Privacy Policy
Last updated: March 6, 2026
1. Introduction
SankalpHub ("we", "us", or "our") operates the website sankalphub.in and the SankalpHub QC automation platform (collectively, the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website and use our Service.
By accessing or using the Service, you agree to this Privacy Policy. If you do not agree with the terms of this policy, please do not access the Service.
2. Information We Collect
2.1 Account Information
When you register for an account, we collect:
- Full name
- Email address
- Company/Organization name
- Password (encrypted)
- Role within your organization
2.2 Business Data
Through your use of the Service, we process:
- Inspection reports and quality control data
- Factory and supplier information
- Order and production tracking data
- Lab testing results
- Defect analytics and quality metrics
2.3 Usage Data
When you access our website (with your consent), we may collect:
- Pages visited and navigation paths
- Click interactions
- Search queries within the Service
- Session duration and frequency of visits
- Referring website or source
2.4 Device Information
We may automatically collect:
- Browser type and version
- Operating system
- Screen resolution
- Language preferences
- Approximate geographic location (country/city level, derived from IP address)
Note: We do not store raw IP addresses. IP addresses are used only transiently for geographic lookup and are then discarded or hashed.
3. How We Use Your Information
We use the information we collect for the following purposes:
- Service delivery: To provide, operate, and maintain the QC automation platform
- Account management: To manage your account, process authentication, and handle billing
- Improvement: To understand how our Service is used and improve user experience
- Analytics: To generate aggregate, anonymized analytics about website usage
- Communication: To send you important updates, security alerts, and support messages
- Security: To detect, prevent, and address technical issues and security threats
4. Cookies and Tracking Technologies
We use cookies and similar technologies to enhance your experience. You can manage your cookie preferences at any time through our cookie consent banner or by visiting our Cookie Policy.
We categorize cookies as follows:
- Essential Cookies: Required for authentication, security, and basic functionality. These cannot be disabled.
- Analytics Cookies: Help us understand website usage patterns. Enabled only with your explicit consent.
- Marketing Cookies: Used for personalized content and campaign measurement. Enabled only with your explicit consent.
5. Data Sharing and Third Parties
We do not sell your personal data. We may share data with:
- Razorpay: For processing payments securely. Razorpay's privacy policy governs their handling of payment data.
- WhatsApp/Communication tools: When you choose to contact us via WhatsApp or other messaging platforms.
- Legal requirements: When required by law, regulation, or legal process.
All third-party service providers are contractually obligated to protect your data and use it only for the purposes we specify.
6. Data Security
We implement appropriate technical and organizational measures to protect your data:
- All data transmitted over HTTPS (TLS encryption)
- JWT-based authentication with automatic token refresh
- Passwords are hashed and never stored in plaintext
- IP addresses are hashed (SHA-256) for privacy
- Regular security reviews and updates
7. Data Retention
- Account data: Retained for as long as your account is active. Deleted upon account deletion request.
- Business data: Retained while your subscription is active. Available for export before deletion.
- Analytics data: Anonymized visitor tracking data is retained for up to 12 months, then automatically deleted.
- Cookie consent records: Retained for the duration of the consent period or until you change your preferences.
8. Your Rights
Under applicable data protection laws, including the EU General Data Protection Regulation (GDPR) and the Indian Digital Personal Data Protection Act, 2023 (DPDP Act), you have the following rights:
- Right to Access: Request a copy of the personal data we hold about you.
- Right to Rectification: Request correction of inaccurate data.
- Right to Erasure: Request deletion of your personal data.
- Right to Portability: Request your data in a structured, machine-readable format.
- Right to Withdraw Consent: Withdraw your consent for analytics/marketing cookies at any time.
- Right to Grievance Redressal: Under the DPDP Act, you may raise concerns with our Data Protection Officer.
To exercise any of these rights, please contact us at the email address provided below.
9. Children's Privacy
Our Service is not directed to individuals under the age of 18. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child, we will take steps to delete it promptly.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by posting the new policy on this page and updating the "Last updated" date. For material changes, we may also notify you via email.
11. Contact Us
If you have questions about this Privacy Policy or wish to exercise your data rights, contact us: