StucareClient OS

Privacy Policy

Stucare Innovation and Creation Private Limited · Last updated 21 September 2026

This policy explains what information Stucare Client OS handles, why, who it is shared with, and how it can be corrected or deleted. It applies to the Stucare Client OS platform and the services provided with it.

1. Introduction

Stucare Innovation and Creation Private Limited (“Stucare”, “we”, “us”) operates Stucare Client OS, an operations platform used by businesses to run their day-to-day work.

The platform helps a business manage its clients, projects, billing, documents, employees, communication, payments and related operations in one place.

Two different relationships. Some information is about the business that subscribes to Stucare Client OS and the colleagues who sign in to it — here we decide how that information is handled. Most information in the platform is about that business’s own clients, staff and records, which it puts in and controls — there we handle it on that business’s instructions. Where the two differ, this policy says so.

2. Information We Collect

A. Account information

  • Name
  • Email address
  • Phone number
  • Sign-in and account information, including authentication and two-factor settings
  • Company and organisation details, and the role a person holds

B. Business and customer information

Entered by the business using the platform, about its own clients:

  • Client and contact names
  • Contact details, including email addresses and phone or WhatsApp numbers
  • Business details and addresses
  • GSTIN, PAN and similar tax identifiers
  • Contract, project and assignment information
  • Interaction and communication history

C. Billing and financial information

  • Quotations, invoices, bills and credit notes
  • Payment receipts and payment records
  • Outstanding balances, ageing and account statements
  • Payment reminders and the record of when they were sent
  • Bank and payment details entered by the business or its customers

D. Documents

  • Generated documents such as invoices, quotations, receipts, contracts and letters
  • Files uploaded by users, including supporting business documents
  • Document versions, and the record of who accessed or shared each one

E. Employee and HR information

Where a business uses the HR features, the platform can store information about that business’s own employees, which may include:

  • Employee profiles and employment details
  • Attendance and leave records
  • Payroll information and payslips
  • PAN, Aadhaar, UAN, ESIC, passport and bank-related details
  • Employment letters and onboarding documents
This is sensitive information, and the business decides to put it there. A business using Stucare Client OS is responsible for having the legal basis, permission and authority to provide such information about its employees, and for telling those employees how it is used. Stucare does not obtain that permission on a business’s behalf.

F. Communication information

  • Messages and notifications sent within the platform
  • Email sent through the platform, and whether it was accepted for delivery
  • WhatsApp message records where the WhatsApp integration is used — see section 4
  • Communication history recorded against a client or contact

G. Technical information

Collected automatically as part of operating and securing the service:

  • IP address
  • Browser and device information sent by your browser
  • Application and security logs, including sign-in attempts and permission checks
  • Timestamps and request identifiers
  • Audit records of actions taken in the platform, including who took them and when

We do not use advertising trackers, analytics pixels or third-party behavioural tracking on the platform. See section 13.

3. How We Use Information

  • Providing and operating the platform, and managing accounts and access
  • Client and relationship management, project management and scheduling
  • Producing quotations, invoices, bills, receipts and account statements
  • Sending payment reminders and other business communications a user asks to send
  • Storing, generating and sharing documents
  • Employee and HR management features, where a business uses them
  • Communication and notifications, including WhatsApp messaging where enabled
  • Security: authentication, access control, rate limiting and detecting abuse
  • Keeping audit records of actions taken in the platform
  • Troubleshooting, support and maintaining reliability
  • Improving the service, and meeting legal, tax and accounting obligations

4. WhatsApp Integration

Stucare Client OS can integrate with Meta’s WhatsApp Business Platform (WhatsApp Cloud API) so that authorised users of a business can send business communications through that business’s own connected WhatsApp Business account. The platform also supports sending a document through the sender’s own WhatsApp application on their own device, which does not pass through our servers.

Where the integration is used, communications may include quotations, invoices, bills, payment receipts, payment reminders, overdue reminders, account statements, letters and other business notifications.

Depending on how the integration is configured, the information involved may include:

  • The recipient’s phone number
  • The content of the message sent
  • Any document or media attached to it
  • The message identifier returned by WhatsApp
  • Delivery, read and failure status reported back by WhatsApp
  • Timestamps and related WhatsApp identifiers

WhatsApp and Meta are separate from Stucare. When a message is sent through the WhatsApp Business Platform, Meta receives and processes it under its own terms and privacy policies. We do not control Meta’s processing of that information, and we cannot delete information held by Meta on your behalf.

Stucare is not Meta, is not affiliated with Meta, and does not claim to be an official Meta partner. We use Meta’s publicly available business platform in the same way any other business may.

A business using this integration is responsible for having the permissions and consents required to message its recipients, and for complying with Meta’s policies and applicable law. See section 5.

5. Business Customer Responsibility

Stucare Client OS is used by businesses to manage information about their own clients, employees and operations. Where we handle that information, we do so on that business’s instructions.

The business using the platform is responsible for:

  • Obtaining any permissions or consents required from its clients, contacts and employees
  • Ensuring it has a lawful basis for the information it puts into the platform
  • The accuracy of the information it enters
  • Complying with applicable privacy and data-protection law
  • Ensuring that communications, including WhatsApp messages, are only sent where they are lawful and permitted
  • Managing who in its organisation has access, using the roles and permissions the platform provides

If you are a client or an employee of a business that uses Stucare Client OS and you want to access, correct or delete information about you, the fastest route is usually to contact that business directly. You may also write to us at privacy@stucares.com and we will direct the request appropriately — see section 11.

