Privacy Policy

1. Who We Are

This Privacy Policy explains how DELTRIG handles personal data in connection with https://deltrig.com and every product, licence and service we provide through it (the “Service”).

DELTRIG is a sole proprietorship owned and operated by Rahul Chouhan, of Dakra, Khalari, Ranchi, Jharkhand, India – 829210. For the purposes of the Digital Personal Data Protection Act, 2023 (India) we are the Data Fiduciary; where the EU or UK General Data Protection Regulation applies to a given processing activity, we are the controller.

This Policy forms part of, and must be read together with, our Terms of Service and Cookie Policy.

For all privacy matters, write to [email protected].

2. Our Approach, Stated Plainly

We are a small business selling software to people who build things. We have no advertising model and nothing to gain from knowing more about you than the transaction requires. So:

  • We do not sell personal data. Not to anyone, in any form, for any price.
  • We do not build advertising or behavioural profiles, and we do not carry out profiling that produces a legal or significant effect on you.
  • We never see your payment credentials. Clause 6 explains what happens instead.
  • We store hashes, not values, where a hash will do — your licence key, the domains your licences activate on, and the IP addresses in our abuse logs are all stored as hashes rather than in the clear.
  • We do not use automated decision-making to decide a refund, a suspension, or a licence dispute. Those are decided by a person.

3. What We Collect

3.1 Information you give us.

  • Account: name, email address, password (stored only as a salted hash, never in a readable form), and optionally an avatar and locale or currency preference.
  • Billing: billing name, email, telephone number, address, country, and a tax identifier where you supply one for invoicing. Collected for invoicing and tax, not for delivery.
  • Orders: what you bought, when, the amount, the currency, and the payment reference.
  • Support: the content of support tickets, messages, enquiry forms and any file you attach.
  • Reviews: where enabled, your rating, review text and the display name shown with it.
  • Enquiries about bespoke work: what you tell us about your project, your budget range and your timeline.

3.2 Information we generate.

  • Licences: a hash of your licence key, a derived verification value, the licence tier, the installation count, the status, and the expiry date. Never the key itself.
  • Licence activations: a hash of each domain the licence is activated on, a hash of the activating IP address, the Product version reported, a label if you set one, and activation and last-seen timestamps.
  • Downloads: which entitlement was used, when, and how many times.
  • Security and abuse logs: hashed IP address, request path, timestamp, and the outcome of authentication, rate-limit and licence-verification checks.

3.3 Information collected automatically. Cookies and similar technologies as described in our Cookie Policy; approximate location derived from IP at country level for currency and tax purposes; browser, device and referrer information; and campaign parameters carried in a marketing link.

3.4 What we do not collect. We do not collect your full card number, card verification value, UPI credentials, netbanking password or one-time codes — see Clause 6. We do not collect your site content, your database, your files, your traffic logs or your own customers' data — see Clause 5. We do not knowingly collect data from children. We do not seek sensitive category data (health, biometrics, religious or political belief, sexual orientation, trade-union membership) and ask that you do not send it in a support ticket.

4. Why We Process It, and On What Basis

PurposeData usedBasis (GDPR)Basis (DPDP Act)
Fulfil your Order, deliver downloads, issue licencesAccount, billing, order, licencePerformance of a contractConsent / legitimate use for the specified purpose
Verify a licence and authorise updatesDerived licence value, hashed domain, version, timestampPerformance of a contractAs above
Provide supportAccount, order, ticket contentPerformance of a contractAs above
Prevent fraud, abuse and licence circumventionHashed IP, security and violation logs, order dataLegitimate interestsLegitimate use
Invoicing, accounting and taxBilling, order, payment referenceLegal obligationCompliance with law
Operate and secure the ServiceTechnical and log dataLegitimate interestsLegitimate use
Improve the ServiceAggregated usage and error dataLegitimate interests / consent for non-essential cookiesConsent where required
Marketing emailEmail address, nameConsent, withdrawable at any timeConsent
Enforce our terms, handle disputesWhatever is relevant to the matterLegitimate interests / legal claimsLegitimate use

Where we rely on legitimate interests, we have considered whether that interest is outweighed by your rights, and we will explain our assessment on request. Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of what was already done.

5. What the Licence Check Actually Sends

Because this is the question people most reasonably worry about when installing licensed software on their own server, we will answer it precisely rather than generally.

A licensed installation contacts us to activate, to confirm it remains entitled, and to check for updates. Each request carries:

  • a derived value computed from your licence key, which lets us recognise the licence without the key itself ever crossing the network;
  • the domain or installation identifier, which we store as a hash;
  • the Product version installed;
  • a timestamp and a single-use value, which exist to stop a captured request being replayed; and
  • a signature over the above.

