Privacy policy
Last updated 10 August 2026
ConeApex is consent-first by construction, and the short version is that we collect very little. No tracking cookies. No advertising networks. No behavioural profiling. Nothing sold or brokered, ever. The longer version follows.
What we collect
- If you buy something
- Your name, email, and the brief and brand material you send us. Enough to do the work and to invoice you.
- If you register interest
- Your email address, and the track or cohort you asked about. Nothing else.
- If you pay us
- We receive a payment reference and a status from Razorpay. We never see or store your card number, CVV, UPI PIN or bank credentials — those go directly to the payment processor and never touch our systems.
- If you only read the atlas
- Nothing that identifies you. Any analytics we add will be aggregate and privacy-preserving, and it is off until it is built.
Why we hold it
- To produce and deliver what you ordered.
- To invoice you and meet Indian tax and accounting obligations.
- To send you the updates you asked for — and only those.
We do not use your material to train models for anyone else, and we do not resell it.
Who else processes it
- Razorpay Software Private Limited
- Payment processing. Receives what you enter at checkout. India-based.
- Notion Labs
- Onboarding form submissions, where that transport is used.
- Vercel
- Website hosting and standard server logs.
Some of these process data outside India. Where that happens it is disclosed here, and it is the reason this page exists rather than a boilerplate. A fuller vendor register — what each one touches, its data-processing terms and where it stores things — is maintained internally and reviewed annually.
How long we keep it
- Order records and invoices — retained as long as Indian tax law requires.
- Your brand material and source files — 12 months after final delivery, then deleted. Ask sooner and we delete sooner.
- Mailing list — until you unsubscribe, which is one email or one click.
Your rights
Under India's Digital Personal Data Protection Act you may ask what we hold about you, have it corrected, have it deleted, or withdraw consent. Write to [email protected].
- We acknowledge within 1 working day.
- Deletion completes within 7 days, except records we are legally required to keep — we will tell you specifically which, and why.
- There is no fee, and no form.
Security
Payment data never reaches our systems. Client material is held on encrypted storage with access limited to the founder. Where a voice model is created for an engagement, it is biometric-class data: it stays on local hardware, is never sent to a third-party service, is never reused elsewhere, and is deleted on request.
Children
Our services are sold to businesses and adults. We do not knowingly collect data from anyone under 18. If you believe we have, tell us and we will delete it.
Changes
If this policy changes materially we will say so here and date it. Continuing to use the site after a change means you accept the updated policy.