Privacy Policy & Security Practices
This Privacy Policy outlines how your personal information is gathered, utilized, and protected when you interact with the digital portfolio and consulting services of Muhammad Arslan.
1. Direct Inquiries & Information Collection
We collect information that you voluntarily submit when initiating project inquiries or communications:
- Contact Identifiers: Name, work email address, and company/organization name.
- Project Briefs: Desired services (UI/UX design, Webflow development, WordPress development), budget estimates, and project scope details.
- Direct Channels: Messages transmitted via direct email or encrypted messaging (WhatsApp).
We never sell, rent, or distribute your inquiry data to data brokers, third-party advertisers, or marketing networks.
2. Browser Storage & Cookies
This website is engineered with a privacy-first, minimal-footprint philosophy:
- Essential LocalStorage: We use browser LocalStorage strictly for functional purposes: caching portfolio taxonomies, retaining reading progress, and preventing automated form spam.
- Zero Invasive Tracking Cookies: We do not deploy third-party advertising pixels, behavioral marketing tracking, or persistent cross-site tracking cookies.
3. Infrastructure & Technical Subprocessors
To deliver high performance and reliable uptime, this website utilizes modern, reputable infrastructure providers:
- Hosting & CDN: Vercel Global Edge Network for static site compilation and content delivery under strict Transport Layer Security (TLS 1.3 / HTTPS).
- Cloud Database & Storage: Google Cloud Firebase for authorized content administration, protected by strict server-side Firestore security rules.
- Media Hosting: Unsplash for high-resolution project reference photography.
- Website Analytics: Google Analytics (GA4) via Google Tag Manager for aggregated, privacy-preserving visitor and page engagement metrics.
4. Security Hardening & Defense-in-Depth
We enforce industry-standard defensive controls across our codebase:
- Strict Content-Security-Policy (CSP): Defends against Cross-Site Scripting (XSS) by restricting executable script, style, and frame sources.
- Anti-Clickjacking Headers: Enforces
X-Frame-Options: DENYand CSPframe-ancestors: none. - MIME Protection: Enforces
X-Content-Type-Options: nosniff. - Bot Protection & Throttling: Incorporates automated honeypot spam detection and client submission rate limiting.
- Strict Non-Disclosure (NDA): All proprietary project briefs and confidential client designs shared during discovery are treated as strictly confidential.
5. Your Rights & Contact Information
You retain full rights to request access to, updates for, or permanent deletion of any personal communications or briefs you have submitted.
For inquiries regarding this privacy statement or to request deletion of your information, please contact: