Privacy Policy
Last updated: 26 February 2026 · Effective immediately upon publication
1. Who We Are
7 Color Box LLP (“7 Color Box”, “we”, “us”, or “our”) is a Limited Liability Partnership registered in India, operating a credit-based digital agency platform at 7colorbox.com. Our registered office is in Noida, Uttar Pradesh, India.
This Privacy Policy governs how we collect, use, store, and share personal information you provide when using our website and client portal. It is drafted in compliance with the Information Technology Act, 2000 and the IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (“SPDI Rules”).
2. Information We Collect
2.1 Information You Provide Directly
- Account registration: Full name, company name, work email address, and password (hashed; never stored in plaintext).
- Task briefs: Descriptions, brand guidelines, reference files, and any content you upload as part of a task brief.
- Communications: Messages sent via task comments, email, or our contact form.
- Payment information: Billing address and payment method details — processed exclusively by our payment processor (Razorpay) and never stored on our servers.
2.2 Information Collected Automatically
- Usage data: Pages visited, features used, session duration, and actions taken within the client portal.
- Technical data: IP address, browser type, operating system, and referring URL.
- Cookies and similar technologies: Session tokens and preference cookies — see our Cookie Policy for full details.
2.3 Sensitive Personal Data
Under the SPDI Rules, financial payment details qualify as sensitive personal data. We do not store raw payment card data. All payment transactions are processed via Razorpay (PCI-DSS compliant). We may store transaction reference IDs and payment status for billing reconciliation.
3. How We Use Your Information
- To create and manage your account and client portal access.
- To process task submissions, credit purchases, and subscription management.
- To communicate project updates, task status changes, and deliverable notifications.
- To send transactional emails (welcome, receipts, task alerts, delivery notifications).
- To improve our platform — analysing usage patterns to fix bugs and enhance features.
- To comply with applicable Indian law, respond to legal process, or enforce our Terms of Service.
- To prevent fraud, abuse, and unauthorised access to the platform.
We do not use your data for third-party advertising. We do not sell or rent your personal information to any third party.
4. Data Sharing and Third-Party Processors
We share your data only with service providers that are strictly necessary to operate the platform. All third-party processors are contractually bound to handle data securely and only for the purposes we specify.
| Processor | Purpose | Data Shared |
|---|---|---|
| Supabase (US) | Database, authentication, file metadata | Email, profile data, task data |
| Scaleway / S3 | File storage for deliverables and briefs | Uploaded files only |
| Razorpay (India) | Payment processing | Billing details, transaction amount |
| Resend (US) | Transactional email delivery | Email address, name |
Some processors (Supabase, Resend) store data outside India. By using our platform, you consent to such cross-border transfer under Section 43A and Rule 7 of the SPDI Rules.
5. Data Retention
- Account data: Retained for the duration of your account and for 7 years thereafter for financial audit purposes, as required under Indian accounting law.
- Task and deliverable files: Deliverable files are available for 15 days after task completion. After 15 days, files are archived. Archived files may be permanently deleted after an additional 180 days.
- Brief files you upload: Retained for the lifetime of the associated task plus 90 days.
- Payment records: Retained for 7 years to comply with Indian financial regulations.
6. Your Rights
Under applicable Indian law, you have the right to:
- Access: Request a copy of the personal data we hold about you.
- Correction: Request correction of inaccurate or incomplete data.
- Deletion: Request deletion of your account and associated personal data (subject to legal retention obligations).
- Withdrawal of consent: Withdraw consent for data processing; note that withdrawal may affect your ability to use the platform.
To exercise any right, email us at contact@7colorbox.com with subject line “Data Privacy Request”. We will respond within 30 days, consistent with our obligations under applicable law.
7. Security
We implement industry-standard technical and organisational security measures including encrypted storage (AES-256), HTTPS-only transport (TLS 1.2+), hashed passwords (bcrypt), and role-based access controls. Authentication is provided via Supabase Auth with row-level security policies enforced at the database layer.
Despite these measures, no internet transmission is 100% secure. We cannot guarantee absolute security, but we commit to notifying affected users and relevant authorities in the event of a breach, as required by law.
8. Children's Privacy
Our services are not directed at individuals under the age of 18. We do not knowingly collect personal information from minors. If we become aware that a minor has registered, we will promptly delete the account.
9. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email and/or a notice on the platform. Continued use of the platform after changes constitutes acceptance of the updated policy.
10. Contact
For privacy concerns, data requests, or complaints: