Privacy Policy
Effective date: 27 August 2026 Last updated: 27 August 2026
1. Who we are
VRankOne (“VRankOne”, “we”, “us”, “our”) operates the website vrankone.com and provides digital marketing services including search engine optimisation, content strategy, paid media management, and conversion optimisation.
- Legal entity: VRankOne
- Registered address: 59, Baridas Temple Street, Kolkata, West Bengal, 700004, India
- Email: connect@vrankone.com
For personal data collected through this website, VRankOne acts as the Data Fiduciary under India’s Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025, and as the data controller under the EU/UK General Data Protection Regulation where that law applies. Where we handle data inside a client’s own systems as part of a service engagement, we act as a Data Processor on that client’s instructions (see Section 12).
This policy explains what personal data we collect, why we collect it, who we share it with, how long we keep it, and the choices and rights available to you.
2. Scope
This policy applies to:
- The website vrankone.com and all its subdomains and landing pages
- Enquiry forms, audit request forms, newsletter sign-ups, and downloadable resources hosted by us
- Marketing emails, calls, and messages we send you
- Advertising we run on Google, Meta, LinkedIn, and other networks that links back to our website
It does not apply to third-party websites we link to, or to our clients’ own websites, which are governed by their own privacy policies.
3. Personal data we collect
3.1 Information you give us directly
| Category | Examples | When collected |
|---|---|---|
| Identity and contact data | Name, business email, phone number, company name, job title, website URL, country/city | Contact form, audit request, proposal request, discovery call booking |
| Enquiry content | Project requirements, budget range, current marketing challenges, and anything else you type into a form or send by email | Forms, email, WhatsApp, chat |
| Marketing preferences | Newsletter subscription status, consent records, opt-outs | Sign-up forms, preference centre |
| Commercial and billing data | Billing name and address, GSTIN, purchase order references, invoice history | Client onboarding and billing |
| Recruitment data | CV, work history, portfolio links | Career applications, if applicable |
| Correspondence | Emails, call notes, meeting recordings where you have been notified and have consented | Ongoing communication |
3.2 Information collected automatically
When you visit vrankone.com, we and our service providers may collect:
- IP address (and the approximate city/region derived from it)
- Browser type and version, operating system, device type, screen resolution, language
- Referring URL, landing page, exit page, pages viewed, time on page, scroll depth, clicks
- Date and time of visit and session duration
- Cookie identifiers, device identifiers, and advertising identifiers
- Google Ads click identifier (GCLID), Meta click identifier (FBCLID), UTM campaign parameters
- Error logs and security event logs
3.3 Information from third parties
- Advertising and analytics platforms (Google, Meta, LinkedIn, Microsoft) that report aggregated or pseudonymised performance data to us
- Lead sources such as referral partners, review directories, or marketplaces where you submitted an enquiry
- Publicly available business information (company website, LinkedIn company page) used to qualify a business enquiry
3.4 What we do not collect
We do not knowingly collect government identification numbers, payment card numbers, health data, biometric data, or other special-category data through this website. Payments, where applicable, are processed by third-party payment gateways that collect card details directly; we never receive or store full card numbers.
4. Why we use your data, and our legal basis
| Purpose | What this involves | Legal basis (GDPR) / Ground (DPDP) |
|---|---|---|
| Responding to enquiries | Replying to your form submission, preparing an audit or proposal, scheduling a call | Steps taken at your request prior to a contract; consent under DPDP Sec. 6 |
| Delivering our services | Account management, reporting, invoicing, support | Performance of a contract; certain legitimate uses under DPDP Sec. 7 |
| Website analytics | Understanding which pages and campaigns work, fixing usability problems | Consent (analytics cookies); legitimate interests where cookies are not used |
| Advertising and remarketing | Measuring ad performance, showing our ads to people who have visited our site, building similar audiences | Consent |
| Marketing communications | Newsletters, service updates, case studies | Consent, with an unsubscribe link in every message |
| Security and fraud prevention | Blocking spam submissions, bot traffic, and abuse; maintaining logs | Legitimate interests; legal obligation |
| Legal and accounting compliance | Tax records, statutory filings, responding to lawful requests | Legal obligation |
We do not use your personal data for automated decision-making that produces legal or similarly significant effects on you.
5. Cookies and similar technologies
Cookies are small text files stored on your device. We also use comparable technologies such as pixels, tags, local storage, and SDKs. We group them as follows:
Strictly necessary — required for the site to function: session management, load balancing, security, and storing your cookie consent choice. These cannot be switched off.
Analytics and performance — help us understand how visitors use the site: Google Analytics 4, and, where enabled, session-behaviour tools such as Microsoft Clarity or Hotjar.
Advertising and remarketing — used to deliver and measure ads: Google Ads remarketing tags, Google Floodlight, Meta Pixel, LinkedIn Insight Tag, and similar tags from partner networks.
Functional — remember preferences such as language or form pre-fill.
Your cookie choices
On your first visit we present a consent banner. Non-essential cookies are not set until you accept them. You can change or withdraw your choice at any time through the “Cookie settings” link in our website footer. You can also block or delete cookies in your browser settings, though strictly necessary cookies are needed for parts of the site to work.
Where required, we operate Google Consent Mode v2, which adjusts how Google tags behave based on the consent signals you give.
6. Advertising, remarketing, and third-party vendors
VRankOne runs advertising campaigns on Google Ads and other networks. The following disclosures are made in line with Google’s advertiser requirements:
- We use remarketing and similar audiences features to advertise our services online. This means that after you visit vrankone.com, our ads may be shown to you on other websites, apps, and platforms you visit.
- Third-party vendors, including Google, show our advertisements on sites across the internet.
- Third-party vendors, including Google, use cookies and device identifiers to serve advertisements based on your past visits to our website.
- We use Google Analytics Advertising features, which may include Google Signals, demographic and interest reporting, and audience lists built from analytics data. These rely on Google advertising cookies and identifiers.
- We do not send personally identifiable information such as your name, email address, or phone number to Google through our website tags. Where we use Customer Match or a similar audience-upload feature, we do so only with data collected under a lawful basis and in accordance with the platform’s own policies.
- We do not sell your personal data, and we do not share it with third parties for their own independent marketing purposes.
How to opt out of personalised advertising
- Google ad personalisation: My Ad Center (or adssettings.google.com)
- Google Analytics: install the Google Analytics Opt-out Browser Add-on
- Multiple vendors at once: Network Advertising Initiative and Digital Advertising Alliance (or youradchoices.com)
- EU users: Your Online Choices
- Mobile devices: reset or limit your advertising identifier in your device privacy settings (iOS: Allow Apps to Request to Track; Android: Delete advertising ID)
- On our site: reject advertising cookies in the consent banner or the “Cookie settings” link
Opting out stops ads from being personalised to you. It does not stop you from seeing ads.
7. Analytics
We use Google Analytics 4, provided by Google LLC, to measure traffic and campaign performance. Google Analytics sets cookies and processes data such as your IP address, device information, and on-site behaviour. IP addresses are truncated or otherwise anonymised by Google before storage where that functionality applies. Google’s privacy policy is at policies.google.com/privacy, and information on how Google uses data from sites that use its services is at policies.google.com/technologies/partner-sites.
We may also use Google Search Console, Google Tag Manager, Meta Pixel, LinkedIn Insight Tag, and Microsoft Clarity. Each of these has its own privacy policy, which we encourage you to read.
8. Who we share your data with
We share personal data only with the following categories of recipients, and only as far as necessary:
- Hosting and infrastructure providers — website hosting, CDN, DNS, backups
- Analytics and advertising platforms — Google, Meta, LinkedIn, Microsoft
- CRM, email, and marketing automation providers — for managing enquiries and sending communications
- Communication and productivity tools — email, cloud storage, video conferencing, project management
- Payment gateways, banks, and accounting professionals — for billing and statutory compliance
- Professional advisers — lawyers, auditors, insurers, where reasonably required
- Government authorities, courts, or law enforcement — where we are legally obliged to disclose, or to establish, exercise, or defend legal claims
- A successor entity — in the event of a merger, acquisition, or sale of assets, in which case you will be notified of any change in how your data is handled
All service providers act under written agreements requiring them to protect your data, process it only on our instructions, and not use it for their own purposes, except where they act as independent controllers of their own (as Google and Meta do for advertising data).
We do not sell personal data, and we do not “share” personal data for cross-context behavioural advertising as those terms are defined under the California Consumer Privacy Act, other than through the advertising cookies described in Section 6, which you can reject.
9. International data transfers
We are based in India. Some of our service providers store or process data in the United States, the European Union, Singapore, and other jurisdictions. When personal data is transferred outside the country where it was collected, we rely on appropriate safeguards, which may include:
- Standard Contractual Clauses approved by the European Commission, or the UK International Data Transfer Agreement/Addendum, for transfers from the EEA and UK
- Adequacy decisions, where the destination country has been recognised as providing adequate protection
- The transfer conditions set out in Section 16 of India’s DPDP Act, 2023 and Rule 15 of the DPDP Rules, 2025
You may request a copy of the safeguards we rely on by writing to us at the address in Section 16.
10. How long we keep your data
| Data | Retention period |
|---|---|
| Website enquiry that does not convert | 24 months from last contact, then deleted or anonymised |
| Client records and correspondence | Duration of the engagement plus 3 years |
| Invoices, tax, and statutory records | 8 years, or as required by Indian tax and company law |
| Newsletter subscriber data | Until you unsubscribe, plus a suppression record so we do not contact you again |
| Analytics data | Up to 14 months in Google Analytics 4, subject to platform settings |
| Cookie consent records | 12 months, or until you change your choice |
| Server and security logs | 12 months |
| Recruitment data | 12 months, unless you ask us to delete it sooner |
Where a longer period is required by law or by an ongoing legal claim, we retain the data for that period and then delete it.
11. Security
We apply reasonable technical and organisational safeguards, including HTTPS/TLS encryption in transit, access control on a need-to-know basis, multi-factor authentication on business-critical accounts, regular software and plugin updates, hardened WordPress configuration, firewall and bot filtering, and periodic backups.
No method of transmission or storage is completely secure. If a personal data breach occurs that is likely to affect you, we will notify you and the relevant supervisory authority within the timelines required by applicable law, including intimation to the Data Protection Board of India and to affected Data Principals under the DPDP Rules, 2025, and within 72 hours to the competent supervisory authority under the GDPR where it applies.
12. Data we process on behalf of clients
As a marketing agency, we are often granted access to a client’s Google Analytics, Google Search Console, Google Ads, Meta Business Manager, CMS, or ecommerce platform. Any personal data of that client’s own customers or visitors within those systems is processed by us as a Data Processor, strictly on the client’s documented instructions and under a service agreement or Data Processing Addendum.
In that role we do not decide the purposes of processing, we do not copy client end-customer data into our own systems except where required to deliver the agreed service, and we delete or return such data at the end of the engagement. If you are an end customer of one of our clients, please direct privacy requests to that business in the first instance; we will assist them in responding.
13. Your rights
13.1 If you are in India (DPDP Act, 2023)
As a Data Principal, you have the right to:
- Access a summary of the personal data we process about you and the processing activities involved
- Correction, completion, updating, and erasure of your personal data
- Grievance redressal through the contact point in Section 16, before approaching the Data Protection Board of India
- Nominate another individual to exercise your rights in the event of your death or incapacity
- Withdraw consent at any time, as easily as you gave it
You also have duties under the Act, including not raising false or frivolous complaints and providing authentic information when exercising the right to correction.
13.2 If you are in the EEA, UK, or Switzerland (GDPR / UK GDPR)
You have the right to access, rectification, erasure, restriction of processing, data portability, and objection to processing based on legitimate interests or direct marketing. You may withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal. You also have the right to lodge a complaint with your local supervisory authority, or with the UK Information Commissioner’s Office.
13.3 If you are in California or another US state with a privacy law
You have the right to know what personal information is collected, used, and disclosed; to delete it; to correct it; to opt out of sale or sharing for cross-context behavioural advertising; to limit the use of sensitive personal information; and not to receive discriminatory treatment for exercising these rights. We honour Global Privacy Control signals as a valid opt-out of sharing where technically supported. An authorised agent may submit a request on your behalf with proof of authorisation.
13.4 How to exercise your rights
Write to connect@vrankone.com with the subject line “Privacy Request”, telling us which right you wish to exercise and from which email address or form submission you contacted us. We may ask for information to verify your identity, so that we do not disclose data to the wrong person.
We respond within 30 days. If the request is complex, we may extend this and will tell you why. Exercising these rights is free of charge unless a request is manifestly unfounded or excessive.
14. Children’s data
Our website and services are directed at businesses, not children. We do not knowingly collect personal data from children.
Under India’s DPDP Act, a “child” is any individual under 18 years of age, and processing their personal data requires verifiable consent from a parent or lawful guardian. We do not undertake tracking, behavioural monitoring, or targeted advertising directed at children. Under the GDPR, the relevant age is 16, or lower where a member state has set a lower threshold.
If you believe a child has provided us with personal data, contact us and we will delete it.
15. Other disclosures
Third-party links. Our website links to external sites, including client websites, case studies, and social platforms. We are not responsible for their privacy practices.
Do Not Track. Browsers vary in how they implement Do Not Track and there is no common standard, so we do not respond to DNT headers. We do honour Global Privacy Control signals and our own cookie consent controls.
Changes to this policy. We may update this policy to reflect changes in our practices or the law. The revised version takes effect when posted, and we will update the “Last updated” date at the top. Where changes are material, we will provide prominent notice on the website or by email before they take effect.
16. Contact and grievance redressal
Grievance Officer / Privacy Contact
Kaustav Sinha, Co-founder
VRankOne, 59, Baridas Temple Street, Kolkata, West Bengal 700004, India
Email: connect@vrankone.com
Response time: acknowledgement within 72 hours, resolution within 30 days
If you are not satisfied with our response, you may escalate to the Data Protection Board of India, or to your local data protection authority if you are in the EEA or the UK.
This policy is published in English. If a translated version conflicts with this version, the English version prevails.