Privacy Policy
Effective date: 1 May 2026 · Version 1.4 · Updated 21 July 2026 — WhatsApp Business messaging now live (direct via Meta Cloud API); clarified SOS safety notifications and account-deletion process
Snapsy Technologies Pvt. Ltd. (“Snapsy”, “we”, “us”) is committed to protecting your personal data. This Privacy Policy explains how we collect, use, store, and protect your information in accordance with the Digital Personal Data Protection Act 2023 (DPDPA), UIDAI guidelines, and applicable Indian laws.
1. Data We Collect
From Users (Customers):
- Phone number (for OTP-based login)
- Name and email address
- Saved delivery addresses (with GPS coordinates)
- Real-time location during active bookings only
- Payment history (card/UPI details are handled by Razorpay and never stored by Snapsy)
- Ratings, reviews, and booking history
- Trusted Safety Contacts — name and phone number of up to 3 emergency contacts you voluntarily add. These are stored on our servers and used solely to notify your contacts in an SOS emergency. This is entirely optional.
From Helpers (Service Providers):
- Phone number, name, email, date of birth, gender
- Aadhaar — the Aadhaar number is encrypted (AES-256-GCM) and never stored in plaintext per UIDAI guidelines; the uploaded document image is held in access-restricted storage and deleted after verification
- PAN — the PAN number is encrypted for tax compliance; the uploaded document image is held in access-restricted storage and deleted after verification
- Selfie / photo for identity verification
- Bank account / UPI details — stored securely in access-restricted systems and used solely for payouts
- Driving licence and vehicle documents (where applicable)
- Real-time GPS location while online and during active bookings
- Service history and earnings data
- Trusted Safety Contacts — name and phone number of up to 3 emergency contacts you voluntarily add. Stored on our servers and used solely to notify your contacts in an SOS emergency. Entirely optional.
2. Legal Basis for Processing (Consent)
We collect and process your personal data on the basis of your free, specific, informed, and unambiguous consent provided at registration via OTP verification, as required under the Digital Personal Data Protection Act 2023. You may withdraw consent at any time by requesting account deletion. Withdrawal of consent will result in termination of your account as services cannot be provided without necessary data.
3. Purpose of Data Collection
- Service delivery: Matching users with nearby helpers and tracking bookings.
- Identity verification: KYC to prevent fraud and ensure safety for all parties.
- Payments & payouts: Processing customer payments and paying helpers.
- Safety: Location tracking during active bookings for user and helper safety.
- Legal compliance: Tax records, RBI guidelines, and other regulatory requirements.
- Platform improvement: Anonymised analytics to improve service quality.
4. How We Protect Your Data
- Sensitive identity numbers (such as Aadhaar and PAN numbers) are stored using AES-256-GCM encryption. Uploaded documents and other sensitive records are held in access-restricted, audit-logged storage and transmitted only over encrypted connections.
- Aadhaar numbers are never stored in plaintext, complying with UIDAI Authentication Regulations.
- Payment card data is never stored — handled entirely by Razorpay (PCI-DSS certified).
- All data is transmitted over HTTPS/TLS.
- Access to personal data is restricted to authorised personnel and systems only.
- Access to encrypted documents is restricted to authorised admin operations only and is audit-logged.
- Automatic KYC document deletion: Helper identity documents (Aadhaar image, PAN image, selfie, driving licence, vehicle documents) are automatically and permanently deleted from our servers on a nightly schedule:
- Approved or rejected helpers — all uploaded documents are deleted within 7 days of the verification decision. Only the verification status (approved/rejected) is retained, not the documents themselves.
- Stale unreviewed applications — if a helper submits documents but the application is not reviewed within 30 days, the documents are automatically deleted.
5. Device Contacts Access & Trusted Safety Contacts
Both the Snapsy user app and the Snapsy helper app include a Trusted Safety Contacts feature. This allows you to designate up to 3 emergency contacts (by name and phone) to be associated with your account for safety purposes.
- Contact picker access: When you choose to add a trusted contact, the app requests permission to read your device's contact list solely to let you search and pick a contact by name or number. We do not copy, sync, or upload your full contact list to our servers.
- What we store: Only the name and phone number of each contact you explicitly select and save. Nothing else from your device contacts is stored.
- Purpose: When you trigger an SOS alert, our safety team is notified immediately so we can respond. Direct notification of your saved trusted contacts is being rolled out and is not yet active; until then, your saved contacts are used to help our team respond on your behalf. Trusted contact details are never used for marketing, analytics, or shared with third parties outside of emergency response.
- Completely optional: Adding trusted contacts is not required to use Snapsy. You can skip this feature entirely or remove contacts at any time via Profile → Safety in the app.
- Retention: Trusted contact data is deleted from our servers within 30 days of account deletion or when you remove the contact in the app.
6. Data Sharing
We do not sell your personal data. We share it only:
- With the matched Helper/User — limited to name and phone number during an active booking.
- With Razorpay — for payment processing.
- With SMS providers (MSG91) — for OTP delivery (SMS fallback) and safety-related notifications.
- With Meta Platforms (WhatsApp Business API) — your phone number and transactional message content (booking confirmations, reminders, OTPs, receipts, safety alerts) are processed by Meta to deliver WhatsApp messages. See Section 11 for full disclosure.
- With regulators — when required by law (tax authorities, courts, law enforcement).
7. Data Retention
- KYC document images (Aadhaar, PAN, selfie): Permanently deleted from our servers within 7 days of verification decision (approval or rejection). Only verification status is retained — not the documents themselves. This complies with UIDAI circular on Aadhaar data minimisation and DPDPA §6.
