Introduction
At Alliostaar Techub LLP ("we", "us" or "our"), we believe privacy is a fundamental right — not a feature. This Privacy Policy explains how we collect, use, store, share and protect personal information when you interact with our website, products, mobile applications and services (collectively, the "Services").
We've written this policy to be readable. Each section starts with an icon and numbered title — if you only want the highlights, jump straight to the Privacy Summary at the end.
Information We Collect
The information we collect falls into ten clear categories:
Name, email address, phone number and any details you voluntarily share with us.
Company name, GST/VAT numbers, designation, industry and business address.
Mailing address, WhatsApp number, alternate phone numbers and preferred contact channel.
Username, hashed password, role, account preferences and profile details.
Project requirements, briefs, uploaded documents, attachments and project communications.
Billing name, address, invoice history. Card data is processed by PCI-compliant gateways — we never store it.
IP address, device type, browser, OS, time zone and approximate geolocation.
Pages viewed, features used, clicks, session duration and product interaction patterns.
Small files stored on your device used for sessions, preferences and analytics. See Cookies Policy.
Aggregated, anonymized metrics about how visitors interact with our site & products.
How We Collect Information
We collect information through ten primary channels — all of them transparent:
How We Use Information
We use the information we collect for these specific, limited purposes:
- Providing Services: Operating our website, delivering products and executing projects you've engaged us for.
- Customer Support: Responding to inquiries, resolving issues and providing technical assistance.
- Software Improvement: Analyzing usage patterns to fix bugs, improve performance and ship better features.
- Communication: Sending updates, notifications and important service-related messages.
- Project Management: Coordinating deliverables, milestones, approvals and timelines.
- Marketing (with consent): Sharing relevant content, product updates and offers — only when you opt in.
- Security: Detecting fraud, preventing abuse and protecting accounts.
- Billing & Invoicing: Processing payments and maintaining financial records.
- Legal Compliance: Meeting tax, accounting and regulatory obligations.
Cookies Policy
Cookies are small text files stored on your device that help our website remember your preferences and behavior. We use four categories of cookies:
Necessary
Essential for the website to function — sessions, security, load balancing. Cannot be disabled.
Analytics
Help us understand how visitors use our website — pages, sessions, performance.
Preferences
Remember your language, theme, region and customization choices.
Marketing
Used to measure ad effectiveness and (with your consent) display relevant offers.
You can manage cookies via your browser settings or by clicking the "Cookie Preferences" link in our footer. Blocking necessary cookies may break certain features.
Data Sharing
We share data only with the following categories of service providers — strictly to deliver our Services:
- Hosting Providers: AWS, Azure, GCP, DigitalOcean for application hosting and storage.
- Cloud Providers: For email, file storage, monitoring and CDN delivery.
- Payment Gateways: Razorpay, Stripe, PayPal, Cashfree — to process payments securely.
- Email Services: SendGrid, Amazon SES, Mailgun for transactional and marketing email.
- SMS / WhatsApp: MSG91, Twilio, WhatsApp Business API for authentication and notifications.
- Legal Authorities: When required by valid legal process (subpoena, court order).
- Professional Partners: Auditors, lawyers and accountants under strict confidentiality.
- Business Transfers: In the rare event of merger or acquisition, with continued protection of your data.
All third-party processors operate under signed data processing agreements (DPAs).
Data Security
We protect your information using industry-standard practices, layered across eight controls:
Encryption
Data encrypted in transit with TLS 1.2+ and at rest with AES-256.
Secure Servers
Hosted on ISO-certified, SOC 2 compliant cloud infrastructure.
Firewalls & WAF
Network firewalls and Web Application Firewall protect every endpoint.
Backups
Daily automated backups with point-in-time recovery, retained for 30 days.
Access Control
Role-based access, least-privilege principles and quarterly access reviews.
Monitoring
24×7 logging, anomaly detection and incident-response procedures.
Authentication
Multi-factor authentication for all administrative access.
Confidentiality
All employees sign NDAs and complete annual security training.
Data Retention
We retain data only as long as needed for the purpose it was collected, or as required by law:
- Account Data: Retained while your account is active, deleted within 90 days of closure.
- Project Data: Retained for 3 years after project completion for warranty & legal records.
- Invoices & Financial Records: Retained for 7 years as required by Indian tax laws.
- Support Tickets: Retained for 2 years for service quality and improvement.
- Career Applications: Retained for 12 months for future opportunities (unless you request earlier deletion).
- Partner Data: Retained for the duration of the partnership plus 3 years.
- Newsletter Subscribers: Retained until you unsubscribe.
- Backups: Routine backups are retained for 30 days and then permanently deleted.
After the retention period, data is securely deleted or fully anonymized.
Your Rights
You have meaningful rights over the personal information we hold about you:
- Right to Access: Request a copy of the personal data we hold about you.
- Right to Correction: Ask us to fix inaccurate or incomplete information.
