Skip to content
NxtHatch TechnologiesNxtHatch TechnologiesNxtHatch Technologies
Let's Talk
Menu
  • HomeHome
  • WorkWork
    PortfolioPortfolioCase StudiesCase Studies
  • ServicesServices
  • IndustriesIndustries
  • SolutionsSolutions
  • ContactContact

Company

  • About Us
  • Our Process
  • Why NxtHatch
  • Careers

Connect

  • info@nxthatch.com
  • (+1) 202 9908556
  • Suite# 201, Shafi Court, Mereweather Road, Karachi, Pakistan
  • Headquarters: Pine Flats, Dr Houston, Texas, US
Home/Privacy Policy

Privacy Policy

What personal information NxtHatch Technologies collects, why we collect it, who we share it with, and the choices and rights you have.

Scroll

Last updated: 10 September 2026

Draft — this privacy policy has not been reviewed or approved.The factual sections describe what the site actually does. The sections marked below are still waiting on input from the business, and this page is excluded from search engines — and unlinked from the footer — until they are filled in and the draft flag is turned off in the studio. Do not rely on this document.

About NxtHatch Technologies

NxtHatch Technologies ("NxtHatch," "the Company," "we," "us," or "our") is a software development and technology consulting business.

  • Headquarters: 10135 Pine Flats Dr, Houston, Texas 77095, United States
  • Regional office: Suite 201, Shafi Court, Mereweather Road, Karachi, Pakistan
  • Contracting and invoicing entity: Our United States headquarters, for all engagements
  • Website: www.nxthatch.com
  • General contact: info@nxthatch.com
  • Privacy contact: privacy@nxthatch.com
  • Phone: (+1) 202 9908556

Our Karachi office is a regional office of the same business, not a separate contracting party. Work may be performed by personnel at either location, but every engagement is contracted with, invoiced by, and paid to our United States headquarters, in United States dollars, unless a Statement of Work expressly says otherwise. Section 4 of Part I sets this out in full.

27. At a Glance

  • Do we sell your personal information? No. We have never sold personal information and do not intend to.
  • Do we share it for targeted advertising? Our website analytics may involve Google advertising features. You can opt out — see Section 33.
  • Do we collect sensitive personal information? No. We do not collect Social Security numbers, government IDs, financial account numbers, precise geolocation, biometric data, health data, or information about race, religion, or sexual orientation.
  • Do we use your data to train AI models? No. We do not use client data or website visitor data to train machine learning models, and we do not permit our vendors to do so.
  • Do you use a cookie banner? No. We run analytics cookies only, and you can opt out at any time — see Section 33.
  • Where is your data processed? The United States and Pakistan. See Section 40.
  • Who can exercise privacy rights? Anyone. We extend the core rights below to all individuals, regardless of where you live.
  • How do I make a request? Email privacy@nxthatch.com with the subject line "Privacy Request."

28. Our Role: Controller vs. Service Provider

We handle personal information in two distinct capacities, and your rights differ depending on which applies.

As a business (controller). For information we collect about website visitors, prospective clients, business contacts, and our own Clients, we decide how and why it is used. This Part governs that information, and you can exercise your rights against us directly.

As a service provider (processor). While delivering Professional Services, we may access systems, databases, or files belonging to a Client that contain personal information about that Client's customers, employees, or users — this is Client Data. We access it only to perform the Services, only on the Client's documented instructions, and never for our own purposes.

We do not sell Client Data, do not retain it beyond the engagement, and do not use it to train models or build our own datasets. If you are an individual whose data appears in a Client's systems, the Client is responsible for responding to your privacy rights request — please contact them directly, and we will assist them promptly. Section 39 describes our contractual commitments to Clients on this point.

29. Personal Information We Collect

The list below uses the categories defined by the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), because they are the most widely recognized framework in the United States.

  • Identifiers — What we collect: Name, business email address, business phone number, company name, IP address. Source: You, via our contact form; public business sources. Why: Respond to inquiries, deliver Services, prevent abuse.
  • Commercial information — What we collect: Services you're interested in, indicated budget range, records of Services provided, billing history. Source: You. Why: Prepare proposals, manage engagements, invoice.
  • Internet or network activity — What we collect: Pages viewed, time on page, clicks and scroll depth, referring URL, browser and device type. Source: Automatically, via analytics. Why: Understand and improve site performance.
  • Geolocation data — What we collect: Approximate city or region inferred from IP address. Not precise geolocation. Source: Automatically, via analytics. Why: Traffic analysis.
  • Professional or employment information — What we collect: Company name, job title, industry, publicly listed business profile. Source: You; public business sources. Why: Assess fit, tailor proposals, business outreach.
  • Audio or visual — What we collect: Recordings of video calls, only where all participants are told in advance and consent. Source: You, during an engagement. Why: Meeting notes, with consent.
  • Inferences — What we collect: Whether a business appears to be a good fit for our Services. Source: Derived from the above. Why: Prioritize outreach and proposals.

Categories we do not collect: sensitive personal information (as defined by the CPRA), biometric identifiers, precise geolocation, protected classification characteristics, education records, or genetic data.

29.1 Where the Information Comes From

  • Directly from you. Our contact forms collect your name, email, company, phone number, type of inquiry, service of interest, budget range, expected timeline, and message, along with your consent to be contacted. You may also email, call, or message us.
  • Automatically. See Section 33.
  • From public sources. For business-to-business outreach, we compile business contact details — first name, last name, company name, company website, publicly listed social profile, and business email — from company websites, public business directories, publicly accessible social profiles, and search engine results. See Section 36.
  • From our Clients. During an engagement, a Client may give us access to systems containing Client Data.

30. How We Use Personal Information

We use personal information for these business purposes:

  • Responding to your inquiry and providing information you requested
  • Preparing proposals and Statements of Work, and communicating about a potential engagement
  • Performing, managing, and supporting Professional Services
  • Invoicing and collecting payment
  • Sending business-to-business communications about our Services to relevant business contacts
  • Measuring and improving website performance and content
  • Detecting and preventing fraud, spam, security incidents, and abuse
  • Complying with legal, tax, and accounting obligations, and establishing or defending legal claims

We do not use personal information for automated decision-making that produces legal or similarly significant effects, engage in profiling for such purposes, or use it to train artificial intelligence or machine learning models.

31. How We Disclose Personal Information

We disclose personal information only as described here. We do not rent or trade contact lists.

  • Website hosting and infrastructure providers — What they receive: Server logs, form submissions in transit. Why: Operate the website.
  • Email and productivity providers — What they receive: Correspondence, contact details. Why: Communicate with you.
  • Analytics providers (Google) — What they receive: Website usage data, IP address, cookie identifiers. Why: Measure website performance.
  • Scheduling provider (Cal.com) — What they receive: Your name, email address, and anything else you enter when you book a call. Why: Schedule and manage discovery calls.
  • Payment processors and accounting providers — What they receive: Billing contact and transaction details. Why: Invoice and collect payment.
  • Our Personnel and subcontractors (United States and Pakistan) — What they receive: Only what their work requires. Why: Deliver Services.
  • Professional advisers (legal, accounting, audit) — What they receive: As necessary. Why: Professional advice.
  • Government or law enforcement — What they receive: As legally required. Why: Comply with law, protect rights and safety.
  • An acquirer — What they receive: As part of a transaction. Why: Merger, acquisition, or sale of assets.

Booking a call takes you to Cal.com's own website. We do not embed their scheduler in this Website (see Section 33), so what you enter on their booking page is provided to Cal.com directly and is also governed by their own privacy policy.

Vendors receive personal information under written terms that limit them to performing services for us and prohibit them from selling it or using it for their own purposes. Under the CCPA, these are service provider relationships, not sales.

If we are acquired, personal information may transfer as part of the transaction. We will provide notice before your information becomes subject to a different privacy policy.

32. We Do Not Sell Your Personal Information

We do not sell personal information, and we have not done so in the preceding twelve months. We do not sell or share the personal information of anyone we know to be under 16.

One disclosure worth making plainly: our Google Analytics configuration includes Google advertising features. Under the CPRA and several other state laws, this may qualify as "sharing" personal information for cross-context behavioral advertising, even though no money changes hands. You can opt out at any time using any of the methods in Section 33, and we honor opt-out preference signals as described there.

33. Cookies and Tracking

We keep our tracking deliberately minimal. Here is everything currently running on our website:

  • Google Tag Manager — Provider: Google. Identifier: GTM-MT35THP9. Purpose: Loads and manages our analytics tags. Duration: Session.
  • Google Analytics 4 — Provider: Google. Identifier: G-V5RYEHTB7B. Purpose: Measures traffic and site usage.
  • _ga cookie — Provider: Google. Purpose: Distinguishes unique visitors. Duration: Up to 2 years.
  • _ga_V5RYEHTB7B cookie — Provider: Google. Purpose: Maintains analytics session state. Duration: Up to 2 years.
  • Google advertising features — Provider: Google. Purpose: May associate site activity with signed-in Google users for audience and remarketing purposes. Duration: Per Google's retention.

We do not use Meta/Facebook Pixel, LinkedIn Insight Tag, TikTok Pixel, session-replay or heatmap tools, live chat widgets, or embedded scheduling tools.

How these cookies are set. Analytics cookies are set when you first load a page on the Website. We do not currently display a cookie consent banner. You can block, delete, or opt out of these cookies at any time using the options below, and doing so does not affect your ability to use the Website.

33.1 Your Options

  • Opt-out preference signals. We honor the Global Privacy Control (GPC) and other universal opt-out mechanisms transmitted by your browser. When we detect one, we treat it as a valid request to opt out of sharing for targeted advertising for that browser. This is required of us in California, Colorado, Connecticut, and Texas, and we apply it to all visitors.
  • Google Analytics opt-out. Install Google's browser add-on.
  • Browser controls. Block or delete cookies in your browser settings. The website works normally without analytics cookies.
  • Email us. Send a request to privacy@nxthatch.com and we will apply it.

We do not respond to legacy "Do Not Track" browser headers, because no common standard for interpreting them was ever adopted. GPC is the mechanism we honor.

34. Your Privacy Rights

We extend the following rights to everyone, regardless of your state or country of residence. You do not need to be a resident of a state with a privacy law to make a request.

  • Know / Access — Confirm whether we process your personal information, and get a copy of it
  • Correct — Have inaccurate personal information fixed
  • Delete — Have your personal information deleted, subject to legal retention obligations
  • Portability — Receive your information in a portable, readily usable format
  • Opt out — Opt out of targeted advertising and of any sale or sharing of personal information
  • Limit sensitive data use — Not applicable — we do not collect sensitive personal information
  • Non-discrimination — We will not deny service, charge a different price, or provide a lesser quality of service because you exercised a right
  • Appeal — Ask us to reconsider if we decline your request — see Section 34.2

34.1 How to Submit a Request

Email privacy@nxthatch.com with the subject line "Privacy Request." Tell us what you would like us to do and give us enough detail to locate your information — typically the email address you used or that we contacted you at.

Response times. We respond within 45 days. If we need more time, we will tell you within that period and may extend by an additional 45 days. Requests are free, up to twice per year.

Verification. We may need to verify your identity before acting, usually by confirming you control the email address associated with the information. We ask only for what is necessary to verify, and we do not use verification information for any other purpose.

Authorized agents. You may use an authorized agent where state law permits. We will ask for written proof of authorization and may still ask you to verify your own identity directly.

