Privacy Policy
Your data is yours. Here is exactly how we collect, use, and protect it — in plain language, not legal jargon.
Last updated: July 13, 2026
TL;DR
- We collect only what we need — email, form responses, payment references, and (for shop downloads) licence-stamp and download-audit fields.
- We never sell your data. It is used only to deliver services you asked for and send emails you subscribed to.
- You are in control. Access, correct, or delete your data anytime by emailing automatewithpriya@gmail.com. We respond within 72 hours.
Who We Are
Automate with Priya is the trading name of SMAT Solutions Pvt Ltd (“we,” “us,” or “our”), an Indian private limited company registered at Uppal, Hyderabad, Telangana, India – 500039. Under the DPDP Act 2023, SMAT Solutions Pvt Ltd is the Data Fiduciary — responsible for how your personal data is processed.
Website: automatewithpriya.com
Contact: automatewithpriya@gmail.com
What We Collect
| Data | Source | Purpose |
|---|---|---|
| Email address | Signup, newsletter, auth | Account creation, service delivery, marketing (with consent) |
| Name & professional role | Service questionnaires | Tailoring your deliverables (Audit, Blueprint, etc.) |
| Organisation details | Service questionnaires | Contextualizing service delivery |
| UPI / gateway transaction reference | Cashfree, Razorpay, or WhatsApp confirmation | Payment verification & tax compliance |
| GSTIN / billing fields | Checkout (optional) | Tax invoice for your finance team |
| Questionnaire responses | Service intake forms | Creating your custom deliverables |
| Licence stamp data | My Library download | Embed purchase email + order ID on digital licence copies to deter redistribution |
| Download audit (item, time, IP hash) | My Library download | Enforce download limits, investigate abuse, support device resets |
| Device & browser info | Automatic (analytics) | Website optimization |
We do NOT collect:
- Bank account numbers, credit/debit card details, or UPI IDs
- Aadhaar, or government identity numbers issued to you as an individual. We do collect a business GSTIN when you supply one for a tax invoice — note that a GSTIN contains the registered entity's PAN within it, so if you give us a GSTIN you are also giving us that PAN. We never ask for a PAN on its own.
- Biometric data
- Data from anyone under 18
How We Use Your Data
- Service delivery: Processing your questionnaire responses to create Audits, Blueprints, Frameworks, or other deliverables
- Shop fulfilment: Granting My Library access, generating licence copies, and emailing purchase confirmations
- Licence enforcement: Stamping downloads and logging download events (with hashed IP) to enforce limits and deter redistribution
- Communication: Sending service updates, deliverables, and follow-ups via email or WhatsApp
- Newsletter: Weekly AI and L&D insights — only if you explicitly subscribe, with one-click unsubscribe in every email
- Improvement: Understanding which services are most valuable to improve our offerings
- Legal compliance: Meeting obligations under Indian law
We never sell, rent, or trade your personal data to third parties. Period.
Third-Party Services
We use these services to operate our platform. Each processes data on our behalf as a Data Processor under the DPDP Act:
| Service | What It Does | Data It Accesses |
|---|---|---|
| Supabase | Authentication & database | Email, auth tokens, questionnaire responses, service progress |
| Resend | Transactional & marketing email | Email address |
| Vercel (Hosting) | Website hosting | Server logs, IP address (standard hosting) |
| Vercel Speed Insights | Core Web Vitals performance telemetry | Anonymous page performance metrics (LCP, INP, CLS). No identifiers stored. |
| PostHog | Product analytics (page views, feature usage) | Anonymous session ID stored in browser localStorage. Page URLs are scrubbed of email addresses before they are sent. Used to measure which features help L&D leaders find what they need. |
| Sentry | Error tracking | Error stack traces, browser + OS info. Helps us fix bugs fast. |
| Cashfree Payments | Payment gateway (UPI, Cards, Net Banking, Wallets) for individual & team purchases | Transaction metadata. Cashfree is PCI-DSS compliant; we never store card/UPI credentials. |
| Razorpay | Payment gateway for enterprise-tier services (incl. payment links) | Transaction metadata, company name + GSTIN when supplied for invoicing. Razorpay is PCI-DSS compliant; we never store card/UPI credentials. |
| WhatsApp Business | Support & pre-launch drop reservations | Phone number, messages (operated by Meta) |
| Calendly | Scheduling for strategy calls, diagnostics & intake bookings | Name, email and the answers you give on the booking form. Stored against the booking so we can prepare for the call. |
| Anthropic (Claude) | Powers the service recommender — the chat that suggests which engagement fits you | Only the messages you type into that recommender. Not used to train models. Do not paste confidential material into it. |
Data Storage & Cross-Border Transfers
Some of our third-party services store data on servers located outside India:
- Supabase: Data may be stored in AWS data centers (US/EU region, depending on project configuration)
- Resend: Email delivery infrastructure located in the United States
- Vercel & Vercel Speed Insights: Edge network with global distribution; performance telemetry aggregated in the US
- PostHog: Anonymous product-analytics data routed to PostHog's US region (
us.i.posthog.com) - Sentry: Error telemetry routed to Sentry's US infrastructure
- Calendly: Booking data processed on Calendly's US infrastructure
- Anthropic: Service-recommender messages processed in the United States
Under the DPDP Act 2023, cross-border transfers are permitted to countries not restricted by the Central Government. As of July 13, 2026, no countries have been restricted. We will update this policy if regulations change.
