Legal
Privacy Policy
ApniSociety — Smart Society Management Platform
Last Updated: July 13, 2026This Privacy Policy explains how ApniSociety ("ApniSociety", "we", "us", or "our") collects, uses, stores, shares, and protects personal information when you use our society management platform.
By creating an account, accepting this Policy in any ApniSociety application, or otherwise using our Services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree, please do not use the Services.
1. Scope of This Policy
This Policy applies to all ApniSociety products and channels, including:
- Member App — for residents and society members
- Society Admin App — for society committee / authorized administrators
- Vendor App — for service providers serving societies
- Gatekeeper App — for security / gate staff
- Visitor Website — for guest / visitor check-in and entry requests
- Marketing Website — apnisociety.in and related landing pages
- Related backend services, notifications, and support channels
Together, these are referred to as the "Services".
2. Who We Are
For the purposes of applicable Indian data protection laws, we act as the entity determining how personal data is processed in connection with the ApniSociety platform. Society administrators may also process certain resident and visitor data in the course of managing their society; where they do so, they are responsible for using that data lawfully and only for legitimate society purposes.
3. Categories of Users
- Members / Residents: Individuals living in or associated with a registered society unit
- Society Admins: Authorized society managers / committee members
- Vendors: Businesses or individuals offering services to societies
- Gatekeepers: Security personnel managing entry and exit
- Visitors: Guests, delivery personnel, cab drivers, or other visitors requesting entry
- Website visitors: People browsing our public website or submitting pricing / enquiry details
- Platform operators: Authorized ApniSociety personnel who administer the platform
4. Information We Collect
The information we collect depends on which Service you use and your role. We collect information that you provide, information created through use of the Services, and information from devices and identity providers.
4.1 Account & Identity Information
- Name, email address, mobile number, and profile photo
- Sign-in identifiers from Google Sign-In or Sign in with Apple (where used)
- Account credentials / PIN hashes for gatekeeper or platform operator access (we do not store gatekeeper PINs in plain text)
- Language preference and login timestamps
4.2 Society & Residence Information
- Society name, address, structure (wings / floors / units), and related society configuration
- Unit / flat details, membership role (owner, tenant, family member), and relationship to family head
- Date of birth, gender, and household / family details (if provided)
- Society verification documents and administrator identity proofs (where required for onboarding)
4.3 KYC & Verification Documents
Depending on your role, we may collect identity and verification documents such as:
- Government ID proofs (for example Aadhaar, PAN, Driving Licence, or Passport images) for members, vendors, society admins, or gatekeepers
- Rental agreements, society registration / ownership proofs, and related supporting documents
- Vendor business proofs, visiting cards, shop photos, and verification selfies
- Gatekeeper profile details including Aadhaar number (where collected by the society for security staffing) and duty selfies for attendance
Important: Identity documents and facial images are sensitive. We process them only for verification, security, attendance, and society operations, and share them only with authorized roles as described in this Policy.
4.4 Vehicle Information
- Vehicle registration number, type, make / model / colour, and owner contact details (where provided)
- Vehicle details linked to visitor entry requests and gate logs
4.5 Visitor & Gate Security Data
- Visitor name, mobile number, email (if provided), purpose of visit, number of people, expected time, and host unit / member
- Visitor photographs (including entry / exit images), approval status, and timestamps
- Gate entry / exit logs, gatekeeper actions, overstay flags, and recurring visit patterns
- Source of the visit request (for example visitor website QR, member app, or manual gate entry)
4.6 Payments, Banking & Subscriptions
- Maintenance, facility booking, and event contribution records, including amount, payment method, UPI references, cheque / bank references, screenshots / proof of payment, and verification status
- Society and vendor bank / UPI details used to receive or settle payments (for example account number, IFSC, beneficiary name, UPI ID)
- Platform subscription billing data processed through Razorpay, including customer, subscription, and payment identifiers
We do not store full payment card numbers on our servers. Card and AutoPay processing for subscriptions is handled by Razorpay. Society maintenance and similar contributions are typically paid via UPI or other offline methods to the society, with proof uploaded for admin verification.
4.7 Service & Community Content
- Notices, announcements, documents, images, and PDFs
- Complaints, service requests, chat messages, and attachments
- Facility bookings, event participation, meeting RSVPs, and voting / poll responses
- Marketplace or rental / sale listings, photos, and expressions of interest
- Vendor service requests, reviews, ratings, and availability status
- Staff / NOC and related society operational records (where used)
- Support tickets, including your contact details and issue description
4.8 Location Data
- Approximate or precise location may be collected from vendors to verify business address / service location (where the vendor enables or completes location verification)
- We do not continuously track member or visitor GPS location as a core feature of the Services
4.9 Device, Usage & Technical Data
- Device information (model, operating system, platform, app version)
- Push notification tokens (FCM) and notification delivery status
- App usage events, diagnostics, crash logs, and performance data
- IP address, access times, pages viewed, and similar log data for websites and backends
- Cookies and similar technologies on our websites
4.10 Website Enquiries
If you submit a pricing or contact enquiry on our website, we may collect your name, society name, role, city / state, number of houses, and contact details. Some enquiries may be handed off via WhatsApp for sales follow-up.
4.11 Legal Consent Records
When you accept our Terms and Privacy Policy in an app, we store a consent record (for example user ID, app, policy version, policy URLs, platform, and acceptance time) for audit and compliance.
5. How We Collect Information
- Directly from you when you register, complete a profile, upload documents, create visitors, make payments, post content, or contact support
- From society administrators when they onboard members, staff, gatekeepers, units, or society records
- From gatekeepers and visitors during entry / exit workflows
- From identity providers such as Google or Apple when you choose those sign-in methods
- Automatically through device sensors (where permission is granted), SDKs, cookies, analytics, and crash reporting tools
6. How We Use Your Information
We use personal information to:
- Create and manage accounts, authenticate users, and enforce role-based access
- Provide society management features such as notices, complaints, bookings, meetings, voting, marketplace, and directories
- Operate visitor management and gate security, including approvals and entry / exit logs
- Process and verify maintenance / event / facility payment proofs and manage society financial records
- Process platform subscriptions and billing through Razorpay
- Verify identities and onboard societies, members, vendors, and gatekeepers
- Send transactional communications and push notifications (for example visitor approvals, notices, payment reminders, complaint updates, and security alerts)
- Provide customer support and resolve disputes or abuse reports
- Improve reliability, security, and user experience, including analytics and crash diagnostics
- Comply with legal obligations, enforce our Terms, and protect the rights, safety, and security of users and the platform
- Respond to website enquiries and share product information you request
We do not sell, rent, or trade your personal information to third parties for marketing purposes.
7. Role-Based Access Within a Society
ApniSociety is a multi-role platform. Data visibility is limited by role and society context:
7.1 Members / Residents
- Can access society notices, events, facilities, marketplace listings, vendor directories, and other features enabled for members
- Can create or approve certain visitor requests for their unit
- Their profile and membership details are visible to authorized society admins as needed to manage the society
7.2 Society Admins
- Can access member details, KYC / verification records submitted for society onboarding, payment and accounting records, bookings, complaints, meetings, voting results, vendor associations, and visitor / gate logs for their society
- Can manage gatekeepers, staff records, society bank / UPI details, and operational configurations
- Must use resident, vendor, and visitor data only for legitimate society administration and security purposes
7.3 Vendors
- Can view service requests and limited contact / unit context needed to fulfil assigned work
- Cannot freely browse unrelated member personal data across the society
7.4 Gatekeepers
- Can view and process visitor details, photos, vehicle information, host unit / member context, and entry / exit actions needed for gate operations
- May capture duty attendance selfies as part of shift check-in / check-out
7.5 Visitors
- Provide identity and visit details to request entry; photos and logs may be shared with the host member, gatekeeper, and society admin
7.6 Platform Operators
- Authorized ApniSociety personnel may access account, onboarding, subscription, KYC, and support data across societies as needed to operate, secure, support, and improve the platform, investigate abuse, and comply with law
8. Sharing With Third Parties
We share personal information only as needed to operate the Services:
- Google Firebase — authentication, database (Firestore), file storage, cloud functions, push notifications (FCM), analytics, and crash reporting
- Google / Apple — when you use Google Sign-In or Sign in with Apple
- Razorpay — subscription and related payment processing; see Razorpay's Privacy Policy
- WhatsApp / Meta — if you choose to continue a website enquiry via WhatsApp
- Professional advisors and authorities — where reasonably necessary for legal, tax, audit, fraud prevention, or regulatory compliance
- Successors — in connection with a merger, acquisition, restructuring, or sale of assets, subject to appropriate confidentiality protections
Our service providers process data on our instructions and are expected to protect it appropriately. Some infrastructure providers may process or store data in locations outside India. Where that occurs, we take steps consistent with applicable law to protect your information.
