Last updated: 7 September 2026
Privacy Policy
The short version: we are a software services company in India, we do not sell personal data, we run no advertising, and the products we publish are built to compute on your own device wherever that is possible. This page explains the little we do collect on this website, how we handle client information during a project, and how you can ask us to change or delete what we hold.
On this page
- 1. Who we are
- 2. What this policy covers
- 3. The law we work under
- 4. What we collect on this website
- 5. Cookies, analytics and your choices
- 6. Business and client data
- 7. Third party processors and cross border transfer
- 8. Our products and health data
- 9. What we never do
- 10. How long we keep things
- 11. Your rights and how to use them
- 12. Grievance Officer
- 13. Children
- 14. Changes to this policy
1. Who we are
Truestep Solutions ("we", "us", "our") is a service based software company in India. Our work is client delivery: web application development, mobile app development for iOS, Android and cross platform, technology consulting and architecture, websites with a content management system, cloud and DevOps, UI and UX design, and maintenance and support retainers. Alongside that services business we also build and publish our own apps, the first of which is Apex Health: Sleep & Recovery, a free app for iPhone and Apple Watch.
For anything in this policy, write to legal@truestepsolutions.in. For sales and general questions the address is hello@truestepsolutions.in, and for help with a product it is support@truestepsolutions.in.
2. What this policy covers
This policy covers our website at truestepsolutions.in, the email you send us, the contact form on this site, and the personal data we handle in the ordinary course of running the services business, for example when we talk to a prospective client or deliver a project.
Individual products can have their own policies, which are presented inside the product and which take precedence for that product. The policy for our app is published at Apex Health: Sleep & Recovery Privacy Policy.
Where we deliver a project for a client, that client is usually the data fiduciary or controller for the personal data inside their own systems, and we act on their instructions as a data processor. Section 6 explains how that works.
3. The law we work under
We are established in India, so our processing is governed by Indian law, in particular the Information Technology Act 2000 together with the rules made under it, and the Digital Personal Data Protection Act 2023. Under that Act you are a Data Principal and we are the Data Fiduciary for the personal data we decide the purposes of, such as the message you send us through the contact form.
If you are in the European Economic Area or the United Kingdom, we handle your personal data in line with the General Data Protection Regulation and the UK GDPR as well. Two lawful bases are actually used on this site and nothing else:
- Legitimate interests. Running and securing the website, keeping cookieless visitor counts so we know which pages are useful, keeping standard server logs, and replying to an enquiry you have chosen to send us. We have weighed these against your interests and consider them limited, expected and low risk.
- Consent. Google Analytics, which loads in a denied state and stores nothing until you say yes, and any marketing email you have specifically asked to receive. You can withdraw consent at any time and it is as easy to withdraw as it was to give.
Where we deliver a project, the lawful basis for processing personal data inside a client's systems is set by that client, and our processing rests on the contract we have signed with them.
4. What we collect on this website
- No advertising pixels. This website carries no advertising trackers and no advertising cookies. Nothing on this site is used to target advertising at you here or anywhere else.
- Cookieless analytics, always on. We use GoatCounter to count page views. It sets no cookies, stores nothing on your device, and does not follow you across websites. Because it stores nothing, it runs for every visitor.
- Google Analytics, only if you allow it. Google Analytics is loaded in a consent denied state and sets no cookies and no identifiers until you agree. If you agree it sets first party cookies named
_gaand_ga_LPN3VNZ68H, which expire two years after they are set and let us tell a returning visitor from a new one. Advertising features and ad data sharing are switched off. - Your consent choice. Your answer to the cookie banner is kept in your browser under the localStorage key
ts-consent-v1. It never leaves your device and it is how we avoid asking you the same question on every page. - Email you send us. If you write to any of our addresses we receive your email address and whatever you put in the message, including any attachment. We use it to reply, to prepare a proposal if you have asked for one, and to keep a record of what was agreed.
- Contact form submissions. If you use the contact form we receive the name, email address, company, budget range and message that you type into it. We use that only to understand your enquiry and to reply to it. Every field you would rather leave blank, other than a way to reach you, is optional as far as we are concerned.
- Server logs. Our hosting provider keeps standard technical logs, which include the requesting IP address, the browser and operating system string, the page requested, and the time of the request. We use these only for security and reliability, for example to investigate an outage or block abusive traffic, and we do not use them to build a picture of you.
5. Cookies, analytics and your choices
The only cookies this site can set are the two Google Analytics cookies described above, and only after you have agreed. Everything else we use is either cookieless or stored in your own browser and never sent anywhere.
You can change your mind at any time from cookie preferences. Declining, or clearing your browser storage, returns the site to the denied state, and no analytics cookie is set again unless you agree again. You can also block or delete cookies in your browser settings, and you can opt out of Google Analytics on every site you visit with Google's browser add on.
6. Business and client data
Running a services business means we handle a certain amount of information about the people we work with. During a normal engagement that includes the names, work email addresses, job titles and phone numbers of the people at the client we deal with, the contents of our correspondence and meeting notes, project documents, requirements, designs and source code, invoicing and payment records, and the credentials or access tokens a client issues us so we can do the work.
In the course of building, testing, migrating or operating a client's system we may also come into contact with personal data that belongs to that client's own users, customers or staff. That data is processed strictly on the client's documented instructions and under the engagement contract signed with them, which sets out the purpose, the duration, the security measures and what happens to the data at the end of the project. We do not decide what that data is used for, and we do not keep it for our own purposes.
