Privacy Policy
Last updated: 12 August 2026
This Privacy Policy explains how ChaseDocs handles personal data. ChaseDocs is a client document-collection service operated by PT Web Industri Teknologi, a limited liability company incorporated in Indonesia, trading as InPresenceLab (“ChaseDocs”, “we”, “us”).
We built ChaseDocs so that we hold as little of your clients' data as possible. Uploaded documents are routed into your own cloud storage wherever you connect it — we keep a reference, not the file. This policy describes exactly what that means.
1. Two different roles
Our responsibilities depend on whose data it is.
- Your firm's account data — we are the controller. Information about you and your staff (name, email, organisation, billing) is data we decide how to use, and this policy governs it.
- Your clients' documents and answers — you are the controller, we are the processor. When your firm requests documents from its clients, your firm decides what to collect and why. We process that data only to provide the service to you, on your instructions. You are responsible for having a lawful basis to collect it and for telling your own clients how you use it.
2. What we collect
From the firm (our customer)
- Account details: name, email address, and a securely hashed password (we never see your plain password).
- Organisation details: firm name, branding (logo, accent colour), and settings.
- Billing details: subscription plan and status. Card details are handled by our payment provider, Polar — we never receive or store your card number.
- Usage and technical data: IP address, timestamps, and request logs, used for security, abuse prevention, and rate limiting.
From your clients (via the no-login upload link)
- Contact details your firm enters about them (such as name and phone number or email) so we can deliver the request and reminders.
- The documents they upload and the answers they type into the request.
- File metadata: filename, file type, size, a checksum, and upload time.
- Message delivery status (for example, whether a WhatsApp message was delivered or read).
- A contact-permission record: whether your firm has confirmed it may contact that person, whether that person has since asked the firm to stop, and when each was recorded. We use it to decide whether a request or reminder may be sent at all.
On this marketing website
This website (usechasedocs.com) uses Google Analytics™ 4 to understand how the marketing pages are found and used — pages viewed, approximate location (derived from your IP address, which Google truncates), device and browser type, and which site or search referred you. It sets Google Analytics cookies in your browser for this purpose. We use it in aggregate, to see which pages work; we do not use it to identify you, and we do not run advertising or remarketing trackers on this site.
You can opt out with Google's browser opt-out add-on, by blocking cookies for this site, or with any tracker-blocking extension — the site works normally either way.
Analytics runs on this marketing site only. The ChaseDocs app and the no-login client upload portal are separate, and Google Analytics is not loaded there. Your light/dark mode choice is also stored in your browser; it never leaves your device and is not linked to you.
One thing does run in the app and the client upload portal: error monitoring (Sentry). It is not analytics — it does not track pages, sessions or people, and it sets no cookies. It reports only when something breaks: the error message, the browser and operating system, and the address of the page it happened on. We need it because the upload portal has no support channel — if an upload fails, there is no way for anyone to tell us, and without this we would never find out.
Two limits on it, which we consider part of the promise above. Access tokens are removed from every address before it is sent — the link your client opens contains a token, and it is replaced with a placeholder, so a working link can never end up in a monitoring log. And we do not use session recording: nothing captures what is on screen, so uploaded documents are never part of an error report.
3. How your clients' documents are handled
This is the part that matters most, so we will be specific.
- If you connect your own cloud storage (Bring Your Own storage). Uploads are routed directly into your own connected storage — currently Google Drive™, into a folder we create called “ChaseDocs Uploads”. ChaseDocs stores only a reference (a pointer to the file), plus metadata and the validation result. We do not keep a copy of the document. The file of record is always yours, in your own account, under your control.
- If you have not connected your own storage. Files are held in an access-restricted ChaseDocs storage bucket as a zero-configuration fallback, and are automatically deleted after a short retention period (14 days by default).
- The AI check. To validate a document, we make a temporary copy in memory, send it to our AI provider for the check, and discard it as soon as the check finishes. It is not written to disk by us and is not retained after processing.
- We never place document contents or personal data on any public or immutable store (including any blockchain).
- We do not sell personal data, and we do not use your clients' documents for advertising.
4. How we use data
- To provide the service: creating requests, delivering upload links, receiving uploads, and showing you results.
- To send request messages and reminders through your chosen channel.
- To run the AI validation check (document type, period, readability, completeness) and suggest a filename.
- To take payment and manage subscriptions.
- To keep the service secure: authentication, rate limiting, abuse prevention, and an audit log of key actions (our audit log deliberately records actions, not document contents).
