What we collect, why we collect it, who it is shared with, and what you can ask us to do with it.
Last updated 4 August 2026
The short version. Spyne is an HR system, so most of the
personal data in it is not ours — it is your employer's, and we handle it on
their instructions. We do not sell data and we run no advertising trackers.
Inside the product we set only the cookies it needs to work; on our public
pages we also use Google Analytics, but only if you accept it, and never
on any page you reach while signed in.
1. Who we are
Spyne is a work operating system for daily delivery, attendance, leave and
payroll, operated by [Registered entity name], [Registered office address], Ahmedabad, Gujarat, India
("Spyne", "we", "us"). This policy covers our public website and the Spyne
application.
You can reach us about anything in this policy at
hello@spyne.app.
2. Our role, and your employer's
Spyne is sold to organisations, and most of the personal data inside it
describes their employees. That split decides who you should ask about what,
so it is worth being precise.
Where your employer is the customer — attendance records,
leave, salary structures, payslips and employee profiles — your employer
decides what is collected and why. They are the data fiduciary (controller);
we are the data processor, acting on their documented instructions. If you
want your record corrected or explained, start with your organisation's
Spyne administrator. If you come to us first, we will point you to them and
let them know you asked.
Where we are the customer-facing business — this website,
enquiries, sign-ups, billing and support — we decide the purposes, and we are
the data fiduciary. This policy governs that part directly.
3. What we collect
Account and organisation data
Your name, work email address and role within your organisation.
Your organisation's name, and when its trial or subscription started.
A one-way hash of your password. We never store, log or transmit the password itself, and nobody at Spyne can read it.
Sign-in metadata: timestamps, sign-in counts and the IP addresses used, kept to detect and investigate unauthorised access.
Employee records entered by your employer
An administrator at your organisation can store the following about you. All
of it is entered by them, not collected by us:
Employee number, designation, joining date and employment status.
Contact details, date of birth, address, and an emergency contact.
Government identifiers — Aadhaar and PAN — and bank account number, IFSC code and account holder name, needed to run payroll. These are encrypted at rest.
Salary structure and its history, deductions, and issued payslips.
Attendance: check-in and check-out times, the IP address the punch came from (read by our server from the request, never reported by your browser), and, where your employer has enabled it and your device permits it, the location your browser reports at the moment you punch.
Leave requests, approvals and balances, and the reasons recorded for administrative edits.
Tasks assigned to you and the activity trail on them.
Billing data
Subscription plan, status, renewal dates and amounts charged.
We do not receive or store card details. Payments are handled by Razorpay; your card is entered on their hosted checkout and never reaches our servers. We store their reference identifiers and the outcome of the payment.
Technical data
Server logs: request paths, response codes, timestamps, IP address and browser user agent. Passwords, tokens, session identifiers and other sensitive fields are filtered out before anything is written to a log.
Messages you send through the contact form, and your email address so we can reply.
4. Why we use it
Purpose
Data used
Basis
Providing the service — daily plans, attendance, leave, payroll
Account and employee records
Performance of our contract with your organisation; your employer's own basis for employment records
Authentication and account security
Credentials, sign-in metadata, IP addresses
Legitimate interest in keeping accounts secure
Billing and collecting payment
Subscription and payment records
Performance of contract; legal obligation to keep financial records
Support and answering enquiries
Contact details and message content
Legitimate interest; your consent when you contact us
Statutory payroll and tax records
Payslips, deductions, salary history
Legal obligation
Keeping the service running and diagnosing faults
Server logs, error reports
Legitimate interest
We do not use your data to train machine learning models, we do not profile
you for advertising, and we do not sell or rent personal data to anyone.
5. Cookies and sessions
Inside the product — every page you reach while signed in — Spyne sets only
cookies that are strictly necessary for it to work. There are no advertising
or cross-site tracking cookies anywhere, and we sell nothing to anyone.
On our public pages (the marketing site) we use Google Analytics
to understand which pages people find useful. It is off until you accept it:
nothing is loaded from Google and no analytics cookie is set unless you choose
"Accept" on the cookie bar. Choosing "Reject analytics" is remembered too, and
you can change your mind at any time —
.
Analytics never runs on the signed-in product, so your attendance, payroll and
profile pages are never reported to Google.
Cookie
Purpose
Lifetime
_humive_lms_session
Keeps you signed in during a visit and carries the anti-forgery token that protects forms. HttpOnly and SameSite=Strict, and Secure in production, so scripts cannot read it and another site cannot send it.
30 minutes of inactivity
remember_user_token
Set only if you tick "Keep me signed in", so you are not asked to sign in on every visit. Signing out deletes it.
2 weeks
cookie_notice
Records that you have seen the cookie notice, so it is not shown on every page. Set only where analytics is switched off entirely and the bar is a notice rather than a choice.
1 year
cookie_consent
Records whether you accepted or rejected analytics, so we do not ask again on every page — and so a rejection is honoured on your next visit.
6 months
_ga, _ga_<id>
Set by Google Analytics on our public pages, and only if you accept. They distinguish one visitor from another so we can count visits and see which pages are read. Rejecting, or clearing them in your browser, stops this.
