Privacy Policy

Last updated: April 18, 2026

support@boostserv.io

This Privacy Policy explains how BOOSTPAD BUSINESS SOLUTIONS (OPC) PRIVATE LIMITED ("BoostServ") collects, uses, and protects your personal data when you use boostserv.io.

01. Data Controller

BOOSTPAD BUSINESS SOLUTIONS (OPC) PRIVATE LIMITED

Plot No 211, Okhla Phase 3, Road 1,
Okhla Industrial Estate, New Delhi,
South Delhi – 110020, Delhi, India

CIN: U62011DL2025OPC443429

GSTIN: 07AANCB2883L1Z4

privacy@boostserv.io

02. Data We Collect

Account data

  • Name and email address
  • Password, stored only as a salted scrypt hash — never in plain text (omitted if you sign in with Google)
  • Two-factor authentication secret (TOTP) and backup codes, encrypted at rest
  • Session tokens used to keep you logged in on your devices

If you sign in with Google

When you choose "Sign in with Google", Google shares the following information with BoostServ under the openid, email, and profile OAuth scopes:

  • Your Google account ID (a stable internal identifier)
  • Your full name
  • Your email address (and whether Google has verified it)
  • Your profile picture URL

Scope of access: BoostServ does not access your Gmail, Google Drive, Google Contacts, Calendar, or any other Google service. The scopes we request are sign-in only — they grant identity verification, not access to your Google data. You can revoke this access at any time at myaccount.google.com/permissions.

Billing data

  • Billing name, billing address, country
  • Registered company name (for B2B invoices)
  • GSTIN for Indian business customers (optional, for GST input-tax credit)
  • Subscription plan, term purchased, and payment status
  • Invoice metadata (FY-scoped invoice number, payment reference, CGST/SGST/IGST split)

We never store card details. Full card, UPI, net-banking, and bank data is handled directly by our payment processors (Razorpay and PayPal) on their own PCI-DSS compliant infrastructure. We only receive a payment reference and the fact that the payment succeeded — never the card number, CVV, or UPI handle.

Setup & product data

  • The IP address assigned to you.
  • Domains you add and DNS records configured
  • Mailbox metadata (addresses, quotas, display names)
  • Mailbox passwords, encrypted reversibly so you can retrieve them
  • Operational logs
  • IP addresses of your logins (for security and fraud prevention)
  • User-agent strings
  • Audit trail of state-changing actions (domain added, mailbox created)

03. What We Do Not Access

We do not access, read, or scan the content of emails sent from or received by your mailbox. Your email stack runs on your dedicated setup under our management, but message bodies are your private data.

Exception

If we receive a formal abuse report (phishing, malware, etc.) we may access specific messages solely to investigate the reported violation, as permitted by our Acceptable Use Policy.

04. How We Use Your Data

  • To provide and operate the Service
  • To process payments and issue invoices
  • To authenticate logins and prevent unauthorized access
  • To send transactional emails (account, billing, service notifications)
  • To investigate abuse reports and comply with legal obligations
  • To send occasional product updates — you may opt out from your account settings

05. Legal Basis (GDPR / UK GDPR)

Where GDPR applies, we process your personal data under the following legal bases:

  • Contract — to deliver the Service you signed up for
  • Legal obligation — to retain billing records as required by tax law
  • Legitimate interests — security, fraud prevention, and improving the Service
  • Consent — for non-essential communications (withdrawable at any time)

06. Sub-processors

We use the following third-party providers to operate the Service. Each is bound by its own data-protection commitments:

  • Cloudflare, Inc. (USA) — Authoritative DNS
  • Chargebee Inc. (USA) — subscription billing and invoicing
  • Razorpay Software Private Limited (India) — payment processing for customers paying in INR (UPI, cards, net banking) and for international customers paying in USD by card
  • PayPal Holdings, Inc. (USA) — payment processing for international customers paying in USD via PayPal wallet or card
  • Resend Inc. (USA) — transactional email delivery (signup confirmations, password resets, invoice receipts, renewal reminders)
  • Google LLC (USA) — OAuth sign-in only, if you choose "Sign in with Google". We receive your Google account ID, name, email, and profile picture — nothing more. We do not access Gmail or any other Google service.

Current list available at privacy@boostserv.io. We notify customers by email at least 30 days before adding a new sub-processor.

07. International Data Transfers

Because our sub-processors are located in multiple countries, your personal data may be transferred to and stored in jurisdictions outside your country of residence — including the United States and the European Union. We rely on Standard Contractual Clauses (SCCs) and equivalent safeguards where required to protect transfers.

08. Your Rights

Depending on your jurisdiction, you may have the following rights regarding your personal data:

  • Access — request a copy of the personal data we hold about you
  • Correction — ask us to correct inaccurate or incomplete data
  • Deletion — ask us to delete your data (subject to legal retention requirements)
  • Export — receive a copy of your data in a portable format
  • Withdrawal of consent — where we process on consent, you may withdraw at any time
  • Complaint — lodge with your data protection authority (India: Data Protection Board under DPDP Act 2023; EU: your national supervisory authority; UK: ICO)

Response time

Email privacy@boostserv.io to exercise any right. We respond within 30 days.

09. Retention

  • Account & setup data — deleted within 30 days of cancellation
  • Billing records & invoices — retained for 7 years as required by Indian tax law (Income Tax Act, GST Act)
  • Security & audit logs — retained for 12 months
  • Abuse investigation data — retained only as long as necessary, up to 2 years

10. Security

  • Passwords are hashed with salted scrypt (never stored or transmitted in plain text)
  • All traffic to and from the Service is encrypted with TLS 1.2 or higher
  • Two-factor authentication (TOTP) is available on every account
  • Admin access is limited to a small number of authorized personnel
  • Regular security reviews and dependency audits

Breach notification

No internet service can be made perfectly secure. We will notify affected users promptly (within 72 hours where required by law) of any confirmed breach of personal data.

11. Cookies

We use strictly necessary cookies plus limited analytics and ad attribution scripts to measure site performance and conversion events (for example: signup and checkout completion).

  • Session cookies (set by better-auth) — keep you logged in across pages. Expire 7 days after last activity.
  • boostserv-region — remembers whether to show you INR (India) or USD (rest of world) pricing. Set based on your first visit, expires in 30 days.
  • CSRF-protection cookies — short-lived tokens used to protect account actions from cross-site request forgery.
  • Analytics & attribution tags — Microsoft Clarity and Meta Pixel may set browser storage identifiers to help us understand visits, user journeys, and ad campaign effectiveness.

12. Children

The Service is not intended for children under 18. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, email privacy@boostserv.io and we will delete it.

13. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be notified by email at least 15 days in advance. The "Last updated" date at the top of this page reflects the latest revision.

14. Contact

BOOSTPAD BUSINESS SOLUTIONS (OPC) PRIVATE LIMITED

Plot No 211, Okhla Phase 3, Road 1,
Okhla Industrial Estate, New Delhi,
South Delhi – 110020, Delhi, India

CIN: U62011DL2025OPC443429

GSTIN: 07AANCB2883L1Z4

privacy@boostserv.io