Privacy Policy

Last updated: June 2026

1. Who we are and what this covers

Redsage ("we", "us") provides project tracking, timesheet and performance management software. This policy explains what personal data we collect, why, and the rights you have over it. For your own account data we act as the data controller. For content your organization stores in Redsage (projects, tasks, timesheets, messages, files) we act as a data processor on behalf of your organization, which remains the controller of that content.

2. Data we collect

  • Account data: name, work email, designation, profile photo, organization name, role.
  • Workspace content: projects, tasks, timesheet entries (including hours, categories, modules and descriptions), milestones, huddle messages, comments, file attachments, kudos and performance signals.
  • Security and usage logs: sign-ins and sign-outs, actions you take (audit trail), and IP-derived identifiers used solely for brute-force protection.
  • Billing data: plan, seat count and payment history. Card and bank details are handled entirely by our payment processor (Razorpay) - we never see or store them.

We do not use advertising trackers, we do not sell personal data, and we do not profile you for marketing.

3. Why we process it (legal bases)

  • Contract: providing the service you signed up for (accounts, projects, timesheets, reports).
  • Legitimate interest: securing the platform (audit logs, lockouts, CSRF protection) and improving reliability.
  • Consent: recorded when you accept these terms at sign-up (we store the timestamp). You can withdraw by deleting your account.
  • Legal obligation: retaining billing and audit records where the law requires it.

4. Your rights (GDPR · CCPA · India DPDP)

Wherever you are, we give every user the same self-service rights:

  • Access & portability: download a machine-readable JSON copy of your personal data anytime from Profile → Privacy & Data → Export My Data.
  • Rectification: edit your name, designation, photo and password from your profile.
  • Erasure: use Profile → Privacy & Data → Delete my account. Your name, email and photo are anonymized everywhere ("Deleted User") and your account is deactivated. Your organization's business records (logged hours, tasks) are retained in anonymized form, as permitted for legitimate business and legal purposes.
  • Complaints: contact our privacy & grievance officer at privacy@redsage.io. We respond within 30 days (GDPR), 45 days (CCPA), and as required by the DPDP Act and its rules. You may also complain to your local supervisory authority or the Data Protection Board of India.

5. Retention

  • By creating an account you consent to Redsage retaining and processing your organization's data as described here.
  • Account and workspace data: retained by Redsage for the life of your organization's account.
  • Deleted items: moved to your organization's Recycle Bin, where admins can restore them or purge them from the organization's view. Purged records remain in Redsage's encrypted storage as legal proof.
  • Security and audit logs: retained indefinitely for security, compliance and dispute resolution.
  • Billing records: retained as required by tax and accounting law.

6. Security measures

  • Encryption in transit (TLS) for all traffic.
  • Passwords hashed with bcrypt - we can never read them. Minimum 8 characters with letters and numbers.
  • Strict per-organization tenant isolation on every query.
  • Role-based access control and least-privilege project permissions.
  • Brute-force lockout (5 failed attempts → 15-minute lock), CSRF protection and httpOnly session cookies.
  • A complete, tamper-evident audit trail of security-relevant actions.

7. Sub-processors

We share data only with the vendors needed to run the service, under data processing agreements:

  • Razorpay (India) - subscription payments.
  • SendGrid / Twilio (USA) - transactional email (invites, digests, reminders).
  • Cloud object storage - encrypted storage of file attachments and profile photos.
  • Cloud hosting provider - application and database infrastructure.

8. Breach notification

If a personal data breach occurs, we will notify the relevant supervisory authority (including the Data Protection Board of India where applicable) within 72 hours of becoming aware of it, and affected organizations without undue delay, including the nature of the breach and the measures taken.

9. Cookies

Redsage uses essential cookies only: an access token and refresh token to keep you signed in (httpOnly, secure) and a CSRF token to protect your session. We set no analytics, advertising or third-party cookies, so no cookie consent wall is required - just this notice.

10. Children

Redsage is a business tool and is not directed at children. We do not knowingly process data of anyone under 18.

11. Changes

When we materially change this policy we update the date shown at the top and notify org admins. Questions: privacy@redsage.io.