Privacy Policy
Last updated: June 23, 2026 · Effective: June 23, 2026
This policy governs how Kraftora collects, uses, and protects your personal information. Please read it carefully before using our services.
Table of Contents
1. Introduction
Welcome to Kraftora ("we", "our", or "us"). We are a premium software engineering company headquartered in Delhi, India, providing custom web development, mobile applications, AI automation, and enterprise digital solutions to clients worldwide.
This Privacy Policy explains how we collect, use, store, share, and protect your personal information when you visit our website (kraftora.in), use our services, or communicate with us. By using our website or engaging our services, you acknowledge and consent to the practices described in this policy.
If you do not agree with any part of this policy, please discontinue use of our website and services and contact us to address your concerns.
2. Information We Collect
We collect information in the following ways:
2.1 Information You Provide Directly
- Contact & Identity: Full name, business email address, phone number, company name, and designation — collected when you submit our contact or inquiry form.
- Project Details: Business requirements, project briefs, technical specifications, and system architecture details shared during onboarding or discovery calls.
- Payment Information: Billing details such as cardholder name, billing address, and transaction references. We do not store raw card numbers — all payments are processed by PCI-DSS compliant third-party gateways (Razorpay / Stripe).
- Communications: Emails, messages, documents, and attachments you send us during the course of a project or support request.
2.2 Information Collected Automatically
- Device & Browser Data: IP address, browser type and version, operating system, screen resolution, and device type.
- Usage Data: Pages visited, time spent on pages, links clicked, referral URLs, and navigation paths.
- Cookies & Tracking: Session cookies, preference cookies, and analytics cookies. See Section 7 for full details.
2.3 Information from Third Parties
- Analytics providers such as Google Analytics may share aggregated or anonymized data about visitor behavior on our site.
- If you connect via LinkedIn or other OAuth providers, we may receive basic profile data as permitted by your account settings.
3. How We Use Your Information
We use the information we collect for the following legitimate purposes:
- Service Delivery: To scope, develop, deliver, maintain, and support the custom digital solutions you commission from us.
- Communication: To respond to inquiries, send project updates, share deliverables, issue invoices, and provide client support.
- Payments & Billing: To process transactions, generate receipts, and manage financial records in compliance with Indian tax law (GST).
- Legal Compliance: To meet obligations under applicable Indian and international laws, including income tax, GST, and data protection regulations.
- Security & Fraud Prevention: To monitor for unauthorized access, fraudulent activity, or misuse of our systems.
- Improvement & Analytics: To understand how our website is used and to improve performance, design, and content.
- Marketing (with consent): To share news, updates, or promotional materials — only if you have opted in. You may unsubscribe at any time.
We do not sell, rent, or trade your personal information to any third parties for commercial purposes.
4. Data Sharing & Disclosure
We only share your data in the following limited circumstances:
- Service Providers: Trusted third-party vendors who assist in delivering our services — including Supabase (database hosting), Razorpay/Stripe (payment processing), Vercel (web hosting), and Google Analytics (usage analytics). These providers are bound by strict data processing agreements.
- Team Members: Internal engineers and project managers who need access to your project details to fulfill the agreed scope of work, bound by confidentiality agreements.
- Legal Obligations: When required by law, court order, regulatory authority, or to protect the rights, property, or safety of Kraftora, our clients, or the public.
- Business Transfers: In the event of a merger, acquisition, or sale of assets, your information may be transferred to the successor entity, with advance notice provided to you.
All client project data, proprietary business logic, and confidential specifications shared with us are protected under Non-Disclosure Agreements (NDAs) and treated with the highest degree of confidentiality.
5. Data Retention
We retain your personal information only as long as necessary for the purposes stated in this policy:
- Active Clients: Data is retained throughout the duration of the client relationship and for a period of 5 years after project completion for legal and tax compliance purposes.
- Prospective Clients: Inquiry data is retained for up to 12 months if no engagement follows.
- Payment Records: Financial records are retained for a minimum of 7 years in accordance with Indian tax law.
- Marketing Subscribers: Retained until you unsubscribe or request deletion.
After the retention period, data is securely deleted or anonymized.
6. Data Security
We take data security seriously and implement multiple layers of protection:
- All data in transit is encrypted using TLS 1.2 / TLS 1.3 (HTTPS).
- Data at rest is encrypted using AES-256 encryption on our hosting infrastructure.
- Access to client data is limited to authorized personnel only, using role-based access control (RBAC).
- Our development and production environments are separated, with regular security audits.
- Payment data is handled exclusively by PCI-DSS compliant payment processors — Kraftora never stores raw card details.
Despite our best efforts, no method of electronic transmission or storage is 100% secure. If you have reason to believe that your data has been compromised, please contact us immediately at hello@kraftora.in.
8. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- Right to Access: Request a copy of the personal data we hold about you.
- Right to Rectification: Request correction of inaccurate or incomplete data.
- Right to Erasure: Request deletion of your personal data, subject to legal retention obligations.
- Right to Object: Object to processing of your data for marketing purposes.
- Right to Data Portability: Request your data in a structured, machine-readable format.
- Right to Withdraw Consent: Withdraw consent for marketing communications at any time.
To exercise any of these rights, email us at hello@kraftora.in. We will respond within 30 days.
9. Third-Party Links
Our website may contain links to third-party websites (e.g., LinkedIn, GitHub, client case study links). We are not responsible for the privacy practices of those sites and encourage you to review their respective privacy policies before sharing any personal information.
10. Children's Privacy
Our services are intended for businesses and professionals aged 18 and above. We do not knowingly collect personal information from individuals under 18 years of age. If we become aware that a minor has submitted personal data, we will delete it promptly.
11. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make significant changes, we will update the "Last updated" date at the top of this page and notify active clients via email. Your continued use of our website after any changes indicates your acceptance of the updated policy.
12. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy, please reach out to us:
