Legal
Privacy Policy
Last updated: 21 April 2026
1. Who we are
Latch CRM is operated by Thoughtful Viewfinder Services ("Latch", "we", "us"), with its registered office in Pune, Maharashtra, India. Contact: hello@latchcrm.com.
This policy describes how we handle personal data collected through our website (latchcrm.com), our admin portal, and our buyer app.
2. Two roles: controller vs processor
Website visitors and prospects. Latch is the data controller for data we collect directly from you — for example, when you book a call, fill a contact form, or subscribe to updates.
Customer-tenant data. When a real-estate developer ("Customer") uses Latch, they remain the data controller for their buyer data. We act as a data processor on their behalf under a signed agreement.
3. Data we collect
- — Contact details — name, email, phone, company — when you book a call or contact us.
- — Account data — login credentials (hashed passwords), role, preferences — for registered users of the portal or app.
- — Usage and telemetry — IP address, device, browser, pages visited, timestamps — via server logs and analytics.
- — Customer-tenant data — buyer records, payment history, documents, tickets and related content — stored in a tenant-specific database.
- — Payment data — processed by Razorpay; we do not store card numbers on our servers.
4. How we use data
- — To deliver and operate the Latch service.
- — To respond to inquiries, schedule calls and provide customer support.
- — To send transactional notifications (invoices, receipts, security alerts, product updates).
- — To comply with legal obligations including Indian tax, RERA and IT Act requirements.
- — To improve product performance and troubleshoot issues.
We do not sell personal data. We do not run advertising on behalf of Customers using their buyer data.
5. Where data is stored
All production data is hosted on Amazon Web Services Mumbai region (ap-south-1). Each Customer-tenant has its own dedicated database. Daily backups with point-in-time recovery are retained for 35 days.
6. Sub-processors
We use the following sub-processors to deliver the service:
- — Amazon Web Services (AWS) India — hosting, storage, email (SES), SMS (SNS).
- — Razorpay — payment processing.
- — Meta (WhatsApp Cloud API) — WhatsApp delivery.
- — Google Workspace — internal email and meeting scheduling.
7. Security
- — HTTPS / TLS across all traffic.
- — Passwords stored using bcrypt; RS256 JWT session tokens.
- — Account lockout after five failed login attempts.
- — Role-based access control enforced on every server-side endpoint.
- — Audit log on every write to a Customer-tenant database.
8. Your rights
You can request access to, correction of, or deletion of your personal data by writing to hello@latchcrm.com. For buyer data held by a Customer-tenant, please contact that Customer directly; we will assist the Customer in honouring your request.
9. Retention
Customer-tenant data is retained for the life of the subscription plus 30 days, after which the tenant database is deleted unless a longer period is required by law. Website visitor data is retained for up to 24 months.
10. Cookies
We use a minimal set of cookies for session management and anonymised analytics (Google Analytics 4, with IP anonymisation). No third-party advertising cookies.
11. Changes to this policy
We will post changes on this page with the updated date. Material changes will be notified to active Customers by email at least 15 days in advance.
12. Contact
Privacy queries and grievance officer requests: hello@latchcrm.com. Postal: Thoughtful Viewfinder Services, Pune, Maharashtra, India.