This Privacy Policy explains what personal data the NivaSetu platform ("the App", "the Service", "we", "us") collects, why we collect it, how it is stored and protected, who it may be shared with, and the rights you have over your own data. It is written to comply with India's Digital Personal Data Protection Act, 2023 ("DPDP Act") and to meet Google Play's Developer Program policies for apps handling personal and sensitive data.
The Service is operated by an individual developer, not a registered company. Where the DPDP Act refers to a "Data Fiduciary," that role is held by the operator identified in the Contact section below. If you do not agree with this policy, please do not use the App.
NivaSetu is a residential-society (housing society / apartment complex / gated community) management platform. It is provisioned for a specific society by its management committee and is not available for open public sign-up. You will typically be invited or approved by a Society Manager, Wing Secretary, or Super Admin, or you self-register using a Society Code issued by your society's management. Accounts exist for the roles: Super Admin, Society Manager, Wing Secretary, Accountant, Security Guard, Service Staff, and Resident.
We only collect data that is entered into the App by you or on your behalf by your society's staff, or that your device provides when you use a specific feature (e.g., location for an SOS alert).
| Data | Why we collect it |
|---|---|
| Name, email address, phone number, password (stored as a salted hash, never in plain text) | Create and secure your account; log you in; contact you about your account |
| Google account identifier (if you use "Continue with Google") | Alternative sign-in via Firebase Authentication |
| Role and society/wing/flat assignment | Determine what you can see and do in the App |
| Data | Why we collect it |
|---|---|
| Date of birth, gender, blood group, occupation, employer, profile photo, emergency contact name/phone, residential address (city/state/country/pincode) | Society directory, emergency preparedness, resident verification |
| Aadhaar number, PAN, driving licence, rental agreement, and property-ownership proof (uploaded document images/PDFs) | Verify a resident's identity and their legal right to occupy the flat (owner/tenant KYC), as required by most Indian housing societies. These are treated as sensitive personal data — see §5 (Security) and §2.5 (Access Controls) for how they are protected. |
When a resident invites a visitor, or a Security Guard registers one at the gate, we store the visitor's name, phone number, purpose of visit, the flat they are visiting, and their entry/exit time. This data belongs to the visitor and is entered by the resident or guard, not by the visitor directly.
NivaSetu does not process payments and does not act as a payment gateway. Maintenance dues and amenity fees are paid by residents directly to the society's own UPI ID via any UPI app of the resident's choice. The App only stores: the amount due, the UPI transaction reference number (UTR) submitted by the resident for staff verification, and the resulting ledger entries in the society's accounting records (chart of accounts, journal entries, invoices, vendor bills, bank/cash account balances entered by the society's Accountant). We never collect card numbers, bank passwords, UPI PINs, or OTPs.
The mobile app requests device location only when you use the Emergency SOS feature. Triggering an SOS alert captures your device's latitude/longitude at that moment and shares it with your society's security/management staff so they can respond. We do not track or store your location in the background or at any other time.
Complaints (with photos/attachments and comments), poll votes, amenity bookings, and notice acknowledgements you submit through the App.
To deliver password resets, payment reminders, notices, and account notifications, we send messages via email and via WhatsApp (through our own self-hosted WhatsApp gateway, not the official WhatsApp Business Platform) to the phone number on your account. A log of message delivery status (not full message content in all cases) is retained for troubleshooting.
Access is restricted by role and scoped to your own society (and, for Wing Secretaries, to their assigned wing only):
Our production infrastructure — backend API, PostgreSQL database, and file storage — runs on a self-managed virtual private server located in India (Bigrock VPS, hosted at hirenarti.in). We use the following infrastructure and third-party services to run the Service. Each only receives the minimum data needed to perform its function:
| Provider | Purpose | Data involved |
|---|---|---|
Self-managed VPS (Bigrock, India — hirenarti.in) | Runs our backend API, PostgreSQL database, and stores uploaded photos and KYC/document files | All account and application data described above |
| Google Firebase (Authentication & Cloud Messaging) | "Continue with Google" sign-in; delivers push notifications | Email/Google ID (sign-in only); device push token |
| Self-hosted WhatsApp gateway (OpenWA, developer-operated, runs on the same India-based server) | Sends password-reset links and notification messages | Phone number; message content |
| Email delivery (SMTP) | Sends account and notification emails | Email address; message content |
Because our core infrastructure is hosted within India, the vast majority of your personal data is stored and processed domestically. See §8 (International Data Transfer) for the limited exceptions.
We do not share your data with data brokers, advertisers, or any party for their own independent marketing purposes. We may disclose data if required by law, court order, or a lawful request from a government authority, or to protect the rights, property, or safety of our users or the public.
No system is 100% secure. If we become aware of a data breach affecting your personal data, we will notify affected users and the relevant authority as required under the DPDP Act.
We retain your personal data for as long as your account is active with your society. Financial and accounting records (ledgers, invoices, vendor bills, audit logs) are retained for longer periods where required by applicable Indian accounting, tax, or audit-retention laws, even after an individual account is deleted, but are disassociated from your day-to-day profile wherever possible. See our Account & Data Deletion page for details on requesting deletion.
The App is not directed at children and does not offer independent accounts to children. Minors may appear only as family members added by an adult head of family who confirms they have the authority to do so on the child's behalf. We collect only the minimal fields needed for the household directory (name, relationship, age, blood group). If you believe a child has been added without appropriate parental/guardian authority, contact us using the details below and we will remove the record.
Our primary infrastructure — database, backend, and file storage — is hosted on a server physically located in India, which we operate directly. The only exception is Google Firebase (used solely for "Continue with Google" sign-in and push-notification delivery), which may process limited data (your email/Google ID for sign-in, and your device's push-notification token) on servers located outside India. We only use such providers where they maintain industry-standard security and confidentiality safeguards.
Under the DPDP Act, 2023 and as a matter of good practice, you have the right to:
The Web Admin Portal uses browser local storage/session storage to keep you signed in ("Remember Me") and to store your interface preferences. The mobile app uses secure on-device storage for the same purpose. We do not use third-party advertising cookies or cross-site trackers.
We may update this Privacy Policy from time to time to reflect changes in the App or in applicable law. We will update the "Effective date" above and, for material changes, notify users in-app or via email/WhatsApp.
Karthik Hirenarti — Developer & Operator, NivaSetu
Email: karthikhirenarti@gmail.com
Phone: +91 72044 04872
Project repository: github.com/Cartlal/society-management-app
For grievances under the DPDP Act, 2023, please contact us using the email above with the subject line "DPDP Grievance." We aim to acknowledge grievances within 7 days and resolve them within 30 days.