Privacy Policy
Last updated in June 2026
Nobody reads privacy policies. We know that. But this one is worth a quick look — because it tells you exactly what information we collect about you, what we do with it, and what your rights are.
We've written it in plain English because we think you deserve to understand it, not just tick a box confirming you've seen it.
1. Who We Are
Honeyrock is a website and lead system provider for local service businesses, trading as Honeyrock Ltd, based in the United Kingdom.
For the purposes of UK data protection law, Honeyrock is the data controller — which means we're responsible for deciding how and why your personal data is used.
Contact details:
Honeyrock
Email: hello@honeyrock.co
Website: www.honeyrock.co
If you have any questions about this privacy policy or how we handle your data, please get in touch. We're happy to talk it through.
2. What This Policy Covers
This policy applies to:
- Visitors to our website (www.honeyrock.co)
- People who enquire about or book a strategy session with us
- Clients who sign up for a Honeyrock plan
- Customers of our clients whose data passes through the Honeyrock platform as part of the services we provide
If you are a customer of a business that uses Honeyrock — for example, you've filled in a contact form on a local business's website that we built — your data is processed by us on behalf of that business. The business you contacted is the data controller for your information; we are their data processor. You should also refer to that business's own privacy policy.
3. What Personal Data We Collect
Depending on how you interact with us, we may collect the following types of personal data:
From website visitors:
- IP address and browser information (collected automatically via cookies and analytics tools)
- Pages visited and time spent on the site
From people who enquire or book a strategy session:
- Name
- Email address
- Phone number
- Business name and details
- The content of any messages you send us via our contact form or chat widget
From clients who sign up for a plan:
- Name and contact details
- Business name, address, and contact information
- Payment information (processed securely by our payment provider — we don't store card details ourselves)
- Information about your business, services, and customers that you share with us during onboarding
- Communications between us by email, phone, or message
From customers of our clients (processed on behalf of our clients):
- Name and contact details
- Enquiry and booking information
- Message history through the SmartSite platform
- Appointment and job information
4. How We Collect Your Data
We collect personal data in the following ways:
- Directly from you — when you fill in a form on our website, book a strategy session, send us a message, or sign up as a client
- Automatically — when you visit our website, through cookies and analytics tools (see Section 9 on cookies)
- From third-party platforms — where you interact with tools integrated into our services, such as the GoHighLevel platform
- From our clients — when they provide us with information about their customers as part of delivering the SmartSite service
5. Why We Use Your Data and Our Legal Basis for Doing So
UK GDPR requires us to have a lawful basis for processing your personal data. Here's what we use your data for and why we're allowed to:
- To respond to your enquiry or strategy session booking
Lawful basis: Legitimate interests — you've reached out to us, so responding is what you'd expect us to do. - To provide the services you've signed up for
Lawful basis: Contract — processing your data is necessary to deliver the SmartSite and associated services you've contracted with us for. - To process your payment
Lawful basis: Contract — we need your payment details to charge for the services. - To send you service-related communications
Things like onboarding information, updates to your SmartSite, support responses, and important notices about your account.
Lawful basis: Contract and legitimate interests. - To send you marketing communications
If you've opted in to receive marketing from us — such as our blog, tips, or updates about new features — we'll send you occasional emails. You can unsubscribe at any time.
Lawful basis: Consent. - To improve our website and services
We use anonymised analytics data to understand how our website is used and where we can make improvements.
Lawful basis: Legitimate interests. - To comply with legal obligations
For example, keeping financial records for HMRC purposes.
Lawful basis: Legal obligation. - To process data on behalf of our clients
When we handle customer data as part of delivering the SmartSite service, we act as a data processor on behalf of our clients (the data controllers).
Lawful basis: Contract (our data processing agreement with our clients).
6. Who We Share Your Data With
We don't sell your data. We don't share it with third parties for their own marketing purposes. Full stop.
We do share data with the following categories of third parties, but only to the extent necessary to provide our services:
- GoHighLevel
Our primary platform for building and operating SmartSites. Your data — and your customers' data — passes through GoHighLevel's infrastructure. GoHighLevel acts as a data processor on our behalf, under a data processing agreement. Their privacy policy is available at www.gohighlevel.com/privacy-policy.
GoHighLevel stores data on servers located in the United States. Where data is transferred outside the UK, we ensure appropriate safeguards are in place in accordance with UK GDPR requirements. - Payment processors
We use a third-party payment provider to process subscription payments securely. We don't store your card details. Our payment provider processes your payment data under their own privacy policy and security standards. - Email and communication tools
We use standard business email and communication tools to correspond with clients and prospects. These providers are bound by appropriate data protection terms. - Analytics tools
We use website analytics tools (such as Google Analytics) to understand how our website is used. This data is anonymised and aggregated — it doesn't identify you personally. - Legal and professional advisers
In rare circumstances, we may need to share data with our solicitors or accountants — for example, in the event of a dispute or to comply with a legal obligation. This is done only when necessary and under strict confidentiality. - Law enforcement or regulatory bodies
If we're required to disclose data by law — for example, by a court order or regulatory requirement — we'll comply. We'll tell you if we're able to.
