Privacy Policy

Last updated 16 September 2026

On this page
  1. 1.Who I am
  2. 2.What I collect
  3. 3.Cookies and similar technologies
  4. 4.Who else processes your data
  5. 5.Why I am allowed to process it
  6. 6.How long I keep it
  7. 7.Your rights
  8. 8.International transfers
  9. 9.Client project data
  10. 10.Security
  11. 11.Children
  12. 12.Changes to this policy

1. Who I am

This website, devanshthakkar.com, is operated by Devansh Thakkar, an independent freelance developer based in Surat, Gujarat, India.

For the purposes of the UK and EU General Data Protection Regulation, I am the data controller for personal data collected through this website. For the purposes of India’s Digital Personal Data Protection Act 2023, I am the Data Fiduciary.

You can reach me at info@devanshthakkar.com about anything in this policy, including a request to access or delete your data.

2. What I collect

Information you give me

When you submit the contact form or book a call, I collect your name, email address, phone number where you provide one, your website URL where you provide one, and whatever you write in the message field. I ask for this because I cannot quote a project without it.

When you email me or message me on WhatsApp, I hold that correspondence and anything in it.

Information collected automatically

Like almost every website, my server records standard request data: IP address, browser and device type, referring page, and the pages you visit with timestamps. Google Analytics records similar information in an aggregated form.

What I do not collect

I do not sell anything on this site, so I never see your payment card details. I do not run advertising pixels from Meta, LinkedIn, TikTok or any ad network. I do not buy or rent mailing lists, and I do not operate a newsletter that adds you without asking.

3. Cookies and similar technologies

This site uses a small number of cookies and scripts. Named honestly, they are:

ServicePurposeType
LiteSpeed CacheServes pages faster by storing a cached copyStrictly necessary
WordPressSession and security cookies, only if you log inStrictly necessary
Google Analytics 4Counts visits and shows which pages get readAnalytics
Google reCAPTCHAStops automated spam on the contact formSecurity
GravatarLoads avatar images on some pagesFunctional

You can block or delete cookies in your browser settings. Blocking the analytics cookie changes nothing about how the site works for you. Blocking the reCAPTCHA scripts may stop the contact form from submitting.

Google Analytics is configured to exclude logged-in users, so my own visits are not counted.

4. Who else processes your data

I use a small set of third-party services to run this site. Each one is named here rather than hidden behind a phrase like “trusted partners”.

  • Hostinger hosts the website and its database, including any form submission stored on it.
  • Google provides Analytics, Search Console and reCAPTCHA. Search Console shows me anonymised search queries and never identifies individuals.
  • Automattic serves Gravatar avatar images, which involves a request to their servers carrying your IP address.
  • My email provider receives and stores form submissions and correspondence.
  • WhatsApp, owned by Meta, if you choose to message me there. That conversation is governed by WhatsApp’s own privacy policy, not this one.

I do not sell your personal data. I have never done so and have no plan to. I do not share it for cross-context behavioural advertising, which is the specific thing California law asks me to tell you about.

6. How long I keep it

  • Enquiries that do not become projects: up to 24 months, then deleted. People often come back a year later.
  • Client project records: for the duration of the engagement and for 7 years afterwards, which is the retention period Indian tax law requires for financial records.
  • Analytics data: Google Analytics 4 retains event data for 14 months by default.
  • Server logs: typically rotated within 30 days by the host.

Ask me to delete your enquiry sooner and I will, unless I need to keep a record for a legal or accounting reason. I will tell you which applies rather than just refusing.

7. Your rights

Depending on where you live, you have some or all of the following rights. I honour them regardless of which law technically applies to you, because operating two standards is more trouble than it is worth.

  • Access. Ask what personal data I hold about you and get a copy.
  • Correction. Have inaccurate data fixed.
  • Deletion. Ask me to erase your data, subject to records I must legally keep.
  • Restriction and objection. Ask me to stop or limit a particular use.
  • Portability. Receive your data in a machine-readable format.
  • Withdraw consent. Where processing rests on consent, withdraw it at any time.
  • No discrimination. Exercising any of these rights never changes the service you get.

Email info@devanshthakkar.com and I will respond within 30 days. If you are in the UK or EEA and think I have handled something badly, you can complain to your national supervisory authority. In India, you may approach the Data Protection Board.

8. International transfers

I am based in India and most of my clients are in the United States, the United Kingdom, Australia, Canada and Europe. That means personal data will cross borders in the ordinary course of working together.

Where data moves out of the UK or the EEA, I rely on the European Commission’s Standard Contractual Clauses, or the equivalent UK International Data Transfer Addendum, as the safeguard. Google and my hosting provider both operate under these mechanisms for their own transfers.

9. Client project data

This section matters more than the rest of the policy if you hire me, and most privacy policies leave it out entirely.

Delivering development work usually means I am given administrator access to your WordPress site, and sometimes to your hosting, domain registrar or payment gateway. That access can expose personal data belonging to your customers: order records, form submissions, user accounts.

When that happens, you are the data controller and I act as your data processor. In practice:

  • I access only what the agreed work requires.
  • I do not copy, export or retain your customer data beyond what a task needs, and I delete working copies when it is finished.
  • I work on a staging copy wherever possible rather than live customer records.
  • Credentials are stored in a password manager, never in plain text, email or chat.
  • I return or destroy access at the end of the engagement, and you can revoke it yourself at any moment.

If your jurisdiction requires a formal Data Processing Agreement, ask and I will sign one before work starts.

10. Security

The site runs over HTTPS. The database and files are backed up by the host. Administrator accounts use strong unique passwords, and access to client systems is stored in a password manager rather than anywhere searchable.

No system is perfectly secure and anyone who tells you otherwise is selling something. If a breach occurs that is likely to put your rights at risk, I will notify you and the relevant authority within 72 hours of becoming aware of it.

11. Children

This is a business-to-business website and it is not directed at children. I do not knowingly collect personal data from anyone under 18. If you believe a child has submitted information through this site, email me and I will delete it.

12. Changes to this policy

I update this policy when the services behind the site change, for example if I add or remove an analytics tool. The date at the top of this page reflects the most recent revision. Material changes will be flagged on the page for a reasonable period rather than slipped in quietly.

Questions about any of this?

Email me and you get a real answer from the person who wrote the page, not a ticket number. Replies within 24 business hours on business days.