Skip to content
SHIVSASTRA
LEGAL & SECURITY MEMORANDUM

Privacy Policy

Last updated: September 24, 2026 · Operator: Shivam Shukla / SHIVSASTRA

1. Scope and Operator Identity

SHIVSASTRA is the personal portfolio, services, and digital product website operated by Shivam Shukla.

The website is currently deployed and accessible at https://shivsastra.vercel.app, with canonical production domain configuration established for https://shivsastra.vercel.app. This Privacy Policy applies to personal information collected through both addresses and related subpaths.

For any privacy questions or requests regarding your data, contact Shivam Shukla directly at: theshivamshukla.4uu@gmail.com.

2. Information Submitted via Contact Form

When you initiate an inquiry or engagement through the public contact form, the following details are collected:

  • Name / Organization: To identify who is contacting the studio.
  • Direct Email: To respond to your inquiry directly.
  • Inquiry Brief: The project details, requirements, or message you provide.

This information is stored in a private, managed Supabase database instance with Row Level Security (RLS) enabled. Public anonymous read access is completely revoked; submissions are accessible solely by authenticated administrative server routines with service-role credentials.

3. Security & Abuse Prevention

We implement reasonable technical and architectural safeguards to protect the website and server infrastructure from distributed denial-of-service (DDoS) and automated spam attacks, including:

  • HTTPS / TLS Encryption: All data transmitted between your browser and the website is encrypted in transit using industry-standard TLS protocols.
  • Anonymized Rate Limiting: Incoming requests extract the client IP address server-side from proxy headers. The IP address is immediately converted into a salted SHA-256 cryptographic hash. This anonymized hash is used as an ephemeral counter in Upstash Redis to enforce rate limits (5 submissions per 10-minute window). Raw IP addresses are never logged or persisted in database tables.
  • Cloudflare Turnstile: We use Cloudflare Turnstile to verify human interaction without intrusive puzzle CAPTCHAs. Verification tokens are checked server-side via Cloudflare Siteverify and are single-use; tokens are never permanently stored.
  • Honeypot Validation: Form fields include invisible honeypot elements to silently trap automated bot submissions.
  • Database Security Policies: Database access is guarded by strict Row Level Security (RLS) policies and least-privilege service credentials.

Please note that while reasonable technical safeguards are deployed, no method of transmission over the Internet or electronic storage can be guaranteed as entirely immune to risk.

4. Infrastructure & Hosting

The deployed website utilizes the following infrastructure providers:

  • Vercel: Application hosting, edge proxy, and production deployment with automated HTTPS/TLS encryption.
  • Supabase: Managed database storage for inquiries and published content.
  • Upstash Redis: Ephemeral in-memory sliding-window counter storage for rate limiting.
  • Cloudflare: Turnstile bot verification service.

5. Cookies & Analytics

The public website does not use marketing cookies, tracking pixels, third-party advertising networks, or invasive analytics services. Essential cookies are utilized solely for authenticated administrative sessions in the private studio dashboard.

6. Digital Product Orders & Payment Processing

When you purchase a digital product from the SHIVSASTRA Store, we collect your direct email address to generate your order record, issue a purchase receipt, and deliver your secure download token.

Payments are processed directly by our payment gateway partner, Razorpay. Sensitive card numbers, CVVs, and banking credentials are handled exclusively by Razorpay under industry payment standards; SHIVSASTRA servers never receive, store, or process raw payment instruments.

Digital delivery links are protected by single-use signed tokens and download attempt limits stored securely in our database.

7. Data Retention & User Rights

Information is retained only for as long as reasonably necessary for the purpose for which it was collected, subject to applicable legal or operational requirements. Ephemeral rate-limiting counters in Redis automatically expire after 10 minutes.

Depending on applicable law, you may have rights regarding access, correction, deletion, or restriction of your personal information. You may contact Shivam Shukla using the contact information provided on this website at theshivamshukla.4uu@gmail.com.

8. Children's Privacy

This website is intended for professional and general audiences and does not knowingly collect personal information from children under 13 (or applicable local age limit). If you believe such information was submitted, please contact us for prompt removal.

9. Policy Updates

This Privacy Policy may be updated periodically to reflect changes in technical infrastructure, operational practices, or applicable legal requirements. The updated date at the top of this memorandum indicates the effective revision.