- To provide support when you contact us.
5. AI processing
Uploaded documents are analysed by Anthropic's Claude models to check whether the document is the right type, covers the right period, is readable, and is complete. Content sent for validation is used solely to produce that result and is not used to train AI models. The result is advisory only — a human at your firm always reviews and decides whether to accept or reject an item.
6. Service providers (subprocessors)
We rely on a small number of providers to run ChaseDocs. Each only receives what it needs:
| Provider | Purpose | What it may process |
|---|---|---|
| Supabase | Database, authentication, fallback file storage | Account data, request/file metadata, fallback files |
| Railway | Application hosting | Traffic and application data in transit |
| Anthropic | AI document validation | A transient copy of an uploaded document |
| Polar | Payments (merchant of record) | Billing and payment details |
| Meta (WhatsApp Business Platform) | Message and reminder delivery | Recipient phone number and message content |
| Google (Drive API) | Bring-Your-Own storage, only if you connect it | Uploaded files, written into your own Drive |
| Google (Analytics) | Marketing-website analytics — this site only, never the app or the client upload portal | Page views, truncated IP address, device, browser, referrer |
| Sentry | Error monitoring for the app and the client upload portal — errors only, never analytics, no session recording | Error message and stack trace, browser and operating system, page address with access tokens removed |
When you connect Google Drive, we request the minimum permission needed
(drive.file), which lets us access only the files ChaseDocs itself creates — we cannot
see the rest of your Drive.
7. How long we keep data
- Files in the ChaseDocs fallback bucket: automatically deleted after the retention period (14 days by default).
- Files in your own connected storage: kept until you delete them. We never delete files from your cloud storage, including when you disconnect.
- Metadata, validation results, and audit records: retained while your account is active, so you have a record of what was requested and reviewed.
- Account and billing records: retained while your account is active and afterwards where we must for legal, tax, or accounting reasons.
- Upload links: expire automatically. We store only a cryptographic hash of each link token, never the link itself.
- Contact-permission records: kept while the account is active, including records that someone asked to stop being contacted. We keep those deliberately — deleting a “do not contact” record is how a person ends up being contacted again.
8. Security
- Encryption in transit (HTTPS) and encryption at rest for stored data.
- Storage credentials for your connected cloud are encrypted before being stored.
- Upload links are single-purpose, expiring, and stored only as a hash.
- Database access is restricted per organisation, so one firm cannot read another's data.
- Rate limiting, file-type restrictions, and security headers to reduce abuse.
- An append-only audit log that records actions without recording document contents.
No system is perfectly secure, but minimising what we hold is our main protection: for firms using their own cloud storage, we simply do not have the documents.
9. Your rights
As an Indonesian company we are subject to Indonesia's Personal Data Protection Law (Law No. 27 of 2022). Depending on where you live — including under Singapore's and Malaysia's Personal Data Protection Acts (PDPA) — you may have the right to:
- Access the personal data we hold about you.
- Correct data that is inaccurate or incomplete.
- Request deletion of your data.
- Withdraw consent, or object to or restrict certain processing.
- Receive a copy of your data in a portable format.
To exercise any of these, email hello@usechasedocs.com. We will respond within the period required by applicable law.
If you are a client of a firm that uses ChaseDocs (that is, you were asked to upload documents), please contact that firm first — they decide what is collected and why. We will support them in responding to you.
If you have asked a firm to stop contacting you, ChaseDocs gives them a way to record that against your details. Once they do, we stop sending you reminders straight away and we will not let a new request be sent to that record unless the firm reverses it. Your existing upload link keeps working, so you can still finish sending documents if you want to — we simply stop contacting you about it.
10. International transfers
We operate from Indonesia and our providers may process data in other countries. Where data is transferred across borders, we rely on the safeguards offered by those providers and take reasonable steps to ensure a comparable standard of protection.
11. Children
ChaseDocs is a business tool and is not directed at children. We do not knowingly collect personal data from children. If you believe a child's data has been provided to us, contact us and we will delete it.
12. Changes to this policy
We may update this policy as the product develops. We will change the “last updated” date above, and for significant changes affecting your rights we will notify account holders directly.
13. Contact us
PT Web Industri Teknologi (trading as InPresenceLab)
A limited liability company incorporated in Indonesia
Jl. Diponegoro
Kranggan, Gurah
Kabupaten Kediri, Jawa Timur 64181
Indonesia
Privacy questions and data requests: hello@usechasedocs.com
Questions about this page? Email hello@usechasedocs.com.
ChaseDocs