Skip to content

Privacy

How this site handles your data

Last updated 2026-09-01

This site collects almost nothing. Use the contact form and whatever you type into it is the only personal data involved. No analytics script and no tracking pixel run on this site at launch; the one exception is a security check on the form itself, covered below. WitNip Inc, the Delaware, USA entity behind this practice, is the controller for anything you send.

Who controls this data

WitNip Inc (Delaware, USA) is the data controller for nipunarora.me. Nipun Arora founded WitNip Inc and is its founder; every engagement and every reply sent through the contact form runs through this entity, not a personal address with no legal standing behind it.

What this site collects

Only what you type into the contact form: your name, your email address, your website address, your market, your message, and, if you check the box, a preferred day or time for a call. Reading a page sets nothing and asks nothing; the site itself runs no analytics. Google Search Console and Bing Webmaster Tools read this site's existing crawl and search data from the outside; neither one runs a script in your browser or collects anything from a visitor reading a page.

The contact form runs one security check before it sends: Cloudflare Turnstile confirms a person submitted it, not an automated script. Turnstile does not read your name, email, or message, and it may set a short verification cookie scoped to that check, nothing wider. There is no cookie banner on this site, because nothing on it collects or stores anything beyond that one security check: no analytics cookie, no advertising cookie, no tracking pixel to get consent for.

Why it's collected

To reply to your message. What you send about a possible engagement gets read, answered, and used to work out whether that engagement makes sense, nothing wider than that.

How long it's kept

As long as it stays useful to the conversation it came from, plus ordinary business recordkeeping for an active or past engagement. There is no fixed deletion timer running in the background. Ask for a message to be deleted and it happens promptly, not on a schedule set months out.

Who else sees it

Nobody. Nothing you send is sold, rented, or handed to a third party for marketing, beyond the ordinary infrastructure that carries the form to a real inbox: Cloudflare's Turnstile check and Resend's email relay. Both move the message; neither analyzes it or resells it.

Access or delete what you sent

Use the contact form and ask, whether the request is to see a copy of a past message, correct it, or delete it outright. That form handles every data-subject request this site can receive, because it is also the only place personal data arrives.

How this site is hosted

nipunarora.me is a static site served from Cloudflare Pages: prebuilt HTML, CSS, and images, no server-side database and no session state attached to a visitor. A page load itself asks nothing of you and stores nothing about you. The one exception is the contact form, which runs as a small serverless function on the same platform to relay a submitted message. That function holds nothing beyond a short-lived counter used to block spam bursts; it is not a database either.

Which rules this policy follows

The UAE's Federal Decree-Law No. 45 of 2021 on personal data protection reaches a Delaware company the moment it takes on a Dubai client, so this policy is written to the standard that law sets: name the controller, state the purpose, state retention, and say how to reach the controller for a deletion or access request. This practice does not market to the European Union, so GDPR's own territorial trigger is not met today, but the policy above is written broadly enough to hold up as good practice under it anyway rather than needing a rewrite the day that changes.

A question about this policy goes through the same place as everything else: the contact form.