PRforBrand
PRforBrand
Legal
This policy explains what personal information PRforBrand collects, how we use and disclose it, how payment data is handled, and the privacy rights available to you under United States federal and state law.
Last updated: August 24, 2026
This Privacy Policy explains how PRforBrand ("PRforBrand," "we," "us," or "our") collects, uses, discloses, retains, and protects personal information when you visit our website, submit an enquiry or consultation request, create an account in our client portal, purchase or receive our public relations and communications services, or otherwise interact with us.
PRforBrand is a communications agency operating from New Delhi, India, and providing services to clients located in the United States and elsewhere. This policy is written to meet the requirements of United States federal and state privacy laws, including the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA"), and comparable laws in Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and other states with comprehensive privacy statutes.
By using this website or engaging our services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with it, please do not use the website or submit information to us.
We collect the following categories of personal information. Not every category applies to every individual; what we collect depends on how you interact with us.
We do not intentionally collect sensitive personal information as that term is defined under the CCPA/CPRA — such as government identification numbers, precise geolocation, racial or ethnic origin, religious beliefs, health information, biometric data, or the contents of your private communications with third parties. Please do not send us such information unless we have specifically requested it in writing for a legitimate business purpose.
We collect this information directly from you when you submit it; automatically through cookies and analytics when you use the website; and occasionally from third-party sources such as our payment processor, publicly available business directories, and referral partners who introduce you to us.
We use personal information for the following business and commercial purposes:
We do not use personal information for automated decision-making that produces legal or similarly significant effects about you, and we do not engage in profiling for such purposes.
Payments for our services are processed by third-party payment processors that are certified as PCI DSS Level 1 compliant. When you submit payment details, that information is transmitted directly to the payment processor over an encrypted connection and is handled under the processor's own security controls and privacy policy.
PRforBrand does not receive, process, or store your full payment card number, magnetic stripe data, CVV/CVC security code, PIN, or full bank account number. Our systems retain only limited transaction records — such as the card brand, the last four digits, the expiration date, the billing name and address, the amount, the currency, the transaction identifier, and whether the transaction succeeded or failed — which we use for order fulfillment, accounting, tax compliance, refunds, and dispute resolution.
Where you authorize recurring or retainer billing, the payment processor stores your payment credentials as a secure token on its systems and charges that token on the schedule set out in your engagement agreement. You may withdraw that authorization at any time as described in your agreement and in our Refund & Cancellation Policy, subject to amounts already due.
We use payment and transaction data, together with device and network signals, to screen for fraudulent or high-risk transactions. Our payment processor may independently perform fraud screening and identity verification in accordance with its own policies and applicable law.
We disclose personal information for business purposes to the following categories of recipients, in each case under contracts that restrict their use of the information to the services they perform for us:
PRforBrand does not sell personal information, and does not share personal information for cross-context behavioral advertising, as those terms are defined under the CCPA/CPRA and comparable state laws. We have not sold or shared personal information in the preceding twelve months, and we do not sell or share the personal information of consumers we know to be under sixteen years of age.
We use cookies and similar technologies to operate the website and understand how it is used. Strictly necessary cookies support core functions such as page navigation, session management, security, and keeping you signed in to the client portal; the website cannot function properly without them. Analytics and performance cookies help us understand aggregate traffic patterns and improve the site.
Most browsers let you refuse or delete cookies through their settings. Blocking strictly necessary cookies may prevent parts of the website, including account login, from working correctly.
Because we do not sell or share personal information for cross-context behavioral advertising, there is no such activity for you to opt out of. We nonetheless recognize and honor the Global Privacy Control (GPC) signal and other legally recognized browser-based opt-out preference signals as a valid request to opt out under applicable state law. We do not currently respond to Do Not Track (DNT) browser signals, as no common industry standard for them has been adopted.
Depending on the state in which you reside, you may have some or all of the following rights regarding your personal information:
To exercise any of these rights, email hello@prforbrand.com with the subject line "Privacy Request" and tell us which right you wish to exercise. We will verify your identity before responding, typically by confirming information already in our records or by asking you to respond from the email address associated with your account or enquiry. Requests to know or delete generally require us to match at least two data points; requests concerning sensitive or high-risk data may require additional verification.
We will acknowledge your request within ten business days and respond substantively within forty-five calendar days. Where reasonably necessary, we may extend that period by a further forty-five days and will notify you of the extension and the reason for it. There is no charge for exercising these rights unless a request is manifestly unfounded or excessive, in which case we will explain our reasoning before proceeding.
An authorized agent may submit a request on your behalf if they provide written proof of authorization signed by you, and we may still ask you to verify your own identity and confirm that you granted the authorization.
If we deny your request, you may appeal by replying to our decision with the subject line "Privacy Appeal." We will review the appeal and inform you in writing of our decision, and the reasons for it, within forty-five days. If your appeal is denied, you may contact your state Attorney General to submit a complaint.
California residents may also request, once per calendar year and free of charge, information about disclosures of personal information to third parties for their direct marketing purposes under California Civil Code Section 1798.83 (the "Shine the Light" law). We do not make such disclosures, but you may submit a request to the address in Section 13.
We retain personal information only for as long as necessary to fulfill the purposes described in this policy, and thereafter as required to comply with our legal, tax, accounting, and regulatory obligations, resolve disputes, prevent fraud, and enforce our agreements.
As general guidance: enquiry and consultation records are retained for up to twenty-four months from your last interaction with us if no engagement follows; client engagement records, deliverables, and correspondence are retained for the duration of the engagement and for up to seven years afterward; financial and transaction records are retained for at least seven years to satisfy tax and audit requirements; and website analytics data is retained in aggregated or de-identified form.
When personal information is no longer needed, we delete it or de-identify it so that it can no longer reasonably be linked to you.
We maintain administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, use, alteration, disclosure, and loss. These include encryption of data in transit using TLS, access controls and role-based permissions, authenticated access to the client portal, restriction of access to personnel who need it to perform their duties, confidentiality obligations for staff and contractors, and periodic review of our security practices.
As described in Section 4, payment card data is handled by PCI DSS Level 1 certified processors and does not reside on our systems.
No method of transmission over the internet or method of electronic storage is completely secure. While we work to protect your information using commercially reasonable measures, we cannot guarantee absolute security. If we become aware of a security incident affecting your personal information, we will notify you and the relevant authorities as required by applicable state breach notification laws.
PRforBrand operates from India. If you are located in the United States, personal information you provide to us will be transferred to, stored in, and processed in India, and may also be processed in the United States and other countries where our service providers maintain facilities.
Privacy laws in these countries may differ from those in your state of residence. Wherever your information is processed, we apply the protections described in this policy and impose contractual obligations on our service providers requiring them to safeguard personal information and use it only for the purposes we specify.
By providing personal information to us, you understand that it will be transferred and processed as described in this section.
Our website and services are directed to businesses and professionals and are not intended for children. We do not knowingly collect personal information from anyone under the age of eighteen, and we do not knowingly collect personal information from children under thirteen in a manner that would be subject to the Children's Online Privacy Protection Act (COPPA).
If we learn that we have collected personal information from a child under thirteen, we will delete it promptly. If you believe a child has provided us with personal information, contact us at hello@prforbrand.com so we can take appropriate action.
Our website and published materials may link to third-party websites, media outlets, publications, and platforms that we do not control. This Privacy Policy does not apply to those sites or services.
We encourage you to review the privacy policies of any third-party site you visit. We are not responsible for the content, security, or privacy practices of third parties.
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we do, we will revise the "Last updated" date at the top of this page. If the changes are material, we will provide additional notice, such as by email to active clients or a prominent notice on the website, before the changes take effect. Your continued use of the website or our services after the effective date constitutes acceptance of the updated policy.
If you have questions, requests, or complaints about this policy or our handling of personal information, contact us:
We aim to acknowledge all privacy correspondence within ten business days.