Enterprise Legal Compliance

Privacy Policy

Effective Date: August 5, 2026

Last Updated: August 5, 2026

1. Corporate Identity and Data Controller

This Privacy Policy is issued by STITCHBYTE LLP (herein referred to as the "Company", "we", "us", or "our"). Under global data protection regulations—including the General Data Protection Regulation (GDPR - Regulation (EU) 2016/679) and the Digital Personal Data Protection Act, 2023 (DPDP Act - India)—STITCHBYTE LLP acts as the Data Controller and Data Fiduciary for the personal information processed through our main site (https://stitchbyte.in), our cloud-hosted administrative panels, pre-built web solutions, social media management channels, and direct B2B consulting services.

Corporate Registrations

Entity: STITCHBYTE LLP

LLPIN: ACJ-8283

Date of Incorporation: Oct 08, 2024

Registrar: ROC - Jaipur

Registered Address

446, Inside Delhi Gate, near Jain Dispensary,

Bhargava Bhawan, Alwar, Rajasthan, 301001, India

Email: info@stitchbyte.in

2. Categories of Information We Collect

We gather the following categories of data in accordance with the principles of data minimization and purpose limitation:

  • A. Personal Data & Identifiers: Name, professional email address, mobile number, job title, and company brand details.
  • B. Billing & Transactional Information: Legal company name, billing address, tax identification numbers (such as GSTIN, VAT, or PAN), corporate banking receipts, transaction logs, and billing contact details.
  • C. Client Credentials & API Secrets: For development operations, clients may securely share hosting portal keys, domain registrar credentials, database connection strings, SSH keys, API keys, or Firebase configurations.
  • D. Technical & Log Data: Internet Protocol (IP) address, geographic region, browser user-agent, operating system, referrer URL, pages visited, timestamp, error codes, and server security event logs.
  • E. Sensitive Personal Data: We do not knowingly collect, parse, or process biometrics, health records, genetic data, or government-issued national identity numbers (except tax IDs required specifically for legal billing compliance).

3. Google API Services & OAuth Consent Policy

STITCHBYTE LLP's internal administrative portal integrates Google OAuth (via Google Sign-In) to verify staff and administrators.

Scopes Requested & Justifications:

  • openid: Used to establish a secure unique session ID for the logging administrator.
  • email: Retrieved to check the user against the whitelist of authorized administrative emails in our database.
  • profile: Used to render the administrator's name and profile avatar on the internal command dashboard.

Google API Services User Data Policy Compliance: Our use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Sharing & Advertising Restrictions: Google user profile data is never sold, leased, shared with third parties, or used to build marketing profiles or display targeted advertising blocks.

Access Revocation: Users can revoke our application's access to their Google profile data at any time via the Google Account Security Permissions management page.

4. Fees, Billing, and Transaction Security

Engaging STITCHBYTE LLP for custom development milestone work or digital asset subscriptions involves strict billing compliance protocols:

  • Payment Gateways: All payment transactions are executed via industry-certified, PCI-DSS compliant third-party payment processors, including Razorpay, Stripe, PayPal, and PhonePe. We do not store or process debit card, credit card, net-banking passwords, or CVV codes on our servers.
  • GST & Invoicing: System-generated invoices will be raised on each project milestone or subscription renewal. All invoices are compliant with Indian GST (CGST/SGST/IGST) and regional corporate registry statutes, noting transactional milestones, GSTINs, corporate addresses, and fees.
  • Non-Refundability: Milestone payments, deposits, discovery hours, and license purchases are non-refundable once work commences, except as explicitly detailed in signed Master Service Agreements (MSAs) or NDAs.
  • Non-Payment & Account Deletion: If any client, partner, or subscriber fails to settle their outstanding invoices or milestone payments when due (including fees for custom development, digital marketing, SEO, or social media management), STITCHBYTE LLP reserves the unilateral right to suspend services, restrict code repository branches, and/or delete associated accounts, databases, hosted files, and campaigns with immediate effect. STITCHBYTE LLP assumes no liability for any data loss, server downtime, or disruptions resulting from deletion due to non-payment.

5. Cookies & Tracking Consent Management

Our website implements a cookie consent mechanism located at the bottom-left of the viewport. We classify our cookies into the following functional groupings:

  • Necessary Cookies (First-party): Essential for core website operations, session state monitoring, and storing your consent preferences. These do not gather tracking details.
  • Analytics & Performance (Third-party): Managed via Google Analytics and Google Tag Manager to evaluate user interaction patterns and optimize load performance.
  • Marketing & Retargeting (Third-party): Managed via Facebook Pixel (Meta) to measure conversion rates of digital advertisements.

Opt-Out & Do Not Track (DNT): No third-party analytics or marketing scripts run, nor do they write database keys to your local storage, unless you explicitly select "Accept All" on the consent banner. We respect your browser's "Do Not Track" (DNT) headers.

