Privacy Policy

Last updated 12 August 2026

Client24 is a customer relationship management service. This policy explains what we collect, where it is stored, who else can reach it, and what you can ask us to do with it. It is written to be read rather than skimmed past.

Who we are

Client24 is operated by Rajvardhan Gharge, Pune, Maharashtra, India. For any question about this policy or about your data, write to rajvardhan0918@gmail.com.

Two different kinds of data

The distinction matters, because our obligations differ for each.

  • Your account data — the email address, name and password you sign up with, and records of your sign-ins. We decide how this is used, so we are the data fiduciary for it.
  • Your workspace content — the leads, contacts, organisations, opportunities, tasks, meetings, projects, tenders, campaigns and proposals you create, including any personal details of your customers that you put in them. This is yours. We only store and process it so the product works, and we act on your instructions. You remain responsible for having a lawful basis to hold it.

What we collect

  • Account details: email address, display name, role, and workspace membership.
  • Content you enter into the CRM, as listed above.
  • An audit log of changes within your workspace — who changed which record, when, and what the values were before and after. This exists so you can answer that question about your own team.
  • Notification and reminder preferences.
  • Ordinary server logs generated by our hosting provider, including IP address and browser user agent.

We do not use tracking cookies, advertising pixels, or third-party analytics. The only cookies set are the ones that keep you signed in.

Where it is stored

The database is hosted by Supabase in the AWS ap-south-1 (Mumbai) region, so your live data stays in India.

Encrypted backups are an exception worth stating plainly: a nightly copy of the database is encrypted with AES-256 before it leaves the server and stored with GitHub, which may hold it outside India. It is retained for 90 days and then deleted automatically. Nobody at GitHub can read it — without the passphrase, which we hold separately, the file is meaningless.

Who else can reach it

We use a small number of service providers. Each is used for one purpose and receives only what that purpose requires.

  • Supabase — database, authentication and storage. Holds all workspace content.
  • Netlify — application hosting. Processes requests in transit and keeps server logs.
  • Brevo — sends transactional email such as reminders, proposals, and password resets. Receives the recipient address and the contents of that message only.
  • Google (Gemini) — powers the optional AI Assistant. If you use it, the text of your question and the records needed to answer it are sent to Google. If you never open the Assistant, nothing is sent.

We do not sell your data, and we do not share it with anyone for advertising.

How your workspace is kept separate

Every record belongs to exactly one workspace, and separation is enforced by the database itself rather than by application code. A query issued on behalf of one workspace cannot return another workspace's rows even if the application asks it to. Administrators are bound by the same rule: being an administrator makes you an administrator of your own workspace, not of anyone else's.

How long we keep it

  • Workspace content: for as long as your account is open.
  • Records you delete: hidden from the application immediately, but retained in the database so that an accidental deletion can be undone. They are removed when the workspace is closed, or sooner if you ask us to purge them.
  • Encrypted backups: 90 days, then deleted automatically.
  • Closed accounts: your workspace content is deleted within 30 days of you asking us to close the account. Copies inside backups age out on the 90-day cycle above.

Your rights

Under India's Digital Personal Data Protection Act, 2023, you may ask us to:

  • tell you what personal data of yours we hold and who it has been shared with;
  • correct anything inaccurate or incomplete;
  • delete your data, where we are not required to keep it;
  • nominate someone to exercise these rights if you are unable to.

Write to rajvardhan0918@gmail.com and we will respond within 30 days. If you are one of our customer's customers and your details sit in someone's Client24 workspace, contact that business directly — they control that record, not us — and we will assist them in responding to you.

Security

Traffic is encrypted in transit. Passwords are hashed and never stored in readable form, and nobody at Client24 can see yours. Access to the production database is limited to the operator named above. Backups are encrypted before storage.

No system is perfect. If we discover a breach affecting your data, we will notify you and the Data Protection Board without undue delay, and tell you what happened rather than what sounds best.

Children

Client24 is a business tool and is not intended for anyone under 18. We do not knowingly collect data from children.

Changes

If this policy changes materially, we will email account holders before the change takes effect. The date at the top always reflects the current version.