Snowbell

Privacy Policy

Effective 9 September 2026

This policy explains what Snowbell collects, why, where it is kept, and what you can ask us to do with it. It covers the website at snowbell.in and the application at app.snowbell.in.

01Who we are

"Snowbell", "we" and "us" mean the operator of snowbell.in and app.snowbell.in. We are based in India and act as the data fiduciary (under India's Digital Personal Data Protection Act, 2023) and as the data controller (under the GDPR) for the personal data described below.

Reach us about anything in this policy at privacy@snowbell.in.

02What we collect

Account information

When an account is created, we store your name, your email address, whether that address has been verified, an optional avatar image, the workspace you belong to, and your role in it. If you sign in with a password, we store a cryptographic hash of it — never the password itself.

What you put into the app

Snowbell is a workplace tool, so most of what we hold is content you or your colleagues create: workspace and project names, tasks and sub-tasks, descriptions, comments, tags, milestones, statuses, and a record of who changed what and when. Some of this is personal data about you simply because your name is attached to it.

Content belongs to the workspace, not to the individual. Your workspace administrator can see it, and can change who else can.

Technical information

Cookies

We set one cookie: the session cookie that keeps you signed in. There are no advertising cookies, no third-party trackers, and no analytics or behavioural profiling on either snowbell.in or app.snowbell.in. Because the only cookie we set is strictly necessary to deliver a service you asked for, there is no consent banner to click through.

03Why we use it, and on what basis

To run the service
Authenticating you, showing your workspace, delivering the features you use. Necessary to perform our contract with you.
To keep it secure
Rate limiting, abuse detection, session records, error diagnosis. Our legitimate interest in a service that is not broken or overrun.
To communicate with you
Verification emails, password resets, invitations, and notices that materially affect your account. Contractual, or our legitimate interest in keeping account holders informed. We do not send marketing email.
To meet legal obligations
Where a law, court or regulator requires it.

Where Indian law applies, we process your personal data for the lawful purpose for which you provided it, or on your consent where consent is the applicable basis.

04Who else touches your data

We do not sell personal data, and we do not share it for anyone else's marketing. A small number of providers process data strictly on our instructions so the service can run:

We may also disclose data if we are legally compelled to, or where it is necessary to protect our rights or someone's safety. If the service is ever transferred to another operator, personal data moves with it and we will tell account holders before that happens.

05Where your data lives

Your data is stored in Germany and is accessed by us from India. If you are in the EEA or the UK, that means your personal data leaves your region; transfers out of the EEA rely on the European Commission's Standard Contractual Clauses or an equivalent safeguard.

06How long we keep it

Account and workspace content is kept for as long as the workspace exists.

Be aware of one deliberate design choice: closing an account deactivates it rather than deleting it. A deactivated user cannot sign in and cannot be assigned work, but the account row and everything authored under it — tasks, comments, the activity history — stays, so a workspace's record of its own work does not develop holes. If you want your personal data erased outright rather than deactivated, write to us and we will do it wherever we are not required to keep it.

Sessions expire on their own schedule and expired rows are cleared. Rate-limit counters are short-lived. Backups are kept on a rolling schedule and are overwritten in turn, so data can persist in a backup for a period after it is removed from the live database.

07Your rights

Whatever your jurisdiction, you can ask us to:

Write to privacy@snowbell.in and we will respond within 30 days. If you are unhappy with our answer, you can escalate to the Data Protection Board of India, or — if you are in the EEA or the UK — to your local supervisory authority.

Where your data sits inside a workspace that someone else administers, we will handle your request and, where the request concerns workspace content, work with that administrator to resolve it.

08Security

All traffic is served over TLS. Passwords are stored only as hashes. Access to the production database is limited to the people who operate the service, and backups are encrypted. Sign-in and other sensitive endpoints are rate limited. No system is perfectly secure; if a breach affects your personal data we will notify you and the relevant authority as the law requires.

09Children

Snowbell is a tool for work and is not intended for anyone under 18. We do not knowingly collect personal data from children. If you believe a child has an account, tell us and we will remove it.

10Changes

We will post any revision here with a new effective date. If a change materially affects how we use your personal data, we will tell account holders by email before it takes effect.

11Contact

Privacy questions, requests and complaints: privacy@snowbell.in.