This policy explains what information LinenAudit (“we”, “us”) collects when you use the website at linenaudit.com and the LinenAudit service, why we collect it, who processes it for us, how long we keep it, and the choices and rights you have. It is written to meet India's Digital Personal Data Protection Act, 2023.
1. What we collect
- Account details: your name, work email, the name of your hotel or group, your role in the workspace, an optional profile photo, and your password (stored only as a salted scrypt hash we can't reverse).
- Documents and audit data: the contracts, invoices, delivery tickets, linen count sheets and occupancy reports you upload, the figures read from them, and the audits, findings and dispute letters you create. These may contain your vendors' and your business's details.
- Billing: your plan, number of properties and billing period, and Razorpay's identifiers for your subscription and payments. Card, UPI and bank details are entered on Razorpay's pages and are never seen or stored by us.
- Messages: what you send through Help & support or the contact form, with the name and email you give.
- Security records: encrypted two-factor secrets and hashed recovery codes if you turn two-factor authentication on, single-use links and codes (stored only as hashes), and short-lived counters keyed by IP address that limit repeated sign-in and form attempts.
- Usage statistics: pages viewed, the referring website, your country, and your type of device. We don't use cookies for this and don't store your IP address; a visitor is counted with an anonymous fingerprint that changes every day. If your browser sends Do Not Track or Global Privacy Control, no statistics are recorded. Our host, Vercel, also counts page views for us with Vercel Web Analytics, which likewise uses no cookies and keeps no IP addresses.
- Error reports: when something breaks, the page address, a technical description of the error and the time, so we can fix it.
2. Why we use it
- To provide the service: reading your documents, running audits, producing reports and emailing them for you.
- To run your account: sign-in, email verification, password resets, team invites and two-factor authentication.
- To take payment and manage your subscription.
- To answer your messages and send service emails (codes, links, receipts of actions you took).
- To keep the service secure, prevent abuse and fix problems.
- To understand, in aggregate, how the site is used so we can improve it.
We process your data because you asked us to provide the service and with your consent, which you give when you create an account or send us a message. We do not sell your data, use it for advertising, or use your documents to train any AI model.
3. Who processes it for us
| Service | What for | Where |
|---|---|---|
| Vercel | Hosting the website and app; anonymous page-view counts | Mumbai, India |
| Supabase | Database and file storage | Mumbai, India |
| Google (Gemini API) | Reading scans, photos and complex documents. PDFs with selectable text and CSVs are read on our own servers. | Google's data centres |
| Google (Gmail) | Sending service emails and delivering support messages | Google's data centres |
| Razorpay | Payments and subscriptions | India |
| Have I Been Pwned | Checking new passwords against known breaches. Only the first five characters of a one-way hash of the password are sent, never the password. | Global |
Your workspace's documents and audits are visible only to people in your workspace. We look at them only if you ask us to (for example, in a support request) or if the law requires it.
4. Cookies and local storage
We use only what is needed for the site to work, so there is nothing to opt in or out of:
- la_session: keeps you signed in (30 days). Secure, httpOnly, not readable by scripts.
- la_2fa: carries a password check to the two-factor code step (10 minutes). Only set if you use two-factor authentication.
- la-theme (local storage, not a cookie): remembers your light or dark choice on this device.
We don't use advertising, tracking or third-party analytics cookies.
5. How long we keep it
- Account, documents and audits: while your account is open. When you ask us to close it, we delete them within 30 days.
- Single-use links and codes: until used or expired (15 minutes to 7 days).
- Sign-in attempt counters: up to an hour.
- Support messages: up to two years, so we can follow up.
- Usage statistics and error reports: up to 13 months, then deleted.
- Payment records may be kept longer where tax or accounting law requires.
6. Your rights
You can:
- see and correct your name, photo and password on your profile at any time;
- ask for a copy of, or a summary of, the personal data we hold about you;
- ask us to correct, complete or delete it, or close your account;
- withdraw consent, which closes your account since the service can't run without it;
- nominate someone to exercise these rights for you;
- raise a grievance with us, and if unresolved, with the Data Protection Board of India.
Write to support.linenaudit@gmail.com from your account's email address. We reply within 7 working days and complete requests within 30 days.
7. Security
Data travels over HTTPS only. Passwords are hashed with scrypt, two-factor secrets are encrypted, and links and codes are stored only as hashes. The database is reachable only by our application's own restricted account. Sign-in, password reset and form submissions are rate-limited, and a strict Content Security Policy limits what can run in your browser. No system is perfectly secure; if we learn of a breach that affects you, we will tell you and the Data Protection Board as the law requires.
8. Children
LinenAudit is a business service and is not meant for anyone under 18. We don't knowingly collect their data.
9. Changes
If we change this policy in a way that matters, we'll update the date above and tell account owners by email before the change takes effect.
10. Contact and grievance officer
For privacy questions, requests or complaints, contact our grievance officer at support.linenaudit@gmail.com.