Privacy policy
Privacy, in plain English.
Last updated: June 2026
In short
I collect only what you choose to send through the contact and newsletter forms, plus traffic stats from Google Analytics. Your details stay in my own database and are used only to reply to you. I never sell data, show ads, build profiles, or train AI on anything you share. Email hamzadevtech01@gmail.com anytime to see, correct, or delete your data.
01Who I am
I am Malik Hamza Shabbir, a solo full-stack and AI engineer in Abbottabad, Pakistan (GMT+5), working with clients worldwide. I run hamzashabbir.dev myself, and I am the data controller for everything described here. For any privacy question or request, email hamzadevtech01@gmail.com. I reply within one business day.
02Contact and hire forms
When you send a contact or hire form, I receive your name, email, and message, plus anything optional you add: phone number, company, service interest, and budget range. I also record which page you sent it from, so I have context when I reply.
Your message is stored in my own MySQL database. Two emails go out: a notification to me and an auto-reply to you, so you know it arrived. I use these details only to reply and discuss your project. You are never added to a marketing list. The legal basis is simple: you asked me to get in touch, and replying is a step toward a possible contract under GDPR Article 6(1)(b).
03Joining the newsletter
The newsletter form collects exactly one thing: your email address. It lives in my database and is used for occasional article updates, nothing else. The legal basis is your consent, and you can withdraw it anytime by replying to any email or writing to hamzadevtech01@gmail.com. The contact form never signs you up; joining is always a separate, deliberate choice.
04Analytics and view counters
Articles carry anonymous view counters. They count reads, not readers; no identity is attached.
For traffic and performance I use Vercel Web Analytics and Speed Insights (both cookieless and aggregated, with no cross-site tracking and no advertising IDs) plus Google Analytics 4. Google Analytics uses cookies to measure visits, such as which pages you view, roughly where you are by country, and what device you use. It is aggregated and is never used to identify you personally, sold, or used for advertising. My legal basis is your consent where it is required and a legitimate interest in understanding which pages are useful elsewhere. You can opt out with Google's browser add-on at tools.google.com/dlpage/gaoptout or by blocking cookies in your browser.
05Cookies and browser storage
Google Analytics sets a small number of analytics cookies to measure traffic, as described above. You can refuse or delete them anytime through your browser settings or Google's opt-out add-on, and the site keeps working normally.
The site uses sessionStorage for two small things: a draft of your form message, so a page refresh does not lose it, and a flag that remembers the message was sent. Both are wiped when you close the tab.
Login cookies exist only on the separate admin panel I use to manage the site. Visitors never receive them.
06What I never do
- I never sell or rent your data, to anyone.
- No ads, no advertising trackers, no profiling.
- Contact form messages never turn into marketing emails.
- No AI model is trained on visitor data.
- This site is not aimed at children, and I do not knowingly collect children's data.
07Where your data lives
Form and newsletter data sits in a MySQL database on hosting infrastructure I control, and notification emails go out through my email provider using nodemailer. I am based in Pakistan, which has no EU adequacy decision, so I will be plain about it: your data is processed and stored on my infrastructure, not under an EU transfer framework. The same rights in this policy apply to you wherever you live.
I am the only person with access, and I take reasonable technical measures to protect the data, though no internet transmission is perfectly secure.
08How long I keep data
Lead messages are kept only while they are relevant to an ongoing conversation. After that, they are deleted, and you can ask me to delete them sooner at any time. Newsletter emails are kept until you unsubscribe. Analytics data is aggregate only, so there is no per-person record to retain.
09Your rights, wherever you are
You can ask me to show you, correct, or delete any data I hold about you, object to its use, or withdraw consent. One email to hamzadevtech01@gmail.com does it, and I respond within one business day.
If you are in the EU or UK, the GDPR and UK GDPR give you these rights formally, including the right to complain to your local supervisory authority.
My one-person business sits far below the CCPA's covered-business thresholds, but California residents get the same rights from me voluntarily. I do not sell or share personal information as the CCPA defines those terms.
10Links to other services
You may follow links from this site to Calendly to book a call, or to WhatsApp, GitHub, LinkedIn, and my other profiles. Each of those services has its own privacy policy, and it applies the moment you leave this site. I do not control what they collect.
11Changes to this policy
When this policy changes, I update the date at the top. If a change is material, for example a new tool that touches personal data, I will flag it clearly on this page rather than slip it in quietly. Questions about anything here: hamzadevtech01@gmail.com.