Privacy Policy
Last updated on September 18 2026
This Privacy Policy describes how AARLABS PRIVATE LIMITED (operating as "AAR Labs"; "we", "us", or "our") collects, uses, and shares your personal information when you use SnapDeploy.
1. Information We Collect
1.1 Information You Provide
- Account information (name, email address, password)
- Sign-in with GitHub or Apple: the name, email address, and account identifier those providers share with us when you choose to sign in with them. Connecting GitHub authorizes SnapDeploy for the repositories your account can access (GitHub's
repo OAuth scope — GitHub does not offer per-repository OAuth permissions); we use this to list your repositories and to read the ones you choose to deploy, and you can revoke it anytime from your GitHub settings
- Billing information (payment details, billing address)
- Profile information (company name, contact details)
- Container and application data you deploy (source code, container images, environment configuration)
- Messages you send to support
1.2 Automatically Collected Information
- Usage data (features used, pages visited, in-app actions)
- Device information (IP address, browser type, operating system, app version)
- Log data (access times, errors, performance)
- Push notification token (a device identifier, collected only in the mobile app so we can deliver deployment and billing alerts; you can disable notifications in your device settings at any time)
- Crash reports and diagnostics from the mobile app
2. How We Use Your Information
- Provide, maintain, and improve our services
- Process payments and send billing notifications
- Send service push notifications (deploy success/failure, container state, billing) to the mobile app
- Understand how the product is used, via the analytics described in section 4
- Respond to requests and provide customer support
- Detect, prevent, and address security issues and abuse (see section 5)
- Comply with legal obligations
3. Cookies & Similar Technologies
The SnapDeploy website uses essential cookies for signing you in and keeping your session secure (session and CSRF-protection cookies), and Cloudflare sets cookies as part of protecting the site and deployed applications against bots and attacks. Our analytics tooling (section 4) may use cookies or similar local storage to recognise a returning browser. We do not use advertising cookies and do not permit third-party ad networks on SnapDeploy. You can control or delete cookies in your browser settings; essential cookies are required for login to work.
4. Analytics & Crash Reporting
To understand product usage and fix problems, we use:
- PostHog — product analytics for the website and mobile app (feature usage, in-app events)
- Google Analytics for Firebase — aggregate usage statistics for the mobile app
- Firebase Crashlytics — crash reports and diagnostics for the mobile app
This data is used solely to improve SnapDeploy. It is not used for advertising and not used to track you across other companies' apps or websites.
5. Automated Security Scanning
To keep the platform safe and enforce our Acceptable Use Policy, deployed source code, container images, and build/runtime logs are subject to automated security scanning (for example, for phishing kits, proxy/tunneling tools, and piracy infrastructure). We also process traffic metadata for deployed applications — including aggregated request counts by country — for abuse prevention, platform operations, and to show you your own application's traffic geography. Flagged deployments may be reviewed by our team and are handled per the Terms.
6. Information Sharing
We do not sell your personal information. We share it only with the service providers below (each for the stated purpose), when the law requires it, or with your consent:
- Payment processing: Razorpay (India), PayPal (international), Apple App Store and Google Play (purchases made inside the mobile apps). Card details are handled by these processors — we never store your full card number.
- Cloud hosting: Amazon Web Services (AWS) — runs the platform and your deployed applications
- Content delivery & security: Cloudflare — sits in front of our websites and deployed applications for DDoS/bot protection
- Email delivery: Twilio SendGrid — sends verification, billing, and service emails
- Analytics & crash reporting: PostHog and Google (Firebase) — as described in section 4
- Sign-in & code hosting: GitHub and Apple — when you sign in with them or connect a repository
- Legal requirements: When required by law or court order
- With your consent: When you give us explicit consent
7. Data Security
- Encryption of data in transit and at rest
- Regular security assessments
- Access controls and authentication
8. Data Retention
- Account and container data: kept while your account is active; deleted when you delete your account (see section 10)
- Operational logs (access, build, and application logs): kept on rolling windows for operations and security, then deleted or anonymized
- Analytics and crash data: retained per the retention settings of the providers in section 4 and then aggregated or deleted
- Backups: rotate on a fixed cycle; deleted data ages out of backups automatically
- Legally required retentions: anonymized tax invoice records for 6 years (Indian GST, CGST Rule 56) and security audit rows per our Terms §9
9. Legal Bases for Processing (EEA/UK users)
Where the GDPR or UK GDPR applies, we process your personal data on these bases:
- Performance of a contract: account management, running your deployments, billing, and support
- Legitimate interests: securing the platform, preventing abuse and fraud (section 5), and product analytics (section 4) — balanced against your rights
- Consent: where we ask for it (for example, optional communications); you may withdraw it at any time
- Legal obligation: tax and accounting record-keeping
10. Your Rights
- Access: Review your personal information
- Correction: Update or correct your data
- Deletion: Delete your account anytime from Settings → Danger Zone. Deletion is immediate, with two intentional retentions: tax invoice records are retained anonymized for 6 years to meet Indian GST requirements (CGST Rule 56), and security audit rows are retained per our Terms §9.
- Data Portability: Export your data
- EEA/UK users may also object to or ask us to restrict processing based on legitimate interests, and may lodge a complaint with their local supervisory authority
11. Children
SnapDeploy is a developer platform and is not directed at children. You must be at least 16 years old (or the age of digital consent in your jurisdiction) to create an account. We do not knowingly collect personal information from children; if you believe a child has provided us personal information, contact us and we will delete it.
12. Changes to this Policy
We may update this policy as the product evolves. The "Last updated" date above always reflects the current version, and material changes will be announced on the website or by email before they take effect.
13. Grievance Officer & Contact
In accordance with Indian law, the Grievance Officer for SnapDeploy is Somdip Roy. Complaints and privacy requests are acknowledged within 24 hours and resolved within 15 days.
AARLABS PRIVATE LIMITED
CIN: U62090PN2026PTC255314
SR.NO.43 Privet Drive, E-Commercial, Baner Gaon
Haveli, Pune — 411045, Maharashtra, India
Email: [email protected]
Phone: +91 9004233112