Privacy Policy

Last updated: 1 August 2026

The short version: we collect what we need to run your membership and send you the emails you asked for. We don't sell your data. Your artwork isn't used in marketing without asking you first. You can see, correct or delete what we hold at any time by emailing yay@getmessyart.com. The full detail is below, and there's a plain-English summary too.

1. Who's responsible for your information

Get Messy is run by Caylee Grey and Vanessa Oliver-Lloyd, through two companies.

More Than Zero, LLC A limited liability company registered in Delaware, United States 2810 N Church St STE 89212, Wilmington, DE 19802, USA

Get Messy (Pty) Ltd A private company registered in South Africa Company registration number: 2024/389594/07 Postal address: PostNet Suite 128, Private Bag X 0002, Sunridge Park, Gqeberha, 6008, South Africa

Email for both: yay@getmessyart.com

More Than Zero, LLC is the data controller under the UK and EU GDPR. It's the company you contract with, it takes your payment, and it decides what happens to your information.

Get Messy (Pty) Ltd handles South African operations and processes member information on More Than Zero's behalf from South Africa. Where it does, POPIA applies to that processing and Get Messy (Pty) Ltd is the responsible party for it.

Both companies are bound by this policy. You can exercise every right in section 12 by emailing the address above, and it doesn't matter which company you address it to.

This policy covers getmessyart.com and all its subdomains, including archive.getmessyart.com, our community platform, and our emails.

2. What we collect

What you give us

What When Name Sign-up Email address Sign-up, newsletter, contact form Password (stored encrypted, never visible to us) Sign-up Postal address Only if you give it, for tax records and for sending happy mail Payment details Taken directly by Stripe. We see the last four digits, card type and expiry, never the full number Country, for tax purposes Sign-up Profile information, artwork, comments and forum posts Whenever you post them Anything you write to us Support emails, contact forms

What we generate

  • Dates you joined, paid, logged in, cancelled, paused or resumed

  • Which classes and pages you've viewed

  • Support history

What's collected automatically

  • IP address, browser type, operating system, device type

  • Referring website, pages viewed, links clicked, dates and times

  • Cookie identifiers

What we get from others

  • Stripe tells us whether a payment succeeded or failed

  • Intercom enriches your record with publicly available contact and social information

3. Why we're allowed to process it

Under the GDPR and POPIA we need a lawful basis for each thing we do. Here's ours:

Because we have a contract with you:

  • Creating and running your account, and giving you access to the Service

  • Taking payment and issuing receipts

  • Sending you service emails, meaning receipts, password resets, payment reminders and policy updates

Because the law requires it:

  • Keeping tax and accounting records, and charging the right VAT or sales tax

Because you've consented, and you can withdraw that consent any time:

  • Sending you marketing newsletters

  • Setting cookies that aren't strictly necessary, meaning analytics and advertising

Because we have a legitimate interest:

  • Keeping the site secure, preventing fraud and defending legal claims

  • Understanding how the Website is used so we can improve it. Where that involves cookies, we rely on your consent instead

Where we rely on legitimate interests, we've weighed our interest against your rights. You can object at any time. Email us and we'll stop unless we have compelling grounds not to.

4. What we use it for

  • Creating and running your account, and giving you the Service you paid for

  • Taking payment and keeping proper financial records

  • Sending administrative emails: receipts, confirmations, technical notices, security alerts, policy changes

  • Sending the newsletter, if you've asked for it. Every email has an unsubscribe link

  • Answering your questions and giving you support

  • Improving the Website and working out what to make next

  • Keeping the Website secure and investigating misuse

  • Meeting our legal obligations

We use your postal address only for tax records and for occasionally posting you something nice. Nothing else.

5. Who we share it with

We use these companies to run Get Messy. Each processes your information under our instructions, and each has its own privacy policy.

  • Stripe, for payment processing. Gets your name, email, billing address, country and payment details. Based in the United States and Ireland.

  • Circle.so, which runs the community platform, forums and member area. Gets your name, email, profile and everything you post. Based in the United States.

  • Kit, for newsletter and email delivery. Gets your name, email and engagement data. Based in the United States.

  • Intercom, for support messaging and product analytics. Gets your email, sign-up date, usage data and enriched contact and social data. Based in the United States and Ireland.

  • Google Analytics, for understanding how the Website is used. Gets your IP address, device and browser data, the pages you viewed and a pseudonymous client identifier. Based in the United States.

  • Amazon Associates, for affiliate link tracking. Gets cookie-based referral data. Based in the United States.

We also share information between More Than Zero, LLC and Get Messy (Pty) Ltd, which is how we run the business day to day.

We do not sell your personal information. We don't rent it out or trade it.

We will disclose information where the law requires it, where we need to defend a legal claim, or if the business is sold, merged or restructured. If Get Messy ever changes hands, we'll tell you before your information moves.

6. Where your information goes

Get Messy is a small business run across two continents by people who love art journals, so your information moves around. Here's the honest map.

Your information is stored in the United States. That's where More Than Zero, LLC is, and where most of the services in section 5 keep their servers. It's also accessed from South Africa, by Get Messy (Pty) Ltd and by us.

If you're in the UK or EU, that means your information leaves your country. Transfers to the US rely on Standard Contractual Clauses and, where the provider is certified, the EU-US Data Privacy Framework. Transfers to South Africa rely on Standard Contractual Clauses between our two companies.

Under POPIA, section 72 allows the transfer of personal information out of South Africa where the recipient is bound by rules giving comparable protection, where you've consented, or where the transfer is necessary to perform our contract with you. We rely on contractual safeguards with each provider, and on necessity for our contract with you in the case of Stripe and Circle.so, since we can't deliver the Service without them.

7. How long we keep it

  • Your account details, while you're a member. For as long as your membership is active.

  • Your account details, after you cancel.24 months, so you can come back without starting over. Then deleted or anonymised.

  • Your artwork and forum posts. Until you delete them or ask us to. Closing your account doesn't automatically delete your posts, so tell us if you want them gone.

  • Invoices, payments and tax records.5 years, as tax rules require.

  • Your newsletter subscription. Until you unsubscribe, plus a suppression record so we don't email you again by mistake.

  • Support emails.36 months.

  • Analytics data.14 months in Google Analytics.

  • Backups. Purged on our normal backup cycle, currently every 14 days.

8. How we look after it

We use encrypted connections (HTTPS) across the Website, store passwords hashed rather than in plain text, limit access to what each person needs to do their job, and rely on providers who maintain their own recognised security standards.

No system is perfectly secure and we won't pretend otherwise.

If there's a breach that puts your information at risk, we'll tell you and the relevant regulator as quickly as we can. GDPR requires notification to the supervisory authority within 72 hours. POPIA section 22 requires notification to the Information Regulator and to you as soon as reasonably possible. US state breach notification laws apply too, depending on where you live. We'll tell you what happened, what was affected and what to do about it.

9. Cookies

Cookies are small files stored by your browser. We use:

  • Strictly necessary cookies, to log you in, keep you logged in and keep the Website secure. These don't need your consent

  • Analytics cookies, Google Analytics, to see how the Website is used

  • Advertising cookies, Facebook and Google, for retargeting

  • Affiliate cookies, Amazon Associates, to track referrals

You control the non-essential ones.

You can also block or delete cookies in your browser settings. If you block all of them, parts of the Website won't work.

10. Advertising and affiliates

Retargeting. We sometimes advertise Get Messy through Facebook, Instagram and Google. These platforms use cookies to show you our ads after you've visited the Website. Your personal information isn't used by them for anything other than showing you our offers.

Affiliate links. Some links on the Website are affiliate links, which means we earn a commission if you buy through them. This includes the Amazon Services LLC Associates Program. Clicking one places a cookie so the sale gets attributed to us. We disclose affiliate links wherever they appear, in line with US Federal Trade Commission guidance.

Newsletters. Our emails contain tracking pixels, so we can see whether an email was opened and which links were clicked. That tells us what's useful to you and what isn't. We don't pass that behaviour on to anyone else. You can stop it by unsubscribing, or by turning off image loading in your email app.

11. Anonymous and aggregated data

We sometimes use data that can't identify you, such as "68% of members open our Monday email" or "the most popular class this season was X". We may share that publicly or with partners. It isn't personal information and can't be traced back to you.

12. Your rights

Whoever you are and wherever you live, you can:

  • See what we hold about you

  • Correct anything that's wrong or out of date

  • Delete your information, subject to what we have to keep for tax and legal reasons

  • Object to processing based on legitimate interests

  • Restrict how we use your information while a dispute is being sorted out

  • Take it with you, in a common machine-readable format

  • Withdraw consent at any time, including for marketing, without affecting anything we did before you withdrew it

  • Unsubscribe from marketing emails using the link at the bottom of every one

We give everyone the same rights regardless of where you live, because running two sets of rules for the same community would be daft.

How: email yay@getmessyart.com. We'll respond within 30 days. There's no charge, unless a request is repetitive or excessive, in which case we'll tell you before doing anything.

We may need to verify it's really you before we hand over personal information. We won't discriminate against you for exercising any of these rights. Your membership, price and access stay exactly the same.

If we get it wrong, please come to us first. We'd rather fix it than have you go to a regulator. If you'd still like to escalate:

  • UK: the Information Commissioner's Office, ico.org.uk

  • EU: your national data protection authority

  • South Africa: the Information Regulator, complaints.IR@inforegulator.org.za

  • United States: your state Attorney General

13. Sensitive information

Please don't send us information about your health, race, ethnic origin, political opinions, religious beliefs, sex life, biometrics, criminal record or trade union membership. We don't need any of it and we don't ask for it.

One honest caveat. Get Messy is a journaling community, and journaling gets personal. Members do sometimes write about their mental health, their grief, their families and their faith in posts and in their artwork. If you choose to share something like that, you're consenting to us processing it as part of running the community, and it will be visible to other members of the group you posted it in.

You can delete a post at any time. You can also ask us to remove it for you at yay@getmessyart.com.

Please think before you post. Community spaces are private to members, not to the world, but they aren't confidential in a legal sense and we can't guarantee another member won't screenshot something despite our rules against it.

14. Children

Get Messy is for adults. You need to be 18 or older to hold an account, and we don't knowingly collect information from anyone under 18.

If you're a parent or guardian and you think a child has given us their information, email yay@getmessyart.com and we'll delete it promptly.

15. What happens when you leave

When you cancel:

  • Your access ends at the end of the period you've paid for

  • We keep your account details for 24 months in case you come back, then delete or anonymise them

  • Your posts and artwork stay in the community unless you delete them or ask us to

  • We keep payment and tax records for as long as the law requires

  • You stop getting marketing emails as soon as you unsubscribe

Want everything gone? Email yay@getmessyart.com and ask us to delete your account and your posts. We'll do it within 30 days and confirm when it's done.

16. Changes to this policy

If we change this policy in a way that materially affects you, we'll email everyone with an active membership and update the date at the top. Smaller changes just get the date updated. The current version always lives at this URL.

Contact

Email: yay@getmessyart.com

More Than Zero, LLC (data controller) 2810 N Church St STE 89212 Wilmington, DE 19802 USA

Get Messy (Pty) Ltd PostNet Suite 128, Private Bag X 0002 Sunridge Park, Gqeberha, 6008 South Africa