Privacy and lead information
Privacy Policy
This development policy describes the approved data-handling design for consultation requests. It must be checked against the implemented form, notifications, and production operations before launch.
Who is responsible
Travel With Zihad is an individual content creator and social influencer providing study abroad guidance described by this policy. The guidance is provided directly on an individual basis and not by a company or corporate agency. The development privacy contact is hello@travelwithzihad.example. A production identity, address, and contact must be approved before launch.
Information the consultation request collects
The approved form is designed to collect information needed to understand and respond to a study abroad consultation request.
- Name, email address, and WhatsApp number
- Highest education level and completion-year range
- English-test result or preparation status
- Service interest and preferred study destination
- Academic background, intended course, maximum budget in BDT, and biggest concern
- Required privacy acknowledgement, copy version, and acceptance time
Attribution and request metadata
The service may collect strictly limited first-party referrer, landing page, form page, UTM, campaign, locale, and user-agent information for request context and operations. It will ignore any client-supplied IP field.
Raw IP addresses will not be stored with leads. When needed for abuse prevention, rate limiting, or duplicate controls, a trusted server or proxy IP may be transformed with a server-keyed hash before use.
Why information is used
Information is intended to assess and respond to a consultation request, deliver an agreed service, maintain consent and lead-event records, prevent abuse and duplicates, and support approved operational reporting. Marketing consent is not collected in the initial form.
Storage, access, and sharing
Lead records are planned for MySQL on the self-managed application VPS. Access must be limited to authorized staff. The production notification recipient and any vendors have not yet been confirmed; this policy must name or accurately describe them before those workflows go live.
WhatsApp and Telegram are third-party channels with their own data practices. Avoid sending unnecessary sensitive information through them.
Retention and deletion
The approved default is to retain lead data for 12 months, then delete or anonymize it unless an active business or legal need supports a documented exception. The operational deletion workflow will be documented before launch.
Security and its limits
The application is designed to validate input, keep database credentials server-only, minimize logs, and avoid personal lead data in URLs or analytics. No internet service can promise absolute security; confirmed production safeguards and incident contacts must be documented before launch.
Your requests and complaints
To ask about access, correction, deletion, retention, or a privacy concern, use the development privacy contact hello@travelwithzihad.example. Identity may need to be verified before acting on a request. Production procedures and jurisdiction-specific rights require owner or legal review.
Changes to this policy
The policy must be reviewed whenever the form fields, purposes, vendors, notifications, retention, or infrastructure change, and at least annually after launch. A confirmed effective date and reviewed date will be displayed with the approved production text.
