Privacy Policy
Redhorse Technologies Private Limited
Version 1.2 • Effective August 24, 2026
1. Introduction
Redhorse Technologies Private Limited ("Redhorse," "we," "us," or "our") operates React Native Stallion, a platform that enables developers to deliver over-the-air updates to their applications. This Privacy Policy describes how we collect, use, and protect personal information in connection with the Services, together with our Terms of Service.
By using the Services, you agree to the collection and use of information as described in this Privacy Policy.
2. Scope
This Privacy Policy applies to personal information collected through the Services, including our website, dashboard, APIs, and SDK components. It applies to customers, authorized users, and, where applicable, end-users of applications that integrate the Stallion SDK.
This Privacy Policy does not apply to information processed by our customers within their own applications, except to the extent such information is processed by us in connection with providing the Services, as described in Section 3.
3. Information We Collect
Information you provide to us:
- Account and profile information, including your name, email address, and company details.
- Application content, including bundles, updates, and configuration data you upload or deploy through the Services.
- Billing information, including billing address and subscription plan details. Payment card details are collected and processed directly by our third-party payment processors and are not stored by us.
- Correspondence, including support requests and communications with us.
Information we collect automatically:
- Technical and usage data, including IP address, browser type, device information, operating system, and diagnostic data, when you access the Services.
- Commercial information, including your plan history and record of Services used.
Information collected through the SDK:
- When end-users use applications integrated with the Stallion SDK, we may collect randomized identifiers and tokens used to determine update delivery status, along with crash logs and telemetry data, necessary to deliver updates and monitor application performance, on behalf of and as directed by our customer.
Aggregated and de-identified information: We may aggregate or de-identify information described above for purposes such as analytics and service improvement. Aggregated or de-identified data is not personal information and is not subject to this Privacy Policy.
4. Cookies & Tracking
We use cookies and similar technologies to operate the Services, remember preferences, and understand usage. We use essential cookies, required for core functionality such as authentication, and analytics cookies, used to understand how the Services are used.
Non-essential cookies are only set with your consent, where required by applicable law. You can manage cookie preferences through your browser settings, or via the Cookie Preferences controls on our site. For the full list of cookies and storage keys we use, see our Cookie Policy.
5. How We Use Information & Legal Basis
We use the information we collect for the following purposes:
To provide the Services: to deliver updates, operate your account, and enable core platform functionality.
To communicate with you: to send account notices, security alerts, and responses to support requests.
To improve the Services: to analyze usage, diagnose issues, and develop new features.
To ensure security: to detect, prevent, and address fraud, abuse, and security incidents.
To comply with legal obligations: where required by applicable law, including the Digital Personal Data Protection Act, 2023.
Our basis for processing this information is one or more of the following: performance of our contract with you, compliance with a legal obligation, our legitimate business interests in operating and securing the Services, or your consent, where required by applicable law. Where we rely on consent, you may withdraw it at any time, without affecting the lawfulness of processing carried out before withdrawal.
6. How We Share Information
We do not sell your personal information. We share information only in the following circumstances:
Service providers: with third-party vendors who help us operate the Services, including cloud infrastructure, content delivery, database hosting, messaging, and analytics providers, bound by contractual confidentiality and data protection obligations.
Payment processors: with third-party payment processors to process your payments. We do not store your payment card information.
Legal requirements: where required by law, regulation, court order, or governmental request, or to protect the rights, safety, or property of Redhorse, our users, or others.
Business transfers: in connection with a merger, acquisition, or sale of assets, subject to the same protections described in this Privacy Policy.
With your consent: for any other purpose disclosed to you at the time of collection or with your consent.
7. Data Residency & International Transfers
You may choose the regional data plane where your application content and related data are stored and processed, as available and selected at signup. We store and process this data in the selected region, subject to the exceptions below.
Certain information, including billing, account, authentication, and related administrative data, is processed on shared global infrastructure regardless of your selected region, as necessary to operate the Services.
Where information is processed outside your selected region, we rely on appropriate safeguards, such as standard contractual clauses or equivalent legal mechanisms, to help ensure it remains protected in accordance with this Privacy Policy.
8. Data Retention
Account information, including your name, email address, and account metadata, is retained for the duration of your active account and deleted or anonymized within 90 days of account closure, unless a longer period is required for legal, regulatory, or contractual purposes.
Application content, including bundles and updates you deploy through the Services, is deleted from production systems within 30 days of account termination or a verified deletion request, subject to the backup retention described below.
Technical, usage, and diagnostic data is retained for up to 90 days from the date of collection, unless a longer period is necessary for security purposes or required by law.
Analytics and telemetry data, including randomized identifiers and tokens used for update tracking and usage analytics, is retained for as long as necessary to support product analytics and service improvement.
Backup copies are retained on a rolling cycle for a longer period than production data, as necessary to support disaster recovery and business continuity, after which they are permanently deleted.
9. Security
We take the security of your information seriously and maintain a comprehensive set of technical and organizational measures designed to protect personal information from unauthorized access, use, disclosure, alteration, or destruction.
Technical safeguards. We encrypt data in transit and at rest using industry-standard encryption methods, and rely on infrastructure providers that maintain their own physical and environmental security controls. Our systems are monitored on an ongoing basis to detect and respond to potential security events.
Access controls. Access to systems and data is restricted based on the principle of least privilege, with multi-factor authentication enforced across critical systems. Access rights are reviewed periodically to ensure they remain appropriate.
Organizational safeguards. We maintain documented information security policies and procedures covering areas such as access management, incident response, vendor risk, and data handling. Personnel are required to acknowledge relevant policies and undergo periodic security awareness training.
Vendor and infrastructure security. Where we rely on third-party infrastructure and service providers to support the Services, we assess their security practices as part of our vendor management process.
Incident response. We maintain documented procedures for identifying, responding to, and managing security incidents.
If you have a security concern related to the Services, please contact us using the details in Section 15.
10. Data Breach Notification
In the event of a security incident that affects your personal information, we will take appropriate steps to investigate and address the incident, and will notify you without undue delay, in accordance with applicable law.
Where required, we will also notify relevant regulatory authorities of a security incident within the timeframes prescribed by applicable law.
11. Your Rights
You have certain rights regarding your personal information, subject to applicable law:
Access: You can request access to the personal information we hold about you.
Correction: You can request that we correct inaccurate or incomplete personal information.
Deletion: You can request deletion of your personal information, subject to any legal, regulatory, or contractual obligations that require us to retain it.
Grievance Redressal: You have the right to raise a grievance regarding our handling of your personal information and to have it addressed within the timelines prescribed by applicable law.
To exercise these rights, please contact us using the details in Section 15. We may need to verify your identity before responding to your request.
12. Children's Privacy
The Services are not directed at, and are not intended for use by, children, as defined under applicable law. We do not knowingly collect personal information from children without appropriate consent, or as otherwise permitted by applicable law.
If we become aware that we have collected personal information from a child without appropriate consent, we will take steps to delete that information from our systems.
13. Links to Other Websites
The Services may contain links to third-party websites or services that are not operated by us. We encourage you to review the privacy practices of any third-party site you visit.
We have no control over, and assume no responsibility for, the content, privacy policies, or practices of any third-party sites or services.
14. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, the Services, or applicable law. We will post the updated policy on this page and revise the effective date accordingly.
We encourage you to review this Privacy Policy periodically. For material changes, we may also notify you by email or through the Services.
Related Documents
15. Contact & Grievance Officer
If you have questions about this Privacy Policy or our data practices, or wish to exercise your rights under Section 11, please contact us at:
For grievances regarding the processing of your personal information, you may also contact our Grievance Officer at the email address above.