Effective date: 5 August 2026 · Developer: CloudEon Tech
Evastra Studio is a CRM application for tailors to manage customers, measurements, orders and payments. This policy explains what data we collect, how we use it, and your rights.
1. Information We Collect
Account data — your name, email address, phone number, shop name and gender preference. If you sign in with Google, we receive your name and email address from your Google account.
Customer data — your customers' names, phone numbers, WhatsApp numbers, email addresses, postal addresses and body measurements that you enter into the app.
Order data — outfit types, prices, quantities, payment amounts, delivery dates and stitching instructions you record.
Photos / attachments — order reference images you capture or upload. These are stored on your device only and are never uploaded to our servers.
Usage data — basic diagnostic information (app crashes, sync errors) to help us fix problems.
2. How We Use Your Data
To sync your business data securely across sessions via Supabase cloud.
To send WhatsApp order-ready messages to your customers — only when you tap the send button.
To verify and activate your subscription after payment on our website.
To restore your data if you reinstall the app or change devices.
We do not use your data for advertising, profiling or marketing of any kind.
3. Payments & Subscriptions
Evastra Studio does not process payments inside the app. When you choose to subscribe, the app redirects you to our website (evastrastudio.netlify.app) where payment is completed via Razorpay. We never see or store your card number, bank account or UPI PIN — Razorpay handles all payment data directly and is PCI-DSS compliant.
After a successful payment on the website, our server-side function (hosted on Supabase) verifies the transaction with Razorpay using a secure server key and activates your subscription automatically. Your email address is used to match the payment to your Evastra Studio account.
4. Data Storage & Security
Cloud — business data is stored in Supabase (PostgreSQL) with row-level security so only your account can read your records. All connections use HTTPS/TLS encryption.
Local cache — a copy of your data is kept on your device in SharedPreferences for instant offline access.
Photos — stored in your device's local storage only. Never uploaded.
Passwords — hashed with bcrypt by Supabase Auth. We never store plain-text passwords.
5. Background Data Collection
Evastra Studio collects and syncs your business data (customers, orders, measurements) to Supabase servers approximately every 15 minutes in the background, even when the app is not actively in use. This ensures your data stays up to date across sessions. No personal information beyond what you have entered is collected during background sync.
6. Third-Party Services
Supabase — receives your account data and all business data (customers, orders, measurements) for secure cloud storage and authentication. Privacy Policy
Razorpay — receives your email address and payment amount when you subscribe via our website. Razorpay handles all card, UPI and bank account data directly. Privacy Policy
Meta WhatsApp Business API — receives your customers' phone numbers and the order message content only when you tap the WhatsApp send button. Privacy Policy
Google Sign-In — if you choose to sign in with Google, Google shares your name and email address with us to create or link your account. We do not receive your Google password or any other Google account data. Privacy Policy
We do not sell or share your data with any other third parties.
7. Data Retention
Your data is retained for as long as your account is active. If you delete your account, all associated data is removed from our servers within 7 business days. Local device data is cleared when you uninstall the app.
8. Children's Privacy
Evastra Studio is a business tool intended for adults. We do not knowingly collect data from anyone under 13 years of age.
9. Your Rights
Access — request a copy of your data.
Correction — update incorrect information directly in the app.
Deletion — request full account and data deletion.
Portability — request your data in a readable format.
We may update this policy as the app evolves. The effective date at the top will always reflect the latest revision. Continued use of the app after changes constitutes acceptance.