HomeFlow
Terms of ServicePrivacy Policy

Privacy Policy

What HomeFlow collects, why, and what you can do about it.

This is a template. It has not been reviewed by a lawyer. Before you operate this service commercially, have it checked against the Digital Personal Data Protection Act 2023 and the Information Technology (Reasonable Security Practices) Rules 2011. Replace the bracketed placeholders with your own details.

1. Who is responsiblePermalink

[Your legal entity name], [Registered address], is the data fiduciary for personal data processed through HomeFlow.

Contact: [privacy email]

[If you are required to appoint one, name your Data Protection Officer and give their contact details here.]

2. A note on owners and tenantsPermalink

Two different relationships run through the same service, and they are worth separating.

  • For your own account data — your name, email, phone — we are the data fiduciary.
  • For tenant records an owner enters, the owner decides what is collected and why. We process it on their instructions. If you are a tenant and want a record corrected or removed, ask your owner first; if they do not respond, contact us.

3. What we collectPermalink

From everyonePermalink

DataWhy
Name, email address, profile photoFrom Google when you sign in — to identify you
Mobile numberSo the other party to a tenancy can reach you
Account type and roleTo decide what you can see
Session cookieTo keep you signed in
Property-selection cookieTo remember which building you were working in

Entered by ownersPermalink

Property addresses, unit details, tenant names and contact details, lease terms, rent and deposit amounts, utility readings and bills, payment records, receipts, maintenance requests and photographs, and any agreement generated from those details.

Generated by using the ServicePermalink

An activity log recording who did what, when, and to which property or unit. This exists so an owner who has delegated work to sub-accounts can see what was done on their behalf.

Identity documentsPermalink

A tenant may upload proof of identity — Aadhaar, PAN, passport, driving licence or voter ID.

This is the most sensitive data in the service, so it is worth being exact:

WhatWhere it lives
The document image or PDFStored against your login, not against any landlord's account
The name printed on itSame
Only the last four characters of the numberThe full number is validated on entry and then discarded
  • We never store a full Aadhaar number. Section 37 of the Aadhaar Act 2016 restricts holding one, and UIDAI's guidance is to display only the last four digits. Tenants are asked to upload the masked Aadhaar.
  • A landlord sees your documents only while you are on a tenancy in their account. Nothing is copied to them; access is recomputed on each request and ends when the tenancy link does.
  • Every view is logged and shown to you — who looked, which account they were acting for, and when.
  • Removing a document deletes the file, not merely hides it.

[If you require a retention period for identity documents after a tenancy ends, state it here.]

What we do not collectPermalink

  • No full identity numbers. Four characters, for every document type.
  • No payment card or bank details. HomeFlow never handles money.
  • No passwords. Sign-in is delegated to Google.
  • No location tracking, no advertising identifiers, no third-party analytics or advertising cookies.

4. Why we process itPermalink

  • To provide the Service.
  • To authenticate you and enforce access rules.
  • To send transactional email — invitations, receipts, notifications. We do not send marketing email.
  • To keep the activity log, which is a record of who did what within an account.
  • To keep the Service secure and to investigate misuse.
  • To meet legal obligations.

We do not sell personal data. We do not use it to train machine-learning models.

5. Who else sees itPermalink

RecipientWhat for
GoogleSign-in only. We receive your name, email and profile photo.
MongoDB AtlasDatabase hosting.
VercelApplication hosting and request logs.
ResendSending transactional email, where configured.

Within an account: an owner sees everything in their account. A sub-account sees only what it was granted, for the properties it was assigned. A tenant sees only their own tenancy, bills, payments, receipts, agreements and requests.

We may disclose data where legally required, and will tell you unless prohibited.

6. Where it is storedPermalink

[Name the region your database and hosting run in. If personal data leaves India, say so and state the basis on which it is transferred.]

7. How long we keep itPermalink

  • Account data: while your account exists.
  • Tenancy records, receipts and agreements: retained after a tenancy ends, because both parties may need them — receipts are commonly needed years later for HRA claims, and agreements for disputes.
  • Activity log entries: retained for the life of the account.
  • Backups: [state your backup retention period].

[State the period after account closure when data is deleted.]

8. Your rightsPermalink

Under the Digital Personal Data Protection Act 2023 you may:

  • ask what personal data we hold about you and why;
  • ask us to correct or complete inaccurate data;
  • ask us to erase data, where we are not required to keep it;
  • nominate someone to exercise these rights if you are unable to;
  • complain to the Data Protection Board of India.

Write to [privacy email]. We will respond within [number] days.

Note the limits honestly: we cannot erase a tenant record on the tenant's request alone where the owner has a legitimate reason to keep it, such as an unresolved dispute or a statutory retention duty.

9. SecurityPermalink

  • Sign-in is delegated to Google; we hold no passwords.
  • Every database query is scoped to one account, enforced in the data layer rather than by convention, so one account cannot read another's data.
  • Permission is checked on the server for every screen and every action, not only in the interface.
  • Invitation links and join codes are stored as one-way hashes; the originals cannot be recovered, only reissued.
  • Identity documents are never served from a public or guessable URL. Every request for one is authorised afresh, logged, and returned with no-store so no copy is left in a cache.
  • Sessions are carried in signed, encrypted cookies.
  • Traffic is served over HTTPS.

No system is perfectly secure. If a breach affects you, we will notify you and the Data Protection Board as required.

10. CookiesPermalink

We use two, both strictly necessary. Neither is used for advertising or analytics:

CookiePurpose
Session cookieKeeps you signed in
hf_propertyRemembers which property you were working in

11. ChildrenPermalink

The Service is not for anyone under 18 and we do not knowingly collect their data.

12. ChangesPermalink

We may update this policy. Material changes will be notified in the Service.

13. ContactPermalink

[Your legal entity name] [Registered address] [privacy email]


Last updated: [date]

← Back to HomeFlow