Privacy Policy
This Privacy Policy explains how Zoibox Creative Labs Pvt. collects, uses, discloses, and safeguards your information when you visit our website or use our services.
Last updated: August 15, 2025
1. 1. Introduction
Zoibox Creative Labs Pvt. (“Zoibox”, “we”, “us”, or “our”) is committed to protecting your privacy. This Privacy Policy describes how we collect, use, store, and share your personal information when you interact with our website, mobile applications, and services (collectively, the “Services”).
By accessing or using our Services, you consent to the data practices described in this policy. If you do not agree with these practices, please do not use our Services.
This policy complies with applicable data protection laws, including the Information Technology Act, 2000 (India), the Digital Personal Data Protection Act, 2023 (India), and the General Data Protection Regulation (GDPR) where applicable to users in the European Economic Area.
2. 2. Information We Collect
2.1 Information you provide directly:
- Contact form submissions: Your name, email address, company name, project type, budget range, and message when you submit our contact form or request a proposal.
- Newsletter subscriptions: Your email address when you subscribe to the studio dispatch newsletter.
- Review submissions: Your name, designation, email, company, mobile number, star rating, and comment when you submit a review through our review form.
- Job applications: Your name, email, portfolio link, and any information you share when applying for a role or contacting our careers team.
- Control panel credentials: Your email and password when you log into the admin control panel (passwords are stored in hashed form).
2.2 Information collected automatically:
- Device and browser information: IP address, browser type, operating system, screen resolution, and device identifiers.
- Usage data: Pages visited, time spent on pages, click patterns, scroll behavior, and referring URLs.
- Cookies and local storage: Theme preferences (light/dark), cookie consent choices, and session identifiers.
2.3 Information from third parties:
We may receive information from third-party services such as analytics providers, social media platforms (when you interact with our social content), and referral sources. We only use this information to improve our Services.
3. 3. How We Use Your Information
We use the information we collect for the following purposes:
- Service delivery: To respond to your inquiries, prepare proposals, and provide the services you request.
- Communication: To send you the studio dispatch newsletter, project updates, and important notifications (only with your consent for marketing communications).
- Review management: To display approved reviews on our website and manage the review submission process.
- Recruitment: To process job applications and communicate with candidates about open roles.
- Website improvement: To analyze usage patterns, improve user experience, and optimize our website's performance and content.
- Security: To monitor for suspicious activity, prevent fraud, enforce our terms, and protect against unauthorized access.
- Legal compliance: To meet our legal and regulatory obligations, maintain records, and respond to lawful requests from authorities.
- Analytics: To measure the effectiveness of our marketing campaigns and understand how visitors discover and use our site.
4. 4. Legal Basis for Processing
We process your personal data on the following legal bases:
- Consent: When you submit a contact form, subscribe to our newsletter, or submit a review, you consent to our use of that information for the stated purposes.
- Contractual necessity: When you engage our services, we process your data to fulfill our contractual obligations.
- Legitimate interests: To improve our website, prevent fraud, and ensure security — where our interests do not override your rights.
- Legal obligation: To comply with applicable laws, regulations, and lawful requests from authorities.
5. 5. Data Sharing and Disclosure
We do not sell, rent, or trade your personal data. We may share your information in the following circumstances:
- Service providers: We may share data with trusted third-party service providers who help us operate our business (e.g., hosting providers like Neon, email delivery, analytics). These providers are contractually bound to protect your data and use it only for the services they provide to us.
- Legal requirements: We may disclose your information if required by law, court order, or government regulation, or to protect our rights, property, or safety.
- Business transfers: In the event of a merger, acquisition, or sale of assets, your data may be transferred to the acquiring entity. We will notify you before such a transfer.
- With your consent: We may share your data with third parties when you explicitly consent to such sharing.
6. 6. Data Retention
We retain your personal data only as long as necessary for the purposes described in this policy:
- Contact form submissions: Retained for up to 24 months after the inquiry is resolved, unless a longer period is required for legal or accounting purposes.
- Newsletter subscriptions: Retained until you unsubscribe or request deletion.
- Review submissions: Retained for as long as the review is displayed on our website, plus 12 months after removal.
- Job applications: Retained for 12 months after the application is processed, unless you request earlier deletion.
- Activity logs: Retained for 90 days for security and audit purposes.
- Login attempts: Retained for 30 days for security monitoring.
When data is no longer needed, we securely delete or anonymize it.
7. 7. Data Security
We implement industry-standard technical and organizational security measures to protect your personal data, including:
- Encryption of data in transit (TLS/SSL) and at rest (database-level encryption).
- Secure password storage using hashing (never in plaintext).
- Brute-force protection on admin login (account lockout after 3 failed attempts with exponential backoff timers).
- Role-based access control — only authorized personnel can access personal data.
- Regular security audits and vulnerability assessments.
- Secure hosting on Neon PostgreSQL with connection pooling and SSL.
- HTTP-only, SameSite cookies to prevent cross-site scripting (XSS) and cross-site request forgery (CSRF) attacks.
Despite these measures, no system is 100% secure. If a data breach occurs that poses a risk to your rights and freedoms, we will notify you and the relevant authorities within 72 hours, as required by law.
8. 8. Cookies and Tracking Technologies
We use cookies and similar technologies to operate our website and improve your experience. We use two categories of cookies:
- Strictly necessary cookies: Required for the website to function (e.g., session management, security). These cannot be disabled.
- Functional cookies: Save your theme preference (light/dark) and cookie consent choice so we don't ask twice. Optional — you can manage these via the cookie settings button.
We do not use advertising cookies, third-party tracking pixels, or behavioral profiling cookies. For full details, see our Cookie Policy.
9. 9. Your Privacy Rights
Depending on your location, you may have the following rights regarding your personal data:
- Right of access: Request a copy of the personal data we hold about you.
- Right to rectification: Request correction of inaccurate or incomplete data.
- Right to erasure: Request deletion of your personal data (“right to be forgotten”).
- Right to restrict processing: Request that we limit our use of your data under certain circumstances.
- Right to data portability: Request your data in a structured, machine-readable format.
- Right to object: Object to our processing of your data for direct marketing or other legitimate-interest-based processing.
- Right to withdraw consent: Withdraw consent at any time for processing based on consent (e.g., newsletter, reviews) without affecting the lawfulness of processing before withdrawal.
To exercise any of these rights, email privacy@zoibox.com with your request. We will respond within 30 days. If you are not satisfied with our response, you may lodge a complaint with your local data protection authority.
10. 10. International Data Transfers
Your data is stored on servers hosted by Neon (PostgreSQL) in the United States (AWS us-east-2). If you are accessing our Services from outside the United States or India, please be aware that your data will be transferred to and processed in these jurisdictions. We ensure appropriate safeguards are in place for such transfers, including standard contractual clauses where required.
11. 11. Children’s Privacy
Our Services are not directed at children under 16. We do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal data, please contact us at privacy@zoibox.com and we will promptly delete it.
12. 12. Changes to This Policy
We may update this Privacy Policy from time to time. We will post the updated version on this page and update the “Last updated” date. If we make material changes, we will notify you via email (if we have your email) or a prominent notice on our website. We encourage you to review this page periodically.
13. 13. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us:
- Email: privacy@zoibox.com
- Legal: legal@zoibox.com
- Address: Zoibox Creative Labs Pvt., 14 Jayanagar 5th Block, Bengaluru, Karnataka, India 560041
Questions about this policy? Email legal@zoibox.com.