Privacy Policy
Last updated: July 12, 2026
End-to-End Encryption
All proposal data is encrypted using TLS 1.3 in transit and AES-256 at rest.
ZKP Authentication
Secure multi-factor authentication ensures only authorized personnel access practice data.
Introduction
PracticeStacks (the "Platform") recognizes that the confidentiality and security of financial and legal advisory data are foundational to our users' practices. This Privacy Policy outlines our uncompromising standards for handling your professional information and sensitive personal data.
Legal Framework
We process personal data in compliance with the Information Technology Act, 2000 and the SPDI Rules, 2011, and are aligning with the Digital Personal Data Protection Act, 2023 (DPDP Act) and the DPDP Rules, 2025 ahead of their full commencement. For your account data (name, email, phone, billing), PracticeStacks acts as the Data Fiduciary. For the client data your firm stores on the Platform (client PAN, GST, contact details, documents), your firm is the Data Fiduciary and PracticeStacks acts as a Data Processor on your written instructions — see the Data Processing terms in our Terms of Service.
Sensitive Personal Data (SPDI)
In compliance with the Information Technology Act (India), 2000, and SPDI Rules, we categorize the following as sensitive data:
- Financial information such as bank account or credit/debit card details.
- Biometric information and physical, physiological, and mental health conditions.
- Professional credentials and practice certification details.
- End-client financial data provided within proposals.
Data Storage & Cross-Border Transfers
Platform data is hosted on enterprise cloud infrastructure (Vercel and managed PostgreSQL) which may store and process data in data centers outside India, including the United States. Such transfers are permitted under applicable Indian law (the DPDP Act follows a negative-list model and no restricted-country list has been notified). All data is encrypted in transit (TLS 1.3) and at rest, and access is limited to authorized personnel.
Your Rights
You may exercise the following rights over your personal data by writing to our Grievance Officer (below):
- Access — request a summary of the personal data we hold about you and how it is processed.
- Correction — have inaccurate or incomplete data corrected or updated.
- Erasure — request deletion of your account and associated personal data, subject to records we must retain under law (e.g. tax and billing records).
- Consent withdrawal — withdraw any consent-based processing (e.g. analytics cookies, marketing) at any time, as easily as it was given.
- Grievance redressal — complain to our Grievance Officer; we respond within 30 days. Once the DPDP Act is fully in force you may also approach the Data Protection Board of India.
Data Retention
We retain personal data only as long as needed for the purposes described here: account data for the life of your account plus 30 days after cancellation (per our Refund & Cancellation Policy); billing and transaction records as required by tax law; security and audit logs for up to 12 months. Data belonging to your firm's clients is retained per your firm's instructions and deleted when you delete it from the Platform or close your account.
Information Sharing Policy
We strictly do not sell, trade, or rent your professional data. Data sharing is limited to:
| Third Party | Purpose | Data Shared |
|---|---|---|
| Razorpay | Billing & KYC | Transaction Info |
| AWS S3 | Secure Document Hosting | Documents & Attachments |
| Google / Microsoft | Secure Login (OAuth) | OAuth Profile |
| Meta (WhatsApp Business) | Client Notifications & OTP | Phone Number, Message Content |
| MSG91 | SMS OTP Delivery | Phone Number, OTP |
| Email Delivery (SMTP) | Transactional Email | Email Address, Message Content |
| Google (Gemini AI) | AI Assistance (email task extraction, proposal & content drafting) | Relevant email/proposal text you process with AI features |
| PostHog (US) | Product Analytics (opt-in via cookie banner) | Usage events, internal user ID — no name, email, or phone |
| Google Analytics | Site Analytics (opt-in via cookie banner) | Page views, device info |
| Glitchgrab | Bug Reports (only when you submit a report) | Name, Email, Report Details, Page Activity Context |
| Hosting & Database | Application Hosting (Vercel), Managed PostgreSQL | All Platform Data |
Grievance Officer
In accordance with the Information Technology Act, 2000 and rules made thereunder, and the Digital Personal Data Protection Act, 2023, the name and contact details of the Grievance Officer are provided below:
Officer: Mr. Shekhar Maske
Designation: Data Privacy & Compliance Lead
PracticeStacks HQ, Pune, Maharashtra.
By using PracticeStacks, you signify your acceptance of this policy. For detailed usage rules, please consult our Terms of Service.
Built for Professionals. Trusted by Experts. © 2026 PracticeStacks.
