MarketRefer

Privacy Policy

Updated: 2 October 2026 · Notice version MR-PRIVACY-2026-10-02-3.

MarketRefer publishes shopping and home guides at www.marketrefer.com. The website owner handles privacy enquiries for MarketRefer through info@marketrefer.com. This notice explains the information involved, why it is used and how you can exercise your choices.

Optional Google Analytics is off until you choose to allow it. Reading our guides does not require analytics consent, registration or payment. We do not run advertising pixels, targeted advertising, public comments, reader accounts, newsletters or on-site order forms.

हिन्दी में गोपनीयता जानकारी. To request this notice or help with a privacy request in another language listed in the Constitution’s Eighth Schedule, email your preferred language to info@marketrefer.com. You do not need to submit identity documents to ask for a translation.

Information and purposes

  • Website delivery and protection: our hosting provider, Hostinger, receives connection information such as IP address, request time, requested URL, browser information and response status. This enables page delivery, availability and security. Administrator cookies support authorised sign-in; public readers do not need to sign in.
  • Security events: our application records selected login, account, permission, software and configuration events. Records contain a time, event type, relevant administrator identifiers and a keyed hash of the connecting network address. Our application audit does not store raw IP addresses, message bodies, passwords or payment details. Hosting logs are separate.
  • Messages and privacy requests: when you email us, we receive your email address, the name and message you choose to send, attachments, and delivery details. We use them to respond, verify relevant requests, resolve complaints and keep an appropriate record of the outcome. Do not include passwords, OTPs, payment-card details or unnecessary identity documents.
  • Optional analytics: with your permission, Google Analytics receives page views and outgoing-click events, cookie identifiers, browser/device details, approximate location and limited referral/campaign information. We use this to understand traffic, including Pinterest visits, and improve our guides. Advertising personalisation and Google signals are disabled. Automatic enhanced-measurement events are switched off; our own events use the public canonical page URL and destination domain rather than full outgoing URLs or their query strings.
  • Privacy-choice evidence: we keep a random receipt reference, your choice, notice version and text hash, language, time, expiry and whether an adult confirmation accompanied an allowance. This private record documents and implements the choice. It contains no raw IP address, email, browser fingerprint or visited URL. It is not sent to Google. Hosting connection logs remain separate.

Tracking and your browser

The banner offers equally prominent “Allow analytics” and “Reject optional” buttons, plus “Manage preferences”. Analytics is optional and its checkbox is not pre-selected. Allowance requires a separate confirmation that you are at least 18. Refusing or closing the banner does not prevent reading the website. The adult confirmation is a self-declaration, not verified identity or age assurance.

No Google tag or consent-mode ping is sent before a valid allowance. The website records the choice with its own server first; analytics stays off if permission cannot be saved or verified. Old opt-ins are not reused. Consent expires after up to 180 days, and a changed notice requires a new choice. Global Privacy Control or Do Not Track keeps analytics off.

Use “Privacy choices” and “Reject optional” to withdraw. This stops future measurement immediately in the current page, clears accessible first-party Google Analytics cookies, and updates other open tabs through the browser’s storage event. Rejection remains effective locally if the server cannot be reached; the site retries recording it on a later visit. Withdrawal does not undo processing already performed or automatically delete historical Google records. Contact us about those records. AMP views do not load analytics.

See the Cookie Policy. The consent banner is available in English and Hindi; contact us for another supported-language notice. Do not enable analytics if you cannot understand the notice.

Who receives information

Hostinger processes website information to provide hosting and security. The email service delivering correspondence processes messages. Google processes analytics data when you allow measurement and may retain historical data already collected. These providers may use infrastructure outside India. We do not promise India-only storage; provider locations, contractual safeguards and applicable transfer restrictions must be considered.

Read Hostinger’s data processing addendum and Google’s explanation of information from partner sites. We do not sell the information in privacy requests or use it for advertising. We may disclose information where required by applicable law or to respond to a valid legal process.

External and affiliate links

Clicking an external or affiliate link takes you to another service, sometimes through a network redirect. That service receives the connection and any link parameters, and its privacy notice applies. MarketRefer does not control its cookies or order records. We do not receive your payment-card details. Affiliate relationships are disclosed on the relevant page; see our Affiliate Disclosure.

Retention and deletion

  • Consent receipts: retained for up to 366 days after their last change, with scheduled daily deletion. Your browser choice lasts up to 180 days. Receipt references help us locate the consent record but do not by themselves identify a Google Analytics record.
  • Application security logs: scheduled rotation removes ordinary log files after 366 days. A documented incident or legal preservation hold can require longer retention. These logs are access restricted outside the public document root.
  • Correspondence: our operating schedule is to review ordinary enquiries for deletion within 12 months of closure. Privacy-request records are reviewed after 24 months of closure to retain a limited record of the request and response. Legal duties or a documented dispute can justify a longer period. The owner performs these mailbox reviews; this is not an automatic email deletion service.
  • Backups and provider logs: separate provider settings and recovery schedules apply. Our local daily-backup script rotates its own snapshots after seven days when it runs; pre-change recovery copies are retained separately. Deletion from an active system may not immediately erase an isolated backup. If a backup is restored, approved deletion requests must be reapplied.
  • Historical Analytics: the Google Analytics property currently has a two-month event-data retention period and a 14-month user-data retention period, with user retention reset on new activity enabled. These controls do not cover most standard aggregated reports. New collection requires your current consent. The earlier browser cookies were configured for up to 90 days; cookie expiry is separate from server-side retention. Contact us about historical Analytics information; we will assess what can be identified and what removal Google supports rather than promise deletion of data we cannot identify.

Access, correction, erasure and complaints

You can request information about our processing, correction or erasure, withdraw a permission, make a privacy complaint, or arrange a nomination for exercising applicable rights in the event of death or incapacity. Send a request to info@marketrefer.com. Our Privacy rights and complaints page explains identification, handling times and escalation. Technical cookie clearing does not replace a request concerning historical information.

Children and lawful guardians

Our shopping information is intended for an adult audience. Optional analytics is not offered to under-18s. A separate adult confirmation is required before it starts. This is a limited safeguard: we do not use identity documents or verified age-assurance services on the site. We do not offer children’s accounts or seek their personal information. A parent or lawful guardian can contact us if a child has sent personal information or help is needed exercising rights. We will use only the information necessary to assess the request and protect the person concerned. Please do not email Aadhaar or other identity documents unless a specific, justified verification step has been explained.

Where GDPR applies

Optional analytics relies on consent. You can withdraw without losing access to the guides. We use correspondence to respond to the request you send and retain limited records for handling the request, security and applicable legal obligations. The correct legal basis and retention of each activity depend on its circumstances; a cookie banner does not waive any of your rights.

Where applicable, GDPR rights include access, rectification, erasure, restriction, objection and data portability. You may complain to the competent data protection supervisory authority, including in the country of your habitual residence, workplace or the alleged infringement. Our rights page provides the request route and response periods. Provider arrangements and international-transfer safeguards require separate assessment; we do not represent this banner as GDPR certification.

Security and changes

We use HTTPS, restricted administrative access, software updates and private application audit logs. Security controls reduce risk but do not guarantee that an incident cannot occur. If a breach affects personal information, the owner will assess the incident, act to contain it, and arrange applicable notifications. No DPDP certification or SOC 2 attestation is claimed.

We update this notice when practices change. The version and date above identify this notice. For website-use terms see our Terms & Conditions.