1. Who We Are
Welcome to Thodar, a job management platform designed for small businesses in India.
This Privacy Policy explains how Indraveen Technologies ("we", "us", "our", or "Company") collects, uses, stores, and protects your personal data when you use our Progressive Web Application and website (collectively, the "Service").
Company Details:
- Business Name: Indraveen Technologies
- Business Location: Selaiyur, Chennai - 600073, Tamil Nadu, India
- Business Contact: +91 79047 54545
- Email: support@indraveentech.in
This Privacy Policy is designed to align with the Digital Personal Data Protection Act, 2023 (DPDPA) and the Digital Personal Data Protection Rules, 2025, as applicable. It applies to users of Thodar in India and to other users where applicable laws require us to provide equivalent privacy protections.
2. Important: Understanding Data Roles
2.1 When You Use Thodar for Your Business
You are the Data Fiduciary for your customer data. We are the Data Processor acting on your behalf.
This means:
- You control what customer data you collect (names, phone numbers, addresses, etc.).
- You are responsible for ensuring that you have a lawful basis for collecting and processing your customers' personal data, including obtaining consent where required.
- You must handle data subject requests (access, deletion, correction) from your customers.
- We process this data solely based on your instructions through the app.
Your Obligations:
- Ensure that you have a lawful basis for collecting and processing customer data and provide any required notice or obtain consent where applicable.
- Inform your customers, where required, that their data may be processed using Thodar.
- Handle customer complaints and data requests as required by applicable law.
- Comply with applicable data protection laws in your capacity as the Data Fiduciary.
Our Obligations:
- Process your customer data only as instructed by you.
- Implement security measures to protect the data.
- Not use customer data for our own purposes.
- Assist you with data subject requests when technically feasible.
2.2 When We Collect Your Business Account Data
We are the Data Fiduciary for your account information. You are the Data Principal (the person whose data we process).
This applies to:
- Your name, email, phone number.
- Your business details (shop name, address, GSTIN).
- Your usage data, billing information, and app activity.
For this data, we are responsible for complying with applicable data protection requirements, and you have the rights described in Section 5 of this policy.
3. Information We Collect
3.1 Account & Authentication Data
What we collect:
- Full name
- Email address
- Phone number (for account recovery)
- Password (stored as hashed value using bcrypt - we never see your plain password)
- Google account information (if you sign in with Google OAuth)
Why we collect it:
- To create and manage your account.
- To authenticate your login (via email/password or Google OAuth).
- To send critical account notifications (password resets, security alerts).
Important: Your email address is your login credential and cannot be removed or opted out of while your account is active. If you wish to stop receiving emails, you must delete your account (see Section 5.3).
Processing basis: Processing necessary to provide and operate the Service, together with any consent or other lawful basis required under applicable law.
3.2 Business Profile Data
What we collect:
- Business name, address, and phone number.
- Business email (optional).
- WhatsApp number (optional - for future integrations).
- GSTIN (optional - for GST invoicing).
- Tax regime preference (GST/Composition/None).
- State code (for tax calculations).
Why we collect it:
- To generate legally compliant invoices.
- To customize the app for your business type.
- To enable multi-location business management.
Processing basis: Processing necessary to provide and operate the Service, together with any consent or other lawful basis required under applicable law.
3.3 Customer Records (You Control This Data)
What you enter into Thodar:
- Your customers' names, phone numbers, emails (optional), postal addresses (optional), WhatsApp numbers (optional).
- Your customers' GSTIN (if B2B transactions).
- Your customers' communication preferences.
Important: We process this data on your behalf. You are responsible for obtaining consent from your customers before entering their data into Thodar.
Why we process it:
- To enable you to track jobs and services.
- To generate invoices addressed to your customers.
- To allow you to send service updates (when you choose to).
Processing basis: Processing on behalf of the Data Fiduciary (you), in accordance with your instructions and applicable law.
3.4 Job & Service Data
What we collect:
- Job descriptions and service notes.
- Photos of devices/vehicles (stored in Cloudflare R2).
- Pricing, invoice details, and payment records.
- Job status history (received → repaired → delivered).
Why we collect it:
- To help you manage repair/service workflows.
