Last changed 2026-09-12
Privacy
This covers Shell, the studio operating system, at crm.turtlelabs.co.in. It is written to describe what the software actually does, so where it is specific, that specificity is deliberate. Turtle Labs runs other sites, and each has its own notice.
Who is responsible
Turtle Labs is the trading name of a sole proprietorship of Aditya Bisen, at #3, L2, Maxx Pride, Manish Nagar, Nagpur, Maharashtra 440037, India.
In the language of the Digital Personal Data Protection Act, Aditya Bisen, trading as Turtle Labs, is the Data Fiduciary and you are the Data Principal. A proprietorship has no legal personality of its own, so the person named here is the one accountable for your information, rather than a company standing between you and them.
You can reach us about anything here at info@turtlelabs.co.in.
What we hold, and why
Grouped by what it is, because the categories behave differently and deserve different treatment.
We do not buy information about you, we do not sell anything about you, and we do not use anything you write to train a model.
| Your account | Your email address, and your name if you gave one. There is no password: signing in works by a link sent to that address, which works once and expires in twenty minutes, and the link is stored hashed rather than in full. | So your workspace can find you, and so the people you invite can be told apart. |
|---|---|---|
| Enquiries | What you type into a contact form, and the address it came from. | To answer you. |
| Payments | What you bought, when, how much, and the reference Paytm gives us. Not your card number, which we never receive. | To prove you paid for what you have, and to keep the books. |
| Technical | Your IP address at the moment of a request, for rate limiting. | So the forms cannot be used to send mail at scale. |
What your studio puts in
Shell holds two different kinds of information, and they are not ours in the same way.
Your own account is ours to look after: the address you sign in with, who else is in your workspace, and what each of them is allowed to see.
The clients, projects, quotes and margins you record are your business records about your own customers. You decide what goes in and what comes out. We hold them so the software can show them back to you, and we act on your instructions rather than on our own judgement. In the language of the Act you are the fiduciary for that material and we process it for you.
- Every query is scoped to one workspace. There is no function in the code that loads a project from an id alone, so one studio’s list cannot be reached from another’s even by mistake.
- The demonstration shown before you sign in is a constant in the code and never in the database. No real client appears in it, and no demonstration row can appear in a real workspace.
- We do not read your client records to sell to those clients, we do not pass them to anybody, and we do not use them to train anything.
- If one of your clients asks you to delete their record, you delete it in Shell and it is gone. You do not have to ask us, and we would rather you did not have to.
You are responsible for telling your own clients what you hold about them. We cannot do that for you, because we do not know who they are or what you promised them.
The lawful basis
Your account and your workspace are processed because you asked for them: without an address there is nowhere to send a sign-in link and no workspace to open.
Your clients’ records are processed on your instructions, under the agreement you accepted when you opened the workspace. We are not the ones deciding what is kept about them; you are.
Enquiries and anything we send you are processed on your consent, which you gave when you submitted the form and can withdraw at any time.
Rate limiting is processed on our legitimate interest in not having the sign-in form used to send mail at scale, which is also your interest.
What is never done with it
We do not approach your clients. Their details are in Shell because you put them there, and a supplier that mines its customers’ customer lists is not a supplier anybody should keep.
Nothing in your workspace is used to train a model, to build a benchmark, or to produce anything shown to another studio. Your margins are not somebody else’s industry average.
Nothing you write to us is used as marketing copy, as a testimonial, or as an example, without asking you first and separately.
Who else touches it
Only the suppliers that make the service run, and each does one job.
Some of these operate outside India, so your information may be processed abroad. We rely on contractual protection with each of them.
We will hand something over if the law requires it. If we are allowed to tell you, we will.
| MongoDB Atlas | Stores the database. | Under contract, on infrastructure we configure. |
|---|---|---|
| Our mail relay | Sends sign-in links and replies. | Sees your address and the message. |
| Our hosting provider | Runs the server. | Sees requests as any host does. |
| Paytm | Takes payments. | Collects your card or bank details on its own page, under its own policy. We never see them. |
How long it stays
| Your clients, projects and figures | Until you delete them, or until you close the workspace, at which point the whole workspace goes. |
|---|---|
| Your account | Until you close it. An account with no activity for three years is deleted after we write to the address first. |
| Sign-in links | Twenty minutes, and once used they cannot be used again. They are stored hashed, so a copy of the database does not let anybody sign in as you. |
| Sessions | Thirty days, then you sign in again. |
| Enquiries | Two years, so we can pick up a conversation you started. |
| Rate limiting records | Minutes. They are held in memory and disappear when the process restarts. |
| Records of payment | Eight years, because tax law requires it. Closing your workspace does not remove these, and we would be breaking the law if it did. They hold what was bought and when, not anything about your clients. |
Your rights
Under the Digital Personal Data Protection Act you can ask us to do all of this, and we will not charge you for it.
Write to info@turtlelabs.co.in. We will answer within thirty days and usually much sooner.
- See what we hold about you, and get a copy of it.
- Correct anything wrong or incomplete.
- Delete it. Where you have a paid record we will tell you what deleting removes before we do it, and the record of the payment itself stays for as long as tax law says it must.
- Withdraw consent for anything based on consent, as easily as you gave it.
- Nominate somebody to exercise these rights if you die or become incapable.
- Complain, to us first and to the Data Protection Board of India if we do not resolve it.
Grievances
Our grievance officer is Aditya Bisen, reachable at info@turtlelabs.co.in.
We acknowledge within forty-eight hours and resolve within thirty days. If you are not satisfied, you may take it to the Data Protection Board of India.
Children
Shell is a tool for running a studio, which means it is for people running a business. It is not built for children and nothing here is aimed at them.
You must be eighteen or older to open a workspace or to be invited into one. We show no behavioural advertising and we do not track anybody across other sites.
If you believe a child has been given an account here, write to us and we will remove it.
Security
No system is perfectly safe. If something happens that puts your information at risk we will tell you and the Board, promptly and in plain words.
- Sign-in links and session tokens are stored hashed, never in readable form, so a copy of the database does not hand anybody a working login.
- A sign-in link works once and expires in twenty minutes.
- Player accounts and staff accounts are kept in separate collections behind separate cookies, so a fault in the public sign-up cannot produce access to the content management system.
- Connections are encrypted in transit.
Cookies
A cookie to keep you signed in, if you sign in. A preference stored in your browser for light or dark. Nothing for advertising, and no third-party tracker.
Changes
If we change something that matters we will say so on this page and, where it affects what happens to your information, write to you. The date at the top is the last change.