7. How Long We Keep Your Data
We don't keep your data longer than we need to. Here's how long we typically retain different types of data:
| Type of data | Retention period |
|---|---|
| Enquiry and strategy session data (non-clients) | 12 months from last contact |
| Client account data | Duration of the contract plus 6 years (for legal and financial record-keeping) |
| Payment records | 6 years (required by HMRC) |
| Customer data processed on behalf of clients | As directed by the client, typically for the duration of our contract with them |
| Website analytics data | 26 months (Google Analytics default) |
| Marketing email data | Until you unsubscribe, then deleted within 30 days |
When data is no longer needed, we delete it securely.
8. Your Rights Under UK GDPR
You have the following rights in relation to your personal data. These aren't just legal formalities — they're real rights and we take them seriously.
- The right to access
You can ask us to provide a copy of the personal data we hold about you. We'll respond within one month. - The right to rectification
If any data we hold about you is inaccurate or incomplete, you can ask us to correct it. - The right to erasure
Also known as the "right to be forgotten." In certain circumstances, you can ask us to delete your personal data. We'll do this unless we have a legal obligation to keep it (for example, financial records). - The right to restrict processing
You can ask us to stop actively using your data in certain circumstances — for example, while a dispute is being resolved. - The right to data portability
You can ask us to provide your data in a commonly used, machine-readable format so you can transfer it to another provider. - The right to object
You can object to us processing your data where we're relying on legitimate interests as our lawful basis. We'll stop unless we have compelling legitimate grounds to continue. - The right to withdraw consent
Where we're relying on your consent to process data (for example, for marketing emails), you can withdraw that consent at any time. This won't affect the lawfulness of processing before your withdrawal. - The right to complain
If you're unhappy with how we've handled your data, you have the right to complain to the Information Commissioner's Office (ICO) — the UK's data protection regulator.
ICO website: www.ico.org.uk
ICO helpline: 0303 123 1113
We'd always prefer you came to us first — we'd genuinely like the chance to put things right before you escalate. But the right to contact the ICO is always yours.
To exercise any of these rights, please contact us at hello@honeyrock.co. We'll respond within one month and won't charge you for reasonable requests.
9. Cookies
Cookies are small text files that get stored on your device when you visit a website. They do various useful things — like remembering your preferences and helping us understand how people use our site.
Here's what we use cookies for:
- Essential cookies
These are necessary for the website to function. They can't be switched off. They don't store any personally identifiable information. - Analytics cookies
We use Google Analytics to understand how visitors use our website — which pages are popular, where people come from, and how long they stay. This helps us improve the site. The data collected is anonymised and aggregated.
You can opt out of Google Analytics tracking at any time using the Google Analytics opt-out browser add-on: tools.google.com/dlpage/gaoptout - Marketing and retargeting cookies
If we run any paid advertising campaigns, these cookies help us understand whether our ads are working and avoid showing you the same ad repeatedly. We'll always ask for your consent before placing these cookies.
Managing your cookie preferences
When you first visit our website, you'll be shown a cookie consent banner that lets you choose which cookies you accept. You can change your preferences at any time by clearing your browser cookies and revisiting the site.
Most browsers also allow you to control cookies through their settings. Visit www.aboutcookies.org for guidance on how to do this in your specific browser.
10. Data Security
We take the security of your data seriously. We use appropriate technical and organisational measures to protect personal data against unauthorised access, loss, or destruction.
Specifically:
- Our website uses SSL encryption (the padlock in your browser)
- Access to client data within our platform is restricted to authorised personnel only
- We use secure, reputable third-party platforms with their own robust security practices
- We don't store payment card data — this is handled entirely by our payment provider
No system is 100% impenetrable — but we take every reasonable step to keep your data safe. In the unlikely event of a data breach that poses a risk to your rights and freedoms, we'll notify you and the ICO within 72 hours of becoming aware of it, as required by law.
11. Data Transfers Outside the UK
Some of the third-party platforms we use — including GoHighLevel — store or process data on servers located outside the United Kingdom, including in the United States.
Where data is transferred outside the UK, we ensure that appropriate safeguards are in place to protect it in accordance with UK GDPR. These safeguards may include standard contractual clauses approved by the ICO or reliance on adequacy decisions.
If you'd like more information about the specific safeguards in place for any international data transfers, please get in touch.
12. Children's Data
Our services are intended for business owners and adults. We do not knowingly collect personal data from anyone under the age of 18. If you believe we've inadvertently collected data about a child, please contact us immediately and we'll delete it.
13. Changes to This Policy
We may update this privacy policy from time to time — for example, if we introduce new features, use new third-party tools, or if data protection law changes.
When we make significant changes, we'll let existing clients know by email. The current version is always available at /privacy and shows the date it was last updated at the top.
14. Contact Us
If you have any questions about this privacy policy, want to exercise any of your rights, or just want to understand more about how we handle data — please get in touch. We're human beings, not a compliance department, and we're happy to talk it through.
Honeyrock
Email: hello@honeyrock.co
Website: www.honeyrock.co
This policy was last updated in June 2026.
