ShipSprint is a product of Quantuva Technologies Pvt. Ltd. ("Quantuva", "we", "us"), a company incorporated in India with its registered office in Hyderabad, Telangana, India. This Privacy Policy explains what personal data we collect when you use ShipSprint at shipsprint.app, why we collect it, how it is protected, and the rights you have over it. It is published in accordance with the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and the Digital Personal Data Protection Act, 2023 ("DPDP Act").
CONSENT. Creating an account requires actively accepting this policy and the Terms of Service — the signup form will not proceed without it. We record when you accepted and which published version, so both of us can prove what was agreed. You can withdraw consent at any time by deleting your account, as described under Your Rights.
WHAT WE COLLECT. Account data: your name, work email address and a password (stored only as a salted bcrypt hash — we can never read it). Workspace content: the projects, issues, comments, documents, time entries and files that you and your teammates create in your workspace. Billing data: your organisation's billing name, address and GSTIN where provided, and records of invoices and payments. Payment card and bank details are collected and processed entirely by our payment gateways and never touch our servers. Operational data: each request to our servers is logged with its method, path, status, duration and acting user identifier, for debugging, security and abuse prevention.
WHAT WE DO NOT COLLECT. We do not take screenshots, log keystrokes, record your screen, track your browsing outside the application, or collect device fingerprints. We measure work outcomes that users record themselves — never surveillance data.
COOKIES AND SIMILAR TECHNOLOGIES. The ShipSprint application does not use advertising or cross-site tracking cookies. Your sign-in session is held in your browser's local storage, not in a cookie. Our public website counts page views and clicks using a random identifier kept in your browser's session storage; it stores no cookie, no IP address and no fingerprint, dies when the tab closes, and honours the Do Not Track and Global Privacy Control browser signals. When you make a payment, the payment gateway's checkout may set cookies of its own, governed by its privacy policy. Because we do not use tracking cookies, no cookie-consent banner is required; if that ever changes, this policy will be updated and consent obtained first.
PURPOSE AND LEGAL BASIS. We process personal data to provide the service you have subscribed to, to bill you and maintain accounts as required by tax law, to secure the service and investigate abuse, and to send transactional email such as verification, invitations and notifications you have enabled. Under the DPDP Act our processing rests on your consent, given at signup, and on legitimate uses connected with providing a service you have requested. Where the EU/UK GDPR applies, our lawful bases are performance of a contract (running the service), legal obligation (tax and accounting records) and legitimate interest (security and abuse prevention). We do not sell personal data and we do not use your workspace content to train machine-learning models.
WHO ELSE PROCESSES IT. We share data only with the sub-processors needed to run the service: Railway (cloud hosting, database and image storage), Razorpay and PhonePe (payments), and our transactional email delivery provider. Each receives only the data its function requires and is bound to process it only on our instructions. The complete, current list — with what each service receives — is published at shipsprint.app/#/subprocessors and is updated before any sub-processor is added or replaced. If you sign in with Google or Microsoft, that provider shares your email address and profile name with us. If your workspace enables the GitHub integration, GitHub sends us the commit and pull-request metadata your team generates; we send nothing to GitHub. If you connect an AI assistant (such as Claude or ChatGPT) to your own account, the data you ask it to read is sent to that provider under your agreement with them; the connection is made by you, scoped to your own permissions, and revocable by you at any time from your profile.
WHERE YOUR DATA LIVES. The service and its database are hosted on Railway infrastructure; uploaded images are stored in Railway object storage in Singapore. If you use ShipSprint from outside these locations, including from the EU or UK, your workspace data is transferred to and processed in them, protected by our sub-processors' industry-standard contractual safeguards for international transfers.
DATA RETENTION. Workspace content remains until you delete it or the workspace is deleted. A workspace owner can delete the entire workspace from within the application (Admin → Danger zone): a 30-day grace window follows, during which any owner can cancel, after which everything is permanently and irreversibly deleted. Workspaces with no activity for 45 days are scheduled for the same deletion with 30 days of email warnings; any sign-in cancels it. A short-lived backup of a deleted workspace is destroyed within 30 days of the deletion running. Invoices are retained for 8 years as Indian tax law requires; if a workspace is deleted, its invoices move to an anonymized tax archive containing no workspace content. Email delivery logs are retained 90 days, audit trails 12 months and in-app notifications 180 days. All of these windows are enforced automatically every night.
YOUR RIGHTS — SELF-SERVE, ON EVERY PLAN, FREE OF CHARGE. Access and portability: any member can download everything attributed to them (profile, comments, time entries, notifications) from their profile, and owners can export the organisation's entire workspace as machine-readable JSON from Admin. Correction: change your display name and email address from your profile; a new email takes effect only after it is verified from that inbox. Erasure: delete your own account from your profile — your account and personal records are removed and your identity is permanently detached from past work, which remains with the workspace in anonymized form. Owners may delete the whole workspace as described above. Marketing email: every digest or offer email carries a one-click unsubscribe link; transactional notices (receipts, password resets, deletion warnings) continue because the service cannot run safely without them. You may nominate another person to exercise these rights on your behalf as provided by the DPDP Act. Anything you cannot do in the product, request at the contact details on our Contact page (shipsprint.app/#/contact); we respond within 30 days.
CHILDREN. ShipSprint is a workplace tool and is not directed at children. You must be at least 18 years old (or the age of majority where you live) to create an account.
REGION-SPECIFIC RIGHTS. European Union and United Kingdom (GDPR/UK GDPR): you additionally have the rights to restrict or object to processing and to lodge a complaint with your supervisory authority. California (CCPA/CPRA): we do not sell or share personal information as those terms are defined; the rights to know, delete and correct are served by the self-serve tools above, and we do not discriminate for exercising them. Canada (PIPEDA) and Australia (Privacy Act): the same access, correction and deletion rights apply through the same tools.
GRIEVANCES. If you believe your data has been mishandled, write to our Grievance Officer at sk@quantuva.in with the subject line "Data grievance". We acknowledge within 72 hours and resolve within 30 days. If you remain unsatisfied you may complain to the Data Protection Board of India constituted under the DPDP Act, or to your local supervisory authority where the GDPR applies.
SECURITY. Every customer workspace is an isolated tenant; cross-tenant access is rejected at the authorisation layer. Passwords are hashed, two-factor authentication is available to every user, administrative actions are recorded in an audit log your organisation can read, and access is transmitted only over HTTPS. These constitute our reasonable security practices under the IT Rules, 2011. No system is perfectly secure; if a breach affects your personal data we will notify you without undue delay — within 72 hours of becoming aware where the GDPR applies — and notify the authorities required by law, including the Data Protection Board of India under the DPDP Act.
CHANGES. Material changes to this policy are notified to account owners by email before they take effect, and the policy version shown at signup is updated so new acceptances reference the current text.
This policy was last updated on 14 August 2026 (version 2026-08-14). Quantuva Technologies Pvt. Ltd., Hyderabad, Telangana, India.