Legal
Privacy policy
How MECoLab handles your data — what we collect, how we use it, and how it's secured.
Last updated · June 2026
MECoLab (“we”, “our”, or “us”) is committed to protecting the privacy of your organisation’s data, including the personal information of your staff and the beneficiaries you serve. This policy explains what we collect, how we use it, and the measures we take to keep it secure.
Data we collect
Account information: name, email address, phone number, and organisation details you provide when you register or are onboarded to MECoLab.
Programme data: project details, budgets, activity logs, milestone updates, beneficiary records, and indicator data that you or your team enter into the platform.
Uploaded content: photos, documents, spreadsheets, and other files you attach as evidence or upload for reporting purposes.
Usage data: information about how you interact with MECoLab, including pages visited, features used, and time spent, collected via standard analytics tools.
Device information: browser type, operating system, and IP address, collected automatically for security and performance monitoring.
How we use your data
To provide, operate, and maintain the MECoLab platform for your organisation.
To generate reports, dashboards, and data exports that you request within the platform.
To improve the platform based on aggregated, anonymised usage patterns.
To communicate with you about your account, including updates, support requests, and service notifications.
To ensure the security and integrity of the platform, including detecting and preventing unauthorised access.
We do not sell your data. We do not share your programme data with third parties. We do not use your data to train AI models.
Data storage & security
All data is stored on secure Supabase infrastructure, which provides encryption at rest (AES-256) and in transit (TLS 1.3).
All data is stored on servers within India. Your data does not leave Indian data centres.
Access to data is governed by role-based access controls (RBAC). Each user sees only what their role permits.
Database-level Row Level Security (RLS) policies enforce access rules at the infrastructure layer.
We conduct regular security reviews and keep all dependencies updated to address known vulnerabilities.
Backups are taken daily and encrypted. In the event of a disruption, data can be restored to the most recent backup.
Data retention
We retain your organisation's data for as long as your account is active. If you discontinue service, we will export and return your data upon request.
Upon account termination, all data is permanently deleted from our systems within 60 days. Backups are purged within 90 days.
Anonymised usage analytics may be retained indefinitely for product improvement purposes.
Third parties
We use Supabase for database and authentication infrastructure. Supabase's privacy and security practices apply to the data stored there.
We may use analytics services to understand platform usage. These services receive only anonymised, aggregate data.
We do not share your data with any other third parties unless required by law or with your explicit consent.
Your rights
You have the right to access, correct, or delete the personal data associated with your account at any time.
You may request a full export of your organisation's data at any point, free of charge.
You may request deletion of your account and associated data at any time. We will comply within 60 days.
To exercise any of these rights, contact us at hello@mecolab.in.
Changes to this policy
We may update this privacy policy from time to time. If we make material changes, we will notify account administrators via email at least 30 days before the changes take effect.
Continued use of MECoLab after changes take effect constitutes acceptance of the updated policy.
Contact us
If you have questions about this privacy policy or how your data is handled, reach out to us at hello@mecolab.in.