Public trust
Privacy Policy
A plain-language explanation of what the public website collects, why it is used, and the practical choices available to you.
Last updated 30 August 2026This policy covers the public pages, forms, tools, payment handoff and Newsroom on MrUsman.com. It does not describe private client systems or third-party services after you leave this website.
1. Overview
MrUsman.com is a portfolio, services and public-tools website operated from Abu Dhabi, UAE. This policy explains how information is handled when you browse the site, send an enquiry, submit a project brief or support request, use a diagnostic tool, read a tracked Newsroom article, or continue to an external payment provider.
2. Information you provide
Contact
The quick enquiry form collects your name, email address, optional phone or WhatsApp number, subject and message. It also includes limited page, intent, referral and campaign context when present in the page URL.
Project intake
The project brief can collect project and business type, goals, existing-system status and public URL, selected requirements, stage, preferred timeline, budget currency and range, name, company, email, phone or WhatsApp number, country, contact preference and limited attribution context.
Support
The support form can collect the affected system and issue type, urgency, public URL or approved reference, issue description, start period, recent changes, optional error and reproduction details, browser or device, tool-result summary, name, company, email, phone or WhatsApp number, contact preference and limited attribution context.
Do not submit passwords, API keys, tokens, payment credentials, private admin URLs, private files or other sensitive credentials. The support form performs limited automated checks for common secret patterns, but that is not a substitute for your own review.
Accepted enquiry, project and support submissions are saved in the existing lead-management database and may be sent by email as a notification so they can be reviewed and answered.
3. Information collected automatically
The web server and hosting infrastructure may process standard request information such as IP address, browser or user-agent information, requested page, date and time, and referral information for delivery, diagnostics and security.
Public forms use an IP address for abuse controls. The lead record currently includes the submitting IP address. A separate hashed IP identifier is used for submission rate limiting and duplicate protection; those rate-control records are automatically pruned after 30 days.
Newsroom interactions
On individual Newsroom articles, a random visitor identifier is kept in local storage and a session identifier is kept in session storage. Article view, reading time, scroll milestones, share actions, related-story clicks, referrer and a broad mobile/desktop classification are recorded in the Newsroom analytics database. The visitor identifier remains until browser storage is cleared; the session identifier lasts for the browser-tab session.
Page interaction events
Public pages place selected interaction events into an in-page dataLayer queue, such as tool starts, form submissions and CTA clicks. The current public build does not load Google Analytics, Google Tag Manager, Google Ads, Meta Pixel or another analytics sender, so this queue is not currently transmitted to those platforms.
4. Website tools
The five public tools process a website URL or domain that you enter. They make bounded, read-only requests to publicly available HTML, headers, DNS, certificate, robots or sitemap information relevant to the selected check. They do not require a login to the target site, and no production AI provider generates the scores.
Recent tool results, including the normalized public destination and public evidence used in the report, may be held in a server-side cache for about 10 minutes to reduce repeat requests. Rate-limit files use hashed client identifiers. The tools do not provide a permanent public scan-history account, although ordinary infrastructure logs may still exist.
Only submit public destinations that you own or are authorized to check. Tool output may include public technical details from the destination.
5. How information is used
- To respond to enquiries and prepare project discussions.
- To review and follow up on support requests.
- To operate public diagnostic tools and return requested reports.
- To route notifications into the existing lead-management workflow.
- To prevent spam, duplicate submissions, abuse and unsafe requests.
- To understand Newsroom reading patterns and improve public content.
- To maintain, diagnose and protect the website.
MrUsman.com does not operate an automated system that makes legal or similarly significant decisions about public visitors.
6. Payment processing
The payment page asks for an agreed payment reference, payment type, USD amount and confirmation. The MrUsman.com handoff validates those values but does not store them in a local payment record. It then redirects you to a PayPal-hosted PayPal.Me page.
Card details, PayPal login credentials and payment authorization are handled by PayPal, subject to PayPal’s own privacy terms. The current website flow does not independently verify or display payment success.
7. Third-party services
- PayPal handles the hosted payment experience after you continue from the payment page.
- Hosting and infrastructure providers, including the current hosting provider, process requests and store website data needed to operate the service.
- Email delivery infrastructure carries notification messages generated by public enquiries and support submissions.
- Google Fonts is loaded from Google’s font servers, which means a request is made to Google when the shared site design loads those fonts.
WhatsApp, LinkedIn, Behance and other external destinations receive information only when you choose to open their links or otherwise interact with those services.
8. Data retention
Lead and Newsroom records do not currently have a universal automatic deletion schedule. Information is kept for as long as reasonably needed to respond, maintain operational records, prevent abuse, protect the service, or meet applicable obligations. Tool caches are short-lived as described above, and hashed public-form rate records are pruned after 30 days.
A deletion request can be considered where applicable, but some records may need to be retained for security, operational or legal reasons.
9. Security
Reasonable technical and operational safeguards are used, including input validation, rate limits, duplicate controls, safe public-URL checks and restricted tool requests. No internet service can guarantee absolute security.
Never submit passwords, API keys, access tokens, payment credentials or other private secrets through public forms or tools.
10. Your choices and rights
You may contact Mr Usman to ask about personal information you submitted, request a correction, request deletion where applicable, or ask to stop non-essential direct communication. A reasonable identity check may be required before acting on a request.
You can clear local or session storage through your browser. Depending on where you are located, local privacy laws may provide additional rights.
11. External links
The site links to external websites and services. Their privacy practices, content and security are controlled by them, not by MrUsman.com. Review their policies before providing information.
12. Changes to this policy
This policy may be updated when public features, providers or data practices change. The date at the top identifies the current published version.
13. Contact
Abu Dhabi, UAE