Privacy Policy
What RunwayDue stores, why, who can see it, and how to make us delete it.
In effect since 24 August 2026.
Who we are
RunwayDue is operated by Omnitics Technologies Pvt. Ltd., registered at C2-303, Sheth Midori, Hanuman Tekdi, Shiv Vallabh Road, Dahisar East, Mumbai 400068, Maharashtra, India. We are the data fiduciary for information about you as our customer, and we are a data processor for everything you store about your own clients.
That split runs through this whole document
When you add a client, send an invoice or collect a signature, the personal data involved belongs to your business relationship, not ours. We hold it on your instructions, use it only to run the product for you, and never for our own purposes. Where a section is about your data we say "you"; where it is about your clients' data we say so explicitly.
Questions, complaints and requests all go to support@runwaydue.com. Under the Digital Personal Data Protection Act 2023 that is also our grievance contact.
What we hold about you
| What | Why |
|---|---|
| Your name, email address and password | So you can sign in. The password is stored as a scrypt hash with a per-password salt, never as text, and cannot be read back by us. |
| Your sign-in sessions | One row per signed-in device, holding a hash of the cookie value rather than the value itself, and the workspace that device is currently looking at. Sessions last 30 days. |
| Your business details | Legal name, address, phone, website, logo, GSTIN and PAN — because they are printed on the invoices you send. |
| What you have tried to buy | When you choose a plan or buy signature documents we keep the order: what it was for, the amount and tax, the currency, how you chose to pay, your name and email address as the contact for it, and whether it was paid. Orders nobody completes are kept too, because they are how we know to follow up — write to us if you would rather one were removed. |
| Signature documents you have bought | A running ledger of documents added and used, so the balance can always be explained rather than merely asserted. It holds no card details: we do not have a payment provider connected, and when we do, card numbers will go to them and never to us. |
| Your bank and payment details | Account name and number, IFSC, SWIFT, UPI ID and any payment link. These are printed on your invoices, so they are stored in ordinary columns rather than encrypted — see the security section, which says plainly what that does and does not mean. |
| Your mail server settings | If you send from your own domain. The username and host are stored plainly; the password is encrypted. |
| What you do in the product | An activity trail of who did what and when, and a usage ledger of which billable actions were taken, by name. This is what makes “what happened to this invoice?” answerable. |
| Whether you have been active | A timestamp updated at most once an hour, so we can tell an active account from a dormant one. |
What we hold about your clients
You put this in, and we process it only to run the product for you.
- Client and supplier records: company and contact name, email, phone, website, postal address, tax identifiers and your own free-text notes.
- The documents you create: invoices, line descriptions, proposals, contracts, bills, payments and their references. Invoices freeze both parties' name and address at the moment of issue, so a later address change does not rewrite an old invoice.
- The files you upload: proposals, agreements, receipts. These are stored as part of the database, not on a separate file service.
- When a client first opened a document you sent them. This is recorded silently on the first view of a share link, and shown to you as “first opened”. Your client is not told. It is a single timestamp, not tracking, but it is behavioural data about somebody who never signed up with us, so we would rather say it here than have you discover it.
Electronic signatures
A signature is a legal record, so it is the part of the product that records the most.
- The signer's name, email address, and the signature image itself, drawn or typed, stored as an image.
- The signer's IP address and full browser identification string, captured at the moment of signing.
- A timestamped, append-only trail of every event on the document: created, sent, reminded, viewed, consented, signed, declined, completed, downloaded. It is never edited or deleted, because an audit trail that can be revised is not an audit trail.
The signer's IP address and browser string are printed into the signed PDF
They appear on the certificate page, and every party to the document — including anyone copied on it — receives that PDF. This is normal for e-signature products and it is what makes the certificate evidence rather than decoration, but it means a signer's network address and operating system are disclosed to the other parties. The consent notice shown before signing says so.
We verify that whoever holds the link, and any access code the sender set, can act on it. We do not verify identity by document, SMS or knowledge-based questions. If the signature you need requires that, this is not the right product for it.
Email we send
Every message the system attempts is logged with the recipient, anyone copied, the full subject line, a preview of the opening text and whether it was delivered.
That log is kept for a year, and it is a record of who was emailed what
The chasing engine reads it to know it has already chased a given invoice on a given day, so entries have to outlive the reminder schedule — which can be set to run as far as a year past a due date. A housekeeping job removes anything older than that. It holds no message bodies beyond the preview of the opening line described above — subject lines and recipients otherwise.
We do not use open-tracking pixels or click-tracking redirects in any message.
The public website
If you fill in the contact form or ask for a demo, we keep what you typed along with your IP address, your browser identification string, the page you were on and where you came from — so we can answer you and so we can tell a person from a bot.
Submissions our filter marks as spam are kept, not discarded
Deliberately, so that a real message wrongly flagged can be found and answered rather than silently vanishing. It does mean that if the filter is wrong about you, your message, IP address and browser string are stored with a score attached. Write to us and we will delete it.
Newsletter subscriptions are single opt-in: we do not send a confirmation email, so anyone who types your address into the box subscribes it. Unsubscribing stops all mail immediately; we keep the address marked as unsubscribed so that we do not mail you again by accident. Ask and we will remove it entirely.
Who else touches your data
- Our hosting and database provider, which runs the servers this application and its database sit on.
- Our mail relay, which delivers messages sent from the shared sender.
- No analytics or advertising vendor. Nothing is measured, and the application makes no outbound requests to any third party other than sending mail.
- Nobody else. There are no enrichment, scoring, lead-brokering or AI vendors involved, and nothing you or your clients store here is sent to any of them.
If you send from your own domain, your mail leaves through your own provider
On plans that allow it you can point invoices at your own mail server. When you do, those messages travel through infrastructure you chose and we have no relationship with, and your provider's terms apply to them rather than ours. That is the point of the feature — but it does mean we cannot answer for what happens to mail on that path.
We do not sell personal data, share it for advertising, or use anything you or your clients store here to train machine-learning models.
What we can see
Being honest about this is more useful than a blanket claim that nobody at our end can see anything, which would not be true.
- Our administrators can see, across every workspace: the business name, contact details, tax identifiers, plan and trial state, any orders you have placed and their amounts, how many records exist, the total amount invoiced, and the names of the people on the account.
- They cannot read the contents of your invoices, proposals, contracts, client records or uploaded documents through that console.
- Anyone with direct access to the server or the database can read everything, as is true of every hosted product. Access is limited to the people who operate the service, and we do not look at customer content except when you ask us to help with something specific.
Where your data is
Your data is stored and processed on servers in the United States. We are a company registered in India, and the people who run this service reach it from there — so your data crosses a border as a matter of routine. We would rather say that plainly than leave it to be inferred from an address at the bottom of the page.
The Digital Personal Data Protection Act 2023 allows this, and none of your rights depend on where the server happens to be — everything described below applies wherever the data physically sits. Mail we send necessarily travels to wherever your recipient's mail provider is, which is outside anybody's control.
How it is protected, and what that does not cover
- Passwords are stored as salted scrypt hashes and compared in constant time.
- Session cookies and password-reset links are stored as hashes, so a copy of the database is not a set of working credentials.
- Reset links work once and expire in an hour, and setting a new password signs out every device.
- Every request is scoped to one workspace at the query level, and that isolation is asserted by an automated check on every change, not assumed.
- Traffic to the site is encrypted. Mail is sent over an encrypted connection unless the operator has deliberately configured a local relay, which the server warns about at startup.
Your bank details are not encrypted at rest, and neither are your documents
Account numbers, IFSC, UPI IDs and tax identifiers sit in ordinary database columns, as do uploaded files — because they are printed onto invoices and rendered in the app constantly, and column-level encryption would protect them only from someone who already has the database. Whether the database file itself is encrypted depends on how the service is hosted. Your mail server password is the one field that is encrypted, because it is a live credential rather than a printed detail.