- Helper location data: Current GPS coordinates are overwritten with each location update. No historical location trail is stored beyond what is needed for active booking tracking.
- Payment records: Retained for 7 years as required by RBI and Income Tax regulations.
- Booking history: Retained in anonymised form after account deletion for financial compliance.
- Account data: Deleted within 30 days of account deletion request. Anonymised booking/earnings records may be retained for regulatory compliance.
8. Your Rights (DPDPA 2023)
- Access: Request a copy of your personal data by emailing hello@snapsy.co.in. We will respond within 30 days.
- Correction: Update your name, email, and address at any time via Profile in the app.
- Deletion (Erasure): To delete your account and all personal data, email hello@snapsy.co.in with subject "Delete My Account". We will process within 30 days. Anonymised booking/earnings records may be retained for financial and regulatory compliance.
- Nomination (DPDPA §14): You may nominate another person to exercise your data rights in the event of your death or incapacity. Email hello@snapsy.co.in with subject "Data Rights Nomination".
- Grievance redressal: Contact our Grievance Officer; we acknowledge within 48 hours and resolve within 30 days.
9. Children's Privacy
Snapsy is not intended for users under 18. We do not knowingly collect data from minors. If you believe a minor has registered, contact us immediately at hello@snapsy.co.in and we will delete the account.
10. Cookies & Analytics
The Snapsy mobile app does not use cookies. We collect anonymised crash reports and usage analytics via Sentry and Firebase. No personally identifiable information is included in analytics data.
11. WhatsApp Business Messaging
Snapsy uses the WhatsApp Business Platform (a Meta Platforms service) to deliver transactional notifications. WhatsApp is our primary channel for one-time passwords (OTPs) and, with your consent, other transactional messages. The categories of WhatsApp messages we send are:
- OTP / Verification codes — one-time passwords for login and sign-up.
- Booking confirmations — confirmation when a booking is placed.
- Helper assigned notifications — name, rating, and ETA of your assigned helper.
- Service completion receipts — summary and amount paid after a job.
- Booking reminders — reminder before a scheduled service.
- Payout notifications (Helpers) — confirmation when a payout is processed to your bank/UPI.
- Refund notifications — confirmation when a refund is initiated.
- SOS safety alerts — emergency alerts relating to an SOS you trigger (direct trusted-contact notification is being rolled out).
- Helper approval notification — confirmation when your helper application is approved.
What data is shared with Meta: When WhatsApp messaging is active, your phone number and the content of each message (booking ID, amount, helper name, or other relevant variables) are transmitted to Meta's servers for delivery. Meta processes this data under its own WhatsApp Privacy Policy and Meta Privacy Policy.
Nature of messages: All WhatsApp messages from Snapsy are transactional / utility only — directly related to actions you have taken on the platform. We do not send promotional or marketing messages via WhatsApp.
Opt-out: To stop receiving WhatsApp messages from Snapsy, email hello@snapsy.co.in and we will disable WhatsApp notifications for your account. SMS will be used as a fallback for critical notifications. OTP messages cannot be disabled while your account is active as they are required for login security.
Message templates: All WhatsApp messages are sent using pre-approved templates reviewed and approved by Meta. No freeform messages are sent outside of approved templates.
12. Data Deletion & Account Removal
You have the right to request deletion of your personal data and Snapsy account at any time. Here is exactly what happens when you do:
How to delete your account
Online (instant): Visit our Data Deletion page, choose your account type, enter your registered mobile number and verify it with the one-time code sent via WhatsApp or SMS. Your account is anonymised and deleted immediately.
By email: Alternatively, email hello@snapsy.co.in with the subject line “Delete My Account” and the phone number registered with your account. We will acknowledge within 48 hours and complete the deletion within 30 days.
Note: your active bookings must be completed or cancelled before your account can be deleted. Deletion is permanent.
What gets deleted
- Your name, email address, and profile data (including profile photo)
- Your phone number — anonymised so it is released and can be re-registered later
- Saved addresses and location history
- Trusted Safety Contacts you added
- Your WhatsApp / SMS messaging preferences
- Helper KYC document files (Aadhaar, PAN, selfie, licence, vehicle documents) — permanently removed from storage
- Bank/UPI details (if applicable) — deleted on request
What is retained (legal obligation)
- Payment and transaction records — retained for 7 years as required by RBI and Income Tax regulations. These records are anonymised (your name and phone are removed; only transaction IDs and amounts are kept).
- Booking records — retained in anonymised form for financial and regulatory compliance.
WhatsApp / Meta data
Where Snapsy has sent you transactional notifications via WhatsApp, message delivery data is processed by Meta and is subject to Meta's own deletion processes. To request deletion of data held by Meta, visit: Meta Data Deletion Request.
13. Changes to This Policy
We will notify you via the app when material changes are made. Continued use after notification constitutes acceptance. The version number above is updated with each revision.
14. Grievance Officer & Contact
As required under IT (Intermediary Guidelines) Rules 2021 and DPDPA 2023, we have designated a Grievance Officer:
Grievance Officer: Pradeep Saravanan
Snapsy Technologies Private Limited
CIN: U74909TZ2026PTC038861
GSTIN: 33ABTCS5055J1ZU
Reg: 5/84, Velampatti, Palacode, Dharmapuri, Tamil Nadu — 636805
Ops: Saibaba Colony, Coimbatore, Tamil Nadu
Privacy Email: hello@snapsy.co.in
General: hello@snapsy.co.in
Grievances acknowledged within 48 hours and resolved within 30 days as per DPDPA 2023 and IT Rules 2021.
Unresolved grievances may be escalated to the Data Protection Board of India once constituted under DPDPA 2023.