Jump to section↓
Short version
- We only store what you submit through a form. No background tracking.
- Card data lives with Chargebee, Stripe, and RazorPay, never on this site.
- Third-party services we use run under their own policies.
01
What We Actually Collect#
When you submit an inquiry, contact, or project form, we keep:
- Your name and email address.
- Phone, company, and website URL if you added them.
- The project details and any other information you wrote in the form.
- A timestamp plus a little routine context so we can spot spam and understand where leads come from: a one-way fingerprint of your network address (so the original cannot be read back), a rough city and country, your browser and device label, the page you submitted from, and any campaign tags carried in the URL.
That is it for personal data.
On our domain marketplace, we keep a short, anonymous record of searches, clicks, and viewport size against a temporary session ID held in your browser, along with the same routine context as above: rough country, referring page, browser label, and the one-way network fingerprint. It helps us understand what names buyers are looking for. It is not linked to a name, email, or device profile.
02
How We Use Form Data#
Information you submit through a form is used to:
- Review your inquiry and assess fit.
- Respond to questions and schedule discovery calls.
- Prepare proposals and scopes of work.
- Deliver services and maintain project communication.
- Send follow-up related to an active or recent inquiry.
We do not sell your information. We do not use it for unrelated marketing or add you to cold-email lists.
03
Analytics and Cookies (Third-Party)#
We use two analytics tools: Rybbit for on-site behaviour and Google Search Console for search performance. Rybbit is cookieless and privacy-focused, so no analytics cookie is set on your device by us. Google Search Console reports on how our pages appear in Google search and does not track individual visitors on this site.
We do not run Google Analytics, Google Ads, Meta Pixel, or any cross-site advertising tracker. There is no way for us to look up an individual visitor's activity. We see counts and patterns, not personal browsing histories.
To opt out of analytics, browser settings or an ad blocker will do it. Core site functionality is unaffected.
04
Third-Party Services We Use#
We are upfront about every external service this site touches. Each runs under its own privacy policy.
Analytics
Infrastructure
Communication
Payments
Domains
Public profile
Privacy requests about data held by these providers should be directed to the provider. We will help where we can, but the data lives with them.
05
Payments#
Payment for projects, one-time purchases, and recurring subscriptions is handled through Chargebee on a custom checkout domain (pay.shifteq.com). Card data is entered directly into Chargebee's PCI-DSS Level 1 environment and is never seen or stored on this website or our own systems.
Under Chargebee, card processing is routed by currency: Stripe for USD, RazorPay for INR. Both run under their own published privacy policies and PCI-DSS controls. ShifteQ receives only the settled funds and a transaction reference. We never receive the raw card number, CVV, or banking credentials.
Chargebee retains the records required to operate billing: customer name, billing email and address, plan and invoice history, and tokenized payment identifiers. The "Manage Subscription" link on this site opens a Chargebee-hosted portal so you can update payment methods, download invoices, or cancel a plan directly with the processor.
One-off project work outside the subscription catalogue is invoiced through Chargebee or a comparable provider. We never accept raw card or bank credentials by email or form submission.
06
Domain Concierge: Buyer Confidentiality#
Concierge briefs contain sensitive information: target domain, brand context, budget ceiling, and acquisition urgency. We treat it as confidential. None of it is shared with the seller, registrant, or any third party during outreach unless the negotiation strategically requires it and the buyer has approved the disclosure.
Outreach runs under buyer anonymity by default. We represent the buyer without revealing name, brand, or budget unless the buyer authorises it. The seller learns the buyer's identity at closing, when terms are already locked.
An NDA is available on request and is signed before any sensitive details are exchanged. Mention it in the brief and we will send it before further discussion.
Closing is routed through Escrow.com or an equivalent escrow service. The escrow provider receives the buyer's name, billing details, and payment information as their KYC and anti-money-laundering obligations require. That data is held under the escrow provider's own privacy policy. ShifteQ does not retain the buyer's payment information. We receive only the commission portion of the disbursement.
Outreach attempts, seller responses, and negotiation records are retained for the duration of the engagement and for the 90-day tail period that follows. After that, records are kept only as needed for bookkeeping, dispute resolution, or legal obligations, consistent with the retention policy below.
07
Data Security#
Form submissions are stored in an encrypted database (Neon). Access is limited to the people directly working on your engagement. Communications and project files are handled with care.
No method of transmission over the internet is completely secure. While we apply standard security practices, we cannot guarantee absolute protection against all threats.
08
Data Retention#
Form submissions and client information are retained only as long as reasonably necessary for:
- Communication and project delivery.
- Service engagement records (email trail, briefs, scope confirmations, delivery notes) kept as evidence of what was agreed and what was delivered, used for support handoffs, refund eligibility, and chargeback defense.
- Bookkeeping and financial records.
- Legal or operational obligations.
- Security review and dispute resolution.
Once retention is no longer required, data is deleted on request or anonymized. Engagement email trails are retained for the duration of the active engagement plus a reasonable post-engagement window aligned with our bookkeeping and dispute-resolution obligations.
09
Your Rights#
You can request the following for data you have submitted through a form:
- A copy of the form data we hold.
- Correction of inaccurate or out-of-date information.
- Deletion of your form data (where legally possible).
- Withdrawal of consent for further processing.
For data held by third parties (analytics, payment processors, etc.), requests should go directly to those providers. They hold the data, not us.
If you are based in the EU/UK, GDPR applies. In India, DPDP applies. In California, CCPA applies. We respond to valid requests within a reasonable timeframe.
10
Children#
This website is intended for business use and is not directed at children under the age of 16. We do not knowingly collect personal information from minors. If you believe a minor has submitted information through this site, contact us and we will delete it promptly.
11
Governing Law#
The data controller for this website is ShifteQ Virtual Innovations Pvt Ltd, Thane, Maharashtra, India.
This privacy policy is governed by the laws of India. Any disputes relating to privacy or data handling that cannot be resolved informally are subject to the jurisdiction of the courts in Thane, Maharashtra, India.
12
Changes to This Policy#
This policy may be updated as the website, tools, or legal requirements evolve. The date at the top reflects the most recent revision. Continued use of the website after an update constitutes acceptance of the revised policy.
Your data. Your call.
Send us a privacy request through the contact form. We respond within 7 business days.
- Copy of your form data
- Correction of inaccurate data
- Deletion where legally possible
- Export in portable format
- Withdrawal of consent at any time