ViralMouth
  • Studio
  • Case Studies ▾
    • Magnum Taxis
    • PDX Padel
    • DJS Taxis
    • iRide Taxis
    • All Case Studies
  • Services ▾
    • Social Content
    • Social Management
    • Campaign Creative
    • Websites
      • Web Design Stoke-on-Trent
    • SEO
    • PPC
  • Industries ▾
    • Restaurants
  • Contact
  • Start a Campaign
Legal

Privacy Policy

Last updated: 27 July 2026

Who we are

This Privacy Policy explains how Kontrola Digital Ltd trading as ViralMouth ("we", "us", "our") collects, uses and protects your personal data when you use our website at viralmouth.com. We are a company registered in England and Wales, company number 15658892, with our registered office at 48 Ricardo Street, Stoke-on-Trent, Staffordshire, ST3 4EU, England. We are the data controller for the personal data described below.

You can contact us at hello@viralmouth.com for any questions about this policy or your personal data.

What we collect and why

Contact form

When you submit our contact form, we collect your name, email address, the service area you are interested in, and your message. We use this information to respond to your enquiry and discuss a potential project. Our lawful basis for this processing is legitimate interests under Article 6(1)(f) of the UK GDPR (responding to business enquiries) and, where relevant, steps prior to entering a contract under Article 6(1)(b).

Your message is delivered to our inbox via our hosting provider. We do not pass your contact form data to any third party for their own purposes.

Content Shoot enquiry form

When you submit our Content Shoot enquiry form at /content-shoot/, we collect your name, email address, business name, your website or social profile, and the shoot location (city or region). You may optionally provide your business type, current content activity, a preferred filming window, and a project note describing what you would like the shoot to promote. You must also confirm that you are the business owner, a decision-maker, or otherwise authorised to discuss the project. The form additionally captures the source URL of the page you submitted from and any UTM attribution values (source, medium, campaign, content and term) present in that URL.

We use this information so that a person at ViralMouth can review the suitability of your business for the Content Shoot, assess the shoot location and practical travel, consider availability, and reply to your enquiry. A human reviews every Content Shoot enquiry; we do not make any automated eligibility or acceptance decision. Our lawful basis for this processing is legitimate interests under Article 6(1)(f) of the UK GDPR (responding to business enquiries) and, where relevant, steps prior to entering a contract under Article 6(1)(b).

Your enquiry is delivered to our inbox via our hosting provider. The source URL and UTM attribution values are included in our internal enquiry email for review purposes only and are not shared with any third party for their own purposes.

Payments

When you book a Content Shoot online, your payment is handled by Stripe on Stripe-hosted checkout pages. Your card details are entered directly into Stripe's secure system and never pass through or are stored on ViralMouth servers.

After checkout, Stripe shares with ViralMouth the information you entered: your name, email address, business name, filming location and website or social page, along with the amount paid and payment status. We use this only to review your booking, deliver the shoot and edits, and handle any refund.

Stripe processes your payment data as an independent controller and processor. You can read Stripe's privacy policy at stripe.com/gb/privacy.

If your booking cannot go ahead or you are due a refund, the money is returned to the original card or payment method used at checkout.

Analytics (Rybbit)

We use Rybbit, a privacy-focused analytics tool that we self-host at rybbit.kontroladigital.com, to understand how visitors use this website. Our implementation stores and accesses nothing on your device: it injects no external script, sets no tracking cookie and assigns no user identifier. It therefore runs by default under our legitimate interests under Article 6(1)(f) of the UK GDPR in measuring aggregate site usage, and you can switch it off at any time, which stops it immediately. Analytics and marketing are independent choices: one does not affect the other. The data controller for analytics data remains Kontrola Digital Ltd; no analytics data is passed to a third-party analytics provider.

While analytics is active, our local wrapper sends a single pageview for the page you are on and then records only named, non-PII interactions. These include clicks on major call-to-action buttons, service links and email links, outbound link clicks (the destination domain only — never the full URL or query string), the contact form lifecycle (started, submitted, succeeded or errored), the service selected in the contact form, the Content Shoot call-to-action click and form lifecycle (started, submitted, succeeded or errored), the Content Shoot purchase confirmation, and scroll-depth milestones. The wrapper also captures the page title, the origin of the referring page (scheme and hostname only — never the full referrer URL or query string), your screen dimensions and browser language, together with the network and user-agent information that the server necessarily receives as part of every request.

We do not send Rybbit your name, email address, contact-form message, full page URLs, URL query strings, or any other field value from the contact form apart from the selected service. For the Content Shoot form and call-to-action, the event properties we send are limited to the placement of the interaction and, only when an error occurs, a low-cardinality error reason (validation, api or network). For the Content Shoot purchase confirmation, the properties are the amount paid and currency and whether the optional add-on was included — never your card details, your name or email, or the Stripe checkout reference. We never send your business name, website or social profile, shoot location, business type, current content activity, preferred filming window, project note, UTM attribution values or any other free text. This implementation disables session replay, automatic error tracking, single-page-application route tracking, automatic outbound tracking and query-string collection, and it does not assign a user identifier. Events are never queued or stored for later: if analytics is off when something happens, that event is simply not sent. One narrow exception exists: the Content Shoot purchase confirmation is reported while that page is open and analytics is active, including if you re-enable analytics from Cookie Settings while the confirmation page is still open.

In this configuration Rybbit sets no tracking cookie and no persistent user identifier in your browser. Your analytics choice, once you make one, is recorded only in the strictly necessary vm_consent cookie (see below).

Refusing or withdrawing analytics stops Rybbit from receiving any further events from your browser. You can change or withdraw your analytics choice at any time using the Cookie Settings link in our footer or on our Cookie Policy page.

Marketing (Meta and Google Ads)

Separately from analytics, we use the Meta Pixel, Meta Conversions API, Google Tag Manager and Google Ads to measure the effectiveness of our advertising. Marketing cookies and enquiry or purchase conversion events run only when you grant marketing consent under Article 6(1)(a) of the UK GDPR, independently of your analytics choice.

Cloudflare supplies the first-party Google Tag Gateway bootstrap across our site. Private report pages set every Google consent purpose to denied before it loads. The Gateway container loads there under denied consent, but no Google page-view or conversion measurement events are initiated. On public pages, Google Tag Manager and the Google tag run under Google Consent Mode v2, which first applies any valid choice already saved on your device. If there is no valid saved choice, advertising storage, advertising user data and advertising personalisation are set to denied. Before marketing consent, Google may receive cookieless pings carrying the page address, denied consent state and the network and browser information necessarily sent with a web request, such as your IP address and user agent. These pings cannot read or write Google advertising cookies, are marked as non-personalised and do not contain a Content Shoot enquiry or purchase conversion. For this limited pre-consent processing we rely on our legitimate interests under Article 6(1)(f) in operating consent-aware, aggregate advertising measurement without accessing advertising storage on your device.

When you grant marketing consent, the Meta Pixel places two cookies in your browser:

  • _fbp — a browser identifier for ad measurement (90 days).
  • _fbc — stores the Meta ad click identifier (90 days).

The Pixel also sends your page URL, IP address and user agent to Meta. When you submit our contact form or our Content Shoot enquiry form with marketing consent granted, we additionally send a Lead event via the Meta Conversions API. For both forms this event contains your email and name in SHA-256-hashed form alongside the same identifiers (IP address, user agent, page URL). For Content Shoot enquiries, the business name, website or social profile, shoot location, business type, current content activity, preferred filming window and project note are not included in the Lead event.

When you complete a Content Shoot booking with marketing consent granted, we also send a Purchase event. It is sent from the browser Pixel and, when your marketing consent was already recorded when the confirmation page loaded, also via the Meta Conversions API; when both are sent, a one-way hashed booking reference deduplicates them. This event contains the amount paid and currency together with your IP address, user agent and the Meta cookie identifiers (_fbp/_fbc) where present — online identifiers that are personal data. It does not contain your name, email address, card details or the Stripe checkout reference. Analytics and marketing remain independent choices: the purchase confirmation is reported to Rybbit unless you have refused analytics, and to Meta and Google Ads only with marketing consent.

The recipient of this data is Meta Platforms Ireland Ltd. Your data may be transferred onward to Meta Platforms, Inc. in the United States, safeguarded under the UK Extension to the EU-US Data Privacy Framework. You can read Meta's privacy policy at facebook.com/privacy/policy.

When you grant marketing consent, the Google tag and Conversion Linker may set _gcl_au and, when you arrive through a Google advert, _gcl_aw, each for up to 90 days. Google Ads receives page and advertising measurement data. A successful Content Shoot enquiry sends a randomly generated event identifier but no form field. A confirmed Content Shoot purchase sends the amount, currency and a one-way event identifier for deduplication. It does not send your name, email, card details or Stripe checkout reference, and checkout query parameters are removed before Google Tag Manager loads.

