Legal
Privacy Policy
1. Who we are and what this policy covers
This Privacy Policy explains how Crazydes Private Limited ("DCI," "we," "us," "our"), operating the Design Credibility Index™ platform at designcredibilityindex.com and app.designcredibilityindex.com (together, the "Platform"), collects, uses, discloses, and protects personal data belonging to anyone who creates an account, submits a case study, or views a public profile on the Platform ("you," "user"). Design Credibility Index is a product of Crazydes Private Limited.
The core commitment this policy exists to state plainly, up front: we do not use your personal data for marketing purposes, and we do not sell, rent, or share your personal data with third parties for their own independent use. The only entities that ever receive your data are the specific, named service providers in Section 5 below, strictly limited to what they need to actually operate the Platform on our behalf: never for their own marketing, never resold, never repurposed.
2. Data we collect, and exactly why
We collect only what the Platform's actual functionality requires. Nothing below is collected "in case it's useful later."
| Category | What, specifically | Why | Source |
|---|---|---|---|
| Account identity | Your first and last name, email address, Google account profile photo (if provided by Google) | To create and operate your account; your name is displayed publicly on your DCI profile by design; see Section 3 | Google Sign-In (OAuth), at account creation |
| LinkedIn connection (optional) | Your LinkedIn-verified name and profile photo (fetched once, at connection time), and the LinkedIn profile URL you type in yourself | To let you connect your DCI profile to your LinkedIn identity, required before your profile becomes publicly visible | LinkedIn OAuth (name/photo only; you enter the profile URL yourself) |
| Payment records | Amount charged, currency, payment status, a payment reference ID | To grant you a submission credit and maintain an auditable purchase history | Razorpay (our payment processor). We never receive, see, transmit, or store your card number, UPI ID, or any other raw payment instrument. All of that is handled entirely within Razorpay's own systems. |
| Submission content | The case study content, links, and materials you submit for review | To have your submission reviewed and scored | Submitted directly by you |
| Review outcome | Your score, per-metric breakdown, and (privately, to you only) reviewer comments | To show you and, if you choose to publish, the public, your DCI result | Generated internally by our review process |
| Session and technical data | Session tokens (to keep you signed in), IP address and basic device/browser information | To keep your account secure and to operate the single-active-session security model described in Section 8 | Collected automatically when you use the Platform |
We do not run any advertising, ad-tracking, or cross-site analytics pixels on the Platform. We do not collect data for the purpose of building an advertising profile of you, on this Platform or anywhere else.
3. Your real name is shown publicly: read this before you continue
Unlike many platforms that let you use a handle or pseudonym, your DCI public profile displays your real first and last name, taken from your Google account, and (once you connect it) a link to your LinkedIn profile. This is a deliberate design choice: the Platform's value depends on showing that scored profiles belong to real, verifiable people, not anonymous or disposable accounts. If you are not comfortable with your real name and a score being publicly associated, you can keep your profile set to private at any time (Section 7), in which case nothing about your submission or score is visible to anyone but you.
4. Legal basis for processing (GDPR Article 6)
For users in the European Economic Area, the UK, or other jurisdictions with an equivalent legal-basis requirement, we rely on the following bases, and only these:
- Performance of a contract (Art. 6(1)(b)): for account creation, authentication, payment processing, submission handling, and score delivery.
- Legitimate interests (Art. 6(1)(f)): for basic security measures (fraud prevention, session integrity, abuse detection), balanced against your rights and never extending to marketing or profiling.
- Consent (Art. 6(1)(a)): for the optional LinkedIn connection specifically, which you separately and explicitly opt into; you can withdraw this at any time by disconnecting LinkedIn (Section 7).
We do not rely on consent as a basis for marketing communications, because we do not send marketing communications and do not process your data for that purpose at all.
