Privacy policy
Last updated 26 August 2026
This policy covers this website, and it covers the people we approach directly about our work. It doesn’t cover what happens once we start working together on a diagnostic, which is set out in the agreement we’d sign.
If you’re here because we emailed you out of the blue, the section you want is if we contacted you first.
Who we are
Piston & Plume is a joint venture between two companies, and for data protection purposes they act as joint controllers of the information this page describes:
- Overeasy Ltd, registered in England and Wales, company number 15208422, registered office 4, 57 Hogan Court, Edmund Street, London SE5 7NF.
- Mechanise Ltd, registered in England and Wales, company number 09055114, registered office W8a Knoll Business Centre, 325–327 Old Shoreham Road, Hove BN3 7GS.
Whichever of us you’d rather deal with, one address reaches both: info@pistonandplume.co.uk. Rights requests are handled once, jointly — you don’t need to write to each company separately.
What we collect
If you request a diagnostic
The form asks for three things, and we only get what you type into it:
- Your name
- Your email address
- Whatever you write in the message box
If you ran the scorecard before submitting, your answers and scores are sent with the request — the form tells you so at the point of submission.
If you run the scorecard
Nothing is sent anywhere while you answer. The scorecard runs entirely in your browser. Your answers and the result are held in your own browser’s session storage so they survive a reload, and they are discarded when you close the tab. They only reach us if you go on to submit the request form.
If you never submit the form, we never see that you ran it, what you answered, or what you scored.
If you book a call
The booking page asks for your name, your email address, and an optional note about what you’d like to talk through, alongside the slot you pick. We use these to put the call in the diary and send you the invite. It’s the same legitimate-interests basis as a diagnostic request — you’ve asked us for a call, and we need your details to arrange it.
The call is run on Google Calendar, so those details reach Google to create the event and send the invite, and Google adds the video link. To keep automated abuse off a page that writes to real calendars, the booking page also runs a Cloudflare check that receives your IP address. Both are described under who else handles it.
Automatically
Our host keeps standard server logs of requests to the site, which include IP addresses. We don’t use them to identify anyone; they exist so the site can be operated and debugged.
If we contacted you first
Some of the people we deal with came to us. Others heard from us first, because we thought what we do was relevant to their job and wrote to say so. If that’s you, here’s exactly what we hold and where it came from.
What we hold
Your name, your job title, who you work for, your work email address, and often your LinkedIn profile.
Alongside that, whatever we noted about your organisation’s marketing while working out whether to get in touch — what your website says, what your campaigns look like, that sort of thing. It’s about the company, not about you.
We don’t collect personal email addresses, personal phone numbers, home addresses, or anything about you outside your working life.
Where we got it
All of it is either published or was given to us. In practice that means:
- your employer’s own website
- Companies House
- industry press, public announcements, conference and event listings
- occasionally, someone we both know suggesting we ought to talk
We don’t buy contact lists, and we don’t use tools that scrape or guess email addresses in bulk. Ask us where yours specifically came from and we’ll tell you.
Why we’re allowed to
Legitimate interests again — ours in finding clients, and the ordinary expectation that someone responsible for a company’s marketing may be approached by people who work in it. We’ve written down the reasoning and weighed it against your interests, as the law requires. Ask and we’ll send you that assessment; it isn’t confidential.
We only send marketing email to people at incorporated organisations — limited companies, LLPs and the like. Sole traders and unincorporated partnerships have stronger protection under the rules on electronic marketing, and we don’t email them.
What we do with it
We write to you, once, about something we think is relevant. If you reply, we carry on the conversation. If you don’t, we may follow up once more and then stop.
Your details sit in our CRM, HubSpot, and in our email. Nobody else gets them. We don’t sell them, share them for anyone else’s marketing, or use them to build a profile of you.
Making us stop
Say so, in any form of words, to info@pistonandplume.co.ukor by replying to whatever we sent. You don’t need to give a reason and we won’t ask for one.
