Your data

1. Who we are

TradeBlitz builds lead-generation websites for trades businesses across the UK. We are in charge of the personal data we collect through this website (www.tradeblitz.co.uk) and through our work with you.

TradeBlitz is a trading name of PR0DUCT1VE LTD, a company registered in England and Wales (company number 14910637). Our registered office is 71-75 Shelton Street, Covent Garden, London WC2H 9JQ, and our VAT number is 441 8335 02. PR0DUCT1VE LTD is the data controller for the personal data described in this policy.

When we build and run a website for a client, the data their visitors leave (names, phone numbers, messages) belongs to the client, not us. We just look after it for them. Same goes when we run their Google Ads.

Got a question about your data? Get in touch through the form on this website and we will help.

2. What we collect

When you fill in a form or send us a message:

  • Your name, email, phone, business name and trade
  • Anything you type into a form or send us in a message
  • Billing details (payments are by Direct Debit through GoCardless, who handle your bank details securely; we do not store them)

Automatically when you visit this site:

  • Your browser, device type and rough location. Your IP address is used to work out that location and is then discarded, not stored against anything
  • Which pages you open, a short fixed list of things you click, and which site sent you

If you become a client:

  • Access to your analytics, ad accounts and form data so we can do the job
  • Leads that come in through websites we built for you, which we look after on your behalf

3. What we do with it

The law makes us tell you our "lawful basis" for using your data, which is just fancy talk for the reason we are allowed to:

  • To reply to you and do the work you have asked for. Basis: we have a contract, or are about to.
  • To send you project updates, invoices and reports. Basis: contract.
  • To make this site better and measure our marketing. Basis: legitimate interest in running the business. You can tell us to stop at any time.
  • To send the odd message about new services, only if you have asked or the law allows. Basis: legitimate interest. You can unsubscribe at any time.
  • To do our taxes and follow the law. Basis: legal obligation.

We do not sell your data. Ever.

4. Who we share it with

We use other companies to run the business. They handle some of your data for us, under written agreements. The main ones:

  • Netlify hosts this site and handles the contact form
  • PostHog measures how this site is used, on servers in the European Union
  • Cloudflare carries those measurement requests from this site to PostHog
  • GoCardless collects your monthly payment by Direct Debit and handles your bank details
  • Google provides the Google Ads platform your campaigns run on, if you are on Fast Start (see section 6)
  • Accounting, invoicing and email tools to keep the business running

We only share what they need to do the job. We may also have to share data if the law makes us, or to defend ourselves in a legal claim.

5. Cookies and tracking

This site sets no analytics or advertising cookies, and there is no cookie notice because there is nothing to ask you about.

We count usage: which page was opened, roughly where in the world from, which site sent you (the site, not what you typed into it), a short fixed list of things happening on the page, and any error the site throws. It writes nothing to your browser's storage and leaves no identifier behind, so nothing joins one page you open to the next, or one visit to another. When you close the tab there is nothing left of you here.

We do not record your screen, we do not track where your pointer goes, and we do not log every click. We did offer that in exchange for a cookie, and stopped on 11 September 2026.

One thing is stored on your device, and only if you start the client brief: your answers, saved in your own browser so a half-finished form survives a closed tab. It never leaves your device until you submit the form, it is cleared when you do, and nothing in it is used to track you.

Our analytics run on PostHog, whose EU servers process this for us under a data processing agreement.

When we run ads for a client, we put a Google Ads tag on the client's website so we can see which ads turn into leads. That is on their site, not this one. The client adds a cookie banner of their own to tell visitors, and we help them get that right.

6. Your Google Ads account

This section applies to Fast Start clients only. If you do not run ads with us, none of it affects you.

Your Google Ads account is your own. It is opened in your name, your payment card sits on it, and Google bills you directly. You grant us manager access so we can do the work, and you can withdraw that access yourself at any time from inside your own account, without going through us.

While we have access, we create and change campaigns, keywords, ad copy and budgets on your behalf, and we read the reporting that goes with them: what your ads cost, which searches triggered them, and which clicks turned into calls or form leads. Some of that we pull through the Google Ads API into our own internal tools, so that several accounts can be managed properly rather than by hand. Those tools are ours alone. We do not offer them to anyone else, and no other client can see your account or your figures.

We use what we take from your account for one purpose: running and reporting on your campaigns. We do not sell it, share it with another client, use it to train anything, or use it for our own advertising. Where we handle Google user data, we follow the Google API Services User Data Policy, including its Limited Use requirements.

If you stop Fast Start, we remove our access. The account, its campaigns and its whole history stay with you. We keep nothing beyond the reports and business records we are required to hold for tax and accounting (see section 8).

7. Where your data goes

PostHog holds this site's usage data on servers in the European Union, so nothing is stored outside it. Cloudflare carries it on the way there, on behalf of PostHog and under the data protection terms PostHog publishes. Where any other provider we use is based outside the UK, we make sure the transfer uses safeguards the UK government accepts: the UK's data transfer agreement, the EU's standard clauses, or an "adequacy" approval.

8. How long we keep it

  • Leads and messages: while it is still useful, then deleted. Sooner if you ask.
  • Client records and invoices: 6 years after the work ends, because UK tax law makes us.
  • Website analytics: event data up to 12 months. Session recordings, which only exist if you accepted, 30 days.
  • Marketing list: until you unsubscribe.

9. Your rights

Under UK GDPR, you can ask us to:

  • Show you what we hold about you
  • Fix anything that is wrong
  • Delete it, where we are not legally required to keep it
  • Stop or limit how we use it
  • Hand it over in a portable file
  • Withdraw consent, where consent was the basis

Get in touch through the form on this website and we will come back to you within a month.

If we have messed up and you would rather complain, you can go to the UK's Information Commissioner's Office (ICO) at ico.org.uk. We would rather you let us fix it first.

10. Keeping your data safe

We protect your data with HTTPS encryption, password-protected accounts and trusted suppliers. Nothing online is 100% safe and we cannot promise it can never be hacked, but we take it seriously.

11. Changes to this policy

We may update this from time to time. The date below shows the latest version.

Last updated: June 2026