It does not and cannot send: your site's content, pages, posts or media; your database or any part of it; your files; your visitor or customer data; your traffic or analytics; your credentials for anything; your server's environment variables; or your own users' personal data. The mechanism has no access to any of that, and adding such access would require a different piece of software than the one we ship.

We log failed verification attempts — a signature that does not match, a replayed request, a licence used from an unregistered installation — because that is how key sharing and circumvention become visible. Those logs contain hashed values, not plain domains or addresses.

If our verification service is unreachable, your installation keeps working. Clause 14 of the Licence Agreement confirms this.

6. Payments

Payments are processed by a third-party payment partner, on its own secure page, window or hosted form.

We do not receive, process, transmit or store your full card number, card verification value, UPI credentials, netbanking password, one-time passcode or any other payment secret. Those exist only inside the payment partner's regulated environment.

What we receive and keep is: a payment reference, the amount, the currency, the method family (for example “card”), the result, and the last four digits of a card where the partner supplies them. That is what allows us to match a payment to an Order and to refund you.

Our payment partner is an independent controller of the data it collects from you, under its own privacy policy, which we encourage you to read at the point of payment. Where the partner acts as merchant of record for your purchase, it is the seller for payment, invoicing and tax purposes, and it processes your billing and tax data in that capacity rather than as our processor. This does not change who supplies or supports the Product, which is DELTRIG in every case.

7. Who We Share It With

We share personal data only where necessary, and only with the following categories:

  • Payment partner — to take payment and issue refunds. See Clause 6.
  • Hosting and infrastructure providers — who store the data on our behalf under contract.
  • Email delivery provider — to send Order confirmations, licence keys, password resets and, where you have consented, marketing.
  • Content delivery and storage providers — to serve files and site assets.
  • Abuse prevention provider — to distinguish automated abuse from real people on our forms.
  • Analytics and error monitoring providers — where enabled, to understand usage in aggregate and to diagnose faults.
  • Professional advisers — accountants and lawyers, where genuinely required.
  • Authorities — where compelled by valid legal process, or where necessary to establish, exercise or defend a legal claim.
  • A successor — where the business or its assets are sold or reorganised, on notice to you.

Each provider acts as our processor on documented instructions, is bound to confidentiality and appropriate security, and may not use the data for its own purposes — other than the payment partner, and any provider acting as an independent controller, in which case its own policy governs.

We do not sell personal data, and we do not share it for cross-context behavioural advertising.

8. International Transfers

We operate from India, and some of our providers operate outside India. Your personal data may therefore be transferred to, stored in, or accessed from a country other than your own.

Where we transfer personal data internationally, we do so under an appropriate safeguard: a decision recognising the destination as adequate, standard contractual clauses, or another mechanism the applicable law permits. Transfers from India are made in accordance with the Digital Personal Data Protection Act, 2023 and any restriction the Central Government notifies under it.

You may request details of the safeguard applicable to a particular transfer from [email protected].

9. How Long We Keep It

CategoryRetentionWhy
Account and profileWhile the Account exists, then deleted or anonymisedTo provide the Account
Orders, invoices, payment references8 years from the end of the relevant financial yearIndian tax and accounting law
Licences and activation recordsWhile the licence is live, then 2 yearsSupport, entitlement disputes, licence enforcement
Download records2 yearsEntitlement and abuse investigation
Support tickets and messages3 years from closureRecurring issues, warranty and dispute history
Security, abuse and licence-violation logs12 months, or longer where an investigation is openFraud and circumvention prevention
Marketing consent and preferencesUntil withdrawn, plus a suppression record kept indefinitelyTo prove consent, and to honour an unsubscribe permanently
ReviewsWhile published; pseudonymised on Account deletionIntegrity of the review record

A suppression record is deliberately permanent and deliberately minimal: it holds your email address and the fact that you unsubscribed, because the only way to guarantee we never email you again is to remember that you asked us not to.

10. Your Rights

Subject to the applicable law, you may:

  • Access the personal data we hold about you, and receive a copy.
  • Correct data that is inaccurate, and complete data that is incomplete.
  • Erase your data, where we have no overriding legal obligation or legitimate ground to retain it.
  • Withdraw consent at any time where processing rests on consent.
  • Object to processing based on legitimate interests, and to direct marketing at any time and without reason.
  • Restrict processing while a dispute about accuracy or lawfulness is resolved.
  • Portability — receive the data you gave us in a structured, machine-readable format, and have it transmitted to another controller where technically feasible.
  • Nominate another person to exercise your rights on your behalf in the event of death or incapacity, as the DPDP Act provides.
  • Complain to a supervisory authority — in India, the Data Protection Board of India; in the EU or UK, your local data protection authority.