5. Who we share data with, and the strict limits on that sharing
We share personal data only with the specific service providers below, each acting as our data processor, strictly to operate the features you use. None of them are permitted to use your data for their own marketing, to sell it, or to combine it with other data they hold about you for any purpose beyond delivering the specific service listed.
| Provider | What they receive | Why | Their role |
|---|---|---|---|
| Razorpay | Payment amount, currency, your name/email as needed for the transaction | To process your payment | Payment processor |
| OAuth authentication tokens | To verify your identity when you sign in | Identity provider | |
| OAuth authentication tokens (only if you choose to connect) | To verify your identity for the optional LinkedIn connection | Identity provider | |
| Resend | Your email address, and the content of the one transactional email we send | To deliver transactional email | Email-delivery processor; never used for marketing sends |
| Neon | All data stored in the Platform's database | To host and store Platform data | Database processor |
| Vercel | Application logs, request metadata | To host and run the Platform's application code | Infrastructure/hosting processor |
We do not share your data with data brokers, advertising networks, analytics companies that build cross-site profiles, or any third party for their own independent commercial use. We disclose data beyond the table above only where legally compelled to do so, and even then, only to the minimum extent legally required. We will notify you of such a request unless legally prohibited from doing so.
Your public profile is different from the sharing above. If you choose to make your DCI profile public (Section 7), the score and content you've explicitly chosen to publish is, by definition, visible to anyone with the link, including search engines that may index it. That is a visibility setting you control directly, not third-party data sharing.
6. International data transfers
Our infrastructure providers (Neon, Vercel, and others in Section 5) may process and store data outside your country of residence, including outside the European Economic Area. Where this occurs for users protected by GDPR, we rely on Standard Contractual Clauses (SCCs) or an equivalent recognized transfer mechanism with each such provider, and we require every processor we use to maintain security and confidentiality standards consistent with this policy regardless of where they operate.
7. Your rights, and how to exercise them
Regardless of your jurisdiction, we extend the following rights to every user, in line with GDPR and India's Digital Personal Data Protection Act 2023:
- Access: request a copy of the personal data we hold about you.
- Rectification: correct inaccurate data (most of your account data is editable directly in Account Settings; contact us for anything that isn't).
- Erasure ("right to be forgotten"): delete your account and associated personal data at any time via Account Settings (certain payment/audit records are retained afterward where required for legal and accounting purposes).
- Restriction of processing: ask us to pause processing of your data in specific circumstances.
- Data portability: receive your data in a structured, commonly-used format. A self-service export feature is not yet available; until it ships, submit this request to the contact below and we will handle it manually.
- Object to processing: object to processing based on legitimate interests (Section 4).
- Withdraw consent: for the LinkedIn connection specifically, at any time, with no effect on the lawfulness of processing before withdrawal.
- Lodge a complaint: with your local data protection authority (in the EU, the supervisory authority in your country of residence; in India, the Data Protection Board once constituted under the DPDP Act).
To exercise any of these rights, contact us at support@designcredibilityindex.com. We will respond within the timeframe required by applicable law (30 days under GDPR, subject to extension in complex cases).
8. Security measures
We maintain security measures appropriate to the sensitivity of the data described in this policy, including: encrypted connections (HTTPS/TLS) everywhere; hashed/tokenized session credentials, never plaintext passwords (we do not store passwords at all; authentication is entirely via Google/LinkedIn OAuth); a single-active-session model that invalidates old sessions on new sign-in; environment-isolated secrets management so no credential is shared across development, staging, and production; and role-restricted internal access to personal data, logged via our administrative audit trail. No security measure is perfect, and we will notify affected users and relevant authorities of any data breach in accordance with applicable law.
9. Data retention
We retain personal data only as long as necessary for the purposes described in this policy: account and profile data for as long as your account is active, plus a limited period after deletion where required for legal, tax, or fraud-prevention purposes (payment records, in particular, are retained per applicable financial recordkeeping law, typically several years, even after account deletion). Administrative audit logs are retained long-term as our accountability record for privileged actions taken on the Platform.
10. Children's privacy
The Platform is not directed at, and is not intended for use by, anyone under the age of 16 (or the higher age of consent applicable in your jurisdiction). We do not knowingly collect personal data from children. If we become aware that we have inadvertently collected such data, we will delete it promptly.
11. Cookies and similar technologies
We use only the minimum technical cookies necessary to operate the Platform: specifically, a session cookie (httpOnly, secure) that keeps you signed in, and a short-lived signed cookie used only during the LinkedIn-connect flow. We do not use advertising cookies, cross-site tracking cookies, or any third-party analytics cookies that build a profile of your browsing activity.
12. Changes to this policy
We will update the "last updated" date above whenever this policy changes, and will provide clear notice (e.g., an in-app notification or email) of any material change before it takes effect.
13. Contact
For any question about this policy or your data: support@designcredibilityindex.com.
This document should be read alongside our Terms of Service and Refund & Cancellation Policy.