Privacy Policy
Explains how Goafreet collects, processes, protects, retains, and disposes of personal data across website and service interactions.
Table of Contents (59)
Legal Questions?
Need commercial clarification on our terms or standard contracts?
Table of Contents (59 Sections)
Scope & Contractual Summary
Comprehensive data protection operating policy explaining how Goafreet collects, processes, protects, retains, and disposes of personal data across website and service interactions.
Who We Are
Goafreet ("Goafreet", "we", "us" or "our") respects the privacy of individuals who interact with our website, digital tools, communications and professional services. This Privacy Policy explains the types of personal information we may receive, the purposes for which it may be used, the circumstances in which it may be shared, the measures used to protect it, and the choices and rights that may be available under applicable law. Goafreet is an India-based brand management, digital marketing, ecommerce, technology and creative services firm operating from Vadodara, Gujarat, India. This Privacy Policy applies to personal information processed in connection with Goafreet's website, enquiries, business communications, client engagements, digital tools and other activities described below.
Where This Policy Applies
This Policy explains how Goafreet may collect, receive, use, process, store, organise, analyse, share, disclose, transfer, retain, protect, correct and delete personal data and other information across our operations:
Website and Digital Tools: The Goafreet website; contact, enquiry and project consultation forms; calculators, generators and browser-based utilities; and downloadable resources.
Business Development and Client Relationships: Service enquiries, consultations, meetings, proposals, quotations, Statements of Work, client onboarding, account administration, and project communications.
Service Delivery: Digital marketing and SEO; paid advertising and performance marketing; social media management; ecommerce and marketplace management; website, web application and software development; UI/UX, branding and graphic design; content, influencer and creator marketing; photography, video and media production; printing, packaging and offline marketing; and research, strategy and consulting.
Business Administration: Invoicing and payment administration, support requests, vendor and contractor interactions, recruitment, security, fraud prevention, legal compliance, and dispute management.
Associated Legal Policies: This Policy should be read together with Goafreet's other applicable policies, including: Terms of Use; Service Terms & Conditions; Service Usage Rules & Limits; Client Data Policy; Cookie Policy; Responsible Outreach & Anti-Spam Policy; Confidentiality & NDA Policy; Intellectual Property Policy; Third-Party Services Disclaimer; and General Disclaimer.
Contract Precedence: Where Goafreet and a client have entered into a signed agreement, accepted proposal, Statement of Work or other written commercial document containing specific terms for an engagement, those specific terms apply to that engagement and prevail over inconsistent general website terms to the extent permitted by law.
Legal Framework
Goafreet seeks to handle personal information in accordance with applicable Indian data-protection and technology laws, to the extent applicable and in force from time to time, including:
• the Digital Personal Data Protection Act, 2023; • the Digital Personal Data Protection Rules, 2025, taking account of their phased commencement; • the Information Technology Act, 2000; • applicable rules and directions relating to reasonable security practices, cybersecurity and electronic records; and • applicable consumer protection, contract, tax, employment, intellectual property, advertising and marketplace requirements.
Scope of Application: Where a law applies only after a notified commencement date, to a prescribed class of organisation, or subject to a threshold, exemption or special condition, Goafreet applies the requirement to the extent legally applicable.
International Interactions: Where Goafreet provides services to or interacts with persons outside India, additional privacy laws may apply depending on the nature of the activity, the country involved and whether Goafreet is legally subject to that jurisdiction. Such obligations, where applicable, may be addressed through additional notices, contractual terms or data-processing agreements.
Key Privacy Roles
Depending on the context, Goafreet may act in different roles under applicable data protection laws:
4.1 Goafreet as Data Fiduciary: For information collected directly for Goafreet's own purposes — for example website enquiries, proposals, invoicing, recruitment, account administration, support, marketing preferences or security — Goafreet generally determines the purposes and means of processing. Under Indian data-protection terminology, Goafreet acts as a Data Fiduciary where applicable.