- Access is limited to the people actually working on that engagement, and it is removed when a person leaves the engagement or when the engagement ends.
- We prefer anonymised or synthetic data in development and test environments, and we ask clients for it wherever a real dataset is not strictly necessary.
- We do not use client data, client code or anything we see during delivery to train models.
- We do not use client data for our own marketing, and we do not name a client or describe their project publicly without their written permission.
- We hold confidentiality obligations to every client and we expect the same from anyone we bring onto a project.
7. Third party processors and cross border transfer
These are the third parties that actually appear on this website or that we rely on to run it:
- Google Fonts. The typefaces on this site are loaded from Google Fonts. Your browser requests the font files directly, and Google receives your IP address as part of that request.
- jsDelivr. The animation libraries used on some pages are loaded from the jsDelivr content delivery network, which receives your IP address in the same ordinary way.
- Google Analytics. Google acts as our processor for the analytics data described in section 4, and only when you have agreed.
- GoatCounter. Our cookieless page view counts, which contain no cookie and no identifier stored on your device.
- Our email provider. The service that carries and stores the mail you send to our addresses, so that we can read and reply to it.
- Our hosting provider. The service that serves this website and keeps the standard server logs described in section 4.
Some of these providers operate outside India, including in the European Union and the United States, so a cross border transfer of the limited data described above can occur. Where that happens the transfer is covered by the relevant contractual protections, including standard contractual clauses and the provider's own data processing terms, and by any conditions that Indian law places on transfers. We do not transfer client project data outside a client's agreed arrangement without their instruction.
8. Our products and health data
Apex Health: Sleep & Recovery reads Apple Health and Apple Watch data only with your explicit permission and processes it entirely on your device. No Truestep Solutions server receives your health data, because we operate none for it. There is no account, no analytics SDK, no advertising and no third party tracking inside the app.
The only outbound network call the app makes is a request that sends coarse coordinates to the Open-Meteo weather service, and only when you have granted location access, so the app can show local weather, sunrise, sunset and the UV index. No identifier is attached to that request.
The full policy for the app, including exactly which Apple Health categories it reads and writes and how to delete everything, is published at Apex Health: Sleep & Recovery Privacy Policy and is also available inside the app.
9. What we never do
- We never sell or rent personal data to anyone, and we do not treat data as a product.
- We never run third party advertising on this website or in our products.
- We never build profiles of you across websites or across products.
- We never use client data or health data to train models.
10. How long we keep things
- Enquiries and correspondence. Kept while the conversation is live and for up to two years afterwards, so we can pick up a thread you return to, then deleted.
- Contact form submissions. Same as above, and deleted sooner on request.
- Client project records. Kept for the length of the engagement and for the period the engagement contract specifies afterwards, then returned or deleted as that contract requires.
- Invoices and accounting records. Kept for as long as Indian tax and company law requires us to keep them.
- Server logs. Kept for a short period for security and reliability, and then rotated out.
- Analytics. Aggregate page view counts, which are not tied to a person, are kept for reporting. Google Analytics data is subject to the retention period configured in that product.
11. Your rights and how to use them
Under the Digital Personal Data Protection Act 2023 you can ask us for the following, and we will act on it unless the law requires us to do otherwise:
- Access. A summary of the personal data we hold about you and how it has been processed.
- Correction and completion. Correction of anything inaccurate and completion of anything incomplete.
- Erasure. Deletion of personal data we no longer need for the purpose it was collected for.
- Withdrawal of consent. Withdrawal of any consent you have given, at any time, as easily as you gave it.
- Grievance redressal. A route to complain to us first, described in section 12.
- Nomination. The right to nominate another person to exercise these rights on your behalf if you die or become incapable of exercising them yourself.
If the GDPR or the UK GDPR applies to you, you also have the rights of access, rectification, erasure, restriction of processing, portability, and objection to processing carried out on the basis of legitimate interests, and you may complain to your national supervisory authority.
To use any of these, write to legal@truestepsolutions.in and tell us what you want done. We may ask for enough information to be sure we are talking to the right person, and we will not use that information for anything else. There is no charge. If your request concerns personal data held inside a client's system, we will pass it to that client, who is the right party to decide it, and we will help them answer it.
12. Grievance Officer
As Indian law requires, we publish a point of contact for privacy grievances. If you are unhappy with how we have handled your personal data or your request, raise it here first and we will look into it properly.
- Role: Grievance Officer
- Organisation: Truestep Solutions
- Country: India
- Email: legal@truestepsolutions.in
We acknowledge every grievance within 48 hours of receiving it and we aim to resolve it within 30 days. If we need longer, we will tell you why and give you a date. If you are still not satisfied, you may take the matter to the Data Protection Board of India, or, where the GDPR applies to you, to your national supervisory authority.
13. Children
This website and our services are meant for businesses and for adults, and they are not directed at children. We do not knowingly collect personal data from a child. Our app is not intended for use by anyone under 16. If you believe a child has given us personal data, write to legal@truestepsolutions.in and we will delete it.
14. Changes to this policy
We will update this page when our practices change, and the date at the top will always show the current version. If a change is material we will make it obvious on the site, and where a change affects a product we will say so inside that product. Some things are not up for revision: we will not start selling personal data, we will not add advertising, and we will not move our on device health processing onto a server.
Questions, requests or complaints? Write to legal@truestepsolutions.in and a person will read it and reply.