Privacy Policy
Last updated: July 2026
1. Information We Collect
Account information: email address, display name, and password hash (or OAuth provider tokens). Business phone number: read from the store’s public Google Places listing during business claim verification — used to place an automated voice call that reads a one-time verification code (OTP). We do not collect or store the personal mobile number of the person initiating the claim. Business documents: when a claimant chooses the document upload verification method instead of a voice call, the uploaded files (utility bill, business license, lease, or tax registration) are stored privately and accessed only by Paasya™ admin reviewers. Approximate location: when you browse the feed, your device computes a coarse grid-cell identifier from your GPS signal (approximately 0.5–1 km accuracy, city-block level) and transmits only that approximate identifier to our servers to show you nearby deals. Your precise GPS coordinates are never transmitted to or stored by Paasya. We store only your city for feed personalization; the grid-cell identifier is used transiently per request and never written to our database. Usage data: interactions with posts (reactions, saves, redemptions) to improve recommendations. Device information: device type, OS version, and Expo push token for notifications.
2. How We Use Your Information
To provide and personalize the feed based on your location. To enable deal redemptions between Users and Stores. To send push notifications about deals and account activity. To place automated voice verification calls and review uploaded business documents when a store owner initiates a business claim (see Section 13 for details). To improve the App through aggregated, anonymized analytics. To enforce our Terms of Service and prevent fraud.
3. Location Data
We take your privacy seriously regarding location. Here is exactly what happens:
On your device: Your device’s GPS computes your location. Before any data leaves your device, the app rounds your coordinates to the nearest city-block grid cell (approximately 0.5–1 km per side). Your precise GPS coordinates never leave your device.
What we transmit: Only the coarse grid-cell identifier — an approximate location with ~635 m maximum error from your true position. This is above the 1,850-foot threshold that California law (CPRA) uses to define “precise geolocation,” meaning we structurally collect only approximate, not precise, location.
What we store: Only the city name you are browsing (e.g. “Austin”). The grid-cell identifier is used transiently to query nearby deals and is not written to any database, log, or analytics system.
Your controls: You can select a city manually at any time without granting location permission. Location access can be revoked in your device settings at any time and the app continues to work via manual city selection.
4. Information Sharing
We do not sell your personal information to third parties. We share data only with: Google Places API (for store information — subject to Google’s privacy policy); cloud infrastructure providers (AWS) for hosting; law enforcement when required by law. Store owners can see aggregated follower counts but not individual follower identities (except recent followers for their own store).
5. Data Security
Passwords are hashed using BCrypt with a cost factor of 12. Authentication uses JWT tokens with short expiry and refresh rotation. All API communication is encrypted via HTTPS/TLS. Sensitive configuration is stored in AWS Secrets Manager, never in code.
6. Your Rights
Access: View your data via the Profile screen. Correction: Edit your display name and profile information; request correction of other inaccurate data by contacting support@paasya.com. Deletion: Delete your account and all associated data from Profile settings. Portability: Request a copy of your data by contacting support. Opt-out of notifications: Disable push notifications in device settings. Limit location use: Revoke location permission in device settings or use the manual city selector at any time.
7. Data Retention
Active account data is retained while your account exists. Deleted accounts are soft-deleted for 30 days (for recovery), then permanently erased. Redemption records are anonymized after 90 days. Push tokens are cleared on logout.
8. Children’s Privacy
The App is not intended for children under 13. We do not knowingly collect information from children under 13. If you believe a child has provided us with personal information, contact us immediately.
9. Third-Party Services
Google Places API: Used for store discovery and photos. Subject to Google’s Privacy Policy. Apple Sign In / Google Sign In: Used for authentication. Subject to their respective privacy policies. Expo Push Notifications: Used for deal alerts. Subject to Expo’s privacy policy.
10. Cookies & Tracking
The App does not use cookies. We do not use third-party tracking or advertising SDKs. Analytics are collected in aggregate and cannot identify individual users.
11. California Residents (CCPA / CPRA)
California residents have the following rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):
Right to know. You may request disclosure of the categories and specific pieces of personal information we have collected about you, the purposes for which it is used, and any third parties with whom it is shared.
Right to correct. You may request that we correct inaccurate personal information we hold about you.
Right to delete. You may request deletion of your personal information. Requests can be submitted from the Profile screen or by contacting support@paasya.com.
Right to opt-out of sale or sharing. We do not sell or share personal information for cross-context behavioral advertising.
