Privacy Policy

Last updated 2026-09-08

We collect very little. There is no account system, no visitor database and no CRM behind this site — the only personal data we hold is what you type into the booking form or the newsletter field, plus what our hosting and anti-spam providers see in the course of serving you a page.

Who we are

We Are Rune AB (organisation number 559348-5476), Grev Magnigatan 19 A, 114 55 Stockholm, is the controller of the personal data described here. We have not appointed a data protection officer; at our size we are not required to. For anything in this policy, write to privacy@wearerune.co.

What this policy covers

This policy covers wearerune.co and everything on it. It does not cover the sites we build for clients, which have their own policies, or third-party sites we link to. The editor tool at /studio is internal and used only by our team.

Booking an intro call

This is the only place on the site where we ask you for anything. When you book a call we collect your name, your email address, your company, the topics you select, any notes you write, and the time slot and person you choose.

We use it to schedule and hold the meeting, and to reply to you. The legal basis is Article 6(1)(b) — steps taken at your request before entering a contract — and, for the record we keep of the conversation afterwards, Article 6(1)(f), our legitimate interest in remembering who we have spoken to.

Where it goes:

  • Microsoft. A calendar event is created in the Microsoft 365 mailbox of the person you booked. Your name and email are added as an attendee, and your company and notes appear in the body of that event.
  • Resend. Sends your confirmation email, copied to the person you booked with.
  • Cloudflare. Verifies the anti-spam token — see below.

Nothing is written to a database, because there isn't one. We keep the calendar event and the email thread as our record of the meeting until you ask us to delete them — one request to privacy@wearerune.co removes both.

Newsletter

If you subscribe, we store your email address and the fact that you confirmed it. We use double opt-in: nothing is sent to you until you click the link in the confirmation email, which is also how we can demonstrate that you agreed. The legal basis is your consent, Article 6(1)(a). Delivery is handled by Resend.

You can withdraw at any time using the unsubscribe link in any email, or by writing to us. We keep your address until you unsubscribe.

Spam and abuse prevention

The booking form is protected by Cloudflare Turnstile. When it verifies that you are a person rather than a script, your IP address is sent to Cloudflare, along with signals its widget gathers about your browser. We also count submissions per IP address to cap them at five an hour; that counter lives in the server's memory for at most an hour and is never written to storage.

The basis for both is Article 6(1)(f) — keeping the service usable. This is a necessary function, so it runs whether or not you accept cookies.

Hosting and server logs

The site runs on Vercel, which processes every request in order to serve it. Their logs contain your IP address, browser user agent, the page requested and the time. We use them to keep the site running and to investigate errors, under Article 6(1)(f). They are retained for at most a day.

Analytics

Nothing beyond the strictly necessary runs until you say so. Google Analytics is held behind your choice, and the Cookie Policy lists every cookie it sets. You can change your mind at any time — .

One exception, stated plainly: we use Vercel Web Analytics and Speed Insights, which measure page views and loading performance without setting a cookie or storing anything in your browser. Because nothing is read from or written to your device, they do not require consent, and we run them on the basis of legitimate interest under Article 6(1)(f). They see no identifying information about you.

What we don't do

  • There are no user accounts and no login for visitors, so there is nothing to profile you against.
  • We do not sell personal data, and we do not share it with anyone beyond the processors listed below.
  • We make no automated decisions about you in the sense of Article 22.
  • Our fonts are self-hosted and served from this domain, so loading a page here does not contact Google — a common exception on sites that use web fonts.
  • We do not track you across other websites, and we run no advertising pixels.

Who processes data for us

  • Vercel Inc.Website hosting and cookieless traffic measurement. United States, with EU edge regions.
  • Microsoft Ireland Operations LtdMicrosoft 365 calendar and mailbox holding your meeting booking. European Union, with support access from the United States.
  • Resend (Plus Five Five, Inc.)Delivers the booking confirmation and newsletter emails. United States.
  • Cloudflare, Inc.Turnstile bot protection on the booking form — receives your IP address. United States, processed at the nearest edge location.
  • Google LLCGoogle Analytics 4 — only after you allow analytics cookies. United States.

Transfers outside the EU/EEA

Several of the providers above are based in, or transfer data to, countries outside the EEA — principally the United States. Where that happens we rely on the European Commission's Standard Contractual Clauses, or on the provider's certification under the EU–US Data Privacy Framework where it holds one.

Your rights

Under the GDPR you can ask us for a copy of the personal data we hold about you, ask us to correct it, ask us to delete it, ask us to restrict how we use it, ask for it in a portable format, and object to processing we base on legitimate interest. Where we rely on consent, you can withdraw it at any time without affecting what we did before you withdrew it.

Email privacy@wearerune.co and we will respond within one month. If you are not satisfied with how we handle it, you can complain to Integritetsskyddsmyndigheten (IMY), the Swedish supervisory authority.

Children

This site is aimed at businesses and is not directed at children. We do not knowingly collect data from anyone under 13.

Security

Everything is served over TLS. Our Microsoft Graph integration is scoped to the specific mailboxes that can be booked rather than the whole tenant, and all credentials live in the hosting environment rather than in our source code.

Changes to this policy

When we change this policy we update the date at the top. If a change materially affects what we do with cookies, we reset everyone's cookie choice and ask again rather than assuming your old answer still applies.

Contact

We Are Rune AB, Grev Magnigatan 19 A, 114 55 Stockholm. privacy@wearerune.co for privacy matters, or hello@wearerune.co for anything else.