- To generate invoices and payment receipts.
- To provide service tracking for your customers.
Processing basis: Processing necessary to provide and operate the Service, together with any consent or other lawful basis required under applicable law.
3.5 Device & Usage Data
What we automatically collect:
- Device type, browser type/version, OS.
- Screen resolution (to optimize PWA layout).
- App usage patterns (feature usage, error logs).
What we DO NOT collect:
- GPS location data.
- IP addresses (not logged or stored).
- Browsing history outside Thodar.
- Contact lists or other phone data.
Processing basis: Processing necessary to operate, secure, maintain, and improve the Service, subject to applicable law.
3.6 Cookies & Local Storage
What we use:
- Better Auth Session Cookie: Essential cookie to keep you logged in (even offline). Contains an session token and expires when you log out or after 30 days of inactivity.
- IndexedDB Storage: Your app stores data locally on your device using browser IndexedDB for offline functionality. This data is not encrypted at rest by the app (see Section 8.2 for security recommendations).
Cookie Banner: We do not require a cookie consent banner because we only use essential cookies necessary for the Service to function.
3.7 Payment Information
What we collect:
- Subscription plan, billing cycle, payment status.
- Razorpay Customer ID and Subscription ID.
What we DO NOT collect or store:
- Credit card numbers, CVV codes, expiry dates, or bank account details.
Why: All payment processing is handled securely by Razorpay (PCI-DSS compliant). We never see or store your payment card details.
4. How We Use Your Data
We use your personal data only for the following purposes:
4.1 Service Delivery
- Create and manage your account.
- Enable offline-first job management.
- Sync data across your devices.
- Generate GST-compliant invoices.
- Process subscription payments.
- Provide customer support.
4.2 Communication
- Send transactional emails (invoice generated, subscription expiring, password reset).
- Send important service updates (maintenance, security, policy changes).
- Send promotional emails about new features or offers (only if you opt in).
4.3 Legal Compliance
- Maintain transaction, invoice, and accounting records for as long as required under applicable tax, accounting, and other legal requirements.
- Respond to lawful requests from authorities.
- Enforce our Terms of Service.
4.4 Analytics & Improvement (Future)
We may implement analytics and error tracking tools in the future (e.g., Sentry, Pino, OpenTelemetry). If we add these tools, we will update this Privacy Policy, notify you, and implement a cookie consent banner if required.
We will NEVER sell your data to third parties, use your data for advertising, or share data with marketers.
5. Your Rights Under DPDPA 2023
As a Data Principal, you have the following rights:
5.1 Right to Access
Request a summary of the personal data we process about you, information about relevant processing activities and third parties with whom your personal data has been shared, as provided under applicable law.
Where available, you may also export your business data in JSON format using the export functionality provided in Thodar.
- How to exercise: Go to Settings → Export Data, or email support@indraveentech.in
5.2 Right to Correction
Request correction of inaccurate or incomplete personal data.
- How to exercise: Edit your profile in Settings → Account, or email support@indraveentech.in
5.3 Right to Erasure (Right to be Forgotten)
Request deletion of your account and personal data. We will process account deletion requests within 30 days, subject to any legal, security, accounting, tax, or other retention requirements that apply.
- Note: Certain transaction, invoice, and accounting records may be retained for the period required under applicable tax, accounting, and other legal requirements. Where appropriate and technically feasible, personal identifiers will be anonymized when they are no longer required for the relevant legal or business purpose.
- How to exercise: Email support@indraveentech.in with subject "Account Deletion Request".
5.4 Data Export
Export your business data (customers, jobs, invoices) in JSON format anytime to take to another provider.
- How to exercise: Go to Settings → Backup → Export Data.
5.5 Right to Withdraw Consent
You can withdraw consent for marketing emails or optional features at any time where those activities are based on your consent.
5.6 Right to Nominate
You may nominate another person to exercise your rights in the event of your death or incapacity, as provided under the DPDPA 2023.
- How to nominate: Email support@indraveentech.in with nominee details.
6. Grievance Redressal & Complaints
6.1 Grievance Officer
If you have any concerns about how we handle your personal data, contact our Grievance Officer:
- Name: Praveen Manickavasagam
- Designation: Proprietor
- Email: support@indraveentech.in
- Response Time: We will acknowledge your grievance within 7 working days and provide a resolution within 90 days.
