Legal document
Terms of Service
What Capstan is, what you get on each plan, how billing works and what happens if an invoice is late, what your data is and how to take it with you, and how either side ends the relationship. The clauses this document does not contain are listed in clause 11 rather than improvised.
This document
- Published by
- N53 Techworks LLP, LLPIN ACI-8879
- Last updated
- State
- Published, with clauses pending counsel
- With counsel
- Four marked clauses
- Questions
- legal@usecapstan.com
1.Parties and scope
1.1 These terms are between you and N53 Techworks LLP, a limited liability partnership registered in India at 19th Floor, Tower-B, Alphathum, Sector-90, Noida, Uttar Pradesh 201305, India. In these terms "we", "us" and "our" mean that entity, and "Capstan" means the service it operates.
1.1.1 Our registration number is ACI-8879.
1.2 "You" means the organisation that opens a Capstan workspace, and the people it authorises to use that workspace. "We" and "Capstan" mean the service described in clause 2 and the entity that will be named at 1.1.
1.3 Two other documents sit alongside this one and are published in full at the same place: the privacy policy, which describes how personal data is handled, and the Data Processing Agreement, which sets out the terms on which we process personal data on your behalf. Which document prevails if they conflict is part of clause 11.
2.The service
2.1 Capstan is a multi-tenant, cloud-hosted human resources platform: a complete core system of record, modules included in a paid plan, and add-on modules you enable individually. The current capabilities of the core, and the current module catalogue with its prices and its inclusions, are published at /product and /pricing.
2.2 The service is delivered per region. Each region is a self-contained stack with its own database, storage, compute and identity store. There is no global control plane and no runtime path between regions.
2.3 Two structural commitments about what the service does not do, because they bound what you are buying. No customer money moves through Capstan: payroll and contractor payouts are compiled, recorded and handed to your bank or your payment partner, so we never hold a balance on your behalf. And no AI evaluates your people: no AI capability is built into the product, no AI credential is required or read by any production code path, and your data is never used to train a model.
2.4 Some capabilities are described on this site as forthcoming. Nothing on the roadmap is promised by this document, and no plan entitles you to a capability that has not shipped. Where a plan tier or a feature is not released, this document and the pricing page say so.
3.Your workspace and your account
3.1 You choose your region when you create your workspace, and it is permanent. Residency commitments are only real if they cannot be quietly changed later, so the region is structural rather than a setting. Moving a workspace to another region is a manual, ticketed procedure on request, described in the DPA.
3.2 Sign-in is passwordless: a one-time code sent to your email address. There is no password anywhere in the product. Codes are single-use, attempt-capped and short-lived.
3.3 The person who creates the workspace is its Owner. Certain acts are Owner-only and cannot be delegated, specifically requesting a full export and scheduling deletion of the workspace. You are responsible for who you invite and what you let them do.
3.4 You can require multi-factor authentication for administrators or for everyone in your workspace. That policy is yours to set.
3.5 Today one email address belongs to one workspace. Membership of several workspaces with a single identity is not built, and we record that here rather than let you discover it.
4.Plans, seats and modules
4.1 Free is not a trial. The Free plan carries the whole core, with a cap of 20 concurrently active employees. The cap counts active employments only: people who have not started yet and people serving notice do not consume a capped seat, so an exit frees a seat and a rehire fits. The cap is enforced at the point an employment is activated, including by the overnight job, not merely in the interface.
4.2 Paid plans lift the seat cap and add the capabilities listed on /pricing. A paid plan includes the same 20 seats the Free plan carries: the per-seat plan charge applies to the billable seats above 20, so a workspace of 21 people is charged for one seat. That allowance applies to the plan charge only, not to add-on modules, and it is subtraction rather than a limit, so a paid workspace still has no cap. A tier that has not been released cannot be granted to anyone: the system refuses it outright, so nobody can be placed on an unreleased tier by mistake. Where the pricing page shows a tier as forthcoming, that is what is meant.
