1. Who we are & scope
HTMLBasket operates globally with a head office in the United States and a core development team in India. This policy applies to visitors, customers, and partners who interact with our websites, forms, chat, support channels, or subscribe to our services.
Data Controller: HTMLBasket
Contact: [email protected]
Primary contact
If you are located in the EEA/UK, we may appoint an EU/UK representative for GDPR/UK‑GDPR compliance. Contact us for the latest details.
2. Data we collect
A. Information you provide
- Contact details: name, email, phone, company, role.
- Account & billing data: billing address, VAT/GST number, limited payment details (handled by PCI‑compliant processors).
- Project information: briefs, assets, brand guidelines, and content you upload.
- Support communications: emails, chat transcripts, tickets, and survey responses.
B. Information collected automatically
- Usage & device data: IP address, browser type, device identifiers, pages viewed, time on site.
- Cookies & similar technologies (see Cookies).
- Log data from servers, CDN, and security tools.
C. Information from third parties
- Analytics, advertising, and referral partners (e.g., campaign performance).
- Payment processors’ status updates (e.g., transaction success/failure).
3. How we use data
- Provide and operate our services, process orders, and manage accounts.
- Communicate with you: service messages, quotes, updates, support.
- Improve performance, security, and user experience of our sites and apps.
- Personalize content, measure campaign performance, and run A/B tests.
- Comply with legal obligations and enforce our terms and policies.
4. Legal bases (GDPR/UK‑GDPR)
We process personal data under these legal grounds where applicable:
- Consent – for optional cookies, marketing emails, and certain forms.
- Contract – to provide requested services or fulfill a subscription.
- Legitimate interests – to secure our services, prevent fraud, and improve features (balanced against your rights).
- Legal obligation – to keep tax/transaction records or respond to lawful requests.
5. Cookies & analytics
We use cookies and similar technologies to operate our site, remember preferences, analyze traffic, and (where enabled) support marketing campaigns.
Types of cookies
- Strictly necessary (security, session, load balancing).
- Preferences (language, theme).
- Analytics (e.g., Google Analytics or privacy‑centric alternatives).
- Marketing (e.g., Meta/LinkedIn pixels) – only with your consent where required.
You can manage cookie preferences via our cookie banner or your browser settings. Where required by law, non‑essential cookies load only after consent.
6. Sharing & processors
We do not sell personal information. We share data only with service providers (processors) that help us deliver our services, such as:
- Hosting/CDN and infrastructure providers.
- Payment processors (e.g., Stripe, Razorpay) – they handle card/UPI data.
- Analytics, error monitoring, and security vendors.
- Email, chat, and CRM platforms for support and communications.
- Professional advisors and auditors (where necessary).
These providers are bound by contracts that limit their use of your data and require appropriate security measures.
7. International data transfers
We operate globally. When data is transferred across borders (e.g., EEA ↔ US/India), we implement appropriate safeguards such as Standard Contractual Clauses (SCCs) and conduct risk assessments where required.
8. Data retention
We keep personal data only as long as necessary for the purposes described in this policy, including to meet legal, accounting, or reporting requirements. Typical retention periods:
- Account, project, and billing records: up to 7 years after last activity (or as required by law).
- Analytics & logs: up to 26 months (or shorter where feasible).
- Marketing preferences: until you withdraw consent or opt out.
9. Your privacy rights
Depending on your location, you may have the right to:
- Access, correct, update, or delete your personal data.
- Object to or restrict certain processing, and opt out of marketing.
- Port your data (receive a copy in a structured, commonly used format).
- Withdraw consent at any time (where processing is based on consent).
To exercise rights, contact us at [email protected]. We will verify your request and respond within applicable timelines.
CPRA/CCPA (California)
California residents may request disclosures about categories of personal information we collect and how we use/share it, request deletion, and opt out of certain sharing. We do not sell personal information. If we ever use cross‑context behavioral advertising, an opt‑out link will be provided.
GDPR/UK‑GDPR (EEA/UK)
You may lodge a complaint with your local supervisory authority, such as the ICO (UK) or your EEA DPA. We aim to resolve issues directly first.
DPDP (India)
You may contact our support to access, correct, or delete personal data and to raise grievances with the Data Protection Board if unresolved.
10. Children’s privacy
Our services are not directed to children under 13 (or under 16 in certain jurisdictions). We do not knowingly collect data from children. If you believe a child has provided us data, contact us to remove it.
11. Security
We implement technical and organizational measures to protect personal data, including encryption in transit, access controls, least‑privilege practices, and vendor due diligence. No method of transmission or storage is 100% secure; we encourage you to use strong, unique passwords and enable available security features.
12. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in law, technology, or our operations. The “Effective date” below indicates the latest revision. We will notify you of material changes as required.
Effective date: 07 November 2025
13. Contact us
For questions, requests, or complaints about this policy or your data, contact:
HTMLBasket – Privacy
Email: [email protected]
If your request concerns a data access/erasure/objection (DSAR), please indicate: your full name, email used with us, country/region, and the right you wish to exercise.