Privacy Policy
Last updated: 20 July 2026
In plain language: Upstrato builds AI-native software, websites, mobile apps, and SaaS products. This policy explains what personal data we collect (for example, when you fill out our contact form, subscribe to our newsletter, or use our SaaS products), why we collect it, who we share it with (such as our hosting, email, analytics, and AI providers), and the rights you have over your data. We collect only what we need, we don't sell your personal data, and you can contact us at privacy@upstrato.co.in at any time to exercise your rights or raise a concern.
1. Introduction
Upstrato ("Upstrato", "we", "us", or "our") is an AI-native software studio operated by Upstrato Technologies Pvt. Ltd., a company registered in India. We provide AI solutions, custom software development, website development, mobile app development, SaaS product development, social-media software tools, AI SaaS products, Agentic AI, and AI agents to business clients and to end-users of our SaaS products.
This Privacy Policy describes how we collect, use, disclose, retain, and protect personal data, and the choices and rights you have. We are committed to handling your data in accordance with applicable data protection laws, including:
- India's Digital Personal Data Protection Act, 2023 (the "DPDP Act") — our primary framework, as our principal operations are in India;
- the EU/UK General Data Protection Regulation ("GDPR") — for individuals in the European Economic Area (EEA), the United Kingdom, and Switzerland; and
- the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA/CPRA") — for California residents.
By using our website at https://upstrato.co.in (the "Website"), engaging our services, or using our SaaS products, you acknowledge that you have read and understood this Privacy Policy. Where the DPDP Act or GDPR requires your consent, we will ask for it separately.
2. Scope
This Privacy Policy applies to:
- Visitors to our Website;
- Individuals who contact us via our enquiry/contact form, email, or phone;
- Newsletter subscribers;
- Prospective and current business clients (and their authorized representatives) who engage us for services;
- End-users of our SaaS products and AI tools; and
- Other individuals whose personal data we process in connection with our business.
Two distinct roles. For much of the data we handle, we act as a Data Fiduciary (under the DPDP Act) / Data Controller (under the GDPR) / Business (under the CCPA/CPRA) — for example, data collected through our contact form, newsletter, or account registration. However, when we build software for, or host services on behalf of, a business client, we often act as a Data Processor (GDPR) / service provider (CCPA/CPRA) processing "client project data" on that client's instructions (see Section 3(c)). In that role, the client is the controller/fiduciary, our processing is governed by our agreement with them (typically a Data Processing Addendum), and end-users should consult that client's privacy notice regarding their data.
This policy does not apply to third-party websites, products, or services that we do not own or control, even if linked from our Website.
3. Information We Collect
We collect the categories of personal data described below. We aim to collect only what is necessary for the purposes set out in this policy.
(a) Information You Provide to Us
We collect data you voluntarily provide, including:
- Contact / enquiry form data: your name, email address, phone number, company/organization name, estimated budget or budget range, project details and requirements, and the content of your message. This is used to respond to your enquiry and scope potential work.
- Newsletter and marketing sign-up: your name and email address, and your subscription preferences.
- Client onboarding data: contact details of your authorized representatives, billing and tax information, project specifications, credentials or access details you share so we can perform the work, and other information exchanged during a project.
- Communications: the content of emails, support tickets, calls, and messages you send us.
- Payment-related information: billing name and address, and transaction records. Full card/bank details are collected and processed directly by our payment processors — we do not store complete payment card numbers on our systems.
(b) Information Collected Automatically
When you visit our Website or use our SaaS products, we (and our providers) automatically collect certain technical data:
- Device and connection data: IP address, device type, operating system, browser type and version, language settings, and screen/viewport information.
- Usage data: pages and screens viewed, links clicked, referring/exit URLs, the referrer that brought you to us, timestamps, session duration, and interaction events.
- Cookies and similar technologies: identifiers and preferences stored via cookies, local storage, and analytics tools (see Section 6 and our Cookie Policy).
