Privacy Policy
Last Updated: September 2026 • Effective Date: September 2026
1. Introduction & Data Controller
DreamCrafts ("we", "us", or "our") is committed to protecting your privacy and personal data in strict compliance with the General Data Protection Regulation (GDPR - Regulation (EU) 2016/679), the California Consumer Privacy Act (CCPA/CPRA), the UK Data Protection Act, and India's Digital Personal Data Protection Act (DPDP).
Data Controller:
DreamCrafts Agency
Sector 62, Noida, Uttar Pradesh 201301, India
Email: info@dreamcrafts.in
2. Personal Data We Collect
We adhere strictly to the principle of Data Minimization. We only collect personal data necessary to provide our digital marketing, engineering, and consulting services:
- Communication & Inquiry Data: Full name, professional email address, company name, project budget range, and message contents submitted via our contact forms or direct email.
- WhatsApp Direct Interactions: Phone number and chat contents when initiating communications via our official WhatsApp business channels.
- Technical & Usage Telemetry: Anonymized/pseudonymized IP addresses, browser user agent, device attributes, and navigation paths collected only upon your explicit cookie consent.
Website Quality and Search Performance
We run automated checks of our public pages to identify technical issues. These checks do not set visitor cookies. When connected, our internal tools also use aggregated Search Console, Analytics and Chrome UX Report metrics to assess search performance and page experience. This does not change your cookie preferences.
When AI prioritization is enabled, OpenRouter receives a limited set of public page paths, technical findings and aggregate performance figures. Our SEO integration does not send raw search queries, visitor identifiers, IP addresses, contact details, enquiry messages or credentials to the model. It requests provider routes with zero data retention and data collection disabled. SEO reports are retained for up to 90 days during normal scheduled operation and are accessible only through our private management tools.
3. Third-Party Service Providers & Data Processors
We partner with vetted, enterprise-grade data processors bound by strict Data Processing Addendums (DPAs) and standard contractual clauses (SCCs):
| Vendor / Service | Purpose | Privacy Guardrail |
|---|---|---|
| Google Analytics 4 (Google LLC) | Aggregated traffic & audience telemetry | Strictly gated by Consent Mode v2 (disabled until consent). IP anonymization active. |
| Microsoft Clarity (Microsoft Corp.) | UX heatmaps & session diagnostics | Gated by consent. All keystrokes and form values are masked by default. |
| LinkedIn Insight Tag (LinkedIn Corp.) | B2B ad campaign attribution & conversion measurement | Gated by consent. Script and tracking pixel load only after user opt-in. |
| Bing Ads UET (Microsoft Corp.) | Search ad conversion tracking | Gated by consent. Pixel and script fire strictly after consent is verified. |
| Microsoft Graph / Office 365 | Secure lead email routing & dispatch | Encrypted in transit via TLS 1.3. Server-to-server OAuth token authentication. |
| Odoo CRM | Customer relationship & pipeline management | Encrypted database storage with role-based access control (RBAC). |
| Cloudflare, Inc. | Global CDN, edge compute, and DDoS mitigation | Strict HTTPS/HSTS enforcement, secure edge TLS termination. |
4. Data Retention Schedules
We do not retain personal data longer than necessary for the fulfillment of the specified purposes:
- Inquiry & Lead Records: Retained for 12 months following initial inquiry, after which unengaged leads are permanently deleted.
- Client Contract & Billing Records: Retained for 7 years in accordance with statutory accounting and tax compliance laws.
- Analytics Telemetry: Retained for up to 14 months within Google Analytics before automated system erasure.
5. Your Data Subject Rights (GDPR, CCPA/CPRA, DPDP)
Under applicable global privacy regulations, you possess comprehensive rights regarding your personal information:
- Right to Access: Request a copy of the personal data we hold about you.
- Right to Rectification: Request correction of inaccurate or incomplete records.
- Right to Erasure ("Right to be Forgotten"): Request permanent deletion of your personal data when no longer needed for legal or contractual fulfillment.
- Right to Data Portability: Receive your data in a structured, machine-readable format (JSON/CSV).
- Right to Restrict or Object to Processing: Object to processing of your personal data for direct marketing or analytics.
- Right to Non-Discrimination: We will never discriminate against you, deny services, or alter pricing for exercising your statutory privacy rights.
To exercise any of these rights, send an email to info@dreamcrafts.in with the subject line "Data Subject Request (DSR)". We respond to verified requests within 30 calendar days at zero cost to you.
6. Cookie Management & Consent Revocation
We do not load non-essential cookies or analytics tracking pixels without your affirmative opt-in consent. You can withdraw or update your cookie consent at any time:
Manage Tracking Preferences
Clear stored consent tokens to display the cookie choice banner again.
7. Data Security Measures
We implement state-of-the-art organizational and technical measures:
- Mandatory HTTPS / TLS 1.3 encryption across all website endpoints.
- Strict Content Security Policy (CSP), X-Content-Type-Options, and HSTS headers.
- Zero hardcoded production secrets in codebase; environment-variable isolation at the Cloudflare edge.
- Granular role-based access control (RBAC) and multi-factor authentication for CRM and communication suites.
8. Contact & Regulatory Inquiries
For questions, concerns, or regulatory communications regarding this Privacy Policy:
DreamCrafts Data Privacy Office
Email: info@dreamcrafts.in
Website: https://dreamcrafts.org