Privacy Policy
v1.0 · Effective 25 September 2026
2.1 Who we are and the two roles we play
This policy is issued by Tangudu Systems Private Limited ("SchemeBook") under the Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and is written to comply with the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025 as they come into force.
SchemeBook processes personal data in two capacities:
- As a Data Fiduciary for people who deal with SchemeBook directly: merchant owners, signatories and staff, website visitors, and people who contact us.
- As a Data Processor for Customers of a Merchant. The Merchant decides why and how Customer data is used; SchemeBook processes it on the Merchant's instructions under the DPA. Customers should read the Merchant's notice on the portal and contact the Merchant first for requests about their data.
2.2 What we collect and why — Merchants and staff
| Data | Source | Purpose | Legal basis |
|---|---|---|---|
| Business name, trade name, type of business, address | You; GSTN | Create and run the workspace; invoices | Contract |
| Signatory name and role, mobile, email | You | Sign-in identity (email, via Clerk), recovery identity (mobile), notices | Contract |
| PAN, name on PAN, entity type and status | NSDL via Setu, with your consent | Verify the business for UPI activation; RBI merchant due diligence | Consent; legal obligation of our payment partner |
| GSTIN, legal name, registered address | GSTN via Setu | Verification; place of supply on invoices | Consent; legal obligation (GST) |
| Aadhaar of the signatory — name and masked number only | DigiLocker via Setu, with your explicit consent | Officially valid document for merchant KYC | Consent (Aadhaar Act, 2016 §8) |
| Bank account number, IFSC, account-holder name | You; your bank via ₹1 penny drop | Settlement account verification | Consent; contract |
| Card token, mandate id, network, issuing bank, last 4 digits, expiry | Razorpay | Subscription billing (we never receive the card number or CVV) | Contract |
| Contact point verification record — visit date, signboard photo, address as seen, person met | Our visit | Merchant due diligence as Setu's agent | Legal obligation of our payment partner |
| Staff names, emails, actions in the console | You; the Platform | Access control; immutable audit trail | Contract; legitimate use |
| Device, browser, IP, usage events | Automatic | Security, fraud prevention, product analytics | Legitimate use |
2.3 What we process — Customers (as Processor for the Merchant)
Name, mobile number, address, optional ID number and photo, Scheme enrollments, payment history, receipts, OTP login events, WhatsApp/SMS delivery logs, and payment-link usage. We process this only to operate the Merchant's Schemes: enrollment, dues, reminders, receipts, the passbook, and online payment via Setu. We never use Customer data to market to Customers, build profiles across Merchants, or sell it.
2.4 What we never do
- We never hold, pool or route Customer money. UPI payments settle from the Customer to the Merchant's bank account through Setu.
- We never store card numbers or CVVs.
- We never store full Aadhaar numbers or Aadhaar documents.
- We never sell personal data or share it with advertisers.
2.5 Who we share data with (sub-processors)
| Provider | What | Where |
|---|---|---|
| Setu (Pine Labs) | UPI payments, merchant verification (PAN, GSTIN, DigiLocker, penny drop) | India |
| Razorpay (contracted through IDFC FIRST Bank) | Card tokenisation and e-mandate for subscription billing | India |
| Meta Platforms (WhatsApp Cloud API) | OTPs, reminders, receipts on WhatsApp | Meta's global infrastructure |
| MSG91 | SMS and transactional email | India |
| Clerk | Staff sign-in for the console | United States |
| Vercel | Application hosting for web, console and portal | India (Mumbai region); static assets cached on Vercel's global CDN |
| Supabase | Postgres database and backups | India (Mumbai region) |
| Zoho | Support email | India |
We share data with authorities, courts or regulators when legally required, and with a buyer or successor if the business is transferred, under the same protections.
2.6 Where your data lives and cross-border transfers
Your data is stored and processed in India by default. The Platform's application servers and database run in Mumbai, and payments, verification, SMS and support email are handled by Indian providers. Three named exceptions leave India: console staff sign-in credentials are handled by Clerk in the United States; WhatsApp messages travel over Meta's global infrastructure; and static, non-personal assets (scripts, images) are cached on Vercel's global CDN. Any transfer outside India is made only to countries not restricted by the Central Government under the DPDP Act and under contracts requiring equivalent protection. We will add a new non-Indian provider only for a stated reason and with notice under §2.14 and DPA §5.
2.7 Security
Encryption in transit (TLS) and at rest; hashed OTPs with expiry and attempt limits; workspace-scoped access so no Merchant can see another's data; immutable audit trail of every financial action; nightly encrypted backups; least-privilege access for our staff; signed, idempotent webhooks. Report a security issue to hello@schemebook.app.
2.8 Retention
| Data | Kept for |
|---|---|
| Workspace and Merchant Data | The life of the subscription + 30 days export window, then deleted |
| Tax invoices, billing records | 8 years (Income-tax and GST record rules) |
| Merchant KYC / CPV records | 5 years after the relationship ends (RBI KYC Directions, via our payment partner's obligations) |
| Audit trail | Life of the workspace + statutory period for financial records |
| OTP codes | Deleted on use or expiry (10 minutes) |
| Backups | Rolling 30 days |
| Support emails | 2 years |
2.9 Your rights
Under the SPDI Rules and the DPDP Act you may: access a summary of your personal data and how it is processed; correct or update it; request erasure once the purpose is served and no law requires retention; withdraw consent (which may end a service that depends on it, e.g. UPI activation); nominate a person to exercise your rights if you are incapacitated or deceased; and raise a grievance.
Merchants exercise these rights from Settings or by email. Customers of a Merchant should contact the Merchant, who can act in the console; if the Merchant does not respond, contact us and we will assist within our role as processor.
2.10 Grievance Officer / Data Protection contact
Name: Srinath Tangudu · Designation: Director and Grievance Officer · Email: hello@schemebook.app · Postal: SF-02, Avonlea Nest, Madhurawada, Visakhapatnam 530048 · Acknowledgement within 48 hours; resolution within 15 days (IT Rules 2021) or the shorter period the DPDP Rules prescribe. If unsatisfied, you may approach the Data Protection Board of India once operational.
2.11 Cookies
The console and portal use only strictly necessary cookies (session, CSRF, sign-in). The public site uses privacy-respecting analytics without cross-site tracking. No advertising cookies.
2.12 Children
The Platform is for businesses and their adult Customers. We do not knowingly process a child's data; a Merchant enrolling a minor must hold verifiable parental consent as the DPDP Act requires.
2.13 Breach notification
If a personal-data breach affects you, we notify the Data Protection Board and affected individuals within the period the DPDP Rules require, and notify affected Merchants (as fiduciaries for their Customers) without undue delay so they can meet their own obligations.
2.14 Changes
Material changes are announced by email and in the console at least 30 days ahead; the version and date at the top of the page are the record.