We're a two-person studio. We collect very little, store it carefully, and never sell it. The rest of this page explains, in plain English, exactly what that looks like.
1 · Who we are
"WebPies" (we / us / our) is an independent design and development studio operated by Vance & Okafor Lda., a Portuguese sole-shareholder company registered at 14 Rua das Janelas Verdes, 1200-690 Lisboa, Portugal. We are the data controller for personal data collected via this website (webpies.com).
2 · What we collect
We only collect what we need to run the business and deliver the products and services you've asked for. Specifically:
- Account & order data — name, email, billing/shipping address, company name and VAT ID (if you provide one), and the items you've ordered.
- Payment data — handled by Stripe and / or PayPal. We never see or store your full card number.
- Communications — emails you send us, replies to our newsletter, and project briefs submitted via the contact form.
- Site analytics — anonymised, aggregated visitor counts via Plausible (no cookies, no personal identifiers).
3 · Why we collect it
We rely on the following legal bases under the GDPR:
- Contract — to deliver the services and digital products you've purchased.
- Legitimate interest — to run, secure, and improve the site, and to answer your enquiries.
- Consent — for the newsletter, which is double-opt-in and unsubscribable at any time.
- Legal obligation — to keep invoices and tax records for the statutory period (currently 10 years in Portugal).
4 · Who we share it with
We share your data only with the processors required to run the business. We have data-processing agreements with all of them:
- Stripe & PayPal — payment processing.
- Fastmail & Buttondown — email and newsletter delivery.
- Vercel & Cloudflare — hosting, DNS, and CDN.
- Plausible — privacy-friendly analytics, hosted in the EU.
- Our accountant, when required to file Portuguese taxes.
We do not sell, rent, or share your data with advertisers or data brokers — ever.
5 · Cookies
We use one strictly-necessary cookie to keep you logged in to your account, and one to remember the contents of your cart between visits. We do not use marketing, tracking, or third-party advertising cookies.
6 · Retention
We keep your data only as long as we need it:
- Account data — until you delete your account, after which it is permanently removed within 30 days.
- Order & invoice data — 10 years, as required by Portuguese tax law.
- Newsletter subscription — until you unsubscribe.
- Contact form messages — up to 24 months, then deleted.
7 · Your rights
Under the GDPR (and equivalent laws elsewhere) you have the right to:
- Access the personal data we hold about you.
- Correct anything that's inaccurate.
- Ask us to delete data we no longer need to hold.
- Restrict or object to certain processing.
- Receive your data in a portable, machine-readable format.
- Lodge a complaint with the CNPD (Portugal) or your local supervisory authority.
To exercise any of these, write to [email protected]. We respond within 30 days.
8 · Security
All traffic to and from the site is encrypted with TLS 1.3. Passwords are hashed with bcrypt. Production data is backed up nightly to encrypted EU-based storage. Only the two of us have access. If we ever experience a breach affecting your data, we will notify you within 72 hours.
9 · Children
Our products and services are intended for use by adults in a professional context. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, please write us and we will delete it.
10 · International transfers
Most of our processors are located in the EU. Where data is transferred outside the EEA (e.g. to Stripe in the US), it is covered by Standard Contractual Clauses and the EU-US Data Privacy Framework.
11 · Changes to this policy
We may update this policy from time to time. If we make material changes, we'll let you know via email (if you have an account) and post a prominent notice on the site for 30 days. The "Last updated" date at the top will always reflect the current version.
12 · Contact
Questions, concerns, or just curious? Write us at [email protected] or visit the contact page. We answer in ~6 working hours.