Privacy Policy
Last updated: June 6, 2026
If you visit our website, buy a license, or contact us for help, this page explains what information we collect, why we collect it, and what we do not do with it.
Who we are
This website and the related software products are operated by Sojatia Infocrafts Private Limited.
If you have a privacy question, or if you want to ask us to access, correct, or delete your information, you can reach us at [email protected].
For privacy-law purposes, we act as the data controller for the personal information described in this policy when we decide how and why that information is used.
What this policy covers
This policy applies to:
- people who visit our website
- people who contact us
- customers who buy a paid license
- users who receive a license after purchase
- customers who send us logs for support
It does not govern third-party services that operate on their own terms, such as your payment provider, your cloud provider, or any infrastructure you manage yourself.
The big point: this is self-hosted software
Our product is sold as self-hosted software, including software delivered as a Docker image.
That matters because it changes the privacy picture in an important way: we do not host your production data just because you use the product.
If you deploy the software in your own environment, your database, your uploaded files, your end-user data, and your runtime environment remain under your control. We do not automatically receive that information.
In normal use, the main information we receive is limited to:
- information you submit on our website
- purchase and license records
- basic site analytics
- support materials you choose to send us, such as logs
If you send us logs during support, those logs may contain technical details and, depending on how your environment is configured, may also contain limited personal or business information. We treat that material as support data, not as something we are trying to collect by default.
Information we collect
Information you give us directly
You may give us information when you:
- email us
- contact us through the website
- buy a paid license
- ask for support
- send logs or diagnostic information
That information may include:
- your name
- your email address
- your company name
- billing or transaction details
- the license or plan you purchased
- the contents of your message or support request
- logs and related troubleshooting information you choose to send
Purchase and license information
When you buy a paid license, we may collect and use the information needed to:
- confirm the order
- issue the correct license
- keep transaction records
- provide customer support
- prevent fraud or misuse
For paid licenses, we may also generate and store license records such as a unique license ID, license key, purchase reference, customer email, and an installation or device identifier, or a hash derived from it, to issue and validate the license for a specific installation and to help prevent misuse.
The free version of the product does not require an explicit paid license.
Payment information
Payments are processed through Razorpay.
We do not store full card details on our own systems. Razorpay handles payment information under its own terms, privacy practices, and security controls. We may receive limited transaction information from Razorpay, such as payment status, order reference, and the basic details needed to match a payment to a purchase.
To maintain accurate accounting, tax, fraud-prevention, and transaction records, invoice-related billing information may be restricted from ordinary self-service changes after an invoice has been generated or payment has been completed. If a correction is required, please contact us and we will review whether it can be handled under the applicable payment, tax, and recordkeeping rules.
Website analytics
We use basic analytics to understand how people use the website, for example which pages are visited and how visitors move through the site.
We do not use analytics to intentionally collect sensitive personal information, and we do not try to build an invasive profile of our visitors.
Depending on configuration, analytics data may include:
- approximate location inferred from IP
- browser and device information
- pages visited
- referring pages
- time spent on pages
- general traffic patterns
Logs and security information
Like most websites, we may create technical logs for security, reliability, and debugging purposes. These may include:
- IP address
- timestamps
- request details
- error details
- basic diagnostic metadata
If you send us support logs from your own deployment, we use them only to investigate the issue, provide support, and protect the security of the product and our systems.
AI-assisted features
Our product may include AI-assisted features that help generate or refine website pages, components, and related content.
If you use these features, we may process the prompts, instructions, text, configuration details, and related materials you submit in order to generate or improve the requested output. Depending on how the feature is configured, this processing may involve our systems and third-party AI service providers acting on our behalf.
Users should avoid submitting unnecessary sensitive personal information, secrets, credentials, or regulated data into AI-assisted features unless clearly required and appropriate for the intended use.
What we do not collect by default
Unless you deliberately send it to us, we do not collect or host your production application data merely because you run our software.
