Shyine Back to the desk

Privacy Policy

SHYINE, PLLC
983 S 1000 E, Salt Lake City - 84105-1442, United States (US)
On this page
  • Introduction
  • Scope of this policy
  • Information about the studio
  • Data we collect
  • Privacy for children
  • How data is collected
  • Lawful bases for processing
  • How we use your data
  • When we might share data
  • Cookies and local storage
  • Data security measures
  • Data retention
  • International transfers
  • Your data protection rights
  • Opt outs and do not track
  • Links to other sites
  • Changes to this policy
  • Contact and feedback
  • Notice summary for users
A plain start to a careful document

The services described on this website are developed and operated by the developer Shyine on behalf of SHYINE, PLLC, a professional limited liability company organised under the laws of the United States, with its registered address at 983 S 1000 E, Salt Lake City - 84105-1442. Shyine builds wireframe systems, interactive prototypes, usability tests, design systems and accessibility reviews for our clients. This privacy policy is written to describe, in honest and plain language, what personal data the studio may receive, why the studio may receive it, and how we protect it. Reading this document should take only a few minutes, and the studio will always keep a copy of the latest version available on this page.

Introduction

Basis of this notice

SHYINE, PLLC respects the privacy of every person who visits our website, sends the studio a message, or works with us on a design and prototype project. We understand that personal information is a responsibility rather than an asset, and we hold ourselves to a practical standard that many organisations quote but few follow. This policy explains what information we gather, the limited reasons we gather it, how long we keep it, and the control you hold over your own data at every step.

The developer Shyine operates the site that presents these services, and SHYINE, PLLC remains the organisation responsible for the lawful handling of any personal data that flows through the studio. When this policy uses the terms the studio, we or our, it refers to SHYINE, PLLC and its cooperating developer, Shyine. When it uses the terms you or your, it refers to any visitor, prospective client, current client, participant or collaborator whose data may come into our care.

Back to top

Scope of this policy

This policy applies whenever you interact with the studio website at shyine.lol, send us an email, telephone the studio, complete the contact form, attend a discovery call, take part in a usability test session, or receive a file prepared on the desk. It also applies to the personal data that client organisations may share with us in the course of drawing wireframes and prototypes for their own products, because that data is never yours alone and your own rights remain intact regardless of who requested the work.

We want to be clear about one boundary from the outset. Where we build an interactive prototype for a client, that prototype belongs to the client. Any personal data a client collects through the eventual live version of that product is processed under the client privacy policy, not under this one. This policy governs the data we collect about you through our own site and studio, and the limited data we touch while a project is on the desk.

Back to top

Information about the studio

SHYINE, PLLC is active within the Computer Systems Design and Related Services industry and within Computer Integrated Systems Design, professional, scientific and technical services carried out in the United States. The registered location of the studio is:

SHYINE, PLLC, 983 S 1000 E, Salt Lake City - 84105-1442, United States (US).

When contact is required for a privacy matter, the studio can always be reached by email at the address shown in the contact section of this policy, or by telephone at the number listed on every page of the site. The studio intends to remain the single accountable point of contact for all questions about your personal data, so you never have to guess which account of your information might be correct.

Back to top

Data we collect

The studio collects only the categories of personal data that are genuinely needed to run the site, to answer enquiries, and to deliver the prototyping services. We keep the list deliberately short and we never set out to harvest information for its own sake. Depending on how you come to us, the categories may include the following.

Information you choose to give us

When you send the contact form, write an email, or leave a voice message, you provide your name, your email address, a subject line, and the text of your message. If the conversation continues, you may voluntarily add a telephone number, a company name, a role, and details about the product you wish to prototype. These details are collected for the direct purpose of answering you and scoping the work.

Automated technical data

Like most websites, the studio server records a small amount of basic technical data while you browse: the general region of the internet address your device uses, the kind of browser and operating system you run, the pages you open on this site, and the approximate time of each visit. This information is used in aggregate to keep the site working, to understand which content helps visitors, and to guard against abuse.

Data from usability and research sessions

If you agree to take part in a research or usability session, we may record observations about how the prototype was used, the answers you gave to task questions, and a set of notes about how easy a task felt. Where a session is recorded, we ask for your separate explicit agreement before any audio or visual recording begins, and you can withdraw that agreement at any moment.

Data related to invoices and accounts

For clients who engage the studio, we hold the business contact information, the billing email, and the delivery details required to issue an invoice and to send project files. Payment itself is normally handled by established payment providers who keep their own privacy records, and the studio never stores full card numbers on its own systems.

