1. Overview
This Privacy Policy describes how Suraj Kadam ("I", "me", "the operator") collects, uses, and protects information when you interact with imsurajkadam.com and any related services operated under the following businesses:
- Hidden Leaf Media (HLM) — performance marketing agency (Meta Ads, Google Ads, lead-gen funnels, daily WhatsApp reports)
- PopWheels — e-commerce store for RC cars and PopBricks Lego-style building sets (popwheels.store)
- RenderCut — SaaS tool for AI-generated captions for short-form video (rendercut.io)
- KyotoOS — internal AI automation infrastructure that powers this site, daily briefings, and lead-gen
Collectively referred to here as "the services". By using any of the services, you agree to the practices described in this policy.
2. Information I Collect
I collect the minimum information needed to run the services. Specifically:
2.1 Information you give me directly
- WhatsApp messages when you click the WhatsApp CTA — your phone number, profile name, and message contents
- Instagram DMs when you message @yesitskyoto
- Email when you write to [email protected]
- Form submissions on any landing page (e.g. "book a call", "free audit") — name, email, phone, business URL, ad account info
2.2 Information collected automatically
- Server logs: IP address, browser user-agent, referrer, pages visited, time of visit (kept for 30 days for security)
- Cookies: a single functional cookie for your "you are here" position on the site. No third-party tracking cookies, no Google Analytics, no Meta Pixel on this portfolio site. (Meta Pixel is used only on ad landing pages for client campaigns, with disclosure on those pages.)
3. How I Use Your Information
I use the information collected to:
- Respond to your WhatsApp / Instagram / email enquiries
- Deliver the service you signed up for (ad reports, audit, retainer work, SaaS access)
- Send you invoices and receipts
- Detect and prevent fraud, spam, or abuse of the services
- Improve the services based on aggregate usage patterns (no individual tracking)
I do not sell, rent, or trade your personal information to third parties for marketing purposes. Period.
4. Data Storage & Security
- This portfolio site is hosted on Cloudflare Pages (Cloudflare's global edge network). Data passes through their infrastructure — see Cloudflare's Privacy Policy.
- Application data (CRM records, ad account credentials, client files) is stored on a private VPS running KyotoOS, secured with HTTPS, firewall, and access logs.
- WhatsApp Business conversations are stored on Meta's servers per WhatsApp's retention policy.
- Payment data (invoices, UPI/bank transfer records) is stored in accounting software (likely Tally/Zoho Books) and not on public-facing systems.
No system is 100% secure. If a data breach occurs, I will notify affected users within 72 hours as required by applicable law.
5. Third-Party Services I Use
The services rely on the following third parties. Each has its own privacy policy:
- Meta (Facebook / Instagram / WhatsApp) — for ads, messaging, and the WhatsApp Business API
- Google — for Google Ads, Google Workspace, and Google Cloud
- Cloudflare — DNS, CDN, Pages hosting, security
- GitHub — code repositories (private repos for client work)
- Stripe / Razorpay / PayPal — if applicable, for SaaS or service payments
- TokenRouter (PaleBlueDot.AI) — AI/LLM inference for KyotoOS automation
- Deepgram / Sarvam — speech-to-text for AI workflows
- Apify — public-data scraping (e.g. for ATC lead generation)
6. Cookies
The portfolio site uses one first-party functional cookie for client-side state (e.g. which section you're reading). I do not use advertising cookies, retargeting pixels, or third-party analytics on this site. You can disable cookies in your browser without affecting your ability to use the site.
7. Data Retention
- WhatsApp / Instagram / email conversations: kept for the duration of our working relationship + 12 months
- CRM records and client work files: kept for the duration of the engagement + 7 years (for tax / accounting purposes)
- Server logs: rolled off after 30 days
- RenderCut account data: kept while your account is active; deleted within 30 days of account closure
8. Your Rights
You can at any time:
- Request a copy of all personal data I hold about you
- Request correction of inaccurate data
- Request deletion of your data (subject to legal retention requirements above)
- Opt out of any future communications
To exercise any of these rights, email [email protected]. I will respond within 7 business days.
9. Children's Privacy
None of the services are intended for children under 18. I do not knowingly collect data from children. If you believe a child has submitted data, contact [email protected] and I will delete it.
10. International Users
The services are operated from India. If you are accessing from outside India (e.g. USA, EU, UK), you acknowledge that your data will be transferred to and processed in India. India's data protection laws (including the Digital Personal Data Protection Act, 2023) provide protections comparable to GDPR for most practical purposes.
11. Changes to This Policy
I may update this policy as the services evolve. Material changes will be announced by updating the "Last updated" date at the top and, where appropriate, by direct email notification to active clients.
12. Contact
For privacy questions or to exercise your rights:
Suraj Kadam
Navi Mumbai, Maharashtra, India
Email: [email protected]
WhatsApp: +91 90049 05332