Legal
Privacy Policy
Last updated 20 Sept 2026
This describes exactly what this website collects, why it collects it, and how long it is kept. It is written from how the site actually works rather than from a template.
Who we are
This website is run by [registered business name to be confirmed], trading as Vellappaniyaram Groups, Mathur, Krishnagiri - 635203, Tamil Nadu.
You can reach us about anything on this page through the contact form.
What we collect
Only what you type into a form, plus one technical detail:
- Enquiries. Your name, and your phone number and/or email so we can reply, plus your message and which division it was about.
- Bookings and quote requests. The same, plus the service, date and time slot you asked for and anything you added in the message.
- Your IP address. Stored with each submission. It is used to rate-limit the forms so they cannot be flooded, and nothing else.
- Your cookie choice. Recorded with a random visitor id so we can show what was consented to, and under which version of this policy. That id is generated here and is not linked to you.
We do not use analytics, advertising pixels, social trackers or session recording. There is no account system and no newsletter list.
What we do not collect
- No card numbers, CVV or bank details. This site does not take payments at all - see the Refund & Cancellation policy.
- No location data, contacts, or anything from your device beyond the page you requested.
- No profiles built across sites, and no data sold or shared for marketing.
Why we are allowed to hold it
Because you asked us to do something with it. When you send an enquiry or request a booking you are asking us to get back to you, and we need your details to do that. The consent checkbox on each form records that, and you can withdraw it at any time by asking us to delete your enquiry.
Who can see it
Only the owner of Vellappaniyaram Groups, through a password-protected admin area on this site. The database sits on our own hosting; we do not pass enquiries to any third-party CRM or marketing service.
If email notifications are switched on, a copy of a new enquiry may be sent to the owner’s inbox through the hosting provider’s mail service.
How long we keep it
- Enquiries and bookings: kept while they are useful for the job and our records, and deleted on request.
- Rate-limit records: automatically deleted after 24 hours.
- Cookie consent records: kept for the life of the consent (about six months) as proof of what was agreed.
- Admin login sessions: expire automatically, by default after 12 hours.
Your rights
You can ask us to:
- Tell you what we hold about you.
- Correct anything that is wrong.
- Delete it.
- Stop using it.
Write to us and we will deal with it. We may ask you to confirm the phone number or email you originally used, so that we do not hand your enquiry to someone else.
Security
The site is served over HTTPS. Admin passwords are stored only as bcrypt hashes and never in readable form. Admin sessions are httpOnly cookies that expire, admin actions are logged, and login attempts are rate limited. Uploaded files are checked by their actual content, not their file name.
No system is perfect. If you believe something here is not secure, please tell us rather than anyone else first.
Cookies
See Cookie Preferences for the full list and to change your choice at any time.
Changes
If this policy changes materially we will update the date at the top and, where the change affects cookies, ask for your choice again. Current policy version: 1.0.
A note on this draft
This policy accurately describes how the website behaves today. It has not been reviewed by a lawyer, and the registered business details are still to be confirmed. Please have it checked against your actual business registration and the law that applies to your visitors before launch.
Questions about any of this? Get in touch.
