← Back to Courtasy

Privacy Policy

Effective Date: April 1, 2026  ·  Last Updated: April 1, 2026

1. Introduction

Courtasy (“Company,” “we,” “us,” or “our”) operates the platform available at https://courtasy.com (the “Platform”). This Privacy Policy explains how we collect, use, store, disclose, and protect personal data when you or your organization (“Customer,” “you,” or “your”) access or use our services.

We are committed to protecting personal data in accordance with the Information Technology Act, 2000 and IT (SPDI) Rules, 2011, the Digital Personal Data Protection Act, 2023 (DPDP Act), the General Data Protection Regulation (GDPR) where applicable, and the California Consumer Privacy Act (CCPA) where applicable.

By accessing or using the Platform, you agree to the practices described in this Privacy Policy.

2. Definitions

TermMeaning
Personal DataAny information that identifies or can identify a natural person, directly or indirectly
Sensitive Personal Data (SPDI)Financial information, passwords, and similar data as defined under IT (SPDI) Rules, 2011
Data FiduciaryCourtasy, as the entity that determines the purpose and means of processing personal data
Data PrincipalThe individual whose personal data is being processed
ProcessingAny operation performed on personal data, including collection, storage, use, or deletion
Sub-processorA third-party service provider engaged by Courtasy to process data on our behalf
Business AccountAn account registered by a legal entity on the Platform

3. Who This Policy Applies To

This Platform is a Business-to-Business (B2B) service. We contract with legal entities and business users, not individual consumers. Personal data we process primarily relates to authorized representatives, employees, and contacts of our business Customers, and end-users who access the Platform under a Customer's account.

4. Data We Collect

4.1 Account & Identity Data

  • Full name, job title, and business email address
  • Business name, address, and registration details
  • Phone number (where provided)
  • Authentication credentials (managed via Clerk)

4.2 Payment & Financial Data

  • Billing address and payment method details
  • Transaction history and invoicing records
  • Payment data is processed by Stripe and is not stored on our servers in raw form. We store only tokenized payment references.

4.3 Usage & Technical Data

  • IP address, browser type, operating system
  • Pages visited, features used, session duration
  • Logs, crash reports, and diagnostic data

4.4 Communications Data

  • Emails sent to or from our support and legal addresses
  • In-product messages or support tickets

4.5 Customer-Submitted Data

Any data your organization uploads, imports, or creates while using the Platform (“Customer Data”). Courtasy processes this data as a Data Processor acting under your instructions.

5. How We Use Your Data

We use personal data only for lawful, specified purposes:

PurposeLegal Basis
Provide, operate, and maintain the PlatformContract performance
Process payments and manage billingContract performance / Legal obligation
Create and manage your accountContract performance
Send transactional and account-related emailsContract performance
Provide customer supportLegitimate interest
Detect fraud, abuse, and security threatsLegitimate interest / Legal obligation
Analyze usage and improve the PlatformLegitimate interest
Comply with legal obligationsLegal obligation
Send product updates or marketing (with consent)Consent

We do not sell personal data to third parties.

6. Data Sharing & Third-Party Services

6.1 Sub-processors

We share personal data only where necessary and with appropriate safeguards.

Sub-processorPurposeData SharedRegion
StripePayment processingBilling name, email, payment methodUSA
ClerkAuthentication & identityName, email, phone, auth tokensUSA
ResendTransactional email deliveryName, email addressUSA
GoogleAnalytics & workspace integrationsUsage data, identifiersUSA / Global
AWSCloud infrastructure & data hostingAll platform dataUSA (US clients) / India

We maintain Data Processing Agreements (DPAs) with all sub-processors.

6.2 Legal Disclosures

We may disclose personal data if required by law, court order, or government authority, or to protect the rights, property, or safety of Courtasy, our Customers, or others.

6.3 Business Transfers

In the event of a merger, acquisition, or sale of assets, personal data may be transferred as part of that transaction. We will notify affected parties as required by applicable law.

7. Data Residency & International Transfers

  • Indian clients: Data is primarily stored and processed in India (AWS infrastructure).
  • US clients: Data is stored and processed in the United States (AWS US regions).
  • Where data is transferred across borders, we implement appropriate safeguards including Standard Contractual Clauses (SCCs) under GDPR and equivalent protections under applicable Indian law.

8. Data Retention

Data TypeRetention Period
Account dataDuration of contract + 3 years after termination
Financial records7 years (tax and accounting law compliance)
Usage logsUp to 12 months
Customer DataDeleted or returned within 30 days of contract termination, on written request

You may request earlier deletion subject to our legal retention obligations.

9. Your Rights

RightDescription
AccessRequest a copy of the personal data we hold about you
CorrectionRequest correction of inaccurate or incomplete data
ErasureRequest deletion of your personal data (subject to legal exceptions)
PortabilityReceive your data in a structured, machine-readable format
ObjectionObject to processing based on legitimate interest
Withdraw ConsentWithdraw consent at any time where processing is consent-based
Grievance RedressalLodge a complaint with our Grievance Officer (see Section 13)

To exercise any right, email legal@courtasy.com with the subject line “Privacy Request.” We will respond within 30 days.

Indian residents may file a complaint with the Data Protection Board of India once constituted under the DPDP Act, 2023. GDPR / EEA users may lodge a complaint with their local supervisory authority.

10. Security

We implement industry-standard technical and organizational measures to protect personal data. See our Security Policy for full details. In the event of a personal data breach likely to result in risk to data subjects, we will notify affected parties and relevant authorities as required by applicable law.

11. Cookies

We use cookies and similar tracking technologies. For full details, see our Cookie Policy.

12. Children's Data

Our Platform is designed exclusively for business use. We do not knowingly collect personal data from individuals under the age of 18. If we become aware that we have inadvertently collected such data, we will delete it promptly.

13. Grievance Officer

In accordance with the IT Act, 2000 and DPDP Act, 2023, we have appointed a Grievance Officer:

Grievance Officer, Courtasy
Email: legal@courtasy.com
Response time: within 30 days of receipt

14. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email or a prominent notice on the Platform at least 14 days before taking effect. Continued use after that date constitutes acceptance of the updated policy.

15. Contact Us

Courtasy
Website: https://courtasy.com
Legal inquiries: legal@courtasy.com