Skip to content

Privacy Policy

How Syahi Technologies LLP handles the personal data you and your team put into ITC Chase, who else can see it, and how to get it back or have it deleted.

Effective
10 September 2026
Entity
Syahi Technologies LLP

1. Who we are

Syahi Technologies LLP (“we”) operates ITC Chase. Our registered address is E-313, Nandi Meraki, Begur, Bangalore 560076, Karnataka, India. For data you upload about your own customers and suppliers, you are the controller and we are the processor; for your account and billing details, we are the controller.

2. What we collect

  • Account data: name, email address and, if you sign in with Google, the profile picture URL Google returns. Passwords are stored only as salted hashes by our authentication provider; we never see them.
  • Workspace data: the workspace name, country and the membership and role of everyone you invite.
  • Customer content: the files and records you import. We do not inspect them except to run the features you asked for, and we do not use them to train models.
  • Billing data: subscription status, plan, period dates and the customer identifier held by our payment provider. Card numbers never reach our servers — they are entered directly with Stripe or Razorpay.
  • Operational logs: timestamps, request paths, error codes and job outcomes. We deliberately keep personal data out of application logs.

3. Why we may use it

  • To provide the product you signed up for (performance of a contract).
  • To bill you and to recover failed payments (performance of a contract).
  • To send service email — trial reminders, payment failures, invitations. These are not marketing and cannot be turned off while your workspace is active.
  • To keep the service secure, including rate limiting and abuse investigation.
  • To meet tax and accounting obligations in Bengaluru, Karnataka, India.

4. Who else processes it

We use the following subprocessors. Each is bound by a data processing agreement and receives only what its function requires.

  • SupabaseDatabase, authentication and file storage.
  • VercelApplication hosting and scheduled jobs.
  • StripeCard payments and subscription billing outside India.
  • RazorpayCard and UPI payments and subscription billing in India.
  • ResendTransactional email delivery, including vendor nudges.

We do not sell personal data, and we do not share it with advertisers. We will tell workspace owners by email at least 30 days before adding a subprocessor that handles customer content.

5. Where it is stored

Data is hosted in ap-south-1 (Mumbai). Every table carries the identifier of the workspace that owns it and is protected by database-level row security, so one workspace cannot read another’s rows even if application code is wrong. Uploaded files are stored in a private bucket under a per-workspace path prefix with matching access policies. Stored third-party credentials are encrypted with AES-256-GCM and are only ever decrypted on the server.

6. How long we keep it

  • Customer content: for as long as your workspace exists.
  • After cancellation: the workspace becomes read-only at the end of the paid period and stays available for export. We delete it on written request.
  • Billing records: seven years, because tax law requires it.
  • Rate-limit counters: 24 hours. Finished background jobs: 30 days.
  • Unaccepted invitations: expire after 14 days.

7. Your rights

You can access, correct, export or delete your personal data, object to processing, or withdraw consent where we rely on it. Most of this is self-service: every list exports to CSV or XLSX, and profile details are editable in settings. For anything else, write to hello@syahi.sh and we will respond within 30 days. If you are an end customer of one of our customers, contact them first — they control that data.

8. Cookies

We set only what the product needs: a session cookie from our authentication provider, a workspace preference cookie (active_org, which the server verifies against your memberships on every request), a sidebar layout preference and a theme preference. There are no advertising or cross-site tracking cookies, which is why you are not asked to dismiss a consent banner.

9. Children

ITC Chase is a business tool and is not directed at anyone under 18. We do not knowingly collect data from children.

10. Security incidents

If a breach affects your data, we will notify affected workspace owners without undue delay and in any case within 72 hours of becoming aware, describing what happened, what we know is affected, and what we are doing about it.

11. Changes

We will post any revision here with a new effective date, and email workspace owners before a material change takes effect. Continuing to use ITC Chase after that date means you accept the revision. Your 14-day trial is covered by this policy from the moment you sign up.

Questions about this document? Write to hello@syahi.sh or to E-313, Nandi Meraki, Begur, Bangalore 560076, Karnataka, India.