1. Information the platform collects
The platform collects only what it needs to do the job you asked it to do.
- Account information. Your name, email address, optional phone number and the role you selected at sign-up. Your password is stored only as a salted hash and cannot be read back.
- Records you create. Properties, tenancies, rent and deposit entries, maintenance requests, vendors, leads, deals, documents, tasks and similar operating records that you enter into a console.
- Files you upload. Documents attached to a property or record, together with the metadata you supply (name, category, status, notes).
- Enquiries. The name, phone number, email address, interest and message submitted through an enquiry form, along with the page it came from and the originating IP address.
- Orders. Products ordered, order status and the resources released to your account as a result.
- Usage counters. Aggregate counts such as how many times a listing was viewed. These are counters, not per-person tracking profiles.
- Security records. Failed sign-in counts, temporary lock state and an audit log of administrative actions.
2. Why it is collected
To operate your account, deliver what you have purchased, keep your records available to you, respond to your enquiries, and protect the platform against abuse. The platform does not sell personal information and does not use it to build advertising profiles.
3. How product suggestions work
Product suggestions come from a fixed rule set that maps your account role to specific catalogue entries. There is no machine learning, no automated profiling and no decision that produces a legal or similarly significant effect on you.
4. How uploaded files are handled
Uploaded files are stored outside the public web directory under a randomly generated name. They are not reachable by guessing a URL. Every download request is authorised against your account before the file is served. File type and size are validated on upload.
5. Cookies
The platform sets a session cookie so it can keep you signed in, and a CSRF token cookie so that form submissions can be verified as coming from you. Both are strictly necessary for the site to function. No advertising or third-party analytics cookies are set by this application.
6. Who can see your records
Records are scoped to the account that owns them. Where a record is deliberately shared — for example a handover record belongs to a tenancy, so both the tenant and the landlord or manager can see it — that sharing is part of the feature and is described where it applies. Administrators of this installation can access records for support and moderation; administrative actions are written to an audit log.
7. Retention
Operating records are retained while your account is active, because their value is precisely that they persist. You can delete records you created. Contact us to request deletion of your account.
8. Payments
This installation is running with the simulated payment provider, so no payment credentials are collected and no money moves. In production a real payment provider is connected through environment configuration, and card details are handled by that provider — they are never entered into or stored by TrustBrick.
9. Your choices
You can view and correct your profile at any time, export or delete records you created, and ask us to delete your account. Write to hr@trustbrick.co.in.