Work Services About Blog Contact WhatsApp
Legal

Privacy Policy

This policy explains what personal data Mind Your Ads collects, why we collect it, who we share it with, how long we keep it, and what you can ask us to do about it. It is written to be read rather than skimmed past, and it describes what this website actually does — not a template.

Last updated: 11 September 2026

The short version

Everything below in plain English, with the detail underneath.

  • If you fill in our enquiry form we collect your name, email, phone number, the service you picked, your message, the page you came from and your IP address. We use it to reply to you and nothing else.
  • This website runs Google Analytics 4. It sets cookies and tells us how many people visit which pages. It does not tell us who you are.
  • We do not sell personal data, and we never have. We do not run advertising pixels on this site and we do not add you to a mailing list because you sent an enquiry.
  • You can ask us what we hold about you, ask us to correct it, or ask us to delete it. Email contact@mindyourads.com and we will deal with it within 30 days.
  • If you are a client, the data we touch inside your ad accounts and analytics stays yours. We are a processor acting on your instructions, and it stays in accounts you own.

Who we are

Mind Your Ads is a digital marketing agency operating in India and the United States. For the purposes of India's Digital Personal Data Protection Act, 2023 we are a Data Fiduciary in respect of the data described below. For the purposes of the UK and EU GDPR we are a controller of that same data.

Privacy questions, requests and complaints all go to the same place: contact@mindyourads.com, marked Privacy. That address is monitored by the person responsible for data protection at Mind Your Ads, who acts as our point of contact for grievances under the DPDP Act.

What we collect

Data you give us

The enquiry form on this site collects exactly the following, and nothing more:

  • Name — so we can address you properly.
  • Email address — so we can reply.
  • Phone number — so we can call or message you if that is faster.
  • Service selected — optional, so the right specialist picks it up.
  • Your message — optional.

Please do not put financial details, identity document numbers, health information or account passwords in the message field. We do not need any of it to answer an enquiry, and we would rather not hold it.

Data collected automatically with the form

  • The page the enquiry was sent from — so we know what you were reading.
  • Your IP address — recorded once, with the enquiry, as an anti-spam and abuse measure. It is not used to profile you or to build a location history.

The form also contains a hidden field that human visitors never see. If it is filled in, we treat the submission as automated and discard it. This is why we do not need to put a CAPTCHA in front of you.

Data collected as you browse

  • Google Analytics 4 — pages viewed, approximate location derived from IP at country or city level, device and browser type, how you arrived, and how long you stayed. Google truncates IP addresses for GA4 and we have no access to the full address through it.
  • Server logs — our host records requests, including IP address, timestamp and user agent, for security and diagnostics.

Data we collect if you become a client

During an engagement we hold business contact details, billing information, the contents of our correspondence, and access to the marketing accounts you grant us. This is covered in more detail under data we handle for clients.

Cookies and analytics

We do not run advertising or remarketing pixels on this website. There is no Meta pixel, no LinkedIn Insight Tag, no TikTok pixel and no third-party advertising cookie. What we do set is listed here in full.

NameSet byPurposeLifetime
_ga, _ga_*Google Analytics 4Distinguishes one visitor from another so we can count visits and see which pages are readUp to 2 years
mindyourads_sessionThis websiteKeeps your session while you use the site; required for the enquiry form to workBrowser session
XSRF-TOKENThis websiteSecurity token that stops other sites submitting our form as youBrowser session
mya-fab-nudgeThis website (session storage, not a cookie)Remembers that the contact shortcut has already been shown once, so it is not shown againUntil you close the tab

How to switch analytics off. Any of these work:

  • Install Google's official Analytics opt-out browser add-on, which blocks GA on every site you visit.
  • Block cookies for this site in your browser settings, or use a private window.
  • Use a browser or extension that blocks analytics scripts. We do not attempt to work around them.

The session and security cookies cannot be switched off separately, because the enquiry form cannot function without them. If you block all cookies, you can still read every page — the form just will not submit.

Why we use it, and on what basis

Where the GDPR applies, we must have a lawful basis for each purpose. Where the DPDP Act applies, processing rests on your consent or on a legitimate use permitted by the Act. This table sets out both.

What we doData usedBasis
Reply to your enquiry and discuss working togetherName, email, phone, service, messageYour consent, given by submitting the form; steps taken at your request before a contract
Stop spam and abuse of the formIP address, hidden fieldOur legitimate interest in keeping the form usable
Deliver services you have engaged us forBusiness contact details, account access, correspondencePerformance of our contract with you
Invoice you and keep accountsBilling details, transaction recordsLegal obligation under tax and companies law
Understand how the website is usedAnalytics dataOur legitimate interest in improving the site; consent where local law requires it
Keep the site and its data secureServer logsOur legitimate interest in security; legal obligation to safeguard data

We do not use your enquiry to add you to a marketing list. If we ever want to send you something you did not ask for, we will ask first, and it will be as easy to stop as it was to start.

Who we share it with

We do not sell personal data and we do not trade it. We share it only with the suppliers who make the service work:

  • Our hosting provider — stores the website and its database, which is where enquiries are held.
  • Our email provider — delivers the notification of your enquiry to us and carries our reply to you.
  • Google (Analytics) — processes website usage data as described above.
  • Our client-management system — where an enquiry becomes a live conversation, it is tracked in a hosted CRM restricted to our team.
  • Professional advisers — accountants and, if ever needed, lawyers, under a duty of confidence.

Each of these acts on our instructions under a contract, and none of them is permitted to use your data for their own purposes. We would also disclose data where the law requires it — a court order, a valid request from a regulator or law enforcement — and we would tell you unless we were prohibited from doing so.

International transfers

We operate in India and the United States, so data may be processed in either country, and our suppliers may process it elsewhere. Where personal data covered by the UK or EU GDPR leaves that jurisdiction, we rely on the transfer mechanisms available to us — most commonly the European Commission's Standard Contractual Clauses, which our major suppliers incorporate as standard. The DPDP Act permits transfer outside India except to countries the Central Government restricts; we will comply with any such restriction if one is notified.

How long we keep it

WhatHow longWhy
Enquiries that do not become clients24 months, then deletedEnquiries often revive months later; after two years it is no longer reasonable to hold it
Client records while engagedFor the life of the engagementWe cannot do the work without them
Client records after the engagement ends8 yearsIndian tax and companies law record-keeping
Invoices and financial records8 yearsStatutory retention
Analytics data14 months in GA4Google's retention setting; aggregate reports persist
Server logsTypically 30–90 daysSecurity investigation window

If you ask us to delete your data sooner, we will, unless we are required to keep a specific record by law — in which case we will tell you which record and why.

How we protect it

  • The whole site is served over HTTPS, so what you type into the form is encrypted in transit.
  • The enquiry form is protected against cross-site request forgery, and submissions are rate-limited.
  • Input is sanitised before it is stored, which prevents stored scripting attacks against our own team viewing enquiries.
  • Access to the admin area is restricted to named accounts, and the number of people who can see enquiry data is deliberately small.
  • Access to client marketing accounts is granted to named individuals, never to shared logins.

No system is perfectly secure, and anyone who tells you otherwise is selling something. If a breach affects your personal data we will notify the relevant authority and you as required — under the DPDP framework that means informing the Data Protection Board promptly and providing a detailed report within 72 hours, and under the GDPR, notifying the supervisory authority within 72 hours where the breach is likely to result in a risk to you.

Data we handle for clients

This is the part most agency privacy policies leave out, and it is the part that matters most if you hire us.

When we run campaigns for you, we work inside Google Ads, Meta, analytics and CRM accounts that you own. For any personal data in those accounts — your customers' data, your leads, your audience lists — you are the Data Fiduciary or controller and we act as a Data Processor on your documented instructions. That means:

  • We access your accounts through our own named user accounts, linked to yours. We do not create accounts in our name that hold your data.
  • We process that data only to do the work you have asked for, never for our own purposes, and never to benefit another client.
  • We do not export your customer lists, and we do not take copies when an engagement ends. Removing our access is enough, and it is a change you can make yourself in seconds.
  • If you need a data processing agreement for your own compliance file, ask and we will sign one.
  • If a supervisory authority or a customer of yours asks you about data we touched, we will help you answer.

We will also tell you when something you have asked for would create a compliance problem — an audience list assembled without consent, a customer-match upload without the right permissions, or tracking that captures more than it should. That conversation is part of the job.

Your rights

If you are in India (DPDP Act, 2023)

  • Access — a summary of the personal data we process about you and what we do with it.
  • Correction and erasure — have inaccurate or incomplete data corrected or completed, and have data erased once the purpose it was collected for is finished.
  • Withdraw consent — as easily as you gave it. Email us and we will act on it.
  • Grievance redressal — raise a complaint with us first. We will respond, and we will not take the maximum 90 days permitted to do it.
  • Nomination — nominate another person to exercise these rights on your behalf in the event of death or incapacity.
  • Escalation — if our response does not satisfy you, you may complain to the Data Protection Board of India.

A note on timing: the DPDP Rules were notified in November 2025 and the substantive obligations phase in through to 13 May 2027. We have written this policy to meet them now rather than closer to the deadline, and we will honour these rights from today.

If you are in the UK or EU (GDPR)

  • Access, rectification and erasure of your personal data.
  • Restriction of processing, and objection to processing based on legitimate interests.
  • Data portability, where processing is based on consent or contract and carried out by automated means.
  • Withdrawal of consent at any time, without affecting processing already carried out.
  • Complaint to your national supervisory authority, or to the ICO in the United Kingdom.

If you are in the United States

There is no comprehensive federal privacy law, and state laws apply by threshold. The California Consumer Privacy Act, as amended, applies to businesses above at least one of three thresholds: more than $25 million in annual gross revenue, personal information of 100,000 or more California consumers or households, or 50% or more of revenue from selling or sharing personal information. We are below all three, so the CCPA does not currently impose obligations on us.

We would rather not hide behind that. If you are a US resident and you ask us for a copy of what we hold, ask us to correct it, or ask us to delete it, we will treat the request exactly as we would a request from India or the EU. For the avoidance of doubt: we do not sell or share personal information as those terms are defined in California law, and we have no financial incentive to start.

How to exercise them

Email contact@mindyourads.com with Privacy request in the subject line, and tell us what you want. You do not need to use any particular form of words, quote a law, or explain why.

  • We will acknowledge within 3 working days.
  • We will complete the request within 30 days, and sooner where we can.
  • We may ask you to confirm your identity — usually just replying from the address you contacted us with — so that we do not hand your data to somebody else.
  • There is no charge. If a request were genuinely excessive or repetitive we would explain why before doing anything, rather than quietly invoicing you.

If you are unhappy with how we handled it, say so and it will be reviewed by someone else. You can also escalate to the Data Protection Board of India, or to your supervisory authority in the UK or EU, and you do not need our permission to do that.

Children

This website is aimed at businesses and is not directed at children. We do not knowingly collect personal data from anyone under 18. Under the DPDP Act, processing a child's personal data requires verifiable parental consent, and tracking, behavioural monitoring and targeted advertising directed at children are prohibited. We do none of these things. If you believe a child has submitted data through this site, email us and we will delete it.

Changes to this policy

We will update this page when what we do changes, or when the law does. The date at the top always reflects the most recent revision. If a change materially affects how we use data we already hold, we will tell the people affected directly rather than relying on you to re-read this page.

Contact

Privacy questions, requests and complaints: contact@mindyourads.com. Postal addresses and phone numbers for both offices are listed under who we are, and on our contact page.

This policy describes our practices in plain language. It is not legal advice, and it does not replace the specific terms of any agreement between us — those are set out in our terms and conditions and in your service contract.

Google Partner certified Verify on Google ↗ +91 965-065-0212
WhatsApp us
No obligation

Get a free proposal

Tell us where to reach you and what you need. We will come back within one working day with an honest read on whether we can help — including if the answer is no.

We use your details to reply to this enquiry and nothing else. No mailing list, no sharing, no selling. See our privacy policy.