6. Disclosed Third-Party Subprocessors

We share personal, transactional, or technical data only with trusted third-party service providers (Subprocessors) to maintain our operational channels:

Subprocessor / ServicePurposePrimary Storage Region
Vercel & NetlifyFrontend Deployment & Serverless Functions HostingUnited States / Global CDN
AWS (Amazon Web Services)Cloud Infrastructure & Secure S3 Storage Asset hostingIndia (Mumbai) / United States
DigitalOceanVirtual Private Servers (VPS) hosting and backend stagingIndia (Bangalore) / Singapore
Oracle Cloud Infrastructure (OCI)Virtual Private Servers (VPS) hosting and backend computation databasesIndia (Mumbai / Hyderabad)
MongoDB AtlasDatabase Cluster StorageIndia (Mumbai) / Singapore
Razorpay, Stripe & PayPalSecure Financial Transactions Processing & BillingIndia / United States
Brevo, Resend & SMTP servicesTransactional Email and Newsletter DeliveryEurope (France) / United States
CloudinaryOptimized Image and Video Asset HostingUnited States
OpenAI & Google GeminiArtificial Intelligence content & text processing helpersUnited States
Cloudflare & Google Fonts/reCAPTCHADNS management, Web Security Shielding & spam mitigationGlobal Anycast Network

7. Legal Bases & Purpose of Processing

Under Chapter II of the Indian DPDP Act 2023 and Article 6 of GDPR, we process personal details under the following legal bases:

  • Consent: When you subscribe to our newsletter, accept cookies, or submit Career and Contact Us forms. Consent can be revoked at any time.
  • Contractual Obligation: To execute Master Service Agreements (MSAs), fulfill client code milestones, manage SSH access, and hand over source code repository packages.
  • Legal Obligation: Mandated data retention for accounting registry auditing, tax compliance (GSTIN filing, Company Audit compliance), and cooperation with legal regulatory bodies.
  • Legitimate Interests: To inspect server logs, prevent security breaches, mitigate spam submissions, and optimize our digital product catalogs.

8. Strict Data Retention Schedule

We retain personal, billing, and transactional data only as long as necessary to fulfill the original purpose of collection or comply with statutory requirements:

Financial Invoices & Tax Logs

8 Years (Statutory requirement under Indian Income Tax Act & GST Act)

Client Project Files & Backups

2 Years following formal project sign-off and milestone closure

Administrative Portal Security Logs

180 Days for active threat and server performance detection

Support Communications & Emails

3 Years to support recurrent troubleshooting requests

Google OAuth Administrative Access

Immediate deletion upon account removal or access revocation

Analytics Logs (GA / GTM)

26 Months following user session activity closure

9. Data Protection Rights (GDPR, DPDP Act & CCPA)

You hold the following rights regarding the personal information we process:

  • Right to Access: You can request a copy of all personal details we hold about you.
  • Right to Rectification & Correction: You can request updates to correct inaccurate or incomplete contact, identity, or billing records.
  • Right to Portability: You can request that we export your data in a structured, machine-readable format.
  • Right to Erasure (Deletion): You can request that we delete your personal details. Legal Exclusion: This right does not apply to transactional billing records, invoices, or signatures on Master Service Agreements (MSAs) which STITCHBYTE LLP is legally bound to retain for tax audit purposes.
  • Right to Lodge Complaints: You have the right to file grievances with local data authorities—such as the Data Protection Board of India or EU-recognized **Supervisory Authorities**—if you believe your data has been handled in breach of compliance laws.

10. Protection of Sensitive Client Credentials & Credentials Management

During deployment phases, clients routinely share server access, domain registrar logins, Firebase keys, or API tokens:

  • Storage and Encryption: All shared credentials are stored in encrypted vaults utilizing Role-Based Access Controls (RBAC). No credentials are cached in plain text files or shared in unencrypted communication channels.
  • Mandatory Deletion: Upon project sign-off and successful server deployment, we enforce a mandatory deletion schedule where staging keys and shared root credentials are removed from our systems. Clients are instructed to rotate staging passwords post-deployment.
  • NDAs & B2B Data Processing: We sign Mutual Non-Disclosure Agreements (NDAs) for custom engineering contracts. Where required, we can execute custom Data Processing Agreements (DPAs).

11. International Transfers & Data Safeguards

STITCHBYTE LLP operates cloud database nodes and utilizes subprocessors situated outside of India (including in the United States, Singapore, and Europe). Consequently, your information may be processed in regions with varying data privacy standards. To ensure safety, we execute Standard Contractual Clauses (SCCs), enforce SSL/TLS encrypted pipelines, and utilize certified enterprise cloud providers that guarantee compliance with international data transfer frameworks.

12. Children's Privacy

Our development, design, and SEO services are not structured for, nor marketed to, individuals under the age of 18. We do not knowingly collect personal data from minors. If we discover that personal details from an individual under 18 have been collected without parental consent, we will delete that data from our database servers immediately.

13. Data Breach and Incident Response

STITCHBYTE LLP maintains active server monitoring for security threat detection. In the unlikely event of a data breach compromising personal, transactional, or client credentials, we will notify affected individuals and regulatory authorities (such as CERT-In or supervisory bodies) within 72 hours of verification, outlining the containment strategies and corrective protocols.

14. Changes to This Privacy Policy

We reserve the right to modify this Privacy Policy to reflect regulatory changes or software updates. When modifications are made, we will update the "Last Updated" date at the top of the policy page. Registered clients and active users will receive notice via email regarding material modifications.

15. Contact Us & Grievance Officer

For inquiries concerning your data rights, cookie consents, or billing invoices, please contact our designated Grievance and Compliance Officer:

Grievance & Privacy Officer

Officer Name: Mayur Bhargava

Title: Head of Compliance & Legal Affairs

Email: info@stitchbyte.in

Response Timeline: Within 30 calendar days

StitchByte Headquarters

STITCHBYTE LLP

446, Inside Delhi Gate, near Jain Dispensary,

Bhargava Bhawan, Alwar, Rajasthan, 301001, India

Email: info@stitchbyte.in