4.2 Goafreet as Data Processor on Behalf of Clients: For contracted client services, a client may provide Goafreet with access to customer records, leads, CRM data, marketplace accounts, ecommerce orders, ad-platform audiences, or marketing lists. In those circumstances, the client determines the relevant purpose and Goafreet processes information on the client's instructions as a Data Processor. The client's own privacy notice, legal basis, permissions, and platform obligations govern the relationship with its end-customers.
4.3 Independent Activities: In limited circumstances, both Goafreet and another organisation may independently determine particular purposes for processing, subject to applicable contracts.
Categories of Individuals Whose Information We May Process
This Policy may apply to personal data relating to:
• website visitors and users of our digital tools; • prospective clients and client leads; • clients and authorised client representatives; • employees and personnel of client organisations; • vendors, suppliers, contractors, freelancers and consultants; • business partners, creators, photographers and videographers; • event, webinar and consultation participants; • job applicants and prospective personnel; • persons communicating directly with Goafreet via phone, email or web forms; and • individuals whose data is processed as part of a client engagement under lawful instructions.
Information We May Collect
The exact information collected depends on how a person interacts with Goafreet. We collect only information reasonably necessary for legitimate business purposes:
6.1 Identity and Contact Information: Full name, business name, company name, job title, designation, work email address, telephone number, WhatsApp number, business address, city, state, country, and preferred communication method.
6.2 Business and Professional Information: Organisation type, industry, company size, website URL, social media profiles, service interests, marketing objectives, target markets, approximate project budget range where voluntarily disclosed, and meeting notes.
6.3 Enquiry and Onboarding Information: Project briefs, scope requirements, brand assets, technical specifications, marketplace store identifiers, communication history, approvals, and feedback.
6.4 Account Authentication and Authorised Access: Where required for service delivery, Goafreet utilizes role-based invitations, delegated partner access, and platform permissions (e.g. Google Ads Manager link, Meta Business Manager Partner access, Amazon Seller Central secondary permissions) rather than requesting master administrative passwords.
Financial, Billing and Tax Information
For billing and commercial administration, Goafreet may process billing entity name, billing address, GSTIN, PAN or tax identification numbers where legally required, purchase orders, quotations, invoices, bank-transfer transaction references, and payment status records. Goafreet does not store full payment-card numbers or sensitive card authentication data. Online payment transactions are processed directly by certified third-party payment aggregators under their respective security standards.
Website and Technical Information
When visiting the Goafreet website, technical telemetry may be recorded automatically by hosting infrastructure, security firewalls, or configured analytics scripts. This may include IP address, browser type and version, device type, operating system, language preferences, referring URL, pages visited, session timestamps, approximate geographic region derived from IP, and diagnostic error logs. Production analytics and cookie controls are detailed in our Cookie Policy.
Information Submitted to Digital Tools
Goafreet provides interactive calculators, generators, and digital utilities. The operational data flow depends on the tool's architecture:
9.1 Browser-Only Tools: Certain Goafreet tools (including the Email Extractor and text utilities) are designed to process user-provided information locally in the user's web browser. Where a tool is expressly described as browser-only, the content entered into that tool is not transmitted to Goafreet's servers merely to perform the tool's core function. General website error telemetry and aggregate page-visit metrics may still generate separately.
9.2 Server-Assisted Tools: If a digital tool requires server-side computation or an external API integration, the tool interface will clearly disclose what information is transmitted and the purpose of the processing prior to execution.
Communications Data
Goafreet retains records of professional correspondence conducted through email, telephone, WhatsApp, contact forms, video meetings, and project management portals. Records may include message text, attachments, timestamps, meeting summaries, project instructions, and approvals. Calls and video conferences are recorded only where advance notice and consent are established.
Vendor, Freelancer and Partner Information
For vendors, contractors, and freelance specialists, Goafreet processes contact information, service proposals, banking details for payment remittance, tax records, confidentiality undertakings, and performance records for commercial administration and accounting compliance.
How We Obtain Information
Goafreet obtains information directly from the individual, through website forms, via client authorised representatives, during project execution, from authorised platform integrations, and from publicly available professional business sources. Public availability does not create unrestricted permission for processing. All data usage remains subject to applicable law, platform rules, and Goafreet's Responsible Outreach & Anti-Spam Policy.
Purposes for Which We Process Information
Goafreet processes personal information strictly for legitimate, specified, and lawful business purposes, including:
• Responding to enquiries, scheduling consultations, and preparing proposals; • Evaluating project scope, onboarding clients, and assigning resources; • Delivering contracted marketing, advertising, ecommerce, technology, and creative services; • Managing project milestones, approvals, task tracking, and deliverable handovers; • Invoicing, payment processing, GST reconciliation, and statutory accounting; • Maintaining security, authenticating users, detecting abuse, and preventing fraud; • Complying with applicable legal, regulatory, and tax obligations; and • Maintaining professional business relationships and sending relevant service updates.
Lawful Basis and Consent
Goafreet processes personal data only where an appropriate lawful basis is available under applicable law, including valid consent, voluntary provision for a specified purpose, fulfillment of commercial contracts, legal compliance, or legitimate uses recognized under the Digital Personal Data Protection Act, 2023. Where processing is based on consent, individuals may withdraw consent at any time by contacting info@goafreet.com. Withdrawal does not affect the lawfulness of processing carried out prior to withdrawal, nor does it require deletion of records mandated by statutory retention requirements.
Data Minimisation
Goafreet strives to collect and process only the information reasonably necessary for the relevant purpose. Users, clients, and personnel are advised to avoid submitting unnecessary sensitive information, including passwords, OTPs, financial account credentials, or unnecessary identity documents.
Accuracy of Information
Goafreet takes reasonable steps to ensure personal data used in decisions affecting an individual is accurate and complete. Individuals are responsible for providing truthful information and promptly notifying Goafreet of material updates to contact details.
Client-Provided Personal Data
When a client provides customer lists, CRM data, or marketplace account access to Goafreet for service delivery, the client represents and warrants that it has established an appropriate lawful basis, provided required statutory notices, and secured necessary permissions under applicable privacy laws. Goafreet may refuse or suspend processing where client instructions appear unlawful, unauthorized, or inconsistent with platform regulations.
Publicly Available Business Information and Outreach
In B2B business development and outreach, Goafreet may reference publicly available corporate contact information. All outreach communications must be contextually relevant, non-deceptive, compliant with anti-spam standards, and accompanied by a frictionless opt-out mechanism.
Sensitive and High-Risk Information
Goafreet does not routinely collect or process highly sensitive personal categories (such as biometric data, health records, genetic data, or religious beliefs) through general website interactions. Users should never submit sensitive personal data through standard website forms.
Children's Personal Data
Goafreet’s website, digital utilities, and professional services are directed to businesses, professionals, and adults capable of entering into lawful commercial relationships. Goafreet does not knowingly collect personal data from children under the statutory age of majority without verified parental or legal guardian consent.
Persons with Lawful Guardians
Where applicable law requires a lawful guardian to exercise data privacy rights on behalf of an individual, Goafreet will require reasonable verification of the guardian's legal authority before acting on any request.
Cookies and Tracking Technologies
Goafreet uses cookies and web storage technologies for essential navigation, display preferences, performance monitoring, and analytics. Detailed descriptions of deployed cookies and user control options are available in our Cookie Policy.
Analytics and Advertising Technologies
Where active, Goafreet may utilize web analytics and measurement tools (such as Google Analytics) to understand aggregate traffic trends. These third-party services process telemetry under their own global privacy disclosures. Goafreet does not configure analytics tools to capture sensitive user inputs.
Sharing of Information
Goafreet does not sell or rent personal information to third parties. Information may be shared strictly under lawful circumstances with:
• Authorised personnel, technical leads, and specialists on a need-to-know basis; • Contractors, freelancers, and professional advisers bound by confidentiality covenants; • Technology infrastructure providers (hosting, cloud storage, CRM, email, accounting) under data processing terms; • Client-authorised platforms (Google, Meta, Amazon, Flipkart, Meesho, Shopify) during service delivery; and • Judicial, statutory, or law enforcement authorities where strictly mandated by law.
Data Processors and Service Providers
Where Goafreet engages third-party providers to process information on its behalf, Goafreet takes reasonable measures to ensure the provider maintains appropriate confidentiality, technical security safeguards, and purpose limitations.
