Legal

Privacy Policy

Last updated: 20 June 2026 · Effective: 9 June 2026 · Applies to: endorphynweb.com

Endorphyn™ Web, operated by Shivansh Chawla, India ("we", "us", "our"), is committed to protecting your personal data. This Privacy Policy explains what data we collect, why, how we use it, and your rights over it.

This policy complies with the EU General Data Protection Regulation (GDPR 2016/679), the UK GDPR, the California Consumer Privacy Act (CCPA/CPRA), and India's Digital Personal Data Protection Act 2023 (DPDP Act).

1. Data we collect

1.1 Data you provide directly

  • Name, email address, phone number (when you submit a form)
  • Business name, business type, current website URL
  • Messages, project briefs, and files you send us
  • Payment references (Razorpay transaction IDs and bank transfer references, we never store card numbers)

1.2 Data collected automatically

  • IP address (anonymised before storage via GA4 anonymize_ip)
  • Browser type, OS, device type, screen resolution
  • Pages visited, time on site, scroll depth, referral source
  • UTM parameters (source, medium, campaign, gclid, fbclid)
  • Session recordings and heatmaps via Microsoft Clarity (anonymised, no keystrokes or personal content recorded)

1.3 Cookies

See our Cookie Policy for full details. All non-essential cookies (analytics, marketing) load only after consent is obtained. For visitors from the US, Canada, Australia, and New Zealand, we apply consent automatically as these jurisdictions do not mandate opt-in for analytics cookies. For EU/UK/EEA visitors, we show a consent banner and wait for your explicit acceptance.

2. Why we collect your data (legal basis)

PurposeLegal basis (GDPR)
Respond to enquiries and deliver servicesContract performance / Legitimate interests
Build and deliver the requested mockup or websiteContract performance
Website analytics (GA4, Clarity)Consent
Marketing / retargeting (Meta Pixel)Consent
Invoicing and tax recordsLegal obligation
Fraud prevention and site securityLegitimate interests

3. How we share your data

We do not sell your personal data. We share it only with the following sub-processors:

ProcessorPurposeLocation
Web3FormsForm submission processingUS
Google (GA4 / GTM)Analytics: anonymisedUS (SCCs in place)
Meta PlatformsMarketing pixel / retargetingUS (SCCs in place)
Microsoft ClaritySession analytics: anonymisedUS (SCCs in place)
Zoho CorporationEmail hosting, CRM, invoicingIN / US
CloudflareHosting, CDN, DDoS protection, Turnstile bot protectionUS (SOC 2 certified)
RazorpayPayment processing (reference only, no card data stored by us)IN
WhatsApp (Meta)Customer communication, when a visitor chooses to contact us via WhatsApp instead of the contact formUS

WhatsApp messages are currently handled manually: we have no automated WhatsApp Business API or third-party integration in use, and messages are read and replied to directly.

4. International data transfers

Your data may be transferred to countries outside your own, including the United States and India. Transfers from the EEA / UK are protected by EU Standard Contractual Clauses (SCCs) or UK adequacy decisions where applicable.

5. Data retention

  • Enquiry form submissions: 3 years from submission
  • Client project records: 7 years (tax/legal compliance)
  • Email correspondence: 3 years
  • GA4 analytics data: 26 months
  • Microsoft Clarity sessions: 13 months

6. Your rights

GDPR / UK GDPR (EU / UK residents): Right to access, rectification, erasure, restriction of processing, data portability, and objection to automated processing.

CCPA (California residents): Right to know, delete, opt out of sale (we do not sell data), and non-discrimination.

DPDP Act (India): Right to access, correction, erasure, and grievance redressal. Requests responded to within 30 days.

To exercise any right: email shivansh@endorphynweb.com with subject line "Privacy Request".

7. Grievance Redressal Officer (DPDP Act, India)

Name: Shivansh Chawla · Email: shivansh@endorphynweb.com · Response time: Within 30 days.

8. Security

We implement HTTPS/TLS on all pages, restricted data access, regular security reviews, and SOC 2-certified hosting infrastructure. No method of internet transmission is 100% secure, but we take all commercially reasonable measures to protect your data.

9. Children

Our website is not directed at anyone under 18. We do not knowingly collect data from minors. If you believe we have, contact us and we will delete it promptly.

10. Changes to this policy

Material changes will be flagged with an updated date at the top of this page. For significant changes, active clients will be notified by email.

11. Marketing communications

If you submitted your email address via our website contact form, tools site, or consultation booking, and provided explicit consent, we may send you occasional emails about web design resources, service updates, and relevant tools. Every marketing email includes an unsubscribe link. You can also email shivansh@endorphynweb.com to be removed at any time. We never sell or rent your email address to third parties.

12. Bank detail security notice

Endorphyn™ Web will never ask for payment via bank transfer details published on a public webpage. Bank transfer details, where applicable, are shared exclusively through private email or Zoho Invoice. If you receive a payment request claiming to be from Endorphyn™ Web that you did not initiate, do not pay and contact us immediately at shivansh@endorphynweb.com.

13. Contact

shivansh@endorphynweb.com, we aim to respond within 2 business days.