What this policy covers and what it does not
This document covers data handling through our public website, our free tools, the DH Auto Refresh Chrome extension, our public-facing forms (booking a call, applying to a role, general contact), and any pre-engagement marketing communications.
It does not cover personal data inside our internal systems used by paying clients. The client portal at business.digitalheroesco.com and the team portal at portal.digitalheroesco.com each run under separately signed Master Services Agreements and Data Processing Agreements with each client. Where a paid engagement makes us a data processor for a client, that client's own privacy notice and our DPA with them govern that processing, not this page.
Who we are
Digital Heroes is the public-facing brand of Digital Heroes Technologies Pvt Ltd, a privately held company incorporated in India, registered as a global supplier (DUNS No. 650878346), and listed on the UN Global Marketplace at Tier 1.
We are the controller of personal data described in this policy under GDPR / UK GDPR terminology, the business under CCPA terminology, the data fiduciary under India's DPDP Act, and the APP entity under Australia's Privacy Act 1988.
Staffed offices: New York (US) and Delhi (India). Satellite teams: London (UK), Lucknow (India), Sydney (Australia). Mail any of the inboxes at the bottom of this page, they reach the same team regardless of which office responds.
Data we collect
The data we collect depends on how you interact with the site. We collect the minimum we need for each interaction; we do not collect more so that we have it later.
When you visit any page
Google Analytics 4 loads with Consent Mode set to denied by default. If you accept analytics or all cookies, it uses a randomised client identifier and receives the page URL, referrer, approximate region, device and browser type, operating system, viewport size, and basic interaction events; IP anonymisation is enabled. Without that consent, Google does not receive analytics-cookie access or a persistent analytics identifier, although Consent Mode can send limited cookieless consent and measurement signals.
Microsoft Clarity is not loaded until you accept analytics or all cookies. Once enabled, it receives page and URL data, device and browser details, IP-derived approximate location, and interaction data used for behavioural metrics, heatmaps, and session replay. It may use first- and third-party identifiers for session continuity. Clarity masks input fields and content it classifies as sensitive by default.
The OpenAI Ads Pixel is loaded only after you choose Accept all. It is used to measure visits and conversions resulting from Digital Heroes ads. OpenAI can receive ad-click or browser-reference cookies, page and device/browser information, an opaque conversion event ID, event time, and source page path. When a lead event is measured, the Pixel's automatic advanced matching detects supported email-address and phone-number fields, normalises and SHA-256 hashes those values in the browser, and sends only the hashes—not the raw values—to OpenAI. Our server-side Conversions API payload does not include raw or hashed email addresses or phone numbers.
When you book a call
From the form at /book/, we collect: your name, work email, phone or WhatsApp number, company name (optional), the service of interest you selected, budget range, the country your business operates in, the date and time slot you chose, your free-text notes, and your browser timezone. If you grant the browser geolocation prompt (best-effort, optional), your approximate latitude and longitude are included so we can suggest a better-aligned overlap window.
Our hosting layer also receives a server-side IP-derived approximate location (city, region, country) for routing context. The submission is written to our database, emailed to our intake inbox, and a confirmation copy is emailed back to you.
When you apply to a role
From the form at /careers/, we collect: the role you selected (job ID), full name, email, phone or WhatsApp, city, current and expected compensation if you provide them, notice period, employment status, a link to your resume, an optional portfolio or profile link, and a free-text "why this role" message. The application is written to our hiring database and a notification is emailed to our HR inbox.
When you use a free tool
In almost every tool at /tools/, nothing reaches our servers. The inputs you paste are processed entirely in your browser and the results render locally, no network round-trip, no server log, no database write.
A small number of tools call public third-party APIs on your explicit click. In every such case the URL or domain you enter is sent only to the named API endpoint; we do not proxy it, we do not log it, and we do not store the response. The complete list of tools that hit third-party APIs lives in the "Tool APIs" section below.
