SKIP TO CONTENT
Blueprint
§01 / 01Privacy Policy

Privacy Policy

Last updated · 22 April 2026 · REV.A

Blueprint Technologies ("Blueprint", "we", "our", "us") is committed to protecting the privacy of personal data we process under the Digital Personal Data Protection Act, 2023 ("DPDP Act"). This Privacy Policy explains what data we collect, how we use it, with whom we share it, and the rights you have as a Data Principal.

Data we collect

When you use Blueprint, we collect only the data needed to operate the platform: account data (name, email, phone, company), project data you create, billing data including GSTIN and TDS information, files you upload, and usage telemetry (page views, errors, request identifiers) for reliability and security.

Purpose of processing

  • Providing the platform and contractual services
  • GST invoicing and statutory compliance under Indian tax law
  • Security, fraud prevention, and service reliability
  • Support and product communication (you may opt out at any time)

Storage and security

Data is stored on Neon Postgres in India-adjacent regions and on AWS S3 / Cloudflare R2. Enterprise customers may pin data residency to a specific region or self-host. All transport is over TLS 1.2+; secrets are held in Key Vault; access is audited.

Third-party processors

Resend (transactional email), Firebase (chat + push notifications), Azure OpenAI (AI reviews, with data used only for inference — not for model training), and Vercel (hosting). Each processor has contractual obligations that mirror the DPDP Act.

Your rights

As a Data Principal, you can:

  • Access the personal data we hold about you
  • Correct inaccurate data
  • Erase your data (subject to retention required by tax law)
  • Withdraw consent where consent is the basis of processing
  • Nominate another person to exercise these rights on your behalf

Grievance officer

Please raise data-protection concerns with our Grievance Officer at support@myblueprint.co.in. We will respond within 15 days, as required by the DPDP Act.

Cookies and analytics

We use Vercel Analytics (cookieless) for Core Web Vitals and privacy-friendly traffic counts. Marketing analytics (GA4) load only after you accept cookies. No cross-site advertising trackers are used.

Changes to this policy

We'll notify account owners of material changes by email. The latest revision number is shown at the top of this page.