Privacy Policy
UX by Ash is the independent practice of Ashwarya Subhluxmi, offering fractional design leadership, startup advisory, product design consulting, AI product strategy, workshops, speaking, and mentoring. This policy explains what personal information the site collects, why it is collected, and the choices you have.
Who is the data controller
Ashwarya Subhluxmi, operating as UX by Ash (an independent sole practitioner based in San Francisco, California), is the controller of personal data collected through uxbyash.com. For any privacy question, request, or complaint you can reach me at ashwarya19@gmail.com.
What I collect and why
Information you submit
- Contact and advisory inquiries. When you use the contact form, advisory form, or a speaking, workshop, or mentoring request, I collect your name, email, company (optional), inquiry type, and the message you send. I use this only to respond, scope the engagement, and keep a record of our conversation.
- Newsletter subscriptions. When you subscribe I store only your email address, used solely to send occasional writing on product design, AI, and design leadership. You can unsubscribe at any time using the link in every email, or by emailing me.
Information collected automatically
- Referrer log. On your first page load per browser tab I record the URL you landed on, the referring URL (for example a LinkedIn post or a search engine), your user agent string, and any UTM parameters. This helps me understand which writing and case studies people find useful. I do not attempt to identify individual visitors from this log.
- Hosting logs. My hosting and backend provider records standard server logs (IP address, timestamp, request path, response code) for security, abuse prevention, and uptime monitoring.
What I do not collect
I do not run Google Analytics, Meta Pixel, LinkedIn Insight Tag, TikTok Pixel, Hotjar, or any advertising or third-party behavioral tracking on this site. I do not sell or share personal information with data brokers or advertising networks. I do not use automated decision-making or profiling that produces legal or similarly significant effects.
Legal bases (GDPR / UK GDPR)
- Consent for newsletter subscriptions. You can withdraw consent at any time.
- Legitimate interests for responding to inquiries, delivering advisory work, maintaining basic server logs, and running the referrer log to understand aggregate site traffic. These interests are balanced against your rights and do not override them.
- Contract when we sign a statement of work, letter of engagement, or NDA for advisory, fractional, or consulting engagements.
- Legal obligation for tax and accounting records tied to invoiced work.
Your rights
Depending on where you live you may have the right to access, correct, delete, port, or restrict processing of your personal data, to object to processing based on legitimate interests, and to withdraw consent. California residents have additional rights under the CCPA and CPRA, including the right to know, delete, correct, and to opt out of the sale or sharing of personal information. I do not sell or share personal information as those terms are defined by the CCPA and CPRA. Residents of the EEA and UK have the right to lodge a complaint with their local supervisory authority.
To exercise any of these rights, email ashwarya19@gmail.com from the address associated with your inquiry or subscription. I respond within 30 days.
How long I keep information
- Contact and advisory inquiries: up to 3 years, or the life of the engagement plus applicable tax retention (typically 7 years for invoiced work in the United States).
- Newsletter subscribers: until you unsubscribe, after which your email is suppressed to prevent accidental re-subscription.
- Referrer and server logs: rolling 12 months.
Service providers
I use a small set of vendors to run this site and my practice. They process data only on my instructions and under their own security programs:
- Hosting, database, and forms backend for storing contact requests, newsletter subscribers, and referrer logs.
- Email delivery for sending newsletters and transactional replies.
- Calendly for booking discovery calls (subject to Calendly's own privacy policy).
- LinkedIn and ADPList as external destinations if you click those links (subject to their own policies).
International transfers
My hosting and email providers may process data in the United States and other countries. Where required, transfers rely on Standard Contractual Clauses or equivalent safeguards.
Security
The site is served over HTTPS. Database access is protected by row-level security policies and scoped access keys. No system is perfectly secure, but I follow reasonable technical and organizational measures and will notify affected users if a breach materially impacts their personal data.
Children
This site is intended for professional audiences and is not directed to children under 16. I do not knowingly collect personal information from children.
Changes to this policy
I will update this policy as the practice evolves. Material changes will be reflected in the "Last updated" date and, where appropriate, communicated by email to active subscribers.