PineMetric

Privacy policy

Effective 1 October 2026 · Version 1.0

Draft prepared for PineMetric's first customers. Have it reviewed by a lawyer before taking payments.

1. Who we are

PineMetric is an invoice validation, duplicate detection and collaboration service at app.pinemetric.com. It is operated by Antara Kar, an individual based in West Bengal, India ("PineMetric", "we", "us"). A postal address for legal notices is provided on request to [email protected].

Questions, requests and complaints about personal data go to [email protected]. That address reaches our grievance officer, Antara Kar, who replies within 30 days.

2. Two roles

For your account — your name, email address, sign-in history and settings — we decide how the data is used. Under India's Digital Personal Data Protection Act, 2023 we are the Data Fiduciary; under the EU and UK GDPR, the controller.

For what your organisation puts into PineMetric — invoices, files, messages, planner cards — your organisation decides. We process it only on its instructions, as its Data Processor (or processor under the GDPR), under our Data Processing Agreement. If you have a question about that data, ask your organisation first; we will help it answer.

3. What we collect

DataWhyLegal basis
Name, work email, role, organisation and regionTo create your account and show you what your role allowsContract; legitimate use for your employer's service (DPDP s.7)
Password (stored only as a one-way hash)To sign you inContract
If you sign in with Google, Microsoft or your organisation's identity provider: that provider's identifier for you, and the name and email it sharesTo sign you in without a passwordContract
For an organisation that pays for itself: its plan, subscription status and the brand and last four digits of the card (never the full number, which only our payment provider sees)To run the subscription and show it to the organisation's administratorsContract
Sign-in records: time, IP address, browser, device sessions, failed attemptsSecurity: locking out guessing, showing you your active sessions, investigating abuseLegitimate interest in keeping the service secure
Activity in the audit log (who changed what, and when)So your organisation can see who did whatContract, on your organisation's instructions
Presence (online, idle, last seen)To show colleagues whether you are availableContract
Content your organisation uploads or writesTo provide the serviceProcessed for your organisation (section 2)
Error reports (no email addresses, passwords, cookies or request bodies)To find and fix faultsLegitimate interest

We do not sell personal data, show advertising, or use your organisation's content to train AI models.

4. Cookies

PineMetric sets two cookies, both strictly necessary, so no consent banner is needed: pine_rt keeps you signed in (secure, HTTP-only, expires after 14 days), and pine_oidc exists only for the few minutes of a Google, Microsoft or company sign-in, to make sure it finishes in the browser that started it. Your theme and layout choices are kept in your browser's local storage. There are no analytics or advertising cookies.

5. Who else handles data

We use a small number of service providers ("sub-processors"). Each is bound by a contract that protects the data.

ProviderWhat forWhere
Hetzner Online GmbHThe servers PineMetric runs on, and its database and filesGermany (European Union)
Cloudflare (R2)Encrypted backups — Cloudflare cannot read themAsia-Pacific (Cloudflare R2)
ResendSending invitations and password-reset emailsJapan (Tokyo region); Resend is a US company
SentryError reports, without email addresses or contentEuropean Union (Germany)
Paddle.com Market LtdOur reseller and merchant of record for paid plans: takes payment and handles tax and invoices. Card details go to Paddle directly, never to PineMetricUnited Kingdom, with processing in the EU and US
AnthropicAI features, only when your organisation turns them on: the parts of a file or record needed for the feature are sent and are not used to train modelsUnited States

Voice and video calls run on our own servers; calls are not recorded. GIF searches in chat are sent to GIPHY from our servers without anything that identifies you. If you choose to sign in with Google or Microsoft, that company confirms who you are to us under its own privacy policy; we receive only your identifier, name and email. The sign-up form may use Cloudflare Turnstile to tell people from bots. When a new password is set, the first five characters of its SHA-1 hash — never the password — are checked against the Have I Been Pwned breach list.

We will list any new sub-processor on this page at least 30 days before it starts handling data.

6. Transfers outside India

Some providers above are in the United States. Where the GDPR applies we rely on the European Commission's Standard Contractual Clauses (and the UK addendum). We will not transfer personal data to any country the Government of India restricts under section 16 of the DPDP Act.

7. How long we keep data

8. How we protect it

Encryption in transit (HTTPS with HSTS) and for every backup; each organisation's data kept apart by the database itself (row-level security), not only by application code; passwords hashed with Argon2; short-lived sign-in tokens; rate limits and lockouts against guessing; least-privilege access for our own staff. If a breach affects your personal data we will tell you, the Data Protection Board of India and, where the GDPR applies, the relevant authority, as the law requires.

9. Your rights

You can ask to see, correct, complete or delete your personal data, to have a summary of how it is processed, to withdraw consent where we rely on it, and to nominate someone to act for you if you die or become unable to. Under the GDPR you can also object, restrict processing, and take your data elsewhere. Write to [email protected]. If you are not satisfied with our answer you can complain to the Data Protection Board of India or, in the EU and UK, your local data protection authority.

You can change your name and password, sign out other devices and delete your account yourself, under Account. Deleting your account removes your name and email at once; work you did stays with your organisation, credited to "Deleted user".

10. Children

PineMetric is a business service and is not meant for anyone under 18. We do not knowingly process children's data.

11. Changes

We will post changes here and, for significant ones, tell account holders by email at least 30 days before they take effect.