Privacy Policy

Effective date: September 16, 2026

This is a working draft prepared for the product's current stage and has not yet been reviewed by legal counsel. Placeholder values in brackets (such as the legal entity name and support contact) must be filled in before this page is treated as final.

1. Who this policy covers

This policy describes how Business Software (“we,” “us”) handles information when you use the product as a signed-in user of an organization (“workspace”), or as a Client Portal user invited by an organization. Blue Rabbit is a multi-tenant business management application — each workspace's data is kept isolated from every other workspace.

2. Information we collect

We collect the following categories of information:

  • Account information: your name and email address when you sign up or are invited to a workspace, and your authentication credentials (handled by our authentication provider, Supabase — we do not store raw passwords ourselves).
  • Workspace and business information: organization details you or your workspace enters, such as business profile fields, tax identifiers (e.g. GSTIN/PAN where applicable), and module configuration.
  • Operational data your workspace creates: CRM records, leads, contacts, companies, sales/proposal records, projects, tasks, invoices, expenses, reminders, and Client Portal data. This data belongs to the organization that created it, not to us.
  • Usage and log data: basic technical information (such as session and error logs) generated as part of operating the application.

3. How we use information

We use the information above to:

  • Provide, operate, and maintain the product for your workspace.
  • Authenticate users and enforce organization-level data isolation.
  • Communicate with you about your account or workspace (e.g. invitations, notifications you've enabled).
  • Diagnose and fix technical issues.

We do not sell your information. We do not currently collect or process payment information, because paid billing has not been activated on the product.

4. Cookies and similar technology

We use strictly necessary cookies to keep you signed in and to maintain your session (via Supabase authentication). We do not currently use advertising or cross-site tracking cookies.

5. Service providers

We use Supabase for authentication, database, and hosting infrastructure. Data you or your workspace enters is stored in that infrastructure. We do not currently use a separate payment processor, since paid billing is not active.

6. Data retention

We retain workspace data for as long as the workspace/account remains active. Specific retention periods for inactive or deleted accounts have not yet been finalized — [retention schedule to be defined by owner/legal review].

7. Your rights and choices

You can review and update most account and workspace information directly within the product. For requests we don't yet support in-product (such as data export or account deletion), contact us using the details below.

8. Children's privacy

Business Software is a business tool and is not directed at, or knowingly used by, children.

9. Changes to this policy

We may update this policy as the product evolves. We'll update the effective date above when we do.

10. Contact us

Questions about this policy can be sent to [support email — to be added] from [legal entity name — to be added].