
Privacy policy
Draft prepared for PineMetric's first customers. Have it reviewed by a lawyer before taking payments.
1. Who we are
PineMetric is an invoice validation, duplicate detection and collaboration service at app.pinemetric.com. It is operated by Antara Kar, an individual based in West Bengal, India ("PineMetric", "we", "us"). A postal address for legal notices is provided on request to [email protected].
Questions, requests and complaints about personal data go to [email protected]. That address reaches our grievance officer, Antara Kar, who replies within 30 days.
2. Two roles
For your account — your name, email address, sign-in history and settings — we decide how the data is used. Under India's Digital Personal Data Protection Act, 2023 we are the Data Fiduciary; under the EU and UK GDPR, the controller.
For what your organisation puts into PineMetric — invoices, files, messages, planner cards — your organisation decides. We process it only on its instructions, as its Data Processor (or processor under the GDPR), under our Data Processing Agreement. If you have a question about that data, ask your organisation first; we will help it answer.
3. What we collect
| Data | Why | Legal basis |
|---|---|---|
| Name, work email, role, organisation and region | To create your account and show you what your role allows | Contract; legitimate use for your employer's service (DPDP s.7) |
| Password (stored only as a one-way hash) | To sign you in | Contract |
| If you sign in with Google, Microsoft or your organisation's identity provider: that provider's identifier for you, and the name and email it shares | To sign you in without a password | Contract |
| For an organisation that pays for itself: its plan, subscription status and the brand and last four digits of the card (never the full number, which only our payment provider sees) | To run the subscription and show it to the organisation's administrators | Contract |
| Sign-in records: time, IP address, browser, device sessions, failed attempts | Security: locking out guessing, showing you your active sessions, investigating abuse | Legitimate interest in keeping the service secure |
| Activity in the audit log (who changed what, and when) | So your organisation can see who did what | Contract, on your organisation's instructions |
| Presence (online, idle, last seen) | To show colleagues whether you are available | Contract |
| Content your organisation uploads or writes | To provide the service | Processed for your organisation (section 2) |
| Error reports (no email addresses, passwords, cookies or request bodies) | To find and fix faults | Legitimate interest |
We do not sell personal data, show advertising, or use your organisation's content to train AI models.
4. Cookies
PineMetric sets two cookies, both strictly necessary, so no consent banner is needed: pine_rt keeps you signed in (secure, HTTP-only, expires after 14 days), and pine_oidc exists only for the few minutes of a Google, Microsoft or company sign-in, to make sure it finishes in the browser that started it. Your theme and layout choices are kept in your browser's local storage. There are no analytics or advertising cookies.
5. Who else handles data
We use a small number of service providers ("sub-processors"). Each is bound by a contract that protects the data.
| Provider | What for | Where |
|---|---|---|
| Hetzner Online GmbH | The servers PineMetric runs on, and its database and files | Germany (European Union) |
| Cloudflare (R2) | Encrypted backups — Cloudflare cannot read them | Asia-Pacific (Cloudflare R2) |
| Resend | Sending invitations and password-reset emails | Japan (Tokyo region); Resend is a US company |
| Sentry | Error reports, without email addresses or content | European Union (Germany) |
| Paddle.com Market Ltd | Our reseller and merchant of record for paid plans: takes payment and handles tax and invoices. Card details go to Paddle directly, never to PineMetric | United Kingdom, with processing in the EU and US |
| Anthropic | AI features, only when your organisation turns them on: the parts of a file or record needed for the feature are sent and are not used to train models | United States |
Voice and video calls run on our own servers; calls are not recorded. GIF searches in chat are sent to GIPHY from our servers without anything that identifies you. If you choose to sign in with Google or Microsoft, that company confirms who you are to us under its own privacy policy; we receive only your identifier, name and email. The sign-up form may use Cloudflare Turnstile to tell people from bots. When a new password is set, the first five characters of its SHA-1 hash — never the password — are checked against the Have I Been Pwned breach list.
We will list any new sub-processor on this page at least 30 days before it starts handling data.
6. Transfers outside India
Some providers above are in the United States. Where the GDPR applies we rely on the European Commission's Standard Contractual Clauses (and the UK addendum). We will not transfer personal data to any country the Government of India restricts under section 16 of the DPDP Act.
7. How long we keep data
- Your account: while it exists. When your organisation asks us to delete it, or closes its PineMetric account, your details are deleted or anonymised within 30 days, except the audit-log entries your organisation keeps as its record.
- Your organisation's content: as your organisation decides; when it closes its account, deleted within 30 days (section 9 of the DPA).
- Backups: encrypted copies are kept for up to 14 days (daily) and 190 days (monthly), then deleted. Something deleted from PineMetric disappears from backups on that cycle.
- Server logs (which include IP addresses) are rotated automatically and normally overwritten within a few weeks. The sign-in history shown on your profile is kept while your account exists.
8. How we protect it
Encryption in transit (HTTPS with HSTS) and for every backup; each organisation's data kept apart by the database itself (row-level security), not only by application code; passwords hashed with Argon2; short-lived sign-in tokens; rate limits and lockouts against guessing; least-privilege access for our own staff. If a breach affects your personal data we will tell you, the Data Protection Board of India and, where the GDPR applies, the relevant authority, as the law requires.
9. Your rights
You can ask to see, correct, complete or delete your personal data, to have a summary of how it is processed, to withdraw consent where we rely on it, and to nominate someone to act for you if you die or become unable to. Under the GDPR you can also object, restrict processing, and take your data elsewhere. Write to [email protected]. If you are not satisfied with our answer you can complain to the Data Protection Board of India or, in the EU and UK, your local data protection authority.
You can change your name and password, sign out other devices and delete your account yourself, under Account. Deleting your account removes your name and email at once; work you did stays with your organisation, credited to "Deleted user".
10. Children
PineMetric is a business service and is not meant for anyone under 18. We do not knowingly process children's data.
11. Changes
We will post changes here and, for significant ones, tell account holders by email at least 30 days before they take effect.