Privacy Policy
Last updated: 23 June 2026
Nippy ("nippy.host", "we", "us") is a hosting service that lets you publish HTML sites, images, and files to the web. This policy explains what personal data we collect, why, and what your rights are. The short version: we collect the minimum we need to run the service, we don't sell data, and we don't run advertising trackers.
Who we are
The data controller is Street Ventures Limited, trading as Nippy — a company registered in England and Wales (company number 16804955), registered office 124 City Road, London, EC1V 2NX. For anything privacy-related, contact us at support@nippy.host.
What we collect
Your account
We use passwordless sign-in: the only credentials we hold are your email address and, if you choose to set one, your display name. We never see or store a password. We also keep standard account records such as when the account was created and which plan it's on.
Content you upload
Files you publish are stored so we can serve them — that's the product. Anything you publish to a live site is publicly accessible on the internet unless you put it behind a site password. Site passwords are stored only as cryptographic hashes; we cannot read them back.
Billing
Payments are processed by Stripe. Your card details go directly to Stripe and never touch our servers; we store only what we need to manage your subscription (plan, billing status — including whether you're on a free trial — and Stripe's customer reference). See Stripe's privacy policy.
Service logs
Like nearly every web service, our servers keep short-lived technical logs (IP address, request path, user agent) for security, abuse prevention, and debugging. These are not used for profiling and are deleted automatically, normally within 30 days.
Why we're allowed to use it (lawful basis)
Under UK GDPR our lawful bases are:
- Performance of a contract — running your account, storing and serving the files you publish, and managing your subscription.
- Legitimate interests — keeping the service secure, preventing abuse, and debugging (service logs). We balance this against your rights.
- Legal obligation — retaining billing and tax records, and responding to lawful requests.
Analytics on sites you publish
If you turn on analytics for one of your sites, we count your visitors using a daily-rotating anonymous hash — no cookies, no persistent identifiers, no cross-site tracking. Visitors cannot be re-identified across days, which is why your sites don't need a consent banner for our analytics. You can turn this off per site at any time.
Cookies
We set one essential cookie: the session cookie that keeps you signed in. There are no advertising or third-party tracking cookies on nippy.host.
Who processes data for us
- Cloudflare — file storage and content delivery for published sites.
- Fly.io — application hosting.
- Stripe — payment processing.
- Postmark — transactional email (sign-in links, invitations).
Each processor receives only what it needs to do its job. Some of them operate globally; where data leaves the UK/EEA, transfers rely on standard contractual clauses or equivalent safeguards.
How long we keep data
Account data is kept while your account exists. If you delete a site, its files are removed from storage, though backups and caches may take a short time to clear. Service logs are normally deleted within 30 days. If you want your account and its data deleted, email us and we'll action it promptly; billing records are retained for as long as tax law requires (currently six years).
Your rights
Under UK GDPR you can ask us to access, correct, export, or delete the personal data we hold about you, and you can object to or restrict certain processing. Email support@nippy.host and we'll respond within a month. You also have the right to complain to the Information Commissioner's Office.
Children
Nippy isn't directed at children under 13, and we don't knowingly collect their data. If you believe a child has created an account, contact us and we'll remove it.
Changes to this policy
If we make material changes we'll update this page and, for significant changes, email account holders. The "last updated" date at the top always reflects the current version.
See also our Terms of Service.