Privacy Policy
What HomeFlow collects, why, and what you can do about it.
This is a template. It has not been reviewed by a lawyer. Before you operate this service commercially, have it checked against the Digital Personal Data Protection Act 2023 and the Information Technology (Reasonable Security Practices) Rules 2011. Replace the bracketed placeholders with your own details.
1. Who is responsiblePermalink
[Your legal entity name], [Registered address], is the data fiduciary for personal data processed through HomeFlow.
Contact: [privacy email]
[If you are required to appoint one, name your Data Protection Officer and give their contact details here.]
2. A note on owners and tenantsPermalink
Two different relationships run through the same service, and they are worth separating.
- For your own account data — your name, email, phone — we are the data fiduciary.
- For tenant records an owner enters, the owner decides what is collected and why. We process it on their instructions. If you are a tenant and want a record corrected or removed, ask your owner first; if they do not respond, contact us.
3. What we collectPermalink
From everyonePermalink
| Data | Why |
|---|---|
| Name, email address, profile photo | From Google when you sign in — to identify you |
| Mobile number | So the other party to a tenancy can reach you |
| Account type and role | To decide what you can see |
| Session cookie | To keep you signed in |
| Property-selection cookie | To remember which building you were working in |
Entered by ownersPermalink
Property addresses, unit details, tenant names and contact details, lease terms, rent and deposit amounts, utility readings and bills, payment records, receipts, maintenance requests and photographs, and any agreement generated from those details.
Generated by using the ServicePermalink
An activity log recording who did what, when, and to which property or unit. This exists so an owner who has delegated work to sub-accounts can see what was done on their behalf.
Identity documentsPermalink
A tenant may upload proof of identity — Aadhaar, PAN, passport, driving licence or voter ID.
This is the most sensitive data in the service, so it is worth being exact:
| What | Where it lives |
|---|---|
| The document image or PDF | Stored against your login, not against any landlord's account |
| The name printed on it | Same |
| Only the last four characters of the number | The full number is validated on entry and then discarded |
- We never store a full Aadhaar number. Section 37 of the Aadhaar Act 2016 restricts holding one, and UIDAI's guidance is to display only the last four digits. Tenants are asked to upload the masked Aadhaar.
- A landlord sees your documents only while you are on a tenancy in their account. Nothing is copied to them; access is recomputed on each request and ends when the tenancy link does.
- Every view is logged and shown to you — who looked, which account they were acting for, and when.
- Removing a document deletes the file, not merely hides it.
[If you require a retention period for identity documents after a tenancy ends, state it here.]
What we do not collectPermalink
- No full identity numbers. Four characters, for every document type.
- No payment card or bank details. HomeFlow never handles money.
- No passwords. Sign-in is delegated to Google.
- No location tracking, no advertising identifiers, no third-party analytics or advertising cookies.
4. Why we process itPermalink
- To provide the Service.
- To authenticate you and enforce access rules.
- To send transactional email — invitations, receipts, notifications. We do not send marketing email.
- To keep the activity log, which is a record of who did what within an account.
- To keep the Service secure and to investigate misuse.
- To meet legal obligations.
We do not sell personal data. We do not use it to train machine-learning models.
5. Who else sees itPermalink
| Recipient | What for |
|---|---|
| Sign-in only. We receive your name, email and profile photo. | |
| MongoDB Atlas | Database hosting. |
| Vercel | Application hosting and request logs. |
| Resend | Sending transactional email, where configured. |
Within an account: an owner sees everything in their account. A sub-account sees only what it was granted, for the properties it was assigned. A tenant sees only their own tenancy, bills, payments, receipts, agreements and requests.
We may disclose data where legally required, and will tell you unless prohibited.
6. Where it is storedPermalink
[Name the region your database and hosting run in. If personal data leaves India, say so and state the basis on which it is transferred.]
7. How long we keep itPermalink
- Account data: while your account exists.
- Tenancy records, receipts and agreements: retained after a tenancy ends, because both parties may need them — receipts are commonly needed years later for HRA claims, and agreements for disputes.
- Activity log entries: retained for the life of the account.
- Backups: [state your backup retention period].
[State the period after account closure when data is deleted.]
8. Your rightsPermalink
Under the Digital Personal Data Protection Act 2023 you may:
- ask what personal data we hold about you and why;
- ask us to correct or complete inaccurate data;
- ask us to erase data, where we are not required to keep it;
- nominate someone to exercise these rights if you are unable to;
- complain to the Data Protection Board of India.
Write to [privacy email]. We will respond within [number] days.
Note the limits honestly: we cannot erase a tenant record on the tenant's request alone where the owner has a legitimate reason to keep it, such as an unresolved dispute or a statutory retention duty.
9. SecurityPermalink
- Sign-in is delegated to Google; we hold no passwords.
- Every database query is scoped to one account, enforced in the data layer rather than by convention, so one account cannot read another's data.
- Permission is checked on the server for every screen and every action, not only in the interface.
- Invitation links and join codes are stored as one-way hashes; the originals cannot be recovered, only reissued.
- Identity documents are never served from a public or guessable URL. Every
request for one is authorised afresh, logged, and returned with
no-storeso no copy is left in a cache. - Sessions are carried in signed, encrypted cookies.
- Traffic is served over HTTPS.
No system is perfectly secure. If a breach affects you, we will notify you and the Data Protection Board as required.
10. CookiesPermalink
We use two, both strictly necessary. Neither is used for advertising or analytics:
| Cookie | Purpose |
|---|---|
| Session cookie | Keeps you signed in |
hf_property | Remembers which property you were working in |
11. ChildrenPermalink
The Service is not for anyone under 18 and we do not knowingly collect their data.
12. ChangesPermalink
We may update this policy. Material changes will be notified in the Service.
13. ContactPermalink
[Your legal entity name] [Registered address] [privacy email]
Last updated: [date]