Privacy Policy
Last updated: 29 June 2026
Zylem ("we", "us", "our") builds websites for small businesses and trades. This page explains what personal information we collect through this website, why, and what we do with it.
The short version: we don't run ads or analytics trackers on this site. We only collect what you give us directly — through a form, at checkout, or in the kick-off questionnaire — and we only use it to reply to you, take payment, or build the site you've asked for. We use Stripe to take payment (your card details never reach us), and GoHighLevel as our CRM to manage client projects.
1. Who we are
This website is operated by Zylem.
Contact us about anything in this policy at contact@zylem.io.
2. Information we collect, and why
Just browsing
We don't use Google Analytics, Meta/Facebook Pixel, or any advertising or tracking cookies. We don't know who's browsing the site unless you tell us. Two things happen automatically in your browser regardless:
- Fonts — this site loads typefaces from Google Fonts (
fonts.googleapis.comandfonts.gstatic.com). Your browser connects to Google's servers to fetch them, which exposes your IP address to Google in the same way any web request does. See Google's Privacy Policy. - Live examples of our work — the homepage embeds live previews of two sites we've built for other clients, shown directly from their own domains. Loading the homepage loads those pages too. We don't control what those sites do; see our Cookies Policy for more.
Getting a quote or registering interest
The "Get a quote" form and the "Register interest" (Grow) form on the homepage ask for your name, email, phone, and (for the quote form) your business name and message. These forms don't send anything to a server — submitting one simply opens your own email app with a drafted message addressed to us. We only ever receive that information if you go on to actually send the email. At that point, it's just an email, handled like any other message sent to contact@zylem.io.
Buying The 14-Day Site
At checkout, we collect your name, email, phone number, business name, and an optional discount code. We send this to Stripe to create a secure, hosted checkout session. You then enter your card (or Klarna/PayPal) details directly on Stripe's own page — we never see or store your payment details. See Stripe's Privacy Policy.
If you choose to spread the cost via Klarna or PayPal, you're entering a separate credit arrangement directly with Klarna or PayPal under their own terms — we're paid in full by Stripe either way and don't see your credit application.
Once payment succeeds, we forward your name, email, phone number and business name to our CRM (GoHighLevel), which automatically emails you a link to the kick-off questionnaire. If you haven't completed it after a day or two, GoHighLevel sends reminder emails and, after two days, a reminder text message to the phone number you provided — this stops as soon as you submit the form.
The kick-off questionnaire
After payment, the questionnaire asks for the details we need to actually build your site — things like your business information, branding preferences, the content and call-to-action you want, and (if relevant) the address or area to show on an embedded map.
- Autosave: as you fill it in, your answers are saved to your own browser's local storage so you can close the tab and pick up where you left off. This stays on your device — it isn't sent anywhere until you submit.
- Photo and logo uploads: any logo, hero image, gallery photos or other pictures you upload are sent to our hosting provider (Netlify) for storage, and a link to each is added to your CRM record so we can retrieve them when building your site.
- On submit: we verify your payment with Stripe, then send your name, email, business name and questionnaire answers to our CRM (GoHighLevel) so we can build your site. Your local autosave copy is then no longer needed.
3. Who we share information with
We don't sell your data. We use a small number of providers ("processors") to run the service:
| Who | What for | What they get |
|---|---|---|
| Stripe | Payment processing | Name, email, business name, payment details (entered directly on Stripe's site) |
| GoHighLevel | Our CRM — managing client projects and communication, sending the automated kick-off email after payment, and sending reminder emails/texts if the kick-off form isn't completed | Name, email, phone number, business name, payment status, questionnaire answers |
| Netlify | Hosting this website and its server-side functions, and storing any photos/logos you upload in the kick-off questionnaire | Standard web request data (e.g. IP address) needed to serve the site, plus any uploaded files |
| Google Fonts | Serving the typefaces used on this site | IP address, via your browser's request for the font files |
We may also disclose information where we're required to by law, or to protect our rights.
4. International transfers
Some of the providers above (notably Stripe and Google) may process data outside the UK. Where that happens, they do so under their own appropriate safeguards (such as Standard Contractual Clauses) — see their respective privacy policies for details.
5. How long we keep it
- Enquiries (quote requests, interest registrations you actually email us) — kept as long as needed to respond, then deleted unless you become a client.
- Client and project data — kept for the duration of the project and afterwards as needed to support the site, plus any period required by law (for example, UK accounting and tax records are typically kept for 6 years).
6. Your rights
Under UK GDPR, you have the right to:
- Ask what personal data we hold about you, and get a copy of it
- Ask us to correct inaccurate data
- Ask us to delete your data, where there's no good reason for us to keep it
- Object to, or ask us to restrict, certain processing
- Ask for your data in a portable format
To exercise any of these, email contact@zylem.io. If you're unhappy with how we've handled your data, you can also complain to the UK's Information Commissioner's Office (ICO).
7. Children
This service is aimed at business owners and isn't directed at children. We don't knowingly collect personal data from children.
8. Security
Payment is handled entirely by Stripe, a PCI-compliant payment processor — we never see or store full card details. This site is served over HTTPS. We rely on our processors' own security measures for the data they hold on our behalf.
9. Changes to this policy
We'll update this page if what we collect or how we use it changes — for example, if we add analytics in future, it'll be reflected here first. Material changes will be dated at the top of this page.
10. Contact us
Questions about this policy or your data: contact@zylem.io.
This policy is drafted to accurately reflect how this specific website currently works. It's provided as a clear, working starting point rather than a substitute for legal advice — worth a solicitor's review before relying on it commercially.