Feature ReleaseAutomated WhatsApp Lead Captures & AI Bots Are Now Live — Discover Capabilities →
Your Data, Your Rights

Privacy Policy

This policy explains what personal data we collect, why we collect it, how long we keep it, who we share it with, and the rights you can exercise over it at any time.

Effective: August 7, 2026 Version: 1.0

1. WHO WE ARE AND HOW TO REACH US

1.1. Data Fiduciary. UrbanXPixels Creative Studio ("UrbanXPixels", "we", "us", "our"), operating from Delhi, India, is the Data Fiduciary (equivalently, the "Data Controller") responsible for the personal data described in this Policy. We determine the purposes and means of processing that data.

1.2. Scope. This Policy applies to the urbanxpixels.com website, our client portal, our WhatsApp Business API channels, our email correspondence, and every service we deliver — web development, WhatsApp automation, graphic design, and video production (collectively, the "Services").

1.3. Contact for privacy matters. Privacy questions, rights requests, and complaints go to privacy@urbanxpixels.com. We acknowledge every request within 72 hours and substantively respond within 30 calendar days.

1.4. Grievance Officer. In accordance with the Information Technology Act, 2000 and the Digital Personal Data Protection Act, 2023 ("DPDPA"), our Grievance Officer can be reached at grievances@urbanxpixels.com. If you are unsatisfied with our response, you may escalate to the Data Protection Board of India.

1.5. Relationship to the Terms. This Policy forms part of, and should be read alongside, our Terms of Service. Where this Policy and the Terms conflict on a data protection matter, this Policy governs.

2. THE DATA WE COLLECT

We collect only what we need to run the Services. We group it into four categories.

2.1. Data you give us directly.

DataWhen we collect it
Full name, email address, phone numberAccount registration, contact form, quote request
Business name, GSTIN, billing addressInvoicing and GST-compliant tax documentation
Password (stored only as a salted PBKDF2 hash)Account registration
Project briefs, brand assets, copy, images, video footageProject onboarding and delivery
Third-party credentials and API keys you choose to shareOnly when a deliverable requires us to configure your systems
Support tickets, chat transcripts, email correspondenceWhenever you contact us

2.2. Data collected automatically. IP address, browser type and version, device and operating system, referring URL, pages viewed, timestamps, session duration, and approximate city-level location derived from IP. We collect this through first-party server logs and privacy-respecting analytics.

2.3. Data from payment processors. When you pay us, our processors (Razorpay and, for international clients, Stripe) send us the transaction ID, amount, currency, status, payment method type, and the last four digits of the instrument. We never receive or store your full card number, CVV, UPI PIN, or net-banking credentials. Those go directly to the PCI-DSS-certified processor.

2.4. Data processed on behalf of our clients. When we build and operate a WhatsApp automation or a website for a business client, that client's own customers may send us data — names, phone numbers, order details, message content. For that data we act as a Data Processor, not a Controller. We process it strictly on the client's documented instructions. See Section 9.

We do not collect special category data — health, biometric, genetic, religious, caste, sexual orientation, or political affiliation data — and we ask that you do not send it to us. If you do, we will delete it on discovery.

3. WHY WE PROCESS IT, AND ON WHAT LAWFUL BASIS

Under the DPDPA and, where applicable, the GDPR, every processing activity needs a lawful basis. Ours are as follows.

PurposeLawful basis
Creating and maintaining your accountPerformance of a contract
Delivering the Services you purchasedPerformance of a contract
Sending transactional email — OTPs, receipts, project updates, outage noticesPerformance of a contract
Processing payments and issuing GST invoicesLegal obligation; performance of a contract
Retaining financial records for statutory periodsLegal obligation (Income Tax Act, 1961; GST law)
Detecting fraud, abuse, and security incidents; rate limitingLegitimate interest in securing the platform
Product analytics and service improvementLegitimate interest, assessed against your rights
Marketing email and newslettersConsent — withdrawable at any time
Displaying completed work in our portfolioConsent, or contractual right where the SOW grants it
Recording your acceptance of these legal termsLegal obligation; legitimate interest in provable consent

3.1. No automated decision-making. We do not subject you to decisions producing legal or similarly significant effects that are based solely on automated processing, and we do not profile you for that purpose.