- Log and diagnostic data: application logs, error reports, and performance metrics used to keep our services secure and reliable.
(c) Client Project Data We Process on Your Behalf
When we develop or operate software for a business client, we may process personal data contained within that client's systems, databases, user accounts, or content ("client project data"). This can include data about the client's own customers and end-users.
We process client project data as a processor, only on the documented instructions of the client, for the purpose of delivering the agreed services (for example, development, testing, hosting, maintenance, and support). We do not use client project data for our own purposes, and we handle it under the terms of our services agreement and, where applicable, a Data Processing Addendum. If you are an end-user of a product we built or host for a client and have questions about your data, please contact that client (the controller/fiduciary) directly.
4. How We Use Your Information
We use personal data for the following purposes:
- To respond to enquiries and provide quotes — reviewing your contact-form submission, scoping projects, and communicating with you about your request.
- To deliver our services — performing custom software, website, mobile app, SaaS, AI, and agentic-AI development and related services, and managing client relationships and projects.
- To operate and improve our SaaS products — providing features, maintaining accounts, delivering AI functionality, and improving performance and user experience.
- To send transactional and service communications — confirmations, account notices, security alerts, and support responses (sent via our email provider; see Section 7).
- To send marketing communications — newsletters and updates, where you have subscribed or where otherwise permitted by law; you can unsubscribe at any time.
- To process payments and manage billing — invoicing, collecting payments, and maintaining financial records.
- To secure, maintain, and improve our Website and services — monitoring for fraud and abuse, debugging, analytics, and performance optimization.
- To comply with legal obligations — including tax, accounting, and regulatory requirements, and to establish, exercise, or defend legal claims.
A note on AI processing. Some features rely on third-party AI providers (such as OpenAI and Anthropic). Where we send content to these providers to deliver a feature, we do so under their business/enterprise terms. We do not knowingly submit personal data to AI providers beyond what is necessary for the feature, and, where our agreements allow, we opt out of having your inputs and outputs used to train their general models. Where we process client project data through AI providers, we do so only on the client's instructions.
5. Legal Bases for Processing
We rely on the following legal bases, depending on the applicable law and the context.
Under India's DPDP Act
We process personal data based on your consent, or on "certain legitimate uses" permitted by the Act (for example, where you have voluntarily provided data for a specified purpose, or to fulfill a legal obligation). Where we rely on consent, our notice describes the purpose, and you may withdraw consent at any time with effect for future processing.
Under the GDPR (EEA/UK/Switzerland)
We rely on one or more of the following lawful bases:
- Consent (Art. 6(1)(a)) — e.g., marketing emails and non-essential cookies;
- Performance of a contract (Art. 6(1)(b)) — e.g., delivering services you or your organization requested;
- Legitimate interests (Art. 6(1)(f)) — e.g., responding to enquiries, securing our systems, and improving our services, where not overridden by your rights;
- Legal obligation (Art. 6(1)(c)) — e.g., tax and accounting duties.
For California Users
We process personal information as described in this policy. We do not sell personal information and do not "share" it for cross-context behavioral advertising in exchange for money. If we ever enable advertising cookies that constitute a "sale" or "share" under the CCPA/CPRA, we will provide a "Do Not Sell or Share My Personal Information" mechanism and honor opt-out preference signals. See Section 12 for your California rights.
6. Cookies & Tracking Technologies
We use cookies and similar technologies to operate the Website, remember your preferences (such as dark-mode/theme), record your cookie-consent choices, and measure usage through analytics. Non-essential cookies are set only where permitted, and where required, only after you consent via our cookie banner.
For a full list of the cookies we use, their purposes, and how to manage them, please see our Cookie Policy.
7. Third-Party Service Providers / Sub-processors
We work with trusted third parties that process personal data on our behalf or as independent controllers for specific functions. We share only the data needed for each purpose and require appropriate confidentiality and security safeguards. The categories below are representative; specific providers may change over time.
| Provider | Purpose | Data Involved | Their Privacy Policy |
|---|---|---|---|
| Resend | Transactional and notification email delivery | Recipient email address, name, message content/metadata | See Resend's privacy policy on their website |
| Vercel | Website/app hosting, edge delivery, and (optionally) privacy-friendly analytics | IP address, request and usage/log data, aggregated analytics | See Vercel's privacy policy on their website |
| Amazon Web Services (AWS) | Cloud hosting, storage, compute, and databases | Application and client project data as stored/processed | See AWS's privacy notice on their website |
| Google Analytics | Website analytics and performance measurement (if enabled) | IP address (truncated where configured), device/usage data, cookie identifiers | See Google's privacy policy on their website |
| Vercel Analytics | Privacy-friendly, cookieless website analytics (if enabled) | Aggregated, non-identifying usage metrics | See Vercel's privacy policy on their website |
| Plausible Analytics | Privacy-friendly, cookieless website analytics (if enabled) | Aggregated, non-identifying usage metrics | See Plausible's data policy on their website |
| OpenAI | AI model inference for AI features and agents | Prompts/inputs and outputs necessary to deliver the feature | See OpenAI's privacy policy on their website |
| Anthropic | AI model inference for AI features and agents | Prompts/inputs and outputs necessary to deliver the feature | See Anthropic's privacy policy on their website |
| Payment processors (e.g., our chosen provider) | Payment processing, invoicing, and fraud prevention | Billing details, transaction data (card data handled by the processor) | See the processor's privacy policy on their website |
| CRM provider | Managing enquiries, leads, and client relationships | Name, email, phone, company, enquiry and project details | See the CRM provider's privacy policy on their website |
We maintain agreements with these providers requiring them to protect personal data and to process it only as instructed. A current list of sub-processors used for a specific client engagement is available to that client on request.
8. How We Share Information
We may disclose personal data:
- To service providers and sub-processors listed in Section 7, to perform functions on our behalf.
- To business clients, where you are their end-user and we process data on their behalf as a processor.
- In business transfers, such as a merger, acquisition, financing, or sale of assets, in which case personal data may be transferred subject to this policy.
- For legal and safety reasons, to comply with applicable law, respond to lawful requests from public authorities, enforce our agreements, or protect the rights, property, or safety of Upstrato, our users, or others.
- With your consent or at your direction, for any other purpose disclosed at the time.
We do not sell your personal data.
9. International Data Transfers
We operate globally and our providers may be located outside your country, including outside India, the EEA, and the UK (for example, in the United States). When we transfer personal data across borders, we take steps to ensure it remains protected, such as:
- transferring only to jurisdictions and providers that offer an adequate level of protection, or
- putting in place appropriate safeguards, such as the EU Standard Contractual Clauses (and the UK Addendum / IDTA) or equivalent contractual protections.
Transfers of personal data outside India are made consistent with the DPDP Act and any applicable restrictions the Government of India may notify. You may contact us at privacy@upstrato.co.in for more information about the safeguards we use.
10. Data Retention
We retain personal data only for as long as necessary for the purposes described in this policy, including to provide our services, comply with legal, tax, and accounting obligations, resolve disputes, and enforce our agreements. Illustrative retention periods:
- Contact/enquiry-form data: kept for the duration needed to respond and evaluate a potential engagement, then deleted or archived when no longer needed for a legitimate purpose.
- Client project data: retained for the term of the engagement and returned or deleted afterward per our agreement, unless retention is required by law.
- Newsletter data: kept until you unsubscribe.
- Billing and financial records: retained as required by applicable tax and accounting laws.
- Logs and analytics: retained for limited periods for security and performance purposes.
When personal data is no longer needed, we delete, anonymize, or securely destroy it.
11. Data Security
We implement reasonable technical and organizational measures appropriate to the risk, including encryption in transit (TLS), access controls and role-based permissions, hosting with reputable providers (Vercel, AWS), logging and monitoring, and least-privilege practices for AI and third-party integrations. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. In the event of a personal-data breach, we will notify the relevant Data Protection Board of India, other competent authorities, and affected individuals as required by applicable law.
