+RELAY.
Home About Contact
Sign in Start free ->

Your data / 02

Privacy
Policy.

Last updated: 25 September 2026

1. What we collect

Relay is a locally hosted, MySQL-backed application. It collects the account, workspace, consent, diagnostic and workspace-content data needed to operate the service:

  • Account details — your name, canonical email address, unique user ID and a one-way bcrypt/PASSWORD_DEFAULT hash of your password. The password itself is never stored or recoverable. We also keep your sign-up IP, most recent sign-in IP and timestamp, account timestamps and default landing-view preference. One email address can create only one account.
  • Password reset records — when you request a reset link we store a SHA-256 hash of the emailed token (never the link itself), the requesting IP address, the time it was created, when it expires and when it was used. Requesting a new link deletes your earlier unused ones, and a completed reset signs out your other sessions.
  • Organisation and workspace details — organisation name, unique org ID, slug, optional phone, owner; workspace name, unique workspace ID, type, initials, membership role, dashboard preset, selected tabs and onboarding timestamp.
  • Consent records — every Accept or Decline click, with the choice, server-observed IP address, consent date, created timestamp, page path (query strings are discarded), browser user-agent string and, when signed in, your user ID, email and name. A consent choice stored in the browser is replayed after sign-in, which creates another linked consent record.
  • Error and crash logs — sanitised PHP, API and browser diagnostic events with the time, source, severity, event type, message, request method, page path, HTTP status, IP address and browser string. When available, the log also stores snapshots of the signed-in user, organisation and workspace plus capped, redacted stack/context data. Request bodies, passwords and access tokens are never stored.
  • Workspace content — the customers, employees, orders, inventory, tasks, planner events, notepad notes, attendance marks, custom details and workspace settings you enter, together with their workspace association and audit timestamps.

2. Cookies, sessions & browser storage

The consent banner normally appears once per browser. Relay stores the choice and timestamp in localStorage under relay-crm-cookies, then records the click through api/cookies.php. Declining consent keeps essential operation available but redirects the dashboard and profile to the consent-declined page until consent is accepted.

A PHP session cookie keeps you signed in; the server-side session stores the active workspace. It is HTTP-only, SameSite=Lax and Secure when the site runs over HTTPS; choosing “Remember me” extends that cookie for 30 days. Relay also keeps a small account/display cache under relay-crm-user (name, email, initials and landing preference), a per-account relay-crm-profile:<user_id> timezone and 12h/24h time-format preference, workspace-scoped UI preferences for navigation, last view, settings and custom tables, and a one-shot relay-crm-just-signed-in marker in sessionStorage. These browser values are not used to bypass workspace membership.

3. Organisations, workspaces & access

Each account receives a unique user ID. Setup creates an organisation with a unique org ID and a workspace with a unique workspace ID; an account may belong to more than one workspace. Workspace membership records determine which organisation and workspace a person may enter. Content APIs scope reads and writes to the active workspace, so records from one organisation or workspace are not returned to another member. Dashboard presets and custom tab selections are stored as workspace settings, with Overview and Settings always retained.

4. Retention & deletion

Records removed through the interface are archived with a deleted_at timestamp rather than erased, so they no longer appear in normal workspace views but remain available for recovery and audit. An Owner may permanently remove an empty workspace, but a workspace containing data must be emptied first. Consent, sign-in and diagnostic records are retained for the lifetime of this installation so reliability and security issues can be investigated. The current build has no automated retention job; contact us if you need a retention or deletion request handled.

5. What we never do

  • We do not sell workspace data or share it with third-party advertisers in the current build.
  • We do not send workspace content to an external analytics or advertising network.
  • We do not store your password in a readable form; only a one-way hash is kept.
  • We do not write request bodies, passwords or access tokens to the diagnostic log.

6. Digital Personal Data Protection Act (DPDPA)

Relay's data-protection approach is informed by the Digital Personal Data Protection Act, 2023 (DPDPA). We use personal data for the purposes described in this policy, record consent choices, limit workspace access by membership, retain diagnostic data in a redacted form and provide a contact channel for requests.

The DPDPA rights and obligations that apply to a deployment depend on its hosting context and the people it covers. This notice is an operational summary, not legal advice. For information, correction, erasure or grievance-related enquiries, use the contact details above.

7. Your choices

You can correct your name and email from Profile, change your password, sign out, change your consent choice from the consent-declined page, and manage workspace tabs and settings from the workspace interface. The current build has no self-service account deletion. An Owner may permanently remove an empty workspace; contact us for a copy, correction or deletion request:

  • Email: hello.zerofy@gmail.com
  • Phone: 8789500326
+RELAY.

Small team energy. Clear system.

About Contact Terms Privacy Sign in
© 2026 Relay CRM