4.3 Modules are a paid-plan capability. Enabling a module requires a paid plan. A workspace that already has modules enabled keeps them if it is on Free.
4.5 Modules included in a paid plan. Some modules are included in every paid plan at no additional charge and carry no separate price. Which modules those are is published at /pricing. They are enabled for your workspace when the paid plan begins, they are not invoiced at any headcount, and they end when the paid plan ends. Because they are part of the plan rather than separately purchased, clause 4.4 does not apply to them and disabling one does not reduce your charges. We may add a module to, or remove one from, what a plan includes; a removal takes effect at your next renewal and never inside a term you have already paid for.
4.4 Enabling a module is the chargeable event, and the price is fixed at the moment you enable it: the catalogue price row in force at that instant is pinned to your entitlement, so a later price change does not reach back into a term you have already bought. Prices are published, and a change to a published price is a new price row rather than an edit to an old one.
4.5 Disabling a module stops the charge at the end of the current period; there is no mid-period refund. The module's data is retained for a stated window, so re-enabling within that window restores it, and is deleted afterwards.
4.6 Self-serve plan upgrade is not built yet. Today you record an upgrade request from your billing page with the details needed to raise an invoice, and we grant the tier. We would rather say that than show a checkout that does not exist.
5.Billing and payment
5.1 Terms are prepaid
A paid workspace holds one subscription term on a quarterly, half-yearly or annual cycle. There is no monthly cycle: prices are quoted per employee per month, but the shortest term anyone can buy is a quarter, and a longer cycle carries the discount published on the pricing page. The plan owns the renewal date and every add-on module binds to it, so there is one renewal date and one invoice rather than a staggered set. Term arithmetic is clamped to month ends, so a term starting 31 January and running three months ends on 30 April.
5.2 Mid-term changes
A module enabled part-way through a term is invoiced prorated from the day you enable it to the current term end, and then co-terminates there. A cycle change applies at the next renewal, never mid-term: the term you have paid for is the term you get.
5.3 Seats
Per-employee charges bill on the people on your roster, which includes people serving notice because they are still employed. The plan charge bills that roster less the 20 seats a plan includes (clause 4.2); per-employee module charges bill the roster itself, from the first person. New seats added part-way through a term are billed by a monthly true-up invoice, at the net new billable headcount since the last baseline, prorated to the term end. That true-up is an adjustment inside the term you have already prepaid, not a monthly billing cycle. Reductions are not refunded mid-term; they apply at the next renewal.
5.4 Renewal, reminders and grace
The renewal invoice is issued at the term end and is due 30 days later. Reminders go out 60 days and 30 days before the term end, at the term end when the invoice issues, and again five days before the deadline. Those reminders are a notification category you cannot switch off, because the notice that a workspace is about to be suspended is not something anyone should be able to mute by accident.
Access is uninterrupted throughout the grace period. A paying customer who is late is still a customer, and we are not going to hold your workspace hostage over an unpaid invoice while a grace period we granted is still running. Your administrators see an honest banner saying where you are.
5.5 If the invoice is not paid
At 30 days past the term end the term lapses and the workspace is suspended for non-payment. Not one row of your data is touched. Suspension restricts reach, not storage, which is what makes reinstatement a true restore rather than a recovery.
Be clear about what suspension means, because it is easy to soften and we would rather not. It is not a read-only state. A suspended workspace is held: every tenant surface refuses, reads included, and the person signing in is told plainly that the workspace is held rather than that their own account is disabled, because those are different facts and telling someone the wrong one is a lie. What survives is your export, which sits outside the billing check by design and is covered in clause 7.
Reinstatement is manual and is done against a recorded payment reference. There is no automatic un-suspension, and a payment arriving on a lapsed workspace is recorded and held rather than silently reopening it. That is deliberate: it means a lapse cannot be waved away without recording that money actually arrived.
The Free plan cannot lapse. A workspace with no paid module and no paid plan has no subscription at all, so there is nothing for the billing clock to act on.
5.6 How you pay
Either by card, through the payment provider's hosted checkout, one invoice at a time, or by bank transfer or purchase order where we have agreed invoice billing with you. No automatic debit mandate is stored. Each term issues a fresh invoice for an exact amount, so nothing varies silently against a card on file. Renewal amounts change with headcount at the term boundary, never mid-term without the invoice in clause 5.3.
There is no card data anywhere in Capstan. No card field, no adjacent column, no payment form. That is a property of the schema, not a promise. The payment provider is the merchant of record: it takes the payment, collects and remits buyer-side tax on the transaction, and issues its own receipt.
You will therefore hold two documents, and they are not duplicates. The Capstan invoice is the commercial statement of account, saying what is owed, for which term, against which plan and modules, with a sequential number and a line-item breakdown. The provider's receipt is the tax document for the transaction, issued by the party that took the money and carries the tax liability on it.
5.7 Current status of live payments
The card rail runs in test mode today. No live customer payment has been taken, because a merchant of record is onboarded as a specific legal entity, and that onboarding is the open decision at clause 1.1. Until it clears, billing runs on the invoice and bank-transfer rails. This paragraph is here because it changes how you would actually pay us, and finding that out after signing would be a poor introduction.
5.8 Credits and refunds
Overpayment is not absorbed. It becomes a credit balance on your workspace, visible on your billing page, and is applied against the next renewal. Credit notes and refunds are recorded acts with a mandatory reason, and above a stated limit they require a second, distinct approver internally.
5.9 Taxes
Where you pay by card, the payment provider as merchant of record collects and remits buyer-side tax and issues the tax document for that transaction. Capstan invoices currently carry line items and a total, and do not carry a separate tax amount line; that is a known gap pending real tax-rate tables, and it is not a statement about what tax is due. The tax treatment of the invoice and bank-transfer rails follows the entity decision at clause 1.1.
6.Acceptable use, and suspension
6.1 The service enforces certain limits directly, and it is worth knowing what they are rather than discovering them:
- Uploads. There is one path for untrusted files and it quarantines by default. A file must have magic bytes that agree with its declared type; executables and scripts are blocked; there are size ceilings. A quarantined file is not downloadable until scanning clears it, and a file identified as infected is permanently blocked and recorded in your audit trail as well as ours.
- Rate limits apply to sign-in code requests and verification, to export initiation and to report runs, and there is a separate limiter on signup.
- Seat caps on the Free plan are enforced at activation, as in clause 4.1.
6.2 The enumerated list of prohibited conduct, and the notice we would give before enforcing against it, is not drafted. Clause 6.1 is what the system enforces today and clause 6.3 is the mechanism we would use; the substantive prohibitions are a contract term and are with counsel.
6.3 A workspace can be suspended manually, separately from the non-payment suspension in clause 5.5. A manual suspension holds the workspace exactly as a non-payment suspension does, it requires a stated reason recorded at the moment it happens, it is written to our internal audit log by the function that performs it so it cannot be done unrecorded, and it does not touch your data. Reinstatement restores reach exactly as it was.
7.Your data, and getting it out
7.1 The data you and your people put into your workspace is yours. We process it to run the service and on your instructions, and for no purpose of our own. The full terms are in the DPA.
7.2 A workspace Owner can export everything, at any time, without asking us: one plain tar archive containing a manifest, one JSON and one CSV file per entity, and every stored document as its original bytes. JSON is the authoritative copy. Sensitive values are exported decrypted, under your own authority over your own data. There are no proprietary formats to escape from.
7.3 Export is never blocked by billing state. This is a deliberate design decision rather than a courtesy: the endpoints sit outside the suspension guard, so a suspended or lapsed workspace can still take its data and go. Your data is not leverage.
7.4 Deletion is described in clause 10.2 and, in more detail, in the DPA.
8.Changes to the service, and to the API
8.1 The service changes. Capabilities are added, and occasionally something is replaced. Where a change removes something you were relying on, we tell workspace administrators directly, before it takes effect.
8.2 Sub-processors: 30 days' advance notice before a change takes effect, as set out on the register and in the DPA.
8.3 The API. Our standing policy is that the HTTP API is versioned in the URI, that a breaking change ships only as a new version, that a deprecation carries a minimum of six months' notice by direct email to key holders and in response headers, that a version is supported for at least twelve months after its successor ships, and that nothing is switched off while a paying customer's keys were used in the last 30 days without contacting them first.
8.3.1 To be exact about what that policy currently governs: there is no public API surface today. Every call in the product is authenticated with a signed-in session, and customer-managed API keys are not built. Webhooks are the real integration surface today, and they are a core feature rather than a priced one. The policy above binds us from the day keys ship.
9.Support and availability
9.1 Support is by email at support@usecapstan.com, with the product documentation as the first line. Support never asks for your password, and there is no password to ask for. Support staff cannot read your data without the consent described in clause 4.3 of the DPA.
9.2 No response-time target is published, and therefore none is promised. Internal targets exist per plan, and our standing rule is that a support target goes on a public page only when staffing can honour it. When they can be honoured they will be published here and on the pricing page, with the plan each applies to.
9.3 There is no availability, recovery-time or recovery-point commitment in this document, and there is no public status page yet. We do not quote numbers we have not measured, and we do not publish a dashboard that would have nothing measured behind it. What exists today is platform backups per region and a documented restore drill whose executed record is committed. A stated objective has to come from an executed drill, and when one does it will be published rather than estimated.
10.Ending it
10.1 You can leave at any time. Take your export first, under clause 7.2. We offer it rather than waiting to be asked.
10.2 Deleting the workspace. The Owner schedules deletion, typing the workspace name back and confirming a second time. The request then sits in a cancellable cooling-off window, seven days by default, and can be cancelled at any point in it. When the window elapses, your encryption keys are destroyed, your stored files are deleted, and every table carrying your workspace identifier is purged except the financial records held to their statutory floors, proven by a scan that counts what is left and finds zero. After the keys are destroyed this is irreversible, and we will not pretend otherwise. Deletion is never blocked by billing state.
10.3 Refunds on leaving. There is no refund of the remaining prepaid term when you leave or move off a paid plan mid-term, which matches the position on disabling a module in clause 4.5. Moving back to Free cancels the live term, which then stops billing and cannot lapse.
10.4 Suspension for non-payment (clause 5.5) and manual suspension (clause 6.3) are not termination. Neither deletes data, and both are reversible.
10.5 The circumstances in which we may terminate the agreement, the notice we would give, and what happens to data afterwards beyond the retention floors, are part of clause 11.
11.What is not in this document, and why
A Terms of Service is a commercial contract, and the parts of it that are genuinely legal are not settled by any description of how the software behaves. Rather than draft them from general knowledge and hope, we are naming them. All of the following are with counsel:
- Warranties and disclaimers.
- Limitation and exclusion of liability, including any cap and how it is calculated.
- Indemnities, in either direction.
- Governing law and jurisdiction.
- Dispute resolution, including whether any form of arbitration applies.
- The licence to use the service, and intellectual property in the service itself. Note that this is separate from your data, which clause 7.1 settles.
- Termination by us, and the notice attaching to it (clause 10.5).
- Order of precedence between this document and the DPA (clause 1.3).
- The contracting entity (clause 1.1).
This list is not a placeholder for a document that exists elsewhere behind a form. There is no other version. When a clause is drafted and signed off it appears here, dated, in the version history, and drops off this list in the same change.
If you are reviewing Capstan and one of these is blocking, write to legal@usecapstan.com and say which one. Knowing which clause actually blocks a real deal is how it gets prioritised.
12.Changes to these terms
This document is versioned and dated, and the version history below records every change. If a statement in it stops being true, the document changes before the product does.
How much notice we give before a change to these terms takes effect, and how that notice reaches you, is not settled. Two related notice periods already are, and they are stated in clause 8: 30 days for a sub-processor change, and six months for an API deprecation. This one is with counsel.
Open items in this document
Every place this document stops short, and why. These are listed rather than drafted because a clause invented to fill a gap is worse than the gap. Each row names what is missing and who has to supply it. Every reference is a link: where the document marks the gap in its own body it lands on that clause, and where it does not it lands on the section the gap belongs to.
| Reference | What is not settled | Why it is not written | Owner |
|---|---|---|---|
| Clause 1.1 | The contracting legal entity, its registered address and its company number | The entity structure is open and counsel-led. Nothing that names a contracting party can be published until it resolves. | Counsel |
| Clause 6.2 | The enumerated acceptable-use prohibitions | What we can state today is the limits the system actually enforces and the suspension mechanism behind them. A list of prohibited conduct, and the notice given before enforcement, is a contract term. | Counsel |
| Clause 11 | Warranties and disclaimers, limitation of liability, indemnities, governing law, jurisdiction and dispute resolution, and the licence to use the service | None of this is a system description, so no product document settles any of it. A half-drafted liability clause is worse than a stated gap. | Counsel |
| Clause 9.2 | Published support response targets | Internal targets exist per plan, but the standing rule is that they go on a public page only when staffing can honour them. They are not published, so they are not promised. | The business |
| Clause 9.3 | Any availability, recovery-time or recovery-point commitment | We do not quote numbers we have not measured. Backups and a restore drill exist and the drill record is committed, but no objective has been derived from an executed drill. | Engineering |
| Clause 12 | How changes to these terms are notified, and how much notice is given | Notice periods are settled for sub-processor changes (30 days) and for API deprecation (6 months). No document settles the notice period for a change to these terms. | Counsel |
Version history
What changed, and when. Entries are added, never edited: if a statement in this document stops being true, the document changes before the product does, and the change is recorded here. The date at the top of the page is the date of the newest entry.
- The version you are reading
- The 20 seats a Free workspace carries are now included on the paid plans as well. Clause 4.2 states the allowance and clause 5.3 states how it is counted: the per-seat plan charge applies to the billable seats above 20, so a workspace of 21 people is charged for one seat rather than 21. The allowance applies to the plan charge only; add-on modules are unchanged and per-employee modules still bill the whole roster. Separately, new clause 4.5 covers the modules a paid plan now includes outright, currently payroll and time and attendance: they carry no price, are never invoiced, and end with the plan rather than on their own terms.
- The contracting entity is published. Clause 1.1 names N53 Techworks LLP and its registered address, and clause 1.1.1 carries its LLP identification number, so the clause is no longer a blank. Clause 11 keeps the commercial and legal clauses that remain with counsel.
- First publication, replacing the placeholder page. Clauses 2 to 10 are drafted from the product documentation for plans, entitlements, billing, payments, export and deletion. Clause 11 lists the commercial and legal clauses that are with counsel and are deliberately not drafted here; clause 1.1 has no contracting entity yet.
The other documents
Four documents cover the relationship, all published in full and none behind a form. You are reading the Terms of Service. The rest:
- Sub-processor register Who else touches your data, what reaches them, and where it rests. Includes the vendors admitted but not engaged.
- Privacy Policy Roles, categories, retention, deletion as cryptographic erasure, export, consented access, rights and transfers.
- Data Processing Agreement Processor obligations, sub-processor change notice, the security annex, breach notification, deletion and return of data.
Questions about this document go to legal@usecapstan.com. Privacy and data-protection questions, including requests about personal data, go to privacy@usecapstan.com.
Terms of Service, N53 Techworks LLP. This copy is the version dated 19 August 2026. The canonical version is at usecapstan.com/legal/terms and supersedes any printed copy.