When you use website chat or an enquiry form
We collect the messages and contact details you choose to provide, together with the page URL and title, referrer, permitted campaign parameters, recent on-site navigation context, and IP-derived approximate country, region, or city used to route and understand the enquiry. The browser caches the current chat token and thread, recent messages, identity details, source and navigation context, and related interface state in first-party localStorage so the conversation can resume. That browser cache remains until you clear site data.
When you email us
If you write to any of our published addresses, we receive the contents of the email, your email address, and any attachments. Email is processed by our standard business email provider.
DH Auto Refresh Chrome extension
This section applies to the DH Auto Refresh Chrome extension published by Digital Heroes under Chrome Web Store item ID bbkakaachnpfbgogodmlmgmpjjdmcbnd.
Data handled locally
When you start a refresh or monitoring job, the extension handles the URL and title of the selected tab, navigation and network status, visible page text or page source, the monitor terms or patterns you enter or select, signals that mouse, keyboard, or scroll interaction occurred (not the content you type), visible CAPTCHA indicators, error indicators, and—when restore-scroll is enabled—the page's scroll position. In Chrome Web Store terminology, this can include web history, user activity, and website content.
Purpose and permissions
The extension uses this data only to run the refresh schedule you configure, maintain per-tab jobs, apply the content checks you select, detect relevant page or network conditions, and show requested alerts. Its tabs, storage, alarms, notifications, offscreen, sidePanel, webRequest, webNavigation, contextMenus, and <all_urls> host permission support those functions. Host access is used only on HTTP and HTTPS pages. The extension does not load or execute remote code.
Storage and retention
Global preferences and per-site settings, including saved monitor terms or patterns, are stored in chrome.storage.local. Active-job state, deadlines, URLs, monitor rules, and alerts are stored temporarily in chrome.storage.session so jobs survive extension service-worker restarts. When restore-scroll is enabled, the latest x/y scroll position is stored under dhar-scroll in that page origin's sessionStorage. Local preferences remain until you change them, clear the extension's data in Chrome, or uninstall the extension. Chrome session storage is cleared with its associated browser or page session. Digital Heroes does not retain a server-side copy.
Sharing and user choice
The extension does not sell this data, transfer it for advertising or unrelated purposes, use it to determine creditworthiness or for lending, show advertising, or send it to Digital Heroes analytics. When it refreshes a page at your request, Chrome necessarily sends a normal page request to the visited website and may load that website's ordinary assets, such as its favicon; those communications are governed by the visited website's privacy practices. The extension does not separately send monitored content, monitor rules, or interaction signals to Digital Heroes or unrelated third parties. You can stop a job at any time, clear the extension's stored data through Chrome, or uninstall the extension. Because Digital Heroes has no server-side copy, it cannot retrieve or delete that local data for you. For extension privacy or support questions, email privacy@digitalheroes.co.in.
How we use it
For data that reaches Digital Heroes through the website, we rely on three lawful bases and three purposes, described below. DH Auto Refresh's operational processing occurs locally at the user's direction and is not received by Digital Heroes.
- Legitimate interest: operating the website, responding to inbound inquiries, vetting applications, and protecting against fraud and abuse.
- Consent: the analytics and marketing cookies that fire only after you accept them, and any newsletter or marketing communication you opt in to.
- Contract: data we process to scope, propose, deliver, invoice, and support a paid engagement once you sign with us.
What we don't do
These promises are unconditional. They apply with or without your consent and override any future ambiguity in the rest of this policy.
- We do not sell or rent personal data or disclose it to data brokers. Limited disclosures to providers for hosting, analytics, support, and consented advertising measurement are named below.
- We do not use the personal data we collect through this website to train our own AI models or to enrich any commercial AI training corpus.
- We do not use Meta Pixel, Google Ads remarketing, LinkedIn Insight Tag, TikTok Pixel, X Pixel, Pinterest Tag, Reddit Pixel, or Snapchat Pixel. The only advertising measurement tag presently enabled is OpenAI Ads, which initializes only after Accept all and is described below.
- We do not fingerprint your browser, device, or canvas. The "device type" and "browser type" Google Analytics records are bucketed (mobile / tablet / desktop; Chrome / Firefox / Safari / etc.), not the dense fingerprint vector that anti-tracker tools warn about.
- We limit analytics and advertising cookies or similar technologies to the providers and consent choices described under "Cookies" below.
- We do not buy or ingest third-party identity datasets. OpenAI click and browser references are used only to attribute conversions from consented Digital Heroes advertising.
Sub-processors and third parties
The vendors below are involved in operating the site and our forms. Each is bound by its own published data-processing terms, linked from each entry. This list reflects the actual production environment of digitalheroesco.com at the date above.
Core infrastructure
- Cloudflare, Inc. (San Francisco, CA, USA), website hosting, edge delivery, security, API execution, and IP-derived approximate geolocation used by our server-side forms and chat. cloudflare.com/privacypolicy
- Supabase Inc. (Delaware, USA), Postgres database and object storage used for job listings, applications, website chat and contact records, attachments, and consented advertising-conversion delivery state. supabase.com/privacy
- Resend Inc. (San Francisco, CA, USA), transactional email delivery for booking confirmations, application notifications, and one-to-one team replies sent from
@digitalheroes.co.inaddresses. resend.com/legal/privacy-policy
Front-end assets and analytics
- Google LLC, Analytics 4 (Mountain View, CA, USA), web analytics with Consent Mode v2 and IP anonymisation. Analytics storage is denied until consent; limited cookieless consent or measurement signals may still be sent while denied. policies.google.com/privacy
- Microsoft Corporation, Clarity (Redmond, WA, USA), behavioural metrics, heatmaps, and session replay loaded only after analytics consent. Clarity advertising storage is granted only with full consent, and sensitive input content is masked by default. privacy.microsoft.com/privacystatement
- OpenAI, LLC, Ads measurement (United States and other processing locations described by OpenAI), the OpenAI Pixel and Conversions API used only after full advertising consent to attribute Digital Heroes ad visits and lead or registration conversions. openai.com/policies/conversion-terms
- Google LLC, Fonts (Mountain View, CA, USA), Space Grotesk, Inter, Instrument Serif, and JetBrains Mono served from
fonts.googleapis.comandfonts.gstatic.com. The font request is a standard HTTP request that Google logs per its privacy policy. - Cloudflare, Inc., cdnjs (San Francisco, CA, USA), open-source JavaScript libraries (currently GSAP) served from
cdnjs.cloudflare.com. cloudflare.com/privacypolicy
If you operate as a corporate buyer and need a signed Data Processing Agreement covering personal data we process for you under a paid engagement, email legal@digitalheroes.co.in. We sign GDPR Article 28 DPAs as a standard part of any engagement that requires one.
Third-party APIs called by free tools
Most tools at /tools/ run entirely in your browser. The handful that need to look up live external data make a single fetch directly from your browser to a public third-party API when you click "run". We do not proxy these calls, your browser talks to the API directly, and we do not store the URL you submitted or the response we receive.
- Google PageSpeed Insights API (
googleapis.com/pagespeedonline/v5/runPagespeed), used by the Website Audit, Lighthouse Score Checker, Core Web Vitals Checker, Mobile-Friendly Test, Multi-URL Audit, Page Weight Analyzer, CSS Size Checker, JavaScript Size Checker, HTTP Status Checker, and Domain Health Checker tools. The URL you enter is sent to Google. policies.google.com/privacy - Cloudflare DNS-over-HTTPS (
cloudflare-dns.com/dns-query), used by the DNS Lookup tool and the Domain Health Checker. The domain you enter is sent to Cloudflare. cloudflare.com/privacypolicy - RDAP (Registration Data Access Protocol) (
rdap.org/domain/), the modern, ICANN-coordinated replacement for WHOIS. Used by the WHOIS Lookup, Domain Age Checker, Domain Availability Checker, and Domain Health Checker tools. The domain you enter is sent to the relevant RDAP server. about.rdap.org - Internet Archive, Wayback Availability API (
archive.org/wayback/available), used by the Domain Age Checker and Domain Health Checker to estimate the first time a domain appeared on the public web. The domain you enter is sent to Internet Archive. archive.org/about/terms
Each tool that triggers one of the above calls names the destination API in its own "Privacy" line beneath its input form, before you submit anything. You can read what will happen before you press the button.
