A printed legal compliance document on a wooden desk beside a fountain pen and reading glasses, with a small wax seal stamp at the bottom of the page.
The reference we keep open when drafting any privacy change: a printed compliance document, an unedited pen, and the question of whether the wording still describes what we actually do.

What this policy covers

The policy below describes the data we hold when you read crazy7in.com, when you write to us through the contact form, or when you reach out to a contributor directly. It does not cover the data handled by any rummy platform we review. Those platforms publish their own policies under their own names, and they are the data controllers for anything you give them. If your question is about a withdrawal, a KYC re-prompt, or a bonus that did not credit, you should write to the platform first and to us second. We list the data we hold about you, the reason we hold it, the period we hold it for, and the way to ask us to delete it.

What we collect

The desk runs a single editorial site. We collect three categories of data, and only these three.

  • Account information you give us. If you write to us through the contact form or by reply to a newsletter, we keep the name, email address and the body of the message. If a tip leads to a published correction, we may store the source attribution in our internal notes for the audit trail.
  • Analytics data. We use a privacy-respecting analytics tool that aggregates traffic without cookies. We see how many readers opened a page, what country they read from at country-level resolution, and the source of the inbound link. We do not see a unique identifier per reader, and we cannot replay your session.
  • Server logs. Our hosting provider keeps standard access logs for thirty days. Logs contain a truncated IP address, the request path, the response code, and the user agent. They are used for security, abuse prevention, and capacity planning. They are not joined to anything else.

What we do not collect

  • Government IDs, PAN numbers, Aadhaar numbers or any payment instrument. We are not a paid rummy platform and we do not process transactions.
  • Precise geolocation. We do not request GPS, browser geolocation, or Wi-Fi based location. We see a country-level read at most, and only from the analytics layer described above.
  • Cross-site tracking data. We do not run third-party trackers, advertising pixels, or social-login scripts that follow you across the web.
  • Biometric or health data. We have no use for it, and we do not want the responsibility of holding it.

How long we keep your data

Contact-form messages are kept until you ask us to delete them or until two years have passed without further contact, whichever comes first. The two-year clock matters because some of our readers write back months after a thread goes quiet, and we want the prior context to be there. Analytics data is aggregated daily and is not personally identifiable. Server logs are kept for thirty days and then deleted.

How to ask us to delete your data

Write to us via the contact form with the email address you used. We will reply within five working days to confirm the request and within thirty days to complete the deletion, except where a legal hold requires us to keep certain records for a longer period. If you wrote to a contributor by personal email rather than the form, write to that contributor directly; their inbox is their own retention policy, not ours.

Your rights under Indian law

The Digital Personal Data Protection Act, 2023 (the DPDP Act) grants you the right to access, correct, erase, and withdraw consent for personal data that an organisation holds about you. The Information Technology (Reasonable Security Practices and Procedures) Rules, 2011 cover the security side of the same obligation. The protections described on this page are the minimum we offer; if you have a request that goes further, write to us and we will read it on its own terms.

Concretely, you can ask us for a copy of the data we hold about you, ask us to correct anything that is wrong, ask us to delete the data subject to the retention rules above, ask us to restrict a particular use, or lodge a complaint with the Data Protection Board of India if you believe we have mishandled your data. Each request comes back to the same desk, and each request gets a written reply. We do not charge a fee for a request that is reasonable in scope. For requests that would require us to compile records across multiple years of correspondence, we may ask to scope the request before we begin, and we will tell you why in plain language.

Children

The site is written for adult readers aged eighteen and over. We do not knowingly collect data from anyone under eighteen. If a parent or guardian believes a minor has written to the form, write to us with the message reference and we will delete the record.

Where the data lives

Our site is hosted on infrastructure inside India. Backups are kept in the same region. Where a third-party processor handles a slice of the data on our behalf (the analytics tool, the transactional email provider), we restrict what they receive to the minimum they need to perform the service and we keep a written processor agreement on file. We do not transfer reader data outside India for routine processing. If we ever need to engage a processor based outside India for a specific task (a security review, a load test, a translation), we do it under a contract that mirrors the DPDP Act's data-fiduciary obligations, and we tell readers in the next quarterly note.

How we handle a security incident

If a security incident affects your data, we notify the affected readers at the email address they wrote to us from, and we notify the Indian Computer Emergency Response Team (CERT-In) within the period required by the CERT-In Directions of 2022. The notification describes what was affected, what we have done, and what the reader should do next. Our internal incident runbook covers the three most common cases: a leaked form export, a misconfigured cloud bucket, and a compromised contributor mailbox. Each case has a containment step, an evidence-preservation step, and a notification step. We log incidents in a register that the desk lead reviews at the start of each month, whether or not anything has been reported, so the register stays useful when we actually need it.

How this policy changes

We update the wording above when our handling of data changes in a way that affects you. The effective date at the top of the page is the date the new wording went live. For material changes (a new processor, a new retention period, a new category of data), we also include a short note on the for one cycle. We do not make material changes retroactively without telling you. If a change reduces your rights in any way, we give readers a thirty-day notice before the change takes effect, and we keep the prior version on file at the bottom of the page so the difference is readable in plain text.

How to reach us

Use the contact form for any privacy question. The form routes the message to the editor who handles policy on the desk. If the question is urgent (an active data subject request, a suspected breach), mark the subject line with "DPDP" so it surfaces in the queue first.

What we keep open by default

The data inventory we maintain for our own use is the same one we describe on the policy above. We do not hold categories of data we have not listed here. If we ever begin to collect a new category (for example, if we add a newsletter and need an email subscription list), we update the wording first and roll the new collection out second. The editorial team cannot launch a new data-collecting feature without a sign-off from the desk lead and a re-read of the policy against the new flow. That gate is the reason a reader who wrote to us once can come back two years later and still find the same retention rules described in the same place.

Cookies and similar storage

Our analytics tool does not require cookies. We do not run advertising trackers. We do not embed third-party fonts, third-party videos, or third-party maps that set their own cookies. The only browser-side storage that crazy7in.com sets is a single session token used by the contact form's anti-spam check, and that token expires when the browser tab closes. If you clear cookies after visiting the site, the only effect is that the contact form's anti-spam check resets for your next visit, which is the intended behaviour.

Effective date

This policy is effective from November 2025 and was last reviewed on the date shown at the top of the file. The desk reviews it every six months even when there has been no incident, because the regulatory landscape under the DPDP Act is still being set by the Data Protection Board of India.