The database is backed up and restoring from a backup has been rehearsed. Backups contain everything, including uploaded documents and signed PDFs, because files live inside the database rather than beside it.
How long we keep it
Until you ask us to delete it, or until the account is closed and the period below has passed.
Nothing is ever deleted because you stopped paying
That is the deliberate design of this product. If you cancel, or your trial ends, or you go quiet for a year, everything you made stays exactly where it is. The self-service export is part of the paid plans and stops with them; getting your data does not, and never will — ask us on any plan and we send it. What that promise never meant is that you cannot leave — see below.
- Invoices, proposals, contracts and payments are kept for as long as your account exists. Indian tax law requires books to be retained for several years, and deleting an issued invoice would break the numbering sequence that makes the rest of them provable.
- The activity trail — who changed what, and when — is kept for two years. The documents it describes are not deleted with it.
- Signature audit trails are never modified or deleted while the account exists, because their value is that they cannot be.
- The email log is kept for a year, for the reason given above.
- Contact form submissions are kept until we no longer need them to answer you, or until you ask.
- Rate-limiting records, which hold an address or an IP for the length of one window, are deleted as soon as the window ends.
- A housekeeping job runs once a week, and it is the only thing that deletes anything on a schedule: expired sign-in sessions a week after they expire, the email log at a year, the activity trail at two years, and abandoned checkout attempts at six months. Nothing you made is in that list.
Your rights, and how to use them
Under the Digital Personal Data Protection Act 2023 — and we extend the same to everyone, wherever they are, because operating two standards is how one of them gets forgotten:
- Access — see what we hold. On a paid plan you can do it yourself, without asking: Settings → Data exports every record in your workspace as CSVs plus the original files, readable without any software of ours. On the free plan the self-service export is not included, so write to us and we will send you exactly the same thing. We do not charge for access to your own data and we do not make you upgrade to get it.
- Correction — fix anything wrong. Most of it you can edit directly; write to us for the rest.
- Erasure — have it deleted. See below.
- Grievance — complain, and have it addressed. Write to us; if you are not satisfied you may escalate to the Data Protection Board of India.
- Nomination — name someone to exercise these rights if you cannot. Tell us who.
Deleting your account
You can do this yourself, in Settings
Settings, then Data, then "Delete this workspace". Only an owner can, and it asks for the workspace's name and your password before it does anything. It shows you exactly what will go — how many clients, invoices, agreements, signature requests and documents — and it deletes all of it, along with any account for which this was the only workspace. There is no queue and nothing to wait for. If you would rather a person did it, or you want only part of it removed, email support@runwaydue.com from the address on the account and we will confirm it is you, tell you what will go, and do it within 30 days.
Take a copy first — ask us if the export is not on your plan. Deletion is permanent: we do not restore a single workspace on request, and once the backups have rotated there is nothing left to restore from at all. Where a backup taken before the deletion still exists, the workspace remains in that copy until it is superseded or destroyed, which takes about a fortnight.
- Deleting a workspace removes its clients, invoices, proposals, contracts, bills, payments, uploaded files, signature records and audit trails.
- Deleting your user account removes you and your sessions. If you are the only person in a workspace, the workspace goes with you.
- We may keep the minimum needed to meet a legal obligation — for example, records of a transaction we are required to retain — and we will tell you exactly what and why rather than keeping it quietly.
- If you are asking us to delete data about somebody else's business, ask them: for their clients' records they are the ones who decide, and we act on their instruction rather than around it.
Children
This is a product for businesses. It is not directed at children, we do not knowingly collect anything about anyone under 18, and if we learn that we have, we will delete it.
Changes to this policy
If we change something that matters, we will email the address on your account before it takes effect — not merely update the date at the top and hope you look.