Up to 2 years, or until you reject or clear them
The first three are strictly necessary and cannot be switched off while using
the product — blocking the session cookie will stop sign-in from working. The
Google Analytics cookies are not necessary, which is why they are set only
after you accept, and why rejecting them leaves the site fully working. You can
also block or delete any of them in your browser. If we ever add another cookie
that is not strictly necessary, we will ask for your consent before setting it,
and update this table.
6. Who we share it with
We share personal data only with the processors we need to run the service:
Razorpay — payment processing for subscriptions. They receive billing details directly from you at checkout.
Google Analytics — visit statistics for our public pages only, and only if you accept analytics cookies. Google receives the page you viewed, roughly where in the world you are, and your device and browser type. It receives nothing from the signed-in product: no employee, attendance or payroll data ever reaches it.
Our hosting and infrastructure provider — runs the application and its database.
Each is bound by contract to use the data only to provide their service to us.
Beyond these, we disclose personal data only where the law requires it, or to
establish or defend a legal claim. If Spyne is ever acquired or merged, we will
tell customers before their data moves, and the buyer stays bound by this policy
until they publish one that is no less protective.
7. How long we keep it
While your organisation's account is active, we keep the data it holds so the product works — historical attendance and payslips are the point of the product, not a by-product of it.
Payslips are immutable snapshots by design. Once issued, a payslip is never recalculated, so this year's salary change cannot rewrite last year's payslip. Your employer decides how long they are retained, subject to Indian payroll and tax record-keeping requirements.
Audit trails — who edited an attendance record, when, and why — are append-only and kept for the life of the account. That is what makes them worth having.
After an account closes, we delete or irreversibly anonymise personal data within [retention period, e.g. 90 days], except where we must keep financial records to satisfy tax and accounting law.
A lapsed subscription is not a deletion. When a trial ends or a subscription is cancelled, access is blocked but nothing is deleted, so you can still resume or ask for an export.
8. How we protect it
All traffic is encrypted in transit with TLS, with HTTP Strict Transport Security enabled in production.
Aadhaar, PAN and bank account numbers are encrypted at rest at the application layer, on top of the database's own protections.
Passwords are stored only as bcrypt hashes, and are never logged.
Access is role-based and scoped to your own organisation. Every request is checked against an authorisation policy, not merely hidden from the interface.
Administrative edits to attendance and payroll require a reason and write an append-only audit row recording who, when, why, and the previous values.
Sign-in is rate limited, accounts lock after repeated failed attempts, and sessions expire after 30 minutes of inactivity.
Attendance IP addresses are read server-side from the request and never accepted from the browser — precisely because that is the field someone would want to fake.
No system is perfectly secure. If a breach affects your personal data we will
notify the affected organisations and the relevant authority without undue
delay, with what we know and what we are doing about it.
9. Your rights
Subject to the law that applies to you, you can ask to:
Know what personal data we hold about you, and why.
Correct data that is wrong or incomplete.
Delete data we no longer have a lawful reason to keep.
Receive a copy of your data in a portable format. Administrators can export records as CSV from inside the product at any time.
Object to or restrict a particular use, or withdraw consent where our use rests on consent.
Nominate someone to exercise these rights for you if you are unable to.
If the data belongs to your employer's account, send the request to their Spyne
administrator — we act on their instructions rather than overriding them, and we
will tell them you asked. For data where we are the fiduciary, write to
hello@spyne.app and we will respond
within 30 days. There is no charge unless a request is repetitive or excessive.
10. Where data is stored
Spyne's application and database are hosted in [hosting region]. Where a
processor handles data outside India, we rely on contractual safeguards and
send only what that processor needs. We will update this section if the hosting
region changes.
Google Analytics is the one processor that operates outside India by design:
if you accept analytics cookies, the visit data described in section 6 is
processed by Google on servers in the United States and elsewhere, under
Google's own terms and safeguards. Rejecting analytics means no such transfer
happens, and no data from the signed-in product is transferred to Google in
either case.
11. Children
Spyne is a workplace tool and is not directed at children. We do not knowingly
collect data about anyone under 18. If you believe a child's data has been
entered into Spyne, tell us and we will remove it.
12. Changes to this policy
We will update this page when the product or the law changes, and move the
"last updated" date at the top. If a change materially affects how we use
personal data, we will email account administrators before it takes effect
rather than relying on you to re-read the page.
13. Contact and grievances
Questions, requests and complaints go to
hello@spyne.app, or by post to
[Registered entity name], [Registered office address], Ahmedabad, Gujarat, India.
Our Grievance Officer under the Digital Personal Data Protection Act, 2023 is
[Grievance Officer name], reachable at the same address and email. If our
response does not satisfy you, you may complain to the Data Protection Board of
India, or to your local supervisory authority if you are in the UK or EU.
Spyne uses the cookies it needs to work — keeping you signed in and keeping
your session secure. We would also like to use Google Analytics to see which
pages people find useful. That one is your call, and nothing is set until you
accept. No advertising cookies, ever.
Read our privacy policy.