Privacy Policy

Last Updated: September 2026 • Effective Date: September 2026

1. Introduction & Data Controller

DreamCrafts ("we", "us", or "our") is committed to protecting your privacy and personal data in strict compliance with the General Data Protection Regulation (GDPR - Regulation (EU) 2016/679), the California Consumer Privacy Act (CCPA/CPRA), the UK Data Protection Act, and India's Digital Personal Data Protection Act (DPDP).

Data Controller:
DreamCrafts Agency
Sector 62, Noida, Uttar Pradesh 201301, India
Email: info@dreamcrafts.in

2. Personal Data We Collect

We adhere strictly to the principle of Data Minimization. We only collect personal data necessary to provide our digital marketing, engineering, and consulting services:

  • Communication & Inquiry Data: Full name, professional email address, company name, project budget range, and message contents submitted via our contact forms or direct email.
  • WhatsApp Direct Interactions: Phone number and chat contents when initiating communications via our official WhatsApp business channels.
  • Technical & Usage Telemetry: Anonymized/pseudonymized IP addresses, browser user agent, device attributes, and navigation paths collected only upon your explicit cookie consent.

Website Quality and Search Performance

We run automated checks of our public pages to identify technical issues. These checks do not set visitor cookies. When connected, our internal tools also use aggregated Search Console, Analytics and Chrome UX Report metrics to assess search performance and page experience. This does not change your cookie preferences.

When AI prioritization is enabled, OpenRouter receives a limited set of public page paths, technical findings and aggregate performance figures. Our SEO integration does not send raw search queries, visitor identifiers, IP addresses, contact details, enquiry messages or credentials to the model. It requests provider routes with zero data retention and data collection disabled. SEO reports are retained for up to 90 days during normal scheduled operation and are accessible only through our private management tools.

3. Third-Party Service Providers & Data Processors

We partner with vetted, enterprise-grade data processors bound by strict Data Processing Addendums (DPAs) and standard contractual clauses (SCCs):

Vendor / ServicePurposePrivacy Guardrail
Google Analytics 4 (Google LLC)Aggregated traffic & audience telemetryStrictly gated by Consent Mode v2 (disabled until consent). IP anonymization active.
Microsoft Clarity (Microsoft Corp.)UX heatmaps & session diagnosticsGated by consent. All keystrokes and form values are masked by default.
LinkedIn Insight Tag (LinkedIn Corp.)B2B ad campaign attribution & conversion measurementGated by consent. Script and tracking pixel load only after user opt-in.
Bing Ads UET (Microsoft Corp.)Search ad conversion trackingGated by consent. Pixel and script fire strictly after consent is verified.
Microsoft Graph / Office 365Secure lead email routing & dispatchEncrypted in transit via TLS 1.3. Server-to-server OAuth token authentication.
Odoo CRMCustomer relationship & pipeline managementEncrypted database storage with role-based access control (RBAC).
Cloudflare, Inc.Global CDN, edge compute, and DDoS mitigationStrict HTTPS/HSTS enforcement, secure edge TLS termination.

4. Data Retention Schedules

We do not retain personal data longer than necessary for the fulfillment of the specified purposes:

  • Inquiry & Lead Records: Retained for 12 months following initial inquiry, after which unengaged leads are permanently deleted.
  • Client Contract & Billing Records: Retained for 7 years in accordance with statutory accounting and tax compliance laws.
  • Analytics Telemetry: Retained for up to 14 months within Google Analytics before automated system erasure.

5. Your Data Subject Rights (GDPR, CCPA/CPRA, DPDP)

Under applicable global privacy regulations, you possess comprehensive rights regarding your personal information:

  • Right to Access: Request a copy of the personal data we hold about you.
  • Right to Rectification: Request correction of inaccurate or incomplete records.
  • Right to Erasure ("Right to be Forgotten"): Request permanent deletion of your personal data when no longer needed for legal or contractual fulfillment.
  • Right to Data Portability: Receive your data in a structured, machine-readable format (JSON/CSV).
  • Right to Restrict or Object to Processing: Object to processing of your personal data for direct marketing or analytics.
  • Right to Non-Discrimination: We will never discriminate against you, deny services, or alter pricing for exercising your statutory privacy rights.

To exercise any of these rights, send an email to info@dreamcrafts.in with the subject line "Data Subject Request (DSR)". We respond to verified requests within 30 calendar days at zero cost to you.

6. Cookie Management & Consent Revocation

We do not load non-essential cookies or analytics tracking pixels without your affirmative opt-in consent. You can withdraw or update your cookie consent at any time:

Manage Tracking Preferences

Clear stored consent tokens to display the cookie choice banner again.

7. Data Security Measures

We implement state-of-the-art organizational and technical measures:

  • Mandatory HTTPS / TLS 1.3 encryption across all website endpoints.
  • Strict Content Security Policy (CSP), X-Content-Type-Options, and HSTS headers.
  • Zero hardcoded production secrets in codebase; environment-variable isolation at the Cloudflare edge.
  • Granular role-based access control (RBAC) and multi-factor authentication for CRM and communication suites.

8. Contact & Regulatory Inquiries

For questions, concerns, or regulatory communications regarding this Privacy Policy:

DreamCrafts Data Privacy Office
Email: info@dreamcrafts.in
Website: https://dreamcrafts.org