Privacy Policy

Effective date: 27 August 2026   Last updated: 27 August 2026

1. Who we are

VRankOne (“VRankOne”, “we”, “us”, “our”) operates the website vrankone.com and provides digital marketing services including search engine optimisation, content strategy, paid media management, and conversion optimisation.

For personal data collected through this website, VRankOne acts as the Data Fiduciary under India’s Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025, and as the data controller under the EU/UK General Data Protection Regulation where that law applies. Where we handle data inside a client’s own systems as part of a service engagement, we act as a Data Processor on that client’s instructions (see Section 12).

This policy explains what personal data we collect, why we collect it, who we share it with, how long we keep it, and the choices and rights available to you.

2. Scope

This policy applies to:

It does not apply to third-party websites we link to, or to our clients’ own websites, which are governed by their own privacy policies.

3. Personal data we collect

3.1 Information you give us directly

CategoryExamplesWhen collected
Identity and contact dataName, business email, phone number, company name, job title, website URL, country/cityContact form, audit request, proposal request, discovery call booking
Enquiry contentProject requirements, budget range, current marketing challenges, and anything else you type into a form or send by emailForms, email, WhatsApp, chat
Marketing preferencesNewsletter subscription status, consent records, opt-outsSign-up forms, preference centre
Commercial and billing dataBilling name and address, GSTIN, purchase order references, invoice historyClient onboarding and billing
Recruitment dataCV, work history, portfolio linksCareer applications, if applicable
CorrespondenceEmails, call notes, meeting recordings where you have been notified and have consentedOngoing communication

3.2 Information collected automatically

When you visit vrankone.com, we and our service providers may collect:

3.3 Information from third parties

3.4 What we do not collect

We do not knowingly collect government identification numbers, payment card numbers, health data, biometric data, or other special-category data through this website. Payments, where applicable, are processed by third-party payment gateways that collect card details directly; we never receive or store full card numbers.

4. Why we use your data, and our legal basis

PurposeWhat this involvesLegal basis (GDPR) / Ground (DPDP)
Responding to enquiriesReplying to your form submission, preparing an audit or proposal, scheduling a callSteps taken at your request prior to a contract; consent under DPDP Sec. 6
Delivering our servicesAccount management, reporting, invoicing, supportPerformance of a contract; certain legitimate uses under DPDP Sec. 7
Website analyticsUnderstanding which pages and campaigns work, fixing usability problemsConsent (analytics cookies); legitimate interests where cookies are not used
Advertising and remarketingMeasuring ad performance, showing our ads to people who have visited our site, building similar audiencesConsent
Marketing communicationsNewsletters, service updates, case studiesConsent, with an unsubscribe link in every message
Security and fraud preventionBlocking spam submissions, bot traffic, and abuse; maintaining logsLegitimate interests; legal obligation
Legal and accounting complianceTax records, statutory filings, responding to lawful requestsLegal obligation

We do not use your personal data for automated decision-making that produces legal or similarly significant effects on you.

5. Cookies and similar technologies

Cookies are small text files stored on your device. We also use comparable technologies such as pixels, tags, local storage, and SDKs. We group them as follows:

Strictly necessary — required for the site to function: session management, load balancing, security, and storing your cookie consent choice. These cannot be switched off.

Analytics and performance — help us understand how visitors use the site: Google Analytics 4, and, where enabled, session-behaviour tools such as Microsoft Clarity or Hotjar.

Advertising and remarketing — used to deliver and measure ads: Google Ads remarketing tags, Google Floodlight, Meta Pixel, LinkedIn Insight Tag, and similar tags from partner networks.

Functional — remember preferences such as language or form pre-fill.

Your cookie choices

On your first visit we present a consent banner. Non-essential cookies are not set until you accept them. You can change or withdraw your choice at any time through the “Cookie settings” link in our website footer. You can also block or delete cookies in your browser settings, though strictly necessary cookies are needed for parts of the site to work.

Where required, we operate Google Consent Mode v2, which adjusts how Google tags behave based on the consent signals you give.

6. Advertising, remarketing, and third-party vendors

VRankOne runs advertising campaigns on Google Ads and other networks. The following disclosures are made in line with Google’s advertiser requirements:

How to opt out of personalised advertising

Opting out stops ads from being personalised to you. It does not stop you from seeing ads.

7. Analytics

We use Google Analytics 4, provided by Google LLC, to measure traffic and campaign performance. Google Analytics sets cookies and processes data such as your IP address, device information, and on-site behaviour. IP addresses are truncated or otherwise anonymised by Google before storage where that functionality applies. Google’s privacy policy is at policies.google.com/privacy, and information on how Google uses data from sites that use its services is at policies.google.com/technologies/partner-sites.

We may also use Google Search Console, Google Tag Manager, Meta Pixel, LinkedIn Insight Tag, and Microsoft Clarity. Each of these has its own privacy policy, which we encourage you to read.

8. Who we share your data with

We share personal data only with the following categories of recipients, and only as far as necessary:

All service providers act under written agreements requiring them to protect your data, process it only on our instructions, and not use it for their own purposes, except where they act as independent controllers of their own (as Google and Meta do for advertising data).

