Privacy policy
This policy explains how Polymorphism Ltd handles personal data in connection with this website.
Who we are
Polymorphism Ltd (“we”, “us”) is the data controller for personal data processed via this site. We are registered in England and Wales (company no. 04658986), at Electric Works, Sheffield, S1 2BJ, United Kingdom. You can contact us at enquiries@poly.io.
What we collect
The pages of this site are static and have no contact forms. We use Cloudflare Web Analytics to understand how the site is used. It is privacy-friendly and cookieless: it does not set cookies, does not track you across other websites, and does not collect or store any personal data — only aggregated, anonymous measurements such as page views, referrers and country.
Our content delivery network keeps server access logs of requests to this site — the page requested, the referring site, the country, the browser’s user-agent string and the response status. We do not record IP addresses in these logs. We use them to understand traffic and diagnose problems, and they are deleted automatically after 90 days.
The only personal data we receive is what you choose to send us — for example, when you email us via the links on our contact or careers pages. That typically includes your name, email address, and anything you include in your message (such as a CV).
The social card API
We run a free API at api.poly.io, used by the social card preview tool and callable directly. It reads the page you ask it about; it does not need to know anything about you, and by default we do not learn anything about you.
Two things are optional and only happen if you choose them. If you send an x-og-contact header or ?contact= value to raise your daily allowance, we store that string — usually an email address — in our request logs, so that we can reach you if your script causes a problem. If we issue you an API key, we store the label and contact address you gave us alongside a one-way hash of the key. We keep both only while you are using the API, and we delete them on request.
To apply a daily limit fairly we count requests per caller. We do that using a salted one-way hash of the network address the request arrived from, not the address itself, and the counter deletes itself after two days. We cannot recover an address from the hash.
The API's own logs record which site you asked us to look at, whether it worked, and the counts above. They are not used for anything except running the service and keeping it within its budget.
How we use it
We use the information you send only to respond to your enquiry or application, to correspond with you about it, or — for the API — to operate your allowance and contact you if something needs attention. Our lawful basis is our legitimate interest in responding to people who contact us, and taking steps at your request prior to entering into a contract.
Sharing and retention
We do not sell your personal data or share it for marketing. Email is handled by our email provider on our behalf. We keep correspondence only as long as needed for the purpose it was sent, after which it is deleted.
Your rights
Under UK data protection law you have rights to access, correct, or delete your personal data, and to object to or restrict our processing of it. To exercise any of these, email enquiries@poly.io. You also have the right to complain to the Information Commissioner’s Office (ico.org.uk).
Changes
We may update this policy from time to time; the current version always appears on this page.