This policy explains what personal data ZOPERZ collects, why we process it, who we share it with, how long we keep it, and the rights you have under India's Digital Personal Data Protection Act, 2023 ("DPDP Act"). We are the Data Fiduciary for the data described here.
1. What we collect
- Account — your mobile number (how you sign in), and optionally your name and email address if you add them.
- Your devices & warranties — the products you add, their purchase and warranty dates, and any invoices, warranty cards or proofs of purchase you upload.
- Service & marketplace activity — repair bookings, quotes, addresses you save, marketplace listings and orders, disputes, and reviews.
- Payments — records of what you paid and refunds, held as integer amounts. Card and bank details are handled by our payment gateway, not stored by us. Service partners provide bank details for payouts.
- Technical — the IP address a request arrives from (used for rate-limiting and security) and, if you turn them on, browser push subscriptions.
2. Why we process it (lawful basis)
Most processing is to provide the service you signed up for — maintaining your vault, sending warranty reminders, booking repairs, taking payments, and settling partner payouts. Some processing rests on our legitimate uses (fraud and abuse prevention, security rate-limits) or on legal obligations (keeping tax and GST records). Where we rely on your consent — for example adding a device, uploading a document, or enabling push notifications — you give it by taking that action, and you can withdraw it by removing the data or turning the feature off.
3. Who we share it with (processors)
We do not sell your data. We share the minimum necessary with the vendors that operate parts of the service on our behalf, each bound to use it only for that purpose:
- SMS provider — to deliver your one-time sign-in codes and reminder texts.
- Payment gateway — to take payments and issue refunds.
- Cloud storage — to hold the documents you upload, in a private store served only through short-lived links.
- Email provider — to send verification codes and receipts, if you add an email.
- Web push services— your browser's own push service, if you enable notifications.
Service partners see only what they need to do a job you booked (your name, contact and address for an accepted job).
4. How long we keep it (retention)
We keep data only as long as we need it for the purpose it was collected, then delete or de-identify it:
- Account & vault data — for as long as your account is open. Closing your account removes your identifying data (see section 6).
- Payment, invoice and GST records — retained for the period tax law requires (currently up to 8 years), even after you close your account. These are kept as financial records and cannot be erased earlier.
- One-time codes — expire in minutes and are stored only as an irreversible hash, never in plain text.
- Security & rate-limit logs — kept briefly and pruned automatically.
- Audit records of admin actions — retained as an integrity record; they identify the acting admin, not your personal data.
5. How we protect it
Sign-in codes and other secrets are stored hashed, never in plain text. Uploaded documents sit in a private store reachable only through short-lived signed links. Sessions can be revoked everywhere at once, and changing your number or recovering your account cuts off every other session. Traffic is served over HTTPS.
6. Your rights
- Access & portability — you can export everything we hold about you from your profile.
- Correction — you can edit your name, email, addresses and devices directly.
- Erasure — you can close your account from your profile. We strip your identifying data; where the law requires us to keep a financial record, that record is retained but detached from your identity.
- Withdraw consent — remove a device or document, or turn off a feature, at any time.
- Grievance — contact our grievance officer at privacy@zoperz.app. You may also complain to the Data Protection Board of India.
7. Children
ZOPERZ is not intended for anyone under 18, and we do not knowingly collect their data.
8. Changes
If we change this policy materially, we bump its version. The next time you sign in you will be asked to accept the new version, and we record that acceptance against the version so there is a clear, dated trail of what you agreed to.
This document describes ZOPERZ's current practices in plain language. It is not a substitute for advice from a qualified lawyer, and should be reviewed by counsel before the service launches to the public.