Privacy Policy
This policy covers two different sets of records: the account data of the operator who subscribes to the service, and the subscriber records that an operator brings into it. They are treated differently, and the distinction matters.
Who holds what
An operator using the platform is the owner of their subscriber records. We process those records on the operator's instruction, for the purpose of running reminders, collection, routing and churn prediction on their network. We do not use one operator's subscriber data to serve another, and we do not build a market-wide subscriber database out of it.
Separately, we hold the operator's own account information, which we use to provide the service, raise invoices and support the account.
Operator account data
What we collect when a business signs up and runs an account:
- Contact name, business name, work email and mobile number
- Service type, approximate connection count, city or area of operation
- Tax registration details where invoices require them
- Login credentials, which are stored as salted hashes and never in readable form
- Product usage and error logs, used to keep the service working and to improve it
Signup and enquiry forms on the website carry an arithmetic check and an automated-submission guard. These are there to stop bots, and neither stores anything beyond the submission itself.
Subscriber records
Operators import the records they already keep. Typically that means subscriber name, mobile number, service address or lane, plan and packs, amount, due date, payment history, complaint history, and equipment serial numbers and deposits where relevant.
These records are used only to deliver the operator's own billing and service functions. We do not market to an operator's subscribers, we do not sell or rent subscriber lists, and we do not share them with other operators under any circumstances.
Sensitive identifiers
Government identity numbers are not required to run reminders, collection or churn prediction. Where an operator chooses to store an identity reference for its own compliance, it is stored against the connection and is not used for any other purpose.
Reminders and messaging
Reminders are delivered through licensed messaging partners on pre-approved templates, under the operator's own registered sender identity. For delivery we pass the subscriber's mobile number and the variables that appear in the message, such as the name, plan and amount.
- Delivery status is recorded against the connection so failures are visible to the operator
- A subscriber who opts out is flagged, and recurring reminders to that connection stop
- Transaction receipts for a payment the subscriber has just made continue after an opt-out
- Messaging windows are limited to daytime hours
Payment information
Card numbers, UPI credentials, bank login details and similar payment instruments are never collected or stored by us. Online payments are processed on the infrastructure of licensed payment partners against the operator's own merchant account, and funds settle from that partner to the operator's bank.
What we retain is the record of the transaction: the amount, the mode, the time, the connection it belongs to and the partner's reference, so that collection can be reconciled and receipts can be issued.
Field agent access
Agent accounts are scoped deliberately narrowly. An agent sees the homes on the routes assigned to them and the amounts due on those homes, and nothing else.
- No access to the full subscriber list, and no bulk export
- No visibility of other agents' collections
- Every collection entry is attributed to the agent, device and time
- Access can be revoked by the operator immediately, with records retained under that agent's name
Churn prediction data
Risk scores are computed from the operator's own records: payment timing, complaint history, plan changes, and patterns across the lane the connection sits on. No external data source, credit information or third-party profile is used.
A score is a statistical prediction about a connection. It is not a credit assessment, it is never shared with the subscriber, and it is not shared outside the operator's account. Scores are advisory and do not trigger any automated action against a connection.
Retention and export
Subscriber records, payment history and invoices are retained for as long as the operator's account is active, and afterwards for the period that tax and accounting rules require invoices to be preserved.
- A full export of subscribers, plans, payments and invoices is available at any time
- On written request after closure, operator and subscriber records are deleted, except what law requires us to keep
- Backups follow a rolling cycle and purge on their own schedule after deletion
- Operational logs are kept for a limited period for security and debugging
Security practices
- Traffic between browsers, agent phones and our servers is encrypted in transit
- Stored data is encrypted at rest, and credentials are hashed
- Access inside the platform is role based, with agents scoped to their routes
- Administrative access to production systems is limited and logged
- Backups are taken on a regular schedule and restoration is tested
No system is beyond compromise. If an incident affects an operator's data, we notify the operator with what we know, what was affected and what we are doing about it, rather than waiting until the picture is complete.
Subscriber requests
A subscriber's relationship is with their operator, so requests to see, correct or delete subscriber data are handled by that operator. Where a request reaches us directly, we refer it to the operator who holds the record and assist them in acting on it.
Opt-out requests sent through the messaging channel are honoured automatically and do not need to pass through the operator.
Changes to this policy
When this policy changes in a way that affects how operator or subscriber data is handled, account holders are notified by email before the change takes effect, and the current version is always the one published here.