Privacy policy

Updated 6 October 2026

This policy covers the Crossruled website and the workspace. It says what data we hold, why, where, for how long, which rights you can exercise today and how, and who to write to.

Who is responsible

Crossruled is operated by Rajan Agarwal, Delhi, India ("we", "us"). For workspace content, the people, allocations, costs and proposals your company puts in, your company decides what is uploaded and why. It is the controller under the GDPR and the data fiduciary under India's Digital Personal Data Protection Act, 2023. Crossruled processes that content on your company's instructions, as a processor. For account data and for what you send us through the early-access form or by email, Crossruled is the controller and data fiduciary.

Data we process

Account data: name, email, sign-in identifiers, workspace membership, role and status. Workspace content: employee records (name, employee code, role, department, skills, capacity, status, monthly cost where a cost role enters it), projects and clients, allocations and bill rates, role salary bands, proposals and their pricing assumptions, rows pasted from the Excel template, and the audit log, which records who changed which record and when. Early-access requests: name, work email, company, rough headcount, the tool you plan in today and the problem you describe. Error reports from the browser: the page path, the error message and stack, and the time, sent to our hosting logs so we can fix faults. Crossruled is a business tool for companies and is not meant for children. Customers should not add a person under 18 unless they have the consent the law requires for that person.

Purposes and legal basis

We use data to run the service, sign you in, keep each workspace separate from every other, calculate utilization, cost and proposal values, keep the audit record, answer support and access requests, and keep the service reliable. Under the GDPR the bases are performance of the contract with your company, our legitimate interest in running and securing the service, legal obligation where one applies, and, for the early-access form, the steps you ask us to take before a contract and our legitimate interest in answering business enquiries. Under the DPDP Act your employer is responsible for the notice and lawful basis for putting employee data into the workspace; where we act for ourselves, we rely on the data you chose to send us for the purpose stated where you sent it, and on your consent where we ask for it. We do not use workspace content to train models, and we do not sell it or use it for advertising.

Where data is stored

Workspace data and account data are stored in Google Cloud Firestore in the multi-region location nam5, which is in the United States, and the app is served by Vercel. Data is stored and processed in the United States. For a company in India this is a cross-border transfer under the DPDP Act. No Indian rule restricts transfer to the United States today; if one is made, we will tell customers before it takes effect. Your sector's rules or your own client contracts may be stricter, so check them before you upload. For the database, Google's Firebase data-processing terms include the EU standard contractual clauses. Vercel's data-processing terms apply to its Pro and Enterprise plans, not to the hosting plan we use during early access, and we have not yet signed transfer clauses with any customer. So during early access we do not take workspaces from companies in the EU or UK; if you are there, write to us before you start. There is no India or EU storage option today; if you need one, say so before you start. We also keep backup copies of the database, made to test that restores work, on the operator's encrypted computer in India. We delete each one within 30 days of making it, and when a workspace is deleted we delete it from every backup we hold.

Demo data only during early access. Do not upload real employee data. Use demo data only until we tell you the hosting plan is ready for it.

Sharing and processors

Google LLC (Firebase Authentication and Cloud Firestore) and Vercel Inc. (hosting, serverless functions and logs) are the only processors that hold workspace or account data. If your company opens Crossruled inside Microsoft Teams, Microsoft hosts the tab under your company's own Microsoft agreement; we send nothing to Microsoft. The exchange rate shown in the workspace is fetched by our server from a public service that publishes the European Central Bank reference rates (Frankfurter), without any personal data. There are no analytics or advertising providers.

Retention

Workspace content is kept for as long as the workspace is open. When a workspace closes, your company exports its data first, and we delete the workspace within 30 days of a written request from the owner, including every backup copy we hold, and confirm by email. If an evaluation has ended and nobody has asked us to keep or delete the workspace, we email the owner and delete it 90 days after the evaluation ended, giving at least 14 days' notice. Audit-log entries are kept for the life of the workspace as the security record of who changed what, and are not edited by anyone in the workspace, so an entry that names a person remains after that person's record is deleted. If the workspace owner instructs us in writing, we remove or mask that person's name in those entries within 30 days. Early-access requests are deleted 12 months after our last contact, or sooner if you ask. Error reports live in Vercel's logs, which on our current plan keep them for about one hour.

Your rights

What exists today, and how to use it. Access: your workspace owner or admin can export everything in Settings as JSON at any time; you can also write to us. Correction: HR, an admin or the owner edits any person's record in the workspace directly. Deletion: HR deletes a person's record in the workspace; an admin deactivates a login; a whole workspace or a whole account is deleted by us on written request from the workspace owner or from you. Export: the same JSON export, plus CSV of the reports. Requests about content your employer put in the workspace go first to your employer, who instructs us; requests about what you sent us directly come to us. We reply by email, usually within a few working days and in any case within 30 days.

Grievance and contact

Grievance Officer: Rajan Agarwal, Crossruled, Delhi, India. Email: codingrajan@gmail.com. The same address takes requests under India's Digital Personal Data Protection Act, GDPR requests, and every privacy or security question. Put "Grievance" in the subject if it is one, and name the workspace. We acknowledge a grievance within 3 working days and resolve it within 30 days of receiving it. If it concerns data your employer put in the workspace, we pass it to your employer within 3 working days and tell you we have done so. Cookies and browser storage are described on the cookie page; how we keep data safe is on the trust page. When this page changes, the date at the top changes with it.

Privacy policy | Crossruled