Back to top

Privacy for children

The studio website, our services, and our prototypes are intended for use by adults and for business audiences. We do not knowingly collect personal data from children under the age of thirteen, and we do not design the studio experience to attract children. A wireframe or prototype that a client eventually builds may reach children, but that live product is governed by the client privacy notice used when the product goes into service.

If you are a parent or guardian and you believe the studio has come into possession of personal data belonging to a child, please contact us without delay and provide enough detail for us to locate the record. We will delete that information promptly and confirm the deletion to you. We return the same careful treatment to any request made on behalf of a young person whose data might have been entered by accident.

Back to top

How data is collected

Data reaches the studio through a small number of ordinary channels, each one visible to you at the moment it happens. You provide the clearest information directly when you fill in a form or write to us. Technical data is gathered automatically by the web server and recorded in brief log files that describe a visit without building a detailed profile of you. Session notes are created by the studio team during research calls and are grounded in words you actually said.

The studio does not buy lists of contacts, does not scrape public profiles to build a marketing file, and does not ask third parties to enrich a profile of you with information you never offered. Every category of data in our care can be traced to an act you took, a message you sent, or a meeting you attended.

Back to top

Lawful bases for processing

Where the data protection rules of your region require a lawful basis for processing, the studio relies on the most suitable of the following grounds for each activity, and we hold a short note beside each dataset that records the basis we rely on.

  • Consent: where you actively agree to something such as receiving a voice recording or a newsletter, we process that data only after your clear consent and only for the purpose you approved.
  • Contract: where we need your details to respond to a request for services or to carry out a signed engagement, processing is necessary for the performance of that arrangement with you or with your employer.
  • Legitimate interest: where the studio needs basic technical logs to keep the site secure and working, we rely on the legitimate interest of running a stable service, balanced against your reasonable expectations.
  • Legal obligation: where a law or a regulator requires us to keep certain records such as invoices or to answer a lawful request, we process data as that obligation demands.

Where consent is the basis for a specific use, you may withdraw that consent at any time without prejudice, and we will stop the activity as soon as it is practical, keeping in mind that some consent follows a recording you already approved.

Back to top

How we use your data

Every use of your data in the studio serves a purpose you can see clearly. We answer your messages with the contact details you supplied. We book and run discovery and usability meetings with the calendar and dial-in details we arranged. We keep in touch with clients about active projects and about deliverables that are due. We issue invoices and receipts for paid services. We keep the site safe and working using the technical logs, and we improve the reading experience using the aggregate page totals rather than individual records.

We do not sell your personal data, and we do not license it to advertisers. We use email addresses only for the conversation you asked to begin, for operational notices about an active project, and for occasional service news if you have separately agreed to it. Every message we send on an operational matter allows you to reply and to ask us to stop or to reduce the frequency of contact.

Back to top

When we might share data

Sharing of your data is the exception rather than the rule, and it only happens under named and necessary circumstances. We share information with providers who help the studio run, such as the service that hosts the website, the tool that delivers email, the calendar that schedules calls, and the processor that takes card payments. These providers act on our instructions and are bound by our agreement to keep your data confidential and secure.

We share minimal project information with client teams who have a genuine need to receive a prototype, a usability report, or a handoff file, always under the confidentiality terms of the client engagement. If a regulator, a court, or a lawful authority asks for specific records, we consider the request carefully, confirm it is valid, and disclose only the narrowest part that the law requires us to hand over.

Back to top

Cookies and local storage

The studio keeps its use of tracking technology modest. On this website we may store a small number of cookies or make use of local storage for strictly functional reasons, for example to remember a preference you chose or to keep a form from losing your work. Where we rely on a measurement cookie to count visits in aggregate, the tool is configured to minimise identifying detail.

You remain in control. Most browsers let you view, block, or delete the cookies any site stores, and the site continues to work normally if you disable those that are not essential. Deleting a functional cookie may cause a small convenience such as a remembered preference to be lost, but it will not remove any personal data that you sent to us earlier through a form or an email.

Back to top

Data security measures

The studio protects your data with security that matches its value. Access to project materials is limited to the people who need them for an active engagement, and each person works under a duty of confidentiality. Files are kept in password protected accounts with reasonable access controls, and the studio keeps the software it relies on up to date with security corrections as their developers publish them.

We take the practical steps that a small studio can genuinely honour: unique passwords, two factor protection where the provider offers it, careful handling of any transfer of research files, and a habit of asking before we store or forward anything sensitive. No method of storage or transfer on the open internet is ever fully free of risk, and the studio makes that plain rather than promising a guarantee it cannot deliver.

Back to top

Data retention

The studio keeps personal data only as long as there is a reason to keep it, and we delete or anonymise it when the reason runs out. Messages and their replies are kept for as long as the conversation is reasonably likely to continue into a project, and then for a short period thereafter in case a follow up arrives. As soon as you ask us to remove your information, we delete it wherever the change is safe and lawful to make.

Financial records such as invoices are kept for the number of years that tax law requires, because a legal obligation outranks a preference for an empty desk. Research notes are kept until the study is written up, after which identifying detail is stripped unless you separately agreed that a quotation may be kept with your name attached.

Back to top

International transfers

The studio operates from the United States, and the providers it relies on may process data in servers located in more than one country. Where your data is moved across a national border, we choose providers that operate in regions with strong protections or that offer suitable safeguards for lawful transfer, and we note the destination in our internal record alongside each dataset.

Nothing in this policy reduces the rights you have under the rules of the location where you live. Where your region extends specific privacy rights to you, the studio honours them for any data that falls within our care, regardless of where the server that touches your record happens to sit.

Back to top

Your data protection rights

Depending on the region you live in, you may hold a recognised set of rights over your personal data. Where those rights apply to you, the studio responds to each one alongside the detail below.

  • Access: a copy of the personal data the studio holds about you, in a readable form.
  • Correction: a fixing of any record that is inaccurate or no longer current.
  • Erasure: a deletion of your data where no lawful reason for keeping it remains.
  • Restriction: a freeze on further processing while a dispute or a request is being examined.
  • Portability: a structured export of data you supplied, in a common format, where the basis for processing is consent or contract.
  • Objection: a stop to processing that relies on legitimate interests rather than on a direct need for the data.

To exercise any of these rights, use the contact route at the foot of this page. We will ask you to confirm your identity so that the record is not handed to someone who happens to know an email address, and we will reply to your request within the period set by the law of your region, or within thirty days if no period is set where you live.

Back to top

Opt outs and do not track

Some browsers send a do not track signal to the sites they visit. The studio does not use cross device or long term tracking that would give such a signal practical force on this quiet site, so we have no advertising profile to switch off and no behavioural trail to trade away. Because we set no retargeting pixels and sell no contact lists, the usual reason for honouring a do not track banner simply does not arise here.

Should the studio ever introduce analytics that a do not track setting is expected to govern, we would update this policy first and respect the preferences your browser sends. Until that day arrives, the most effective opt out for any future promotional contact is a short message asking us to remove the address from our occasional notes.

Back to top

Links to other sites

This policy page and other studio pages may occasionally refer to or link to websites run by other organisations, such as industry references, regulatory bodies, or the tools we use in a project. Once you follow such a link and leave the studio site, this policy no longer governs your visit. We encourage you to read the privacy practice of any site you visit after leaving ours, because the studio has no control over how other organisations treat the data you give them.

Back to top

Changes to this policy

The studio reviews this policy from time to time as services, law and habits evolve. When a meaningful change is made, the revision date at the foot of the page is updated, and the most recent wording becomes the version that applies from the moment it is published on this site. We will not reduce the protection promised by a previous version simply by editing this document without telling you that a change has been made.

If a change is significant enough to affect a live agreement, we will draw it to the attention of active clients by email before it takes effect. For ordinary visitors the posted policy is the single source of truth, and we recommend a brief re-read whenever a long gap has passed since you last reviewed our practice.

Back to top

Contact and feedback

Questions about this policy, about your own data, or about the privacy of a prototype you commissioned can always be directed to the studio. Write to the email address shown on this website, or call the telephone number listed on every page, and the person who answers will route your matter to the right desk without delay. For a written record you can copy that message into the contact form so a confirmation note exists on both sides.

Back to top

Notice summary for users

If you would rather hold one summary in mind than the full detail above, the studio practice fits a few plain sentences. We collect only what a conversation requires, we keep it for only as long as it is needed, we protect it with access that matches its value, we share it only with the providers who run the studio and the teams who need the files, and we delete it when you ask and the law allows. Those few sentences are the promise this whole policy exists to keep, and they are the standard we hold every member of the studio team to.

Back to top
SHYINE, PLLC Privacy Policy

983 S 1000 E, Salt Lake City - 84105-1442, United States (US)

direct@shyine.lol  ·  +14128305231 · Revision date October 2026

Return to the SHYINE homepage