International and Cross-Border Processing
Certain cloud infrastructure, software, and advertising platforms utilize globally distributed server networks. Where cross-border data transfers occur, Goafreet complies with applicable Indian legal guidelines and ensures reasonable data protection safeguards are maintained.
Data Security Safeguards
Goafreet implements reasonable administrative, organizational, and technical safeguards appropriate to the nature of the information processed. Safeguards include role-based access limits, multi-factor authentication (MFA), TLS encryption for data in transit, encrypted storage repositories, and access reviews. No internet-connected system can be guaranteed 100% secure, and Goafreet cannot warrant absolute immunity from sophisticated cyber incidents.
Personnel Access Controls
Personnel access to client and visitor information is governed by least-privilege principles. Access is granted only as necessary for assigned responsibilities, reviewed periodically, and revoked immediately upon conclusion of engagement.
Remote Work and Device Security
Where personnel access business systems remotely, Goafreet enforces endpoint security standards, including strong device passcodes, full disk encryption, secure networks, and prompt reporting of lost or compromised hardware.
Security Incident and Breach Management
In the event of a confirmed personal data breach affecting systems under Goafreet’s direct control, Goafreet will take immediate containment steps, assess the impact, and notify affected parties and competent regulatory authorities in accordance with applicable legal timelines.
Data Retention Standards
Goafreet retains personal data only for as long as reasonably necessary to fulfill the purpose of collection, provide contracted services, satisfy statutory tax and accounting requirements, and defend against potential legal claims. Detailed retention principles are documented in our Data Retention & Deletion Policy.
Erasure and Disposal
When personal data is no longer required, Goafreet securely deletes, anonymizes, or destroys the records using industry-standard erasure practices, subject to legal hold requirements.
Rights of Individuals
Subject to applicable law, identity verification, and statutory exceptions, individuals may have rights concerning their personal data, including:
• Right to access a summary of personal data being processed; • Right to request correction of inaccurate, outdated, or misleading information; • Right to request completion of incomplete personal data; • Right to request erasure of personal data where retention is no longer justified; • Right to withdraw consent where processing is based on consent; and • Right to nominate another individual in the event of death or incapacity, as provided under Indian law.
Limitations on Rights
Privacy rights are not absolute. Goafreet may lawfully decline or restrict a request where identity cannot be verified, where the request infringes upon another person’s rights, where retention is mandated by tax or legal statutes, or where records are required for active commercial dispute resolution.
Verification of Privacy Requests
To safeguard individuals against fraudulent access or unlawful data deletion, Goafreet may require reasonable verification of the requester’s identity (such as confirmation from the registered email address) prior to processing privacy requests.
Authorised Representatives
Where an individual acts through an authorised legal representative, Goafreet may require written proof of authority or power of attorney before disclosing or modifying personal information.
Privacy Questions and Grievance Redressal
Questions, requests, or grievances concerning this Privacy Policy or Goafreet's handling of personal data may be submitted to Goafreet's designated compliance channel:
Organisation: Goafreet | Operating Location: Vadodara, Gujarat, India | Official Email: info@goafreet.com | Business Phone: +91 9106981512 | Response Timeline: Acknowledged within 48 hours; substantive resolution within the timeframe required by applicable law or otherwise within a reasonable period.
Note: Data Principals should utilize Goafreet's internal grievance mechanism before escalating matters to statutory authorities.
Direct Marketing Preferences
Recipients of promotional communications can opt out at any time by clicking the unsubscribe link in the email footer or emailing info@goafreet.com. Transactional, billing, operational, and security notices will continue as required for active client relationships.
Third-Party Websites and Links
Goafreet’s website may contain hyperlinks to external third-party platforms. Goafreet does not control the independent privacy policies or operational practices of external sites, and users should review their respective disclosures.
Social Media Platforms
When users engage with Goafreet across social media networks (Instagram, LinkedIn, Facebook, X, YouTube), the host platform processes personal data independently under its own terms. Goafreet receives only public profile details and interaction metrics.
Client Platform Accounts
When Goafreet manages client advertising or marketplace accounts (Google Ads, Meta Business Manager, Amazon Seller Central, Flipkart Seller Hub), Goafreet operates within the client-authorized permission scope. Platform data remains subject to client instructions and platform policies.
