1. Who We Are
Sprint Track is a project and work management platform operated by Axceera (Private) Limited, also written Axceera (Pvt) Ltd., a company incorporated in Sri Lanka, company registration number PV 00252314, with its registered office at 157/3 Kadawatha Road, Nadimala, Dehiwala, Sri Lanka.
In this Privacy Policy, "Axceera", "we", "us", and "our" mean Axceera (Private) Limited. "Sprint Track" means the Sprint Track product and service, including sprintrack.com, app.sprintrack.com, api.sprintrack.com, our APIs, and related services.
Axceera (Private) Limited is the data controller for personal information described in this Privacy Policy, except where we act as a processor on behalf of a customer, as described in section 6.
For any privacy question or request, contact us at hello@sprintrack.com.
2. Scope
This Privacy Policy explains how we collect, use, share, and protect personal information when you visit our website, create an account, join a workspace, use the Sprint Track platform, access a shared project as a guest, contact us, or otherwise interact with our services.
Sprint Track includes workspaces, projects, tasks, cycles, modules, comments, documents, dashboards, labels, imports, notifications, attachments, roles, permissions, time tracking, and related collaboration features. Some features described in this policy are optional and apply only where they are enabled for your workspace or where an administrator has connected them.
By using Sprint Track, you acknowledge that your information will be handled as described in this Privacy Policy.
3. Information We Collect
Account Information
When you create or use an account, we collect your name, email address, authentication credentials (stored only as a hash, never in plain text), profile image, workspace memberships, role, preferences, verification status, and account activity.
If you enable two-factor authentication, we store a time-based one-time password secret and a set of encrypted backup codes.
Authentication and Device Information
We record information about sign-in activity, including IP address and browser user agent, on session records, sign-in attempts, and security events. We read your IP address from standard proxy headers provided by our infrastructure provider.
We also record failed sign-in attempts, including the email address used and the originating IP address, in order to detect and block credential-stuffing and brute-force attacks.
This information is retained server-side for security and abuse prevention only. It is not returned through the product's interfaces: the workspace audit log shows only whether an IP address and user agent were recorded, never the values themselves, and session responses are stripped of them. Workspace administrators therefore cannot use the audit log to see a colleague's IP address.
Enterprise Identity Information
If your organisation connects single sign-on (SSO) or SCIM user provisioning, we receive identity information from your identity provider. This includes the issuer, verified domains, group memberships, and a user profile attribute set whose contents are determined by your identity provider, not by Sprint Track. Your organisation controls which attributes are sent.
Workspace and Project Content
We store the content you and your colleagues create in Sprint Track: projects, tasks, issues, comments, documents, decisions, dashboards, labels, time logs, notifications, and related records. Depending on how your workspace is configured, this may include member hourly rate information used for cost and budget reporting.
Files and Uploads
We store files you upload — issue attachments, project and workspace documents, and integration artifacts — in object storage. Where the planning features are enabled for your workspace, uploaded sources may include audio recordings, which are sent to our AI provider for processing as described in section 7.
Guest Project Share Information
Where a project is shared externally, a guest who opens that share is not an account holder but is still a data subject. For guest sessions we collect the guest's name and email address, a hashed access token, IP address and user agent during verification, and derived browser and location hash values used to detect session sharing and abuse. Guest sessions expire automatically.
Billing Information
Payments are processed by Paddle, which acts as Merchant of Record. Paddle collects and processes your payment details directly. We never receive or store your full card number. We store Paddle identifiers (customer, subscription, transaction, address, and payment method references), plan and billing status, and invoice metadata. Card brand, last four digits, and expiry are retrieved from Paddle when displayed and are not retained by us.
AI Usage Information
Where AI features are enabled, we record operational telemetry for each AI operation: the model used, token counts, latency, status, rate version, and cost. This telemetry contains no prompt text and no model output.
Communications
When you contact us, respond to a form, or receive product and service email, we collect the content of those communications and related delivery metadata.
Service Logs
Our infrastructure provider records request logs and traces for the Sprint Track application. These are retained by that provider and used for reliability, debugging, abuse prevention, and security investigation.
Cookies and Similar Technologies
Sprint Track uses a small number of cookies, all of which are strictly necessary or functional. We do not use advertising cookies, analytics cookies, tag managers, or third-party tracking pixels. See our Cookie Policy for the full inventory.
4. How We Use Information
We use personal information to:
- Provide, operate, maintain, and secure Sprint Track.