9. Legal Bases & Compliance (India)
We process personal data in accordance with applicable Indian laws, including:
- The Digital Personal Data Protection Act, 2023 (DPDP Act) and rules framed thereunder (as applicable)
- The Information Technology Act, 2000
- The Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011
We process personal data based on your consent (including in-app acceptance of this Policy), for performance of the Services you request, for legitimate society and platform operations, and where required by law. You may withdraw consent where consent is the basis of processing, subject to the impact on your ability to use certain features and any legal retention requirements.
10. Data Security
We implement technical and organisational measures designed to protect personal information, including:
- Encryption of data in transit and at rest (as supported by our cloud providers)
- Authentication controls and role-based access within societies
- Hashed credentials / PINs where applicable
- Secure cloud infrastructure with monitoring and backups
- Access logging and operational controls for platform administration
No method of transmission or storage is completely secure. Please protect your devices, accounts, and OTP / sign-in credentials, and notify us promptly of any suspected unauthorized access.
11. Data Retention
- Account and profile data are retained while your account remains active and as needed to provide the Services
- Society operational records (for example notices, complaints, bookings, visitor logs, and membership history) may be retained for the life of the society workspace and a reasonable period thereafter for audit, dispute resolution, and security
- Financial and subscription records may be retained for up to 7 years (or longer if required) for accounting, tax, and legal compliance
- Visitor photos and gate security images are retained as needed for society security and operational history; societies may request shorter retention where operationally feasible
- Legal consent / acceptance records may be retained to demonstrate compliance
- When you request deletion, we delete or anonymize personal data as described in Section 12, except where retention is required by law or needed for legitimate unresolved matters
12. Your Rights & Choices
Subject to applicable law, you may request to:
- Access the personal data we hold about you
- Correct inaccurate or incomplete information (including through in-app profile updates where available)
- Delete your account and associated personal data
- Withdraw consent where processing is based on consent
- Opt out of push notifications through device or app settings
- Request a portable copy of certain personal data you provided
- Raise a grievance regarding our handling of your personal data
To exercise these rights, email help@apnisociety.in or use our Data Deletion Request page.
For account deletion requests, we typically: (1) verify your identity, (2) deactivate the account after verification, and (3) delete or anonymize personal data within 30 days, except for information we must retain for legal, tax, accounting, security, or dispute-resolution purposes. Some society operational records may remain in anonymized or minimized form.
If you are a member, vendor, gatekeeper, or visitor whose data was uploaded by a society, we may also need to coordinate with the relevant society admin before completing certain requests.
13. Children's Privacy
The Services are intended for users aged 18 years and older. We do not knowingly create accounts for, or collect personal information directly from, children under 18. If you believe a child has provided personal data to us, please contact help@apnisociety.in and we will take appropriate steps.
14. Cookies & Similar Technologies
Our websites may use cookies and similar technologies to operate the site, remember preferences, and understand usage. You can control cookies through your browser settings. Disabling certain cookies may affect website functionality.
Our mobile apps may use analytics and crash-reporting SDKs that collect device and usage information to improve stability and performance.
15. Third-Party Links & Services
The Services may contain links to third-party websites or open third-party apps (for example UPI apps, WhatsApp, or payment pages). Their privacy practices are governed by their own policies. We are not responsible for the privacy practices of third parties we do not control.
16. Updates to This Privacy Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last Updated" date above and may notify you through in-app notices, email, or a prominent website notice. In some apps, you may be asked to re-accept the updated Policy before continuing.
Continued use of the Services after an update becomes effective constitutes acceptance of the revised Policy, except where applicable law requires a different form of consent.
17. Grievance Officer & Contact
For privacy questions, data rights requests, or grievances, contact:
We aim to acknowledge and respond to privacy-related inquiries within 7–10 business days. Complex deletion or access requests may take longer where identity verification or society coordination is required.