Privacy Policy
On this page
Last updated: August 2026
Your privacy matters to us. This policy describes what data we collect, why we collect it, how we protect it, and the choices and rights you have.
1.Overview
This Privacy Policy explains how Anested Labs Private Limited, operating as Anested Infrastructures ("Anested", "we", "us", "our"), collects, uses, discloses, and protects information when you visit infra.anested.com and related subdomains, or use our services (collectively, the "Services").
By using the Services, you consent to the practices described in this policy. If you do not agree, please discontinue use of the Services. This policy should be read together with our Terms of Service.
2.Information we collect
We collect the following categories of information:
- Contact & lead information — name, phone number, email address, selected service of interest, and message content you submit through contact forms, support forms, or lead popups.
- Account information — name, email, phone number, profile details, and authentication identifiers when you register (authentication is handled through Firebase Authentication).
- Phone verification data — phone numbers and one-time password (OTP) verification status when you verify your number through our SMS provider.
- Project & billing information — project requirements, selected plans, invoices, and payment records. Card/UPI details are processed directly by our payment gateway (Razorpay) and are never stored on our servers.
- Technical & usage data — IP address, browser type, device information, pages visited, interactions with components, referral source, and approximate location derived from your IP.
- Device identifiers — a randomly generated device ID stored in your browser's local storage, used to remember form submissions and control popup frequency.
- Precise location — only if you explicitly grant permission through your browser; never collected silently.
- Communications — emails, support tickets, and chat messages you exchange with us.
3.How we use information
We use the information we collect to:
- Respond to enquiries, support requests, and lead submissions, and connect you with our team.
- Provide, operate, deliver, and maintain the Services and your projects.
- Create and manage your account, authenticate you, and secure access.
- Process payments, generate invoices, and manage subscriptions.
- Send transactional emails (confirmations, receipts, password resets, OTPs, project updates).
- Send service-related or promotional communications you have opted into (you may opt out at any time).
- Analyze usage to improve performance, content, design, and search engine optimization.
- Prevent spam, fraud, abuse, and bot-driven submissions (e.g. honeypot fields, verification checks).
- Comply with legal obligations and enforce our Terms.
4.Legal bases for processing
Where applicable data protection law requires a legal basis, we rely on:
- Consent — when you submit a form, opt into communications, grant location access, or accept cookies.
- Contract — processing necessary to deliver services you have requested or to take pre-contract steps.
- Legitimate interests — improving our Services, securing our systems, preventing fraud, and marketing our own services in a proportionate manner.
- Legal obligation — retention of billing and tax records, and responses to lawful requests.
6.Analytics
We operate an in-house analytics system alongside Google Analytics. Our in-house tracking stores aggregated interaction data — such as page views, component interactions, and session information — to help us understand and improve the experience.
Google Analytics may set its own cookies and collect data in accordance with Google's privacy policy. You can opt out using Google's browser opt-out tools. Analytics data we hold is used in aggregate and is not used to personally identify you.
7.Payment information
All payments are processed by Razorpay (or other payment gateways we may add). Your card, UPI, or banking credentials are transmitted directly to the payment processor over encrypted connections and are never stored on Anested servers. We retain only transaction metadata (amount, status, reference IDs, invoice details) needed for billing, accounting, and support.
Payment processors act as independent data controllers for the payment data they collect, under their own privacy policies.
8.Data storage & security
Relational data such as accounts, projects, leads, and queries is stored in Supabase (PostgreSQL). Authentication is managed by Google Firebase. Files and media may be stored in Microsoft Azure Storage. Analytics events are stored in our own databases. Some operational data may be stored in MongoDB Atlas.
We apply reasonable technical and organizational safeguards, including encrypted connections (TLS), access controls, credential hashing, environment isolation, and least-privilege access for staff. However, no method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
In the event of a data breach affecting your personal data, we will notify you and the relevant authorities where required by applicable law.
10.Data retention
We retain personal data only as long as necessary for the purposes described in this policy:
- Lead and contact submissions — until resolved and for a reasonable follow-up period, or until you request deletion.
- Account data — for the life of your account and a short period after closure.
- Billing and tax records — as required by applicable law (typically 7–8 years in India).
- Analytics data — retained in aggregated or de-identified form.
When data is no longer needed, we delete it or irreversibly anonymize it.
11.Your rights
Subject to applicable law, you have the right to:
- Access a copy of the personal data we hold about you.
- Correct inaccurate or incomplete data.
- Request deletion of your personal data ("right to be forgotten").
- Object to or restrict certain processing, including direct marketing.
- Withdraw consent at any time, without affecting prior lawful processing.
- Opt out of promotional emails via the unsubscribe link or by contacting us.
To exercise any of these rights, email us at infrastructures@anested.com. We will respond within a reasonable timeframe and may need to verify your identity before acting on a request.
12.Children's privacy
The Services are not directed to children under 18, and we do not knowingly collect personal data from them. If you believe a child has provided us personal data, contact us and we will delete it promptly.
13.International data transfers
Our service providers (such as Supabase, Firebase, Azure, and analytics platforms) may store or process data in countries other than your own. Where data is transferred internationally, we rely on our providers' compliance frameworks and contractual safeguards designed to protect your data to a standard consistent with this policy.
14.Changes to this policy
We may update this Privacy Policy from time to time. The "Last updated" date reflects the most recent revision. Material changes will be highlighted on the website or notified by email where practical. Continued use of the Services after changes take effect constitutes acceptance of the updated policy.
15.Contact
Anested Labs Private Limited (Anested Infrastructures). For privacy questions, data requests, or complaints, contact us at infrastructures@anested.com. Website: infra.anested.com.