The recipient of this data is Google Ireland Ltd. Google may process data outside the United Kingdom using the safeguards described in its privacy policy, available at policies.google.com/privacy.

You can withdraw your marketing consent at any time using the Cookie Settings link in our footer or on our Cookie Policy page. Withdrawal stops future Meta and Google Ads conversion events, returns Google Consent Mode to denied and deletes Meta and Google advertising cookies from this site.

Private client reports

Some client reports are protected by a password. When you log in to view a report, we set a strictly necessary session cookie called vm_report_auth that authenticates your access for that session. This cookie lasts 7 days and is only set when logging into a report under /reports/. It is not used for tracking or measurement.

Hosting and security

Our website is served and protected by Cloudflare, Inc., our hosting and security provider. Cloudflare processes IP addresses and request logs for site security and delivery purposes. When Cloudflare's bot protection is active it may set a strictly necessary cookie called __cf_bm (approximately 30 minutes).

Both ordinary contact enquiries and Content Shoot enquiries are transmitted through our hosting and email systems and handled by ViralMouth staff with appropriate technical and organisational access controls. Access to enquiry data is limited to authorised members of Kontrola Digital Ltd who need it to review and respond to your enquiry.

Fonts

Our pages load typefaces from Google Fonts, provided by Google Ireland Ltd. When fonts are fetched, Google receives your IP address. Google states that font requests do not set cookies in your browser.

How long we keep your data

  • Contact enquiries — kept for as long as needed to handle your enquiry and for business records.
  • Content Shoot enquiries — kept for as long as needed to review your suitability, assess location and travel, arrange the shoot and for business records.
  • Consent choices — your analytics and marketing preferences are stored together in the vm_consent cookie for 180 days.
  • Rybbit analytics — this implementation sets no Rybbit cookie in your browser; server-side analytics records are held by Kontrola Digital Ltd as controller.
  • Report sessions — the vm_report_auth cookie lasts 7 days.
  • Meta-side data — retention is governed by Meta's Data Policy once data is shared with Meta.
  • Google-side data — retention is governed by Google's Privacy Policy once data is shared with Google.

Your rights

Under the UK GDPR you have the following rights over your personal data:

  • Right of access to your personal data.
  • Right to rectification of inaccurate data.
  • Right to erasure ("right to be forgotten").
  • Right to restriction of processing.
  • Right to data portability.
  • Right to object to processing.
  • Right to withdraw consent at any time.

To exercise any of these rights, email us at hello@viralmouth.com. We will respond within one month. If you are not satisfied with our response, you have the right to complain to the Information Commissioner's Office at ico.org.uk.

Third-party links

Our website may contain links to third-party sites we do not control. This policy applies only to viralmouth.com. We are not responsible for the privacy practices of external sites.

Changes to this policy

We may update this Privacy Policy from time to time. Any changes will be published on this page with a revised "Last updated" date.

Related documents

See also our Cookie Policy and our Terms of Use.

ViralMouth

Social-first creative, websites and growth systems built to make brands impossible to ignore.

Services
Social ContentSocial ManagementCampaign CreativeWebsitesSEOPPC
Industries
Restaurants
Locations
Web Design Stoke-on-Trent
Studio
StudioCase StudiesServicesIndustriesContact
START
THE NOISE.
START A CAMPAIGN
© 2026 VIRALMOUTH. WORD OF MOUTH. TURBOCHARGED.
Privacy Policy | Terms of Service | Cookies |

COOKIES & TRACKING

We use strictly necessary cookies to run this site. Privacy-first analytics (Rybbit) also runs by default: it records page views and named on-site actions without cookies or user IDs, and you can switch it off in settings. With your consent, we use Meta and Google Ads tools to measure advertising performance. See our Cookie Policy.

COOKIE PREFERENCES

Manage how ViralMouth uses cookies on this device. You can change these at any time. See our Cookie Policy.

STRICTLY NECESSARY Required for the site to function. Includes vm_consent (stores your cookie choice) and vm_report_auth (password-protected report access). Cannot be disabled.
ANALYTICS — RYBBIT Lets us count page views and record named on-site actions (button clicks, form interactions, scroll depth). No cookies, no session replay, no user IDs, no automatic error collection, no query-string tracking. On by default because it stores nothing on your device; switch off to opt out.
MARKETING — META & GOOGLE ADS Measures advertising results with the Meta Pixel, Meta Conversions API and Google Ads conversion tracking. May set _fbp, _fbc and _gcl_* cookies and share online identifiers, page details and conversion data with Meta and Google. Off by default.