Home/Privacy Notice

Privacy Notice

How we handle analytics data on www.ciss.co.in — what we collect, why, and how you control it.

Effective: 6 August 2026 · Consent policy version: a1

Your choice matters

Optional analytics only runs if you click Accept. You can change your mind at any time.

Who we are

Central India Security & Services (CISS), MIG-11, Padmakar Nagar, Makronia, Sagar — 470004, Madhya Pradesh, India. Contact: drsangtomar@gmail.com · +91 99267 73460

What analytics is for

When you accept, we use first-party analytics to:

  • Understand which pages are visited and how often
  • Measure call and WhatsApp button clicks (counts only — not who called)
  • See approximate city/region distribution to understand our service-area reach
  • Detect abuse and prevent automated flooding of our analytics
  • Improve site content and deployment decisions

What we collect — always vs linked to your browser

Always counted (by default, no consent): page path (/sagar/), button clicks (target ID + channel), engagement time, device class, browser/OS, viewport, referrer hostname, UTM, and approximate city/region derived from your current network address (IP is never shown to you or stored raw — masked/encrypted). These batches use an ephemeral per-page-load ID — no persistent browser fingerprint, no way to link your future visits.

Only after you click Accept: a random Browser ID and Session ID cookie let us link your clicks/page views across pages and visits into one journey (top-visitor table). Reject or do nothing → each page is an anonymous visitor.

What we never collect

  • Names, phone numbers, or messages you type into the enquiry form
  • Full URLs, query strings, or fragment identifiers
  • Keystrokes, mouse movements, scroll recordings, or session replay
  • GPS coordinates — unless you explicitly grant location permission in your browser after clicking Accept (you can always deny; IP-based approximate location still applies)
  • Device fingerprinting (canvas, WebGL, fonts, sensors, etc.)
  • Any attempt to recreate an identifier you deleted

Browser ID ≠ Person

A “visitor” in our dashboard means one browser profile with a random ID — not a verified person or physical device. One person may appear as multiple visitors (different browsers, after clearing cookies, private browsing, or expiry). Multiple people sharing one browser appear as one visitor. The dashboard explains this.

Location is approximate

City and country are derived from your real network address — via our hosting provider's IP-location headers or a free public IP lookup service. It can be wrong, missing (“Unknown”), or reflect a nearby hub — never your precise address. If you click Accept and then explicitly allow location access when your browser asks, we additionally store that GPS fix and its reverse-geocoded city/region on your browser profile for up to 30 days (cached in your own browser storage, never re-prompted). You can deny the prompt at any time and analytics keeps working with the network-based approximate location.

Third-party analytics (PostHog)

We also use PostHog (posthog.com, US cloud) to visualize visits — page views, clicks, and device/location data derived from your network address. Before any consent choice it runs in strictly cookieless, anonymous mode: no cookies, no browser storage, and identity is a privacy-preserving server-side hash that cannot follow you between visits. Only when you click Accept do its cookies and persistent storage activate, letting your visits link into one journey. Clicking Reject keeps PostHog permanently cookieless. Its data is subject to PostHog's own privacy policy.

Cookies we use

CookiePurposeLifetime
ciss_consentYour analytics choice (yes/no) — same value for everyone making that choice180 days
ciss_bidRandom Browser ID (HttpOnly, not readable by page scripts)180 days
ciss_sidSession ID, rolling 30-minute window (HttpOnly)30 min (rolling)

All cookies use SameSite=Lax, Path=/, and Secure on HTTPS. Page/CTA counts work without cookies. Browser/session cookies and IP storage only happen after you Accept.

How to withdraw

At any time:

  • Click and choose Reject, or clear cookies for www.ciss.co.in in your browser
  • Withdrawing stops new collection immediately and deletes your Browser/session cookies
  • Previously collected events are retained until the retention period below, then deleted automatically

How long we keep data

DataRetention
Exact encrypted network address30 days, then ciphertext deleted
Events & masked network / approximate geo180 days
Inactive visitor/session rows with no retained events180 days of inactivity

Who processes data

Analytics is hosted on Vercel (application hosting) and Turso (database). Both act as processors for this first-party analytics. No third-party advertising tracker is loaded before your consent. An embedded Google Map is replaced with a click-to-open link so no Google request happens until you explicitly open it.

Your rights

To make a privacy request (access, correction, erasure, grievance), contact us at the address above or email drsangtomar@gmail.com. We will respond in accordance with applicable law, including India's Digital Personal Data Protection Act, 2023 where applicable. This notice is not legal advice.

Changes

When this notice changes materially, the consent version increments and the banner will ask for a fresh choice. Previous consent does not carry over.

Manage your analytics preference

← Back to home

Mobilise Today

Ready to Secure Your Premises?

Get in touch today and let us build a security plan for your facility. MHA-approved, ISO-certified, and trusted since 1994.

Call NowWhatsApp