Privacy policy
Last updated 7 September 2026
This policy explains what personal information Miz Commerce LLC collects when you use this site or work with us, why we collect it, and what you can ask us to do with it. It is written to be read, not to be survived.
Who we are
Miz Commerce LLC operates this website and sells the service described on it. In this policy, we, us and our mean Miz Commerce LLC. We are the controller of the personal information described here, which means we decide why it is collected and how it is used.
You can reach us about anything in this policy at support@mizcommerce.com. Email is the only contact route we publish, and it is monitored.
What we collect
This site collects four kinds of information, and nothing else. The booking calendar and the measurement tags are provided by third parties under their own policies, described below.
- The enquiry form. The form on this site asks for your first name, last name, email address, phone number, website address and a monthly revenue band. It is submitted to our own server, which passes it to our customer relationship system so we can reply and prepare for the call.
- Your visit. Our hosting provider keeps standard server logs, which record your IP address, the pages requested, the time, and your browser type. We use them to keep the site running and to investigate abuse. That is all our own server records about your visit.
- The booking calendar. After the form you are sent to a booking page. The calendar on that page is an embedded frame served by our customer relationship provider. To save you typing, your name, email address and phone number are held briefly in your browser's session storage on our site and handed to the calendar to prefill it. Session storage is cleared when you close the tab. Once you are inside the calendar, the provider's own policy applies to what it collects.
- Measurement tags. The site loads Google Tag Manager, which runs Google Analytics and Google Ads conversion measurement. Together they record the pages you view, how you arrived, including any campaign tags on the link, your approximate location, your device and browser, and whether you submitted the form or booked a call. They use cookies and similar identifiers set by Google, and Google's own privacy policy applies to what it collects. You can block these tags with your browser settings or an ad blocker, and the site works without them.
Why we use it and our lawful basis
We use what we collect for four purposes. Where the UK GDPR or EU GDPR applies to you, the lawful basis for each is named beside it.
- To reply to your enquiry, book and hold the call, and prepare for it. Basis: steps taken at your request before entering a contract, and our legitimate interest in responding to people who contact us.
- To do the work once you have signed the agreement, including keeping a record of what was agreed and delivered. Basis: performance of a contract with you.
- To keep the site available and secure. Basis: our legitimate interest in running our own website.
- To meet tax, accounting and legal obligations. Basis: compliance with a legal obligation.
Who processes it for us
We do not sell personal information and we do not share it for anyone else's advertising. We use a small number of service providers who process information on our instructions. They are listed here in full.
- GoHighLevel, also known as LeadConnector, which holds our customer relationship records and runs the booking calendar. Your form submission is stored there, and the calendar on the booking page is served by it.
- Stripe, which takes payment after you have signed the agreement. Card details are entered on Stripe's pages and never reach us or this website. We receive the outcome of the payment and the billing email.
- Vercel, which hosts this website and keeps standard server logs.
- Google, whose Tag Manager, Analytics and Ads services measure how the site is used and which advertising brought you here, as described above.
- Slack, used only as the shared working channel during a build. It holds what you and we post there while the work is under way.
- Klaviyo, Meta and Google, only as your own accounts. To do the work, we sign in to the accounts you give us access to. The data in them belongs to you and stays there. We act on your instructions inside those accounts and do not copy their customer data into our own systems.
Where information is held
Our providers are based in the United States and may process information there and in other countries where they operate. Where information about someone in the UK or the European Economic Area is transferred out of those areas, the transfer relies on the standard contractual clauses or another approved safeguard offered by the provider in question.
How long we keep it
Enquiries and form submissions that do not become work are kept for twenty four months, then deleted. Client records, briefs, correspondence and delivered files are kept for six years after the engagement ends, because the work and the invoices behind it have to be reconstructable. Records needed for tax and accounting are kept for the period the law requires. Server logs are kept for the short period set by our hosting provider.
Your rights
Depending on where you live, you can ask us to do any of the following, and we will not charge you or treat you differently for asking.
- Get a copy of the personal information we hold about you.
- Correct anything about you that is wrong or out of date.
- Delete your personal information, where we are not required to keep it.
- Restrict or object to a use of your information that relies on our legitimate interest.
- Receive your information in a portable format, or have it sent to another provider.
- Withdraw consent at any time, where a use relies on consent. Withdrawing it does not undo what was done before.
How to make a request
Email support@mizcommerce.com and say what you want us to do. We answer within thirty days. We may ask you to confirm something only you would know about your dealings with us, so we do not hand your information to somebody else.
If you are in the UK or the European Economic Area and you are not satisfied with our answer, you can complain to your national data protection authority. We would rather you told us first.
Children
This site sells a business service and is not directed at children. We do not knowingly collect information from anyone under sixteen. If you believe a child has given us information, email us and we will delete it.
Security
The site is served over an encrypted connection. Form submissions travel to our own server, and from there to our customer relationship system, over encrypted connections. Access to enquiries and client files is limited to the people who need it to do the work. No system is perfect, and we do not claim otherwise. If a breach affects your information and the law requires us to tell you, we will tell you.
Changes to this policy
We update this policy when what we do changes. The date at the top is the date of the current version. If a change materially affects how we use information you have already given us, we will tell the people affected by email. This version is dated 7 September 2026.