Privacy Policy
SourceFuse Reporting · Insights (“SF_Insights”, “the app”, “we”) is an internal business application operated by SourceFuse for its authorized personnel. It reports on resource utilization, bench cost, and revenue using data drawn from SourceFuse’s own systems. This policy explains what data the app processes, why, and the choices you have.
This is an internal tool, not a consumer product. It is made available only to authorized SourceFuse employees and contractors, and it is not intended for the general public.
1. Information we process
- Account data: your name, work email, role, department, and a securely hashed password used to sign you in. Your department is looked up from SourceFuse’s employee records and is used to decide which page you land on after signing in.
- Business & workforce data, resource/employee records, practice and utilization data, project and deal/revenue data, and compensation-derived figures (e.g. bench cost). This data originates in SourceFuse’s internal systems, not from you directly.
- Financial & accounting data, SourceFuse’s own accounting records across its operating entities: invoices, bills, payments, ledger transactions, and profit-and-loss figures, together with the business contact details of the customers and vendors those documents belong to.
- Usage & audit data, records of sensitive actions (e.g. permission changes, data exports, configuration changes that move reported figures, and the creation of share links) with the actor, timestamp, and what changed, kept for security and audit purposes.
- Google account data, only if you choose to link Google for exports (see Section 4).
2. How the data is collected
Business, workforce and financial data is read from SourceFuse’s connected systems: its BI/reporting datasets, workforce spreadsheets, and its accounting system (Zoho Books). The app reads from these sources on a read-only basis and does not write back to them. Account data is provided when an administrator invites you and when you first sign in.
3. How we use the data
- To provide the reporting, dashboards, and analysis the app exists to deliver.
- To authenticate you and enforce role-based access to sensitive information.
- To maintain an audit trail of security- and configuration-relevant actions.
- To send account-related email (invitations, password resets, and account notices).
We do not sell personal data, and we do not use it for advertising or for any purpose unrelated to operating this internal tool.
4. Google account data & “Export to Google Sheets”
The app offers an optional feature to export the table you are viewing to a Google Sheet. If you choose to use it, you link your own SourceFuse Google account, and the app requests a single, narrow permission: the Google Drive drive.file scope.
Google API Services User Data Policy, Limited Use. SF_Insights’ use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
- The
drive.filescope lets the app create and manage only the files it creates on your behalf: the export spreadsheets. It does not allow the app to see, read, or access any other files in your Google Drive. - Each export is created in your own Google Drive and owned by you. SourceFuse does not receive ownership of, or automatic access to, those files.
- We store an encrypted Google refresh token so you don’t have to re-authorize on every export. It is used solely to create your exports and is never shared or used for any other purpose.
- You can disconnect your Google account at any time, which revokes the app’s access and deletes the stored token.
5. Shareable report links
An administrator can generate a share link for a Quarterly report. A link is a pointer, not a credential: opening it requires signing in with an account whose access includes the Quarterly Report. The link itself should still be treated as confidential. It names a specific report.
- Each link carries a long, unguessable token and opens one frozen report, not the live app, not any other page, and not anyone’s account.
- Links expire (30 days by default) and can be revoked by an administrator at any time, which takes effect immediately.
- Shared pages are marked so search engines do not index, follow, or archive them.
- Creating and revoking a share link is recorded in the audit log, so it is always attributable.
Whoever creates a link remains responsible for who receives it. See the Terms of Service and Acceptable Use Policy.
6. Where the data lives (service providers)
We use a small number of vetted providers to run the app. They process data on our behalf:
- Amazon Web Services (AWS), application hosting and the application database, in its Mumbai (India) region.
- Zoho, SourceFuse’s accounting system, read as a source of the financial data described in Section 1.
- GitHub, where the app’s code is kept, built and deployed. The data described in Section 1 is not sent there.
- Google, only for the optional export feature you initiate, and email delivery via SourceFuse’s Google Workspace.
The app was previously hosted on Vercel, with its database on Supabase. Until that earlier setup is retired, a copy of the data also remains there.
7. Security
Passwords are stored using a strong one-way hash; two-factor secrets and the Google and Zoho connection tokens are encrypted at rest; traffic is served over HTTPS; and access to information is controlled by a role- and permission-based system with server-side enforcement. Sensitive actions are recorded in an append-only audit log. Sign-in sessions expire 48 hours after you sign in and are not extended by activity, so an unattended session cannot stay open indefinitely (see the Cookie & Session Notice).
8. Retention
Account and business data is retained for as long as needed to operate the tool and meet SourceFuse’s internal recordkeeping needs. Audit records are kept as an append-only history. Google tokens are kept only while your account is linked and are deleted when you disconnect.
9. Your choices
- Use of the Google export feature is entirely optional; you can decline to link Google and continue using the rest of the app.
- You can disconnect a linked Google account at any time.
- For questions about, access to, or correction of your personal data, contact us (Section 10). Access is otherwise governed by SourceFuse’s internal policies.
10. Contact
Questions about this policy or your data: ashwani.diwedi@sourcefuse.com.
11. Changes
We may update this policy as the app evolves. Material changes will be reflected here with a new “last updated” date at the top of the page.

