Legal
Privacy Policy
This explains what we collect, why, who else sees it, and what you can make us do about it. It is written to be read rather than to be survived.
1. Who we are
Flying Star Technologies (“Flying Star”, “we”, “us”) is a web development, ecommerce and digital marketing business operating from Krishna Niwas, A 203, Iraniwadi Road No. 3, Kandivali West, Mumbai 400067, Maharashtra, India.
For the purposes of the Digital Personal Data Protection Act, 2023, we act as a Data Fiduciary in respect of personal data you give us directly. Where we work inside a client’s own systems — their website, their analytics, their advertising accounts — we act as a Data Processor on that client’s instructions, and the client remains the Data Fiduciary for the data held there.
This policy covers flyingstar.in and our subdomains. Third-party websites we link to have their own policies and we are not responsible for them.
2. What we collect
Information you give us. When you submit an enquiry form we collect your name, email address, phone number if you provide it, your website address if you provide it, the service you selected, and whatever you write in the message field. When you contact us on WhatsApp, by email or by phone, we hold that correspondence.
Information collected automatically. Our hosting provider records standard server logs, which include IP address, browser type, the pages requested and the time of the request. These exist for security and diagnostics.
Analytics. This website uses Google Analytics 4. It records which pages were viewed, how they were reached, the browser and device type, and approximate location at city level. Google uses your IP address to derive that location and does not store it. We do not use analytics to identify individual visitors, and we have turned off the setting that would let this data feed advertising audiences.
Client account access. When you engage us, you may grant us access to your Google Search Console, Google Analytics, Google Ads, Meta Business Manager, Merchant Center, hosting control panel or website administration. Through that access we may see data belonging to your business and your customers.
What we do not collect. We do not collect payment card details on this website. We do not ask for and do not want your Aadhaar, PAN, bank credentials or any government identifier through this site. We do not buy personal data from third parties.
4. Why we use your data
To reply to your enquiry and, where you have asked for it, to prepare an audit or a quote for you.
To deliver the services you have engaged us for, and to support them afterwards.
To raise invoices and maintain the books and records we are required by law to keep.
To keep our website and our clients’ websites secure, and to investigate misuse.
To comply with a legal obligation, a court order or a lawful request from an authority.
We do not sell your personal data. We do not rent it, trade it, or hand it to data brokers. We do not add you to a marketing list because you filled in an enquiry form — if you want to hear from us periodically you have to ask.
5. Consent and lawful use
We process personal data on the basis of your consent, which you give by submitting a form or contacting us, and for the legitimate uses permitted under Section 7 of the Digital Personal Data Protection Act, 2023 — including where you have voluntarily provided data for a specified purpose and have not indicated any objection.
Consent is not a trap. You may withdraw it at any time by writing to us at [email protected]. Withdrawing consent does not make anything we did before it unlawful, and it does not remove records we are legally required to retain, such as invoices.
Where withdrawing consent means we can no longer deliver a service you are paying for, we will tell you that clearly rather than quietly stopping.
7. Data outside India
Some of the providers above operate servers outside India. Where personal data is transferred outside India it is done in accordance with the Digital Personal Data Protection Act, 2023, and only to countries not restricted by the Central Government.
We keep the list of providers deliberately short, which is the most effective control available to a business our size.
8. How long we keep it
Enquiries that do not become projects are kept for up to 24 months, then deleted, so that we can pick up a conversation if you come back to us.
Client project records are kept for the duration of the engagement and for up to three years afterwards, so that we can support work we delivered.
Invoices, contracts and accounting records are kept for eight years, as required under Indian tax and company law.
Website analytics is held by Google for the retention period set on our Analytics property. It is aggregated usage data and is not linked to your enquiry, your name or your email address.
Access to your platform accounts is used only for as long as the engagement lasts. When it ends, ask us to be removed and we will confirm once it is done — and you should remove us yourself as well, which is good practice regardless of who your agency is.
9. Your rights
Under the Digital Personal Data Protection Act, 2023 you have the right to:
Access a summary of the personal data we hold about you and what we do with it.
Correction, completion and updating of data that is inaccurate or incomplete.
Erasure of personal data where we no longer need it for the purpose it was given, and where no law requires us to keep it.
Grievance redressal — to raise a complaint with us and get a response, before escalating to the Data Protection Board of India.
Nomination — to nominate another person to exercise these rights on your behalf in the event of death or incapacity.
To exercise any of these, write to [email protected] from the email address concerned. We respond within 30 days. There is no charge for a reasonable request.
10. Security
We maintain reasonable security practices and procedures as required under Section 43A of the Information Technology Act, 2000 and the rules made under it. In practice: the site is served over HTTPS, access to client systems is held by a small number of people, credentials are stored in a password manager rather than in email or chat, and access is reviewed when an engagement ends.
We ask clients to send credentials through a password manager share rather than over email or WhatsApp, and we will say so if you send them the other way.
No system is perfectly secure. If a personal data breach affects you, we will notify you and the Data Protection Board of India as required, and we will tell you what actually happened rather than a sanitised version of it.
11. Children
Our services are sold to businesses and are not directed at children. We do not knowingly collect the personal data of anyone under 18. If you believe a child has given us personal data, write to us and we will delete it.
12. Grievance Officer
In accordance with the Information Technology Act, 2000 and the rules made under it, and the Digital Personal Data Protection Act, 2023, complaints about the handling of personal data may be addressed to our Grievance Officer:
Niral Sura — Grievance Officer, Flying Star Technologies
Krishna Niwas, A 203, Iraniwadi Road No. 3
Kandivali West, Mumbai 400067, Maharashtra, India
Email: [email protected]
Phone: +91 97696 65665
Hours: Monday to Saturday, 10:00 to 18:00 IST
We acknowledge complaints within 48 hours and resolve them within 30 days. If you are not satisfied with the outcome, you may escalate to the Data Protection Board of India.
13. Changes to this policy
We update this policy when what we do changes, or when the law changes. The effective date at the top always reflects the current version. Material changes affecting existing clients are communicated directly rather than left to be discovered.
Anything here you want explained?
These are the terms we actually work under, not boilerplate copied off another site. If a clause is unclear, or you want it changed for your engagement, ask — it is a conversation, not a wall.
No pitch deck, no obligation. Bring your URL and we will look at it together.