How Contact Convoy collects, uses, stores, and protects personal data under the Digital Personal Data Protection Act, 2023 and applicable Indian law.
Last updated: 28 May 2026 · Effective immediatelyThis Privacy Policy ("Policy") is issued by Contact Convoy ("we", "us", or "our"), the SaaS brand operated in India by A R ENTERPRISE (GSTIN 24GETPP7285F1ZQ), a proprietorship of Patel Ayush Bharatkumar, Gujarat. We own and operate the Contact Convoy mobile application, web dashboard, super-admin portal, APIs, and all related services (collectively, the "Service").
This Policy describes how we collect, use, store, disclose, transfer, and protect personal data of users of the Service. It is published in compliance with:
By registering for, accessing, downloading, installing, or using the Service in any manner — including by clicking "I Accept", creating an account, scanning a card, or making payment — you confirm that you have read, understood, and unconditionally agree to this Policy and to our Terms & Conditions. If you do not agree, you must immediately stop using the Service and uninstall the application.
If you are accepting on behalf of a company, partnership, LLP, or other entity ("Customer Organisation"), you represent that you are duly authorised to bind such entity and that the entity shall be jointly and severally responsible for all use of the Service under its account.
We collect only the categories of data necessary to operate, secure, improve, and bill for the Service. We do not collect any "Sensitive Personal Data" within the meaning of the SPDI Rules (such as financial account passwords, biometrics, medical records, or sexual orientation) and you must not upload such data to the Service.
We process Personal Data only for the following specified, lawful, and clearly stated purposes, with the legal basis indicated:
| Purpose | Legal basis |
|---|---|
| Provide, maintain, and operate the Service | Performance of contract |
| Authenticate users, issue OTPs, prevent account takeover | Contract / legitimate interest |
| Enforce Card Credit, seat, and fair-use limits | Contract |
| Bill and invoice you, process payments | Contract / legal obligation |
| Improve AI accuracy and feature quality | Legitimate interest (anonymised/aggregated where feasible) |
| Detect fraud, abuse, security threats | Legitimate interest / legal obligation |
| Send transactional emails, push notifications | Contract |
| Send marketing communications to you (the Customer) | Consent — opt-out anytime |
| Comply with law, court orders, regulatory requests | Legal obligation |
| Establish, exercise, or defend legal claims | Legitimate interest |
This means:
The Service uses machine-learning models (including third-party LLMs and OCR engines such as Google Cloud Vision, Groq, OpenAI, or equivalent) to extract text from card images, structure contact data, and provide suggestions.
We do not sell, rent, or trade Personal Data. We share data only with the following categories of recipients, under written agreements requiring confidentiality and security at least as strict as this Policy:
| Category | Examples | Purpose |
|---|---|---|
| Cloud hosting & database | Hostinger / AWS / GCP / MongoDB Atlas | Server & database hosting |
| Image storage & CDN | Cloudinary | Card image storage |
| Email delivery | Resend / Gmail SMTP | OTP & transactional email |
| Payment processing | Razorpay, Google Play Billing, Apple App Store | Billing & subscription |
| AI / OCR providers | Google Cloud Vision, Groq, OpenAI | Text extraction, AI features |
| Push notifications | Firebase Cloud Messaging | Mobile push delivery |
| Analytics & crash reporting | Firebase Analytics, Crashlytics | Diagnostics & product improvement |
| Professional advisers | Lawyers, auditors, accountants | Legal, audit, tax compliance |
| Government / law enforcement | Indian courts, regulators | Where compelled by valid legal process |
| Successor entity | In M&A, asset sale, restructuring | Business continuity |
Some of our processors operate servers outside India. Where Personal Data is transferred outside India, we rely on (i) the recipient country not being restricted by the Central Government under §16 of the DPDP Act, (ii) contractual safeguards (such as Standard Contractual Clauses or equivalent), and (iii) the principle that the level of protection remains substantially equivalent to that under Indian law. By using the Service you consent to such transfers.
Our website and dashboard use a minimal set of cookies and local-storage items for: (a) keeping you signed in, (b) remembering your preferences, (c) basic analytics. We do not use third-party advertising cookies. You can disable cookies in your browser, but parts of the Service may stop working.
We implement reasonable security practices and procedures within the meaning of §43A of the IT Act and the SPDI Rules, including:
In the event of a Personal Data breach that is likely to result in risk to Data Principals, we will notify the Data Protection Board of India and affected Data Principals without undue delay, in the manner and within the time prescribed under the DPDP Act and rules. Where the breach concerns Card-Subject data of which you are the Data Fiduciary, you remain primarily responsible for notifying the Data Principals and authorities; we will cooperate and provide reasonable assistance.
Subject to applicable law and verification of your identity, you may:
We will respond to verified requests within the timelines prescribed by law (and in any case within 30 days). Frivolous, vexatious, or repetitive requests may be refused or charged a reasonable fee in accordance with §15 of the DPDP Act.
Pursuant to the IT Rules 2021 and the DPDP Act, our Grievance Officer is:
Grievances will be acknowledged within 72 hours and resolved within 15 days, in line with applicable law.
The Service is intended exclusively for business users aged 18 years and above. We do not knowingly collect Personal Data from children (under §2(f) of the DPDP Act). If we learn that we have inadvertently collected children's data, we will delete it promptly. Parents or guardians who believe their child has provided data should contact our Grievance Officer.
The Service may contain links to third-party websites or services (e.g. Razorpay checkout, Google Maps for office locations on scanned cards). We are not responsible for the privacy practices, content, or accuracy of any such third party. Your interaction with third parties is governed by their own policies.
You may close your account at any time using the steps on our Delete account & data page (in-app Delete Account or email to support), or by writing to support. Once closure is confirmed, your account becomes inactive and data is retained in accordance with §12. We may suspend or terminate accounts that violate our Terms, abuse the Service, or pose security/legal risk; in such cases data may be retained for evidence and legal-defence purposes.
Without limiting the above, we do not warrant that: (i) the Service will meet your specific business requirements; (ii) extracted text from cards will be 100% accurate; (iii) the Service will be available without downtime; (iv) defects will be corrected within any particular time; (v) any data will be permanently retrievable in case of force majeure or hardware failure beyond our reasonable backup procedures.
Our aggregate cumulative liability to you for all claims of any kind, whether in contract, tort (including negligence), strict liability, or otherwise, arising out of or related to the Service or this Policy, shall not exceed the total fees actually paid by you to Contact Convoy in the three (3) months immediately preceding the event giving rise to the claim, or INR 5,000, whichever is lower.
You agree that the limitations in this section are a fundamental basis of the bargain between you and Contact Convoy, and that the Service would not be provided to you without these limitations.
You agree to defend, indemnify, and hold harmless Contact Convoy, its founders, directors, officers, employees, contractors, agents, affiliates, and licensors from and against any and all claims, demands, suits, proceedings, losses, damages, liabilities, costs, and expenses (including reasonable legal fees) arising out of or in connection with:
We reserve the right, at our own expense, to assume exclusive defence and control of any matter subject to indemnification by you, in which case you agree to cooperate fully.
This Policy is governed by and construed in accordance with the laws of the Republic of India, without regard to its conflict-of-laws principles. Subject to §24, the courts at Ahmedabad, Gujarat shall have exclusive jurisdiction over all disputes arising out of or in connection with this Policy.
Before initiating any litigation, the parties shall attempt in good faith to resolve any dispute through informal negotiation by writing to legal@contactconvoy.in. If the dispute is not resolved within 30 days, it shall be referred to and finally resolved by arbitration under the Arbitration and Conciliation Act, 1996, by a sole arbitrator appointed by Contact Convoy. The seat of arbitration shall be Ahmedabad, the language shall be English, and the award shall be final and binding.
We may revise this Policy from time to time to reflect changes in law, technology, or our practices. Material changes will be communicated by email and/or in-app notice at least 7 days before they take effect. The "Last updated" date at the top will always reflect the latest version. Continued use of the Service after the effective date constitutes acceptance of the revised Policy.
For any questions, concerns, complaints, or requests regarding this Policy or your Personal Data: