Privacy Policy
Last updated: 27 June 2026
This Privacy Policy explains how Sachin Rana (“we”, “I”) collects, uses, stores and protects personal data when you use this dashboard (the “Service”). It is written to align with the EU General Data Protection Regulation (GDPR), the California Consumer Privacy Act as amended by the CPRA (CCPA/CPRA), India’s Digital Personal Data Protection Act, 2023 (DPDP Act), and the data-handling requirements of the Apple App Store and Google Play.
1. Who we are (Data Controller)
Sachin Rana is the data controller (and, under the DPDP Act, the Data Fiduciary) for personal data processed in the Service. For privacy requests, contact rockinsachinrana@gmail.com.
2. What data we collect
- Account data: name, work email, job title, phone, role, profile photo, and your hashed password.
- Operational data: audit applications, schedules, master sheets, performance and finance records you create or are assigned to as part of your work.
- Security & audit logs: sign-in events, IP address, browser/device, and actions you take (create, edit, delete, export, approvals).
- Precise location (GPS): when you record audit check-in/out events or capture audit evidence photos, the Service may store the precise GPS coordinates (latitude/longitude) and timestamp of capture as part of the audit trail. This is optional and only collected in the field-audit workflow.
- Essential cookies: a session cookie (authentication), an entity-preference cookie, and a theme cookie. We do not use advertising or third-party tracking cookies.
3. Why we process it (lawful basis)
We process data to provide the Service (performance of a contract), to keep it secure and meet certification record-keeping obligations (legitimate interests and legal obligation), and, where required, on the basis of your consent. Under the DPDP Act, our lawful bases are your consent and the certain legitimate uses permitted by the Act (including processing for employment-related and business purposes for which you have voluntarily provided your data). You may withdraw consent at any time. We do not sell personal data.
4. How we protect it
Data is encrypted in transit (TLS 1.3) and at rest (AES-256). Access is role-based and least-privilege. Sensitive references can be encrypted at the field level. A nonce-based Content-Security-Policy and other security headers protect the application. See our security posture for detail.
5. Sharing & sub-processors
We do not share personal data with advertisers and we do not sell personal data. We use a small number of infrastructure sub-processors, engaged under data-processing agreements, solely to operate the Service:
- Vercel Inc. — application hosting and edge delivery. Region: United States.
- Neon Inc. — managed PostgreSQL database (runs on AWS), where account, operational and audit-trail data is stored. Region: United States.
- Resend (Plus Five Five, Inc.) — transactional email delivery (e.g. notifications, account messages). Engaged only when email delivery is enabled. Region: United States.
6. International data transfers
The Service’s infrastructure sub-processors (Vercel and Neon) process data in the United States, so personal data of users in India, the EU/EEA and elsewhere is transferred to and processed in the USA. For transfers from the EU/EEA and the UK we rely on the EU Standard Contractual Clauses (SCCs) (and the UK International Data Transfer Addendum) or an equivalent safeguard in our processor agreements. For Indian Data Principals, transfers are made consistent with section 16 of the DPDP Act (which permits cross-border transfer except to countries restricted by the Central Government); we will adjust our processing if any such restriction is notified.
7. Data retention
We keep personal data only as long as needed for the purpose it was collected, then delete or anonymise it. Concrete periods:
- Account data (name, email, phone, title, profile photo): kept for the life of your account and deleted/anonymised within 30 days of account deletion.
- Activity & audit-trail logs (sign-in events, IP, actions): retained for 24 months, then automatically purged, unless a longer period is required by a legal hold or certification/record-keeping obligation.
- Read in-app notifications: automatically deleted 90 days after they are read.
- Completed/cancelled scheduled-notification queue rows: automatically deleted 30 days after they are sent, cancelled or failed.
- Business & certification records you contributed: retained where legally required for compliance, then personal identifiers are anonymised so the records no longer identify you.
8. Personal-data breach notification
If a personal-data breach occurs, we will act without undue delay. Where the GDPR applies we will notify the competent supervisory authority within 72 hours of becoming aware, and affected individuals where the breach is likely to result in a high risk to their rights. Under the DPDP Act we will notify the Data Protection Board of India and each affected Data Principal. Where the CCPA/CPRA or other state breach-notification laws apply, we will notify affected California (and other) residents as required by law.
9. Your rights
Subject to applicable law you may access, correct, export (portability) and delete your personal data, object to or restrict processing, and withdraw consent. Signed-in users can export their data and delete their account directly under Account → Privacy & Data. You may also email rockinsachinrana@gmail.com. California residents have the right to know, delete, correct and to opt out of “sale/share” — we do not sell or share personal information.
10. India DPDP Act 2023 — Grievance Officer & redressal
For Data Principals in India, our Grievance Officer is Sachin Rana, reachable at rockinsachinrana@gmail.com. You have the right to grievance redressal: you may raise any concern about how your personal data is handled and we will respond within the timelines required by the DPDP Act and its rules. If your grievance is not resolved to your satisfaction, you may escalate to the Data Protection Board of India. As Data Fiduciary we will provide access, correction, completion, updating and erasure of your personal data, and will notify the Data Protection Board of India and affected Data Principals in the event of a breach (see section 8).
11. Account & data deletion
You can permanently delete your account and erase your personal data in-app under Account → Privacy & Data. Business and certification records you contributed are retained where legally required but are anonymised so they no longer identify you.
12. Children
The Service is a business tool intended solely for use by authorised business personnel and is not directed to or intended for children. Consistent with the DPDP Act, which defines a child as an individual under 18 years of age, we do not knowingly collect personal data from children. If you believe a child has provided personal data, contact us and we will delete it.
13. Changes & contact
We will post any changes here with a new “last updated” date. Questions: rockinsachinrana@gmail.com.
This document is provided for transparency and should be reviewed by qualified legal counsel before production use.