Privacy Policy
Last updated: 8 July 2026
This Privacy Policy explains how Netssta ("we", "us", "our") collects, uses, stores, and shares information when you use CostLoom AI ("CostLoom", "the Service"). It applies to visitors, registered users, and organisations using the Service.
1. Information We Collect
Account & profile information
When you sign up, our authentication provider (Clerk) collects your name, email address, and login credentials. We store a corresponding user record linked to your organisation, including your role and team membership.
Organisation & billing information
Organisation admins may provide business details such as company name, GSTIN, billing state, and billing email, used to generate GST-compliant invoices. Subscription payments are processed by Razorpay; we receive confirmation of successful or failed charges and subscription status, but we do not receive or store your card, UPI, or bank account details — Razorpay handles and secures that information directly.
Customer content
Cost sheets, customer records, templates, quotations, and files you upload (including tech packs, images, and spreadsheets used for AI extraction) are stored so the Service can function. These may contain business data about your own customers, which you are responsible for having the right to process.
Usage & technical data
We automatically collect log data (IP address, browser type, timestamps, pages visited) and error/performance diagnostics via Sentry, used to keep the Service reliable and secure.
2. How We Use Information
- To provide, maintain, and improve the Service, including costing calculations, quotation generation, and AI tech-pack extraction;
- To process subscription payments and generate tax-compliant invoices;
- To send transactional emails — invoices, team invitations, password resets, and service notices — via Resend;
- To detect, investigate, and prevent fraud, abuse, and security incidents;
- To respond to support requests;
- To comply with legal and tax obligations, including GST record-keeping requirements under Indian law.
We do not sell your personal information to third parties.
3. Third-Party Service Providers
We share data with the following categories of processors, only as needed for them to perform their function on our behalf:
- Clerk — authentication and user identity management;
- Razorpay — payment processing and subscription billing;
- Amazon S3 — encrypted storage of uploaded files and generated documents;
- Resend — delivery of transactional emails, including invoices;
- Sentry — error monitoring and diagnostics;
- Upstash — rate-limiting infrastructure to protect the Service from abuse;
- Our AI provider — processes tech-pack uploads and text you submit for extraction and cost-optimisation features. Content sent for AI processing is used only to generate the requested output and is not used by us to train unrelated models.
These providers are contractually bound to protect your data and use it only for the purposes we specify. We may also disclose information if required by law, regulation, legal process, or governmental request.
4. Data Storage & Security
Data is stored on encrypted infrastructure with access restricted to authorised systems and personnel. We apply industry-standard security headers, transport encryption (HTTPS), and access controls across the Service. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
5. Data Retention
We retain account and organisation data for as long as your account is active, and for a reasonable period afterward to comply with tax, accounting, and legal obligations (GST invoices, in particular, are retained per statutory record-keeping requirements). You may request deletion of your account data as described in Section 7, subject to these retention obligations.
6. Cookies
We use essential cookies required for authentication and session management. We do not use third-party advertising or cross-site tracking cookies.
7. Your Rights
Subject to applicable law (including India's Digital Personal Data Protection Act, 2023), you may have the right to access, correct, or request deletion of your personal information, or to withdraw consent for optional processing. Organisation admins can update most information directly from account and organisation settings; for other requests, contact us using the details below.
8. Children's Privacy
The Service is intended for business use and is not directed at individuals under 18. We do not knowingly collect personal information from children.
9. International Data Transfer
Our infrastructure and service providers may process and store data outside India. Where this occurs, we rely on our providers' contractual and technical safeguards to protect your information consistent with this Policy.
10. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be notified by email or through the Service before they take effect.
11. Grievance Officer & Contact
For privacy questions, data requests, or grievances regarding the handling of your personal information, contact us at support@netssta.com. We aim to acknowledge grievances within the timelines required under applicable Indian data protection law.