Privacy Policy
Last updated: June 2026
1. Information We Collect
Account information: email address, display name, and password hash (or OAuth provider tokens). Business phone number: read from the store’s public Google Places listing during business claim verification — used to place an automated voice call that reads a one-time verification code (OTP). We do not collect or store the personal mobile number of the person initiating the claim. Business documents: when a claimant chooses the document upload verification method instead of a voice call, the uploaded files (utility bill, business license, lease, or tax registration) are stored privately and accessed only by Paasya admin reviewers. Location data: used transiently to personalize your feed — we store only city and neighborhood, never precise GPS coordinates (CCPA compliant). Usage data: interactions with posts (reactions, saves, redemptions) to improve recommendations. Device information: device type, OS version, and Expo push token for notifications.
2. How We Use Your Information
To provide and personalize the feed based on your location. To enable deal redemptions between Users and Stores. To send push notifications about deals and account activity. To place automated voice verification calls and review uploaded business documents when a store owner initiates a business claim (see Section 13 for details). To improve the App through aggregated, anonymized analytics. To enforce our Terms of Service and prevent fraud.
3. Location Data
We take your privacy seriously regarding location data. Your GPS coordinates are used transiently to find nearby deals — they are never stored in our database. We store only your city and neighborhood for feed personalization. You can change your location manually at any time via the city selector. Location permissions can be revoked in your device settings.
4. Information Sharing
We do not sell your personal information to third parties. We share data only with: Google Places API (for store information — subject to Google’s privacy policy); cloud infrastructure providers (AWS) for hosting; law enforcement when required by law. Store owners can see aggregated follower counts but not individual follower identities (except recent followers for their own store).
5. Data Security
Passwords are hashed using BCrypt with a cost factor of 12. Authentication uses JWT tokens with short expiry and refresh rotation. All API communication is encrypted via HTTPS/TLS. Sensitive configuration is stored in AWS Secrets Manager, never in code.
6. Your Rights
Access: View your data via the Profile screen. Correction: Edit your display name and profile information. Deletion: Delete your account and all associated data from Profile settings. Portability: Request a copy of your data by contacting support. Opt-out: Disable push notifications in device settings.
7. Data Retention
Active account data is retained while your account exists. Deleted accounts are soft-deleted for 30 days (for recovery), then permanently erased. Redemption records are anonymized after 90 days. Push tokens are cleared on logout.
8. Children’s Privacy
The App is not intended for children under 13. We do not knowingly collect information from children under 13. If you believe a child has provided us with personal information, contact us immediately.
9. Third-Party Services
Google Places API: Used for store discovery and photos. Subject to Google’s Privacy Policy. Apple Sign In / Google Sign In: Used for authentication. Subject to their respective privacy policies. Expo Push Notifications: Used for deal alerts. Subject to Expo’s privacy policy.
10. Cookies & Tracking
The App does not use cookies. We do not use third-party tracking or advertising SDKs. Analytics are collected in aggregate and cannot identify individual users.
11. California Residents (CCPA)
California residents have additional rights under the CCPA: Right to know what personal information is collected. Right to delete personal information. Right to opt-out of the sale of personal information (we do not sell data). Right to non-discrimination for exercising these rights.
12. Residents of India (Digital Personal Data Protection Act, 2023)
If you access Paasya from India, the Digital Personal Data Protection Act, 2023 (“DPDP Act”) applies to our processing of your personal data. This section explains how we comply.
Lawful basis. We process your personal data on the basis of your consent, given when you create an account or sign in. You may withdraw your consent at any time by deleting your account from the Profile screen. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
Your rights as a Data Principal. Under the DPDP Act you have the right to:
- obtain a summary of the personal data we process about you,
- correct, update, or complete personal data that is inaccurate or incomplete,
- erase your account and the personal data associated with it,
- nominate another individual to exercise your rights in the event of your death or incapacity, and
- raise a grievance with our Grievance Officer (below) and, if not satisfactorily resolved, escalate to the Data Protection Board of India.
Children. The DPDP Act treats every person under 18 as a child. Paasya is not directed at users under 18, and we do not knowingly collect or process the personal data of users under 18. If you are a parent or guardian and become aware that a child under 18 has provided us personal data, please contact us at the address below and we will delete it promptly.
Cross-border transfer. Your personal data is stored on Amazon Web Services infrastructure located in the United States (us-east-1 region). This transfer is permitted under Section 16 of the DPDP Act. We do not transfer your personal data to any country that the Central Government has notified as restricted.
Retention. We retain your personal data only while your account is active. Upon deletion, data is soft-deleted immediately and permanently erased within 30 days, except where retention is required by law (for example, redemption records anonymized after 90 days; see Section 7).
Grievance Officer. For questions about how we process your personal data, or to file a grievance, contact our Grievance Officer:
- Email: support@paasya.com
- Response time: We aim to acknowledge within 7 working days and resolve within 30 days of receipt.
If our response does not adequately address your grievance, you may escalate it to the Data Protection Board of India in accordance with the DPDP Act.
13. Voice Verification, Document Upload & Consent
Paasya offers two methods to verify ownership when a store owner initiates a business claim through the App: (a) an automated voice call to the store’s listed phone number, or (b) upload of business-ownership documents for admin review. We do not send SMS marketing or promotional texts.
Voice verification: when you tap “Initiate Voice Call” on the claim screen, you consent to Paasya placing an automated, robocaller-style voice call to the phone number listed for that store on Google Places (not your personal mobile). The call reads a six-digit verification code aloud twice and ends. Frequency is one call per claim attempt, with up to a few retry attempts during a single 5-minute verification window. The call lasts roughly 30 seconds. Standard call rates may apply from the recipient’s carrier. We do not store voice recordings — Twilio places the call on Paasya’s behalf and Paasya retains only the call timestamp and Twilio call SID for support diagnostics. If a store has no Google-listed phone number, the voice option is hidden and document upload is the only path.
Document upload: when you tap “Upload Documents” on the claim screen, you consent to Paasya storing the uploaded files privately in encrypted cloud storage and sharing them with Paasya admin reviewers (and, where required by law, with law enforcement). Documents are not made public, never indexed, and never shared with the store. Reviews typically complete within 48 hours. Rejected claims may be resubmitted with additional documentation. Documents are retained for the lifetime of the claim record plus 30 days after a final decision, then permanently deleted.
For both methods: voice calls and SMS delivery are provided by our third-party carrier Twilio; phone numbers and call metadata are shared with Twilio only to the extent required to place the call and are not used for any other purpose. Document storage is provided by AWS S3 in encrypted private buckets. For help reply HELP or contact support@paasya.com.
14. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes via the App. Continued use after changes constitutes acceptance.
15. Contact Us
For privacy-related questions or to exercise your rights, contact us at support@paasya.com.