Privacy notice

Effective 15 August 2026

This notice explains what we do with personal data on yesroll.com and in the Yesroll application. It is written to be read, not to be survived.

1. Who we are

Yesroll is operated by SIMINO LABTEST PRIVATE LIMITED, incorporated in India. For anything in this notice — including a request about your own data — write tohello@yesroll.com. That address reaches the person responsible for privacy and grievances, and we answer it ourselves.

2. Two different roles, and which one applies to you

Almost every complaint about privacy policies comes from mixing these up, so they are separated here:

  • We are the controller for data about visitors to this website, people on the early-access list, and account holders. We decide why and how it is used, and sections 3 to 5 describe it.
  • We are the processor for data an organiser collects from their guests through a roll — the RSVPs, bookings, signups and answers. The organiser decides what to ask and why; we only hold and handle it on their instructions. Section 6 covers this.

If you responded to someone’s invitation and want your answer changed or removed, the organiser who invited you is the fastest route. If you cannot reach them, write to us and we will pass the request on and help.

3. What we collect as controller

  • Early-access sign-ups. Your email address, the time you submitted it, and a one-way hash of your IP address. We never store the IP address itself.
  • Account data. If you create an account: your email address, authentication records, the settings and rolls you create, and your plan and billing status.
  • Support and security correspondence. Whatever you choose to put in an email to us, and our reply.
  • Server and edge logs generated by our hosting provider, which may include IP address, user agent, requested URL and timestamp.

We do not buy personal data, we do not build advertising profiles, and we do not sell or share your personal data for cross-context behavioural advertising — under the California Consumer Privacy Act or otherwise.

4. Why we process it, and on what basis

  • To contact you about early access — your consent, given when you submit the form, withdrawable at any time.
  • To provide the service you asked for — performance of our contract with you, or steps taken at your request before it.
  • To keep the service available and prevent abuse — our legitimate interest in running a functioning, non-spammed service, weighed against your interests. This is why the anti-bot check and the rate limits exist.
  • To meet legal and tax obligations — compliance with law.

If you are in India, these correspond to processing for the purpose for which you gave consent, and to the legitimate uses recognised by the Digital Personal Data Protection Act, 2023. If you are in the UK or EEA, they are the UK GDPR and GDPR bases named above.

We will not sell your data, share it with advertisers, or send you a newsletter you did not ask for.

5. Cookies, analytics and third-party code

This site sets no advertising cookies, runs no third-party analytics, and loads no third-party fonts or images. Marketing pages are static files; visiting one runs no code of ours on a server at all.

There is exactly one third-party script on the site: Cloudflare Turnstile, the “are you human” check on our forms. It runs only on pages carrying a form, and Cloudflare states it is not used to track individuals across sites. Where you have an account, we use cookies that are strictly necessary to keep you signed in.

6. Data organisers collect from their guests

When you respond to a roll, the organiser who invited you chose what to ask. We hold their rolls and responses on their behalf and act on their documented instructions. We do not use guest data to market to guests, do not sell it, and do not use it to train models.

Organisers are responsible for having a lawful basis, for telling their guests what they are collecting, and for handling requests about it — see section 7 of theterms of service. Where an organiser needs a data processing agreement, write to hello@yesroll.com.

7. Who else processes it

We keep this list short on purpose, and it names the providers in use today rather than ones we might adopt:

  • Cloudflare, Inc. — Hosting, content delivery, DNS, DDoS protection, the Turnstile anti-bot check on our forms, and the key-value store holding early-access sign-ups. Global edge network, including servers outside your country.
  • Supabase, Inc. — The database and authentication service behind Yesroll accounts and rolls. Cloud regions selected by us; see their sub-processor list for detail.

We may also disclose personal data where we are legally required to, or to establish or defend legal claims. If Yesroll is ever acquired or merged, personal data may transfer to the successor under this same notice, and we will tell account holders before it does.

8. How long we keep it

  • Early-access sign-ups — until we have contacted you about access or you ask us to delete them, whichever is first, and no longer than 24 months from submission.
  • The hashed IP stored with a sign-up — deleted with the sign-up record. The separate rate-limiting counter expires automatically one hour after it is written.
  • Account and roll data — for as long as the account is open, then 30 days after it closes so it can be recovered, then deleted.
  • Billing and tax records — for the period the applicable tax law requires, which is longer than the account itself.
  • Server and edge logs — for the short retention window our hosting provider applies, after which they age out automatically.

9. Where it goes

Our providers operate global networks, so your data may be processed outside your country of residence, including in the United States. Where personal data protected by UK or EU law leaves that jurisdiction, we rely on the European Commission’s Standard Contractual Clauses (with the UK Addendum where applicable) as agreed in our contracts with the providers named in section 7, together with the technical measures in section 10.

10. How we protect it

Traffic is encrypted in transit. IP addresses used for abuse prevention are hashed, never stored raw. Access to production data is limited to those who need it. The site sets a strict Content Security Policy that permits no inline scripts and exactly one external origin. No system is perfectly secure, but these are the measures we actually run — not aspirations.

Suspected vulnerabilities:hello@yesroll.com.

11. Your rights

Wherever you live, you may ask us to give you a copy of your personal data, correct it, delete it, or stop using it, and you may withdraw a consent you gave. Depending on your jurisdiction you may also have rights to restrict or object to processing, to receive your data in a portable form, to nominate someone to act for you, and not to be subject to decisions made solely by automated means — we make none.

Email hello@yesroll.com. We do not require an account to make a request and we do not charge for one. We will verify who you are before acting, and we answer within 30 days. You may use an authorised agent. Exercising a right never results in worse service.

If you are unhappy with our answer: in India you may complain to the Data Protection Board of India; in the UK to the Information Commissioner’s Office; in the EEA to your local supervisory authority.

12. Children

Yesroll is not directed at children. We do not knowingly create accounts for, or take early-access sign-ups from, anyone under 16. An organiser who invites minors — a school or a club, for instance — is responsible for obtaining whatever parental consent their own law requires. If you believe a child’s data has reached us, write to us and we will delete it.

13. Changes

If we change this notice we update the effective date at the top of this page. Material changes are notified by email to account holders and early-access subscribers before they take effect.

14. Contact

Privacy, grievances and data requests:hello@yesroll.com