12. Your Rights & Choices
Subject to applicable law, you may have the following rights. To exercise them, contact us at privacy@upstrato.co.in (see also Grievance Redressal). We will verify your identity before acting and respond within the timeframes required by law. We will not discriminate against you for exercising your rights.
| Right | DPDP Act (India) | GDPR (EEA/UK) | CCPA/CPRA (California) |
|---|---|---|---|
| Access / know what data we hold and how it's used | Yes | Yes | Yes |
| Correction / rectification of inaccurate or incomplete data | Yes | Yes | Yes |
| Erasure / deletion of your data | Yes | Yes | Yes |
| Data portability (receive data in a portable format) | — | Yes | Yes |
| Restrict or object to certain processing | — | Yes | Right to limit use of sensitive info |
| Withdraw consent (with effect for future processing) | Yes | Yes | n/a |
| Opt out of "sale"/"share" of personal information | n/a | n/a | Yes |
| Nomination (nominate someone to exercise rights on death/incapacity) | Yes | — | — |
| Non-discrimination for exercising rights | — | — | Yes |
| Lodge a complaint with a supervisory authority | Data Protection Board of India | Your local DPA | California Privacy Protection Agency / Attorney General |
Choices you can make directly:
- Marketing: unsubscribe using the link in any marketing email, or email privacy@upstrato.co.in.
- Cookies: manage non-essential cookies via our cookie banner or your browser settings (see the Cookie Policy).
- Authorized agents (California): you may use an authorized agent to submit requests on your behalf, subject to verification.
13. Grievance Redressal
If you have concerns about how we handle your personal data, or wish to exercise your rights, please contact our Grievance Officer. As required by India's DPDP Act (and its rules), we provide the following point of contact:
Grievance Officer Name: Grievance Officer name Email: privacy@upstrato.co.in Postal address: Registered office address, City, State, PIN, India Company: Upstrato Technologies Pvt. Ltd.
We will acknowledge and respond to grievances within the timeframes required by applicable law. If you are not satisfied with our response, you may escalate to the Data Protection Board of India or, if applicable, your local data protection authority.
14. Children's Privacy
Our services and Website are directed to businesses and professionals and are not intended for anyone under the age of 18. Our SaaS products are not intended for children under 13 (or under 16 in jurisdictions where a higher age of digital consent applies). We do not knowingly collect personal data from children. Under the DPDP Act, processing of a child's data requires verifiable consent of a parent or lawful guardian, and we do not knowingly undertake such processing without it. If you believe a child has provided us with personal data, please contact privacy@upstrato.co.in and we will take appropriate steps to delete it.
15. Do Not Track
Some browsers offer a "Do Not Track" (DNT) signal. There is no consistent industry standard for how to respond to DNT signals, and we do not currently respond to them. Where legally required (for example, under the CCPA/CPRA), we honor recognized opt-out preference signals such as the Global Privacy Control (GPC). You can control tracking through our cookie banner and your browser settings.
16. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will update the "Last updated" date above and, where appropriate, provide additional notice (such as a notice on the Website or by email). We encourage you to review this policy periodically.
17. Contact Us
If you have questions, requests, or complaints about this Privacy Policy or our data practices, please contact us:
- Privacy matters: privacy@upstrato.co.in
- Legal matters: legal@upstrato.co.in
- General enquiries: hello@upstrato.co.in
- Product support: support@upstrato.co.in
- Phone: +91-XXXXXXXXXX
- Mail: Upstrato Technologies Pvt. Ltd., Registered office address, City, State, PIN, India
- Website: https://upstrato.co.in
This Privacy Policy is governed by the laws of India. Any disputes are subject to the exclusive jurisdiction of the courts of City, India.
Questions about this policy?
We're happy to help. Email privacy@upstrato.co.in or reach out through our contact page.
Contact us