Right to non-discrimination. We will not discriminate against you for exercising any of these rights.
Limit the Use of My Sensitive Personal Information. Approximate location data is classified as sensitive personal information under CPRA. We collect approximate location (city-block level, ~0.5–1 km accuracy) solely to show you nearby deals — this is the core function of the service. We do not use it for advertising, profiling, or any secondary purpose. To limit our use of your approximate location: open the app → Profile → Location Privacy toggle, or revoke location permission in your device settings. You can also contact us at support@paasya.com to request this limitation and we will respond within 45 days. Limiting location use does not affect your ability to use the app — you will see city-level deals instead of closest first.
To exercise any of these rights, contact us at support@paasya.com. We will respond within 45 days as required by law.
12. Residents of India (Digital Personal Data Protection Act, 2023)
If you access Paasya from India, the Digital Personal Data Protection Act, 2023 (“DPDP Act”) applies to our processing of your personal data. This section explains how we comply.
Lawful basis. We process your personal data on the basis of your consent, given when you create an account or sign in. You may withdraw your consent at any time by deleting your account from the Profile screen. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
Your rights as a Data Principal. Under the DPDP Act you have the right to:
- obtain a summary of the personal data we process about you,
- correct, update, or complete personal data that is inaccurate or incomplete,
- erase your account and the personal data associated with it,
- nominate another individual to exercise your rights in the event of your death or incapacity, and
- raise a grievance with our Grievance Officer (below) and, if not satisfactorily resolved, escalate to the Data Protection Board of India.
Children. The DPDP Act treats every person under 18 as a child. Paasya is not directed at users under 18, and we do not knowingly collect or process the personal data of users under 18. If you are a parent or guardian and become aware that a child under 18 has provided us personal data, please contact us at the address below and we will delete it promptly.
Cross-border transfer. Your personal data is stored on Amazon Web Services infrastructure located in the United States (us-east-1 region). This transfer is permitted under Section 16 of the DPDP Act. We do not transfer your personal data to any country that the Central Government has notified as restricted.
Retention. We retain your personal data only while your account is active. Upon deletion, data is soft-deleted immediately and permanently erased within 30 days, except where retention is required by law (for example, redemption records anonymized after 90 days; see Section 7).
Grievance Officer. For questions about how we process your personal data, or to file a grievance, contact our Grievance Officer:
- Email: support@paasya.com
- Response time: We aim to acknowledge within 7 working days and resolve within 30 days of receipt.
If our response does not adequately address your grievance, you may escalate it to the Data Protection Board of India in accordance with the DPDP Act.
13. Voice Verification, Document Upload & Consent
Paasya offers two methods to verify ownership when a store owner initiates a business claim through the App: (a) an automated voice call to the store’s listed phone number, or (b) upload of business-ownership documents for admin review. We do not send SMS marketing or promotional texts.
Voice verification: when you tap “Initiate Voice Call” on the claim screen, you consent to Paasya placing an automated, robocaller-style voice call to the phone number listed for that store on Google Places (not your personal mobile). The call reads a six-digit verification code aloud twice and ends. Frequency is one call per claim attempt, with up to a few retry attempts during a single 5-minute verification window. The call lasts roughly 30 seconds. Standard call rates may apply from the recipient’s carrier. We do not store voice recordings — Twilio places the call on Paasya’s behalf and Paasya retains only the call timestamp and Twilio call SID for support diagnostics. If a store has no Google-listed phone number, the voice option is hidden and document upload is the only path.
Document upload: when you tap “Upload Documents” on the claim screen, you consent to Paasya storing the uploaded files privately in encrypted cloud storage and sharing them with Paasya admin reviewers (and, where required by law, with law enforcement). Documents are not made public, never indexed, and never shared with the store. Reviews typically complete within 48 hours. Rejected claims may be resubmitted with additional documentation. Documents are retained for the lifetime of the claim record plus 30 days after a final decision, then permanently deleted.
For both methods: voice calls and SMS delivery are provided by our third-party carrier Twilio; phone numbers and call metadata are shared with Twilio only to the extent required to place the call and are not used for any other purpose. Document storage is provided by AWS S3 in encrypted private buckets. For help reply HELP or contact support@paasya.com.
14. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes via the App. Continued use after changes constitutes acceptance.
15. Contact Us
For privacy-related questions or to exercise your rights, contact us at support@paasya.com.