Privacy Policy
Last updated 21 July 2026
Opslane is an internal request and approval tool. Companies use it to handle reimbursements, leave, software access and similar requests, which means we hold information about your employees on your behalf. This page explains exactly what that involves.
Who is responsible for your data
When your company signs up, your company is the data fiduciary for the employee information in its workspace, and Opslane acts as a data processor — we store and process that data on your instructions and do not use it for our own purposes. If you are an employee and want your information changed or removed, please contact your own admin first; they control the workspace.
What we collect
| Data | Why |
|---|---|
| Name, work email, department, role | To identify who raised and who approved each request |
| Company name | To separate your workspace from every other company |
| Request contents — title, description, amounts, dates | The core function of the product |
| Comments and approval decisions | To provide an audit trail |
| Authentication data — hashed password, session tokens | To keep your account secure |
We do not collect bank account numbers, card details, government identifiers, salary data, or biometric information. Please do not put them into request descriptions.
Where your data is stored
All application data is stored in Mumbai, India, in a managed PostgreSQL database provided by Supabase. Your data does not leave India in the normal course of operating the service.
Who we share it with
We do not sell your data, and we do not use it for advertising. We rely on a small number of service providers to run Opslane:
- Supabase — database, authentication and file storage, hosted in Mumbai (ap-south-1).
- Vercel — application hosting and content delivery.
These providers process data only to deliver their service to us. We will update this list if it changes.
How your data is separated
Every table in our database enforces row-level security, so a query from one company physically cannot return another company's rows. This is enforced by the database itself rather than by application code alone. Within your workspace, access depends on role: employees see their own requests, managers and admins see the company queue, and comments marked internal are hidden from the requester.
How long we keep it
We keep your data for as long as your workspace is active. If you close your account, write to us and we will delete your workspace data within 30 days, except where we are required to retain records by law.
Your rights
Under India's Digital Personal Data Protection Act, 2023, you may request access to your personal data, ask for corrections, ask for erasure, or withdraw consent. Email hello@opslane.in and we will respond within 30 days. If you are an employee of a customer company, we may need to route your request through your workspace admin.
Cookies
We set cookies only to keep you signed in. We do not currently run advertising trackers or third-party analytics. If that changes, we will update this page and ask for consent where required.
Security
Traffic is encrypted in transit with TLS, passwords are hashed and never stored in readable form, and database access is restricted. We are an early-stage company and hold no formal security certification such as SOC 2 or ISO 27001 — we would rather tell you that plainly than imply otherwise. If you have a security concern, please write to us and we will take it seriously.
Changes
If we make a material change to this policy we will notify workspace admins by email before it takes effect.
Contact
Questions about privacy: hello@opslane.in