Legal

Privacy Policy

Effective date: 11 July 2026

This Privacy Policy explains how Horizonn (“Horizonn”, “we”, “us”, or “our”) collects, uses, stores, and shares personal information when you use our websites, applications, and related services (the “Service”). It is written for customers, administrators, employees invited into a workspace, and visitors — including requirements commonly reviewed by payment partners and Google OAuth verification.

01Who we are

Horizonn is a multi-tenant company operating system for India-focused organizations. The Service helps companies manage presence (attendance), time away (leave), compensation workflows, work logs, documents, announcements, and related people operations.

Our primary product domains are https://horizonn.in (marketing) and https://app.horizonn.in (application). For privacy questions, contact us at app@horizonn.in.

02Scope and roles

When an organization (“Customer”) creates a Horizonn workspace, that Customer is typically the data controller for employee and HR records they upload or generate in the workspace. Horizonn acts as a processor / service provider for that Customer data, processing it on the Customer’s instructions to provide the Service.

For account registration, billing, product analytics limited to operating the Service, security logs, and our own marketing site, Horizonn acts as a controller of the personal data we collect for those purposes.

03Information we collect

Account and organization information

  • Name, work email address, and password (stored as a secure hash) for administrators and users
  • Organization name, legal name, company email, GSTIN (if provided), and related company profile fields
  • Authentication and session data needed to keep you signed in securely

Google Sign-In information

If you choose “Continue with Google”, we request access to basic Google account profile information needed to authenticate you. In practice this includes your verified email address and display name from Google’s userinfo endpoint. We use this only to create or sign you into a Horizonn account, verify email ownership, and associate you with the correct organization workflow.

We do not use Google user data for advertising. We do not sell Google user data. We do not allow human review of Google user data except where required for security, abuse investigation, legal compliance, or with your explicit consent. Access tokens obtained during Google Sign-In are used to complete authentication and are not retained as a standing credential store beyond what is needed for the sign-in flow.

Employee and HR data (Customer content)

Depending on how a Customer configures the Service, workspaces may store employee profiles and operational records such as:

  • Identity and employment details (name, employee ID, department, role, contact details)
  • Attendance / presence records and work logs
  • Leave / time-away requests, balances, and approvals
  • Documents and announcements uploaded by the Customer
  • Sensitive identifiers where the Customer chooses to store them (for example PAN, Aadhaar, UAN, or ESIC numbers), which we encrypt at rest using application-level field encryption
  • Audit logs of administrative actions inside the workspace

Payment and billing information

Subscription and activation payments are processed by Razorpay on Razorpay-hosted checkout pages. Horizonn does not store full card numbers, UPI PINs, or netbanking credentials on our servers.

We may receive and store limited billing metadata from Razorpay such as payment link identifiers, payment status, amount, currency, timestamps, and the payer email associated with the transaction so we can activate the Customer workspace and support billing inquiries.

Technical and usage information

  • IP address, browser/device type, approximate location derived from IP, and timestamps
  • Security and diagnostic logs (for example failed sign-in attempts, webhook delivery status)
  • Cookies or similar technologies required for sessions, CSRF protection, and remembering preferences such as theme

04How we use information

  • Provide, operate, secure, and improve the Service
  • Create and authenticate user accounts, including Google Sign-In
  • Verify organization email addresses and complete onboarding / payment activation
  • Process payments through Razorpay and reconcile subscription status
  • Send transactional emails (verification, password reset, invites, billing notices, product notices required to operate the account)
  • Detect, prevent, and investigate fraud, abuse, and security incidents
  • Comply with applicable law and enforce our Terms of Service
  • Respond to support requests sent to app@horizonn.in

05Google API Services User Data Policy

Horizonn’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically: Google user data obtained through Google Sign-In is used only to provide or improve user-facing authentication and account features that are prominent in the Service’s user interface. We do not transfer Google user data to third parties except as necessary to provide/improve those features, for security, to comply with law, or as part of a merger/acquisition with notice. We do not use Google user data for serving advertisements. We do not allow humans to read Google user data unless we have your affirmative agreement for specific messages, it is necessary for security/compliance, or the data is aggregated and anonymized for internal operations.

06How we share information

We do not sell personal information. We share information only in the following circumstances:

  • Service providers who help us run Horizonn (for example cloud hosting, email delivery, and payment processing). These providers are bound to process data only for contracted purposes.
  • Razorpay, for payment collection and settlement related to Customer subscriptions.
  • Google, only as needed to complete OAuth authentication when you choose Google Sign-In.
  • Within a Customer workspace, to other authorized users of that organization according to roles and permissions configured by the Customer.
  • When required by law, regulation, legal process, or to protect the rights, safety, and integrity of Horizonn, our users, or the public.
  • In connection with a merger, acquisition, financing, or sale of assets, subject to appropriate confidentiality and notice where required.

07Storage, security, and location

We host the Service on cloud infrastructure and apply administrative, technical, and organizational measures designed to protect personal data, including encryption in transit (TLS), encryption of selected sensitive fields at rest, access controls, and session security.

No method of transmission or storage is perfectly secure. Customers remain responsible for configuring workspace access carefully, protecting administrator credentials, and deciding which employee data to store in Horizonn.

Where Customer content includes Indian identity or payroll identifiers, Customers should ensure they have a lawful basis and employee notice under applicable Indian law before uploading that data.

08Retention

We retain account and billing records for as long as the Customer account remains active and for a reasonable period afterward as needed for audits, dispute resolution, fraud prevention, and legal obligations.

Customer workspace content is retained according to the Customer’s account lifecycle. If a Customer requests deletion of a workspace, we will delete or anonymize associated personal data within a commercially reasonable period, except where we must retain limited records for legal, security, or financial compliance.

Security logs and backup copies may persist for a limited additional period before being rotated.

09Your choices and rights

Depending on your role and applicable law, you may request access, correction, or deletion of personal information we hold about you.

  • Employees and workspace users should generally contact their organization administrator first, because the Customer controls most HR records in the workspace.
  • Account holders and administrators can update profile and organization settings in the product, or email app@horizonn.in.
  • You may disconnect Google Sign-In by using password-based access (where available) and removing Google authorization from your Google Account permissions page.
  • You can opt out of non-essential marketing emails by following unsubscribe instructions in those emails. Transactional emails required to operate the Service will continue.

10Children

The Service is designed for business use by organizations and working adults. It is not directed to children under 18, and we do not knowingly collect personal information from children.

11Changes to this policy

We may update this Privacy Policy from time to time. We will post the updated version on this page and revise the effective date. Material changes may also be communicated by email or in-product notice where appropriate. Continued use of the Service after an update constitutes acceptance of the revised policy to the extent permitted by law.

12Contact

Privacy requests and questions: app@horizonn.in

Website: https://horizonn.in

Application: https://app.horizonn.in

Questions about this document? Email app@horizonn.in.

Also see our Terms of Service.