for flooring contractors
The two products and this website

Privacy

Version 1.1, 8 September 2026

What we hold, where we hold it, and what you can ask us to do about it.

This covers two separate things: the website at halcyon.uno, and the two products, Halcyon Quote and Halcyon Crew. They collect very different things, so they are set out separately.

P1 Who we are

Halcyon is a proprietorship of Sanjith Dhandapani, based in Chennai, Tamil Nadu, India. For anything in this policy, write to sanjith@halcyon.uno or message +91 91768 88661. One person reads both.

P2 The website

P2.1 There is no form on our site. We removed it. The contact section writes a WhatsApp message for you and hands it to WhatsApp. Nothing you type into it reaches us until you press send in WhatsApp yourself, and at that point it is an ordinary WhatsApp message, held under WhatsApp’s own rules and its own encryption, not on our website.

P2.2 What we see when you message us. Your WhatsApp display name, your number, and what you wrote. We keep the conversation in our WhatsApp Business account for as long as we are talking, and afterwards as a record of what was agreed.

P2.3 What our hosting provider records. Our site is hosted on Vercel. Like every web host, it keeps a short server log of requests: an IP address, the page asked for, the time, and the browser string. We do not use those logs for anything and we do not join them to anything else.

P2.4 Advertising tags and analytics. There is no advertising tag and no analytics on this site today. Nothing measures you here: no Meta pixel, no Google Analytics, no third-party script of any kind. The two slots in our configuration for a Meta pixel and for Google Analytics are empty, and while they are empty nothing loads. If we switch either of them on, we will name the tool in this policy and say what it records before it goes live, and what is written here about it will apply from that day.

P2.5 Cookies. The site sets no cookies of its own today. If we add analytics, whatever it sets will be listed here before it goes live.

P3 Halcyon Quote

P3.1 The people who sign in. Name, role, and a four digit PIN. There is no email address and no password. Every PIN is stored as a bcrypt hash, so what is stored cannot be turned back into the PIN, and the table it sits in cannot be read with the key the app ships with.

P3.2 The work itself. Your customers’ names, their site addresses, their contact details and their GSTINs. Your rate card, your catalogue and your systems. Every quotation and every revision, with its serial number, its line items, its rates, its tax working and its totals. The PDF that went out. Who created it, who amended it, and when.

P3.3 Why we hold it. Because it is the product. There is no secondary use.

P4 Halcyon Crew

P4.1 The people who sign in. Supervisor and manager names, their role, their phone number if you enter one, and their four digit PIN. In both apps that PIN is stored as a bcrypt hash, so what is stored cannot be turned back into the PIN. The table the PINs sit in cannot be read with the key the app ships with, every sign-in check runs inside the database, and the app refuses to let two people who are switched on hold the same PIN.

P4.2 Location. The phone’s location is recorded at four moments and no others: when a supervisor starts the work day, when they check in at a site, when they check out, and when they end the work day. That is it. The app does not follow anybody between those moments, it records no location while it is closed, and it takes no location in the background. The distance flag on a check-in is worked out from that single check-in point against the site’s own recorded location.

P4.3 The map of the day’s travel. The route shown on the dashboard, and the kilometres in the travel record, are drawn from those four points and from nothing else. There is no continuous tracking and no background location, so the map is a line joining four recorded moments rather than a trace of where a phone has been.

P4.4 Photographs. Photographs taken deliberately at check-in and at check-out, with the time they were taken. People appear in some of them, because that is what a site photograph is.

P4.5 The rest of the record. Plan, team, headcount, work done, stage reached, stock left, quality and safety issues, the written progress assessment and its working.

P4.6 What is not collected. No microphone. No camera except when somebody presses the button. No contacts. No messages. No background location. No health data. No biometrics.

P5 Where it is stored

P5.1 In India. All product data sits with Supabase, in its Mumbai region, ap-south-1. Photographs sit in the same region.

P5.2 One project per customer. Each customer gets their own Supabase project. No two customers share a database. There is no shared table with everybody’s quotations in it.

P5.3 Backups. Supabase takes the backups, for disaster recovery, and holds them in the same Mumbai region as the database they came from. They do not leave India and they are not a service we sell you: your own export, which you can take any day, is the copy to rely on.

