Privacy Policy
Last updated: May 13, 2026
1. Introduction
Welcome to NextGenSoft ("we," "our," or "us"), a software development agency based in Toronto, Ontario, Canada. We are committed to protecting your privacy and handling your personal information in a safe and responsible manner. This Privacy Policy explains how we collect, use, and protect your data when you use our website and services.
By using our website or services, you agree to the collection and use of information in accordance with this policy.
2. Information We Collect
2.1 Information You Provide
- Contact Forms: Name, email, subject, and message.
- Account Data: Name, email, password, and optional profile image.
- Communication: Any messages you send to us directly.
2.2 Automatically Collected Data
- Authentication Data: When using Google OAuth, we may receive your name, email, and profile image.
- Session Data: Login session tokens for secure authentication.
- Device Data: Browser type, IP address, and usage data.
- Analytics: Page views and engagement metrics.
2.3 Image Uploads
Uploaded images may be processed and stored via third-party services such as Cloudinary. These images are stored securely according to their infrastructure.
3. How We Use Your Information
- To provide and maintain our services.
- To authenticate users and manage accounts.
- To respond to inquiries and support requests.
- To improve website performance and user experience.
- To send important account-related notifications.
4. Third-Party Services
- Google OAuth: Used for authentication.
- Cloudinary: Image storage and optimization.
- NextAuth.js: Session and authentication management.
- Vercel / Cloudflare: Hosting and security infrastructure.
5. Cookies
- Authentication cookies for login sessions.
- Security and session management cookies.
- Analytics cookies for usage tracking.
- Preference cookies (theme settings).
You can disable cookies in your browser settings, but some features may not work properly.
6. Data Security
- Passwords are hashed using secure algorithms (bcrypt).
- All data is transmitted using HTTPS encryption.
- Access control and authentication protect user data.
While we take strong security measures, no system is 100% secure.
7. Data Retention
- We retain data as long as your account is active.
- Data is deleted upon verified account deletion requests.
- Some data may be retained if required by law.
8. Data Sharing
We do not sell your personal data. We may share information only in limited cases:
- With service providers under strict confidentiality agreements.
- When required by law or legal process.
- To protect security, rights, or prevent fraud.
9. Your Rights
- Access your personal data.
- Request corrections or deletion.
- Withdraw consent at any time.
- Request a copy of your data.
To exercise your rights, contact us at mwaduzzaman@gmail.com
10. Children's Privacy
Our services are not intended for individuals under 18. We do not knowingly collect data from children. If discovered, such data will be removed immediately.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Updates will be posted on this page with a revised "Last updated" date.