Privacy Policy
Last updated: 29 July 2026
This Privacy Policy explains how SaranshDesigns, a sole proprietorship owned by Saransh Sharma, based in Bhopal, Madhya Pradesh, India (“we”, “us”) collects, uses and protects your information when you use MakeLogo at makelogo.in (the “Service”). We are the data controller for that information.
If you are in the European Economic Area or the United Kingdom, this Policy is written to meet the GDPR and UK GDPR. If you are in India, it is written to meet the Digital Personal Data Protection Act, 2023. If you are in California, see “California residents” below.
1. Information we collect
- Account information: when you sign in with Google, we receive your name, email address and profile picture from Google. We never see your Google password.
- Content you provide: the brand briefs, business names, taglines, requirements and edit instructions you type, and the logo images generated from them.
- Payment records: a record of what you bought, when, for how much, and a payment reference. Card and UPI details are entered inside our payment provider’s own checkout — we never receive or store your card number.
- Technical and security data: IP address, device and browser information, and server logs of sign-in attempts, failed authorisation attempts and rate limits. We use these to keep the Service working and to stop abuse.
- Cookie choices: your answer to the cookie banner, so we don’t ask again.
We do not ask for, and do not want, sensitive personal data — health, biometrics, government IDs, religion or the like. Please don’t put any into a logo brief.
2. Why we use it, and our legal basis
| What we do | Why | Legal basis (GDPR Art. 6) |
|---|---|---|
| Create your account, generate and store your logos, deliver purchased files | It is the service you asked for | Performance of a contract |
| Take payment, track credits, handle refunds | To complete your purchase | Performance of a contract |
| Keep records of what was sold | Tax and accounting law | Legal obligation |
| Security logging, rate limits, the anti-bot check, abuse investigation | To keep the Service available and stop fraud and automated abuse | Legitimate interests |
| Reply to your support emails | To help you | Legitimate interests |
| Advertising and conversion measurement cookies | To see which ads bring people here | Consent — and only after you accept in the cookie banner |
Where we rely on legitimate interests, we have weighed them against your rights; you can object at any time (see “Your rights”).
We do not use your briefs or logos to train our own AI models, and we do not sell your personal data — to anyone, ever.
3. Who else processes your data
Running the Service means a small number of specialist providers handle data on our behalf, under contract and only on our instructions:
| Provider | What it does | Where |
|---|---|---|
| Google (Sign-In) | Verifies who you are when you log in | USA / global |
| Supabase | Login sessions, database, storage of your logo files | See “International transfers” |
| Google Cloud (Cloud Run) | Runs the application server | India (Mumbai) |
| Cloudflare | Website hosting, security, the anti-bot check | Global network |
| Dodo Payments | Takes payment as Merchant of Record; handles card data and tax | Global |
| AI processing providers | Turn your brief into logo concepts and print-ready vector files | USA / global |
| Google Ads, Meta | Advertising measurement — only if you accept advertising cookies | USA / global |
What this means in practice: the text of your brief is sent to AI processing providers so they can draw your logo. Don’t include confidential information you wouldn’t want processed by a third party.
This table lists the categories of provider, which is what the law asks us to publish. If you would like the current list of the specific companies we use in any category — for your own due diligence, or to exercise a right below — email support@makelogo.in and we will send it to you.
We also disclose data if the law genuinely requires it, and we would tell you unless legally barred from doing so.
4. International transfers
We are based in India, and our providers operate globally, so your data may be processed outside your country — including in India and the United States. India has not received an EU “adequacy decision”, so where we transfer personal data of people in the EEA or UK, we rely on the European Commission’s Standard Contractual Clauses (and the UK Addendum) in our contracts with these providers, together with appropriate technical safeguards including encryption in transit. You may request a copy of the relevant safeguards by writing to us.
5. How long we keep it
- Your account, briefs and logos: for as long as your account exists. Delete your account and they are erased — including the image files themselves — not merely hidden.
- Payment records: retained after account deletion for as long as Indian tax and accounting law requires (currently up to 8 years). These are minimal records of the transaction, not your card details.
- Security and server logs: up to 90 days, then discarded.
- Cookie choice: up to 12 months, or until you change it.
6. Cookies and similar technologies
We use as few as we can get away with.
- Strictly necessary (no consent needed, and the Service cannot work without them): your login session, the brief you are part-way through, your cookie choice, and Cloudflare’s anti-bot check.
- Preference: your language choice, stored in your own browser.
- Advertising and measurement (Meta, and Google Ads if enabled): these measure whether an ad led someone to us.
- In the EEA, UK and Switzerland they are never loaded unless you accept them. Until you answer the banner, those scripts are not placed on the page at all — not merely disabled — and if you reject, they never load.
- Elsewhere, including India, they load by default and you can switch them off at any time using Cookie settings below. Turning them off reloads the page without them.
You can change your mind at any time via Cookie settings, in the footer of every page, or by clearing cookies in your browser. Your choice is remembered wherever you are, and always overrides the default.
We also set a short-lived cookie recording the country your connection appears to come from, so we know which of the two rules above to apply to you.
7. Your rights
Wherever you live, you can ask us to:
- Access your data — or just download it yourself, any time, from your account page (“Download my data”).
- Correct anything that is wrong.
- Delete your account and everything in it — there is a button for this in your account, and it works immediately.
- Port your data — the download is a standard, machine-readable JSON file.
- Restrict or object to processing based on legitimate interests.
- Withdraw consent for advertising cookies, without affecting anything that happened before.
Write to support@makelogo.in and we will respond within 30 days. We will not charge you or make it difficult, and we will never refuse a deletion request to keep you as a customer.
If you are in the EEA or UK and you think we have got this wrong, you may complain to your local data protection authority. If you are in India, you may complain to the Data Protection Board of India. We would rather you told us first so we can fix it.
8. California residents
We do not sell your personal information, and we do not “share” it for cross-context behavioural advertising as CCPA/CPRA define those terms. You have the right to know what we hold, to delete it, to correct it, and not to be discriminated against for exercising those rights. Use the same account controls or email address above.
9. Security
Payment card data never touches our servers. Access to your logos and account is checked on every request, files you have paid for are served only to you, and our systems are built to refuse rather than guess when something is wrong. We keep security logs and review our dependencies for known vulnerabilities. No system is perfectly secure, but if a breach ever affects your data we will notify you and the relevant authority as the law requires — within 72 hours where the GDPR applies.
10. Children
The Service is not for children. You must be 18 or older to use it, and we do not knowingly collect data from children. If you believe a child has given us data, write to us and we will delete it.
11. Automated decisions
Your logos are generated by AI, but no automated system makes a decision that has a legal or similarly significant effect on you. Our anti-abuse checks may temporarily rate-limit a request; email us and a human will look at it.
12. Changes
We may update this Policy. Material changes will be reflected by updating the “Last updated” date above, and if the change affects your rights we will tell you in the Service before it takes effect.
13. Contact
For any privacy question, or to exercise any right above, email support@makelogo.in or see our Contact page.