Transparency & Data Protection · Last Updated: 2026

Privacy Policy & Security Practices

This Privacy Policy outlines how your personal information is gathered, utilized, and protected when you interact with the digital portfolio and consulting services of Muhammad Arslan.

1. Direct Inquiries & Information Collection

We collect information that you voluntarily submit when initiating project inquiries or communications:

  • Contact Identifiers: Name, work email address, and company/organization name.
  • Project Briefs: Desired services (UI/UX design, Webflow development, WordPress development), budget estimates, and project scope details.
  • Direct Channels: Messages transmitted via direct email or encrypted messaging (WhatsApp).

We never sell, rent, or distribute your inquiry data to data brokers, third-party advertisers, or marketing networks.

2. Browser Storage & Cookies

This website is engineered with a privacy-first, minimal-footprint philosophy:

  • Essential LocalStorage: We use browser LocalStorage strictly for functional purposes: caching portfolio taxonomies, retaining reading progress, and preventing automated form spam.
  • Zero Invasive Tracking Cookies: We do not deploy third-party advertising pixels, behavioral marketing tracking, or persistent cross-site tracking cookies.

3. Infrastructure & Technical Subprocessors

To deliver high performance and reliable uptime, this website utilizes modern, reputable infrastructure providers:

  • Hosting & CDN: Vercel Global Edge Network for static site compilation and content delivery under strict Transport Layer Security (TLS 1.3 / HTTPS).
  • Cloud Database & Storage: Google Cloud Firebase for authorized content administration, protected by strict server-side Firestore security rules.
  • Media Hosting: Unsplash for high-resolution project reference photography.
  • Website Analytics: Google Analytics (GA4) via Google Tag Manager for aggregated, privacy-preserving visitor and page engagement metrics.

4. Security Hardening & Defense-in-Depth

We enforce industry-standard defensive controls across our codebase:

  • Strict Content-Security-Policy (CSP): Defends against Cross-Site Scripting (XSS) by restricting executable script, style, and frame sources.
  • Anti-Clickjacking Headers: Enforces X-Frame-Options: DENY and CSP frame-ancestors: none.
  • MIME Protection: Enforces X-Content-Type-Options: nosniff.
  • Bot Protection & Throttling: Incorporates automated honeypot spam detection and client submission rate limiting.
  • Strict Non-Disclosure (NDA): All proprietary project briefs and confidential client designs shared during discovery are treated as strictly confidential.

5. Your Rights & Contact Information

You retain full rights to request access to, updates for, or permanent deletion of any personal communications or briefs you have submitted.

For inquiries regarding this privacy statement or to request deletion of your information, please contact:

Muhammad Arslan

Lead UI/UX Designer & Webflow Developer

marslanprofessional@gmail.com ↗
← Return to Portfolio Home