Kaamio
Join the Waitlist

Privacy Policy

Effective Date: 【Please fill in: Effective Date (DD/MM/YYYY)】

This Privacy Policy ("Policy") describes how Kaamio ("we," "us," or "our"), operated by 【Please fill in: Company Legal Name】 ("Company"), collects, uses, discloses, stores, and protects the personal information of users of the Kaamio mobile application ("Customer App") and Kaamio Partner mobile application ("Partner App"), collectively referred to as the "Platform." This Policy is published in compliance with the Digital Personal Data Protection Act, 2023 ("DPDP Act") of India, the Information Technology Act, 2000, and the rules framed thereunder, including the SPDI Rules, 2011. By accessing or using the Platform, you explicitly consent to the collection, processing, storage, and transfer of your personal data as described in this Policy. If you do not agree with any provision of this Policy, you must discontinue use of the Platform immediately.

We are committed to ensuring that your personal data is handled lawfully, fairly, and transparently. We collect only such personal data as is necessary for the purposes specified in this Policy, and we process such data with your free, specific, informed, and unambiguous consent, or as otherwise permitted under applicable law. This Policy applies to all users of the Platform irrespective of their location; however, the primary regulatory framework governing our data processing activities is the DPDP Act of India.

1. Information We Collect

We collect several categories of personal information to provide, improve, and secure our Platform and services. The information we collect may vary depending on whether you are a Customer or a Partner, but broadly includes the following categories:

1.1 Information You Provide Directly

Account Registration Data: When you register on the Platform, we collect your full name, mobile phone number, email address, and a password. For Partners, we additionally collect your business name, service categories offered, service area, years of experience, and professional qualifications or certifications that may be relevant to the services you intend to provide through the Platform.

Identity Verification Data: For Partners, we collect government-issued photo identification (Aadhaar card, PAN card, Voter ID, or Driving Licence) for KYC (Know Your Customer) verification purposes. This is a mandatory requirement for Partner onboarding and is essential for the safety and trust of all Platform users. We also collect selfie photographs for identity matching against the submitted documents.

Profile Information: Both Customers and Partners may provide additional profile details such as profile photographs, gender, date of birth (for age verification), and preferred language. Partners may also provide portfolio images, service descriptions, pricing information, and business hours.

Communication Data: We collect the content of messages, chats, and calls made through the Platform between Customers and Partners for the purposes of dispute resolution, quality assurance, and compliance with legal obligations. We do not monitor communications in real time unless required by law or to investigate suspected fraud or policy violations.

Payment and Financial Data: For payment processing, we collect bank account details, UPI IDs, and payment instrument information. Credit/debit card details are NOT stored on our servers and are processed directly by our third-party payment gateway partner (currently Razorpay). We store transaction records, invoices, and payment histories for accounting and compliance purposes.

1.2 Information Collected Automatically

Device and Technical Data: When you access the Platform, we automatically collect device identifiers (IMEI, Android ID, or IDFV), device model, operating system version, browser type, screen resolution, and mobile network information (carrier name, network type). This data is essential for providing a stable and optimized user experience across diverse devices and network conditions prevalent in India.

Location Data: With your explicit permission, we collect precise geolocation data (GPS coordinates) to enable hyperlocal service discovery, matching Customers with nearby Partners, real-time service tracking, and route optimization. Location data is collected only while you are actively using the Platform or have enabled location sharing for an active service booking. You may revoke location permission at any time through your device settings, though this may affect the availability of certain features.

Usage Analytics: We collect information about how you interact with the Platform, including pages viewed, features used, search queries, booking patterns, session duration, click patterns, and error reports. This data is collected through our analytics providers and helps us improve the Platform's usability, performance, and relevance.

Cookies and Similar Technologies: We use cookies, web beacons, and similar tracking technologies to maintain session information, remember your preferences, deliver personalized content, and analyze Platform traffic. You can manage cookie preferences through your device or browser settings, though disabling certain cookies may affect Platform functionality.

