Legal
Privacy Policy
Last updated: 12 May 2026
Who we are
Heirloom ("Heirloom", "we", "us", "our") is a small family studio based in Cumbria, United Kingdom, that creates keepsake films and audio recordings of family stories. This policy explains how we handle the personal information you share with us via yourheirloom.co.uk.
We are the data controller for the personal information described in this policy. To get in touch about anything privacy-related, email hello@yourheirloom.co.uk.
What we collect
When you join the waitlist we collect:
- Your first name
- Your email address
- Who you're capturing stories for (e.g. "my mother")
- Optional: which plan interests you and a one-line note about your story
- Referral source (e.g. utm_source) if present in the URL
- The date and time you joined
We also collect limited technical and analytics information (e.g. pages visited, device type, anonymised performance metrics) only if you accept analytics cookies via our consent banner.
Why we use it and our lawful basis
- To email you about the Heirloom waitlist and launch — lawful basis: your consent, given when you submit the form. You can withdraw consent at any time (see "Your rights" below).
- To understand how the site is used and improve it — lawful basis: your consent, given via the cookie banner.
- To keep records of who consented and when — lawful basis: legal obligation and our legitimate interest in being able to demonstrate compliance.
- To respond to your enquiries — lawful basis: legitimate interest in answering people who contact us.
Who we share it with
We share your information only with service providers acting on our behalf:
- Lovable Cloud / Supabase — secure database hosting (EU region)
- Google Sheets — internal record of waitlist signups, accessible only to Heirloom staff
- Google Analytics and Meta Pixel — only if you accept analytics/advertising cookies
- Email delivery providers — to send you the waitlist update emails you've consented to receive
We do not sell your data. We do not share it with third parties for their own marketing.
International transfers
Some of our service providers (e.g. Google) may process data outside the UK/EEA. Where they do, we rely on appropriate safeguards such as the UK International Data Transfer Addendum and the EU Standard Contractual Clauses.
How long we keep it
We keep waitlist information until you ask us to delete it, or for up to 24 months after the Heirloom product launch and final follow-up email — whichever comes first. After that we delete or anonymise it.
Your rights
Under UK GDPR you have the right to:
- Access the personal information we hold about you
- Have inaccurate information corrected
- Have your information deleted
- Restrict or object to how we use it
- Receive a copy of your data in a portable format
- Withdraw your consent at any time (this won't affect the lawfulness of anything we did before you withdrew it)
To exercise any of these rights, email hello@yourheirloom.co.uk. Every email we send you will also include a one-click unsubscribe link.
If you're unhappy with how we've handled your data, you can complain to the UK Information Commissioner's Office at ico.org.uk or on 0303 123 1113. We'd appreciate the chance to put things right first, though.
Cookies
We use a small number of cookies and similar technologies. You can accept or reject the optional ones via the consent banner shown on your first visit, and change your mind later by clearing your browser storage for this site.
- Strictly necessary — remember your cookie choices. Always on.
- Analytics — Google Analytics. Only set if you accept.
- Advertising — Meta Pixel. Only set if you accept.
Security
Your information is stored on encrypted, access-controlled infrastructure. Only Heirloom staff who need to see it can access it. No system is perfectly secure, but we take this seriously.
Changes to this policy
If we make material changes, we'll update the "Last updated" date and, where appropriate, let you know by email before the changes take effect.