Privacy Policy.
We collect as little as possible. We share none of it. Here’s exactly what that means.
If you trust us with your data, we earn that trust back.
WebBrandify is a one-operator studio run by Rohit Sharma in Jammu, India. This policy explains what data we collect when you visit webbrandify.com, request an audit, book a walkthrough, or engage us for a project.
Plain-English summary: we collect what we need to reply to you, nothing more. We do not sell, rent, or trade your data. We do not use third-party analytics that fingerprint you. We delete what we no longer need.
The data we touch.
- When you submit the lead form or booking: name, email, phone, segment, budget bracket, and any note you add.
- When you run an AI Site Audit: the URL you submit. We do not crawl your site — the audit infers from the URL pattern.
- When you chat with the portfolio bot: the text of your messages within that session. Stored only in your browser.
- Anonymous performance signals: page load time, browser type, country. No fingerprinting, no per-user tracking.
- Cookies / local storage: only for remembering your booking, theme preference, and chat history — on your device, never sent to us.
Why we hold it.
- Reply to you. Email, WhatsApp, or calendar invite for the consultation you requested.
- Send the audit verdict. A one-time email with the requested 60-second audit.
- Improve the studio. Aggregated, anonymous patterns — “how many people booked this month,” not “who.”
What we do NOT do: sell your data, share with marketing networks, retarget you across the web, or train any third-party AI on your conversations.
Sub-processors.
We use a small set of trusted services to operate. Each one sees only the data needed for its job:
- Web3Forms — receives the booking form payload to email it to Rohit. (policy ↗)
- Cal.com — handles calendar bookings if you use the Cal embed. (policy ↗)
- Anthropic Claude — powers the AI Site Audit and chat bot. Messages are sent through Anthropic’s API. (policy ↗)
- Google Fonts — serves the typography. No identifiable user data passes through.
- Hosting — webbrandify.com is hosted on Vercel/Cloudflare with industry-standard logs.
What you can ask for.
Under GDPR, DPDP Act 2023 (India), and basic decency, you have the right to:
- Access — request a copy of everything we have on you.
- Correction — fix anything that’s wrong.
- Deletion — ask us to wipe your record. We will comply within 7 days.
- Portability — get your data in a machine-readable format.
- Objection — opt out of anything you’re uncomfortable with.
Email rohit@webbrandify.com with the subject line “Privacy request” and you’ll hear back within 48 hours.
How long we keep it.
- Audit URLs: deleted after 30 days.
- Lead form submissions: retained for 2 years if we’re in active discussion; deleted otherwise.
- Engaged client data: retained for 7 years (GST / accounting compliance) post-engagement, then deleted.
- Chat bot transcripts: stored only in your browser. Clearing your localStorage removes them entirely.
How we protect it.
All form submissions travel over TLS 1.3. Stored data lives on encrypted-at-rest infrastructure. We use 2FA on every operator account. We do not maintain a plaintext database of contacts — your data only exists in the sub-processor services listed above and in our encrypted email archive.
In the event of a data breach affecting your records, we will notify you within 72 hours, per GDPR Article 33.
The human accountable.
Rohit Sharma · Founder & Data Controller
WebBrandify Studio · Jammu, India
rohit@webbrandify.com · +91 91860 57407
If you’re not satisfied with our response, you may lodge a complaint with the relevant Data Protection Authority — in India, the DPDP Board; in the EU, your local supervisory authority.