PRIVACY POLICY
1. Introduction
Welcome to [Company Name] ("we", "our", or "us"). We are committed to protecting your personal information and your right to privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile applications, web applications, websites, and related software services (collectively, the "Services").
Please read this Privacy Policy carefully. By accessing or using our Services, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. This policy is designed to comply with the Google Play Store Developer Program Policies, Apple App Store Review Guidelines, India's DPDP Act 2023, GDPR, and CCPA.
2. Information We Collect
2.1 Information You Provide to Us
- Full name, email address, phone number
- Username and password (stored encrypted — never in plain text)
- Profile photograph (if provided)
- Date of birth (where required)
- Professional details (designation, organization — where applicable)
- Content you create, upload, or share within the Services
- Communications you send to us (support requests, feedback)
2.2 Information Collected Automatically
- Device info: Device type, OS version, unique device identifiers
- Usage data: Features accessed, pages viewed, session duration, crash reports
- Location: Approximate location from IP address; precise GPS only with explicit permission
- Log data: IP address (for security), date/time of access, browser type
2.3 Information from Third-Party Services
If you sign in via Google, Apple, or Facebook, we receive your name, email, profile picture, and account ID from that service. We request only the minimum permissions necessary.
2.4 Information We Do NOT Collect
- Credit card or bank account numbers (handled by certified payment gateways)
- Biometric templates (device biometrics used for local auth only — not sent to our servers)
- SMS content, call logs, or messages from other applications
- Government ID numbers (Aadhaar, PAN) unless explicitly required by a regulated service
3. How We Use Your Information
- To provide our Services: Account creation, authentication, core app functionality
- To improve our Services: Usage analysis, bug fixes, feature development, personalization
- To communicate with you: Transactional notifications, security alerts, support responses, promotional messages (with consent and easy opt-out)
- For safety & legal compliance: Fraud detection, Terms enforcement, regulatory compliance, law enforcement response
4. How We Share Your Information
We do not sell, rent, or trade your personal information. We share data only as described below:
| Service Category | Examples | Data Shared |
|---|---|---|
| Cloud Hosting | AWS, Google Cloud | Account data, app content, files |
| Analytics | Firebase Analytics | Anonymized usage events, crash data |
| Push Notifications | Firebase FCM, APNs | Device token, notification content |
| Email Delivery | Resend, SendGrid | Email address, email content |
| Payment Processing | Razorpay, Stripe | Transaction amount, order ID only |
| Crash Reporting | Sentry, Crashlytics | Error logs, device state |
| Customer Support | Freshdesk, Zendesk | Name, email, support messages |
We may also share data for legal compliance, safety, or in connection with a business transfer (merger/acquisition) — in which case you will be notified.
5. Data Retention
| Data Category | Retention Period |
|---|---|
| Account data | Duration of account + 3 years after deletion |
| Transaction records | 7 years (Indian tax law compliance) |
| Usage & analytics logs | 13 months rolling |
| Crash & error logs | 90 days |
| Support communications | 3 years |
| Deleted account data | 30 days grace period, then permanent deletion |
6. Your Rights & Choices
6.1 Rights Available to All Users
- Access: Request a copy of your personal data — email privacy@[yourdomain].com
- Correction: Update your information in account settings or contact us
- Deletion: Delete your account via Profile > Settings > Delete Account in-app, or email privacy@[yourdomain].com
- Opt out of marketing: Use the unsubscribe link in emails or disable in app Notification Settings
6.2 EU Users (GDPR)
Additional rights: Data portability, right to restrict processing, right to object, right to withdraw consent, right to lodge a complaint with your local DPA. Requests processed within 30 days.
6.3 California Users (CCPA)
Rights to know, delete, opt out of data sale (we don't sell data), and non-discrimination. Requests processed within 45 days.
7. Children's Privacy
Our Services are not directed to children under 13 (or 16 in the EU). We do not knowingly collect personal information from children. If you believe a child has provided us personal information, please contact privacy@[yourdomain].com immediately. We will delete the information and disable the account within 72 hours of notification.
8. Data Security
- All data transmitted using TLS 1.2/1.3 encryption
- Data at rest encrypted with AES-256
- Passwords hashed with bcrypt (never stored in plain text)
- Two-Factor Authentication (2FA) available for all accounts
- Role-based access controls limit employee access to personal data
- Regular security assessments and penetration testing
- Data breach notification within 72 hours to relevant authorities; users notified without undue delay
If you believe your account is compromised, contact security@[yourdomain].com immediately.
9. Cookies, Tracking & Analytics
Mobile apps: We use Firebase Analytics (anonymized usage) and Firebase Crashlytics (crash reports). You can opt out of analytics in app Settings.
Web: We use essential cookies (required for login/security), functional cookies (preferences), and optional analytics cookies (Google Analytics — consent required). You can manage cookie preferences via our Cookie Consent Banner or browser settings.
10. Third-Party Links & Services
Our Services may link to third-party websites or integrate third-party SDKs (analytics, payments, social login). This Privacy Policy does not apply to those services. Please review their individual privacy policies. Key policies: Google · Meta/Facebook · Apple.
11. International Data Transfers
Our primary operations are based in India. If you access our Services from outside India, your data may be transferred to and processed in India. For EU users, international transfers are governed by Standard Contractual Clauses (SCCs) or other appropriate safeguards.
12. Changes to This Privacy Policy
We may update this policy periodically. For material changes, we will display a prominent notice in-app and send an email notification to registered users at least 30 days before the change takes effect. Your continued use after the effective date constitutes acceptance. Previous versions are available upon request.
13. Contact Us
| Contact Type | Details |
|---|---|
| Company Name | ARASMO Technologies Private Limited |
| Registered Address | 10-3-282/2/2, Humayun Nagar, Hyderabad |
| Privacy Inquiries | info@arasmotech.com |
| Security Issues | info@arasmotech.com |
| General Contact | info@arasmotech.com |
| Phone | [+91 7799039601] — Mon–Fri, 9 AM–6 PM IST |
| Response Time | Within 72 hours for all privacy inquiries |