Legal

Privacy Policy

Effective July 2, 2026

the short version

We collect what you type into the audit-request form, use it to reply to you, and nothing else. No cookies, no analytics, no trackers, no selling data. Email admin@fixier.co any time to see or delete what we hold about you.

Who we are

Fixier ("we") operates fixier.co and provides production audits, fixes, and builds for software products. For everything in this policy, we are the data fiduciary under India's Digital Personal Data Protection Act, 2023 (DPDP Act), and you can reach us at admin@fixier.co.

What we collect

What you submit. The audit-request form asks for your email address, and optionally a phone number, a repository or app URL, a description of your stack, and a description of your product. If you email us instead, we receive whatever you choose to send.

What the infrastructure sees. Your IP address is used to rate-limit the form (an anti-abuse measure) and is deleted automatically shortly after — we keep no long-term record of it. The phone field prefills your country's calling code using Cloudflare's edge geolocation; that lookup is not stored. Cloudflare, which serves the site, generates short-lived operational logs of requests; these expire within days.

What we don't collect

The site sets no cookies and runs no analytics, advertising, or tracking scripts of any kind. There is nothing to opt out of and no consent banner because there is nothing to consent to. If you never submit the form or email us, we hold no personal data about your visit.

Why we process it

One purpose: responding to your request — scoping the work you asked about and corresponding with you about it. The legal basis is your consent, given by voluntarily submitting the form or emailing us. We don't use your details for marketing lists, and we don't sell or rent personal data to anyone.

Where it lives

Form submissions are stored in a Cloudflare D1 database in Cloudflare's Asia-Pacific region (Singapore). When you submit the form, a notification email is delivered to our inbox via Resend (servers in the United States) and GoDaddy's email service. If you go on to book a call, scheduling is handled by Calendly (servers in the United States) — the booking page arrives pre-filled with what you typed into the form, so you don't enter it twice, and Calendly stores what you submit there. These providers process data on our behalf; the DPDP Act permits such cross-border transfers. Access to the stored data is limited to the founder.

How long we keep it

Submissions are kept while we're discussing or doing work for you, and deleted when they're no longer needed for that — or immediately on your request, whichever comes first. Rate-limiting records and infrastructure logs delete themselves automatically on much shorter cycles.

Your rights

Under the DPDP Act you can ask us what personal data we hold about you, ask us to correct or delete it, withdraw consent, and nominate someone to exercise these rights for you. Email admin@fixier.co — that address is also our grievance contact, and we respond promptly. If you're not satisfied with our response, you may escalate to the Data Protection Board of India.

Security

The site is served exclusively over HTTPS, submissions are validated and rate-limited at the edge, and stored data sits in managed, access-controlled infrastructure. No system is perfectly secure — if a breach ever affects your personal data, we'll notify you and the Data Protection Board as the DPDP Act requires.

Children

Our services are for businesses and are not directed at anyone under 18. We don't knowingly collect children's personal data.

Changes

If this policy changes, the new version appears here with an updated effective date. Material changes to how we handle already-submitted data will be emailed to affected people first.