Privacy Policy
Effective 18 July 2026
1. Who is responsible for your data
techdevcity.com is operated by MyDigiShell, a software practice based in India working with clients internationally. MyDigiShell is a registered trading name rather than a separate company. We are the data controller. Within the team, access to your information is limited to the people who need it to answer your enquiry or work on your engagement, and everyone is bound by the same confidentiality obligations.
For any privacy question, or to exercise any right described below, email mijanur@mydigishell.com.
2. What we collect
- Contact form submissions: your name, email address, optionally a company name, which service you selected, and the content of your message.
- Quotation requests: the options you selected, the resulting estimate, any discount code applied, and your contact details. These are stored in our database so a quotation can be retrieved, referenced and honoured later.
- Account data: if you create an account to track your quotes and orders, we store your name, email address and a securely hashed password. We never store the password itself.
- Technical data processed in transit: when your browser requests a page or submits a form, the infrastructure provider processes your IP address and request metadata to serve the request and block automated abuse. We do not build profiles from this.
Please do not send credentials, production data, or anyone else's personal information through this site. If an engagement needs system access, that is arranged separately under a written agreement.
3. Accounts, cookies and sessions
There are no advertising or analytics trackers anywhere on this site. The only cookie we set is a session cookie after you sign in: it holds a random token, is marked HttpOnly so scripts cannot read it, and lets you stay signed in. Signing out deletes the session on our side, so the cookie stops working immediately. The automated-abuse check on our forms may set storage necessary to confirm a submission is not a bot; it is not used to track you across sites.
4. Payments
Payment is handled entirely by the payment provider on their own checkout — currently PayPal for international clients. Card numbers, UPI credentials and bank details are never entered on this site, never transmitted through it, and never reach any system we control. We receive confirmation that a payment succeeded, the amount, and which quotation it relates to. The payment provider is an independent controller of the data you give them, under their own privacy policy.
5. Why we collect it, and on what basis
To read and reply to your enquiry, to prepare and honour quotations, to let you track your quotes and orders, and where it leads to work, to carry out and invoice that engagement. Under the GDPR this rests on our legitimate interest in responding to someone who has deliberately contacted us, and on steps taken at your request prior to and under a contract. Your details are never used for marketing, and there is no mailing list to be added to.
6. Who else processes it
A small number of providers process this data strictly to deliver the service:
- Our hosting and database provider — runs the API and the PostgreSQL database that stores accounts, quotations and orders (a managed provider such as Neon or Supabase, or our own server).
- Cloudflare — serves the site at the edge and provides the automated-abuse check on our forms.
- Resend — delivers submissions and quotation copies as email.
- Google Workspace — hosts the mailbox those messages arrive in.
- PayPal — processes payments where you choose to pay online.
Nothing is sold, shared for advertising, or passed to anyone else. We would disclose data only where legally compelled to.
7. Where your data goes
We are based in India, and the providers above operate infrastructure in the United States, the European Union and elsewhere. If you contact us from outside India, your data will be transferred and processed internationally, which is inherent to working with a team in another country.
8. How long we keep it
- Enquiries that do not lead to work are deleted once the conversation is clearly over — generally within twelve months.
- Quotations are kept for twelve months from issue so the price can be honoured and referenced, then deleted unless they led to an engagement.
- Accounts are kept while active; ask us and we will close and delete yours, subject only to records we must keep for tax.
- Records relating to actual engagements and payments are retained for as long as needed for the work and for the tax and accounting obligations that follow it.
9. Your rights
You can ask us for a copy of what we hold about you, correct it, delete it, or stop using it. Email mijanur@mydigishell.com and we will action it within thirty days, subject only to records we are legally required to keep for tax purposes. If you are in the UK or EU and think we have handled your data badly, you may complain to your local supervisory authority.
10. Security
The site is served over HTTPS and submissions are encrypted in transit. Passwords are stored using Argon2id hashing, never in a readable form. Session tokens are stored only as a hash, so a database leak would not hand anyone a working session. The administrative area is behind authentication and role checks, so only staff accounts can reach client data, and only senior staff can manage the business. No system is perfect, and we would rather say that plainly than claim a standard we cannot audit.
11. Changes
If this policy changes materially, the effective date above changes with it. The current version is always the one published here.