Privacy Policy for Shahnanigans

Last updated: 8 February 2026

This Privacy Policy explains how Shahnanigans (“we”, “us”, “our”) collects and uses personal data when you visit our website, contact us, or book a call with us.

1) Who we are (data controller)
Shahnanigans is the data controller for personal data collected via this website.

Contact email: mail@shahnanigans.co.uk

We operate from the United Kingdom. If you need our postal address for any reason (including to exercise your legal rights), email us and we will provide it.

2) What personal data we collect
A) Information you provide
- Contact details: name, email address, phone number (if provided)
- Company details: company name, role/title (if provided)
- Your message/enquiry and any information you choose to share
- Booking information if you book a call (date/time, and any details you submit via the booking form)

B) Information we collect automatically (website use)
- Device and browser information
- IP address (and approximate location derived from it)
- Pages you view and actions you take on the site
- Referral source (how you found our site)
- Cookie and similar technology identifiers (see our Cookie Policy)

We do not intentionally collect “special category” data (e.g., health, religion, political opinions). Please do not send it to us.

3) How we use your data and our lawful bases
We only process personal data where we have a lawful basis under the UK GDPR (and where applicable, the EU GDPR).

A) Responding to enquiries and managing relationships
Purpose: respond to messages, arrange calls, provide information, prepare proposals, and manage our relationship with you.
Lawful basis: Legitimate interests (running our studio and communicating with potential clients) and/or taking steps to enter into a contract.

B) Delivering our services (clients)
Purpose: project delivery, account management, support, and administration.
Lawful basis: Contract (performance of a contract) and/or legitimate interests.

C) Website analytics and performance (Google Analytics)
Purpose: understand how visitors use our website so we can improve content, performance, and user experience.
Lawful basis: Consent (we treat analytics cookies as non-essential and only use them when you consent via the cookie banner/settings).

D) Advertising measurement and marketing (Meta Pixel)
Purpose: measure the performance of our advertising, understand conversions, and build audiences for advertising (where applicable).
Lawful basis: Consent (we treat advertising/marketing cookies as non-essential and only use them when you consent via the cookie banner/settings).

E) Security and fraud prevention
Purpose: protect the website and our systems, prevent misuse, and maintain security.
Lawful basis: Legitimate interests.

F) Legal obligations
Purpose: comply with legal, regulatory, and tax/accounting obligations.
Lawful basis: Legal obligation.

4) Cookies and tracking (summary)
We use:
- Google Analytics (analytics cookies)
- Meta Pixel (marketing/advertising cookies)
- Calendly (embedded scheduling widget, which may set cookies needed for booking functionality)

Non-essential cookies (including analytics and marketing) require your consent. See our Cookie Policy for details and how to manage preferences.

5) Who we share personal data with
We do not sell your personal data.

We share data only when needed to run our website and business, including with:
- Website hosting, infrastructure, and security providers
- Google Analytics (Google LLC and its affiliates) for website analytics, if you consent
- Meta (Meta Platforms, Inc. and its affiliates) for advertising measurement/targeting, if you consent
- Calendly, LLC (and its service providers) to enable call booking via the embedded widget
- Professional advisers (e.g., accountants/legal advisers) where necessary
- Authorities/regulators where required by law

Some providers process data as “processors” on our behalf; others may act as independent controllers for their own purposes (for example, Meta and Google may use data in accordance with their own policies when their services are used).

6) International transfers
Some of our providers (e.g., Google, Meta, Calendly) may process personal data outside the UK and/or EEA. Where this happens, we rely on appropriate safeguards such as adequacy decisions or standard contractual clauses (and any additional measures required).

7) How long we keep your data (retention)
We keep personal data only as long as needed:
- Enquiries/prospects: typically up to 12 months from our last interaction (unless you become a client or we have a lawful reason to retain longer).
- Clients: for the duration of the relationship and then typically up to 6 years to meet legal/accounting requirements and to handle legal claims.
- Analytics/marketing data: retained according to our platform settings and cookie lifetimes; you can withdraw consent at any time.

8) Your rights
You may have rights under data protection law, including:
- Right of access
- Right to rectification
- Right to erasure (in certain circumstances)
- Right to restrict processing (in certain circumstances)
- Right to object (where we rely on legitimate interests)
- Right to data portability (in certain circumstances)
- Right to withdraw consent (where processing is based on consent)

To exercise your rights, email: mail@shahnanigans.co.uk

9) Complaints
If you have concerns, contact us first and we will try to resolve them.

If you are in the EEA, you may also complain to your local data protection authority.

10) Children
Our website is not directed to children and we do not knowingly collect personal data from children.

11) Changes to this policy
We may update this Privacy Policy from time to time. The “Last updated” date above will show when changes were made.

By using our website, you hereby consent to our Privacy Policy and agree to its terms.