- Right to Deletion ("Right to be Forgotten"): Request that we delete your personal data, subject to legal retention obligations.
- Right to Restriction: Limit the ways we process your data while a question is being resolved.
- Right to Object: Object to processing for direct marketing or other legitimate-interest based processing.
- Right to Data Portability: Receive your data in a machine-readable format you can take elsewhere.
- Right to Withdraw Consent: Withdraw any consent you previously gave, at any time.
- Right to Account Closure: Close your account and request deletion of all associated personal data.
Children's Privacy
Our Services are designed for businesses and adults aged 18 or older. We do not knowingly collect personal information from children under 18.
Our School ERP and College ERP products may process student information as part of our customers' operations. In such cases, the educational institution acts as the Data Controller and Alliostaar as a Data Processor — student data is handled strictly per the institution's contractual instructions and applicable child-data protection laws.
If we become aware that we have inadvertently collected personal information from a child under 18 without verifiable parental consent, we will delete it promptly. Parents or guardians can contact us at privacy@alliostaar.com.
International Data Transfers
We primarily store data in India. As our international client base grows, data may occasionally be transferred to and processed in other countries (United States, European Union, United Kingdom, UAE, Singapore, etc.).
When transferring data internationally, we use the following safeguards:
- Standard Contractual Clauses (SCCs) approved by the European Commission.
- Adequacy decisions where applicable.
- Service providers with binding corporate rules.
- Encryption in transit and at rest, regardless of destination.
You can request information on the specific safeguards applied to your data by contacting our Privacy Officer.
Third-Party Services
Our website and Services integrate with reputable third-party providers, each governed by their own privacy policies:
We carefully select providers with strong privacy practices, but their handling of data is governed by their own policies. We encourage you to review them.
Software & Mobile Applications
This policy applies across every channel through which we deliver software:
- Web Applications — Our SaaS products, customer dashboards and portals.
- Android Apps — Native and Flutter apps published via Google Play.
- iOS Apps — Native and cross-platform apps via the Apple App Store.
- Cloud Software — Hosted ERP, CRM, HRMS and other SaaS platforms.
- APIs — Programmatic access for integrations and partner platforms.
Mobile apps may request device permissions (camera, location, notifications) only when needed for a specific feature. You can grant or deny each permission via your device settings. We do not access these permissions in the background.
For embedded customer products (where Alliostaar acts as a Data Processor), detailed Data Processing Agreements supplement this Privacy Policy.
Partner & Career Applications
Career applicants — The information you submit during the recruitment process (résumé, portfolio, references) is used solely to evaluate your application:
- Shared internally only with the hiring panel and HR team.
- Stored for up to 12 months to consider you for future opportunities (deletion-on-request honoured).
- Background verification (where applicable) is performed only with your written consent.
Partner registrations — Partner data (KYC, business details, bank information) is used to:
- Verify partner eligibility and onboard you onto the program.
- Track referrals, deals and commissions through the partner portal.
- Process commission payouts and generate tax invoices.
- Comply with Know-Your-Customer and anti-money-laundering regulations.
All partner and career data is treated with the same level of confidentiality as Client data.
Policy Updates
We may update this Privacy Policy to reflect changes to our practices, our Services or applicable laws. When we do, we'll:
- Update the "Last Updated" date at the top of this page.
- Bump the version number for material changes.
- Notify registered users by email at least 30 days before changes take effect (for material updates).
- Display a notice on our website for significant updates.
Version History (placeholder for dynamic rendering):
- v2.0 — June 1, 2026 — Added child-data section, updated cookies categories, refined data-retention windows.
- v1.5 — January 15, 2026 — Added international transfer safeguards.
- v1.0 — March 10, 2024 — Initial policy publication.
Contact Our Privacy Officer
For any privacy-related questions, requests, or to exercise your rights, our Privacy Officer is just an email away:
Company
Alliostaar Techub LLP
Attn: Privacy Officer
5th Floor, Tech Park One,
Pune, Maharashtra — 411014, India
Privacy Email
Phone
+91 00000 00000
Mon–Fri · 10:00 AM – 5:00 PM IST
Response Time
We acknowledge privacy requests within 5 business days and resolve them within 30 days.
Privacy Summary
If you only read one section — read this. The TL;DR of our entire policy in five cards:
Your Data
We collect only what we need — name, contact, billing and project details — to deliver our services to you.
Your Control
Update preferences, opt out of marketing or delete your account whenever you choose. No friction.
Your Rights
Access, correct, export or delete your data. Withdraw consent at any time — a single email is enough.
Our Security
Encryption end-to-end, role-based access, daily backups, 24×7 monitoring and annual security audits.
Transparency
No selling of data. Ever. Clear list of subprocessors. Plain-English updates whenever this policy changes.
By using Alliostaar's website, products or services, you acknowledge that you've read this Privacy Policy and understand how we handle your information.