Last updated: 15 May 2026
Privacy Policy
This policy explains what information Drimigo collects when you interact with us — on this website, by email, on WhatsApp, on a discovery call, or while we're actively working together — and how we use it.
We aim for plain language. If anything here is unclear, write to za@drimigo.com and we'll explain.
Who we are
“Drimigo” refers to the studio operating at drimigo.com, headquartered in Mumbai, India. We are the data fiduciary (DPDPA) and data controller (GDPR) for the information described here.
What we collect
We only collect what we need to do the work and stay in touch:
- When you submit a brief or book a call: name, email, optional phone / WhatsApp, company name, the message you write, the page you came from, and basic UTM parameters if you arrived via a link.
- While we're working together: the things you share with us as part of the project — copy, images, brand assets, credentials (encrypted at rest in our credentials vault), feedback on deliverables.
- Automatically as you browse: aggregated visit analytics (page views, referrer, country) via Plausible Analytics, which is cookieless and does not identify individuals.
- When you sign in to the client portal: a Drimigo SSO session, name, avatar, and the projects, deliverables, and credentials assigned to you.
How we use it
- To respond to your brief and run discovery, scoping, and delivery on your project.
- To send you transactional emails: brief acknowledgement, proposal links, calendar invites, status updates, and invoices.
- To improve the site — understanding which pages help visitors decide and which don't, based on aggregate analytics.
- To meet our tax and legal obligations.
We do not sell your data, share it with advertisers, or use it for third-party marketing.
Who processes data on our behalf
A short list of carefully chosen processors. Each is contractually bound to handle your data the same way we do:
- Supabase (database + auth + edge functions, AWS Mumbai)
- Cloudflare (CDN + edge routing)
- Amazon SES (transactional email delivery)
- Plausible Analytics (visit analytics, cookieless)
- Google Workspace (calendar bookings, internal mailbox)
- Razorpay / Stripe (payment processing, when an invoice is paid)
Where data lives
Primary storage is in AWS Mumbai (Supabase). Cloudflare caches static assets at the edge worldwide. We don't transfer data outside India for marketing purposes; transfers that do happen (e.g., to Amazon SES's region or Stripe's servers) are for the service to function and are covered by those providers' cross-border safeguards.
How long we keep it
- Inquiries that don't become projects: kept for 24 months, then deleted.
- Active project data: kept as long as we're working together, plus 7 years for tax/accounting records (per Indian law).
- Credentials in our vault: deleted within 30 days of project handover or on your request — whichever is sooner.
- Analytics: aggregated, not tied to you, kept indefinitely.
Your rights
Under DPDPA 2023 (India) and GDPR (EEA/UK) you have the right to access, correct, port, and delete the personal data we hold about you. To exercise any of these, write to za@drimigo.com. We respond within 30 days.
Cookies
We don't set tracking cookies. The session cookie used by our portal sign-in is essential to keep you logged in and isn't used for tracking.
Children
Drimigo's services are aimed at businesses. We don't knowingly collect data from anyone under 18. If we learn we have, we delete it.
Changes
When we update this policy materially we'll note the new date at the top and, if you have an active project with us, email you a summary of what changed.
Questions
Reach out at za@drimigo.com.