Privacy Policy
Effective
This policy explains what personal data Pleostack Private Limited ("PleoStack", "we", "us") collects, why, who we share it with, how long we keep it, and the rights you have. It covers our website at pleostack.com, our web and mobile apps, and any emails or support we provide (together, the "Services").
Who we are
Pleostack Private Limited is a company registered in India (CIN U62011KA2026PTC223761), with its registered office at MBM Greenwoods, 2nd Block, BDA Layout, JP Nagar VIII Phase, Bangalore South, Bengaluru 560076, Karnataka, India.
Our role depends on the data:
- Website visitors, enquiries and account details. We decide how this data is used, so we are the Data Fiduciary under India's Digital Personal Data Protection Act, 2023 ("DPDP Act") and the controller under the GDPR and similar laws.
- Customer Data. Everything an organisation and its users put into the apps — projects, records, photos, documents, member details — belongs to that organisation (our "Customer"). We process it only on the Customer's instructions, as a Data Processor / processor. If you are a user or subject of a Customer's records, that Customer is responsible for your data, and we will pass your request to them.
What we collect
When you visit the website or contact us
-
Details you give us in a contact, demo or enquiry form: your name, work email, company, role, phone number and message.
-
Basic technical data that every web server records: IP address, browser type, pages requested and the time of the request.
-
Analytics, only if you accept. With your permission, Google Analytics records which pages you view, how far you scroll, which free tools you use, which links you click, which videos you play and how much of them you watch, and whether you start our demo request form and whether it sends. It never records what you type into a form. It also records your approximate location (country or city), device and browser type, and the campaign link that brought you to the site. It stays off until you press Accept on the cookie banner, it never runs on our staging or test sites, and we do not use it for advertising.
-
Videos. Our tutorial and product videos are hosted on YouTube. A page with a video shows a preview picture from our own site and loads nothing from YouTube until you press play; the video player then loads from YouTube's privacy-enhanced (no-cookie) domain. Once a video plays, YouTube may store information in your browser under Google's own privacy policy.
-
Where you came from. If you arrived through a campaign link (for example a QR code on a visiting card), the site remembers that link in your browser and sends it with a demo request you make, so we know which campaign reached you. If you have not accepted analytics, it is kept only for the open tab.
When you use the apps
- Account details: your name, email address, organisation, role and team memberships.
- Sign-in data: your password (stored only in hashed form by our authentication provider, never readable by us), one-time sign-in links, session tokens and the time of each sign-in.
- Customer Data you or your colleagues enter: project and work records, comments, photos, documents, signatures, and any other content the product lets you add. Depending on the product your organisation uses, this may include health, fitness or performance information about people your organisation serves, including minors, entered by your organisation.
- Location, only when you allow it on your device, attached to the item you capture (for example, a photo or inspection).
- Camera and photo library access on mobile, only when you choose to take or attach a photo.
- Activity records: who created or changed a record and when, kept so your organisation has an audit trail.
Emails we send — invitations, notifications and reports — record delivery details such as the recipient address and whether delivery succeeded.
How we use it
- To provide, secure and support the Services, including signing you in and keeping each organisation's data separate.
- To send service emails you need: invitations, sign-in links, notifications and reports.
- To reply to enquiries and arrange demos you ask for.
- To detect, investigate and prevent misuse, fraud and security incidents.
- To meet legal, tax and accounting obligations.
We do not sell personal data, we do not use it for advertising, and we do not use Customer Data to train AI models.
Legal basis. Under the DPDP Act we rely on your consent, which you may withdraw at any time, or on the legitimate uses the Act permits, such as providing a service you asked for. Under the GDPR we rely on contract (providing the Services), legitimate interests (security, replying to enquiries, improving the Services), consent (website analytics, and device location where required) and legal obligation.
Who we share it with
We share personal data only with service providers that help us run the Services, under contracts that require them to protect it and use it only for that purpose:
| Provider | What it does | Where |
|---|---|---|
| Railway | Hosts our apps, database, file storage and backups | Singapore |
| Supabase | Accounts, sign-in and sessions | Cloud hosted |
| Resend | Delivers service emails | Cloud hosted |
| Netlify | Hosts pleostack.com and relays website form submissions | Global edge network |
| Google (Google Analytics) | Website analytics, only after you accept | United States and global |
| Google (YouTube) | Plays our videos, when you press play | United States and global |
We may also disclose personal data when the law requires it, to protect the rights or safety of people or of PleoStack, or to a successor if our business is merged or sold, in which case this policy continues to apply.
Where your data is stored
Customer Data and account data are stored in Singapore. If you are in India, your data is transferred there as the DPDP Act permits. Where the GDPR or a similar law applies to you, we use appropriate safeguards for international transfers, such as the European Commission's Standard Contractual Clauses.
How long we keep it
- Account and Customer Data: for as long as your organisation's account is active, and for up to 12 months after it ends, so your organisation can come back without losing its work. After that it is deleted or anonymised. A Customer can ask us to delete it sooner, and a signed agreement with a Customer may set a different period.
- Enquiries: for up to 12 months after our last contact with you, unless you become a Customer.
- Website analytics: kept by Google Analytics for 14 months, then deleted. Your cookie choice is kept in your browser for 13 months, after which the banner asks again.
- Backups: kept for 14 days, then overwritten. Deleted data disappears from backups within that window.
- Records we must keep by law (such as invoices) are kept for the period the law requires.
How we protect it
Data is encrypted in transit. Each organisation's data is kept separate, and access inside an organisation is limited by role. Passwords are handled by our authentication provider and are never stored in readable form. If a personal data breach affects you, we will notify you, the affected Customer and the relevant authority, including India's Data Protection Board, as the law requires.
Your rights
You have the right to:
- access the personal data we hold about you, and a summary of how it is used;
- correct or complete inaccurate data;
- erase your data, where we no longer need to keep it;
- withdraw consent, without affecting processing already done;
- receive your data in a portable format, and object to or restrict certain processing, where the GDPR applies;
- nominate another person to exercise your rights if you die or become incapacitated (DPDP Act); and
- complain to us through our Grievance Officer and, if unresolved, to the Data Protection Board of India or your local data protection authority.
Email privacy@pleostack.com to use any of these rights. We reply within 30 days. For Customer Data, we will pass your request to your organisation and help them answer it.
Children
The Services are for businesses and their staff, and are not meant for anyone under 18 to use directly. A Customer may enter data about minors, for example the members it serves. In that case the Customer is responsible for obtaining verifiable consent from a parent or guardian, and we process that data only on the Customer's instructions.
Cookies and local storage
The apps use only strictly necessary cookies and browser storage: to keep you signed in, protect your session and remember settings such as your theme. The apps use no analytics, advertising or tracking cookies.
The website asks before it sets any analytics cookie. If you press Accept, Google Analytics sets its cookies (_ga and _ga_<id>, kept up to 14 months) to count visits. If you press Reject, or do nothing, no analytics cookie is set and nothing is sent to Google. Either way the site stores your choice in your browser. You can change it at any time under Cookie settings at the foot of every page; withdrawing consent stops analytics from that point on. We use no advertising cookies anywhere in the Services.
Changes to this policy
We will post any change on this page with a new effective date. If a change materially affects how we use your data, we will also tell account holders by email before it takes effect.
Contact us and Grievance Officer
- Privacy requests and questions: privacy@pleostack.com
- Grievance Officer: Praful, Founder — privacy@pleostack.com, at the registered office above
- Legal notices: legal@pleostack.com
- General support: hello@pleostack.com