Confidential Business Information
Goafreet treats client business strategies, creative assets, pricing frameworks, and customer lists with strict confidentiality. Personnel are bound by non-disclosure agreements as detailed in our Confidentiality & NDA Policy.
Intellectual Property and Data
Exercise of data privacy rights does not transfer ownership of proprietary software source code, creative designs, agency methodologies, or trade secrets developed by Goafreet.
Automated Tools and AI-Assisted Workflows
Goafreet may utilize automation and artificial intelligence tools to assist in research, drafting, and operational analysis. Goafreet does not input confidential client data or personal records into public AI models without appropriate privacy protections and human review.
Personnel Data Handling Obligations
Client and personal information accessed by Goafreet personnel is accessed strictly for authorized business duties. Personnel are prohibited from exporting client databases for personal use or retaining records post-engagement.
Protection of Goafreet Personnel
Clients and users must respect the privacy and security of Goafreet personnel. Harassment, unauthorized publication of staff personal details, or attempts to compromise staff accounts are strictly prohibited.
System Monitoring and Security Audits
Goafreet maintains proportional system access logs and security telemetry to prevent cybersecurity incidents, detect fraud, and verify system integrity. Monitoring is used strictly for legitimate security purposes.
Law Enforcement and Government Requests
Goafreet cooperates with lawful judicial warrants and statutory agency requests under Indian law. Where legally permissible, Goafreet validates the jurisdiction of requests and seeks to narrow excessive demands.
Legal Claims and Fraud Prevention
Relevant communication records, contract documentation, and server logs may be retained beyond standard periods where necessary to investigate fraud, enforce contracts, defend against legal claims, or address disputes.
Business Continuity and Backups
Goafreet utilizes secure, redundant backups to preserve operational continuity. Data purged from active production systems will automatically expire from encrypted backups in accordance with standard backup rotation schedules.
Data Portability and Export
Where legally mandated or contractually agreed, Goafreet will provide clients with an export of their primary data in a standard machine-readable format, excluding proprietary agency software architecture.
Anonymised and Aggregated Information
Data that has been genuinely and irreversibly anonymized such that no natural person can be identified falls outside the scope of personal data. Goafreet may utilize aggregated statistics for industry benchmarking and service improvement.
Case Studies and Portfolio Use
Goafreet does not publicly publish client performance metrics or case studies containing identifying information without prior written client authorization or appropriate masking of confidential data.
Testimonials and Endorsements
Client testimonials, quotes, and photographs are published exclusively with the individual’s explicit consent and may be edited for typographical clarity without altering substantive meaning.
Changes to This Privacy Policy
Goafreet may periodically update this Privacy Policy to reflect statutory developments, new digital tools, or operational changes. Updated versions will be published with a revised "Last Updated" date.
Governing Interpretation
This Policy constitutes an operational privacy framework and does not waive statutory defenses or contractual limitations available to Goafreet. In the event of an irreconcilable conflict between this Policy and mandatory statutory law, mandatory law prevails.
Contact Information
For privacy inquiries, rights requests, or regulatory communications, contact Goafreet's designated compliance channel:
Trade Name: Goafreet | Operating Location: Vadodara, Gujarat, India | Official Email: info@goafreet.com | Business Phone: +91 9106981512
Operational Consistency Notice
This Privacy Policy reflects Goafreet’s actual technical and organizational practices across its website and service operations.
Contractual Hierarchy & Precedence
This document forms part of Goafreet’s operational legal architecture and is intended to be read in conjunction with our Master Service Terms and specific engagement proposals. Where a mutually signed Master Service Agreement (MSA), Statement of Work (SOW), or bilateral Non-Disclosure Agreement (NDA) contains more specific or differing terms, the signed agreement shall strictly prevail for that engagement.
Public Corporate Identification & Contact
Goafreet is an India-based brand management, digital marketing, ecommerce operations, technology engineering, and creative consulting firm operating from Vadodara, Gujarat, India.
Official Communications: info@goafreet.com | Telephone: +91 9106981512