- Create and manage accounts, workspaces, memberships, roles, and permissions.
- Authenticate users, enforce two-factor authentication, and support enterprise identity.
- Deliver the features you use, including AI features where enabled for your workspace.
- Process payments, manage subscriptions, and maintain billing and usage records.
- Provide customer support and respond to requests.
- Detect, investigate, and prevent fraud, abuse, spam, and security incidents.
- Monitor reliability, diagnose faults, and improve performance and product quality.
- Send transactional, account, billing, support, legal, and security messages.
- Send product and marketing communications where permitted, subject to section 18.
- Comply with legal obligations and enforce our agreements.
We do not sell personal information, and we do not share it for cross-context behavioural advertising. We do not use your workspace content to train AI models — see section 7.
5. Legal Bases for Processing
Where a legal basis is required, we rely on one or more of the following:
| Purpose | Legal basis |
|---|---|
| Providing Sprint Track under our Terms | Performance of a contract |
| Billing, invoicing, and collections | Performance of a contract; legal obligation |
| Account security, abuse prevention, and fraud detection | Legitimate interests; legal obligation |
| Service reliability, diagnostics, and product improvement | Legitimate interests |
| Customer support | Performance of a contract; legitimate interests |
| Marketing communications | Consent, or legitimate interests where permitted |
| Optional cookies and optional processing | Consent |
| Responding to legal process and regulatory requirements | Legal obligation |
Where we rely on legitimate interests, we have assessed that those interests are not overridden by your rights and freedoms. You may object to that processing as described in section 13.
6. Customer Content and Workspace Control
When an organisation uses Sprint Track, that organisation is the controller of the personal information contained in its workspace content, and Axceera acts as a processor on its behalf, subject to our Data Processing Agreement.
In that situation:
- The customer decides who may join the workspace, what content is stored, and how long it is kept.
- Workspace administrators can access, export, modify, and delete workspace content, including content you created.
- If you ask us to exercise a data subject right over workspace content, we will direct your request to the customer, or assist the customer in responding, rather than acting unilaterally.
Axceera remains the controller for account, authentication, security, billing, and service-operation information described in section 3.
7. Artificial Intelligence Features
Sprint Track includes optional AI features. They operate only where enabled for your workspace, and an administrator controls whether they are available.
Provider. AI inference is performed by Google's Gemini API. Content you submit to an AI feature — your prompt, the project or document context that feature is grounded in, and any uploaded source including audio — is transmitted to that provider in order to generate a response.
Retention at the provider. For the conversational AI surfaces — Ask, agents, and Project Memory — we send requests with the provider's stateless option enabled, so the provider is instructed not to retain the interaction. This option is not available on all provider endpoints. Document summarisation, document answers, and embedding generation use standard provider endpoints that do not offer it. For those operations, the provider's handling of submitted content is governed by Google's API terms.
Training. Axceera does not use your workspace content to train, fine-tune, or improve any AI model, and does not sell or license it. We have no training pipeline and no mechanism to export customer content to a model provider for that purpose. The AI provider's own use of submitted data is governed by their API terms, linked above.
What we retain.
- Conversation history — your AI conversations, including message content and generated summaries, are stored in our database as workspace content and remain available to you until deleted. Conversations attached to a project are deleted automatically when that project is deleted.
- Semantic index — Project Memory stores embedding vectors together with scope identifiers (workspace, project, source, timestamp). The vector store holds no raw text. A separate full-text search index in our database does hold the indexed source text.
- Spend ledger — AI usage is billed from a prepaid balance recorded in an append-only ledger that stores model, rate, and unit counts only. It contains no prompt content and no model output.
Grounding and citations. AI answers may cite workspace sources. Citations are re-authorised against your current permissions every time an answer is read, and content is redacted if a cited source has since become inaccessible to you. Grounding material is treated as untrusted input throughout.
8. How We Share Information
We do not sell personal information or workspace content. We share information only as described below.
Sub-processors
We share information with a small set of vendors that host, operate, secure, support, and bill for Sprint Track. Our current sub-processors, the purpose of each, their processing locations, and the data each receives are published at sprintrack.com/sub-processors.
We maintain that list and give customers at least 30 days' notice before adding or replacing a sub-processor.
Workspace Members and Administrators
Workspace content and activity are visible to workspace administrators and to authorised members according to the roles, permissions, and project access configured in your workspace.