6.2 Complaint to Data Protection Board
If you are not satisfied with our response, you may exercise any further rights available to you under applicable law, including the right to approach the Data Protection Board of India through its applicable official channels.
7. Data Sharing & Third-Party Services
We share your data only with essential service providers required to operate Thodar. We do not sell, rent, or trade your data.
7.1 Service Providers
- Payment Gateway: Razorpay, used to process subscription payments.
- Cloud Hosting & Database: Railway and Neon Database, used to host application services and store application data.
- File Storage: Cloudflare R2, used to store uploaded files and images.
- Email Service: Resend, used to send transactional and service-related emails.
- Authentication: Google OAuth, used where users choose Google sign-in.
These providers may process or store personal data as necessary to provide their respective services. Their processing is subject to their own applicable privacy and security practices.
7.2 International Data Transfers
Some of our service providers may process or store data outside India. Where personal data is processed outside India, we will take reasonable steps to comply with applicable Indian data protection requirements governing such processing and any restrictions on transfers that may be notified by the Government of India.
8. Data Security & Storage
8.1 Security Measures We Implement
- Encryption in Transit: TLS 1.3 (HTTPS).
- Password Security: Hashed using bcrypt.
- Database Security: Encryption at rest (AES-256).
- Backups: Encrypted backups stored in Cloudflare R2.
8.2 Offline-First Architecture & Device Security (Critical)
Thodar is an offline-first Progressive Web App.
- A significant portion of your data is stored locally on your device using IndexedDB.
- This local data is not encrypted at rest by the Thodar app.
- If someone gains physical access to your unlocked device, they may be able to view locally stored data.
Your Responsibility:
- Use a strong PIN, password, or biometric lock on your device.
- Enable device-level encryption.
- Do not leave your device unlocked in public places.
9. Data Retention Policy
9.1 While Your Account is Active
- Account & Business Data: Retained while your account remains active and for as long as reasonably necessary to provide the Service, meet legal obligations, resolve disputes, enforce agreements, and maintain necessary business records.
- Job Photos: 90 days (auto-deleted).
- Invoice PDFs: 180 days (can be regenerated).
9.2 After Account Deletion
- Grace Period: 30 days to cancel deletion.
- Anonymization: After 30 days, identifiers are removed.
- Tax & Accounting Records: Certain transaction, invoice, and accounting records may be retained for up to 7 years, or for any longer period required by applicable law.
10. Data Breach Notification
In the event of a personal data breach, we will take appropriate steps to contain, investigate, and remediate the breach.
Where required by applicable law, we will:
- Notify the Data Protection Board of India without delay and provide the detailed information required by law within the applicable prescribed timeframe.
- Notify affected Data Principals without delay, where required, with information about the nature of the breach, likely consequences, measures taken or proposed to mitigate the impact, and steps they can take to protect themselves.
- Provide an appropriate contact point for questions relating to the breach.
11. Children's Privacy
Thodar is intended for business owners aged 18 years or older. We do not knowingly collect personal data from minors. If discovered, such accounts will be deleted immediately.
12. Marketing Communications & Opt-Out
- Transactional Emails: Mandatory (invoices, security, resets). You cannot opt out unless you delete your account.
- Promotional Emails: Optional. You can opt out via the "Unsubscribe" link or App Settings.
13. Changes to This Privacy Policy
We may update this policy to reflect legal or product changes.
- Material Changes: We will notify you via email at least 30 days in advance.
- Minor Changes: We will update the "Last Updated" date.
Where appropriate, we will provide notice of material changes before they take effect. The updated Privacy Policy will apply from its stated Effective Date.
14. Governing Law & Jurisdiction
This Privacy Policy is governed by the laws of India. Any disputes shall be subject to the exclusive jurisdiction of the courts in Chennai, Tamil Nadu, India.
15. Contact Us
For questions or Data Subject Rights Requests, please contact:
Indraveen Technologies
Business Location: Selaiyur, Chennai - 600073, Tamil Nadu, India
Business Contact: +91 79047 54545
Email: support@indraveentech.in