This Privacy Policy explains what personal data M-Track ("we", "us") collects when you use our website, the M-Track web application, or the M-Track mobile app (together, the "Service"), why we collect it, and the rights you have over it. It is written to comply with the Digital Personal Data Protection Act, 2023 (India) and other applicable Indian privacy laws.
Legal
Privacy Policy
Last updated: 8 July 2026
1. About this policy
2. Who we are
M-Track is a construction and interior-project operations platform operated by a sole proprietorship registered in India. For the purposes of the DPDP Act we are the Data Fiduciary for the personal data you provide to us. You can reach our privacy team at privacy@mtrack.in.
3. What we collect
Account & billing data — Your name, email, phone number, organisation name, GSTIN (if provided), billing address, and payment records processed by our payment partner (Razorpay). We don't store card numbers or full bank details.
Project data — Everything you and your team create inside M-Track: projects, tasks, quotations, orders, approvals, meetings, attendance records, chat messages, and uploaded files. This content is yours; we process it to provide the Service.
Usage data — Log entries, device information, IP address, browser type, timestamps of important actions (sign-in, punch-in, approval decisions). We use these to keep the Service secure and to diagnose issues.
Location data — For labour and staff attendance features, your device's GPS location at punch-in / punch-out. This is stored against the specific attendance row and shown only to your organisation's admins.
4. How we use it
We use your personal data to:
- Provide and improve the Service, including new features.
- Send account, billing and service-related notifications.
- Provide customer support and respond to your requests.
- Detect and prevent fraud, abuse, and security incidents.
- Comply with legal or regulatory obligations.
We do not sell your personal data. We do not use your project data to train third-party AI models. Where we use data for our own Service-quality analytics it is aggregated and stripped of identifiers.
5. When we share
We share personal data only with the following categories of recipient, and only what's necessary:
- Sub-processors — Cloud infrastructure (Supabase / AWS), transactional email (Resend), payments (Razorpay), analytics (Vercel Analytics), push notifications (Firebase). Each is contractually bound to protect your data.
- Members of your organisation — Data you enter in M-Track is visible to the people at your organisation whom your admin grants access to it, per the role permissions your admin configures.
- Legal recipients — Courts, regulators, or law enforcement when we're required by law to disclose.
6. Where we store data
Your data is stored on Supabase infrastructure in the Asia-Pacific region. Backups are encrypted at rest. Data in transit is encrypted with TLS.
7. How long we keep it
We keep your project data for the entire duration of your paid subscription, plus a 30-day export window after cancellation. Account and billing records are retained for at least 8 years to meet Indian tax and accounting obligations. Log data is retained for 90 days unless a security incident requires us to hold it longer.
8. Your rights
Under the DPDP Act you have the right to:
- Access — Ask for a copy of your personal data.
- Correction — Ask us to correct data that's inaccurate or out of date.
- Erasure — Ask us to delete data we no longer need to hold.
- Nominate — Appoint another person to exercise these rights on your behalf if you're unable to.
- Grievance redressal — Raise a complaint with our privacy team.
To exercise any of these, email privacy@mtrack.in. We'll respond within 30 days. If we can't resolve your complaint you have the right to escalate to the Data Protection Board of India.
9. Cookies
We use a small number of cookies and equivalent local-storage keys, all essential to the Service: session cookies to keep you signed in, a preferences cookie for your theme + language choices, and a short-lived cookie to cache your account's active status. We don't use advertising cookies or cross-site tracking.
10. Security
We take reasonable technical and organisational measures to protect your data — role-based access controls, encryption in transit and at rest, principle-of-least-privilege service accounts, audit logs of admin actions. No system is perfectly secure; if a breach affects you we'll notify you and the Data Protection Board without undue delay.
11. Children
M-Track is not intended for use by anyone under 18. We don't knowingly collect personal data of children. If you believe a child has provided us data, contact us and we'll delete it.
12. Changes to this policy
If we change how we handle your data in a way that materially affects you, we'll notify you by email and in the app at least 30 days before the change takes effect.
Privacy questions? Reach the privacy team at privacy@mtrack.in, or read our Terms of Service for the wider contract.