We do not sell personal data, and we do not “share” personal data for cross-context behavioural advertising as those terms are defined under the California Consumer Privacy Act, other than through the advertising cookies described in Section 6, which you can reject.

9. International data transfers

We are based in India. Some of our service providers store or process data in the United States, the European Union, Singapore, and other jurisdictions. When personal data is transferred outside the country where it was collected, we rely on appropriate safeguards, which may include:

You may request a copy of the safeguards we rely on by writing to us at the address in Section 16.

10. How long we keep your data

DataRetention period
Website enquiry that does not convert24 months from last contact, then deleted or anonymised
Client records and correspondenceDuration of the engagement plus 3 years
Invoices, tax, and statutory records8 years, or as required by Indian tax and company law
Newsletter subscriber dataUntil you unsubscribe, plus a suppression record so we do not contact you again
Analytics dataUp to 14 months in Google Analytics 4, subject to platform settings
Cookie consent records12 months, or until you change your choice
Server and security logs12 months
Recruitment data12 months, unless you ask us to delete it sooner

Where a longer period is required by law or by an ongoing legal claim, we retain the data for that period and then delete it.

11. Security

We apply reasonable technical and organisational safeguards, including HTTPS/TLS encryption in transit, access control on a need-to-know basis, multi-factor authentication on business-critical accounts, regular software and plugin updates, hardened WordPress configuration, firewall and bot filtering, and periodic backups.

No method of transmission or storage is completely secure. If a personal data breach occurs that is likely to affect you, we will notify you and the relevant supervisory authority within the timelines required by applicable law, including intimation to the Data Protection Board of India and to affected Data Principals under the DPDP Rules, 2025, and within 72 hours to the competent supervisory authority under the GDPR where it applies.

12. Data we process on behalf of clients

As a marketing agency, we are often granted access to a client’s Google Analytics, Google Search Console, Google Ads, Meta Business Manager, CMS, or ecommerce platform. Any personal data of that client’s own customers or visitors within those systems is processed by us as a Data Processor, strictly on the client’s documented instructions and under a service agreement or Data Processing Addendum.

In that role we do not decide the purposes of processing, we do not copy client end-customer data into our own systems except where required to deliver the agreed service, and we delete or return such data at the end of the engagement. If you are an end customer of one of our clients, please direct privacy requests to that business in the first instance; we will assist them in responding.

13. Your rights

13.1 If you are in India (DPDP Act, 2023)

As a Data Principal, you have the right to:

You also have duties under the Act, including not raising false or frivolous complaints and providing authentic information when exercising the right to correction.

13.2 If you are in the EEA, UK, or Switzerland (GDPR / UK GDPR)

You have the right to access, rectification, erasure, restriction of processing, data portability, and objection to processing based on legitimate interests or direct marketing. You may withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal. You also have the right to lodge a complaint with your local supervisory authority, or with the UK Information Commissioner’s Office.

13.3 If you are in California or another US state with a privacy law

You have the right to know what personal information is collected, used, and disclosed; to delete it; to correct it; to opt out of sale or sharing for cross-context behavioural advertising; to limit the use of sensitive personal information; and not to receive discriminatory treatment for exercising these rights. We honour Global Privacy Control signals as a valid opt-out of sharing where technically supported. An authorised agent may submit a request on your behalf with proof of authorisation.

13.4 How to exercise your rights

Write to connect@vrankone.com with the subject line “Privacy Request”, telling us which right you wish to exercise and from which email address or form submission you contacted us. We may ask for information to verify your identity, so that we do not disclose data to the wrong person.

We respond within 30 days. If the request is complex, we may extend this and will tell you why. Exercising these rights is free of charge unless a request is manifestly unfounded or excessive.

14. Children’s data

Our website and services are directed at businesses, not children. We do not knowingly collect personal data from children.

Under India’s DPDP Act, a “child” is any individual under 18 years of age, and processing their personal data requires verifiable consent from a parent or lawful guardian. We do not undertake tracking, behavioural monitoring, or targeted advertising directed at children. Under the GDPR, the relevant age is 16, or lower where a member state has set a lower threshold.

If you believe a child has provided us with personal data, contact us and we will delete it.

15. Other disclosures

Third-party links. Our website links to external sites, including client websites, case studies, and social platforms. We are not responsible for their privacy practices.

Do Not Track. Browsers vary in how they implement Do Not Track and there is no common standard, so we do not respond to DNT headers. We do honour Global Privacy Control signals and our own cookie consent controls.

Changes to this policy. We may update this policy to reflect changes in our practices or the law. The revised version takes effect when posted, and we will update the “Last updated” date at the top. Where changes are material, we will provide prominent notice on the website or by email before they take effect.

16. Contact and grievance redressal

Grievance Officer / Privacy Contact
Kaustav Sinha, Co-founder
VRankOne, 59, Baridas Temple Street, Kolkata, West Bengal 700004, India
Email: connect@vrankone.com
Response time: acknowledgement within 72 hours, resolution within 30 days

If you are not satisfied with our response, you may escalate to the Data Protection Board of India, or to your local data protection authority if you are in the EEA or the UK.

This policy is published in English. If a translated version conflicts with this version, the English version prevails.