The clear version

Privacy,
no smoke.

What this website may collect, why it may be used and the choices you have.

1. Scope

This privacy notice explains how GooGoGoGo Studio (“we”, “our” or “us”) handles personal information when you browse this website, contact us or prepare a project inquiry. A service we build for a client may have its own privacy notice and is not covered here.

2. Information you provide

When you use the contact form, the project brief on /start-project, the free store scan on the homepage, a form on one of our service pages or the newsletter box, we receive what you type: your name, email address and message, and where you provide them, your store URL, budget range, timing and what you want to build.

With each submission we also record the page it was sent from, your country as reported by our CDN, your browser’s user-agent string and your IP address. We keep these with the inquiry to answer you, to tell genuine inquiries from automated spam, and to trace abuse.

Inquiries are stored in our database on Cloudflare and forwarded to us as an email and an instant message so we can reply quickly. If you give us your email address we may send you one confirmation of receipt. The free store scan runs a read-only audit of the public storefront URL you enter; the report is kept together with the email address you gave us.

3. Technical information and analytics

Cloudflare hosts and serves this site. To deliver and protect it, Cloudflare processes ordinary request data such as IP address, browser type, requested page and time, and keeps security logs under its own policies.

We run our own first-party analytics: page views, scroll depth, clicks on key elements, Core Web Vitals, the referring site, campaign (UTM) parameters, and the page path and query string with any token-like values removed. We never store your raw IP address for analytics. The visitor identifier is a one-way hash of your IP address, user-agent and a salt that changes every day, so the same visitor can only be recognised within a single day. Raw analytics events are kept for 90 days and then reduced to daily aggregates; security event logs are kept for 30 days. Cloudflare Web Analytics, a cookie-less beacon, may also run.

Your browser may also send us Content Security Policy reports (the page, the blocked address and the policy directive) when something on a page is not on our allow-list. These contain no personal data.

4. Cookies, browser storage and consent

This site sets no tracking cookies of its own. It keeps a few values in your browser’s local storage: gg_consent (your cookie choice), gg_optout (analytics opt-out), gg_vid and gg_sid (pseudonymous visitor and session identifiers for our first-party analytics), gg_attr (the campaign parameters you arrived with) and gg_pop_seen (whether the newsletter prompt has already been shown). Cloudflare may set its own security cookies to protect the site.

Advertising and measurement tags from Google (Ads and Analytics), Meta and TikTok run only with your permission. In the EEA, the United Kingdom and Switzerland they load only after you choose “Accept” on the consent banner; elsewhere they load unless you decline, and a browser Global Privacy Control or Do Not Track signal is treated as a decline everywhere. You can change your choice at any time with “Cookie settings” in the footer. Once loaded, these tags set their own cookies under their providers’ policies: Google, Meta, TikTok.

5. How we use information

  • To answer inquiries and assess potential projects.
  • To plan, deliver and communicate about agreed services.
  • To operate, secure, debug and improve the website.
  • To meet legal, accounting or compliance obligations.

Where required by applicable law, we rely on consent, steps requested before a contract, performance of a contract, legal obligations or our legitimate interests in operating the studio.

6. Sharing

We do not sell personal information. We share it only with the service providers we need to run the studio, each under its own terms and safeguards: Cloudflare (hosting, content delivery, database and security), Google (Workspace email and, with your consent, Ads and Analytics), Meta and TikTok (measurement tags, with your consent) and Telegram, which delivers the instant notification of new inquiries to us. We may also disclose information when required by law.

7. Retention

Inquiries and project briefs are kept as business records for as long as we may need to follow up, handle a dispute or meet legal obligations, and are deleted on request. Raw analytics events are kept for 90 days, after which only daily aggregates remain; security logs for 30 days; policy-violation reports for the current review cycle. Cloudflare keeps request logs under its own retention rules.

8. International processing

We work internationally, so information may be processed in countries different from yours. Where required, we use appropriate contractual or legal safeguards for international transfers.

9. Your choices and rights

Depending on where you live, you may have rights to access, correct, delete, restrict or object to processing, receive a portable copy, withdraw consent or complain to a data protection authority. To make a request, email us. You can change your cookie choice at any time with “Cookie settings” in the footer. We may need to verify your identity before acting.

10. Security

We use reasonable organizational and technical measures appropriate to a small digital studio. No internet transmission or storage method can be guaranteed completely secure, so avoid sending sensitive credentials or payment information through ordinary email.

11. Children

This website and our studio services are directed to businesses and are not intended for children. We do not knowingly seek personal information from children.

12. Changes and contact

We may update this notice when the site, providers or legal requirements change. The effective date above will identify the latest version. Questions or requests can be sent to hello@googogogo.com.