Legal
Privacy Policy
Last updated: June 3, 2026
Who we are
Plinth is a product of Ditador Labs LLP, a company registered in India. We provide a digital governance platform for residential housing societies. When this policy refers to "Plinth", "we", "us", or "our", we mean Ditador Labs LLP.
Questions about this policy can be directed to privacy@plinth.in.
What data we collect
We collect only what is necessary to provide the service:
- Account data — your email address, used to authenticate you and send important notifications. We do not collect passwords; authentication is via one-time codes and magic links.
- Flat and society data — your flat number, block, and society membership, provided by your society administrator.
- Vote receipts — a cryptographic record that you voted, the weight applied, and the timestamp. For secret ballots, your specific choice is never stored in a way that links it back to you.
- Credential documents — ownership proof documents you optionally upload when required by your society for certain polls. These are stored in a private encrypted bucket and automatically deleted after the retention period.
- Usage statistics — we collect anonymous, aggregated analytics (page views, feature usage patterns, error rates). These statistics contain no personally identifiable information. They are never linked to your account or individual activity, and are used solely to understand how the product is used and to improve it.
How we use your data
- To authenticate you and provide access to your society's polls.
- To send transactional emails — vote notifications, claim status updates, and poll reminders. We do not send marketing or promotional emails.
- To enforce one-vote-per-flat integrity and prevent duplicate voting.
- To maintain an audit trail for your society's governance records.
- To improve the platform using anonymous, aggregated usage data.
We do not use your personal data for advertising, profiling, or any purpose not listed above.
Data sharing
We do not sell your personal data. We do not share your data with third parties for marketing purposes.
We may share data in the following limited circumstances:
- Within your society — society administrators can see member lists, claim requests, and poll participation counts. They cannot see the content of secret ballots.
- Service providers — we use Supabase (database and authentication), Brevo (transactional email), and Vercel (hosting). These providers process data on our behalf under data processing agreements and may not use your data independently.
- Legal requirement — if required by applicable law, court order, or government authority in India.
Data retention
- Account data — retained while your account is active. You may request deletion at any time.
- Vote records — retained for the lifetime of the society's account for governance and audit purposes.
- Credential documents — automatically purged 30 days after the relevant poll closes (the retention window is configurable per society, minimum 7 days).
- Society data — deleted within 30 days of a society account deletion request.
Security
All data is encrypted in transit using TLS 1.3 and at rest using AES-256. Credential documents are stored in a private bucket accessible only via short-lived signed URLs. Votes are written only through server-side functions — clients cannot directly write to the votes table. Every state-changing action is logged to an append-only audit log.
Despite these measures, no system is 100% secure. We will notify affected users and relevant authorities promptly in the event of a data breach.
Your rights
You have the right to:
- Access — request a copy of the personal data we hold about you.
- Correction — ask us to correct inaccurate data.
- Deletion — request deletion of your account and personal data, subject to legal and governance retention obligations.
- Portability — request your data in a machine-readable format.
- Objection — object to processing where we rely on legitimate interests.
To exercise any of these rights, email us at privacy@plinth.in. We will respond within 30 days.
Cookies
Plinth uses only strictly necessary cookies and browser storage (localStorage) to maintain your session and remember your active society. We do not use advertising cookies, tracking pixels, or third-party analytics cookies.
Children's privacy
Plinth is not directed at persons under the age of 18. We do not knowingly collect personal data from minors. If you believe a minor has provided us with personal data, contact us and we will delete it promptly.
Changes to this policy
We may update this Privacy Policy from time to time. We will notify users by email and by posting the updated policy on this page with a revised "Last updated" date. Continued use of Plinth after the effective date constitutes acceptance of the updated policy.
Contact
Ditador Labs LLP
Hyderabad, Telangana, India
Email: privacy@plinth.in