Legal

Privacy Policy

The short version: we collect what you send us when you get in touch, we use it to reply and to run projects, we do not sell it, and we do not track you around the web.

Last updated: 15 August 2026

1. Who we are

Butterfly is a Sharetribe partner agency based in Belgrade, Serbia. We build and maintain online marketplaces for clients worldwide. For the purposes of data protection law, Butterfly is the controller of the personal data described in this policy.

You can reach us at [email protected] for anything related to this policy.

2. What we collect

We keep this deliberately minimal. Depending on how you interact with us, we may collect:

  • Contact form on this site. Your name, email address, an optional website or marketplace URL, and the message you write. The form also contains a hidden anti-spam field that real visitors never see or fill in.
  • Email and calls. Whatever you choose to send us by email, and the details you enter when booking a call through Calendly (Calendly's own privacy policy applies to that booking).
  • Client project data. If we work together: contact details, project requirements, and any access credentials or content you share so we can do the work. This is governed by the written agreement for that project.
  • Technical data. Our hosting and CDN providers keep standard server logs (IP address, browser type, pages requested, timestamps) for security and operations. We do not use these to profile visitors.
  • A single local flag. If you dismiss the announcement banner at the top of the site, we store one value in your browser's local storage so it stays dismissed for a day. It contains no personal data.

We do not currently run analytics or advertising trackers on this site, and we do not buy or enrich data about visitors from third parties.

3. How we use it

  • To reply to your inquiry and, if you ask us to, scope and propose a project.
  • To plan, deliver, support, and invoice client projects.
  • To keep the site and our systems secure and running.
  • To meet legal and accounting obligations.

We do not sell personal data, and we do not use it for advertising.

4. Legal bases

Where the GDPR or UK GDPR applies, we rely on:

  • Consent, when you send us a message through the contact form or by email. You can withdraw it at any time by asking us to delete the conversation.
  • Contract, or steps taken at your request before a contract, when we scope, quote, and deliver work.
  • Legitimate interests, for security, operations, and keeping records of past inquiries and projects.
  • Legal obligation, for accounting and tax records.

5. Who we share it with

Only service providers that help us run the site and the business, each under their own data processing terms:

  • Resend delivers contact form submissions to our inbox by email.
  • Calendly handles call scheduling if you book through the link on our contact page.
  • Heroku (Salesforce) hosts the site, and Cloudflare sits in front of it for performance and security. Both process request logs.
  • Sanity stores our blog content. It does not receive visitor data.
  • Google Workspace for email and documents when we correspond and run projects.

Some of these providers process data in the United States. Where that happens for EU or UK personal data, we rely on their standard contractual clauses and data processing agreements. We may also share data if the law requires it, or with a successor if the business is ever transferred, on the same terms.

6. How long we keep it

  • Inquiries that do not turn into a project: up to 24 months after our last exchange, then deleted.
  • Client project data: for the length of the engagement, plus any period we are legally required to keep invoices and contracts.
  • Server and security logs: kept by our providers for a short rolling period, typically days to a few weeks.
  • The banner-dismiss flag in your browser: 24 hours, and you can clear it any time by clearing site data.

7. Your rights

Depending on where you live, you may have the right to:

  • Ask what personal data we hold about you and receive a copy.
  • Ask us to correct or delete it.
  • Ask us to restrict how we use it, or object to a use based on legitimate interests.
  • Receive the data you gave us in a portable format.
  • Withdraw consent where we rely on it.

Email [email protected] and we will respond within 30 days. If you are in the EU or UK and are unhappy with our answer, you can complain to your local data protection authority. In Serbia, that is the Commissioner for Information of Public Importance and Personal Data Protection.

8. Security

The site is served over HTTPS. Access to inquiry and project data is limited to the people who need it to do the work. We do not take payments on this website, so we never handle your card details here.

9. Children

This site and our services are for businesses and adults. We do not knowingly collect data from anyone under 16.

10. Changes to this policy

When we change how we handle data, we update this page and the date at the top. Material changes that affect you as an existing client will also be communicated directly.

11. Contact

Questions, requests, or concerns: [email protected].