1.3 Information from Third Parties

We may receive information about you from third-party sources, including: (a) Google Sign-In or other social login providers, from whom we receive your basic profile information (name, email, profile picture) as authorized by you during the login process; (b) Our payment gateway partner Razorpay, which provides transaction status and completion confirmations; (c) Google Maps API services, which provide location and mapping data; (d) Government databases, for verification of Partner KYC documents where permitted by law; and (e) Referral partners, from whom we may receive your name and contact information if you are referred to the Platform.

2. Data Retention Policy

We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, or as required by applicable laws, regulations, or legal obligations. Our data retention framework is designed to balance your privacy rights with our legitimate business needs and regulatory compliance requirements. The following retention periods apply to different categories of data:

2.1 Active Account Data

All personal data associated with an active account is retained for the duration of the account's existence plus a period of three (3) years following the last activity on the account. This includes your profile information, booking history, transaction records, communication logs, and any other data generated through your use of the Platform. The three-year post-activity retention period is maintained to comply with tax audit requirements under the Income Tax Act, 1961, and to address any potential disputes that may arise from past transactions or services.

2.2 KYC and Verification Data

KYC documents (government-issued identification, photographs, and verification results) submitted by Partners are retained for a period of five (5) years from the date of submission, or for the duration of the Partner's association with the Platform, whichever is longer. This extended retention period is necessary for compliance with RBI guidelines on KYC norms, prevention of money laundering under the PMLA, 2002, and for ensuring the safety and integrity of the Platform's user base. Even after a Partner account is deactivated or terminated, KYC data is retained in a secure, access-restricted archive for the full five-year period.

2.3 Transaction and Financial Records

All transaction records, invoices, payment histories, GST-related documentation, and financial records are retained for a minimum of eight (8) years from the date of the relevant transaction. This retention period is mandated by the Goods and Services Tax (GST) Act, 2017, and the Income Tax Act, 1961, which require businesses to maintain financial records for audit and assessment purposes. These records are stored in encrypted form with access limited to authorized finance and compliance personnel.

2.4 Communication Logs

Chat messages, call records, and other communication logs between Customers and Partners are retained for a period of one (1) year from the date of communication. After this period, communication logs are automatically purged from our active systems, except where they have been flagged as relevant to an ongoing dispute, legal proceeding, or regulatory investigation. In such cases, the relevant communication logs are preserved until the conclusion of the matter plus an additional twelve (12) months.

2.5 Analytics and Usage Data

Anonymized and aggregated usage analytics data may be retained indefinitely for research, product improvement, and statistical analysis purposes. Once data has been sufficiently anonymized such that it can no longer be used, either directly or indirectly, to identify an individual, it falls outside the scope of this Policy and may be used freely for business intelligence and Platform enhancement.

2.6 Data Deletion Upon Request

You have the right to request the deletion of your personal data at any time, subject to the limitations described in this Policy and applicable law. Upon receiving a verified deletion request, we will delete or anonymize your personal data within thirty (30) calendar days, except where retention is required by law (such as financial records under GST and Income Tax Acts), or where the data is necessary for the establishment, exercise, or defense of legal claims. In cases where complete deletion is not legally permissible, we will minimize the data to the extent possible and restrict its processing to only those purposes mandated by law. You will be informed of any data categories that cannot be deleted and the legal basis for their continued retention.

3. Account Deletion and Data Erasure

We provide clear and accessible mechanisms for both Customers and Partners to request the deletion of their accounts and associated personal data. Account deletion can be initiated through the following channels:

  • In-app: Navigate to Settings > Account > Delete Account, which will guide you through a verification and confirmation process;
  • Email: Send a deletion request to 【Please fill in: Privacy Officer Email Address, e.g., privacy@kaamio.in】 from your registered email address;
  • Written Request: Submit a signed written request to our Data Protection Officer at 【Please fill in: Registered Office Address】.

