Privacy Policy

Last updated: 20 September 2026

This Privacy Policy explains how DesiAcres Advisory Group (“DesiAcres”, “we”, “us”, “our”) collects, uses, discloses and protects information in connection with the AcreTerminal platform (the “Service”). It applies to visitors of our marketing site and to every organisation and user account on the Service.

1. Introduction

AcreTerminal is a commercial real estate leasing and asset management platform built for companies, their finance and real-estate teams, and the advisors who work with them. We handle organisation, property, lease, financial and document data on behalf of the businesses that use the Service, and we take that responsibility seriously. This policy describes what we collect, why, who we share it with, and the controls you have over it.

2. Who we are

DesiAcres Advisory Group operates AcreTerminal. For the purposes of applicable data protection law, DesiAcres acts as the data controller for account, organisation and billing information, and as a data processor for the portfolio, lease, financial and document records an organisation enters into the Service on behalf of its own end users and counterparties.

3. Scope of this policy

This policy covers the AcreTerminal marketing site, the authenticated application, and the platform administration console. It does not cover third-party websites we link to (for example a landlord's or partner's own site), which have their own privacy practices.

4. Information we collect

We collect information in three ways:

(a) Information you provide directly — account details (name, work email, password hash), organisation details, the portfolio, building, unit, lease, requirement, transaction, due-diligence, comparable and scenario records you or your team enter, documents you upload, billing and tax details needed to invoice you, and anything you send us through the contact form or support channels. Where the Commute Friction Score is explicitly enabled, we accept only a pre-aggregated distribution of commute minutes per employee — the module is designed to never accept or store an individual employee's home address.

(b) Information collected automatically — usage and audit logs (who did what, when, from where), device and browser information, IP address, and cookies or similar technologies described in Section 7.

(c) Information from third parties — payment confirmation and subscription status from our payment processor, and delivery/bounce status from our transactional email provider. See Section 8.

5. How we use information

We use the information above to:

provide, maintain and secure the Service; run the deterministic calculation engines against the data your organisation enters; authenticate users and enforce role-based access; process subscription billing and transaction fees; respond to support requests; send service, security and billing communications; maintain the append-only audit log required for accountability; detect and prevent fraud, abuse and unauthorised access; understand aggregate product usage so we can improve the Service; and comply with our legal obligations.

We do not sell personal data, and we do not use your organisation's data to train any AI or machine-learning model — AcreTerminal does not use AI to process your data at all.

7. Cookies and tracking technologies

We use a small number of cookies and browser-storage mechanisms:

Strictly necessary — authentication session cookies that keep you signed in, set by our infrastructure provider and required for the Service to function. These cannot be switched off without losing the ability to sign in.

Preference — a local-storage flag that remembers your light/dark theme choice. This stays on your device and is never transmitted to us.

Analytics — where configured, we use a product analytics provider to understand aggregate feature usage (for example, which modules are used most) so we can prioritise product work. This does not read the content of your portfolio, lease or financial records.

We do not use third-party advertising cookies or cross-site tracking.

8. How we share information

We share information only with the sub-processors needed to run the Service, under contractual confidentiality and security obligations, and never for their own marketing purposes:

ProviderPurposeData involved
SupabaseDatabase, authentication and document storageAll application data, tenant-isolated by Row Level Security
RazorpaySubscription billing and payment processingBilling contact details and payment status (we do not store card numbers)
ResendTransactional email deliveryRecipient email address and message content for account/notification emails
Product analytics providerAggregate usage analytics, where enabledAnonymised or pseudonymised event data

No paid integration is active for your organisation until it is explicitly configured. We may also disclose information where required by law, to enforce our terms, or to protect the rights, property or safety of DesiAcres, our customers or the public.

9. International data transfers

India is our fully operational market and the primary jurisdiction from which the Service is run. Our sub-processors may store or process data in other countries in which they operate infrastructure. Where data is transferred outside the jurisdiction in which it was collected, we require our sub-processors to maintain security and confidentiality protections consistent with this policy.

10. Data retention

We retain organisation and account data for as long as the subscription is active and for a reasonable period afterward to allow reactivation, satisfy legal, tax and accounting retention requirements, and resolve disputes. Audit logs are retained in an append-only form for accountability. An organisation owner can request account deletion and a full data export from Settings; retention periods for specific record types can be configured per organisation where the product supports it.

11. Data security

Every table in our database enforces Row Level Security scoped to organisation membership, so one tenant's data is never visible to another by default. Privileged operations run server-side only — service credentials never reach the browser. Every material change to portfolio, lease, transaction and billing data writes an append-only audit-log entry. Full detail is on our Security page. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.

12. Your rights

Subject to applicable law — including, for data principals in India, the Digital Personal Data Protection Act, 2023 — you may have the right to: access the personal data we hold about you; request correction of inaccurate data; request erasure of your data, subject to our legitimate retention needs described above; withdraw consent where processing is based on consent; request a copy of your data in a portable format; and lodge a grievance with us (see Section 15) or with the competent supervisory authority.

For organisation and account-level data, an organisation owner or admin can export or delete data directly from Settings. For any other request, use the channel in Section 17.

13. Children's privacy

AcreTerminal is a business-to-business platform intended for use by working professionals on behalf of a company or organisation. It is not directed at, and we do not knowingly collect personal data from, individuals under the age of 18.

14. No AI, no automated profiling

Every score AcreTerminal produces — Property Suitability, Lease Health, Fair Rent, Negotiation Opportunity, the Corporate Verdict and every other algorithm — is a deterministic, versioned calculation over the property, lease and financial data your organisation enters. None of it is generated by an AI or machine-learning model, and none of it is used to make an automated decision producing legal or similarly significant effects about an individual person.

15. Grievance officer

In accordance with applicable Indian data protection and information technology law, DesiAcres Advisory Group has designated a privacy contact point to address grievances relating to the processing of personal data. You can reach this contact point through the channel in Section 17; we will acknowledge and work to resolve grievances within a reasonable time.

16. Changes to this policy

We may update this policy as the Service, our sub-processors, or applicable law change. We will update the “Last updated” date above, and for material changes we will make reasonable efforts to notify active organisation owners in advance of the change taking effect.

17. Contact us

Questions, requests or grievances about this policy can be directed to the DesiAcres team via our Contact page. Please describe your request clearly — including your organisation name if applicable — so we can route it correctly.

This document explains our practices in plain terms and is not a substitute for legal advice. If your organisation needs a signed Data Processing Agreement, custom contractual terms, or has questions this page doesn't answer, contact us directly.

We use only strictly necessary cookies — to keep you signed in and remember which organisation you're working in. We don't run analytics or advertising cookies today. See our Privacy Policy for details.