7. Data Sharing

Information may be shared with:

  • Authorised users within the business customer’s own organisation, according to the roles and permissions that business sets
  • People a user deliberately sends a document or message to, such as a client receiving an invoice
  • Service providers that operate parts of the platform on our behalf
  • Meta, where the WhatsApp integration is used, as described in section 4
  • Professional advisers, where necessary and subject to confidentiality
  • Authorities or other parties where required by law, or to establish, exercise or defend legal claims

The service providers currently used to operate this deployment are:

  • Render — application hosting
  • Supabase — managed PostgreSQL database hosting
  • Cloudflare — R2 object storage for documents and files, and network services
  • Clerk — authentication and sign-in
  • ZeptoMail (Zoho) — outbound email delivery
  • Amazon Web Services — key management for encrypting stored secrets
  • Upstash — rate-limit counters
  • Sentry — application error monitoring
  • Meta Platforms — WhatsApp Business Platform, where that integration is enabled

We do not sell personal information, and we do not share it for advertising purposes.

8. Data Security

The platform includes the following controls:

  • Role-based permissions, with scopes that limit what each role can see
  • Separation of each organisation’s data, enforced at the database level
  • Audit logging of actions taken in the platform, recorded so that they cannot be edited afterwards
  • Access control on documents, with downloads recorded
  • Encryption of stored credentials and other sensitive stored secrets
  • Signed, expiring links for documents shared outside the platform, which can be revoked
  • Malware scanning of uploaded files before they can be downloaded
  • Two-factor authentication, and an additional challenge before certain sensitive actions
  • Rate limiting and flood protection
  • Encryption in transit using HTTPS
No system can guarantee absolute security. We use reasonable technical and organisational safeguards appropriate to the information involved, but we do not and cannot promise that the platform will never be compromised.

9. Document Security

Documents are stored in object storage rather than in the application database, and are reached only through the platform’s own access checks. Uploaded files are scanned before they can be downloaded, and document access is recorded.

When a user shares a document outside the platform — for example by sending an invoice to a client — the platform can create a link that expires after a period the business sets, can be revoked at any time, and records when it was opened. Private storage locations are never exposed directly.

10. Data Retention

Information is retained for as long as it is needed for the purposes described in this policy. How long that is depends on the information and the reason for holding it, including:

  • Providing the service while an account is active
  • Legal, tax and accounting obligations, which in India commonly require financial records to be kept for a number of years
  • Resolving disputes and establishing or defending legal claims
  • Security and audit purposes

We do not publish fixed retention periods for every category, because the applicable period depends on the record and on the law that applies to it. Where a deletion request is made, some information may need to be retained where we are required or permitted to keep it — see Data Deletion.

11. Data Deletion

Requests to delete eligible personal information can be made at any time. The process, what can be deleted, and what may need to be retained are set out on the User Data Deletion page:

https://stucare.solutions/data-deletion

Requests may also be sent directly to privacy@stucares.com with the subject Data Deletion Request.

12. Your Rights

Depending on where you are and which law applies, you may have the right to:

  • Ask what information about you is held, and obtain a copy of it
  • Ask for information that is inaccurate to be corrected
  • Ask for information to be deleted
  • Ask us to restrict or object to certain processing
  • Withdraw consent, where processing is based on consent
  • Complain to a supervisory authority, where one applies to you

Not every right applies in every jurisdiction or to every record, and some are subject to legal exceptions. Where information belongs to a business customer’s account, a request may need to be handled with that business — see section 5.

To exercise a right, write to privacy@stucares.com.

13. Cookies and Analytics

The platform uses cookies that are necessary for it to work: to keep you signed in, to maintain your session securely, and to remember basic preferences such as your chosen theme.

We do not use advertising cookies, analytics pixels or third-party behavioural tracking. There is no Google Analytics, no Meta Pixel and no similar tracking technology on the platform. Our authentication provider sets its own cookies as part of signing you in, and our error monitoring records technical diagnostics when something fails.

14. Children's Privacy

Stucare Client OS is a business tool intended for use by businesses and their staff. It is not directed at children, and we do not knowingly collect personal information directly from children. If you believe a child’s information has been provided to us, write to privacy@stucares.com and we will look into it.

15. Third-Party Services

The providers listed in section 7 process information under their own terms and privacy policies. Where the WhatsApp integration is used, Meta’s terms and privacy policy apply to what Meta receives. We are not responsible for how a third party processes information under its own policies, and deleting information from Stucare does not delete information a third party holds.

16. Security Incidents

We maintain logging, audit records and monitoring intended to help us identify and investigate security incidents. If we become aware of an incident affecting personal information we handle, we will investigate it, take steps we reasonably consider appropriate to contain and address it, and notify affected business customers and any authority where we are required to do so.

We do not commit to a fixed notification timeline here, because what is required depends on the incident and on the law that applies to it.

To report a suspected security issue, write to privacy@stucares.com.

17. Changes to This Policy

This policy may be updated from time to time. The current version is always published at this address, with the date it was last updated shown at the top. Where a change is significant, we will take reasonable steps to bring it to the attention of business customers.

18. Contact

Stucare Innovation and Creation Private Limited

Privacy and data protection: privacy@stucares.com
General enquiries: ceo@stucares.com
Website: https://stucare.solutions