Open navigation

Legal

Privacy Policy

This Privacy Policy explains how personal data is handled when people visit SupportMesh, register for a Trial, use a workspace or Client Portal, communicate by email, or use enabled APIs and webhooks.

Effective August 2, 2026

1. Operator and scope

SupportMesh is operated by Burhanuddin Hamzabhai, an individual sole proprietor based in Pune, Maharashtra, India. In this policy, SupportMesh, we, us, and our refer to that operator.

This policy covers the public SupportMesh website, Trial registration, authenticated workspaces, the Client Portal, email-to-ticket processing, APIs and webhooks, and SupportMesh communications. It does not govern third-party services a workspace independently chooses to connect.

2. Our role for different data

SupportMesh acts as the responsible operator, data fiduciary, or controller, as applicable, for direct account registration, Trial and service administration, enquiries, security, operational logs, and product administration.

SupportMesh commonly processes workspace and customer content on behalf of the subscribing organization. This includes Clients, tickets, replies, internal notes, files, inbound emails, delivery records, and Client Portal data. The subscribing organization determines much of the purpose and content of that processing and remains responsible for its notices, permissions, and lawful instructions.

3. Information we collect

  • Name, email, optional phone, avatar, locale, timezone, account and authentication identifiers, and account activity timestamps.
  • Workspace identity, settings, memberships, roles, Trial or plan state, entitlements, and usage data.
  • Client organization and contact information, Products, Projects, versions, and relationship context.
  • Ticket subjects and descriptions, categories, priorities, structured bug and environment information, public replies, internal notes, followers, references, and attachments.
  • Estimates and decisions, Defects, Releases, Downloads, and Knowledge Base content.
  • Inbound and outbound email addresses, metadata, message identifiers, threading references, sanitized content, delivery records, and attachment metadata.
  • API and webhook configuration, integration mappings and logs, notification preferences, jobs, retries, audit records, and security records.
  • IP, device, browser, and user-agent information where the service or its providers actually log that context for security or operations.

4. How information is obtained

People provide information when they create accounts, contact SupportMesh, submit or respond to support requests, upload files, configure integrations, or otherwise use the service. Workspace organizations and their authorized users provide most Client and support content.

The service also creates essential session records, timestamps, operational logs, audit and security events, retry records, and usage counts as people and systems use SupportMesh.

5. Why we process information

  • Provide and administer the service, authenticate users, and operate workspaces and Client Portal access.
  • Manage client support, email processing, transactional notifications, Estimates, Defects, Releases, Downloads, and Knowledge Base content.
  • Secure SupportMesh, prevent misuse, enforce access boundaries, troubleshoot failures, and maintain audit and security records.
  • Provide reporting, integration delivery, APIs, webhooks, and background processing.
  • Administer the Trial, plans, commercial relationships, feature access, and usage limits.
  • Respond to enquiries, resolve disputes, protect rights and safety, and comply with legal obligations.

7. How information is shared

Information is shared only as needed to provide and secure SupportMesh, follow lawful workspace instructions, comply with law, or protect rights and safety. Authorized workspace and Client users see information according to their roles and product permissions.

SupportMesh does not sell personal data and does not currently use personal data for third-party behavioural advertising.

8. Service providers

  • Vercel provides application hosting and runtime infrastructure.
  • Supabase provides PostgreSQL database, authentication, and private object storage infrastructure.
  • Resend provides transactional email delivery and inbound email receiving infrastructure.
  • GitHub provides source-code hosting and development tooling; ordinary production customer content is not intentionally stored in source control.

9. International processing

SupportMesh is based in India. Service providers may process information in jurisdictions outside a user's location according to their infrastructure, contracts, and applicable safeguards. We do not claim a specific transfer mechanism where it has not been confirmed.

10. Cookies and similar storage

SupportMesh uses essential authentication, session, and security cookies or storage required to operate the requested service. The current product does not evidence advertising or behavioural-marketing cookies, so a non-essential advertising consent banner is not used.

11. Retention

We retain information for as long as reasonably necessary to provide and secure SupportMesh, administer accounts and workspaces, resolve disputes, satisfy contractual or legal obligations, and maintain appropriate operational records. Some configured retention periods are not yet enforced through a fully automated deletion process.

Current system metadata describes approximately 3,650 days for certain audit and security records, 180 days for selected operational metadata, and 90 days for inbound-email records. These are configuration intentions, not a promise of exact automatic deletion. Active content, attachments, backups, disputes, security needs, and legal obligations may require different or longer retention, and deletion may not be immediate across every backup.

12. Attachments

Files are stored privately and access is permission-controlled. Signed links may be used, and files may remain pending until approved. Malware scanning is not currently provided. Users must not upload harmful, unlawful, infringing, or unnecessary sensitive files.

13. Security

SupportMesh uses role-based access, workspace and Client boundaries, PostgreSQL Row Level Security, private Storage, signed downloads, public-reply and internal-note separation, HTTPS, webhook signature verification, API-key hashing, audit and security records, server-secret protection, and restricted server and database operations.

No method of transmission, storage, or security is absolutely secure. SupportMesh does not claim SOC 2, ISO 27001, HIPAA, dedicated single-tenant infrastructure, or uninterrupted operation.

14. Individual rights and grievances

Depending on applicable law, individuals may request access or information about processing; correction, completion, or updating; deletion; withdrawal of consent where relevant; grievance resolution; and, where applicable, objection, restriction, portability, or complaint to an appropriate authority.

Identity and authority may need to be verified. Client users or contacts may need to contact their organization first when SupportMesh processes their information on that organization's instructions.

15. Children

SupportMesh is a business service intended for adults and is not intended for individuals under 18. The service does not provide a parental-consent workflow.

16. Automated decisions

SupportMesh does not currently make solely automated decisions that produce legal or similarly significant effects about people.

17. Security incidents

Security incidents will be assessed and notifications will be made as required by applicable law and applicable contractual obligations. We do not promise a fixed notification deadline beyond those requirements.

18. Updates and contact

Material changes may be communicated through the service, website, or email and will be reflected by an updated effective date. Privacy requests and grievances may be directed to the contact shown below.

SupportMesh Privacy and Grievance Contact

supportmesh.hq@gmail.com

Burhanuddin Hamzabhai, individual sole proprietor operating SupportMesh
Pune, Maharashtra, India

https://www.supportmeshplatform.com