Privacy Policy

Privacy, plainly.

This policy explains what personal data Funky Rabbit collects when you visit funky-rabbit.com, why we collect it, how it’s processed, and the rights you have under the EU GDPR, the UK GDPR, and equivalent laws.

v1.1 · last updated 17.08.2026

The short version

  • We’re the controller — a small studio, not a data broker.
  • Default-deny tracking — analytics blocked until you say yes.
  • Self-hosted fonts & assets — your IP doesn’t leak to font CDNs.
  • 30-day reply on every privacy request, no runaround.

01 Who is the data controller

Funky Rabbit, an independent design studio. For any privacy request you can reach us at [email protected].

02 What we collect and why

Information you provide

If you contact us through the contact form, we receive the name, email address, and message body that you submit. We use this information solely to reply to your enquiry. The submission is passed to Brevo, our transactional email provider, which delivers it to our inbox — it is not added to any mailing list. Automated submissions are filtered with a hidden form field that real visitors never fill in; this check looks only at the form itself and does not profile you or run any script in your browser.

Information collected automatically

Like most websites, our host and CDN log technical request data — IP address, user agent, timestamp, and the URL you accessed — for security, abuse prevention, and traffic statistics. These logs are retained for a short, rolling period and are not used to identify individual visitors.

03 Cookies and similar technologies

When you first visit funky-rabbit.com, our own consent banner asks whether you allow non-essential cookies. Until you accept, all analytics and advertising cookies are blocked at the source via Google Consent Mode v2 — measurement tags receive a denied signal and do not write tracking cookies. You can change or withdraw that choice at any time via the Cookie settings link in the footer of every page, which re-opens the banner.

Strictly necessary Always on

Remembering your consent choice does not use a cookie at all. The banner stores a single value in your browser's local storage:

  • fr-consent — the string grant or deny. It stays in your browser, is never transmitted to us or to anyone else, and can be removed by clearing site data.

Analytics Only after you accept

If you accept, Google Analytics 4 sets its own measurement cookies (_ga and _ga_*, typically a two-year lifetime) to count returning visitors. Reject, and those tags stay denied and write nothing.

04 Third parties that may receive data

We do not share or sell your personal data to data brokers, advertisers, or any third party other than the operational processors listed below.

Cloudflare, Inc. Hosting · CDN · WAF · TLS · Email routing

Serves every page from its edge network and stores the site files. Logs request metadata (IP, user-agent, URL) for security and abuse prevention, and routes mail sent to our @funky-rabbit.com addresses.

cloudflare.com/privacypolicy ↗
Google Ireland Limited Analytics · Tag Manager

Aggregate visitor metrics via GA4 (loads only after analytics consent). IPs anonymised by default; no Google Signals, no cross-device personalised reporting.

policies.google.com/privacy ↗
Brevo (Sendinblue SAS) Transactional email

Delivers contact-form enquiries to our inbox. Receives the name, email address, and message body you submit through the form — nothing else, and never for marketing.

brevo.com/legal/privacypolicy ↗

05 Fonts and external assets

Web fonts on funky-rabbit.com are self-hosted. We do not load fonts from fonts.googleapis.com or fonts.gstatic.com, so visiting our pages does not transmit your IP address to Google for font delivery. The same applies to icons, scripts, and stylesheets — almost everything is served from our own domain or via Cloudflare.

06 How long we keep your data

  • Contact form messages — kept until the conversation is resolved, then deleted within 12 months.
  • Server logs — rotated and deleted on a 30-day cycle.
  • Analytics data — retained according to GA4’s standard 14-month event-data setting.
  • Consent choice — stored only in your own browser, for as long as you keep it there. We hold no server-side record of it.

07 Your rights

Under GDPR (and equivalent laws in your jurisdiction) you have the rights listed below. To exercise any of them, email [email protected]. We will respond within 30 days.

  • Right of access
  • Rectification
  • Erasure
  • Restriction
  • Objection
  • Data portability
  • Withdraw consent
  • Lodge a complaint

08 International transfers

Cloudflare, Google, and other listed processors operate global infrastructure, which can mean processing outside the EU/EEA. Where this happens, transfers rely on the EU Standard Contractual Clauses or the EU–U.S. Data Privacy Framework, as published by each processor.

09 Security

The site is served over HTTPS with HSTS enabled and sits behind Cloudflare’s WAF. It is a static site — there is no database, no login, and no content management system exposed to the internet, so the usual classes of attack against a CMS do not apply. Despite reasonable safeguards, no system is 100% secure; we cannot guarantee absolute security of data transmitted over the internet.

10 Changes to this policy

We update this Privacy Policy when our tools, processors, or processing purposes change. The “Last updated” date at the top reflects the most recent material change. We recommend reviewing the policy periodically.

Got a privacy question? We’ll answer it.

Email us about access, deletion, or anything else in this policy. We reply within 24 hours on weekdays — and always within 30 days, as required by GDPR.

Email us