Legal · Privacy

Privacy Policy

This policy explains how CSHUBB Innovations collects, uses, and protects your data when you use the CSHUBB platform.

Sole ProprietorshipUdyam MSME CertifiedIndiaLast updated: June 2026
01

Who We Are

CSHUBB is a web-based Customer Success workspace for SaaS teams, built and operated by CSHUBB Innovations — a sole proprietorship registered under the Government of India, Udyam MSME Certified.

This Privacy Policy explains how we collect, use, store, and protect your personal data when you use CSHUBB ("the Service"). By using the Service, you agree to the practices described here.

Legal entity: CSHUBB Innovations, Sole Proprietorship · Udyam MSME Certified · India · support@cshubb.com
02

What Data We Collect

Account data — Your full name, work email address, and organisation name, collected when you register via an invite code.

Workspace data — Customer account records you import or create (ARR, health scores, NPS, renewal dates, etc.). This is your business data — we process it only to provide the Service.

Usage data — Page views, feature interactions, and AI tool runs, collected via PostHog with autocapture disabled, session recording disabled, and no personally identifiable information in event payloads.

Technical data — IP address, browser type, and device information, retained for security and audit purposes.

Support data — The content of help requests, feedback, or deletion requests you submit within the platform.

Google Calendar data — If you connect Google Calendar via the Meetings module: your calendar event metadata (title, time, attendees, description) for the purpose of logging meeting notes against customer accounts. We access only what you explicitly authorise via Google OAuth. We do not access personal calendar events unrelated to your workspace accounts.

What we do NOT collect: Passwords (passwordless auth only) · AI provider API keys (browser-only) · Payment card data (not processed by us) · Session recordings · Screen captures · Google Calendar events unrelated to your CS accounts
03

How We Use Your Data

To provide, operate, and maintain the CSHUBB workspace
To send magic-link authentication emails via Resend (mail.cshubb.com)
To generate audit logs visible to your workspace administrator
To respond to support requests and account deletion requests
To improve the product using anonymised, aggregated analytics
To detect and prevent fraud, abuse, or security incidents
To comply with applicable Indian laws and regulations

We do not sell, rent, share, or trade your personal data with third parties for marketing purposes under any circumstances.

04

Third-Party Processors

CSHUBB uses the following third-party services to operate the platform. Each is bound by its own data processing agreements:

VendorRoleData processedCertification
Supabase (AWS)Database hosting, Auth, RealtimeAccount & workspace dataSOC 2 Type II
CloudflareCDN, TLS, DDoS mitigationNetwork traffic onlyISO 27001, SOC 2
ResendTransactional emailEmail address onlySOC 2 Type II
PostHogProduct analyticsAnonymised events, no PIIGDPR compliant
AI Providers (Groq/Anthropic/Google)AI inferenceDirect browser-to-API, we are not in the data pathOwn policies apply
Google Calendar APICalendar integration for Meetings module (optional)Event metadata you authorise via OAuth — title, time, attendees, descriptionGoogle Privacy Policy applies
AI note: When you use AI tools, prompts go directly from your browser to the AI provider. CSHUBB servers are never in the data path. Your AI API keys are stored only in your browser's localStorage and are never transmitted to or stored on our servers.
05

Google Calendar Integration

CSHUBB's Meetings module includes an optional Google Calendar integration. This section explains exactly what we access and how that data is handled.

What we access:

Calendar event metadata you explicitly authorise via Google OAuth — event title, date and time, duration, attendee email addresses, and event description
Only events associated with customer accounts in your CSHUBB workspace are read and stored

What we do NOT access:

Personal calendar events unrelated to your workspace or CS accounts
Google Drive, Gmail, or any other Google service beyond Calendar
Calendar events outside the scope you authorise at connection time

Token storage: Your Google OAuth refresh token is stored encrypted in Supabase, scoped to your workspace, and protected by Row-Level Security. It is used solely to fetch calendar data on your behalf. We never share or expose OAuth tokens to third parties.

Disconnect behaviour: You may disconnect Google Calendar at any time from Workspace Settings → Integrations → Google Calendar → Disconnect. Upon disconnection, your OAuth token is immediately revoked and deleted from our systems. Previously imported meeting metadata already associated with accounts is retained until you delete it or request account erasure.

Not used for AI: Google Calendar data is never sent to AI providers. Meeting notes and metadata are stored in your workspace database and displayed in the Meetings module only. AI tools operate on your account data (health, ARR, NPS, etc.) — not on your calendar or meeting content.
06

Data Storage & Retention

Location: Data is stored in Supabase's PostgreSQL database hosted on AWS infrastructure. Data residency options available on Enterprise plans.
Encryption at rest: AES-256 via Supabase/AWS RDS
Encryption in transit: TLS 1.2+ enforced via Cloudflare on all connections
Account data: Retained while your workspace is active
Audit logs: Retained for 12 months from creation date
After deletion: Personal data purged within 5 business days of a verified deletion request
Backups: Encrypted backups retained for up to 30 days, then permanently purged
07

Your Rights

Depending on your location, you may have the following rights under applicable law (including GDPR for EU users and IT Act / DPDP Act 2023 for Indian users):

Right to access — Request a copy of personal data we hold about you
Right to correction — Ask us to correct inaccurate personal data
Right to deletion — Request complete removal of your account and associated data
Right to portability — Export all your workspace data at any time via CSV or JSON
Right to objection — Opt out of product analytics at any time
Right to restriction — Ask us to limit processing of your data in certain circumstances

Right to erasure — how to request it: Users and org admins may request complete data erasure by contacting support@cshubb.com. Org admins can also trigger erasure directly from the Admin Panel → Data & Privacy tab. Erasure requests are processed within 5 business days and permanently remove all personal and workspace data associated with the account.

To exercise any of these rights, email support@cshubb.com. We will respond within 30 days.

08

Security Measures

We implement multiple layers of technical and organisational security controls:

Passwordless authentication — no passwords stored or managed anywhere
PostgreSQL Row-Level Security (RLS) at the database engine level
Invite-only workspace access — no public signup
AES-256 encryption at rest and TLS 1.2+ in transit
Full audit trail — 210+ event types logged with attribution
HMAC-SHA256 webhook payload signing (Pro/Enterprise plans)
Service role keys stored exclusively in server-side Edge Functions
No third-party tracking scripts or session recording tools

To report a security concern or vulnerability, email security@cshubb.com. We aim to acknowledge reports within 24 hours.

09

Children's Privacy

CSHUBB is a professional business tool intended for adults (18+) operating in a business capacity. We do not knowingly collect personal data from individuals under the age of 18. If you believe a minor has provided data to us, please contact support@cshubb.com and we will remove it promptly.

10

International Data Transfers

CSHUBB Innovations is based in India. Data is processed on Supabase's AWS infrastructure which may be located in the United States or other regions. All cross-border data transfers are conducted in compliance with applicable laws and under standard data processing agreements with our service providers.

For EU/EEA users, transfers are covered under Standard Contractual Clauses (SCCs) maintained by Supabase and Cloudflare.

11

Cookies & Analytics

CSHUBB uses minimal cookies strictly necessary for session management (authentication JWT). We do not use advertising cookies or cross-site tracking cookies.

Product analytics are collected via PostHog with the following settings: autocapture disabled, session recording disabled, no PII in event payloads, EU data residency endpoint used where applicable.

You may disable cookies in your browser settings, though this will prevent login from functioning
You may opt out of analytics by contacting us at support@cshubb.com
12

Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify active workspace administrators via email at least 30 days before the changes take effect.

Continued use of the Service after the effective date of any changes constitutes your acceptance of the updated policy. The date of the last update is always shown at the top of this page.

13

Contact Us

For any privacy-related questions, data requests, or concerns:

General enquiries: support@cshubb.com
Security & vulnerability reports: security@cshubb.com
Founder / data controller: founder@cshubb.com
Response time: Within 5 business days for privacy requests, within 24 hours for security reports
CSHUBB Innovations · Sole Proprietorship · Udyam MSME Certified · India
This policy was last updated: June 2026