Skip to content
RanWebs Technologies logo
GDPR · UK GDPR · CCPA/CPRA · DPDP 2023 · Google API User Data Policy

Privacy Policy

How RanWebs Technologies collects, uses, shares and safeguards your personal data across our website, mobile apps and Google-connected features — for clients across the US, UK, Europe, Asia Pacific and India. Written in plain English, engineered for compliance.

Last updated: July 2026Applies to website + mobile appEnglish
Section 01

Overview & scope

RanWebs Technologies Private Limited ("RanWebs", "we", "us", "our") respects your privacy. This Privacy Policy explains how we collect, use, disclose and safeguard personal information when you visit ranwebs.com, use our mobile applications, sign up for our services, or interact with us through email, phone, WhatsApp or in person.

By using our website, mobile app or services you agree to the practices described here. This policy applies to both our web platform and any RanWebs mobile applications distributed through Google Play or the Apple App Store.

Section 02

Data we collect

We collect only the information needed to deliver, secure and improve our services:

  • Identity & contact — name, email, phone number, company name, job title, and postal address you provide via forms, chat or during onboarding.
  • Account credentials — hashed passwords, OAuth tokens (Google, Microsoft, Zoho) when you choose social sign-in.
  • Project & billing — project scope, invoices, GST/PAN details, purchase orders and payment references.
  • Device & usage — IP address, browser, OS, device model, app version, session duration, referring URL, crash logs and diagnostic data.
  • Cookies & pixels — Google Analytics 4, Meta Pixel, LinkedIn Insight and similar (see Cookie Policy).
  • Communications — email, WhatsApp, call recordings and support tickets kept for quality and compliance.
Section 03

How we use your data

  • Deliver the services you request (consultations, projects, retainers, support).
  • Authenticate users and secure accounts against fraud and abuse.
  • Send transactional notifications (invoices, tickets, delivery updates).
  • With your consent, send marketing newsletters and event invitations.
  • Improve product quality via aggregated analytics, crash diagnostics and A/B testing.
  • Comply with legal, tax and audit obligations in India and destination countries.
Section 04

Google API Services & Google Apps data

Some RanWebs products let you sign in with Google or connect your Google Workspace account (Gmail, Google Drive, Google Calendar, Google Contacts, Google Ads, Google Analytics, Google Search Console, Google Business Profile). When you grant access, RanWebs' use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

What we access: only the specific scopes shown on Google's consent screen — e.g. read Drive metadata to sync a document, read Gmail headers to draft a reply template, or read Ads/Analytics reports to generate performance dashboards.

How we use it:

  • Only to provide or improve the user-facing features you enabled.
  • Not for serving advertisements — RanWebs does not use Google user data for ads.
  • Not for training generalised AI/ML models. If any AI feature processes Google user data, it does so in-session for the signed-in user only and is not used to train models.
  • Not transferred to third parties except (a) to provide the feature, (b) for security & compliance, (c) with your explicit consent, or (d) as required by law.
  • Not read by humans, except with your explicit consent, to debug a specific issue you reported, or when required by law.

Revoke access at any time from myaccount.google.com/permissions. You may also email info@ranwebs.com to request deletion of any residual data.

Section 05

Mobile app privacy (Android & iOS)

Our mobile apps collect only what is required for the feature you use. Consistent with the Google Play Data Safety disclosure and Apple App Privacy nutrition labels:

  • Account data — email, name — used for account management and support.
  • App activity — in-app interactions, crash logs — used for analytics and app functionality.
  • Device IDs — used for fraud prevention and analytics; not linked to advertising.
  • Permissions we may request: notifications (transactional alerts), camera (document scan), storage (attach files), contacts (optional invite feature). All permissions are opt-in and can be revoked from OS settings.
  • Data in transit is encrypted using TLS 1.2+. Locally cached data is stored in the app's private sandbox.
  • We do not sell mobile user data. We do not use mobile data for third-party advertising or data brokers.
Section 06

Sharing & processors

We share limited personal data with vetted processors under signed Data Processing Agreements:

  • Cloud infrastructure — Microsoft Azure, Google Cloud, AWS (hosting & storage).
  • Analytics & marketing — Google Analytics, Google Ads, Meta, LinkedIn.
  • CRM & helpdesk — Zoho, HubSpot, Freshdesk.
  • Communications — SendGrid/Resend (email), WhatsApp Business API, Twilio.
  • Payments — Razorpay, Stripe, Paddle (PCI-DSS certified).

We do not sell personal data. Cross-border transfers use Standard Contractual Clauses or equivalent safeguards.

Section 07

Security measures

  • TLS 1.2+ everywhere; HSTS enforced on all production domains.
  • Encryption at rest for databases, backups and object storage.
  • Role-based access control, MFA and principle of least privilege for staff.
  • Continuous vulnerability scans, quarterly penetration tests and annual SOC 2 / ISO 27001 aligned reviews.
  • Incident response with 72-hour breach notification per the DPDP Act and GDPR.
Section 08

Data retention

  • Marketing leads: up to 24 months from last interaction.
  • Client project data: duration of the engagement plus 7 years for statutory audit.
  • Invoices & tax records: 8 years (Indian statutory requirement).
  • Support tickets & call recordings: up to 24 months.
  • Backups purge on a rolling 90-day cycle.
Section 09

Your rights & choices

Subject to applicable law you may request to:

  • Access the personal data we hold about you.
  • Correct inaccurate or outdated information.
  • Delete your data (subject to statutory retention).
  • Withdraw marketing consent — one click via the unsubscribe link.
  • Port your data in a structured, machine-readable format.
  • Lodge a complaint with the Data Protection Board of India, ICO (UK) or your local supervisory authority.

Email info@ranwebs.com — we respond within 30 days.

Section 10

GDPR — UK & EU residents

If you are located in the United Kingdom, the European Economic Area or Switzerland, the UK GDPR / EU GDPR apply. RanWebs acts as a data controller for enquiries submitted through this site and as a data processor when handling personal data on behalf of client organisations under a Data Processing Agreement (DPA).

Lawful basis for processing:

  • Contract — to deliver services you or your employer contracted us to provide.
  • Legitimate interest — to respond to sales enquiries, secure our services, and improve our platform (balanced against your rights).
  • Consent — for marketing emails, non-essential cookies and optional integrations. You may withdraw at any time.
  • Legal obligation — statutory record-keeping, tax, anti-fraud and law-enforcement requests.

Your GDPR rights include access, rectification, erasure, restriction, portability, objection and the right not to be subject to solely automated decisions. Email info@ranwebs.com to exercise any right; we respond within 30 days.

International transfers. Where we transfer UK/EU personal data outside the UK/EEA (including to our India delivery centre), we rely on the European Commission's Standard Contractual Clauses (2021), the UK International Data Transfer Addendum, and supplementary technical measures (encryption in transit and at rest, access controls, pseudonymisation).

Supervisory authority. UK residents may complain to the Information Commissioner's Office (ICO). EEA residents may complain to their local data protection authority.

EU representative. Clients requiring a designated Article 27 EU representative may request one under their DPA. Email info@ranwebs.com.

Section 11

CCPA / CPRA — California residents

If you are a California resident, the California Consumer Privacy Act (CCPA) as amended by the CPRA gives you additional rights over your personal information.

Categories of personal information we may collect: identifiers (name, email, IP), commercial information (services enquired about), internet/network activity (site usage, cookies), professional information (company, job title), and inferences drawn from the above.

Sale & sharing. RanWebs does not sell personal information for money. We do share limited identifiers with analytics and advertising partners (Google, Meta, LinkedIn) for cross-context behavioural advertising — which under the CPRA counts as "sharing".

Your California rights:

  • Right to know what personal information we collect, use, disclose and share.
  • Right to delete personal information we hold about you.
  • Right to correct inaccurate personal information.
  • Right to opt out of the sale or sharing of your personal information.
  • Right to limit use of sensitive personal information.
  • Right to non-discrimination for exercising any CCPA/CPRA right.

How to opt out. Use the "Cookies" link in our footer to reject analytics and marketing categories, honour Global Privacy Control (GPC) signals from your browser, or email info@ranwebs.com with subject line "Do Not Sell or Share My Personal Information". Authorised agents may submit requests on your behalf with written proof.

Section 12

Asia Pacific — regional data protection

Where APAC data-protection frameworks apply (Singapore PDPA, Australia Privacy Act, Japan APPI, and similar), RanWebs adheres to the higher of the applicable regional standard and the safeguards described elsewhere in this policy: purpose limitation, consent for marketing, breach notification, and reasonable security controls. Contact info@ranwebs.com to raise a regional query or exercise rights available under your local law.

Section 13

Cookies & tracking

We use essential, analytics and marketing cookies. Detailed categories, providers and durations are listed in our Cookie Policy. You can manage preferences via the on-site cookie banner or your browser settings.

Section 14

Children's privacy

Our services target businesses and adults. We do not knowingly collect personal information from children under 16. If you believe a child has provided us data, email info@ranwebs.com and we will delete it promptly.

Section 15

International transfers

We are headquartered in India and use processors in the EU, UK, US and Singapore. Transfers rely on Standard Contractual Clauses, adequacy decisions or your explicit consent.

Section 16

Push & marketing notifications

Transactional notifications (invoices, ticket updates, security alerts) are sent based on legitimate interest. Marketing notifications require opt-in and can be turned off any time from your profile, browser or device settings.

Section 17

Changes to this policy

We may update this policy to reflect product, legal or regulatory changes. Material changes will be announced via email and a banner on this page at least 14 days before they take effect.

Section 18

Grievance officer & contact

Under the Information Technology Act 2000 and DPDP Act 2023, our Grievance Officer is:

  • Data Protection Officer, RanWebs Technologies Private Limited
  • Email: info@ranwebs.com
  • Phone: +91 8002200227 (Mon–Fri, 10:00–18:00 IST)
Questions about this policy?
Talk to our compliance team