1.Overview
Qube CRM is a hosted project management service operated by Qube Foundation from Tiruchirappalli, Tamil Nadu, India. This policy explains what we collect when you use it, why we collect it, who we share it with, how long we keep it, and what you can do about all of that.
The short version, and every point below is expanded further down:
- We collect what an account needs — your name, your work email, a hash of your password — and the work you put into your workspace.
- We use it to run the service for you. We do not sell it, we do not share it with advertisers, and we do not use your workspace content to train machine-learning models.
- There is no analytics product, no advertising network and no third-party tracker on the application. The only cookie we set is the one that keeps you signed in.
- Your workspace content belongs to your organisation. You can export it or delete the workspace outright at any time, and deleting it deletes the content.
2.Information we collect
Information you give us
When you create an account we collect your name, your email address and a password. The password is stored only as a one-way hash — we cannot read it, and neither can anyone who obtains a copy of the database. You may optionally add an avatar image URL and set a time zone.
When you create or join a workspace we record which workspace you belong to and your role in it. An account belongs to exactly one workspace, which is what lets a person have exactly one role rather than a different one in each place.
Workspace content is everything you and your colleagues put into the product: projects, tasks and subtasks, comments, time entries, meetings and bookings. We process this on your behalf. We do not read it except where it is strictly necessary to operate or support the service.
Information we collect automatically
- A session cookie. Signing in sets one first-party cookie named
qube_session. It is HTTP-only, sent same-site, expires after seven days, and holds a signed token identifying your session — nothing else. It is strictly necessary: without it the service cannot know who you are. - Server logs. Our servers record the ordinary details of a request — IP address, browser user-agent, the path requested, a timestamp and the response status — as every web server does. These are used for security, debugging and abuse investigation.
- Activity within your workspace. The product keeps an activity log of who changed what and when — the record that makes an audit trail possible. It is visible to your workspace, not to other customers.
We do not use analytics services, advertising identifiers, tracking pixels, session recording or fingerprinting, and we do not set any cookie you would have to consent to for those purposes.
Information from other people
If a colleague invites you to a workspace, we receive the email address they used to invite you before you have an account. If someone assigns work to you or mentions you in a comment, that appears in your workspace.
3.How we use information
We use what we collect to:
- run the service — authenticate you, show you your work, and keep your workspace separate from every other one;
- maintain the audit trail, notifications and reporting the product is for;
- keep the service secure, investigate abuse, and diagnose faults;
- answer you when you contact us for support;
- tell you about material changes to the service, this policy or our terms;
- meet our legal obligations, including tax and accounting records for paid plans.
We do not use your workspace content to train machine-learning models, we do not profile you for advertising, and we make no automated decisions about you that have a legal effect.
4.How we disclose information
Inside your workspace. Your name, avatar and the work you do are visible to the other members of your workspace according to their role. That is the point of a shared workspace, and it is worth knowing before you write something in a comment.
Service providers. We use a small number of processors to run the service, under contract and only for that purpose:
- MongoDB Atlas
- Managed database hosting. Your account and workspace data are stored here.
- Our cloud hosting provider
- Runs the application servers that respond to your requests, and holds the server logs described above.
We will name a payment processor here when paid plans go live, and an email provider when the service starts sending transactional email. Until then, invitations are shared as a link by the person inviting you rather than emailed by us.
Legal reasons. We may disclose information if we are required to by law, or where it is necessary to protect the rights, safety or property of Qube Foundation, our customers or the public. If we receive a request for your data and we are permitted to tell you, we will.
Business transfers. If the service is ever acquired or reorganised, your information may transfer as part of that. You will be told before it happens, and this policy will continue to apply until it is replaced by one you are told about.
We do not sell personal information, and we never have.
5.How we store and secure information
Data is stored in managed database clusters, encrypted in transit over TLS and encrypted at rest by the provider. Passwords are stored only as one-way hashes. Session tokens are signed and short-lived.
Tenancy is enforced at the database query level rather than filtered in the interface: your workspace forms part of every query the application makes, and a valid identifier belonging to another workspace returns nothing at all rather than a redacted row. Access within a workspace is governed by roles and per-project grants.
No service can promise perfect security, and we will not pretend otherwise. If we become aware of a breach affecting your data we will tell you and the relevant authority as the law requires, with what we know and what we are doing about it.
6.How long we keep information
- Account and workspace content
- Kept while your account and workspace exist. Deleting a workspace deletes its content.
- Session cookie and token
- Expires seven days after it is issued, or immediately when you sign out.
- Activity log
- Kept for the life of the workspace, because it is the audit trail the product provides.
- Server logs
- Kept for a short operational period and then rotated out.
- Billing and tax records
- When paid plans are live, kept for as long as Indian tax and accounting law requires, which is longer than the account itself.
Deleting an account or workspace is not reversible. Where we are obliged to keep a record — a tax invoice, for instance — we keep only that record and not the content.
7.How to access and control your information
You can do the following yourself, at any time, from inside the product:
- see and correct your name, email, avatar and time zone on your profile;
- change your password;
- see every member of your workspace and their role;
- export your workspace data, or delete the workspace outright.
You can also ask us to access, correct, export or delete your personal information by writing to contact@qubefoundation.com. We will respond within thirty days. If you are a member of a workspace someone else administers, we may need to route your request through that administrator, since the workspace content is theirs to control.
Nothing is held hostage to keep you subscribed. If you want your data out and your workspace gone, that is a decision you can carry out without talking to us.
8.Our policy towards children
Qube CRM is a tool for people at work and is not directed at children. We do not knowingly collect personal information from anyone under 18. If you believe a child has given us information, write to us and we will delete it.
9.Regional disclosures
India
We process personal data in accordance with the Digital Personal Data Protection Act, 2023. You have the right to access a summary of your data, to have it corrected or erased, to nominate someone to exercise your rights, and to complain to the Data Protection Board of India. Requests reach us at the address in section 11.
The EEA and the United Kingdom
Where the GDPR or UK GDPR applies: for your own account data we are the controller, and for workspace content we are the processor acting for your organisation. We rely on the performance of a contract for running the service, our legitimate interests for security and fault diagnosis, and your consent where we ask for it. You have the rights of access, rectification, erasure, restriction, portability and objection, and you may complain to your supervisory authority. Data may be processed in India and in the regions our providers operate in, under the safeguards those providers offer.
California
We do not sell personal information or share it for cross-context behavioural advertising, so there is no opt-out to offer. You may still request access, deletion or correction, and we will not discriminate against you for asking.
10.Changes to this policy
We will update this page when the service changes — a new processor, a new category of data, a different retention period. The date at the top always reflects the current version. If a change materially affects your rights we will tell you in the product or by email before it takes effect, rather than quietly editing the page.
11.How to contact us
Questions, requests and complaints about privacy go to contact@qubefoundation.com, or by post to Qube Foundation, Tiruchirappalli, Tamil Nadu, India.
Our terms of service cover the rest of the relationship — what you may do with the service, what we owe you, and how either of us can end it.