Privacy Policy
Last updated 10 August 2026
This Privacy Policy explains what personal data CaivaOS collects, why, and what rights you have over it. It applies to everyone who uses CaivaOS — a company's own internal team, and every vendor a company invites into its portal.
This is a draft prepared for CaivaOS's own review, not a substitute for advice from a qualified lawyer — it should be reviewed by counsel, in particular against India's Digital Personal Data Protection Act, before being relied on as final.
1. What we collect
Account data — name, email address, phone number, and job title, collected when you sign up, get invited, or update your profile. If you sign in with Google, we receive the name, email and profile photo Google shares for that purpose.
Business data — everything a company or its vendors enter into CaivaOS to run their business: leads, pipeline activity, product catalogues, pricing, orders, invoices, payments, support tickets, and similar records. This is the core of what the platform stores, and it's covered separately in §4 below because how it's isolated matters more than a typical "usage data" description would suggest.
Usage data — basic technical data (IP address, browser type, pages visited, timestamps) collected automatically to keep the platform secure and to understand how it's used, in the same way most web applications do.
Payment data — for paid subscriptions, billing details are handled by Razorpay directly; CaivaOS does not store full card numbers.
2. How we use it
- to provide and operate the platform — authenticate you, apply your permissions, render your data;
- to send account-related email — invitations, password resets, notifications you've opted into;
- to process payments for paid subscriptions;
- to maintain security — detect abuse, investigate incidents, keep the audit log accurate;
- to improve the platform — understood in aggregate, not by reading into any one company's business data.
We do not sell personal data, and we do not use a company's business data to train models or to benefit any other customer.
3. Where data is stored
Data is stored with Supabase (database, authentication, file storage) and served via Vercel. We chose providers with strong security practices; neither has independent access to use your data beyond providing the infrastructure we run on top of.
4. How isolation actually works
CaivaOS is multi-tenant: many companies, and many vendors within each company, share the same underlying database. Isolation between them is enforced at the database level through row-level security — every query is scoped to the company or vendor making it, not just hidden by the interface. A vendor's portal can only ever read that vendor's own rows; one company's internal team can never read another company's data, regardless of how the request is made. This isn't a policy promise layered on top of the product — it's how the schema itself is built.
5. Who we share data with
We share personal data only where necessary to operate the platform:
- Supabase — database, authentication and file storage infrastructure;
- Vercel — application hosting;
- Resend — transactional email delivery (invitations, notifications);
- Razorpay — payment processing for paid subscriptions;
- Google — only if you choose to sign in with Google.
We do not share data with any other third party for their own marketing purposes, and we do not sell personal data.
6. How long we keep it
We retain account and business data for as long as the workspace it belongs to remains active. If a workspace is deleted, data is retained for a limited period to allow recovery, then permanently deleted, except where we're required to keep records longer for legal or tax purposes (for example, billing records under Indian tax law).
7. Your rights
Depending on your role, you can access, correct, export, or request deletion of your personal data. For data you've entered as part of a company's workspace, requests are generally handled by that company's administrators, since they control the workspace — CaivaOS will support either you or the company in fulfilling a legitimate request. You can reach us directly at the contact below for any request we can act on ourselves.
8. Cookies
CaivaOS uses essential cookies to keep you signed in and to remember preferences like light/dark mode. We don't use third-party advertising or tracking cookies.
9. Children's privacy
CaivaOS is a business tool, not directed at children, and we don't knowingly collect data from anyone under 18.
10. Changes to this policy
We may update this policy as the platform changes. For material changes, we'll provide notice before they take effect.
11. Contact
Questions about this policy, or a request regarding your personal data, can be sent to hello@os.caiva.in or +91 84870 21720.