P5.4 The website. The site itself is hosted outside India by Vercel, and its server logs sit wherever that provider keeps them. No customer product data is on the website.

P6 Who can see it

P6.1 Your own people. Whoever you have set up, seeing what their role allows. Owners see everything. Salespeople in Halcyon Quote see their own quotations. Supervisors in Halcyon Crew see the sites they are working.

P6.2 Us. The proprietor of Halcyon, and nobody else at present. We open a customer’s database only to run the service, to fix a fault, to do work the customer asked for, or where the law requires it. We keep a written note of each time we do.

P6.3 Our hosting provider. Supabase, under its own contract, its own staff controls and its own security. It is the infrastructure the software runs on.

P6.4 Nobody else. We do not sell data. We do not share it with advertisers, brokers, insurers or anybody in your trade. We do not use one customer’s data to do anything for another customer. We do not use customer data to train anything.

P6.5 If the law requires it. We will tell you before we hand anything over, unless the law forbids us from telling you.

P7 How long we keep it

P7.1 While your account exists. For as long as you are a customer, and afterwards, because we do not delete accounts for non-payment.

P7.2 We delete only on your written instruction. Then within thirty days, confirmed in writing, and it cannot be undone.

P7.3 The one other route. If we ever cannot keep a closed account open any longer, we ask you first. We delete an account only on your written instruction, after ninety (90) days’ written notice with your full extract sent to you first, and never inside the first twelve months after your last payment. Clause 6.6 of the agreement is the same sentence.

P7.4 WhatsApp conversations and email. Kept as our record of what was agreed, for as long as we might need to show what was agreed.

P8 Rights, and whose they are

P8.1 Whose data it is. Under the Digital Personal Data Protection Act 2023, the company that decides what goes into an account is the Data Fiduciary and Halcyon is its Data Processor. So for anything inside a customer’s account, including a supervisor’s location and photographs, the request goes to the customer’s own office first, not to us.

P8.2 What a supervisor or a customer’s customer can ask for. Under that Act, a person can ask what is held about them and how it is used, ask for it to be corrected or completed, ask for it to be erased where it is no longer needed, raise a complaint and have it dealt with, and nominate somebody to act for them. Those requests go to the employer or the company that holds the record. We will help our customer answer inside the time the law gives them.

P8.3 What a customer can ask us for directly. An export any day from inside the software. A full extract of everything, including original photographs and a database dump, within seven working days of asking, at no charge. Deletion, on a written instruction. An account of when we last opened their database and why.

P8.4 Where to write. sanjith@halcyon.uno, or the WhatsApp number in the Service Order. We reply within twenty four hours on working days and we will not ask you why you want it.

P9 Which data protection law is in force today

The Digital Personal Data Protection Act 2023 was passed in 2023 and its rules were notified on 14 November 2025, but its substantive duties are being switched on in phases. The notice and consent duties, the security safeguards, the breach reporting duty and the rights listed in P8.2 come into force on 14 May 2027. Until then, the law that binds us is section 43A of the Information Technology Act 2000 and the rules made under it in 2011, and we comply with those. We are building to the DPDP duties now so that we meet them from the day they start, and this policy will be rewritten before that date. We hold no certification and we have not been audited by anybody, and we are not going to imply otherwise.

P10 Children

Neither product is for anybody under 18. We do not knowingly hold data about a child. If a customer sets up a user under 18, that is their responsibility and their notice to give.

P11 Changes to this policy

We will post a new version here with a new date, and we will email every customer when anything material changes. Nothing in a new version reduces a promise made in the agreement.

P12 Complaints

Write to us first, at the address in P1. If we cannot settle it, the Data Protection Board of India is the body the DPDP Act sets up for complaints, and it is already constituted.

This policy is written to be true today and true when the DPDP Act’s substantive duties start on 14 May 2027. Where the two differ, section P9 says which law is actually in force.

Questions: WhatsApp +91 91768 88661, or write to sanjith@halcyon.uno.

The agreement

Talk to us.

WhatsApp

We will write back on WhatsApp.

What do you do?
Message us on WhatsApp