data processing agreement and sub-processor list for Provenance — apply to those applications specifically. Installing one of our applications is a separate relationship from engaging the studio, and this policy does not replace it.
7. Design and strategy work
Design and strategy engagements usually involve no personal data at all — they run on documents, interviews and aggregate figures. Where a piece of research does involve people, for example user interviews, participants are told who we are and what the recording is for, and the material is used only for that engagement and deleted at the end of it.
8. Where data is stored
Wherever the engagement allows, client data stays in the client’s own systems — their Shopify org, their cloud account, their warehouse — in infrastructure the client owns and controls, in a region they choose. In that arrangement we hold access, not the data.
Where Monochrome hosts infrastructure instead, each client is given a separate, isolated project rather than a shared database, and the storage region is agreed with the client before any data is loaded. Credentials and API tokens are held in a dedicated secrets manager, not in code, spreadsheets or shared documents.
9. Infrastructure providers
We use a small number of providers to run our own business and to host client infrastructure — cloud hosting and warehousing, email, and source control. They process data on our instruction, under contract, and are not permitted to use it for their own purposes. We will name the specific providers relevant to an engagement on request, and we list them in the data-processing terms attached to every contract.
10. How long we keep things
- Client warehouse data is kept for the term of the engagement, or as agreed in the contract where a longer history is the point of the project.
- Platform and store access ends when an engagement ends. We ask clients to revoke our access and remove our accounts, and we delete stored credentials and tokens on our side within 30 days.
- Copies we hold — extracts, working datasets, migration files, analysis files — are deleted within 30 days of the end of an engagement unless the client asks us in writing to retain them.
- Source code and design files for client work are kept for the term of the engagement and handed over at the end of it. We retain a copy only where the contract says we should, for support purposes.
- Business records such as contracts and invoices are kept for as long as applicable tax law requires.
11. Security
Access to client systems is limited to the people working on that engagement. Accounts we use are protected by multi-factor authentication. Credentials are stored in a secrets manager. Data in our infrastructure is encrypted at rest and in transit. We prefer client-owned infrastructure precisely because it reduces the number of copies of anything in existence.
12. Your rights and how to make a request
Where the law gives you rights over your personal data, you can ask us to confirm what we hold, correct it, provide a copy, restrict how it is used, or delete it.
Write to hello@monochrome.digital with “Data request” in the subject line. We acknowledge requests within two business days and complete them within 30 days.
If your request concerns data we hold on behalf of a client — if you are a customer of one of our clients, or shopped at a store we built — we will forward it to that client, who is the controller of that data, and support them in responding. We cannot delete a client’s records on the instruction of a third party, but we will make sure the request reaches the person who can.
13. Children
Our services are sold to businesses and this website is not directed at children. We do not knowingly collect data from anyone under 16.
14. Changes to this policy
If this policy changes, the revised version is published here with a new date at the top. Material changes affecting an active engagement are communicated to that client directly rather than left to be discovered.
15. Contact
Questions about this policy, or about anything above: hello@monochrome.digital.