Upon receiving a verified account deletion request, we will process it as follows: First, we will verify your identity by sending a confirmation to your registered email and mobile number. You must confirm the deletion request within seven (7) calendar days. Upon confirmation, your account will be deactivated immediately, meaning you will no longer be able to log in or access any Platform features. During a cooling-off period of fourteen (14) calendar days following deactivation, your data will remain in our system in case you wish to reverse the decision. After the cooling-off period expires, we will initiate the permanent deletion of your personal data from our active databases within thirty (30) calendar days, and from our backup systems within ninety (90) calendar days.

Please note that certain data may be retained beyond the deletion period as required by applicable law. Specifically: (a) Financial and transaction records will be retained for eight (8) years as required by GST and Income Tax laws; (b) KYC documents of Partners will be retained for five (5) years as required by PMLA and RBI guidelines; (c) Data related to ongoing disputes, legal proceedings, or regulatory investigations will be retained until the conclusion of such matters; (d) Anonymized and aggregated data that cannot be used to identify you may be retained indefinitely. We will provide you with a detailed breakdown of data categories that have been deleted and any that have been retained, along with the legal basis for such retention, upon completion of the deletion process.

4. How We Use Your Information

We use the personal information we collect for the following specific, explicit, and lawful purposes:

  • To provide, operate, and maintain the Platform and its core functionality, including service booking, matching, and fulfillment;
  • To verify the identity and credentials of Partners through KYC processes to ensure the safety and trustworthiness of service providers on the Platform;
  • To process payments, manage commissions, facilitate refunds, and maintain financial records in compliance with applicable tax laws;
  • To communicate with you regarding your account, bookings, service updates, promotional offers (with your consent), and important Platform announcements;
  • To provide customer support and Partner support, respond to inquiries, and resolve disputes between Customers and Partners;
  • To monitor and analyze Platform usage patterns, detect fraud, prevent unauthorized access, and protect the security and integrity of the Platform;
  • To comply with applicable laws, regulations, court orders, and government requests, including but not limited to the DPDP Act, GST laws, and the Information Technology Act;
  • To improve, personalize, and develop new features and services based on user feedback and usage analytics;
  • To enforce our Terms and Conditions and other Platform policies.

5. Information Sharing and Disclosure

We do not sell, rent, or trade your personal information to third parties for their marketing purposes. We share your personal information only in the following limited circumstances:

  • With Partners or Customers as necessary to facilitate service bookings and fulfillment (e.g., sharing Customer location and service details with the assigned Partner, and Partner profile and estimated arrival time with the Customer);
  • With our trusted third-party service providers who perform services on our behalf, including payment processing (Razorpay), cloud hosting (Supabase), mapping services (Google Maps), analytics, and communication services. These providers are contractually bound to process your data only as instructed by us and to maintain appropriate security measures;
  • With law enforcement agencies, regulatory authorities, or other government bodies when required by law, court order, or legitimate government request;
  • To protect the rights, property, or safety of Kaamio, our users, or the public, including the detection and prevention of fraud, security breaches, and violations of our Terms and Conditions;
  • In connection with any merger, acquisition, reorganization, or sale of all or a portion of our assets, your personal data may be transferred to the acquiring entity, subject to the same level of data protection as outlined in this Policy;
  • With your explicit, informed, and specific consent for any other purpose not described above.

6. Your Consent and Rights

Your use of the Platform constitutes your informed, specific, and unambiguous consent to the collection, processing, storage, and transfer of your personal data as described in this Policy. However, we recognize that consent must be freely given, revocable, and granular. Accordingly:

  • You may grant or withhold consent for specific data processing activities at the time of account registration and at any time thereafter through the Privacy Settings section of the App;
  • Consent for location tracking, push notifications, and marketing communications is requested separately and independently from the consent for core service functionality;
  • You may withdraw your consent at any time by adjusting your Privacy Settings or by contacting us at 【Please fill in: Privacy Officer Email Address】. Withdrawal of consent will not affect the lawfulness of processing carried out prior to the withdrawal; however, it may affect your ability to use certain features of the Platform that depend on the processing of the relevant data.

