Information We Collect
PV Cristal collects data strictly required to deliver agile web development, native Android applications, and targeted marketing deployments. Data is grouped into the following classifications:
Names, corporate email addresses, direct phone numbers, project scopes, and billing identifiers submitted via quote requests or discovery sessions.
IP coordinates, browser user-agent tokens, session duration metrics, screen view paths, and performance logs collected via diagnostics.
How We Use Information
We leverage collected signals under lawful, explicit bases under the Indian Digital Personal Data Protection Act (DPDPA 2023) and cross-border standards:
- check_circle Contract Delivery: Designing, configuring, and publishing websites, mobile applications, and lead engines agreed upon in client service agreements.
- check_circle Ad Optimization & Attribution: Measuring cost-per-acquisition (CPA), conversion rates, and user journeys across paid Meta and Google marketing channels.
- check_circle Infrastructure Safeguarding: Preventing automated denial of service (DoS), malicious scrapers, and fraudulent lead injection attacks.
Cookies & Tracking Technologies
We employ first-party and trusted tracking identifiers to sustain session states, retain user preferences, and observe user interaction vectors.
Lead Forms & Meta/Google Pixel Handling
Every prospect record acquired through campaigns engineered by PV Cristal belongs 100% exclusively to the contracting client. We never pool, cross-target, resell, or co-mingle your leads with competitor portfolios.
When orchestrating ad campaigns via Meta Conversions API (CAPI), Meta Pixel, Google Tag Manager, or Google Ads Conversion Tracking:
Personally Identifiable Information (PII) like emails and telephone numbers are normalized and SHA-256 hashed on modern servers before transmission, ensuring privacy compliance with Meta and Google endpoints.
Campaign inquiries bypass intermediary open brokers. Data streams instantly via secured webhook directly into the client's localized CRM, WhatsApp business gateway, or password-protected Google Workspace.
Third-Party Disclosures
We never monetize, rent, or trade private user records. Disclosures occur exclusively with verified service infrastructure partners bound by rigorous data-handling contracts:
Data Security & Storage Architecture
Security at PV Cristal is engineered into the software development pipeline from day zero:
Client repositories and configuration variables are protected using AES-256 keys.
All web endpoints utilize strict Transport Layer Security (TLS 1.3) with forward secrecy.
Internal developer access operates under strict least-privilege rules with mandatory 2FA.
Your Rights & Access Requests
Under India's Digital Personal Data Protection Act (DPDPA 2023) and global benchmarks, you have unequivocal rights:
Third-Party Hyperlinks
Our site and portfolio showcases feature outbound links to third-party domains (such as GitHub, Figma, Meta ad dashboards, and live client URLs). PV Cristal maintains no jurisdiction over the external privacy routines of these autonomous web environments.
Changes to This Policy
As digital advertising frameworks, privacy directives, and web technologies progress, PV Cristal may publish updated versions of this document. Revisions will post here accompanied by an updated effective date timestamp.
Data Protection Officer (DPO)
For compliance audits, data subject requests, or questions regarding our processing protocols: