How Tracery looks after your data
What we keep about the people who use Tracery, why we keep it, for how long, and how to use your rights under the Digital Personal Data Protection Act, 2023.
Last updated 6 October 2026
Who we are
Tracery is run by Qbler Technolabs Private Limited, Kochi, Kerala. Two kinds of data live in it, and who answers to you depends on which.
Your Tracery account
Qbler decides how the data about you as a user is used, so Qbler is answerable to you for it. This notice is about that data.
Records in a business's books
Each business decides about the records it keeps on Tracery, such as its employees, clients and vendors. Qbler keeps and works on them only for that business. Ask the business about those records.
Tracery is for businesses and the people who work with them. It is not meant for anyone under 18, and we do not knowingly keep an account for a child.
What we keep
Only what Tracery needs to let you in and do your work. We never ask for your password, because there is none.
Your name and email
Given by the business that invited you. You sign in with the email, and can change your name yourself.
Your sign-ins
When you signed in, with a code or a passkey, your network address, your browser, and the rough place it came from, such as Kochi, India.
Your devices
The browsers you use and when each was last used, so we can tell you when your account opens somewhere new.
Your passkeys
The public half of each passkey and its name. Your fingerprint or face never leaves your device.
Your businesses
The businesses you belong to, your role in each, and when you were invited and joined.
Notices and emails
The notices and emails we sent you, and the kinds of email you turned off.
Your privacy choices
The privacy requests you send, our answers, and the people you name to act for you.
What you do in a business
Changes you make are kept in that business's change history with your name. That history belongs to the business.
Why we use it
For these purposes only. We do not sell your data or use it for advertising.
To let you in, and keep others out
Signing you in, warning you of a sign-in from a new device, and letting you sign devices out.
To open the businesses that invited you
With the role and access each business gave you, and nothing more.
To tell you what your work needs
Notices in the app and emails, such as approvals waiting for you. You choose which emails come.
To keep what the law asks, and answer you
Keeping records for the time the law sets, and answering your privacy requests.
Tracery uses only the cookies it needs to keep you signed in and to know your device again. There are no tracking or advertising cookies. This website sets no cookies of its own, and keeps the look you choose, paper or blueprint, in your browser. Cloudflare, which serves both, may set a cookie it needs to tell people from bots, and measures how fast pages load, without cookies and without keeping your network address.
How long we keep it
The DPDP Rules ask us to keep records of how your data was used for at least a year. After that, we remove them.
| What | How long |
|---|---|
| Your account | While it is open, then one year after you close it. Then it is erased. |
| Your sign-ins and devices | One year from each sign-in or last use. |
| Emails we sent you | Their words for 30 days (90 if one could not be sent). Who and when, for one year. |
| Notices in the app | 90 days after you read them, and one year at most. |
| Privacy requests and the people you name | While your account is open, then one year after you close it. |
| Records in a business's books | As long as the business keeps them. The law asks a company to keep its books for eight years. |
Where it is kept
Tracery runs on Cloudflare. These are the companies that process data for us, what they do, and where.
Cloudflare, Inc.
Runs Tracery and keeps its data: the app and its servers, the databases, stored files, sending email, printing PDFs and the check on the sign-in page that a person is not a bot.
Where: Cloudflare's Asia Pacific region, which may be outside India, and its network wherever a person uses Tracery from.
How it is kept safe
Kept apart
Each business's books are kept in a database of their own, and its files away from the books. Data travels between your device and Tracery over an encrypted connection.
Opened only by those let in
Only the people a business lets in can open its books, each as far as their role allows. Our staff read them only through a support request an owner approves, for the hours the owner allows.
No passwords to steal
You sign in with a code sent to your email or with a passkey. A sign-in ends after seven days unused, and you can sign out any device.
No way of storing or sending data is completely secure, so we cannot promise that yours will never be reached by someone it should not be. If your data is ever caught in a breach, we tell you without delay: what happened, what it may mean for you, and what we are doing about it.
Your rights
Use any of these from the Privacy page of your account, or by writing to us.
See your data
Download a copy of everything we keep about you, at any time, from your Privacy page.
Correct or update it
Change your name yourself. For anything else, send a privacy request.
Have it erased
Close your account, or ask us to erase some of your data. We keep only what the law needs kept.
Withdraw your consent
Close your account from your Privacy page, as easily as you signed in. You can also stop any email you are allowed to turn off.
Name someone you trust
Name up to 3 people who may use these rights for you if you cannot, through illness or death.
Raise a grievance
Tell us if you are unhappy with how your data was handled. Every grievance gets a reference and an answer.
Or write to privacy@tracery.in from the email you sign in with.
The Act also asks something of you: not to pretend to be someone else, to give only true details when you ask for a correction or erasure, and not to raise a false or frivolous grievance.
How we answer
You get a reference
Each request and grievance gets one, sent to your email, so you can follow it up.
We answer within 90 days
By email, and on your Privacy page. Most answers come much sooner.
Not satisfied?
After you have raised a grievance with us, you may complain to the Data Protection Board of India.
When this notice changes
We may change this notice as Tracery or the law changes, and the date at the top says when it last changed. When a change affects how your data is used, we tell you by email or in Tracery before it applies.
Questions
Write to Qbler Technolabs Private Limited's privacy contact at privacy@tracery.in, and quote your reference if you have one. For any other complaint about Tracery, write to our Grievance Officer at grievance@tracery.in. The terms of service say how complaints are handled.