Website design, fixes & care · US, UK & Australia Get my free website auditFree audit Book 20 minutes with usBook 20 min (opens in a new tab)
Privacy

Privacy policy, in plain English.

What we collect, why, who we share it with, how long we keep it, and how to make us stop or delete it. Written for people in the US, the UK and Australia.

Last updated:

The short version: we collect only what we need to review websites, reply to you and do the work you ask for. We never sell or share your personal information for advertising. Analytics only run if you click "Accept". If we emailed you first and you'd rather we didn't, reply "no" and we stop straight away.

Who we are

This website is run by Shivoham Prime ("we", "us"), a founder-led web studio. We decide how your personal information is used and are responsible for it (the "controller"). We also run MedSpa Prime (medspaprime.com), a specialized brand for med spas; this policy covers both websites and both brands.

Questions or requests about your data: info@shivohamprime.com.

What we collect

When you request a free Website Audit

Our form asks for:

  • your name;
  • your business name;
  • your website address;
  • your work email;
  • optionally, the type of business you run.

We also note which page the request came from. Depending on how the form is set up, your request either reaches us directly or opens your own email app with the details filled in, so you can see exactly what you're sending.

When you email us or book a call

We receive what you choose to share: usually your name, email address, the time you booked and any notes or messages. Calls are booked through Cal.com, which handles the booking for us and has its own privacy policy.

When you become a client

We keep your contact details, the project scope and messages, invoicing details, and the content and files you give us. If you give us logins to your website or tools, we use them only for your project, store them securely and ask you to change them when the work ends.

When you visit this website

Our hosting provider keeps basic technical logs (such as IP address, browser type and the pages requested) to keep the site secure and working. Your cookie choice is saved in your own browser. Analytics only run if you accept them (see Cookies and analytics).

Business contact details we collect for outreach

We sometimes contact businesses first, by email, about a specific problem we found on their website. For that we collect business contact details only from public sources: the business's own website, its Google Business Profile and public professional profiles. This can include the business name, website address, a published work email address, the name and role of a contact person where it's published for business purposes, business phone and address, public review ratings, and our notes about the website issue we found. We never buy email lists.

Your business's public website

To prepare an audit, we review your public website and public business listings. We don't log in to anything or access private systems.

How we use it, and why we're allowed to

The second part of each line is our "lawful basis" under UK data protection law.

  • To prepare and send the audit you ask for, and to reply to you: because you asked for it (taking steps at your request) and our legitimate interest in answering inquiries.
  • To do client work and keep business records: to perform our contract with you, and to meet our legal obligations (for example, tax and accounting).
  • To email businesses about a relevant website issue we found: our legitimate interest in offering our services to businesses, balanced against yours. We keep these emails short, relevant and easy to stop (see If we emailed you first).
  • To keep a do-not-contact list: so we respect your opt-out and never email you again (legal obligation and legitimate interest).
  • Analytics: only with your consent, which you can withdraw at any time.
  • To keep the website and our systems secure: our legitimate interest.

We use software to help us work, including tools that check website speed and AI tools that help us review public websites and draft text. A person reviews every audit and every email before it's sent. We don't make decisions about you that have legal or similarly significant effects using automated means alone.

If we emailed you first

Here is exactly how we handle cold emails and follow-ups, in every market we work in:

  • We only email businesses, at work addresses that the business has publicly listed, about a relevant website issue we actually found. We never buy lists.
  • Every email says who we are, includes our business postal address, and has a one-step opt-out: reply "no" (or "stop", "unsubscribe", or anything similar).
  • We send at most two short follow-ups, and we stop as soon as you reply or opt out.
  • UK: we only email corporate addresses (for example, limited companies and LLPs), not sole traders or personal addresses.
  • Australia: we only email addresses that are conspicuously published, where our message is relevant to the recipient's role, and never where the website says it doesn't want unsolicited commercial email.
  • US: our emails follow the CAN-SPAM Act: truthful sender and subject lines, our postal address, and an opt-out that works.

To opt out or object, reply "no" to any of our emails or write to info@shivohamprime.com. We act on it immediately (always well within the legal deadlines). We then delete your outreach details and keep only a minimal record on our do-not-contact (suppression) list: your email address, the business website and the date you opted out. That record is the only thing we keep, and it exists for one reason: so we never email you again. If you'd like to see what we held before we delete it, say so in the same message.

Cookies and analytics

When you first visit, a banner asks whether you accept analytics cookies. Decline is as easy as Accept, and the site works the same either way.

  • If you decline, or don't answer, no analytics or advertising cookies are set and no analytics script is loaded.
  • If you accept, we may load a web analytics tool (such as Google Analytics) to see, in aggregate, which pages are visited and whether forms are sent. At the moment no analytics tool is switched on, so nothing loads even if you accept.
  • Your choice is saved in your browser's local storage (key sp-consent) so we don't ask again. This storage is strictly necessary to remember your choice.
  • You can change your mind at any time with the Cookie settings link at the bottom of every page.

We don't use advertising cookies or tracking pixels on this site. If that ever changes, we'll ask for consent first and update this policy.

Who we share it with

We don't sell personal information and we don't share it for cross-context behavioral advertising. We only pass it to the service providers that help us run the business, and only what they need:

  • website hosting and form handling;
  • email;
  • call scheduling (Cal.com);
  • software and AI tools that help us review public websites and draft text;
  • accounting and invoicing;
  • web analytics, only if you consent.

These providers may only use the information to provide their service to us. We may also disclose information if the law requires it, or to a buyer if our business is ever sold (they would have to respect this policy).

International transfers

We work from more than one country, including India, and some of the tools we use store or process data in the United States and other countries. So your information may be handled outside the country where you live. Where UK data protection law applies, we rely on recognised safeguards, such as UK adequacy regulations or standard data protection clauses (for example, the UK International Data Transfer Addendum) offered by our providers. Whichever country your data is in, we protect it as this policy describes. For Australian residents: by working with us you understand that your information may be held overseas as described here, and we take reasonable steps to make sure overseas providers handle it consistently with the Australian Privacy Principles.

How long we keep it

  • Audit requests and related emails: while we're in touch about your website, then up to 24 months, so we have a record of what we sent you.
  • Outreach details (if you didn't reply): deleted within 12 months of our last email.
  • Do-not-contact list: for as long as we send business emails, so your opt-out keeps working.
  • Client records: for as long as we need them for the work, then as long as tax and accounting laws require (usually 6 to 8 years for invoices).
  • Website logs: kept by our hosting provider for a short period, usually a few weeks.

You can ask us to delete your information sooner (see Your rights).

Security

We use reputable providers, encrypted connections (HTTPS), strong passwords with two-step login where available, and access only for people who need it. No system is perfectly secure, so we keep what we collect to a minimum. If a breach affects your personal information in a way the law says we must report, we'll tell you and the regulator.

Your rights

Wherever you are, you can ask us to tell you what we hold about you, correct it, delete it, or stop contacting you. Email info@shivohamprime.com. We may ask you to confirm it's really you, and we'll reply within 30 days. It's free.

United Kingdom (and EU)

Under the UK GDPR you have the right to: access your data; have it corrected; have it erased; restrict how we use it; object to how we use it (including an absolute right to object to direct marketing); data portability; and withdraw consent at any time. If you're unhappy with how we've handled your data, please tell us first, and you can also complain to the Information Commissioner's Office (ICO) at ico.org.uk.

Australia

Under the Privacy Act 1988 and the Australian Privacy Principles you can ask to access the personal information we hold about you and to have it corrected. You can also tell us you don't want to receive direct marketing from us. If you have a complaint, contact us first; we'll respond within 30 days. If you're not satisfied, you can complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.

United States

Every commercial email we send includes a working opt-out, as the CAN-SPAM Act requires, and we honor opt-outs immediately. Some states, such as California, give residents the right to know what personal information a business collects, to access it, to correct it, to delete it, and to opt out of its "sale" or "sharing". We don't sell or share personal information, and we honor access, correction and deletion requests from anyone in the US, whether or not a state law requires it. We won't treat you differently for using these rights. You can also make a request through an authorized agent.

Children

This website and our services are for businesses. They're not directed at children, and we don't knowingly collect personal information from anyone under 16. If you think a child has sent us information, email us and we'll delete it.

Changes to this policy

If we change this policy, we'll update this page and the date at the top. If a change is significant, we'll make it clear on the site.

Contact

Shivoham Prime · info@shivohamprime.com

Questions about this page?

Email info@shivohamprime.com. A person reads every message and replies within 1 business day.

Free Website Audit

Find out what your website is costing you.

Send us your website. Within 2 business days you get a short audit: what's losing you inquiries, the proof, and what to fix first. Free, and yours to use with anyone.

Prefer a quick call? Book 20 minutes with us

Get my free website audit