3.2. No sale of personal data. We have never sold personal data and we do not intend to. We do not share it with data brokers or advertising networks.

4. HOW LONG WE KEEP IT

We keep personal data only as long as the purpose requires, then delete or irreversibly anonymise it.

CategoryRetention period
Active account dataFor the life of the account, plus 90 days after closure
Invoices, receipts, tax records8 financial years (statutory minimum under Indian tax law)
Project deliverables and source files24 months after final delivery, then archived or purged on request
Server and security logs90 days
OTP and verification codes20 minutes, then invalidated; audit record kept 12 months
Legal acceptance records (Terms and Privacy)7 years after account closure — needed to evidence consent
Marketing consent and unsubscribe recordsUntil withdrawn, plus 3 years to honour the opt-out
Support correspondence36 months

Where a legal hold, live dispute, or regulatory investigation applies, we retain the affected records until it concludes, regardless of the periods above.

5. WHO WE SHARE IT WITH

5.1. Sub-processors. We rely on a small set of vetted vendors. Each is bound by a written data processing agreement and may use your data only to serve us.

Sub-processorFunctionRegion
Turso (libSQL)Primary application databaseIndia (ap-south-1)
Amazon Web ServicesApplication hosting and computeIndia (Mumbai)
VercelEdge delivery of the marketing siteGlobal edge network
Cloudflare R2Object and asset storageGlobal, India-preferred
BrevoTransactional email deliveryEuropean Union
RazorpayPayment processing (India)India
StripePayment processing (international)United States, EU
Meta PlatformsWhatsApp Business Cloud APIGlobal

5.2. Professional advisers. Our accountants, auditors, and lawyers, under professional duties of confidentiality, where a genuine need arises.

5.3. Legal disclosure. We disclose data when compelled by a valid court order, warrant, or binding request from a lawful authority. Unless legally gagged, we notify you first so you can seek protective relief.

5.4. Business transfer. If UrbanXPixels is acquired or merges, personal data may transfer to the successor. We will give you at least 30 days' notice and an opportunity to close your account and request deletion first.

5.5. Cross-border transfers. Some sub-processors operate outside India. Where data leaves India, we rely on Standard Contractual Clauses or an equivalent safeguard, and we transfer only to jurisdictions not restricted by the Central Government under Section 16 of the DPDPA.

6. HOW WE PROTECT IT

6.1. In transit. All traffic is encrypted with TLS 1.2 or higher. HTTP requests are redirected to HTTPS and we send HSTS headers.

6.2. At rest. Databases and object storage are encrypted at rest by the provider.

6.3. Credentials. Passwords are stored as PBKDF2-SHA512 hashes with a unique per-user salt and 10,000 iterations. We never store them reversibly and cannot recover one for you — we can only reset it. Comparison is constant-time to resist timing attacks.

6.4. Access control. Staff access follows least privilege, is tied to named accounts, and is logged. Production database access is restricted to personnel who require it for a specific task.

6.5. Session security. Sessions use signed, HTTP-only, Secure, SameSite cookies. Changing your password or invoking "log out of all devices" revokes every outstanding session immediately.

6.6. Platform hardening. We enforce origin validation on state-changing requests, rate limit sensitive endpoints, verify webhook signatures, and parameterise every database query.

6.7. Breach notification. On becoming aware of a personal data breach we notify the Data Protection Board of India and every affected person without undue delay, describing what happened, what data was involved, what we have done, and what you should do.

No system is perfectly secure. We commit to industry-standard safeguards and prompt, honest disclosure — not to a guarantee that a breach can never occur.

7. YOUR RIGHTS

You may exercise any of the following at no charge by writing to privacy@urbanxpixels.com. We may ask you to verify your identity before acting, to make sure we are not disclosing your data to someone else.

7.1. Access. Obtain confirmation of whether we process your data, a copy of it, and a summary of the processing.

7.2. Correction. Have inaccurate or incomplete data corrected or completed.

7.3. Erasure. Have your data deleted where it is no longer needed and no legal retention duty applies.

7.4. Withdraw consent. Where processing rests on consent, withdraw it at any time. Withdrawal does not affect processing already carried out lawfully.

