Shoris trust centre

Privacy, without the mystery.

This policy explains what the Shoris website collects when you request an ROI audit or deployment review—and what that information is used for.

Updated 14 July 2026

Plain-language policy

This page explains the current Shoris website and agent-scoping process. A signed client scope may add project-specific terms.

01

Effective date and scope

Effective 14 July 2026. This notice covers the public Shoris website, ROI Audit, private proposals, and deployment-enquiry forms. It is a transparency notice, not a claim of certification under the Digital Personal Data Protection Act, ISO 27001, SOC 2, or any other standard.

02

Information we collect

When you request an audit or contact us, we collect the information you choose to submit: name, business details, email, phone number, workload information, audit answers, and the report generated from them. Do not submit passwords, API keys, payment details, patient records, customer lists, identity documents, or other third-party sensitive data.

03

Purposes and contact

We use submitted information to generate and deliver the requested audit, create its private proposal, respond to the enquiry, evaluate whether a deployment is practical, prevent abuse, and maintain service security. A service reply by email, phone, or WhatsApp is not consent to unrelated promotional broadcasts.

04

Service providers and transfers

Hosting, storage, email, rate-limiting, analytics, and operational suppliers may process limited information for Shoris. Current suppliers may include Vercel, Supabase, Resend, Upstash, and PostHog where configured; their infrastructure may process data outside India under their own contractual and technical safeguards.

05

Retention and protection

Submission records are retained only while needed for the requested service, documented follow-up, security, dispute handling, or applicable legal obligations, then deleted or anonymised under the operating process in force. Privileged credentials remain server-side and production access is limited to authorised operators. A formal retention schedule is confirmed in each paid deployment scope.

06

Access, correction, deletion, and complaints

You may ask to access, correct, or delete information you submitted, or raise a privacy concern, subject to applicable legal and operational requirements. Use the contact form, select a privacy or security request, and include the business name or audit reference. Shoris will verify the requester before acting.

07

Legal operator details

The contracting legal name, registered address, tax details, and designated grievance contact must be confirmed in the written proposal or engagement document before paid work begins. Until those details are published here, do not treat this website alone as an invoice, contract, or proof of statutory registration.

Need a project-specific answer?

Share the workflow and the exact data or system concern you want reviewed.

Contact Shoris