Under the DPDP Act and other applicable laws, you have the following rights with respect to your personal data:

  • Right to Access: You may request a copy of the personal data we hold about you, along with information about the purposes of processing, categories of data processed, and the recipients or categories of recipients to whom your data has been disclosed;
  • Right to Correction: You may request the correction of any inaccurate or incomplete personal data we hold about you;
  • Right to Erasure: You may request the deletion of your personal data, subject to the exceptions described in Section 3 of this Policy;
  • Right to Data Portability: You may request your personal data in a structured, commonly used, and machine-readable format;
  • Right to Grievance Redressal: You have the right to lodge a complaint with the Data Protection Board of India if you believe that your personal data has been processed in violation of the DPDP Act. To exercise any of these rights, please contact our Data Protection Officer at 【Please fill in: DPO Email Address, e.g., dpo@kaamio.in】.

7. Data Security

We implement industry-standard technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These measures include: (a) Encryption of all data in transit using TLS 1.2/1.3 protocols and encryption of data at rest using AES-256 encryption; (b) Regular security audits, vulnerability assessments, and penetration testing conducted by independent third-party security firms; (c) Access controls based on the principle of least privilege, ensuring that only authorized personnel with a legitimate business need can access personal data; (d) Secure data storage through our cloud infrastructure provider (Supabase) with multi-region redundancy and automated backups; (e) Employee training on data protection and information security best practices; (f) Incident response procedures for prompt detection, reporting, and mitigation of data breaches.

Despite our best efforts, no method of electronic storage or transmission is 100% secure. In the event of a data breach that is likely to cause harm to you, we will notify you and the Data Protection Board of India without unreasonable delay, in accordance with the DPDP Act.

8. Age Restriction and Children's Privacy

The Platform is intended solely for individuals who are eighteen (18) years of age or older. We do not knowingly collect, use, or disclose personal information from children under the age of 18. If we discover that we have inadvertently collected personal information from a child under 18 without verifiable parental consent, we will take immediate steps to delete such information from our servers.

By registering on the Platform, you represent and warrant that you are at least 18 years of age. If we determine that a user is under 18, their account will be terminated immediately and all associated data will be deleted in accordance with our data retention policy. Parents or guardians who believe that their child has provided personal information to us should contact us immediately at 【Please fill in: Privacy Officer Email Address】 so that we can take appropriate action.

9. Cookies and Tracking Technologies

We use cookies and similar tracking technologies to enhance your experience on the Platform. Essential cookies are necessary for the basic functioning of the Platform and cannot be disabled. Performance cookies help us understand how users interact with the Platform so we can improve it. Functionality cookies remember your preferences and settings. Marketing cookies (used only with your consent) help us deliver relevant advertisements. You can manage your cookie preferences through the App settings or your device settings. For more details on the specific cookies we use, please contact us at 【Please fill in: Support Email Address】.

10. International Data Transfers

Our primary data processing and storage infrastructure is located in India. However, some of our third-party service providers may process data outside of India. In such cases, we ensure that appropriate safeguards are in place, including standard contractual clauses, data processing agreements, and compliance with the DPDP Act's requirements for cross-border data transfers. We will not transfer your personal data to a country or territory that has been restricted by the Indian government under the DPDP Act. By using the Platform, you acknowledge and consent to the transfer of your personal data outside of India as described in this section, subject to the safeguards mentioned above.

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will notify you through: (a) A prominent notice within the App; (b) An email notification to your registered email address; (c) A notification at the time of your next login. We will obtain your fresh consent if the changes involve the collection of new categories of data or the use of your existing data for materially different purposes. Your continued use of the Platform after the effective date of any revised Policy constitutes your acceptance of the changes.

12. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact our Data Protection Officer at: