Legal

Privacy policy

What this website collects, why, who else can see it, and how to make us delete it. Written to describe what actually happens here rather than to cover every possibility a template can imagine.

Last updated 24 August 2026. Applies to www.uniquesmartweb.com.

If you read nothing else

The short version

  • We collect what you type into the contact form, and nothing else about you personally
  • There is no Google Analytics here, no advertising pixel and no cross-site tracker
  • We do not sell, rent or share your details, and we do not run a mailing list
  • Your enquiry is used to write your audit and reply to you. That is the whole purpose
  • Ask us to delete it and we will, and we will confirm when it is done

Who we are

Unique Smartweb is a WordPress engineering studio at SCO No 15, Sector 03, Rajpura 140401, Punjab, India. We build, repair and maintain WordPress and WooCommerce sites for clients in the United States, the United Kingdom, Europe and Australia.

For anything you send through this website, we are the data controller — we decide what is collected and what happens to it. Privacy questions and requests go to [email protected], which is read by the same people who do the work.

This policy covers this website. It does not cover a site we build or maintain for a client — that site is the client’s own, under their own policy, and any data in it belongs to them. Where we work on a client’s site we act on their instructions as a processor, under whatever agreement is in place with them.

What we collect, and when

What you send us

The contact form asks for your name, your email address, a subject and a message. That is all it asks for, and all four go straight to our inbox as an email. The form does not save anything into this website’s database — there is no stored table of enquiries here to be leaked or subpoenaed.

Whatever you choose to put in the message comes with it: your site address, your host, your deadline, and sometimes your frustration. All of that is treated as part of the enquiry. Please do not email us passwords or API keys. If we need access to your site once work is agreed, we will ask for a temporary account you can revoke, and we will say so explicitly.

Emailing or calling us directly does the same thing by a different route. There is no account to create on this website, no payment is taken here, and no card details are ever handled by this site.

What is collected automatically

Like every website, this one sits behind a server that keeps logs. A request records your IP address, your browser and device type, the page asked for, and the time. Those logs exist so the site can be kept online and attacks can be identified; they are not used to build a profile of you and they are not linked to anything you send us.

We also see aggregate visit numbers through Cloudflare Web Analytics — page views, referring site and country, counted without cookies and without following anyone between websites. It tells us that a page was read forty times last week. It cannot tell us who read it.

What is deliberately not here: Google Analytics, Google Tag Manager, Meta or LinkedIn advertising pixels, heatmap recorders, session replay, and any other cross-site tracker. None of them are installed, and none are planned. Comments are closed across the site, so there is nothing collected there either.

If you use the SEO checker

The free SEO checker asks for a web address and nothing else. There is no account and no email field. Reports are not saved anywhere, which is also why we cannot send you a copy of one afterwards.

We keep a list of the websites checked, so we can see how the tool is used. Each entry holds the website address and the country the request came from, as reported by Cloudflare, and nothing else: no IP address, no browser details, no report and nothing that links an entry to you. Checks made by our own staff are not recorded. Entries are deleted automatically after 90 days.

Two things happen with what you type. Our server fetches the address you gave it, exactly as a search engine would, and reads the public page. Then the same address is sent to Google’s PageSpeed Insights API, because that is the only way to produce the performance scores. Google’s handling of it falls under its own privacy policy. If you would rather Google did not see the address, do not use this tool on it.

There is a limit of twenty checks an hour from one connection, so that the tool cannot be used as a free bulk scanner at our expense. Counting them requires knowing you are the same visitor, so a one-way hash of your IP address is held for one hour and then expires by itself. The hash cannot be turned back into an address, it is not linked to anything else, and after an hour there is nothing left to link.

If you use the hosting checker

The free hosting checker asks for a web address and nothing else. Our server looks that website up in public DNS, reads its public page as any visitor’s browser would, and asks the official domain and network registries about it through rdap.org. A theme name may also be checked against the WordPress.org theme directory. Those services see the website being checked, not who asked.

We keep a list of the websites checked, so we can see how the tool is used. Each entry holds the website address and the country the request came from, as reported by Cloudflare, and nothing else: no IP address, no browser details and nothing that links an entry to you. Checks made by our own staff are not recorded. Entries are deleted automatically after 90 days.

The hosting checker has the same kind of limit as the SEO checker: twenty checks an hour from one connection, counted with a one-way hash of your IP address that expires by itself after an hour.

The free broken link checker asks for a web address and nothing else. Our server reads that website’s public pages as any visitor’s browser would, and requests each link and image found on them. The websites it requests see our server, not who asked.

The results of a check – the addresses checked, their status and the pages they were found on – are stored so the report can be reopened from its link, and are deleted automatically after 48 hours. We also keep a list of the websites checked, with the country the request came from as reported by Cloudflare and the totals the check found: no IP address, no browser details and nothing that links an entry to you. Checks made by our own staff are not recorded. Entries in that list are deleted automatically after 90 days.

The broken link checker allows five checks an hour from one connection, counted with a one-way hash of your IP address that expires by itself after an hour.

Why we hold it, and for how long

Under UK and EU data protection law we have to name a lawful basis for holding anything. Ours are straightforward. Replying to an enquiry and writing the audit you asked for rests on legitimate interests — you contacted us wanting an answer, and answering is what you expected. Keeping the site online and free of abuse also rests on legitimate interests. Keeping invoices and project records rests on legal obligation.

We do not rely on consent for any of it, because we do not do the things consent is usually needed for: no marketing emails, no profiling, no advertising cookies.

WhatKept for
Enquiry emails and audit correspondenceThe length of the conversation, then up to 24 months
Client project records and invoicesAs long as the law requires business records to be kept
Server and security logsA short rolling window, set by our host and Cloudflare
Aggregate analytics countsRetained by Cloudflare, holds no personal data

Twenty-four months is the outer limit, not a target. It exists because clients come back — someone we audited last year often returns with the same site, and the earlier thread saves them explaining it twice. If you would rather we did not keep it that long, say so and we will delete it immediately.

Cookies and tracking

This site sets no analytics cookies and no advertising cookies, which is why you are not being asked to dismiss a consent banner. Reading these pages does not require you to accept anything.

Three things can still place a cookie in your browser, and it is fairer to name them than to claim there are none at all:

  • Cloudflare may set a bot-management cookie such as __cf_bm to tell human visitors from automated traffic. It is strictly functional and short-lived.
  • Google reCAPTCHA loads on the contact page to stop the form being used by spam bots, and sets Google’s own cookies when it does. See the note below.
  • WordPress sets a session cookie only if somebody logs in to administer the site. Ordinary visitors never receive one.

You can block or clear cookies in your browser settings. Nothing on this site stops working if you do, apart from the contact form, which needs reCAPTCHA to submit. If that is a problem, email us instead — it reaches exactly the same place.

The fonts on this site are served from our own server, not from Google Fonts, so simply loading a page makes no request to a third party for typography.

Who else touches your data

We do not sell, rent or trade personal information, and we have never done so. A short list of suppliers necessarily handles data on our behalf in order for the site and the inbox to work at all.

WhoWhat they handleWhy
CloudflareTraffic, IP addresses, cookieless visit countsContent delivery, DDoS and bot protection, analytics
Google (reCAPTCHA)Device and interaction signals on the contact pageStopping automated spam through the form
Google (email)The contents of your enquiry, once it is sentOur mailbox is hosted on Google’s email service
Google (PageSpeed Insights)Any web address you submit to the SEO checkerProducing the performance scores in the report
Our web hostSite files, database and server logsRunning the website

Because the contact form is protected by reCAPTCHA, Google collects hardware and software information and interaction data from that page to tell people from bots. That use is governed by Google’s own privacy policy and terms of service, and Google states it is used for improving reCAPTCHA and for general security, not for personalised advertising.

We may also disclose information if the law genuinely requires it — a valid court order or a legal obligation we cannot refuse. If that ever happens and we are permitted to tell you, we will.

Where your data goes

We are based in India, and we say so plainly rather than hiding behind a forwarding address in a Western city. If you are writing from the United Kingdom, the European Union or Australia, your enquiry leaves your country the moment you send it, and is read and stored in India.

Cloudflare and Google both operate global networks, so traffic and form checks may be processed in whichever region is nearest to you. Both publish their own transfer safeguards, including standard contractual clauses for transfers out of the UK and the EEA.

If your organisation’s own rules prevent data leaving a particular region, tell us before you send anything and we will work out what we can do — sometimes the answer is that we are the wrong studio for that project, and it is better to know at the start.

Your rights

Wherever you are, you can ask us for these and we will act on them. Under the UK GDPR and the EU GDPR they are legal rights; we apply the same process to everyone regardless of where they live, because running two standards would be more work than running one.

  • See it. Ask what we hold about you and we will send you a copy
  • Correct it. Tell us anything that is wrong and we will fix it
  • Delete it. Ask us to erase the thread and anything you sent with it
  • Object or restrict. Tell us to stop using it, or to hold it without using it
  • Take it with you. Ask for it in a portable format
  • Complain. Raise it with a regulator if we handle it badly

Email [email protected] with what you want. We answer within thirty days and usually within two business days, because there is very little to search through — for most people it is one email thread. There is no charge and no form to fill in.

If you are in the United Kingdom you can complain to the Information Commissioner’s Office. If you are in the European Union you can complain to the supervisory authority in your own country. We would rather you told us first and gave us the chance to put it right.

Security, children and changes

Security is the thing we sell, so this site had better be an example of it. Everything is served over HTTPS. The site sends standard protective headers, hides the WordPress version from scanners, blocks public listing of usernames, and sits behind Cloudflare. Administrative access is limited to the people who need it and is protected by strong, unique credentials.

No website can promise perfect security, and anybody who does is selling something. What we can promise is that there is very little here to steal: no customer accounts, no card numbers, no stored form submissions. If a breach ever did affect your information, we would tell you and the relevant regulator within the time the law allows.

This site is a business service aimed at adults and is not directed at children. We do not knowingly collect information from anyone under sixteen. If you believe a child has sent us something, email us and we will delete it.

When this policy changes, the date at the top changes with it. If a change materially affects what we do with information already sent to us, we will say so at the top of this page rather than quietly editing a paragraph. This site links out to other places — client sites on the work page, and our Instagram — and once you follow a link you are on somebody else’s site under somebody else’s policy.

Questions about your data?

Ask what we hold, or tell us to delete it. Either one is answered by a person, usually within two business days, and there is nothing to fill in — an email is enough.