34.2 Right to Appeal

If we decline your request, our response will explain why. You may appeal by replying to that response or emailing privacy@nxthatch.com with the subject line "Privacy Appeal." We will review the appeal and give you a written decision, with our reasoning, within 60 days.

If we deny your appeal, you may submit a complaint to your state attorney general. Texas residents may file with the Texas Attorney General's Consumer Protection Division. California residents may contact the California Privacy Protection Agency.

35. State-Specific Disclosures

35.1 Texas

Our headquarters is in Texas, and the Texas Data Privacy and Security Act (TDPSA) applies to businesses that conduct business in Texas and process personal data, without any revenue or data-volume threshold. Texas residents have all the rights listed in Section 34, including the right to appeal.

We do not sell sensitive personal data or biometric personal data, so the notices required by Texas Business & Commerce Code § 541.102 do not apply to us.

35.2 California

In addition to the rights above, California residents should note:

  • Categories collected, sources, purposes, and recipients are set out in Sections 29, 30, and 31, which together serve as our Notice at Collection.
  • Retention is described in Section 37.
  • Shine the Light (Cal. Civ. Code § 1798.83): we do not disclose personal information to third parties for their own direct marketing purposes.
  • Sensitive personal information: we do not collect it, so the right to limit its use and disclosure does not apply.

35.3 Other States

Residents of Virginia, Colorado, Connecticut, Utah, Oregon, Montana, Florida, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky, Rhode Island, and other states with comprehensive privacy laws have the rights described in Section 34, including access, correction, deletion, portability, opt-out of targeted advertising, and appeal. Submit requests the same way. Where a state law grants a right we have not listed, we will honor it.

35.4 Nevada

Nevada residents may direct us not to sell certain personal information. We do not sell personal information, but you may submit a request to privacy@nxthatch.com to be recorded.

36. Business Communications and Outreach

We conduct business-to-business outreach and compile business contact details from publicly available sources, as described in Section 29.1.

We collect this information only in a professional or business capacity. We do not purchase consumer data lists, do not scrape private or password-protected content, and do not collect sensitive personal information through this activity.

Our commitments to you:

  • Every marketing email includes a working unsubscribe link and our physical mailing address, as required by the CAN-SPAM Act.
  • We honor opt-out requests within 10 business days, the deadline CAN-SPAM sets.
  • Opted-out addresses go on a permanent suppression list, checked before every send, so you are not contacted again.
  • Our sender name, "From" address, and subject lines accurately identify us and the content of the message.
  • If you want to know how we obtained your business contact details, email us and we will tell you the source.

Opting out of marketing does not stop transactional or engagement-related messages if you are an active Client.

37. Data Retention

We keep personal information only as long as necessary:

  • Contact form inquiries that do not become engagements — 24 months from last contact
  • Client records, contracts, and correspondence — Duration of engagement, plus 7 years for tax, accounting, and legal-claim purposes
  • Client Data accessed during Services — Returned or deleted at the Client's direction at the end of the engagement; otherwise deleted within 90 days
  • Business contact data used for outreach — Until you opt out, or until the contact is no longer relevant
  • Opt-out and suppression records — Retained indefinitely, so we can continue honoring your request
  • Website analytics — Up to 14 months, per our Google Analytics retention setting
  • Records of privacy requests — 24 months, as required to demonstrate compliance

When a retention period ends, we delete the information or de-identify it irreversibly.

38. Security

We maintain administrative, technical, and physical safeguards designed to protect personal information, applied identically at both of our offices, including:

  • Encryption of data in transit using current TLS standards
  • Role-based access controls, so Personnel access only what their work requires
  • Multi-factor authentication on business-critical systems
  • Written confidentiality obligations binding all Personnel and subcontractors at both offices
  • Vendor review before granting any third party access to personal information
  • Prompt revocation of access when Personnel leave or an engagement ends

No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

Breach notification. If we become aware of a security breach affecting your personal information, we will notify you and the relevant regulators as required by applicable law, including the Texas Identity Theft Enforcement and Protection Act and the breach notification statutes of other states. Texas law requires notice to affected individuals without unreasonable delay and within 60 days, and notice to the Texas Attorney General where more than 250 Texas residents are affected. We will meet or beat these deadlines.

