Storey — Privacy Policy
DRAFT for lawyer review · NOT yet published
Drafted 2026-05-22 · Status: DRAFT — do not publish until reviewed by an Indian-law SaaS specialist
⚠️ This is a TEMPLATE. It captures Storey's specifics honestly, but needs a qualified Indian-law SaaS lawyer to review for compliance with the DPDP Act 2023, IT Act 2000, and SPDI Rules 2011 before being published at
storeyinfra.com/privacy. Estimated review cost: ₹3-5k for a one-time review by an experienced startup lawyer.
Privacy Policy
Effective date: 5 June 2026 Last updated: 5 June 2026
1. Who we are
This Privacy Policy applies to the Storey application and website operated by Storey Infra (the "we", "us", "Storey"), with primary contact based in Guwahati, Assam, India.
Storey Infra is currently being organised as a private limited company under the Companies Act 2013. Once incorporated, this Policy will be updated to reflect the corporate entity.
For all privacy-related questions or requests:
- WhatsApp: +91 98640 66898
- Email: help@storeyinfra.com
- Postal correspondence: Storey Infra, Guwahati, Assam, India. Until our registered office is published, please use email (help@storeyinfra.com) or WhatsApp (+91 98640 66898) — both are monitored 7 days a week and are our primary channels of record.
2. What this Policy covers
This Policy explains:
- What personal data we collect from you
- Why we collect it
- How we store, use, and protect it
- Your rights regarding your data
- How to contact us with privacy-related questions
It applies to:
- The Storey mobile app (Android, distributed via Google Play)
- The Storey web app at storeyinfra.com
- The Storey support channels (WhatsApp, email)
3. Data we collect
We collect only the data necessary to provide Storey's site-operations features. Specifically:
Data you provide to us directly
| Category | Examples | Why we need it |
|---|---|---|
| Account identity | Name, email address, password (encrypted), phone number (optional) | To create your user account and authenticate you |
| Business identity | Company name, role within the company | To set up your tenant workspace and assign permissions |
| Site data | Site names, locations, budgets, start/end dates | Core operational data — these are the sites you are managing |
| Worker data | Worker names, trade, daily wage, phone number, last 4 digits of ID proof (Aadhaar/PAN/Voter ID) | To support your daily attendance and payroll workflows |
| Material data | Material names, quantities, unit, allocations, transfers | Core operational data |
| Task data | Task descriptions, assignees, status, due dates, daily updates | Core operational data |
| Expense data | Expense amounts, categories, receipts | Core operational data |
| Photos | On-site photos for daily logs, attendance, expenses, materials | Verification + documentation of site activity |
Data we collect automatically
| Category | Examples | Why |
|---|---|---|
| Device data | Device model, OS version, app version | To improve compatibility and fix bugs |
| Connection data | IP address (anonymised for storage), connection timestamps | Security monitoring and debugging |
| Usage data | Pages visited, features used, error logs | To improve the product |
Data we DO NOT collect
- We do not collect your full Aadhaar or PAN numbers — only the last 4 digits, for human verification purposes. The full number stays with the worker.
- We do not collect biometric data.
- We do not access your phone's contacts, calendar, or other apps.
- We do not collect location data continuously — only when you take a geo-tagged photo and choose to attach location to that photo.
- We do not collect payment-card information directly — any payment processing in future will be handled by certified payment providers who handle that data themselves.
4. Why we process your data — the legal basis
Under the Digital Personal Data Protection Act 2023, we process your personal data based on:
- Your consent — given when you sign up by accepting these Terms. You can withdraw consent at any time by closing your account; we will delete or anonymise your personal data within 90 days, subject to legal retention requirements.
- Necessity to perform a contract — to deliver the service you signed up for.
- Compliance with legal obligations — tax, financial, and regulatory reporting requirements applicable to us as an Indian business.
5. How we use your data
- To provide the Storey service to you and your team
- To send you transactional emails (password resets, important account notifications, security alerts)
- To debug issues and improve product reliability
- To respond to your support requests
- To comply with our legal and regulatory obligations
- To analyze aggregated, anonymised usage patterns to improve the product
We do NOT:
- Sell your data to third parties
- Use your data to train AI models for resale
- Share your data across tenants (each company's data is fully isolated by access rules and encryption)
- Send marketing emails without your separate consent
5.1 Beta-period reminder about the data you upload
Storey is currently in free beta. The data-protection duties we owe you under the DPDP Act 2023 and IT Act 2000 apply in full — see Section 10 for what we do to protect your data. However, because the service is in active development and provided at no charge, we strongly recommend that during beta you:
- Do not upload data you cannot afford to lose without an independent backup of your own.
- Do not rely on Storey as your sole or primary system of record for business-critical information.
- Verify any output (reports, calculations, balances) against your own source documents before acting on it commercially.
- Maintain your own copies of statutory records (tax invoices, worker IDs, payment ledgers) that you would otherwise be obliged to retain under Indian law.
This is not a waiver of our duties — it is a sensible precaution while Storey is still maturing. See Section 3 of our Terms of Service for the corresponding allocation of risk during the free beta period.
6. Where your data is stored
Your data is stored on Supabase (Amazon AWS Mumbai region) — India-domiciled servers. We chose Mumbai specifically to avoid any cross-border data transfer questions for Indian customers.
Photos are stored in Supabase Object Storage in the same region. Email communications are handled by Resend, with delivery servers that may transit international infrastructure but messages are not stored long-term outside India.
7. Who can access your data
- You and your authorised team members — based on the permissions set by your tenant administrator (typically the contractor)
- Storey staff — only when necessary for support, debugging, or legal compliance, and only with documented reason
- Service providers we use (Supabase, Vercel, Resend, Google) — acting as our processors under appropriate data processing agreements
- No one else — we do not share your data with other contractors, competitors, advertisers, or third parties without your explicit consent
8. Your rights
Under the DPDP Act 2023, you have the right to:
- Access the personal data we hold about you
- Correct any inaccurate or incomplete data
- Delete your data (subject to legal retention requirements)
- Receive a copy of your data in a portable format
- Withdraw consent for data processing (which will result in account closure)
- File a grievance with us — and if unresolved, with the Data Protection Board of India
To exercise any of these rights:
- WhatsApp: +91 98640 66898
- Email: help@storeyinfra.com
We will respond to your request within 30 days (often faster — usually within 7 days).
9. How long we keep your data
- Active accounts: for the duration of your active subscription / account
- Closed accounts: we retain personal data for 90 days after closure to allow for re-activation, then permanently delete or anonymise
- Backup retention: encrypted backups may be retained for up to 90 days as a routine disaster-recovery measure
- Legal-hold retention: if litigation or regulatory action is pending, we may retain specific data longer as required by law
10. How we protect your data
We use industry-standard practices:
- Encryption in transit — all communication uses HTTPS / TLS 1.2+
- Encryption at rest — all data stored on Supabase is encrypted at the storage layer
- Row-Level Security — Postgres RLS policies enforce that each tenant can only see their own data, with no app-layer guards as the only line of defence
- Authentication — passwords are hashed; multi-factor login via Google OAuth available
- Access controls — Storey staff access requires documented reason
- Regular security reviews — at least two independent RLS audits completed in May 2026
No security system is perfect. If you discover a security issue, please report it confidentially to security@storeyinfra.com (or via WhatsApp). We commit to a fix or disclosure within 90 days of disclosure.
11. Photos and on-site documentation
Storey allows you to capture photos as part of daily logs, attendance, material receipts, and other workflows. These photos:
- Are captured using your device's camera with your active action (not in the background)
- Are stored in your tenant's private storage space, not publicly accessible
- May include date-time stamps burned into the image as proof of capture time
- Remain your tenant's property — Storey does not claim ownership or rights to use them beyond providing the service
- Are deleted when you delete the parent record (e.g. daily log) or your account, subject to backup retention windows
12. Cookies and tracking
We use a minimal set of cookies — primarily:
- Session cookies to keep you signed in
- Functional cookies to remember your preferences
We do NOT use:
- Third-party advertising cookies
- Cross-site tracking pixels
- Marketing analytics tools that profile individual users
Aggregated, anonymised usage data may be collected to improve the product (e.g. "what % of users complete the onboarding flow") — but this is not tied to your individual identity.
13. Children
Storey is a business tool for construction professionals. It is not intended for users under 18 years of age. If you become aware that a minor has provided us with personal data, please contact us and we will delete it promptly.
14. Cross-border data transfers
Currently, your data is stored exclusively in India (AWS Mumbai). If this changes — e.g. if we add an international customer or infrastructure outside India — we will update this Policy and notify existing users at least 30 days before the change takes effect.
15. Changes to this Policy
We may update this Privacy Policy from time to time. When we make material changes:
- We will update the "Last updated" date at the top
- We will notify active users via in-app notification and email
- For significant changes affecting your rights, we will give at least 30 days' notice before they take effect
16. Grievance officer
For privacy-related complaints or queries that aren't resolved through ordinary support channels:
Grievance officer: Karun Roongta Email: help@storeyinfra.com (mark "Privacy Grievance" in subject) WhatsApp: +91 98640 66898
We will acknowledge your grievance within 48 hours and resolve within 30 days. If you remain unsatisfied, you have the right to escalate to the Data Protection Board of India.
17. Governing law
This Policy is governed by the laws of India. Any disputes shall be subject to the exclusive jurisdiction of the courts in Guwahati, Assam.
This Policy was drafted in good faith by Storey's founder with domain-knowledge support, not legal expertise. Please review with a qualified lawyer before relying on it for compliance purposes.