Last updated August 20, 2026
Privacy Policy
This Privacy Policy explains how Rowsh (“we,” “us,” or “our”), based in Pakistan, collects, uses, stores, and protects personal information when you access the Rowsh platform — including our marketing website, web application, desktop application, mobile application, and public links such as booking links and forms. By using Rowsh, you agree to the practices described below. If your organization has executed a separate Data Processing Agreement (DPA) or enterprise contract, that document takes precedence where it explicitly differs.
Controller vs. processor. For content your team creates and the third-party personal data you process inside Rowsh (for example, CRM contacts, job candidates, helpdesk requesters, and form respondents), the organization that owns the workspace is the controller, and Rowsh acts as its processor, acting on the organization's instructions. For our own marketing site and account administration, Rowsh is the controller.
1. Information We Collect
We collect information in the following categories depending on how you use the platform:
1.1 Account & Profile Data
- Name, email address, profile photo, and role within your organization.
- Authentication credentials (stored as salted hashes — we never store plaintext passwords), multi-factor authentication settings, and login events.
- Membership, team assignments, space access, and permission levels (Owner, Admin, Member, Viewer, Guest).
1.2 Workspace & Space Content
Content you and your team create while using Rowsh modules, including:
- Projects & Tasks — project names, task titles, descriptions, subtasks, comments, assignees, due dates, priorities, custom fields, time tracking entries, and status updates.
- Team Chat & Calls — messages, threaded replies, reactions, channel membership, direct messages, and call metadata such as duration and participants. We do not record the audio or video content of calls.
- Calendar & Scheduling — events, recurring schedules, availability rules, public booking link settings, and reminders.
- Files & Documents — uploaded files, file metadata (name, type, size), version history, and folder structure.
- Notes & Whiteboards — documents, notes, whiteboard canvases, and their revision history.
- Approvals, Goals & Automations — approval workflows and decisions, goal and key-result definitions and progress, and automation rules with execution logs.
- Business modules — CRM deals, companies, contacts, and proposals; HR job openings and candidate records; Helpdesk tickets, messages, and SLA data; Marketing content and campaigns; and Operations processes (SOPs), vendors, and assets.
- Reports — report and KPI configurations, computed over your workspace data.
1.3 Chat Message Encryption & Compliance Access
Chat message content is encrypted in storage. To satisfy legal and safety obligations, an escrowed encryption key may allow a small number of authorized platform personnel to decrypt conversation content — but only where this is required for a compliance or safety investigation, in response to a valid legal request, or where your workspace has enabled a compliance feature that requires it. Such access is logged.
1.4 AI Feature Data
If you use Rowsh AI features (AI Copilot, task suggestions from chat, summaries, document Q&A, or daily briefings), we process relevant organizational content to generate responses. AI processing uses third-party model providers (currently OpenAI) or, where configured, self-hosted models via Ollama that keep processing inside the hosting infrastructure. We do not use your workspace content to train AI models, and we use provider API terms under which submitted data is not used for model training.
1.5 Website Chat Assistant
Our marketing website offers an AI chat assistant. Conversations with the assistant are associated with a random session identifier (not your browsing history) and are stored so we can answer your questions, hand the conversation to a human where needed, and improve the assistant's answers. Please don't share sensitive personal information in the website chat.
1.6 Forms, Booking Links & Guest Data
When someone submits a public or internal form, books a meeting through a public scheduling link, joins a call as a guest, or participates in guest chat, we collect the details they provide (such as name, email, message content, and any uploaded files) and the associated metadata, in order to deliver that feature to the organization that invited them. To protect against automated abuse, public forms may use a hidden honeypot field and a bot-protection challenge (Cloudflare Turnstile). The organization that created the form or link is the controller of the submitted data.
1.7 Technical & Security Data
- IP addresses, browser type, operating system, and device information.
- Server logs, error reports, and performance diagnostics collected to keep the Service reliable and secure.
- Audit logs recording security-relevant actions (login, permission changes, administrative actions).
1.8 Billing & Payment Data
- Billing contact name, email, and plan details.
- Payments are processed by third-party payment processors (currently Stripe and JazzCash) through their hosted checkout pages. Your full card or account details are handled by the processor and are never stored on Rowsh servers.
- Billing history, plan type, and subscription status.
1.9 Usage Analytics
We use privacy-focused, aggregate analytics on our marketing website (page views and web performance measurements that do not build individual visitor profiles or track you across other websites) and aggregated, de-identified product usage statistics (such as feature adoption) to improve the platform. Per-project and per-space analytics inside an organization (status breakdowns, assignee workloads, KPIs) are visible only to authorized members with appropriate permissions.
2. How We Use Your Information
We use the information we collect to:
- Operate the platform — authenticate users, enforce role-based and per-space access controls, deliver product features, and process real-time messaging and notifications.
- Provide AI-powered features — generate task suggestions, summaries, briefings, and answers based on your content when you use those features.
- Deliver forms, intake, and scheduling — accept form submissions and bookings, route them to the right space, send receipts and notifications, and block spam.
- Enable storage and integrations — store uploaded files in S3-compatible storage and support configured services.
- Send notifications — deliver in-app notifications and email alerts based on your configured preferences, plus essential service emails (signup verification, billing, and security notices).
- Ensure security — detect and prevent unauthorized access, fraud, abuse, and security incidents.
- Improve the service — analyze aggregated usage patterns to improve reliability, performance, and user experience.
- Fulfill legal obligations — comply with applicable laws, regulations, and valid legal processes.
3. Data Isolation, Spaces & Multi-Tenancy
Each Rowsh customer environment operates with tenant-level database isolation. Your data is stored in a dedicated database, logically separated from other customers. Spaces help organize work inside your environment — each with its own modules and access — but they do not change the isolation boundary between customers. Within your environment, visibility depends on space membership, role, and permission configuration.
4. Data Sharing & Third Parties
We do not sell, rent, or trade your personal information. We share data only in these circumstances:
- Service providers (subprocessors) — hosting and infrastructure providers, file storage providers, email delivery providers, real-time calling infrastructure, bot-protection (Cloudflare Turnstile), error and performance monitoring, payment processors (Stripe, JazzCash), and AI model providers (OpenAI), each engaged to help us run the Service and bound by contractual confidentiality and data-protection commitments.
- At your direction — when you share public booking links or forms, connect supported integrations, or invite guests and external collaborators.
- Legal requirements — when required by law, court order, or to protect the rights and safety of our users and the platform.
Customers may request a current list of subprocessors at any time via our contact page.
5. Data Security
- Encryption in transit — data transmitted between your device and our servers is encrypted using TLS.
- Encryption in storage — chat message content is application-level encrypted, and stored data and backups use the encryption-at-rest capabilities of our infrastructure providers.
- Access controls — role-based and per-space permissions (Owner, Admin, Member, Viewer, Guest) restrict access, and project visibility can be limited to specific members.
- Authentication — passwords are stored as salted hashes, multi-factor authentication is available, and sessions use HTTP-only cookies scoped to your environment with expiring tokens.
- Audit logging — security-relevant actions are logged and available to authorized owners and administrators.
No system is perfectly secure. If we become aware of a breach affecting your personal data, we will notify affected customers without undue delay and in accordance with applicable law.
6. Data Retention
- Active environments — data is retained for the duration of your subscription and active use of the platform.
- Cancelled or lapsed environments — after a subscription ends, data is retained for a grace period so you can renew or export, after which it may be permanently deleted.
- Account deletion — upon a verified deletion request, we remove personal data within 30 days, except where retention is required by law or for legitimate business purposes (e.g., billing and tax records).
- Backups — encrypted backups may retain data for up to 90 days after deletion for disaster recovery purposes, after which they are overwritten on a rolling basis.
7. Cookies & Tracking
We use essential cookies for authentication and security, functional cookies for preferences (such as theme), and privacy-focused, aggregate analytics on our marketing pages. We do not use advertising cookies or cross-site tracking pixels. See our Cookie Policy for details.
8. Your Rights & Choices
Depending on your jurisdiction, you may have the right to:
- Access — request a copy of the personal data we hold about you.
- Correction — update inaccurate or incomplete personal data via your profile settings or by contacting us.
- Deletion — request deletion of your account and associated personal data.
- Export — export your data using in-app export tools where available (including CSV export of forms and reports), or request a copy from us.
- Notification preferences — configure email notification settings from your account preferences. Essential service and security emails cannot be disabled.
- Restrict or object to processing — request that we limit certain processing of your data where applicable law provides this right.
To exercise these rights, contact your administrator or reach us directly. We will respond within 30 days. Note that for workspace content, the organization owner is generally the controller of that data and we act on their instructions; if you submitted data to an organization through a form or booking link, please contact that organization to exercise your rights.
9. International Data Transfers
Our infrastructure providers may store and process data in data centers located in different countries. Where personal data is transferred across borders, we rely on our providers' contractual data-protection commitments and, where required, appropriate legal transfer mechanisms. Customers with specific data residency requirements should contact us before purchasing.
10. Children's Privacy
Rowsh is a business tool and is not directed at individuals under the age of 16. We do not knowingly collect personal information from children. If we learn that we have collected data from a child under 16, we will delete it promptly.
11. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify account owners or administrators via email or in-app notification before the changes take effect. Continued use of the platform after the effective date constitutes acceptance of the updated policy.
12. Contact Us
If you have questions about this Privacy Policy or how we handle your data:
- Use the Contact page on our website.
- Email us at team@rowsh.com.
- Company: Rowsh, Pakistan.