Privacy Policy
Last updated: 2026-05-14
Too Many Hats (“we”, “us”, “our”) is the data controller for personal data collected through toomanyhats.net. This policy explains what we collect, why, and the rights you have under the UK GDPR and EU GDPR.
Information We Collect
When you use our website or engage our consultancy services, we may collect the following information:
- Contact details such as your name, email address, phone number, and company name, provided when you contact us or sign up for our services.
- Usage data including pages visited, time spent on the site, and referring URLs, collected automatically through the analytics tools described below.
- Communications including any messages, feedback, or enquiries you send to us.
We do not collect sensitive personal data unless specifically required to deliver our services, and only with your explicit consent.
How We Use Your Information
We use the information we collect for the following purposes:
- To provide, maintain, and improve our consultancy and SaaS services.
- To respond to your enquiries and communicate with you about your projects.
- To send relevant updates about our services, where you have opted in to receive them.
- To analyse site usage and improve the user experience.
- To comply with legal obligations.
Data Sharing
We do not sell your personal data to third parties. We may share your information in the following circumstances:
- Service providers who assist us in operating our business, such as hosting providers, email services, and analytics platforms. These providers are contractually bound to protect your data.
- Legal requirements where we are obliged to disclose information to comply with applicable law, regulation, or legal process.
- Business transfers in the event of a merger, acquisition, or sale of assets, your data may be transferred as part of that transaction.
Cookies and Analytics
We use two analytics tools on this website:
Self-hosted analytics (always on)
We operate a self-hosted analytics service at analytics.wildsun.net that records aggregated visit data (page URL, referrer, approximate country, device type). This service is hosted by us in the United Kingdom, does not share data with any third party, and runs on the lawful basis of legitimate interest (Article 6(1)(f) UK GDPR / EU GDPR) for understanding aggregate site performance. No advertising profile is built from this data.
Google Analytics 4 (only with your consent)
If you accept the cookie banner, we load Google Analytics 4 (provided by Google Ireland Limited and Google LLC) using the measurement ID G-82E06CLDPM. Google Analytics sets the following cookies:
| Cookie | Purpose | Expiry |
|---|---|---|
_ga |
Distinguishes unique users | 2 years |
_ga_82E06CLDPM |
Persists session state for this property | 2 years |
We have enabled IP anonymisation, disabled Google Signals, and disabled advertising personalisation features. Data is retained in Google Analytics for 14 months before automatic deletion.
Google Analytics may transfer data outside the UK / EEA to the United States. Such transfers are protected by the EU-US Data Privacy Framework and the UK Extension, and by Google’s Standard Contractual Clauses where applicable.
The lawful basis for Google Analytics is your consent (Article 6(1)(a) UK GDPR / EU GDPR), captured through our cookie banner.
Withdrawing or changing your consent
You can withdraw or change your consent at any time by clicking “Cookie settings” in the site footer. Declining clears the Google Analytics cookies from your browser. You can also delete cookies via your browser settings.
Essential storage
We use a single local-storage entry (tmh_consent) to remember your cookie choice. This is strictly necessary to honour your preference and does not require consent.
Data Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. However, no method of transmission over the internet is completely secure, and we cannot guarantee absolute security.
Your Rights
Under the UK GDPR and EU GDPR, you have the following rights regarding your personal data:
- The right to access the personal data we hold about you.
- The right to rectification of inaccurate data.
- The right to erasure (“right to be forgotten”).
- The right to restrict or object to processing.
- The right to data portability.
- The right to withdraw consent at any time, where processing is based on consent.
- The right to lodge a complaint with a supervisory authority. In the UK, this is the Information Commissioner’s Office (ico.org.uk).
To exercise any of these rights, please contact us using the details below.
Contact Us
If you have any questions about this Privacy Policy or how we handle your data, please contact us at:
Too Many Hats 167-169 Great Portland Street, Fifth Floor, London, W1W 5PF, United Kingdom Email: contact@toomanyhats.net Website: toomanyhats.net