Back to Home

Privacy Policy

Version 1.0 | Effective Date: April 1, 2026 | Last Updated: March 2026


1. Who We Are

KnitTrace (“we”, “us”, “our”) is a B2B SaaS platform for the global textile industry operated by Time In Software, registered in India. This Privacy Policy explains how we collect, use, store, and protect your personal data when you use our platform at knittrace.com.

Contact: timeinsoftware@gmail.com


2. Data We Collect

2.1 Data You Provide

DataWhen CollectedPurpose
Full name, email, passwordSignupAccount creation and authentication
Company name, GST/Tax ID, address, phone, contact emailOnboardingCompany verification, tax compliance
Production mode selections, knitting types, business typeOnboardingService configuration
Order details, quantities, stage logs, timestampsPlatform usageCore traceability service
Chat messages, RFQ content, support ticketsPlatform usageMessaging, marketplace, support
Company logos, gallery photos, garment imagesPlatform usageProduct showcasing, document verification
Billing period preference, plan selectionOnboarding/BillingSubscription management

2.2 Data We Collect Automatically

DataPurpose
IP address, device info, browser typeSecurity monitoring, anomaly detection
Login timestamps, activity logsAudit trail, fraud prevention
Factory lat/lng (if provided)Factory mapping on platform
Driver GPS pings (transport mode only)Live transport tracking

2.3 Data We Do NOT Collect

  • Credit card or bank account numbers (handled entirely by Razorpay/Stripe)
  • Biometric data
  • Personal health data
  • Political or religious affiliation
  • Data from individuals under 18 (B2B platform only)

3. How We Use Your Data

PurposeLegal Basis
Provide traceability, production logging, and marketplace servicesContract performance
Authenticate users and manage sessionsContract performance
Process payments via Razorpay/StripeContract performance
Validate GST numbers via GSTZenLegal obligation
Send transactional emails (invoices, alerts, password resets)Contract performance
Detect anomalous logins, bulk exports, suspicious activityLegitimate interest
Generate Textile Passports (aggregated, public)Contract performance + Consent
Live transport tracking (GPS)Consent
Improve platform performance with aggregated analyticsLegitimate interest

We do not use your data for advertising, profiling, or automated decision-making that produces legal effects.


4. Data Sharing

4.1 Service Providers (Sub-Processors)

ProviderData SharedPurpose
Supabase (AWS Mumbai)All platform dataDatabase, auth, file storage
VercelRequest logs, IP addressesHosting, CDN
CloudflareIP addresses, request headersDDoS protection, DNS
UpstashCached query results (no PII)Redis caching
RazorpayTransaction IDs, company namesIndia payment processing
StripeTransaction IDs, company namesInternational payment processing
Resend (AWS SES)Email addresses, email contentTransactional emails
GSTZenGST numbersGSTIN validation (India)
Google MapsCoordinates, addressesPlaces Autocomplete, Directions

All sub-processors have Data Processing Agreements (DPAs) in place.

4.2 What We Never Do

  • Sell personal data to third parties
  • Share production data between competing companies
  • Provide bulk data access to advertisers
  • Share individual user behaviour with analytics platforms

5. Data Storage & Security

AspectDetail
Primary storageSupabase (AWS Mumbai, ap-south-1)
Encryption at restAES-256
Encryption in transitTLS 1.3 on all connections
Field-level encryptionpgcrypto on GST numbers, phone numbers, emails
Password hashingbcrypt via Supabase Auth
Access controlRow Level Security (RLS) on all database tables
Two-Factor AuthTOTP (mandatory for Admin, optional for Exporter/VI)
Session managementSingle active session per user
Rate limiting100 requests/min per IP via Vercel Edge Middleware
File uploadsMagic byte validation on all uploads
Audit trailImmutable append-only activity logs
Webhook verificationCryptographic signature validation (Razorpay/Stripe)
BackupsDaily automated backups, 7-day retention

6. Data Retention

Data TypeRetained ForDeletion Method
Account dataDuration of accountHard delete on account deletion
Production logs7 years after order completionAuto-delete (tax/legal compliance)
Transport GPS pings90 daysAuto-purge
Activity/audit logs1 yearAuto-archive, then delete
Chat messagesDuration of accountHard delete on account deletion
Financial/billing records7 yearsAuto-delete (tax compliance)
Textile PassportsIndefiniteCompany names anonymised on account deletion
Support ticketsDuration of account + 1 yearHard delete
Uploaded media/filesDuration of accountHard delete from storage

7. Your Rights

RightHow to Exercise
Access your dataSettings > Privacy > Download My Data
Correct inaccurate dataEdit Profile / Company Settings
Delete your account and dataSettings > Privacy > Delete Account (30-day cooling-off)
Export data in JSON/CSVSettings > Privacy > Export Data
Restrict processingEmail timeinsoftware@gmail.com
Object to processingEmail timeinsoftware@gmail.com
Withdraw consent (e.g., GPS tracking)Settings > Privacy > Manage Consent

All requests are fulfilled within 30 days.

Account deletion process: 30-day cooling-off period during which you can cancel deletion. After 30 days, personal data is permanently deleted, production/order data is anonymised (for traceability integrity), and all media files are removed. Account deletion is blocked if you are the sole owner of a company with active subscriptions or pending orders until ownership is transferred or orders are completed.


8. Cookies

CookiePurposeDurationConsent Required
sb-access-tokenAuth sessionSessionNo (essential)
sb-refresh-tokenAuth refresh7 daysNo (essential)
themeLight/Dark mode1 yearNo (functional)
cf_clearanceCloudflare bot check30 minNo (security)

We do not use advertising cookies, tracking pixels, or third-party analytics cookies.


9. Cross-Border Transfers

Primary data storage is in Mumbai, India. Where data is transferred internationally (e.g., email delivery via Resend in the US, Stripe payment processing), we rely on Standard Contractual Clauses (SCCs) and explicit user consent as applicable under GDPR, KVKK, PIPL, and DPDPA.


10. Children's Privacy

KnitTrace is a B2B platform for business use only. We do not knowingly collect data from anyone under 18. If we discover a minor has created an account, we will delete it immediately.


11. Changes to This Policy

Material changes are communicated via email 30 days before taking effect. Continued use after the effective date constitutes acceptance. Previous versions are available upon request.


12. Contact

For all privacy-related inquiries, data requests (access, deletion, export), and security incidents:

Email: timeinsoftware@gmail.com

Phone: +91 88708 72911

Registered Address:
Time In Software
B2, 4F1, Parsn Antara, Nanjundapuram Road,
Ramanthapuram, Coimbatore, Tamil Nadu, 641036
India

Website: timeinsoftware.com