Legal
Privacy Policy
Last updated:
This Privacy Policy describes how mysphurit (“we”, “us”, “our”) collects, uses, stores, and protects personal information when you visit our website or use our software-as-a-service platform.
1. Data we collect
1.1 Information you give us
- Account data — your name, work email, phone, company name and role when you register, contact sales, or invite a colleague.
- Business data — information you enter into the platform (tasks, invoices, employees, customers, quotes, payroll, leads, documents you upload).
- Payment data — we do not store card numbers. Payments are processed by Razorpay (PCI-DSS Level 1); we retain only the payment id + status.
- Support messages — any email, chat, or form submission you send to support or sales.
1.2 Information we collect automatically
- Device & session data — IP address, browser, operating system, referrer, session identifiers, and pages visited.
- Usage data — feature interactions, audit trail entries (logins, record changes, impersonation events) for security and product improvement.
- Cookies — strictly-necessary session cookie + anti-CSRF token. We do not set third-party advertising cookies on our own domain.
1.3 Information from integrations you authorise
- Google Drive (optional) — access token, drive folder id, and file metadata for the tenant folder you nominate. We never read unrelated Drive files.
- Meta (Facebook / Instagram) (optional) — page list, lead form data, ad-level metadata under scopes you explicitly grant.
- GSTN directory — we look up public GSTIN metadata on your behalf only when you enter a GSTIN and click Verify.
2. How we use the data
- To provide, maintain, and improve the service.
- To authenticate and secure your account (2FA, rate limiting, anomaly detection).
- To process your subscription, billing, and renewals via Razorpay.
- To send transactional email and WhatsApp (password resets, invoices you send from the platform, payment receipts).
- To provide support when you contact us.
- To comply with Indian statutory, GST, and accounting retention requirements (where applicable).
We do not sell personal data, share it with advertisers, or use your business data to train AI models outside of features you explicitly enable inside your own tenant.
3. Where your data lives
Your business data is stored in encrypted databases hosted in India (Mumbai region). Attachments can optionally be routed to your own Google Drive — in that case the files live in your Drive, under a folder you own, and you can revoke our access at any time.
Sub-processors we rely on:
- Razorpay — payments
- Google Cloud / Drive — optional tenant storage (customer-controlled)
- Meta Graph API — optional Lead Ads + Conversions API (customer-controlled)
- MSG91 — OTP and transactional SMS
- Email provider configured by the SuperAdmin (SMTP / Amazon SES / Gmail)
4. Retention
We retain tenant business data for as long as the subscription is active, plus a grace period matching the data-retention window on your plan (typically 24–84 months). Indian statutory records (GST invoices) are held for 7 years per CBIC rules. You can request export or deletion at any time via support@mysphurit.com.
5. Your rights
- Access, export, or delete the data we hold about you.
- Object to or restrict specific processing.
- Withdraw consent for optional integrations (Drive, Meta) at any time — revocation is immediate.
- Complain to the relevant data-protection authority if you believe your rights have been infringed.
6. Security
See our Security & Trust page for the full list of safeguards (AES-256 encryption, 2FA, audit log, IP allowlisting, rate limiting, and session hardening).
7. Contact
Data protection enquiries: support@mysphurit.com. We reply within 5 business days.