We’ll then delete everything except the minimum needed to make sure we don’t contact you again by accident — which is the one thing it would be unhelpful to erase. You can ask us to remove that too, and we will.
How long we keep it
If we never hear back from you, we delete your details 12 months after the last time we tried to make contact.
Cookies and tracking
We use Google Analytics and HubSpot, and only if you accept them. Nothing is loaded and no cookie is set until you say yes on the bar. Say no and neither script is requested at all — they aren’t loaded-but-disabled, they simply don’t run. There are no advertising or social pixels either way.
The full list of what they set, and how to change your mind later, is in the cookie policy.
The one thing stored regardless is the scorecard result described above. It’s session storage rather than a cookie, it’s strictly necessary for the tool you chose to run, it never leaves your device on its own, and it isn’t used to recognise you.
What we do with it
We use your name and email to run the free diagnostic you asked for and to reply to you. If you sent a scorecard result, we read it so we arrive at that conversation already knowing where you think you stand.
We don’t sell your data, and we don’t add you to a marketing list off the back of a diagnostic request.
Our legal basis
For anything you send us through this site, we rely on legitimate interests: you’ve asked us for a piece of work, and we need your details to do it and to reply. If we later want to send you anything you didn’t ask for — a newsletter, say — we’d ask your consent first.
Where we approached you rather than the other way round, the basis is also legitimate interests, and it’s set out at greater length above.
Who else handles it
We keep the list of people touching your data as short as we can:
- Vercel hosts the site and produces the server logs described above.
- Resend delivers the email your request generates. Your name, email address, your message and any scorecard result pass through them to reach our inbox.
- Google receives analytics data about how the site is used — but only from people who accepted analytics. If you rejected it, or haven’t answered, Google gets nothing about your visit.
- HubSpot is our CRM. If you accepted, it records which pages you read and ties that history to your enquiry when you send the form. If you rejected it, or haven’t answered, HubSpot gets nothing about your visit.
- Google (Google Workspace) runs the booking calendar. When you book a call, the name, email address, note and time you enter are used to create a calendar event with a video link, and Google sends the invite. This is separate from the analytics above — it isn’t optional and isn’t about tracking your visit; it’s how a call you asked for gets arranged. The event is held in our own Google Workspace under Google’s data-processing terms.
- Cloudflare runs the anti-bot check on the booking page — the booking form writes to live calendars, so it’s protected against automated abuse. Cloudflare receives your IP address and how you interact with the check, and nothing else, under its own privacy policy. It’s used only to tell people from bots.
They act on our instructions. They may all process data outside the UK, including in the United States, under the safeguards their own terms provide. Nobody else receives your details.
Google Analytics and HubSpot are the only things here that run on consent rather than legitimate interests, which is why they’re the only things you get asked about — and why you can withdraw at any time from the cookie policy without it affecting anything else.
How long we keep it
Diagnostic requests live in our email and in our CRM. We keep them for 12 months from our last contact with you, after which they’re deleted from both. Ask us to delete yours sooner and we will.
A booked call is held as an event in our calendar on the same footing: we keep it for 12 months from our last contact with you and review and delete on that basis. Ask us to remove yours sooner and we will.
The same 12 months applies to people we approached who never replied, as described above.
Your rights
You can ask us for a copy of what we hold about you, ask us to correct it, ask us to delete it, or object to us holding it at all. Write to info@pistonandplume.co.uk and we’ll deal with it within a month.
One of those is absolute rather than a request we weigh up: if you tell us to stop marketing to you, we stop. There’s nothing for us to balance and no reason for you to give.
If we get it wrong, you can complain to the Information Commissioner’s Office at ico.org.uk. We’d rather you raised it with us first so we can fix it.
Changes
If this policy changes, the date at the top changes with it. We won’t quietly start doing something with your data that this page doesn’t describe.