How to exercise a right. Email [email protected] from the address on your Account, saying which right you are exercising. We will respond within 30 days. Where a request is complex we may extend that once and will tell you why.

Verification. We may need to confirm your identity before acting, particularly for access or erasure. This protects you: acting on an unverified erasure request would let anybody delete your purchase history.

No charge, and no penalty. We do not charge for a request, and exercising a right will never affect the service you receive. We may charge a reasonable fee for a manifestly unfounded or excessive repeat request, and will say so before doing so.

11. Deleting Your Account

Email [email protected] from the address on the Account.

Two things to know first, and they matter:

  • You lose access to everything you have bought. Downloads, licences and update entitlements go with the Account. Save your files before you ask. We cannot restore a deleted Account's entitlements.
  • Some records survive deletion. Order, invoice and payment records are retained for the period in Clause 9 because tax and accounting law requires it. Those are reduced to what the obligation requires and are not used for anything else.

On deletion we remove or anonymise your profile, preferences, support history and marketing record, and pseudonymise any review you have published so it remains part of the honest review record without identifying you.

12. Security

We apply technical and organisational measures appropriate to the risk, including: encryption in transit for all traffic; passwords stored only as salted hashes; stored credentials and secrets encrypted at rest; licence keys stored only as hashes; domains and IP addresses in licence and abuse logs stored as hashes; two-factor authentication available on Accounts and used on our own administrative access; least-privilege access, with administrative access limited to the proprietor; rate limiting and automated abuse prevention; signed, short-lived download links; server-side payment verification that does not trust anything reported by a browser; and regular backups.

No system is perfectly secure, and we do not claim otherwise. If a personal data breach occurs that is likely to result in risk to you, we will notify the relevant authority and affected individuals as the applicable law requires, and we will tell you what happened rather than minimising it.

Your part. Use a strong, unique password, enable two-factor authentication, and keep your email account secure — it is the recovery route for everything else. We will never ask you for your password or a one-time code. Anyone who does is attempting to take your Account.

To report a vulnerability, follow our Security Policy.

13. Cookies

Cookies and similar technologies are covered in detail by our Cookie Policy, including what each category does, how long each lasts, and how to give or withdraw consent. Essential cookies keep you signed in and keep checkout working; anything beyond that is set only where you agree.

14. Marketing

We send marketing email only where you have consented, or where the applicable law permits it on the basis of an existing customer relationship for similar products.

Every marketing email carries a one-click unsubscribe, and your Account settings offer the same control. Unsubscribing takes effect promptly and permanently.

Transactional email continues after you unsubscribe: Order confirmations, invoices, licence keys, expiry notices, password resets and security alerts. Those are part of the service you bought, not marketing, and we cannot exclude you from them while you hold an active Order or licence.

15. Children

The Service is not directed at children and is intended for users aged 18 or over. We do not knowingly collect personal data from a child, and we do not carry out behavioural tracking or targeted advertising directed at children.

If you believe a child has provided us with personal data, write to [email protected] and we will delete it.

16. Third-Party Links and Products

The Service links to third-party sites, marketplaces, documentation and repositories. We do not control them and are not responsible for their privacy practices. Read their policies.

Where a Product you buy from us integrates with a third-party service, and you configure that integration on your own installation, any data flowing to that service does so under your control and under its policy, not ours. We are not a controller or processor of data your own installation sends to a third party at your direction.

17. Automated Decision-Making

We do not make decisions producing legal or similarly significant effects about you by automated means alone.

Automated systems do assist us — rate limits, abuse detection, and licence-verification checks all operate automatically — but a decision to refuse a refund, suspend an Account, or revoke a licence is made by a person, who will tell you the reason and will review it if you ask. Clause 6 of the Refund & Cancellation Policy and Clause 15 of the Licence Agreement say the same.

18. Complaints

Raise a privacy concern with [email protected] first. We will acknowledge it and respond substantively.

If you are not satisfied, escalate to [email protected], where it will be reviewed by the proprietor.

You retain the right to complain to a supervisory authority at any time: in India, the Data Protection Board of India; in the EU or UK, your local data protection authority. You do not need to exhaust our process first.

19. Changes to This Policy

We may update this Policy when we add or change a provider, add a feature that processes data differently, or when the law changes.

The current version is published on this page with its effective date. Where a change is material, we will give notice through the Service and, where we hold your email address, by email — and where the change requires consent, we will ask for it rather than assume it.

Superseded versions are retained and available on request from [email protected].

20. Contact

Privacy questions, data requests and complaints: [email protected].
Escalations and legal notices: [email protected].
Order and account help: [email protected].

DELTRIG
Sole proprietorship — Proprietor: Rahul Chouhan
Dakra, Khalari, Ranchi, Jharkhand, India – 829210
Website: https://deltrig.com