Privacy Policy

Version 1.0 · Effective July 4, 2026

This Privacy Policy explains how RacLink ("RacLink", "we") collects, uses, and protects personal data when you use our website and Services. It applies alongside our Terms & Conditions. We comply with applicable data-protection laws, including India's Digital Personal Data Protection Act (DPDP) and, where applicable to our users, the EU/UK GDPR.

1. Data We Collect

Account data: name, email address, profile image, and authentication identifiers, processed via our identity provider (Clerk).

Organization & business data: the CRM contacts, companies, deals, invoices, documents, messages, and other content you and your team upload or create on the platform. This data belongs to you; we process it only to provide the Services.

Usage & device data: pages visited, feature usage, approximate location, browser and device information, collected via cookies and analytics tools (Google Analytics, PostHog) to improve the product.

Payment data: processed by Razorpay. We store order identifiers, amounts, and payment status — we never store your card number, CVV, or banking credentials.

AI interaction data: prompts and content you submit to AI features are processed by the AI model providers configured for your workspace in order to generate results.

2. How We Use Data

To provide, operate, secure, and improve the Services; to authenticate you; to process payments and prevent fraud; to provide support; to send service communications (and, with your consent, product updates); to enforce our Terms; and to comply with legal obligations. We do not sell your personal data.

3. AI Processing

When you use AI features, the relevant content is transmitted to third-party AI model providers (such as Google, OpenAI, or Anthropic, depending on the models configured) to generate the requested output. If you connect your own API keys, your direct relationship with that provider applies. We do not use your business data to train our own models.

4. Security

We use industry-standard measures: encryption in transit (TLS), encryption of sensitive fields at rest (AES-256-GCM), strict tenant isolation with verified membership checks on every request, role-based access controls, rate limiting, and a security audit log. Access to production data is restricted. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.

5. Sharing & Processors

We share data only with the processors needed to run the Services: Clerk (authentication), MongoDB Atlas (database hosting), Razorpay (payments), AI model providers (AI features), email delivery providers, analytics providers (Google Analytics, PostHog), and cloud storage providers. Each processor is bound by its own data-protection obligations. We may disclose data if required by law or to protect our rights, users, or the public.

6. Cookies

Essential cookies keep you signed in and your session secure. They are required for the Services to work and are always active.

Analytics cookies (Google Analytics and PostHog) help us understand how the site and product are used. They are strictly optional: when you first visit our website we ask for your permission, and the analytics scripts are not loaded and no analytics cookie is set unless you choose "Accept". Choosing "Decline", or ignoring the banner, means no analytics tool ever runs for you.

Your choice is remembered in your own browser's local storage so we do not ask again on every page. You can change or withdraw it at any time from the "Cookie Preferences" link in our website footer, and you can clear cookies and site data through your browser settings at any point. Blocking essential cookies will break sign-in.

7. Retention

We retain account and organization data while your account is active and for a reasonable period afterwards for legal, dispute, and backup purposes, after which it is deleted or anonymized. Security audit logs are retained for approximately 400 days. Payment records are retained as required by tax law.

8. Your Rights

Subject to applicable law, you may request access to, correction of, export of, or deletion of your personal data, and may object to or restrict certain processing. Organization business data is controlled by the organization's admins — direct requests concerning it to your admin. To exercise your rights, contact [email protected]; we respond within the timeframe required by law. You may also lodge a complaint with your local data-protection authority.

9. Children

The Services are for business use and not directed at children under 18. We do not knowingly collect data from children.

10. Changes & Contact

We may update this Policy; material changes will be notified in-app or by email. Contact: [email protected] (RacLink). Our full business contact details are available on the Contact page of our website.

This document is part of the RacLink legal agreements. See also our other policies linked in the site footer and in Settings → Legal inside the platform.