ShopOur StoryRecipesContact

Legal

Privacy Policy

Last updated: 19 April 2026

Modern Savage (“we”, “us”, “our”) respects your privacy. This policy explains what personal data we collect when you visit modernsavage.co, why we collect it, how we use it, and the rights you have over it. It applies whether you visit us from the UK, the US, or anywhere else. It covers the UK GDPR and the Data Protection Act 2018 for UK visitors, and the California Consumer Privacy Act as amended by the CPRA, along with the Virginia, Colorado, Connecticut, Utah and Texas state privacy laws, for US visitors.

Pre-launch status

Modern Savage is currently in a pre-launch phase. You cannot place orders yet. Until launch, the only personal data we handle is what you actively give us (email address to join the launch list, messages to support) plus the technical data we need to keep the site running and measure traffic. This policy will be updated before orders open to describe order, payment and shipping data in full.

Data controller

The data controller for personal data collected through this site is Modern Savage. If you live in the UK or EU, Modern Savage is the controller for the purposes of the UK GDPR and the EU GDPR. If you live in the US, Modern Savage is the business that determines the purposes and means of processing your personal information for the purposes of state privacy laws (such as the CCPA/CPRA).

You can reach us at support@modernsavage.co.

What we collect

  • Launch-list signups: your email address. If you give us your name you can, but we do not require it.
  • Support messages: anything you include when you email support@modernsavage.co.
  • Country cookie (ms_country): stores “GB” or “US” so we can show prices in the right currency. Set on first visit based on the country our hosting provider (Vercel) associates with your IP, or by your choice in the country switcher.
  • Security data: a one-way cryptographic hash of your IP address and a shortened browser User-Agent string, used for a short period to rate-limit forms and block abuse.
  • Analytics: aggregated, privacy-friendly site analytics via Vercel Web Analytics. We see page views, referrer, country and device type. It does not use cookies and does not identify individual visitors.

Purpose of processing

We use your email address for direct marketing communications: launch updates, special offers and promotional emails about Modern Savage products. We also use personal data to reply to support messages, to keep the site secure, and to show the right currency.

Legal basis (UK / EU visitors)

  • Explicit consent, Article 6(1)(a) UK GDPR: the legal basis for sending you direct marketing emails is the explicit consent you give by entering your email in our signup form. Ticking a consent box is not required in addition because submitting the form is itself an unambiguous, affirmative act of consent made for the single purpose described at the form (joining the Modern Savage launch list / marketing list). You can withdraw that consent at any time, see “How to unsubscribe” below. Withdrawing consent does not affect the lawfulness of emails we already sent.
  • Legitimate interests, Article 6(1)(f): keeping the site secure, preventing spam and abuse, and understanding which content is useful to visitors.
  • Contract, Article 6(1)(b) (from launch, once orders open): for processing orders you place with us.
  • Legal obligation, Article 6(1)(c) (from launch): for order records, tax and consumer-law records.

Data retention

  • Email address: kept until you unsubscribe, then removed (or suppressed for deliverability and to honour your unsubscribe) within 30 days.
  • Support messages: kept for up to 24 months so we can help you on follow-up queries, then deleted, unless we are required to keep them longer by law.
  • Security data (hashed IP): minutes only. Used to rate-limit forms, then discarded.
  • Analytics: aggregated, no individual retention.
  • Order data (from launch): kept for as long as required by tax and consumer law, usually 6 to 7 years.

Your rights

Under UK / EU GDPR you have the right to:

  • Access the personal data we hold about you
  • Correct / update data that is inaccurate or incomplete
  • Delete your personal data (the right to be forgotten / right to erasure)
  • Restrict or object to certain uses of your data
  • Ask for a copy of your data in a portable format (data portability)
  • Withdraw consent and unsubscribe at any time (see below)
  • Lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk

If you live in a US state with a privacy law (California, Virginia, Colorado, Connecticut, Utah, Texas, and others), you have parallel rights including the right to know / access, the right to delete, the right to correct, the right to opt out of sale or sharing (we do not sell or share your personal information, see below), and the right not to be discriminated against for exercising these rights. We honour the Global Privacy Control (GPC) browser signal as an opt-out of sale / sharing.

How to unsubscribe or exercise your rights

You can unsubscribe or withdraw consent in any of the following ways:

  • click the Unsubscribe link in the footer of every marketing email we send, this is the quickest way and it takes effect immediately
  • use the one-click unsubscribe option that your email client may show next to the sender name (Gmail, Apple Mail, and Yahoo support this where available)
  • visit modernsavage.co/unsubscribe and enter your email
  • email support@modernsavage.co from the address you signed up with

To exercise any other right (access, correction, deletion, portability, restriction, objection), email support@modernsavage.co from the address you signed up with. We will respond within 30 days (UK/EU) or 45 days (US state laws), as required by law. In rare complex cases we may extend this by a further two months and will tell you if we do.

Who we share your data with

We do not sell your personal data. We do not share it for cross-context behavioural advertising. We do not rent or trade your email address to third parties for their own marketing.

We use a small number of service providers (processors) who handle data on our behalf strictly to run the site and send you the emails you asked for:

  • Supabase (EU-hosted), stores the launch-list email database and short-lived security data.
  • Resend, sends the emails you've asked for (launch updates, welcome, support replies, marketing emails).
  • Vercel, hosts the site and provides the cookieless Vercel Web Analytics described above.

Each of these providers is bound by a data processing agreement with appropriate safeguards. We will only disclose your data outside these processors if the law requires us to (for example a valid court order).

Data security

We take appropriate technical and organisational measures to protect your personal data:

  • all traffic to and from modernsavage.co is encrypted in transit using HTTPS (TLS)
  • data at rest on Supabase is encrypted using AES-256
  • server-side secrets (API keys for email, database credentials) are stored as Vercel encrypted environment variables, not in source code
  • access to the production database is restricted to a small number of admin accounts protected by unique, strong credentials
  • form submissions are rate-limited using a hashed IP to prevent automated abuse
  • a honeypot field and anti-spam checks run on every form submission
  • we minimise the data we collect, for the launch list, just your email (and optionally your name)

No system is 100% secure, but we follow industry-standard practices and will notify affected users and regulators of any data breach in line with UK GDPR and applicable US state law timelines.

International transfers

If you are in the UK or EU, your data may be processed on servers in the US (by Vercel, and sometimes Supabase). Where that happens, we rely on the UK International Data Transfer Agreement or the EU Standard Contractual Clauses, as appropriate, to protect your rights.

Cookies and similar technologies

The site uses one functional cookie (ms_country) to remember the country / currency to show you. It does not track you across other sites. We do not use any advertising cookies. Vercel Web Analytics does not use cookies.

You can block or delete cookies in your browser at any time. Doing so will not break the site, we will just need to re-detect your country on your next visit.

Children

The site is not intended for children under 13 (US) or under 16 (UK/EU). We do not knowingly collect data from anyone below those ages. If you believe a child has given us personal data, email support@modernsavage.co and we will delete it.

Changes to this policy

If we change this policy we will update the date at the top of the page. Material changes will be flagged in the site's announcement bar before they take effect, and, where the changes affect how we use your email, we will email you before they apply.

Contact

Questions about this policy, or want to exercise any of the rights above? Email support@modernsavage.co.