That means we do not automatically receive things like:
- your production database contents
- your user records
- your uploaded files
- your internal business data
- your customer activity inside your deployment
Why we process information
We use information for a small set of practical reasons:
- to run the website
- to respond to messages and inquiries
- to process purchases
- to issue and manage paid licenses
- to provide support
- to keep records of transactions and customer communications
- to improve site reliability and security
- to understand general site usage through basic analytics
- to comply with legal obligations
- to establish, exercise, or defend legal claims
Legal bases for processing
If GDPR, UK GDPR, or similar laws apply, our legal bases for processing may include:
- contract, where processing is necessary to sell software, issue a license, or provide requested support
- legitimate interests, where processing is necessary to secure the site, prevent fraud, maintain records, and respond to business inquiries in a proportionate way
- legal obligation, where we are required to keep or disclose information for tax, accounting, legal, or regulatory reasons
- consent, where consent is required by law for a particular activity
Cookies and similar technologies
Our website may use cookies or similar technologies for:
- essential site functionality
- security
- analytics
- remembering preferences where relevant
- maintaining the checkout session when a user decides to purchase and completes the checkout flow
In particular, we may use a session cookie during checkout so the purchase process works correctly from start to finish. That kind of cookie is generally used for functionality rather than advertising.
You can usually manage cookies through your browser settings. If your jurisdiction requires consent for non-essential cookies, those tools should only be used in line with the applicable legal requirements.
When we share information
We do not sell personal information in the ordinary sense of turning customer data into a product.
We may share limited information when it is reasonably necessary, including with:
- Razorpay, to process payments
- service providers that help us operate the website or support business operations
- professional advisers such as accountants, auditors, lawyers, or insurers
- authorities or counterparties where disclosure is required by law or necessary to protect rights, safety, or security
- a buyer, investor, or successor if the business is reorganized, merged, acquired, or sold
When we do share information, we try to keep it proportionate to the actual need.
International transfers
Depending on where you are located and where our service providers operate, your information may be processed outside your own country.
Where the law requires it, we will rely on appropriate legal safeguards for international data transfers.
How long we keep information
We keep personal information only for as long as there is a legitimate reason to do so, including for:
- customer relationship management
- license issuance and recordkeeping
- support and troubleshooting
- security and fraud prevention
- accounting and tax compliance
- legal claims and dispute handling
Support logs are not kept forever by default. When they are no longer reasonably needed, we may delete or anonymize them.
Security
We use reasonable technical and organizational measures to protect the information we hold. We also use HTTPS (TLS encryption) to help protect information transmitted through our website during checkout, account, and contact interactions.
At the same time, no system is perfect, and no method of transmission or storage can be guaranteed to be completely secure.
If you send us logs or support materials, please avoid including secrets, passwords, tokens, or highly sensitive data unless absolutely necessary.
For self-hosted deployments, you are responsible for the privacy and security of the environment where you run the software. That includes server security, access control, secrets management, network protection, backups, and the way you govern data in your own system.
Your privacy rights
Depending on where you live, you may have the right to:
- know what personal information we collect and how we use it
- request access to your information
- ask us to correct inaccurate information
- ask us to delete information
- object to or restrict certain processing
- receive portable copies of information where the law provides that right
- withdraw consent where processing depends on consent
- complain to a regulator or supervisory authority
To exercise any of these rights, email [email protected].
We may need to verify your identity before responding, and some rights are subject to legal exceptions.
Additional notice for EEA and UK users
If you are in the European Economic Area or the United Kingdom, you may have rights under GDPR or UK GDPR, including rights of access, correction, erasure, restriction, objection, portability, and the right to complain to your local data protection authority.
Additional notice for California residents
If California privacy law applies to you, you may have rights to:
- know the categories of personal information we collect
- know where that information comes from
- know why we collect it
- know the categories of third parties with whom it is shared
- request deletion of personal information, subject to exceptions
- request correction of inaccurate personal information
- receive equal treatment for exercising your privacy rights
Based on how we operate today, we do not sell personal information in the traditional sense, and we do not knowingly share personal information for cross-context behavioral advertising as described under California privacy law.
Children's privacy
Our website and products are not directed to children under 13, and we do not knowingly collect personal information from children under 13.
If you believe a child has provided personal information to us, contact us and we will review the issue and take appropriate action.
Changes to this policy
We may update this Privacy Policy from time to time to reflect legal, operational, or product changes.
If we do, we will update the date at the top of this page. If a change is material, we may also provide a more prominent notice where appropriate.
Contact
If you have questions about this Privacy Policy or want to exercise your privacy rights, contact:
Sojatia Infocrafts Private Limited
Email: [email protected]