Customer-Enabled Integrations
If a customer or authorised user connects an integration — for example a source-code provider, or an assistant application that connects to Sprint Track — we share information with that service as necessary to provide the requested connection. These integrations are off unless enabled, and once enabled the third-party service is governed by its own terms and privacy policy.
Legal and Safety Reasons
We may disclose information where we believe in good faith that disclosure is necessary to comply with law, legal process, or a lawful government request; to enforce our agreements; to protect rights, property, or safety; to investigate abuse; or to protect the security of Sprint Track, our users, our customers, or the public.
Business Transfers
If Axceera is involved in a merger, acquisition, financing, reorganisation, sale of assets, insolvency, or similar transaction, information may be transferred as part of that transaction, subject to appropriate confidentiality and legal protections. We will notify affected customers where required.
9. International Data Transfers
Axceera is established in Sri Lanka, and our sub-processors process data in several countries including the United States and the European Union. Sri Lanka is not the subject of a European Commission adequacy decision.
Where we transfer personal information out of the European Economic Area, the United Kingdom, or Switzerland, we rely on appropriate safeguards, including:
- The European Commission's Standard Contractual Clauses;
- The UK International Data Transfer Addendum for transfers subject to UK GDPR;
- Equivalent contractual protections in our agreements with sub-processors.
You may request further information about the safeguards applying to a specific transfer by contacting us at hello@sprintrack.com.
10. Data Retention
We retain information for as long as necessary to provide the service, maintain security, comply with legal obligations, resolve disputes, and enforce our agreements. Specific periods:
| Information | Retention |
|---|---|
| Workspace content (projects, issues, comments, documents, files) | Retained until deleted by an authorised user or administrator, or until the workspace is deleted |
| AI conversations | Retained until deleted by you, until the project they belong to is deleted, or until the workspace is deleted. Conversations that never received a message are cleared after 30 days |
| Workspace audit logs | 90 days on standard plans; up to 12 months where an Enterprise plan provides extended retention |
| IP address and user agent within audit and security records | Redacted after 90 days, on every plan, even where the underlying record is retained longer |
| Security event records | Up to 13 months, for security investigation |
| Platform administrator audit records | Up to 24 months, to maintain accountability for internal access to customer environments |
| Sign-in attempt records | 90 days, excluding records subject to an active account lockout |
| Expired sessions and verification codes | Purged shortly after expiry |
| Pending invitations | Purged after expiry |
| AI usage telemetry (no prompt content) | Up to 13 months, for billing and dispute resolution |
| Action and event records in the platform runtime | 180 to 365 days depending on record type |
| Deleted workspaces and projects | Recoverable for 30 days, then permanently purged |
Some information may persist for a limited additional period in backups, infrastructure logs, or archived systems. We may retain information longer where required by law, necessary for fraud or abuse prevention, or necessary to establish, exercise, or defend legal claims.
11. Deletion and Recovery
When a workspace or project is deleted, it is suspended rather than immediately destroyed. A recovery export is created, and the data remains restorable for 30 days. After that window it is permanently purged, including the associated files in object storage.
A workspace with an active paid subscription must have that subscription cancelled before it can be deleted.
12. Security
We use administrative, technical, and organisational safeguards designed to protect personal information and customer content. These include encryption in transit, encryption at rest provided by our infrastructure provider, envelope encryption of third-party connector credentials, hashed storage of authentication and API tokens, two-factor authentication with step-up verification for sensitive actions, workspace isolation with role and permission checks on every request, approval gates on outbound writes to connected systems, and monitoring for abuse and unauthorised activity.
Our Security page describes these measures in more detail.
No service can guarantee absolute security. You are responsible for protecting your credentials, using appropriate account security practices, reviewing workspace membership, and notifying us promptly at hello@sprintrack.com if you suspect unauthorised access.
13. Your Rights (EEA, UK, and Switzerland)
Subject to applicable law, you have the right to:
- Access the personal information we hold about you;
- Rectify inaccurate or incomplete information;
- Erase personal information in certain circumstances;
- Restrict processing in certain circumstances;
- Object to processing based on legitimate interests, and to direct marketing at any time;
- Portability — receive personal information you provided in a structured, commonly used, machine-readable format;
- Withdraw consent at any time where processing is based on consent, without affecting processing carried out before withdrawal.
How to exercise these rights. Contact us at hello@sprintrack.com. We will respond within one month, and may extend by two further months for complex requests, telling you if we do. We may need to verify your identity before acting.
Please note: Sprint Track does not currently provide a self-service data export or self-service account deletion feature. Requests under these rights are fulfilled manually by our team following the process above. We are working to make these available in-product.
If your information is controlled by a Sprint Track customer, such as your employer or workspace owner, we will direct your request to that customer or assist them in responding, as described in section 6.
Complaints. You have the right to lodge a complaint with your local supervisory authority. In Sri Lanka, this is the Data Protection Authority established under the Personal Data Protection Act, No. 9 of 2022. We would appreciate the chance to address your concern first.
EU and UK representative. Axceera has not appointed a representative under Article 27 of the GDPR or UK GDPR. You may contact us directly at hello@sprintrack.com on any matter that would otherwise be directed to a representative.
14. Your Rights (United States)
If you are a resident of California or another US state with a comprehensive privacy law, this section applies to you in addition to the rest of this policy.
Categories of personal information we collect, using the categories set out in the California Consumer Privacy Act:
| Category | Collected | Examples |
|---|---|---|
| Identifiers | Yes | Name, email address, account identifier, IP address |
| Customer records | Yes | Account credentials (hashed), billing contact details |
| Commercial information | Yes | Subscription plan, transaction and usage records |
| Internet or network activity | Yes | Sign-in activity, audit records, service logs |
| Professional or employment information | Yes | Workspace role, team membership, hourly rate where configured |
| Geolocation data | No | We do not collect precise geolocation |
| Biometric information | No | — |
| Sensitive personal information | No | We do not knowingly collect it, and we do not use or disclose it for purposes requiring a right to limit |
| Inferences | No | We do not build profiles or draw inferences for advertising |
Sources. Directly from you; from your organisation and its administrators; from your identity provider where SSO or SCIM is connected; automatically from your use of the service; and from our payment processor.
Business purposes for disclosure. We disclose personal information to the sub-processors listed at sprintrack.com/sub-processors for the operational purposes described in section 4.
We do not sell personal information, and we do not share it for cross-context behavioural advertising. We have not done so in the preceding twelve months. We do not knowingly sell or share the personal information of consumers under 16 years of age.
Your rights. You have the right to know, to access, to correct, to delete, to opt out of sale or sharing (which does not apply, as we do neither), to limit the use of sensitive personal information (which does not apply, as we do not collect it for such uses), and to be free from discrimination for exercising any of these rights.
How to exercise. Contact hello@sprintrack.com. We will confirm receipt within 10 business days and respond within 45 days, extendable by a further 45 days where reasonably necessary. You may use an authorised agent, who must provide written proof of authorisation.
15. Administrator Responsibilities
If you administer a Sprint Track workspace, you are responsible for:
- Ensuring you have a lawful basis and all necessary rights, notices, and consents for the personal information placed in your workspace.
- Informing your users about how workspace content is handled.
- Managing membership, roles, permissions, and project access.
- Managing exports, imports, integrations, file access, and external project shares.
- Deciding whether AI features and third-party integrations are enabled.
- Ensuring workspace content is lawful and appropriate for Sprint Track.
- Responding to privacy requests concerning workspace content you control.
16. Sensitive Information
Sprint Track is intended for project and work management. Unless we have entered into a separate written agreement that expressly permits it, you must not submit protected health information, full payment card numbers, government identification numbers, financial account credentials, biometric data, children's data, or other highly regulated sensitive information to the service.
17. Children's Privacy
Sprint Track is a business product and is not directed to children. We do not knowingly collect personal information from anyone under 16 years of age in the European Economic Area and the United Kingdom, or under 13 years of age elsewhere, or under the higher minimum age required by applicable local law. If we learn that we have collected such information without appropriate consent, we will take reasonable steps to delete it.
18. Marketing Communications
We may send product, educational, event, or marketing communications where permitted. You can opt out at any time using the unsubscribe link in the message or by contacting hello@sprintrack.com. We will still send transactional, account, billing, support, legal, and security messages, which are necessary to provide the service and cannot be opted out of while you hold an account.
19. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will provide notice through the service, by email, on our website, or by another appropriate channel. The updated policy takes effect when posted unless a later effective date is stated. The "Last updated" date and version number at the top of this page always reflect the current version.
20. Contact
For any privacy question, request, or complaint:
Axceera (Pvt) Ltd 157/3 Kadawatha Road, Nadimala, Dehiwala Sri Lanka Company registration number: PV 00252314
Email: hello@sprintrack.com
