What we collect, why we collect it, and how you stay in control. Written to be read, not skimmed past.
Last updated: September 2026
01Who we are
The Craft Media (“we”, “us”) is a digital agency headquartered at 350 Fifth Avenue, Suite 4100, New York, NY 10118, United States. We are the controller of the personal data described in this policy, which covers www.thecraftmedia.com and the ways you contact us through it.
Data we process on behalf of clients during a project is governed by our contract and data processing agreement with that client, not by this policy.
02Information we collect
We only collect what we need to reply to you and run a secure website:
- Contact form: your name, email, and optionally your company, phone number, services of interest, budget, timeline and the message you write.
- Chat widget: the messages you send and, if you choose to leave them, your name and email so we can follow up. A transcript of that conversation is attached to your enquiry.
- Newsletter: your email address and the date you subscribed.
- Technical data: IP address, browser type and request timestamps, processed by our servers to deliver the site, limit abuse and prevent spam.
We do not ask for sensitive data. Please don't include health, financial or other special-category information in your messages.
03How we use it & legal bases
Under the GDPR and UK GDPR we rely on the following legal bases:
- Replying to enquiries and preparing proposals — steps taken at your request before entering a contract, and our legitimate interest in responding to business enquiries.
- Sending the newsletter — your consent, which you can withdraw at any time via the unsubscribe link.
- Keeping the site secure (rate limiting, spam and bot detection) — our legitimate interest in protecting our systems and users.
- Meeting legal obligations — such as tax, accounting and responding to lawful requests.
We never sell your personal data, and we do not use it for automated decision-making or profiling.
05Who we share it with
We share personal data only with trusted service providers who process it on our instructions:
- Email delivery (Resend) — to deliver form and chat enquiries to our team.
- Hosting and content delivery — our cloud hosting provider serves the website and processes technical data.
- Spam protection (Cloudflare Turnstile) — to distinguish people from bots.
- Workspace and email tools — where our team stores and answers your enquiry.
Each provider is bound by a data processing agreement. We may also disclose data if required by law, or as part of a merger or acquisition, in which case this policy continues to apply.
06International transfers
Our team works across the US, UK, UAE and Pakistan, and some providers operate in the US. When personal data leaves the UK or EEA we rely on adequacy decisions or the European Commission's Standard Contractual Clauses (and the UK Addendum), together with appropriate safeguards.
07How long we keep it
- Enquiries and chat transcripts — up to 24 months after our last contact, unless we start working together.
- Client records — for the length of the engagement plus up to 7 years to meet accounting and legal requirements.
- Newsletter — until you unsubscribe; we then keep your address on a suppression list so we don't email you again.
- Security data — rate-limit counters are held in memory for minutes; server logs are kept for no longer than 30 days.
08How we protect it
We apply technical and organisational measures appropriate to the risk, including:
- Encryption in transit on every page and request (HTTPS with HSTS).
- A strict Content Security Policy and hardened security headers.
- Rate limiting, same-origin checks and input validation on every form and API endpoint.
- Spam and bot protection, including honeypot fields and Cloudflare Turnstile.
- Access limited to team members who need it, protected by multi-factor authentication.
No system is perfectly secure, but if a breach affects your data we will notify you and the relevant authorities as required by law.
09Your rights
Under GDPR / UK GDPR, you can ask to access, correct, delete or export your data, restrict or object to how we use it, and withdraw consent at any time. You can also complain to your local data protection authority — though we'd appreciate the chance to help first.
Under the CCPA / CPRA, California residents can request to know what personal information we collect and how we use it, ask us to delete or correct it, and opt out of its sale or sharing. We do not sell or share personal information for cross-context behavioural advertising, and we will never discriminate against you for exercising your rights.
To make a request, email info@thecraftmedia.com. We'll verify your identity and respond within 30 days (45 days where the CCPA applies). You may use an authorised agent.
10Children
This website is intended for businesses and is not directed at children under 16. We do not knowingly collect their data.
11Changes to this policy
We may update this policy as our services or the law change. The “Last updated” date above shows the latest version; significant changes will be highlighted on this page.
12Contact us
Questions about privacy? Email info@thecraftmedia.com, or write to The Craft Media, 350 Fifth Avenue, Suite 4100, New York, NY 10118, United States. You can also read our Terms of Use.