1. What we collect
Relay is a locally hosted, MySQL-backed application. It collects
the account, workspace, consent, diagnostic and workspace-content
data needed to operate the service:
- Account details — your name, canonical email address, unique user ID and a one-way bcrypt/PASSWORD_DEFAULT hash of your password. The password itself is never stored or recoverable. We also keep your sign-up IP, most recent sign-in IP and timestamp, account timestamps and default landing-view preference. One email address can create only one account.
- Password reset records — when you request a reset link we store a SHA-256 hash of the emailed token (never the link itself), the requesting IP address, the time it was created, when it expires and when it was used. Requesting a new link deletes your earlier unused ones, and a completed reset signs out your other sessions.
- Organisation and workspace details — organisation name, unique org ID, slug, optional phone, owner; workspace name, unique workspace ID, type, initials, membership role, dashboard preset, selected tabs and onboarding timestamp.
- Consent records — every Accept or Decline click, with the choice, server-observed IP address, consent date, created timestamp, page path (query strings are discarded), browser user-agent string and, when signed in, your user ID, email and name. A consent choice stored in the browser is replayed after sign-in, which creates another linked consent record.
- Error and crash logs — sanitised PHP, API and browser diagnostic events with the time, source, severity, event type, message, request method, page path, HTTP status, IP address and browser string. When available, the log also stores snapshots of the signed-in user, organisation and workspace plus capped, redacted stack/context data. Request bodies, passwords and access tokens are never stored.
- Workspace content — the customers, employees, orders, inventory, tasks, planner events, notepad notes, attendance marks, custom details and workspace settings you enter, together with their workspace association and audit timestamps.
2. Cookies, sessions & browser storage
The consent banner normally appears once per browser. Relay stores
the choice and timestamp in localStorage under
relay-crm-cookies, then records the click through
api/cookies.php. Declining consent keeps essential
operation available but redirects the dashboard and profile to
the consent-declined page until consent is accepted.
A PHP session cookie keeps you signed in; the server-side
session stores the active workspace. It is HTTP-only, SameSite=Lax
and Secure when the site
runs over HTTPS; choosing “Remember me” extends that cookie for
30 days. Relay also keeps a small account/display cache under
relay-crm-user (name, email, initials and landing
preference), a per-account relay-crm-profile:<user_id>
timezone and 12h/24h time-format preference, workspace-scoped UI
preferences for navigation, last view, settings and custom tables,
and a one-shot
relay-crm-just-signed-in marker in
sessionStorage. These browser values are not used to
bypass workspace membership.
3. Organisations, workspaces & access
Each account receives a unique user ID. Setup creates an
organisation with a unique org ID and a workspace with a unique
workspace ID; an account may belong to more than one workspace.
Workspace membership records determine which organisation and
workspace a person may enter. Content APIs scope reads and writes
to the active workspace, so records from one organisation or
workspace are not returned to another member. Dashboard presets
and custom tab selections are stored as workspace settings, with
Overview and Settings always retained.
4. Retention & deletion
Records removed through the interface are archived with a
deleted_at timestamp rather than erased, so they no
longer appear in normal workspace views but remain available for
recovery and audit. An Owner may permanently remove an empty
workspace, but a workspace containing data must be emptied first.
Consent, sign-in and diagnostic records are
retained for the lifetime of this installation so reliability and
security issues can be investigated. The current build has no
automated retention job; contact us if you need a retention or
deletion request handled.
5. What we never do
- We do not sell workspace data or share it with third-party advertisers in the current build.
- We do not send workspace content to an external analytics or advertising network.
- We do not store your password in a readable form; only a one-way hash is kept.
- We do not write request bodies, passwords or access tokens to the diagnostic log.
6. Digital Personal Data Protection Act (DPDPA)
Relay's data-protection approach is informed by the Digital
Personal Data Protection Act, 2023 (DPDPA). We use personal data
for the purposes described in this policy, record consent
choices, limit workspace access by membership, retain diagnostic
data in a redacted form and provide a contact channel for requests.
The DPDPA rights and obligations that apply to a deployment depend
on its hosting context and the people it covers. This notice is an
operational summary, not legal advice. For information, correction,
erasure or grievance-related enquiries, use the contact details
above.
7. Your choices
You can correct your name and email from Profile, change your
password, sign out, change your consent choice from the
consent-declined page, and manage workspace tabs and settings from
the workspace interface. The current build has no self-service
account deletion. An Owner may permanently remove an empty
workspace; contact us for a copy, correction or deletion request: