⚠️ DRAFT — not legal advice. Replace every [ bracketed ] field and have a lawyer or a compliance tool (Termly, iubenda) review before publishing. Covers DPDP (India), GDPR (EU/UK) & CCPA (California).
Privacy Policy
Last updated: [ date ]
01 Who we are
This Privacy Policy explains how [ Legal company name, e.g. RevoRank Pvt. Ltd. ] ("RevoRank", "we", "us") collects and handles personal data when you use our website and services.
Data controller: [ Registered entity name ], [ registered address, Gurugram, Haryana ]. Contact: [ privacy@revorank.io ].
GDPR note: if you offer services to people in the EU/UK, you may need to appoint an EU/UK representative and name them here. [ EU representative, if required ]
02 Information we collect
You give us directly
- Contact details when you fill a form or book a call — name, email, phone, website URL.
- Information you send in messages, applications, or onboarding.
- Billing details for paid services [ confirm: do you store these or does your payment processor? ].
Collected automatically
- Device and usage data — IP address, browser, pages viewed, referrer — via cookies and analytics.
- [ list real tools: Google Analytics, Meta Pixel, etc. ]
03 How we use your information
- To respond to enquiries, provide quotes, and deliver our services.
- To manage billing, subscriptions, and one-time projects.
- To improve our website and measure marketing performance.
- To send updates you've asked for [ confirm if you do email marketing ].
- To meet legal and accounting obligations.
04 Legal bases for processing (GDPR / UK GDPR)
Where GDPR applies, we rely on: consent (e.g. marketing, non-essential cookies), contract (to deliver services you've engaged us for), legitimate interests (to run and improve our business), and legal obligation (tax, accounting).
Under India's DPDP Act 2023, we process personal data based on your consent or other lawful grounds permitted by the Act.
05 Cookies & tracking
We use cookies and similar technologies for essential site function, analytics, and advertising. The specific tools we use: [ Google Analytics 4, Meta Pixel, etc. ].
Compliance action required: because you use analytics/ad pixels and serve EU/UK visitors, GDPR requires a consent banner that blocks non-essential cookies until the visitor opts in — a written disclosure alone is not enough. Implement a consent tool (e.g. Cookiebot, Termly, Osano) and link your cookie settings here: [ cookie settings link ].
06 Who we share data with
We don't sell your personal data. We share it with service providers who help us operate, under appropriate agreements:
- Payment processing — [ e.g. Razorpay, Stripe ]
- Analytics & advertising — [ e.g. Google, Meta ]
- Email & CRM — [ e.g. your email/CRM tool ]
- Hosting & infrastructure — [ e.g. your host ]
- Where required by law or to protect our rights.
07 International data transfers
As we serve clients in India and globally, your data may be processed outside your country. Where required, we use safeguards such as Standard Contractual Clauses for transfers out of the EU/UK. [ confirm your transfer mechanism ]
08 How long we keep data
We keep personal data only as long as needed for the purposes above, or as required by law (e.g. tax records). Typical periods: [ specify, e.g. enquiry data 24 months; billing records 8 years per Indian law ].
09 Your rights
Depending on where you live, you may have the right to access, correct, delete, or port your data, to object to or restrict processing, and to withdraw consent.
- EU/UK (GDPR): access, rectification, erasure, restriction, portability, objection, and the right to complain to a supervisory authority.
- California (CCPA/CPRA): know, delete, correct, and opt out of "sale"/"sharing"; we will not discriminate for exercising these.
- India (DPDP): access, correction, erasure, grievance redressal, and nomination.
To exercise any right, contact [ privacy@revorank.io ]. India users can reach our Grievance Officer: [ name & contact — required under DPDP ].
10 Security
We use reasonable technical and organisational measures to protect personal data. No method of transmission or storage is completely secure, so we can't guarantee absolute security.
11 Children
Our services are not directed to children under [ 18 — note DPDP treats under-18 as a child ], and we do not knowingly collect their data.
12 Changes & how to contact us
We may update this policy and will revise the "last updated" date above. For any privacy question or request, contact [ privacy@revorank.io ] or write to [ registered address ].