39. For Our Clients

If you engage us, we will:

  • Sign a Data Processing Addendum on request, covering our obligations as a service provider or processor
  • Process Client Data only on your documented instructions
  • Impose written confidentiality obligations on every person who accesses your data, at either office
  • Provide a list of subprocessors on request, and give notice before adding a new one
  • Assist you in responding to privacy rights requests from your own users
  • Notify you without undue delay if we become aware of a breach affecting your data
  • Return or delete your data at the end of the engagement, at your direction
  • Never use your data to train models, build datasets, or for any purpose other than serving you

Data residency requirements, access restrictions, or security questionnaires should be raised before an engagement begins so we can address them in the Statement of Work.

40. Where Your Information Is Processed

We operate from our headquarters in the United States and a regional office in Pakistan. Personal information we collect — including website inquiries, business contact data, and, where an engagement requires it, Client Data — may be accessed and processed by our Personnel at both locations.

We disclose this plainly because it is a routine question in vendor security reviews, and because you should know where your information goes. Access by Personnel at our Karachi regional office is governed by the same access controls, confidentiality obligations, and security safeguards described in Section 38.

Clients who require US-only processing or data residency restrictions should tell us before an engagement begins, and we will address it contractually in the Statement of Work.

For individuals in the EU, UK, or EEA. Pakistan has not been the subject of an adequacy decision by the European Commission or the UK government. Where we transfer personal information of individuals in the EU, UK, or EEA to Pakistan or to any other country without an adequacy finding, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, together with the internal controls described in Section 38.

You retain the rights available under the GDPR and UK GDPR, including access, rectification, erasure, restriction, objection, and portability, and the right to lodge a complaint with your local supervisory authority or the UK Information Commissioner's Office. Where we rely on legitimate interests — as we do for business outreach — you may object at any time. Where we rely on consent, you may withdraw it at any time, without affecting processing carried out beforehand.

41. Children's Privacy

Our website and Services are directed to businesses and to individuals over 18. We do not knowingly collect personal information from anyone under 18, and we do not knowingly collect information from children under 13 as defined by the Children's Online Privacy Protection Act (COPPA).

If you believe a child has provided us with personal information, email privacy@nxthatch.com and we will delete it promptly.

42. Accessibility

If you have a disability and need this document in an alternative format, email privacy@nxthatch.com and we will provide one at no charge.

43. Changes to This Privacy Policy

We may update this Part. We will post the revised version here and update the "Last updated" date at the top of this document. If changes are material, we will provide more prominent notice — such as an email or a website banner — before they take effect.

We will not apply material changes retroactively to information already collected without your consent where the law requires it.

Contact Us

  • Privacy requests and questions: privacy@nxthatch.com (subject line "Privacy Request")
  • General inquiries and legal notices: info@nxthatch.com
  • Contact form: www.nxthatch.com/contact
  • Phone: (+1) 202 9908556

Headquarters and address for legal notices: NxtHatch Technologies, 10135 Pine Flats Dr, Houston, Texas 77095, United States

Regional office: NxtHatch Technologies, Suite 201, Shafi Court, Mereweather Road, Karachi, Pakistan

Notice sent only to the regional office is not effective notice under Part I, Section 22.

Company

  • About Us
  • Our Process
  • Why NxtHatch
  • Careers

Reach out to us

(+1) 202 9908556
info@nxthatch.com
Let's Connect

Social

  • LinkedIn (opens in a new tab)
  • Instagram (opens in a new tab)
  • GitHub (opens in a new tab)

© 2026 NxtHatch Technologies

Pakistan:Suite# 201, Shafi Court, Mereweather Road, Karachi, Pakistan•US:Pine Flats, Dr Houston, Texas, US
All Services