Privacy Policy
& Data Protection Standards.
Clear transparency on how CropMyImages handles your data, respects your privacy, and enforces strict compliance under India's Digital Personal Data Protection (DPDP) Act 2023.
CropMyImages acts as a Data Fiduciary under the Digital Personal Data Protection Act, 2023 (DPDP Act). We process personal digital data only for specified, lawful purposes with explicit consent or legitimate statutory uses. You, as a Data Principal, enjoy full statutory rights to access, correct, erase, or withdraw consent at any time.
Introduction & Scope
Welcome to CropMyImages ("Company", "We", "Us", or "Our"). We operate the website located at https://cropmyimages.com and associated web application utilities (including image cropper, unit resizer, format converters, QR generator, IP lookup, and URL shortener; please note that QR Generator and URL Shortener features are currently under active development and do not have full functionality).
This Privacy Policy outlines how we collect, store, process, transfer, and safeguard your personal data. By accessing or using our service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our data practices, please refrain from using our services.
Information We Collect
We adhere to strict data minimization principles. We only collect information that is strictly necessary to provide and optimize our web tools.
Email address, display name, profile image, and hashed credentials when you register an account or subscribe to paid plans.
IP address, browser user-agent, operating system, referrer URL, diagnostic request metrics, and daily usage quota counters.
Image files uploaded for cropping or conversion. Client-side canvas editing is performed locally in your browser. Ephemeral server-processed files are held in RAM and purged automatically.
Payment transactions are handled directly by PCI-DSS certified payment gateways (Stripe / Razorpay). We never store full credit card details.
Purpose & Lawful Grounds for Processing
Under Section 4 and Section 6 of the DPDP Act 2023, personal data is processed solely for lawful purposes on the basis of consent or specified legitimate uses:
- Service Execution: Executing image cropping, format conversions, unit resizing (px, cm, in, mm), QR rendering, and IP lookups as requested.
- Account Management: Authenticating your login sessions, managing billing plans, and delivering transaction receipts.
- Security & Abuse Prevention: Monitoring API rate limits, detecting bot traffic, preventing DDoS attacks, and ensuring platform integrity.
- Legal & Regulatory Compliance: Fulfilling statutory requirements under applicable Indian laws and global regulations.
Third-Party Data Processors (Sub-Processors)
We work with trusted third-party service providers (Data Processors) under strict data protection agreements. These processors operate under contract and cannot use your data for any unauthorized purpose:
| Processor | Category | Purpose | Data Location |
|---|---|---|---|
| Vercel Inc. | Hosting & Edge Network | Web hosting & serverless deployment | USA / Global Edge |
| Cloudflare, Inc. | CDN & DDoS Security | DNS, SSL encryption & bot protection | Global Edge |
| Stripe / Razorpay | Payment Gateway | PCI-DSS checkout & subscription billing | USA / India |
| Google LLC | Analytics & Advertising | Traffic insights & Google AdSense ads | USA / Global |
Data Retention & Automated Disposal Schedule
Data is retained strictly for as long as necessary to fulfill the processing purpose or satisfy statutory obligations under applicable law:
Purged automatically from ephemeral RAM cache
Hard deleted 30 days after account deletion request
Retained for intrusion detection & rate limit enforcement
Data Principal Rights under DPDP Act 2023
As a Data Principal under the DPDP Act 2023 (and equivalent rights under GDPR/CCPA for international users), you possess the following enforceable statutory rights:
Request a summary of your personal data being processed and identities of all sub-processors.
Correct inaccurate data or request complete deletion ("Right to be Forgotten").
Easily revoke previously granted processing consent at any time without fee or restriction.
Nominate another individual to exercise your data rights in the event of death or incapacity.
To exercise any of these rights, email your written request to contact@cropmyimages.com.
Children’s Personal Data Protections
In compliance with Section 9 of the DPDP Act 2023, CropMyImages does not knowingly process personal data of children under 18 years of age without verifiable parental consent. We do not conduct targeted advertising, tracking, or behavioral monitoring directed at minors.
If you believe a child has provided us with personal data without parental authorization, please contact our Grievance Officer immediately for prompt data erasure.
Data Security Measures
We employ rigorous technical, organizational, and physical safeguards to protect personal data against unauthorized access, loss, or disclosure:
- TLS 1.3 Encryption: All data in transit is encrypted using modern SSL/TLS protocols.
- AES-256 Storage: Database backups and tokens stored at rest are encrypted using 256-bit encryption.
- Access Controls: Strict role-based access control (RBAC) and mandatory multi-factor authentication for technical staff.
- Client-Side Isolation: Image rendering and pixel operations run inside client browser sandboxes whenever possible.
Grievance Officer & Statutory Redressal Details
Under Section 10 and Section 13 of the DPDP Act 2023, CropMyImages has designated a Data Protection & Grievance Redressal Officer. For any privacy inquiries, data deletion requests, or formal complaints, please reach out directly using the details below:
Grievance Redressal Officer
Within 30 Days (DPDP Mandate)
If your grievance is not resolved satisfactorily by our officer within the 30-day statutory period, you hold the legal right under DPDP Act Section 13 to escalate your complaint to the Data Protection Board of India.