Payments
Payments are processed through two licensed, PCI-DSS-compliant gateways: Cashfree (individual & team purchases — UPI, Cards, Net Banking, Wallets) and Razorpay (enterprise-tier services, including admin-issued payment links). This means:
- The transaction happens on the gateway's secure checkout — card/UPI details go to the gateway, never to us
- We never store your UPI ID, card number, bank account number, or any payment credentials
- We do store: gateway transaction references, payment amounts, dates, and (when you supply them) company name + GSTIN — for order fulfillment, invoicing, and tax compliance
- In rare offline cases (e.g. a custom engagement settled via bank transfer or UPI with WhatsApp confirmation), we store only the transaction reference and amount; confirmation screenshots are used solely for verification
Data Retention
| Data Type | Retention Period | Reason |
|---|---|---|
| Newsletter subscribers | Until you unsubscribe | Consent-based |
| Service questionnaire data | 12 months after delivery | Follow-up support & upgrades |
| Payment references | 7 years | Indian tax law requirement |
| Website analytics | Aggregated indefinitely | Anonymised, non-personal |
| Auth/session data | Until account deletion | Required for login |
After the retention period, data is permanently deleted. You can request early deletion at any time.
Your Rights Under the DPDP Act 2023
As a Data Principal, you have the right to:
Right to Access: Request a copy of all personal data we hold about you.
Right to Correction: Request correction of inaccurate or incomplete data.
Right to Erasure: Delete your data yourself anytime — sign in and use “Delete my data” on the My Services page — or request deletion by email. Subject to legal retention requirements.
Right to Withdraw Consent: Withdraw consent for marketing emails at any time. One-click unsubscribe in every email.
Right to Grievance Redressal: Raise a complaint about our data practices — we respond within 72 hours.
Right to Nominate: Nominate another person to exercise your data rights on your behalf.
To exercise any right, email automatewithpriya@gmail.com. We respond within 72 hours and complete actions within 30 days.
You also have the right to lodge a complaint with the Data Protection Board of India.
Children's Privacy
Our services are designed for L&D professionals and enterprise teams. This website is intended for users aged 18 and above. We do not knowingly collect personal data from anyone under 18. If you believe a minor has provided us with data, please contact us immediately and we will delete it.
Data Security
- All data transmission encrypted via HTTPS/TLS
- Database access restricted via Row-Level Security (RLS) policies
- API keys and service credentials are never exposed in client-side code
- Questionnaire responses stored in encrypted databases with access controls
- Regular security reviews of codebase and infrastructure
No system is 100% secure, but we take reasonable and appropriate measures to protect your information. In the event of a data breach, we will notify the Data Protection Board and affected users as required by the DPDP Act.
Changes to This Policy
We may update this privacy policy to reflect changes in our practices or legal requirements. Material changes will be communicated via email to active clients and subscribers. The “Last Updated” date at the top of this page indicates when the policy was last revised.
Questions About Your Data
Name: Vishnu Priya
Role: Founder & Data Protection Contact
Email: automatewithpriya@gmail.com
Response time: Within 72 hours
Resolution time: Within 30 days
Still not resolved? You have the right to raise a complaint with the Data Protection Board of India.