Legal / Privacy Policy
Privacy at
DriveShift.
Your migration graph — folders, files, identities, permissions — is your organization's data. Here is exactly what we collect, why, where it lives, and how to get it removed. Last updated: 19 July 2026.
Information we collect
Account data: your name, email address, and profile picture from Google sign-in (we never see or store a password). Organization data: organization name, members, roles, and invitations. Migration data: tenant connections, folder selections, migration jobs, stage timelines, permission and identity mappings you confirm (saved per organization so your next migration pre-fills them), and reports. Contact data: details you submit through our contact form. Payment data: plan, invoices, amounts, applied coupons, and payment identifiers from Razorpay — card and bank details are handled entirely by Razorpay and never reach our servers. Technical data: IP address and browser user-agent in audit and session records.
How we use it
To operate the service: authenticate you, run and schedule migrations, apply permission mappings, generate reports, bill your plan, and email you transactional messages (welcome, invitations, invoices, and migration completion). We do not sell personal data, and we do not use your migrated file content for anything other than performing the migration you requested.
Google user data
DriveShift accesses Google Drive exclusively through service accounts that your organization connects, scoped to the migration you configure. Google sign-in uses the basic OpenID profile (name, email, picture). Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
Storage and security
Data is stored in PostgreSQL, scoped per organization. Tenant service-account credentials are sealed with AES-256-GCM envelope encryption under a key that exists only for your organization; the ciphertext is cryptographically bound to your organization and tenant role, and the public-facing API service is not permitted to decrypt it — only the isolated migration engine can. Your migrated file content is streamed directly between your tenants and is never stored on our servers; reports (which list file names, paths, and outcomes) carry SHA-256 integrity checksums. Sessions are HttpOnly secure cookies. Authentication, credential changes, billing events, and migration actions are written to an append-only audit trail that you can review in your dashboard's Audit section at any time.
Third-party processors
Google (OAuth sign-in and Drive/Workspace APIs for migrations), Razorpay (payment processing), Resend (transactional email delivery), and our cloud infrastructure provider. Each processor receives only the data required for its function.
Data retention and deletion
Migration history, reports, and audit logs are retained while your organization account is active so you have a durable audit trail. You may request deletion of your organization and its data at any time by emailing support@mysticmatrix.cloud from an owner account; we delete within 30 days, except records we must keep for legal, billing, or fraud-prevention purposes.
Your rights
You can request a copy of the personal data we hold about you, correct it, or ask for deletion (subject to the retention note above). Contact support@mysticmatrix.cloud and we will respond within 30 days.
Cookies
DriveShift uses only functional cookies: an HttpOnly session cookie after sign-in, a short-lived state cookie that protects the Google sign-in flow against forgery, and a short-lived signup cookie during account creation. Your light/dark theme preference is kept in your own browser's local storage. No third-party advertising or tracking cookies are set.
Changes and contact
We will post any material change to this policy on this page and update the date below. Questions: support@mysticmatrix.cloud, or Mystic Matrix Technologies via our contact page.
Related policies
See also our Terms and Conditions and Refund & Cancellation Policy.