Home / Privacy Policy

Privacy Policy

Your privacy, intellectual property, and confidential project data are paramount to SiteJupiter. This policy outlines how we collect, process, safeguard, and manage your personal and technical information in full compliance with applicable data protection laws.

Effective Date: August 2026
AES-256 Session Encrypted
DPDP Act 2023 & GDPR Compliant

1 Information We Collect

When you visit SiteJupiter, submit a project lead, communicate through our forms, or execute project agreements via our Client Portal, we collect purposeful personal and technical data:

  • Contact Information: Your Full Name, Business Email Address, Phone Number, and Preferred Communication Channel (WhatsApp, Phone Call, Email, Telegram) along with any provided contact handle.
  • Project & Technical Specifications: The selected service category (Business Website, WordPress, E-commerce, Custom Website, Web Application, Enterprise), budget estimate and currency (INR/USD), technology stack preferences, and project scope details.
  • Client Portal & Signature Data: Authorized signatory name, company designation, electronic signature timestamps, and SHA-256 agreement verification hashes for legally binding contract execution.
  • Invoicing & Transaction Details: Billing entity name, registered business address, GSTIN / Tax ID (if applicable), invoice tokens, and payment reference numbers. (Note: We do not store credit card numbers or banking PINs; all payments are processed securely by certified payment gateways).
  • Technical Security & Geolocation Headers: Client IP Address, browser User-Agent, and CDN Geolocation headers (e.g. Cloudflare Country Code) used exclusively for anti-tamper CSRF token generation, bot defense, and localized currency presentation (INR for India, USD for global visitors).

2 How We Use Your Information

The personal and project information you provide is utilized solely for legitimate business operations and project delivery:

  • Preparing, calculating, and dispatching customized web development quotations, timeline schedules, and project proposals.
  • Direct project communication via your selected contact channel regarding active milestones, staging reviews, and feedback.
  • Executing official digital agreements and issuing statutory GST/MSME commercial invoices and payment receipts.
  • Providing post-launch technical warranty assistance and customer helpdesk support.
Zero Monetization Guarantee
Privacy First

We do not sell, rent, lease, trade, or monetize your contact records or project details to third-party telemarketers, data brokers, or advertising networks under any circumstances.

3 Data Security & AES-256 Session Encryption

SiteJupiter employs enterprise-grade cryptographic security measures to protect website traffic, form transmissions, and Client Portal transactions:

State-of-the-Art Anti-Tamper Security
Encrypted
  • AES-256-CBC Token Encryption: Form submissions use dynamic, encrypted cryptographic tokens combining session hashes, IP fingerprints, and CRC32 verification to prevent CSRF exploits, cross-site forgery, and replay attacks.
  • SSL/TLS Transport Layer Security: All data transmitted between your web browser and our servers is protected by modern HTTPS/TLS 1.3 encryption.
  • Input Sanitization & Prepared Statements: Strict server-side validation, sanitization filters, and parameterized SQL queries block injection attacks and malicious payloads.

4 Cookies, Sessions & Local Storage

We use minimal, privacy-respecting storage mechanisms essential for website performance and user preferences:

  • Theme Preference (`localStorage`): We use your browser's local storage to remember your selected dark or light mode preference without tracking personal data.
  • Currency Selection (`user_currency`): A 30-day functional cookie/session is used to remember your preferred currency view (INR ₹ vs USD $) across pages.
  • PHP Session Cookie (`PHPSESSID`): A temporary, secure session cookie used to maintain cryptographic CSRF tokens. This cookie automatically expires when your browser is closed.

Zero Cross-Site Tracking: SiteJupiter does not use invasive behavioral tracking cookies, cross-site ad retargeting pixels, or third-party profiling cookies.

5 Third-Party Service Providers

To deliver secure, high-performance web services and seamless billing, we integrate with trusted third-party providers bound by stringent security standards:

  • Payment Gateways (Razorpay, UPI, Stripe, PayPal): Online payments are processed via PCI-DSS compliant payment gateways. Payment credentials are handled directly by the processor under strict encryption.
  • Cloudflare & CDN Infrastructure: Provides DDoS mitigation, edge caching, web security firewalling, and GeoIP detection for optimized load speeds.
  • Google Workspace / SMTP: Form inquiry emails, quotation notices, and system alerts are dispatched securely via TLS-encrypted SMTP mail servers.
  • Google Fonts: Web typography is delivered via Google Fonts CDN for optimized visual rendering.

6 Your Rights Under DPDP Act 2023 & GDPR

In accordance with India's Digital Personal Data Protection Act, 2023 (DPDP Act), the Information Technology Act, 2000 (SPDI Rules), and international data protection standards (including the General Data Protection Regulation - GDPR for European and international clients), you have the following rights regarding your personal information:

  • Right to Access: You may request a complete copy of all personal details and communication records we hold regarding your inquiries or account.
  • Right to Rectification: You have the right to request correction or updating of any inaccurate, outdated, or incomplete personal details.
  • Right to Erasure (Right to be Forgotten): You may request that we permanently delete your contact records, lead submissions, and communication logs, subject to statutory tax retention laws.
  • Right to Withdraw Consent: You may withdraw your consent for business communications at any time by contacting our privacy team.
  • Confidentiality & NDA: All proprietary client source code, database credentials, wireframes, and business logic shared during development are protected under strict internal non-disclosure practices.

7 Data Retention Schedules

SiteJupiter retains personal data only as long as necessary to fulfill the purposes for which it was collected:

  • General Inquiry Leads: Retained for a maximum of 24 months to facilitate follow-up quotations and project history, or until an erasure request is submitted.
  • Executed Contracts & Invoices: Invoices, payment receipts, and executed digital agreements are retained for seven (7) years to comply with Indian statutory accounting, GST, and commercial legal requirements.
  • Security & CSRF Logs: Temporary anti-tamper session logs automatically rotate and expire within 72 hours.

8 Children's Privacy (18+ Requirement)

Our web development services, quotations, and Client Portal are intended exclusively for commercial entities, entrepreneurs, and individuals who are at least 18 years of age. We do not knowingly solicit, collect, or process personal data from children or individuals under the age of 18. If we become aware that personal data of a minor has been submitted, we will promptly delete such information from our records.

9 Data Protection & Grievance Officer

In compliance with the Digital Personal Data Protection Act, 2023 and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, if you have any questions, concerns, or grievances regarding our privacy practices or wish to exercise your data protection rights, please contact our designated Grievance & Privacy Officer:

  • Designation: Data Protection & Grievance Officer, SiteJupiter
  • Email: [email protected] / [email protected]
  • Corporate Entity: SiteJupiter (MSME Registration No: UDYAM-WB-20-0008871 | West Bengal, India)
  • Response Timeline: All privacy inquiries and data access/erasure requests are acknowledged and resolved within 48 to 72 business hours.