Privacy Policy
Last updated: June 1, 2026
1. Introduction
BRIXFLY Services ("we," "us") is committed to protecting your privacy. This policy explains how we collect, use, store, and protect personal information when you use brixfly.com or engage our services.
2. Information We Collect
2.1 Information You Provide
- Name, email, phone number, company name (contact forms, enquiries)
- Project details, business requirements, and briefs
- Payment information (processed via secure third-party providers)
- Communications (emails, messages, call recordings if consented)
- Credentials and access details shared for project delivery
2.2 Automatically Collected
- IP address, browser type, device information, operating system
- Pages visited, time spent, referral source
- Cookies and local storage data (see Section 5)
3. How We Use Information
- Respond to enquiries and provide quotes
- Deliver, manage, and support our services
- Process payments and send invoices
- Communicate project updates and deliverables
- Improve our website and service offerings
- Send relevant marketing communications (with consent)
- Comply with legal and regulatory obligations
- Protect against fraud and unauthorised access
4. Legal Basis for Processing
We process data based on:
- Contract performance: Necessary to deliver services you engaged us for
- Legitimate interest: Business communications, service improvement, security
- Consent: Marketing emails, analytics cookies
- Legal obligation: Tax records, compliance requirements
5. Cookies and Tracking
- Essential cookies: Required for website functionality (no consent needed)
- Analytics cookies: Google Analytics / PostHog to understand site usage (consent-based)
- No advertising cookies: We do not run retargeting pixels on our own site
You can manage cookies through your browser settings.
6. Data Sharing
We do NOT sell personal data. We share data only with:
- Payment processors: Stripe, Razorpay, PayPal (PCI-compliant)
- Hosting providers: Vercel, DigitalOcean, Cloudflare
- Analytics: Google Analytics, PostHog (aggregated/anonymised)
- Communication tools: Email providers for transactional emails
- Legal authorities: When required by law or court order
All third parties are bound by data processing agreements.
7. Data Security
We implement:
- HTTPS encryption on all pages and communications
- PCI-compliant payment processing (we never store card details)
- Access controls (role-based, principle of least privilege)
- Regular security updates and vulnerability patching
- Encrypted storage for sensitive credentials
8. Data Retention
| Data Type | Retention Period |
|---|---|
| Active client data | Duration of engagement + 3 years |
| Enquiries (non-converting) | 12 months |
| Financial/tax records | 7 years (legal requirement) |
| Analytics data | 26 months |
| Project credentials | Deleted within 30 days of project completion |
9. Your Rights
You have the right to:
- Access the personal data we hold
- Rectification of inaccurate data
- Erasure ("right to be forgotten") where legally applicable
- Restrict processing in certain circumstances
- Data portability (receive your data in a structured format)
- Object to processing based on legitimate interest
- Withdraw consent at any time for consent-based processing
To exercise any right: email support@brixfly.com with the subject "Data Request."
10. International Transfers
Data may be processed in India, the USA, or the EU, depending on the service providers used. All transfers are protected by appropriate safeguards (standard contractual clauses, adequacy decisions).
11. Children
Our services are not directed at individuals under 18. We do not knowingly collect data from minors.
12. Changes
We may update this policy. Material changes will be communicated via email to active clients. Check this page for the latest version.
13. Contact
Data Controller: BRIXFLY Services
Email: support@brixfly.com