Privacy Policy
1. Who we are
Rebaar(“Rebaar”, “we”) operates the Rebaar ERP platform at rebaar.in. We are the data processor for the workspace data you upload (you, the workspace Owner, are the data fiduciary under DPDP terminology). We are the data fiduciary for the small set of operational data we collect about you as a Rebaar user.
Contact for privacy and DPDP-related correspondence: [email protected].
2. What we collect — and why
Two categories:
2a. Account & usage data (Rebaar is the fiduciary)
- Identity: name, email, phone (optional), workspace name, GSTIN (optional)
- Authentication: password (bcrypt-hashed; we never see it), 2FA secret (encrypted), session cookies
- Billing: plan, billing cycle, last 4 digits of payment method (via Razorpay; full PAN never touches our servers)
- Audit: every mutation in your workspace is logged with actor + timestamp + diff. Stored 8 years for tax / dispute resolution.
- Telemetry: server-side error logs (Sentry). On the public marketing site only, Google Analytics 4 measures aggregate page views — but only if you accept the analytics cookie category (off by default; it never runs inside the logged-in product). No advertising or cross-site tracking cookies. See Section 8.
2b. Workspace data (you are the fiduciary; we are the processor)
- Project records, BOQs, schedules, daily progress, photos, drawings, contracts
- Client records (names, emails, phones, GSTINs of the people you bill)
- Vendor records, materials, indents, POs, GRNs, vendor bills
- Quotations and invoices
- Payroll: worker register, attendance, salary slips, PF/ESI/PT/TDS computations
- Integration credentials you connect (encrypted at rest — see Section 4)
We process this data only on your instructions (i.e. only when you or your team triggers an action in the product). We don't mine it, sell it, or use it to train models.
2c. Rebaar mobile app (the field app)
The Android / iOS field app collects the following, only while you actively use the relevant feature:
- Precise location (GPS): captured only when you check in for attendance or take a geo-tagged site photo, to record where the action happened. Foreground only — we never collect location in the background.
- Camera & photos: used to capture geo-tagged site photos you choose to upload. We access the camera only when you take a photo; we do not scan or read your photo library.
- Push notification token: a device token used solely to deliver app notifications. You can disable notifications in your device settings.
- Biometric / PIN app-lock: handled entirely by your device's operating system (Face ID / fingerprint / device PIN). The biometric data never leaves your device and is never transmitted to or stored by Rebaar.
- Sign-in tokens: stored in the device's secure keystore (iOS Keychain / Android Keystore), never in plain text.
All app data is transmitted over HTTPS/TLS. You can request deletion of your account and data at any time — see Section 6.
3. How we use it
Strictly to operate the product. Specifically:
- Authenticate you and your team
- Render projects, invoices, reports requested by users in your workspace
- Relay communications you initiate (invoice emails, WhatsApp reminders, Razorpay payment links) to the integrations you've connected
- Bill you for your subscription
- Send service emails (welcome, password reset, payment receipts, security alerts)
- Detect anomalies that might indicate abuse or compromise
- Improve the product (aggregate, anonymised usage signals only — never per-user)
We don't use your data for:marketing, ad targeting, third-party data brokers, ML training. If we ever change this, we'll ask for affirmative consent first.
4. Who else processes it (subprocessors)
Rebaar relies on a small number of third-party services to operate. The current list, with what each one handles:
- Infrastructure: AWS Mumbai (ap-south-1) — all primary data stays in India
- Subscription billing: Razorpay
- Email delivery: Resend
- Error monitoring: Sentry (PII redacted before transmission)
- Marketing-site analytics: Google Analytics 4 (Google LLC) — consent-gated; loads only on the public rebaar.in marketing pages after you accept the analytics cookie category, never inside the logged-in product. Used for aggregate visit measurement only.
- Optional, per-workspace: Meta WhatsApp, Anthropic Claude (OCR), Zoho Books / QuickBooks — only active when you opt in
Material changes to subprocessors are announced at least 14 days in advance via the workspace Owner's email.
5. Data retention
- Active workspaces: kept indefinitely while your subscription is active
- After cancellation: workspace remains accessible in read-only mode for 90 days; after that we may permanently delete it unless you re-subscribe
- Audit log: retained 8 years (Indian tax law requires it for financial records)
- SaaS tax invoices: Rebaar-issued invoices for your subscription are retained 8 years anonymised
- Backups: daily encrypted snapshots kept for 30 days; older snapshots are deleted on rolling basis
6. Your rights under the DPDP Act
You have the following rights at any time, exercisable from Settings → Privacy:
- Access & export (§11(1)(a)) — download every row of every table in your workspace as a JSON bundle plus your uploaded files. Available immediately, no waiting period.
- Correction (§11(2)) — edit any record at any time via the product UI
- Erasure / right to be forgotten (§12) — Owner-only action that permanently deletes your workspace. Audit log + SaaS invoices retained per legal requirement (Section 5).
- Withdraw consent — cancel your subscription, request deletion. We don't hold you in.
- Grievance redressal (§13) — escalate to [email protected]. We respond within 7 working days.
7. Security
Operational controls in place:
- TLS 1.3 in transit, AES-256 at rest (database + file storage)
- Third-party tokens (Razorpay key secrets, GST credentials, WhatsApp access tokens) encrypted with AES-256-GCM at the application layer, key derived from a deployment-level master secret
- 2FA TOTP available; Owners can require it via env-var policy
- Cross-tenant access is impossible by construction — every query filters by workspace ID
- Daily encrypted backups; point-in-time recovery for 30 days
- Annual third-party penetration test planned once we cross paying-customer scale. SOC 2 Type II and ISO 27001 are on our post-launch roadmap — not certified today.
For more detail, see Security overview.
8. Cookies
We use necessary cookies always, and analytics cookies only after you opt in. We never use advertising, ad-network, or cross-site tracking cookies.
Necessary (always on)
construct_session— your authenticated session. Required for login.- Short-lived OAuth and SAML state cookies during sign-in flows. Deleted on completion.
- A small cookie that remembers your cookie-consent choice so we don't ask again.
Analytics (off until you opt in)
On the public marketing site (rebaar.in), if and only ifyou accept the “analytics” category in the cookie banner, we load Google Analytics 4, which sets first-party cookies:
_ga,_ga_*— distinguish anonymous visitors and measure aggregate page views. They expire after about 13 months.
These do not load before you consent, and they never load inside the logged-in product. If you decline, or later withdraw consent from the cookie banner, Google Analytics is switched off and the_ga cookies are deleted. IP addresses are anonymised, and the data is never used for advertising or to identify you personally. Google LLC processes this analytics data — see Sections 4 and 10.
9. Children
Rebaar is a B2B product. We don't knowingly collect personal data from anyone under 18. If you discover a minor's data in your workspace (e.g. a worker register), it's your responsibility to handle it per Indian child-labour law.
10. Data transfers outside India
Primary data lives in AWS Mumbai (ap-south-1). Some subprocessors have offices or sub-processors outside India (Resend, Anthropic, Meta, Sentry, Google) — see Section 4 for specifics. By using Rebaar you consent to data being transferred to these processors for the specific purposes listed. We use Standard Contractual Clauses where applicable.
11. Changes to this policy
We'll announce material changes 14 days in advance via Owner email. Minor edits (typos, clarifications) are made silently with the “Last updated” date refreshed at the top of this page.
12. Contact us
Data Protection Officer (DPDP Act 2023): [email protected] — responds within 30 days as required by §10 of the Act.
Grievance officer (per IT Act 2000, Rule 3(11) IT Rules 2021): [email protected] — responds within 7 working days.
Security vulnerabilities: [email protected] (see also /.well-known/security.txt).
Postal: Rebaar, Bengaluru 560102, Karnataka, India