PracticeStacks
Data Sovereignty Guaranteed

Privacy Policy

Last updated: July 12, 2026

End-to-End Encryption

All proposal data is encrypted using TLS 1.3 in transit and AES-256 at rest.

ZKP Authentication

Secure multi-factor authentication ensures only authorized personnel access practice data.

Introduction

PracticeStacks (the "Platform") recognizes that the confidentiality and security of financial and legal advisory data are foundational to our users' practices. This Privacy Policy outlines our uncompromising standards for handling your professional information and sensitive personal data.

Legal Framework

We process personal data in compliance with the Information Technology Act, 2000 and the SPDI Rules, 2011, and are aligning with the Digital Personal Data Protection Act, 2023 (DPDP Act) and the DPDP Rules, 2025 ahead of their full commencement. For your account data (name, email, phone, billing), PracticeStacks acts as the Data Fiduciary. For the client data your firm stores on the Platform (client PAN, GST, contact details, documents), your firm is the Data Fiduciary and PracticeStacks acts as a Data Processor on your written instructions — see the Data Processing terms in our Terms of Service.

Sensitive Personal Data (SPDI)

In compliance with the Information Technology Act (India), 2000, and SPDI Rules, we categorize the following as sensitive data:

  • Financial information such as bank account or credit/debit card details.
  • Biometric information and physical, physiological, and mental health conditions.
  • Professional credentials and practice certification details.
  • End-client financial data provided within proposals.

Data Storage & Cross-Border Transfers

Platform data is hosted on enterprise cloud infrastructure (Vercel and managed PostgreSQL) which may store and process data in data centers outside India, including the United States. Such transfers are permitted under applicable Indian law (the DPDP Act follows a negative-list model and no restricted-country list has been notified). All data is encrypted in transit (TLS 1.3) and at rest, and access is limited to authorized personnel.

Your Rights

You may exercise the following rights over your personal data by writing to our Grievance Officer (below):

  • Access — request a summary of the personal data we hold about you and how it is processed.
  • Correction — have inaccurate or incomplete data corrected or updated.
  • Erasure — request deletion of your account and associated personal data, subject to records we must retain under law (e.g. tax and billing records).
  • Consent withdrawal — withdraw any consent-based processing (e.g. analytics cookies, marketing) at any time, as easily as it was given.
  • Grievance redressal — complain to our Grievance Officer; we respond within 30 days. Once the DPDP Act is fully in force you may also approach the Data Protection Board of India.

Data Retention

We retain personal data only as long as needed for the purposes described here: account data for the life of your account plus 30 days after cancellation (per our Refund & Cancellation Policy); billing and transaction records as required by tax law; security and audit logs for up to 12 months. Data belonging to your firm's clients is retained per your firm's instructions and deleted when you delete it from the Platform or close your account.

Information Sharing Policy

We strictly do not sell, trade, or rent your professional data. Data sharing is limited to:

Third PartyPurposeData Shared
RazorpayBilling & KYCTransaction Info
AWS S3Secure Document HostingDocuments & Attachments
Google / MicrosoftSecure Login (OAuth)OAuth Profile
Meta (WhatsApp Business)Client Notifications & OTPPhone Number, Message Content
MSG91SMS OTP DeliveryPhone Number, OTP
Email Delivery (SMTP)Transactional EmailEmail Address, Message Content
Google (Gemini AI)AI Assistance (email task extraction, proposal & content drafting)Relevant email/proposal text you process with AI features
PostHog (US)Product Analytics (opt-in via cookie banner)Usage events, internal user ID — no name, email, or phone
Google AnalyticsSite Analytics (opt-in via cookie banner)Page views, device info
GlitchgrabBug Reports (only when you submit a report)Name, Email, Report Details, Page Activity Context
Hosting & DatabaseApplication Hosting (Vercel), Managed PostgreSQLAll Platform Data

Grievance Officer

In accordance with the Information Technology Act, 2000 and rules made thereunder, and the Digital Personal Data Protection Act, 2023, the name and contact details of the Grievance Officer are provided below:

Officer: Mr. Shekhar Maske

Designation: Data Privacy & Compliance Lead

PracticeStacks HQ, Pune, Maharashtra.

support@practicestacks.in

By using PracticeStacks, you signify your acceptance of this policy. For detailed usage rules, please consult our Terms of Service.

Built for Professionals. Trusted by Experts. © 2026 PracticeStacks.