AlphaSutra
Help Login

Privacy Policy

Last updated: March 21, 2026

AlphaSutra ("we", "us", "our") operates the alphasutra.com website and WhatsApp-based platform. This policy describes how we collect, use, and protect your personal information across our Trading and CA/Tax Filing services.

1. Information We Collect

All users:

  • Account information: Name, WhatsApp phone number, role (trader or CA).
  • Messages: WhatsApp messages sent to our bot for command processing. Logged for debugging; not shared with third parties.
  • Usage data: Login timestamps, session data, and feature usage.

Traders:

  • Trading credentials: Zerodha Kite API key and secret (encrypted, used solely for executing trades on your behalf).
  • Trading data: Order history, positions, P&L records generated through the platform.

Chartered Accountants:

  • Client information: Client names, phone numbers, PAN numbers, email addresses, and broker details entered by the CA.
  • Uploaded documents: Form 16, AIS, capital gains statements, tradebooks, and other tax-related documents uploaded by CA clients via secure upload links.
  • Extracted data: Income, trade, and TDS data extracted from uploaded documents using automated processing.
  • Tax filings: Tax computations, filing status, and audit assessments generated on the platform.
  • Document passwords: Passwords provided for protected PDFs (used only during processing, not stored long-term).

2. How We Use Your Information

  • To authenticate you and provide platform services.
  • To execute trades on your behalf via Zerodha Kite Connect (traders).
  • To process uploaded documents and extract structured financial data (CA service).
  • To send trading signals, document upload requests, alerts, and reports via WhatsApp.
  • To generate P&L reports, tax computations, and analytics for your account.
  • To improve the accuracy of our AI models and document processing.

3. Data Storage and Security

Your data is stored on AWS infrastructure (Mumbai region, ap-south-1). API credentials are encrypted using AWS Secrets Manager. Uploaded documents are stored in Amazon S3 with encryption at rest. Database backups are stored in Amazon S3 with 90-day retention. We use HTTPS for all web traffic and HMAC signature verification for webhook security.

CA client documents are stored in isolated S3 paths per CA account. Upload links are token-based with 30-day expiry and do not require the client to create an account.

4. Third-Party Services

  • Meta (WhatsApp Business API): For message delivery. Subject to WhatsApp's Privacy Policy.
  • Zerodha Kite Connect: For trade execution (traders only). Subject to Zerodha's Privacy Policy.
  • AI providers (Anthropic, OpenAI, Google): For signal generation and document data extraction. Market data and document text may be sent for analysis; no raw personal information beyond document content is shared.
  • AWS Textract: For extracting text from uploaded documents. Documents are processed within the AWS Mumbai region.
  • Amazon Web Services: For hosting, storage, and infrastructure.

5. CA Client Data

CA clients (individuals whose documents are uploaded by a CA) are not platform users. They interact solely via tokenized upload links. We collect only the information the CA provides (name, phone, PAN) and the documents the client uploads. CA clients can request deletion of their data through their CA or by contacting us directly.

6. Data Sharing

We do not sell, rent, or share your personal information with third parties for marketing purposes. Data is shared only with the service providers listed above, solely for operating the platform. CA client data is accessible only to the CA who added the client.

7. Data Retention

Your account data, trading history, and tax filing data are retained as long as your account is active. Uploaded documents are retained in S3 until you or your CA requests deletion. Database backups are automatically deleted after 90 days. You may request deletion of your data at any time.

8. Your Rights

  • Access your personal data via the dashboard or by requesting an export.
  • Request correction of inaccurate data.
  • Request deletion of your account and all associated data.
  • Withdraw consent for data processing at any time.

9. Data Deletion

To request deletion of your data, visit our Data Deletion page or send "DELETE ACCOUNT" via WhatsApp. We will process your request within 30 days.

10. Contact

For privacy-related inquiries, contact us at contact@innorag.com.

11. Changes

We may update this policy from time to time. Changes will be posted on this page with an updated revision date.