7.5. Portability. Receive the data you gave us in a structured, commonly used, machine-readable format.

7.6. Object and restrict. Object to processing based on legitimate interest, and ask us to restrict processing while a dispute over accuracy or lawfulness is resolved.

7.7. Nominate. Under Section 14 of the DPDPA, nominate someone to exercise these rights on your behalf in the event of your death or incapacity.

7.8. Complain. Raise a grievance with our Grievance Officer, and escalate to the Data Protection Board of India — or, if you are in the EEA or UK, to your local supervisory authority — if you remain unsatisfied.

7.9. No retaliation. We will never degrade your service or charge you more for exercising a privacy right.

8. COOKIES AND SIMILAR TECHNOLOGIES

8.1. Strictly necessary cookies. These keep you signed in, protect against cross-site request forgery, and remember your consent choices. The Services cannot function without them, so they are set without consent, as the law permits.

8.2. Analytics cookies. Used only with your consent, to understand aggregate usage. You can decline without losing any functionality.

8.3. No third-party advertising cookies. We run no ad-network trackers, no cross-site advertising pixels, and no fingerprinting.

8.4. Managing cookies. Every browser lets you view, block, and delete cookies. Blocking strictly necessary cookies will break sign-in.

8.5. Do Not Track. We honour the Global Privacy Control signal where your browser sends it.

9. WHEN WE ACT AS A PROCESSOR FOR OUR CLIENTS

9.1. Roles. Where we operate a WhatsApp automation, CRM, or website on behalf of a business client, that client is the Data Fiduciary for their end-customers' data and we are the Data Processor.

9.2. Our commitments. We process such data only on the client's documented instructions; we impose confidentiality on everyone we let near it; we apply the safeguards in Section 6; we engage sub-processors only under equivalent written terms; we assist the client in responding to data-principal requests; and on termination we delete or return the data at the client's election.

9.3. End-customer requests. If you are an end-customer of one of our clients and want to exercise a right, contact that business directly — they control the data. Tell us and we will route your request to them promptly.

10. CHILDREN

10.1. The Services are intended for businesses and for individuals aged 18 or over. We do not knowingly collect data from children.

10.2. Consistent with Section 9 of the DPDPA, we do not undertake tracking, behavioural monitoring, or targeted advertising directed at children.

10.3. If you believe a child has given us personal data, write to privacy@urbanxpixels.com and we will delete it promptly.

11. CHANGES TO THIS POLICY

11.1. We may update this Policy as the Services or the law change. The version number and effective date at the top of this page always reflect the current text.

11.2. Material changes. For changes that materially affect your rights or how we use your data, we give at least 14 days' advance notice by email to your registered address and by prominent notice in the product.

11.3. Re-acceptance. Where the law requires fresh consent, we will ask you to accept the new version on your next sign-in, and we will record that acceptance as described in Section 12.

11.4. Prior versions. Superseded versions are archived and available on request from privacy@urbanxpixels.com.

12. RECORDS OF YOUR ACCEPTANCE

12.1. What we record. When you accept our Terms of Service and this Privacy Policy at registration, we store an immutable audit record containing: your account identifier, the exact version of each document you accepted, the UTC timestamp of acceptance, the originating IP address, and the browser user-agent string.

12.2. Why. This is how we evidence that consent was freely given, specific, informed, and unambiguous, as the DPDPA and the GDPR both require. Without it we could not demonstrate compliance to a regulator.

12.3. Retention. Acceptance records are retained for 7 years after account closure. Because they exist to prove a legal event occurred, they survive an erasure request — but they contain no project data, and we will confirm to you exactly what is held.

12.4. Your copy. Write to privacy@urbanxpixels.com at any time for a copy of every acceptance record we hold for you.

13. CONTACT

Entity: UrbanXPixels Creative Studio, Delhi, India

Privacy and data protection: privacy@urbanxpixels.com

Grievance Officer: grievances@urbanxpixels.com

General enquiries: hello@urbanxpixels.com

We acknowledge every privacy request within 72 hours and respond substantively within 30 calendar days. If a request is unusually complex we will tell you why and give a firm date.