Privacy Policy
What personal data Supply Saarthi holds, why, who can see it, and what you can ask us to do about it.
Supply Saarthi is operated by Swatah Software, a sole proprietorship registered in India. Effective 15 August 2026.
1.Two different roles, and why it matters
Supply Saarthi holds personal data in more than one capacity, and our responsibility differs between them. Under India's Digital Personal Data Protection Act, 2023 the distinction decides who you ask for what.
- Your own account data — your name, email, mobile, and how you use the product. For this, Swatah Software is the Data Fiduciary. Ask us directly.
- Your workers' and clients' data — everything you enter to run your business: payroll, attendance, PF/ESI, registers, KYC on your own workers. For this, you are the Data Fiduciary and we are your Data Processor, acting under a data processing addendum (see Terms clause 15): we hold and process it only on your instructions, for you, and for nothing else. This processing does not run on consent — employment-purpose processing (payroll, attendance, statutory deductions, register maintenance) is a legitimate use under section 7(i) of the Act, requiring none. A worker asking about their own data should be directed to their employer, which is you — and we will help you answer.
- A pool worker's data — where a worker signs up with us directly, rather than being entered by an employer, Swatah Software is itself the Data Fiduciary to that worker, with notice, consent, rights and breach obligations running directly to them. This role applies to the live worker pool, where a worker registers themselves, manages their own listing, availability and consent from their phone, and pays a ₹99 annual listing fee by UPI (see the pool terms and refund policy). The notice that governs this data — given at the point of collection, not folded into this policy — lives at the collection notice. Consent is asked only for pool listing, matching and discoverability, never for the employment-purpose processing above, and withdrawing it delists a worker and erases their pool KYC without touching payroll history an employer is statutorily required to keep.
2.What we hold
About the people who sign in: name, email address, mobile number, the role each holds in each business, sign-in times, and a Google account identifier if Google sign-in is used. Passwords are never stored — only a value derived from them that cannot be reversed.
About workers, entered by their employer: name, employee identifier, contact details, wage rate, bank details for payslips, attendance, deployments, and statutory identifiers such as UAN, ESIC number and Aadhaar.
About client businesses: legal and trade names, GSTIN, PAN, addresses, sites, contacts, rate contracts, orders and invoices.
Operational records: an audit trail of significant actions — who approved attendance, who changed a rate, who issued an invoice — and ordinary server logs.
3.Aadhaar, specifically
Aadhaar numbers are encrypted before they are stored, with a key held separately from the database. They are not readable by inspecting the data.
Because that encryption produces different output every time, it cannot be used to spot the same worker entered twice — which is how one person ends up with two payslips and an EPFO filing that gets rejected. So we also store a one-way fingerprint of the number: enough to notice a duplicate, not enough to recover the number, and useless without our key.
We do not share Aadhaar numbers with anyone, and we do not use them for any purpose other than identifying a worker within their employer's own records.
4.Why we hold it
- To provide the service — computing payroll, producing payslips and registers, raising invoices, tracking deployments and attendance.
- To keep accounts secure and to show who did what, which is what makes an audit trail worth having.
- To bill for the subscription and to contact you about the service.
- To meet our own legal obligations.
We do not sell personal data. We do not use it for advertising. We do not use your business's operational data to build anything for anyone else.
5.Who else can see it
- Nobody in another business. Each tenant's operational data lives in its own isolated database schema, and requests are scoped by the signed session rather than by anything the browser can change.
- Within your business, what someone sees follows their role. A client portal user sees only their own sites, orders and invoices — never your other clients, your workforce or your payroll.
- Google, if a user chooses Google sign-in — which tells us their verified email address and nothing more.
- Our hosting and database providers, who store the data on our behalf under contract and may not use it for their own purposes.
- Authorities, where we are legally required to disclose. We will tell you unless we are prohibited from doing so.
6.Where it is stored
The application runs on infrastructure in India (Mumbai), and the database that holds your operational data — including your workers' encrypted Aadhaar numbers — runs in India (Mumbai). Both the app and its primary database run in Google Cloud's asia-south1 (Mumbai) region, and the database is not reachable from the public internet. Your personal data, including encrypted Aadhaar, is processed and stored in India.
Processing and storing this data in India is a deliberate choice rather than a legal minimum. The Digital Personal Data Protection Act, 2023 would permit us to hold it in most other countries; we do not route it offshore as a matter of design, because that is not what a business handing over its workers' identity documents expects of us.
We do not claim there is never any copy of the data outside India at any instant — a managed cloud provider may, for example, hold a short-lived operational backup while infrastructure is migrated. What we commit to is that the service is run as a single-region India deployment, and if that materially changes — a provider we depend on with no Indian region, or personal data deliberately held elsewhere — this clause will say so in plain words and the effective date at the top will change.
7.How it is protected
- Encrypted in transit, always. Aadhaar numbers encrypted at rest with a separately held key.
- Schema-per-tenant isolation, so one business's data is not merely filtered out of another's queries — it is in a different place.
- Sessions can be revoked everywhere at once: changing a password invalidates every session issued before it, on every device and in every business that person belongs to.
- An audit trail of significant actions that ordinary users cannot alter.
No system is perfectly secure, and we will not claim otherwise. If a breach affects your data we will tell you and the Data Protection Board as the law requires.
8.How long we keep it
While your account is active, we keep your data so the product works — payroll and statutory records in particular have to remain available for the periods Indian law requires of an employer. Three clocks apply, the third for the live worker pool:
- Payroll, wage and other statutory registers: 8 years.
- GST records: 72 months from the annual return's due date.
- A pool worker's KYC (Aadhaar, bank details taken for the pool, not for an employer's payroll) — erased on consent withdrawal or after inactivity, with no fixed hold. We do not keep a lapsed worker's identity documents indefinitely. Erasing pool KYC never deletes the employment/payroll history an employer is separately required to keep.
After an account closes we retain the data for a limited period, so an accidental closure can be undone, and then delete it — apart from anything we must keep for legal or accounting reasons.
9.Your rights
Under the DPDP Act you may ask us to:
- tell you what personal data of yours we hold and who we have shared it with;
- correct anything inaccurate, or complete anything missing;
- erase data we no longer need for the purpose it was collected;
- nominate someone to exercise these rights if you die or become incapacitated;
- raise a grievance about how we have handled any of it.
Write to admin@swatahsoftware.com. Our Grievance Officer is The Proprietor, Swatah Software — full contact details, including the postal address the Act requires, are on the Grievance Officer page. We will respond within the period the Act requires.
If your request concerns data your employer entered about you, we will point you to them and help them answer it — see clause 1.
10.Children
Supply Saarthi is for businesses and is not intended for anyone under 18. Recording a worker below the lawful minimum age for their work is a matter for the employer and the law; the product does not make it acceptable.
11.Changes
We will update this policy as the product changes, and give reasonable notice of anything that materially affects you. The effective date at the top always reflects the current version.