ProcureTrack·Terms of Use·Home
Legal · ProcureTrack

Privacy Policy

Effective Date: 30 May 2026  ·  Last Updated: 30 May 2026

This Privacy Policy explains how ProcureTrack collects, uses, stores, shares, and protects your personal data. It is published in accordance with the Digital Personal Data Protection Act, 2023, the Information Technology Act, 2000, and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.

01Who We Are

ProcureTrack ("ProcureTrack", "we", "us", "our") is a construction procurement management platform currently operated by Avon Kumar Sahni, sole proprietor, with operations to be transferred to a Private Limited company upon its incorporation. The transferee entity will assume all obligations under this Policy without diminishing any user right.

Registered correspondence address: Ardee City, Gurugram, Haryana, India.
Email: admin@procuretrack.in

02Scope and Applicability

This Policy applies to all users of the ProcureTrack web application, its sub-domains, and any related services (collectively, the "Service"). By accessing or using the Service, you confirm that you have read this Policy and consent to the practices described.

The Service is intended for business use by construction firms, contractors, consultants, suppliers, and their authorised personnel. It is not directed at children under the age of 18, and we do not knowingly collect data from minors.

03What We Mean By "Personal Data"

"Personal data" means any data about an individual who is identifiable by or in relation to such data, as defined under Section 2(t) of the Digital Personal Data Protection Act, 2023. "Sensitive personal data or information" carries the meaning given under Rule 3 of the SPDI Rules, 2011.

04Data We Collect

4.1 Information You Provide Directly

CategoryExamples
Identity & ContactName, designation, employer, business email, mobile number, postal address
Account CredentialsUsername, encrypted password, authentication tokens
Business DataProject information, bills of quantity (BOQ), vendor master records, purchase orders, rate contracts, invoices, payment status, GSTIN, PAN of business entities
Billing DataSubscription plan, invoice address, GSTIN (for tax invoicing); payment instrument details are handled directly by our payment partners and are not stored by us
CommunicationsSupport tickets, queries, feedback, and any correspondence with us

4.2 Information Collected Automatically

When you use the Service we automatically collect: IP address, device and browser identifiers, operating system, access timestamps, pages viewed, click events, error logs, and similar technical information. We use cookies and similar technologies for session management, security, and basic usage analytics.

4.3 Information from Third Parties

We may receive data from authentication providers (where you sign in via a third-party account) and from your employer organisation if it has enrolled you on the Service.

Note on Business DataMost data you upload to the Service relates to commercial entities rather than identifiable natural persons, and may not constitute "personal data" under the DPDP Act, 2023. We nevertheless apply the same security and confidentiality safeguards to such commercial data as we do to personal data.

05Purpose and Legal Basis

We process personal data for the following purposes, and rely on the lawful grounds indicated below as required by Sections 4 to 7 of the DPDP Act, 2023:

PurposeLawful Ground
To create and operate your accountConsent & contractual necessity
To provide procurement, vendor, and project management featuresConsent & contractual necessity
To process subscription payments and issue tax invoicesLegal obligation (GST law) & contractual necessity
To provide customer supportConsent & legitimate use
To send service notifications, security alerts, and policy updatesContractual necessity
To improve product performance, diagnose errors, and maintain securityLegitimate use under Section 7 of the DPDP Act
To comply with law, court orders, and government directionsLegal obligation
To send marketing or product update communicationsConsent (with opt-out)

06Third-Party Service Providers (Data Processors)

We engage the following categories of service providers to operate the Service. Each is contractually required to process personal data only on our documented instructions and to apply appropriate security safeguards:

ProviderPurposeData AccessedLocation
Razorpay Software Private LimitedPayment processingBilling name, contact, payment instrument detailsIndia
PayU Payments Private LimitedPayment processing (alternate gateway)Billing name, contact, payment instrument detailsIndia
Google LLC / Google India Private LimitedAuthentication, email delivery, usage analyticsAccount email, IP address, usage eventsServers located within and outside India
Supabase Inc.Application and database hostingAll Service dataAWS ap-south-1 (Mumbai, India)
Vercel Inc.Application delivery and edge networkRequest data, IP addressGlobal CDN; primary region configurable
Anthropic PBC ("Claude" API) — planned, not yet activeAI-assisted features such as document parsing, classification, and drafting suggestionsOnly the specific document or text snippet you submit to the AI feature; will be invoked only after you opt inOutside India
AI Features DisclosureWe plan to introduce AI-assisted features powered by the Anthropic Claude API. When activated, this will cause selected content (such as a document you submit to the feature) to be transferred outside India for processing. We will obtain your explicit consent before any such transfer occurs, and you will be able to use the rest of the Service without enabling AI features. Per Anthropic's commercial terms, data submitted to the Claude API is not used to train its models.

07Cross-Border Data Transfer

Some of our service providers (notably Google, Vercel, and in future Anthropic) operate infrastructure located outside India. By accepting this Policy, you acknowledge that your personal data may be transferred to, stored in, or processed in countries other than India. Such transfers are made in accordance with Section 16 of the DPDP Act, 2023, and we do not transfer personal data to any country that the Central Government may, by notification, restrict.

Our primary application database is hosted on Supabase infrastructure located in AWS ap-south-1 (Mumbai, India).

08Data Retention

We retain personal data only for as long as necessary to fulfil the purpose for which it was collected, or as required by applicable law (whichever is longer):

  • Account data — for the duration of your active subscription, plus 90 days after termination to allow for export and reactivation.
  • Trial accounts — account and all associated data are permanently deleted 14 days after the trial period expires if no paid subscription is taken up.
  • Business data uploaded by you — for the duration of your active subscription; deleted within 90 days of account closure unless you request earlier deletion.
  • Tax invoices and billing records — for 8 years from the end of the relevant financial year, as required under Section 36 of the CGST Act, 2017.
  • Server logs and security records — typically 180 days.

After the applicable retention period, personal data is securely deleted or irreversibly anonymised.

09Your Rights as a Data Principal

Subject to verification of identity and the limits of applicable law, you have the following rights under the DPDP Act, 2023:

  • Right to access a summary of your personal data and how it is processed (Section 11).
  • Right to correction and erasure of inaccurate, incomplete, or out-of-date personal data (Section 12).
  • Right of grievance redressal, exercisable through the contact below (Section 13).
  • Right to nominate another individual to exercise these rights in the event of your death or incapacity (Section 14).
  • Right to withdraw consent at any time, where processing is based on consent (Section 6). Withdrawal does not affect prior lawful processing.

To exercise any of these rights, write to our Grievance Officer (Section 13 below). We will respond within the timelines prescribed under the DPDP Rules.

10Security Practices

We follow reasonable security practices and procedures consistent with Rule 8 of the SPDI Rules, 2011, including:

  • Encryption in transit (TLS 1.2 or higher) for all data exchanged between your device and the Service.
  • Encryption at rest for the application database.
  • Row-level security (RLS) ensuring each organisation's data is strictly isolated from all other organisations.
  • Role-based access control and the principle of least privilege for internal personnel.
  • Routine backups, security patching, and vulnerability monitoring.
  • Confidentiality obligations on all personnel and contractors.

No system can be guaranteed perfectly secure. You are responsible for keeping your account credentials confidential and for notifying us promptly of any suspected unauthorised access.

11Personal Data Breach Notification

In the event of a personal data breach, we will notify the Data Protection Board of India and affected users in the manner and within the timelines prescribed under the DPDP Act, 2023 and CERT-In Directions dated 28 April 2022.

12Cookies

We use only essential and analytical cookies. Essential cookies are required for authentication and security and cannot be disabled. Analytical cookies (where used) help us understand aggregate usage and can be disabled through your browser settings; doing so may degrade certain features.

13Grievance Officer

In compliance with Section 8(9) of the DPDP Act, 2023, and Rule 5(9) of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, the following officer has been designated to address grievances:

NameAvon Kumar Sahni
DesignationGrievance Officer, ProcureTrack
Emailadmin@procuretrack.in
Postal AddressArdee City, Gurugram, Haryana, India
HoursMonday to Friday, 10:00 to 18:00 IST (excluding public holidays)

We will acknowledge your grievance within 48 hours and aim to resolve it within 30 days of receipt.

14Children

The Service is not directed at, and we do not knowingly collect personal data from, individuals under 18 years of age. If we become aware that we have inadvertently collected such data, we will delete it without undue delay.

15Changes to This Policy

We may update this Policy from time to time. Material changes will be notified through the Service or by email at least 7 days before they take effect. Continued use of the Service after the effective date constitutes acceptance of the updated Policy.

16Contact

For any questions about this Policy or our data practices, write to:
Email: admin@procuretrack.in
Address: Ardee City, Gurugram, Haryana, India

© 2026 ProcureTrack. All rights reserved. This Policy is governed by the laws of India.  ·  Terms of Use  ·  Home