International transfers
As a dual-HQ company with offices in the United States, India, the United Kingdom, and Australia, we routinely transfer personal data internationally between our offices and our sub-processors.
Where data on a person resident in the European Economic Area, the United Kingdom, or Switzerland is transferred to a country without an adequacy decision, the transfer is protected by the European Commission's Standard Contractual Clauses (the 2021 SCC modules, including the UK Addendum where the UK is involved) executed with each sub-processor.
Where data on a person resident in India is transferred outside India, the transfer is conducted under the cross-border transfer mechanisms set out in the Digital Personal Data Protection Act, 2023 and any rules notified under it.
Where data on a person resident in Australia is transferred outside Australia, we comply with Australian Privacy Principle 8, meaning either the recipient is bound by substantially similar protections, or you have been informed of the disclosure and have consented.
Your rights, per jurisdiction
European Economic Area (GDPR)
You have the right to access, rectify, erase, restrict, port, and object to the processing of your personal data, and to withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal. You also have the right to lodge a complaint with your national data protection authority, a directory is maintained by the European Data Protection Board.
United Kingdom (UK GDPR + Data Protection Act 2018)
You have the same rights as EEA residents, plus the right to complain to the Information Commissioner's Office.
California (CCPA as amended by CPRA)
You have the right to know what personal information we collect about you, the right to delete, the right to correct, the right to opt out of sale or sharing of personal information, and the right not to be discriminated against for exercising these rights. We do not sell your personal information. OpenAI conversion measurement may be treated as sharing or targeted advertising under some US privacy laws; it is disabled unless you choose Accept all. Choosing reject or analytics-only—or enabling Global Privacy Control—opts out, and you may also email us to exercise any applicable right.
Other US states (Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, and beyond)
We honour applicable US state rights to access, correction, deletion, portability, opt-out of sale or targeted advertising, and appeal of a refused request. We do not sell personal data. You can opt out of OpenAI advertising measurement by choosing reject or analytics-only or by enabling Global Privacy Control, and you can email privacy@digitalheroes.co.in with your state of residence for any additional request.
India (Digital Personal Data Protection Act, 2023)
You have the right to obtain confirmation and access, the right to correction and erasure, the right to grievance redressal, and the right to nominate another individual to exercise these rights on your behalf in case of incapacity or death. Our designated grievance contact is privacy@digitalheroes.co.in.
Australia (Privacy Act 1988 + Australian Privacy Principles)
You have the right to access personal information we hold about you, to seek correction, and to make a complaint. If we cannot resolve a complaint to your satisfaction, you may escalate to the Office of the Australian Information Commissioner.
How to exercise any of these rights
Email privacy@digitalheroes.co.in from the address on file (or, if that address has changed, with sufficient detail to verify your identity through alternate means). We respond within thirty days for GDPR / UK GDPR / DPDP requests, forty-five days for CCPA requests (extendable once by another forty-five days where reasonably necessary), and within the timelines required by Australian Privacy Principle 12. There is no fee for exercising a right; we may charge a reasonable fee or refuse the request only where it is manifestly unfounded or excessive, as permitted by the applicable statute.
Data retention
- Google Analytics: event data follows the retention period configured in our GA4 property and Google's applicable retention rules. GA browser cookies can persist for up to 400 days in current Chrome unless you clear them sooner.
- Microsoft Clarity: playback data is generally retained for thirty days; click and heatmap data and selected or favourited sessions can be retained for up to nine months under Microsoft's current retention schedule.
- OpenAI Ads measurement: OpenAI retains conversion data under its applicable Ads terms. Our Supabase database stores the opaque conversion ID, source path, attribution references, and delivery metadata. No automatic expiry is currently configured; we delete those records when required by an applicable deletion request.
- Booking submissions: retained for the duration of the active conversation plus twelve months thereafter for record-keeping. Delete-on-request honoured at any time.
