Skip to content
Security & data handling

What This Site Does With Your Data

Devkart is a software studio, so this page is short: what devkart.com itself collects, how what you share during an engagement is handled, and where the security pages for the two products we operate live.

devkart.com

What This Website Handles

A static site with one form, a chat widget and consent-gated analytics. Everything below is what its own configuration and policies say.

Contact form

Submissions go to Netlify Forms, which hosts this site, and are forwarded to us by email. The form asks for your name, email, company, phone and message, carries a honeypot field against bots, and includes a consent checkbox. There are no accounts and no logins on this site.

Analytics, only with consent

Google Analytics loads only after you accept analytics cookies in the banner. IP anonymisation is on, Google Signals and ad personalisation are off, and declining clears the cookies a previous acceptance set. The cookie policy lists every cookie the site can write.

Chat

The Crisp chat widget loads after your first interaction with the page. Messages you send through it are stored by Crisp; its cookies are functional and are listed on the cookie policy. Block them in your browser and the rest of the site still works.

Booking a call

Scheduling is an external link to Cal.com, opened in a new tab. Nothing is embedded here — you enter your details on their page, under their privacy terms, only if you choose to book.

Transport and headers

HTTPS only, with HTTP Strict Transport Security preloaded. The Content Security Policy permits scripts from this origin, Crisp and Google Tag Manager and nothing else, forbids embedding the site in a frame, and restricts form posts to this origin.

Card data

None. This site sells nothing directly and takes no payment details. Invoices for engagements are settled outside the website, under the project agreement.

The full register is on the cookie policy and the privacy policy.

Working with us

Information Shared During an Engagement

A project puts repositories, credentials and business data in front of us. This is what the agreement you sign says about them, in plain language.

Confidentiality
Client information is treated as confidential under our terms, access to it is limited to the people working on your project, and we sign a separate NDA when you require one.
Access you grant
Repositories, cloud accounts and third-party services are yours: you grant the access the engagement needs, in your own systems, and you can narrow or withdraw it at any time.
Subcontractors
Anyone working on your project who is not on our staff does so under the same confidentiality obligations we hold, and only for that project.
Ownership
Intellectual property in the delivered work is defined in the project agreement. Deliverables are handed over on completion, and a 90-day warranty period follows delivery.
Retention
Project material is kept for the duration of the project plus two years, and financial records for seven years where the law requires it. Both periods are published in the privacy policy.
Where the software runs
What we build is delivered to run on infrastructure you own or contract, so the security posture of a delivered system is set by that platform and by how it is operated — which is what an IT consulting engagement reviews.

The binding text is the terms and conditions and your project agreement; where they differ from this summary, they win.

The Boundaries, Stated Up Front

The scope of what this site and this studio will assert, written down so you can weigh it now rather than meet it in a procurement review.

  • Everything we assert about this site is checkable against its own configuration and the two policy pages. Formal certification (SOC 2, ISO 27001) is not something we hold, so no badge appears here.
  • devkart.com is a static marketing site hosted by Netlify, so its availability is our host's rather than a commitment of ours — no uptime figure or SLA is attached to it.
  • Support runs business hours, with replies across time zones; the response commitments that bind us are written into each engagement's agreement rather than advertised on this site.
  • Payments never touch this site — it sells nothing directly and takes no card details — so there is no card data here for PCI scope to cover.
  • What we publish about data protection is concrete: the privacy policy names what we collect, why, and for how long. Compliance itself is a property of how a client operates, so 'GDPR-compliant' is not a label we apply to ourselves.
  • The site is static and collects only what the sections above describe, which is why no third-party penetration test of devkart.com has been commissioned or published.
For your security questionnaire

Five Questions Clients Ask a Studio

Answered here the way we answer them on the form, so nothing surprises you later in the process.

  • Certifications

    Do you hold SOC 2 or ISO 27001?

    No. Devkart is a software studio, and the systems we build are deployed into infrastructure the client owns, so a certification of our own office would not describe the system you end up running. For the two products we operate, the security detail is published on supaorder.com/security and superapphq.com/security.

  • This website

    What does devkart.com collect, and where does it go?

    Contact form submissions go to Netlify, which hosts the site, and are forwarded to us. Chat messages are stored by Crisp. Google Analytics runs only after you consent, with IP anonymisation on. Booking a call takes you to Cal.com. The privacy policy names each provider and what it receives.

  • Engagement data

    How is information we share during a project handled?

    As confidential information under our terms, with a separate NDA when you require one. Access is limited to the people on your project, subcontractors work under the same obligations, and access to your own systems is granted and withdrawn by you. Project material is retained for the project plus two years.

  • Support and availability

    Is support 24/7, and is there an uptime guarantee?

    Support runs business hours with responses across time zones, and the response commitments that apply to an engagement are written into its agreement. devkart.com itself publishes no uptime figure; a system we build for you runs on your platform, and its availability is a property of that platform and how it is operated.

  • Reporting

    How do we report a security issue?

    Email contact@devkart.com with enough detail to reproduce it. The same address is published in the machine-readable security.txt at devkart.com/.well-known/security.txt. We acknowledge every report, say what we intend to do, and credit you if you would like us to.

Reporting a vulnerability

If you believe you have found a security issue in this website or in software we operate, email contact@devkart.com with enough detail to reproduce it. We will acknowledge it, tell you what we intend to do, and credit you if you would like us to. Please do not test against a client's live system — ask us and we will arrange a safe way to look.

The same contact is published in machine-readable form at /.well-known/security.txt, which names this section as the disclosure policy.

Ready to ship custom software that scales?

Custom software, SaaS platforms, and MVPs — engineered to scale from day one. Tell us what you're building — we'll reply within 24 hours with a clear plan and an honest estimate.

Free consultation · No upfront costs · Reply within 24 hours