Legal · Aadhaa

Privacy Policy

Effective 28 May 2026 9 min read Aadhaa Innovative Solutions Private Limited

This Privacy Policy explains how Aadhaa Innovative Solutions Private Limited ("Aadhaa", "we", "us", or "our") collects, uses, stores, shares, and protects your personal data when you use the Aadhaa consumer app, the Aadhaa vendor app, and any related websites or services (together, the "Platform").

We are the Data Fiduciary for your personal data under India's Digital Personal Data Protection Act, 2023 (DPDP Act) and the Information Technology Act, 2000 and rules made under it. By using the Platform, you agree to the practices described here.

If you do not agree with this Policy, please do not use the Platform.


1Who this Policy covers

The Platform has two kinds of users, and we collect different data for each:

  • Consumers — people who use the Aadhaa consumer app to discover stores and deals, claim deals, and redeem them in-store.
  • Vendors and vendor staff — businesses (and the staff they authorise) who use the Aadhaa vendor app to list stores, products, and deals, and to redeem customer vouchers.

Where a practice applies only to one group, we say so.


2The personal data we collect

2.1Information you give us

When you create an account (consumers and vendors):

  • Mobile phone number — required. This is your primary identity and is verified by a one-time password (OTP).
  • Name — collected during onboarding.
  • Email address — optional for consumers; optional for vendor staff.
  • Date of birth — optional, consumer only.
  • Profile photo — optional, if you choose to upload one.

Additional information from vendors and vendor staff:

  • Business details — business/legal name, business phone number.
  • GST number and business registration / certificate documents, where you provide them for verification.
  • Store details — store name, description, category, address, area, city, operating hours, contact phone, and the store's geographic location (latitude/longitude).
  • Staff details — name, phone, optional email, and the role/permissions you assign to each staff member.

Content you upload:

  • Profile photos, store images, product images, and business-certificate documents.

2.2Information we collect automatically

  • Location data (consumer app): With your permission, we collect your device's precise and/or approximate location to show you nearby stores and deals and to power location-based notifications. You can also save named locations (e.g., Home, Work) yourself. You can disable location access at any time in your device settings; some features (such as "near me" discovery) will not work without it.
  • Location data (vendor app): We use your location only to help you place your store on the map during setup. We do not continuously track vendor location.
  • Device and technical data: device type and operating system, app version, device platform (Android/iOS), and a push-notification token (Firebase Cloud Messaging) so we can send you notifications.
  • Usage and analytics data: screens viewed and in-app events (for example, viewing, claiming, redeeming, or sharing a deal; searches performed). We use this to understand and improve the Platform.
  • Crash and diagnostic data: crash reports and error logs to help us fix problems.

2.3Transaction and activity data

  • Deal claims and vouchers: the deals you claim, the unique voucher (QR) code generated for each claim, claim quantity, status, and redemption details (when, at which store, by which staff member).
  • Store ratings: if you rate a store (1–5 stars), we store that rating against your account.
  • Notification preferences: your notification settings and the saved location(s) and preference groups you use to tune which deals you hear about.

Note: In-app payments are not enabled at launch, so we do not currently collect any payment information. If in-app payments are introduced, we will update this Policy before doing so.


3How we use your data, and our lawful basis

Under the DPDP Act, we process your personal data on the basis of your consent (which you give when you sign up and use specific features) and, where permitted, for legitimate uses necessary to provide the service you asked for.

Purpose Examples
Provide the service Create and secure your account; verify you by OTP; show nearby stores and deals; let you claim and redeem deals; let vendors list and manage deals and redeem vouchers.
Location features Show "near me" deals; power location-based notifications; place vendor stores on a map.
Communications Send transactional messages (OTP, voucher and redemption updates) and, where enabled, deal notifications.
Safety and fraud prevention Detect and prevent fraudulent claims/redemptions; rate-limit abuse; keep audit logs of redemption attempts.
Improve the Platform Analytics and crash diagnostics to understand usage and fix issues.
Legal and compliance Meet legal, tax, and regulatory obligations; respond to lawful requests.

We will not use your personal data for a materially new purpose without telling you and, where required, obtaining your consent.


4Where your data is stored — data localisation

Your core personal data (accounts, profiles, deals, stores, vouchers, uploaded images and documents, and notifications) is stored on Amazon Web Services (AWS) infrastructure located in the Mumbai, India region (ap-south-1). Storing your data in India is a deliberate choice that supports our compliance with India's data-protection framework.


5Who we share your data with

We do not sell your personal data. We share it only as described below.

5.1Between users, to make the marketplace work

  • What consumers see about vendors: your store's public profile — name, category, description, address/area/city, operating hours, images, products, deals, and average rating. We do not show consumers a vendor's internal data (e.g., GST number, business certificate, staff list, or internal configuration).
  • What vendors see about consumers: when you redeem a voucher in-store, the vendor's staff can see the voucher and the fact that it was redeemed. Vendors do not receive your phone number, profile, or contact details through the Platform.

5.2Service providers and processors

We share limited data with trusted providers who process it on our behalf:

Provider What they receive Purpose Where
Amazon Web Services (AWS) All core data; authentication (Amazon Cognito) Hosting, database, storage, authentication India (ap-south-1)
2Factor.in (with AWS SNS as fallback) Your mobile phone number Sending login OTP by SMS India
Google Firebase (Google LLC) Push-notification token; analytics events; crash/diagnostic data Push notifications, analytics, crash reporting Google Cloud (may be processed outside India — see Section 6)
OLA Maps (with OpenStreetMap/Nominatim fallback) Addresses and/or coordinates you search Converting between addresses and map locations (geocoding) India

Each provider is permitted to use your data only to perform services for us.

We may disclose personal data if required by law, court order, or a valid request from a government or law-enforcement authority, or where necessary to protect the rights, safety, or property of Aadhaa, our users, or the public.

5.4Business transfers

If Aadhaa is involved in a merger, acquisition, or sale of assets, your data may be transferred as part of that transaction. We will notify you and ensure your data remains protected under terms consistent with this Policy.


6Cross-border transfer

Most of your data stays in India (Section 4). However, certain providers — notably Google Firebase (push notifications, analytics, crash reporting) — may process some data (such as your device push token, analytics events, and crash logs) on infrastructure outside India. We rely on these providers' contractual and security commitments to protect your data, and we transfer such data only to the extent permitted by applicable Indian law.


7How long we keep your data

  • We keep your account and profile data for as long as your account is active.
  • Transaction records (claims, redemptions, ratings) are kept for as long as needed to provide the service and to meet legal, tax, accounting, and fraud-prevention obligations.
  • Analytics and crash data are retained for the provider's standard retention periods.
  • When you log out, locally stored data on your device is cleared and your push token for that device is deactivated.
  • When you delete your account, we delete or anonymise your personal data within a reasonable period, except where we must retain it to comply with law or to resolve disputes.

8Your rights

Under the DPDP Act, you have the right to:

  • Access a summary of the personal data we hold about you and how we process it.
  • Correct, complete, or update inaccurate or incomplete data.
  • Erase your personal data where it is no longer needed for the purpose it was collected (subject to legal retention requirements).
  • Withdraw consent at any time (this will not affect processing already done, and may limit your ability to use the Platform).
  • Nominate another individual to exercise your rights in the event of death or incapacity.
  • Grievance redressal — raise a complaint with our Grievance Officer (Section 11) and, if unsatisfied, escalate to the Data Protection Board of India.

To exercise any of these rights, contact us at privacy@aadhaa.in or use the in-app account controls where available. We may need to verify your identity before acting on a request.


9Children's data

The Platform is intended for users aged 18 and above. We do not knowingly collect personal data from children. If you are a parent or guardian and believe a child has provided us personal data, contact us at privacy@aadhaa.in and we will delete it.


10How we protect your data

We use reasonable technical and organisational measures to protect your data, including: encryption of data in transit and at rest, OTP-based authentication, scoped access controls for vendor staff, rate-limiting and audit logging of sensitive actions (such as voucher redemption), and storage in a private, access-controlled environment. No method of transmission or storage is perfectly secure, but we work to protect your data and to notify the relevant authorities and affected users of a personal-data breach as required by law.


11Grievance Officer

In accordance with the DPDP Act and the Information Technology (Intermediary Guidelines) Rules, 2021, you may contact our Grievance Officer for any data-protection concern or complaint:

Grievance Officer: Prasanth Chakka
Aadhaa Innovative Solutions Private Limited
B304, DSR Fortune Prime, Madhapur, Hyderabad, Telangana 500081
Email: grievance@aadhaa.in

We will acknowledge your complaint promptly and aim to resolve it within the timelines required by law.


12Changes to this Policy

We may update this Policy from time to time. When we make material changes, we will update the "Last updated" date and, where appropriate, notify you in the app. Your continued use of the Platform after changes take effect means you accept the updated Policy.


13Contact us

For any questions about this Policy or your personal data:

Aadhaa Innovative Solutions Private Limited
B304, DSR Fortune Prime, Madhapur, Hyderabad, Telangana 500081
Privacy: privacy@aadhaa.in · Support: support@aadhaa.in