- Website chat and enquiries: browser-cached chat state remains until you clear site data. Server-side chat and enquiry records currently have no automatic expiry; we retain them for operational follow-up and business records and delete them when required by an applicable request.
- Applicant data: resumes that do not lead to an offer are deleted on request, otherwise retained for up to twelve months in case a relevant role opens. Resumes for hired candidates move into our employee-record system under a separate retention schedule.
- Email correspondence: retained for the operating-business reasonable period (we do not bulk-delete inboxes). Specific thread deletion available on request.
- Marketing-list subscribers: retained until you unsubscribe, after which we keep a minimal suppression record (your email address only) so we do not accidentally re-add you.
- DH Auto Refresh: preferences remain in Chrome until changed, cleared, or the extension is uninstalled. Active-job data in
chrome.storage.sessionis cleared with the browser session, and a saved scroll position in a page origin'ssessionStorageis cleared with that page session. Nothing from the extension is retained on Digital Heroes servers.
Security
The site is served over HTTPS only with HSTS enabled. Form submissions are encrypted in transit. Server-side endpoints validate inputs and rate-limit by IP. Personal data inside our hosting and database providers is protected by access controls native to those platforms; only employees and contractors who need access for a documented purpose receive it.
DH Auto Refresh processes its operational data inside the user's Chrome profile and does not separately transmit monitored content, monitor rules, or interaction signals to Digital Heroes. A refresh still makes a normal request to the website selected by the user. Chrome's profile and operating-system access controls protect the extension's local storage.
We never store credit card or banking information on our infrastructure. If a paid engagement requires payment, we issue an invoice and you pay through your banking channel of choice or a payment processor (Stripe or Razorpay) where the card data goes directly to the processor and never touches our servers.
No system on the public internet is invulnerable. If you become aware of a security issue affecting personal data on this site, please email legal@digitalheroes.co.in with the details and we will respond within five business days. We will notify affected users and the relevant supervisory authority as required by GDPR Article 33, the Indian DPDP Act, and any other applicable breach-notification rule.
Children
Our services are not directed at children under sixteen. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact privacy@digitalheroes.co.in and we will delete it.
Automated decision-making
We do not make decisions that produce legal or similarly significant effects on you using solely automated processing. Applicant review, pricing decisions, and engagement scoping are reviewed by a human before a decision is communicated.
Changes to this policy
We update this policy when our practices change. The last updated date and version at the top reflect the most recent revision. Material changes (anything that would make us collect more, share more, or retain longer) will be flagged at the top of the page for at least thirty days after publication.
Contact
- Privacy questions, data-rights requests, complaints: privacy@digitalheroes.co.in
- General support: support@digitalheroes.co.in
- Legal notices, security disclosures, DPAs: legal@digitalheroes.co.in
- India grievance officer (per DPDP Act): privacy@digitalheroes.co.in
We are reachable through any of these inboxes from any of our offices in New York, Delhi, London, Lucknow, or Sydney.
Glossary
- Controller / Business / Data Fiduciary
- The entity that decides why and how personal data is processed. We are this entity for the personal data described in this policy.
- Processor / Service Provider / Data Processor
- An entity that processes personal data on the controller's behalf, under contract. We act as a processor for our paying clients, that work is governed by a separate Data Processing Agreement.
- Sub-processor
- A vendor we use to deliver part of our service. Each one we use is named in the Sub-processors section.
- Consent Mode v2
- A Google-defined framework that lets analytics adjust its behaviour based on the consent state you select on the cookie banner. Even after granting analytics consent, ad-personalisation signals remain off unless you specifically accept all cookies.
- Standard Contractual Clauses (SCCs)
- A set of model contract terms approved by the European Commission for transferring personal data from the EEA / UK to a country without an adequacy decision. We execute the 2021 SCC modules with each affected sub-processor.
- DPA (Data Processing Agreement)
- A contract specifically governing the processor relationship, Article 28 of GDPR, equivalent provisions in UK GDPR / DPDP / CCPA. We sign these as a standard part of any paid engagement that requires one.