Privacy Policy
Effective Date: August 11, 2026 • Last updated: August 2026
Our Core Privacy Commitment & DPDP Act Alignment
At Vasishtha, we believe financial tooling requires strict data minimization, zero unauthorized tracking, and transparent architecture. In alignment with India's Digital Personal Data Protection (DPDP) Act 2023, we do not sell your data, we do not embed third-party advertising trackers, and we collect only the minimal information needed to deliver our services.
1. Data Minimization: What We Collect
We deliberately limit our data intake to functionally essential fields:
- Demo Requests: Name, work email address, company/firm name, and optional message notes provided voluntarily by you.
- Demo Inquiry Data: We collect only the information you provide in a demo request, including name, work email, company, and any optional message details. We do not collect passwords or account credentials.
- What We DO NOT Collect: No phone numbers, no personal home addresses, no payment card details on this site, and no invasive behavioral profiling trackers.
2. Zero Third-Party Advertising Trackers
This website does not load Google Analytics, Meta Pixels, LinkedIn Insight tags, or any third-party ad-network tracking scripts.
Anonymized Telemetry: To understand basic site usage (such as how many visitors click “Explore Invoice AI”), we record anonymous event counts. These events are hashed using a daily-rotating SHA-256 cryptographic salt. They do not store your IP address, browser fingerprint, or permanent device identifier.
3. Encryption & Database Security
- In Transit: All HTTP traffic is enforced over TLS 1.3 encryption.
- At Rest: Databases and server stores are encrypted at rest with industry-standard AES-256 encryption.
- Row Level Security (RLS): Our database utilizes PostgreSQL Row Level Security policies ensuring authenticated users can only query rows associated with their verified account.
- Session Security: Authentication tokens are stored in secure, HttpOnly, SameSite cookies to protect against Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF).
4. Two-Factor Authentication (TOTP)
To safeguard administrative workflows, access to the management console strictly mandates Time-based One-Time Passcode (TOTP) 2FA verification in conjunction with Google OAuth and a server-side allowlist. Standard users may also opt-in to 2FA for enhanced account defense.
5. 24-Month Retention & Automatic Purge Policy
We do not keep data indefinitely. Completed demo inquiries and anonymous telemetry logs are retained for a maximum window of 24 months, after which they are systematically purged via automated database retention procedures.
6. No Sale or Commercial Sharing of Data
We never sell, rent, monetize, or disclose your contact information or inquiries to third parties, data brokers, or marketing syndicates. Data is processed exclusively by our infrastructure and trusted email delivery provider (Resend) solely to fulfill your requested communications.
Contact & Privacy Inquiries
If you have any questions regarding this policy or wish to request the deletion of your submitted demo request record, contact us directly at:
privacy@vasishtha.ai