Privacy Policy
Pixel Street ("we", "us") runs pixelstreet.in and its blog. This policy explains what we collect, why, who else sees it, and what you can make us do about it.
It is written to India's Digital Personal Data Protection Act, 2023 ("DPDP Act"). Where the Act uses "Data Principal" we say you, and where it uses "Data Fiduciary" we mean us.
If you only read one section, read What you can ask us to do.
1. Who to contact
Grievance Officer: Khurshid Alam
Email: info@pixelstreet.in
Post: Pixel Street, Martin Burn Business Park, Office #900B, 9th Floor, BP Block, Sector V, Bidhannagar, Kolkata, West Bengal 700091, India
Phone: +91 90072 95096
Use the same address for any request under section 5 below. We answer within 30 days.
2. What we collect
When you send us an enquiry
The form asks for, and we store:
| Field | Required |
|---|---|
| Name | Yes |
| Email address | Yes |
| Phone number | Yes |
| Service you are interested in | No |
| Your message | No |
Submitted with it, without you typing it: the page you submitted from, a timestamp, and how you arrived at the site (search, a referring link, or a campaign parameter in the URL). We use that last one to know which of our own efforts brought you here.
The form also contains a field that is hidden from you and left empty. Automated scripts fill it in; people do not. A submission with that field filled is discarded as spam. It collects nothing about you.
When you simply read the site
Our host records standard server logs — IP address, browser, pages requested, time. These exist to keep the site running and secure.
Beyond that, nothing that profiles you runs until you allow it. See section 4.
What we do not collect
We do not ask for, want, or knowingly store: payment card details, government identifiers, health information, or any of the special categories the DPDP Act treats as sensitive. Please do not put them in the enquiry message.
3. Why we hold it, and on what basis
Under the DPDP Act we process your data on the basis of your consent, given when you submit the enquiry form or accept a category in the cookie notice.
| Purpose | What it uses |
|---|---|
| Replying to your enquiry and quoting for work | Name, email, phone, message |
| Keeping a record of who asked us for what | The same, in our CRM sheet |
| Preventing spam and abuse of the form | reCAPTCHA, the hidden field, server logs |
| Understanding which pages are useful | Analytics — only with consent |
| Seeing where a page confuses people | Session recording — only with consent |
We do not sell your data. We do not share it for anyone else's advertising.
4. Cookies and tracking
The first time you visit, you get a notice with three categories. Nothing in the second or third runs until you choose — the scripts are inert in the page until consent activates them, so no request is made and no cookie is set.
Strictly necessary — always on. Remembers your choice from this notice, secures the enquiry form with Google reCAPTCHA, and routes your message. Sets no advertising cookie and profiles nobody.
Analytics — off by default. Google Analytics and Google Ads, which tell us which pages are read and which campaigns bring people here. Sets cookies beginning _ga, _gid and _gcl, and shares data with Google.
Session recording — off by default. Hotjar records how pages are used — scrolling, clicks, mouse movement — and builds heatmaps. It does not capture what you type into the enquiry form. Sets cookies beginning _hj.
Changing your mind is one click. "Cookie preferences" sits in the footer of every page. Turning a category off stops it *and deletes the cookies it already set*. If your browser sends a Global Privacy Control signal we treat that as a refusal and never ask.
5. Who else sees your data
| Who | What they get | Where |
|---|---|---|
| Google (Workspace, Sheets, Apps Script) | Your enquiry, stored in our CRM sheet | Outside India |
| Google (Analytics, Ads) | Usage data — only with consent | Outside India |
| Google (reCAPTCHA) | Signals that decide whether you are a bot | Outside India |
| Hotjar | Interaction recordings — only with consent | Outside India |
| SiteGround | Hosting and server logs | Outside India |
| Cloudflare, jsDelivr | Delivery of shared code libraries | Global |
Transfer outside India
Yes — your data is processed outside India. Our email, our CRM sheet and every service above run on infrastructure outside the country. The DPDP Act permits this except to countries the Central Government restricts by notification; we will stop any transfer that becomes restricted.
6. How long we keep it
Enquiry data: two years from your last contact with us, then deleted.
If you become a client, the records that belong to that engagement are kept for as long as the relationship lasts and afterwards for as long as tax and contract law requires. Server logs are kept for a short operational period. Analytics and recording data are kept according to the retention set in those tools, and are deleted when you withdraw consent.
You can ask us to erase your data sooner. See below.
7. What you can ask us to do
Under the DPDP Act you have the right to:
- Know what we hold about you and who we have shared it with.
- Correct anything inaccurate, and complete anything incomplete.
- Erase your data, unless we are required by law to keep it.
- Withdraw consent at any time — as easily as you gave it. Withdrawal does not undo what was lawful beforehand.
- Nominate someone to exercise these rights for you if you die or become incapable.
- Complain to us first, and to the Data Protection Board of India if we do not resolve it.
Email info@pixelstreet.in. We reply within 30 days. There is no charge.
8. Children
The site is for businesses and is not directed at children. We do not knowingly collect data about anyone under 18. The DPDP Act requires verifiable parental consent for a child's data, and we do not process children's data at all — if you believe a child has sent us something, tell us and we will delete it.
9. Keeping it safe
Enquiries travel over HTTPS. Access to the inbox and the CRM sheet is limited to people who need it. Credentials for the form handler are held on the server and are not in our code repository or any published archive.
No system is perfectly secure. If a breach affects your data we will notify you and the Data Protection Board as the Act requires.
10. Links out
The site links to LinkedIn, Instagram, Behance, Dribbble, Google Maps and WhatsApp. Following one takes you to a service with its own policy, which we do not control.
11. Changes
This policy takes effect on 30 September 2026. If we change it materially we will update the date and, where the change affects what you consented to, ask again.