Privacy Policy

Data Collection Scope

  • Personal Data: Name, email, phone, business address, GSTIN, PAN, and payment method (processed via Razorpay).
  • Usage Data: IP address, device type, cookies (e.g., session cookies for login).
  • No Sensitive Data: Aadhaar, biometrics, or health data is not collected.

Purpose of Data Processing

  • Service Delivery: Account creation, payment processing, and customer support.
  • Internal Use: Analytics, feature improvement, and personalized marketing (e.g., promotional emails).
  • Legal Compliance: Sharing data with tax authorities (Income Tax Act) or law enforcement (CrPC).

Data Sharing & Third Parties

  • Service Providers: Razorpay (payments), AWS (hosting), Google Analytics (traffic monitoring).
  • Legal Requirements: Data shared with authorities under valid court orders or statutory requirements.
  • No Commercial Sharing: Personal data never sold or rented to third parties.

Data Security Measures

  • Technical Controls: SSL encryption, firewalls, and access controls as per ISO 27001 standards.
  • Organizational Controls: Employee NDAs, access logs, and regular security audits.
  • Breach Response: Incidents reported to CERT-In within 6 hours as per cybersecurity guidelines.

Data Retention & Deletion

  • Retention Period: Data kept for 5 years post-account closure (IT Act requirement).
  • Deletion Requests: Processed within 30 days except data required by law.
  • Backup Retention: Archived data retained for 180 days for disaster recovery.

Cookies & Tracking Technologies

  • Types: Essential cookies (login sessions), Analytics cookies (Google Analytics for traffic monitoring).
  • Management: Users can disable cookies via browser settings but may lose features.

Children's Privacy

  • Accounts created by minors will be terminated immediately.
  • Parents/guardians can request data deletion by submitting ID proofs to subscriptions@fridayy.ai.

Policy Updates & Notifications

  • Updates published on the platform's website.
  • Material changes (e.g., data-sharing practices) notified via email 15 days in advance.

Grievance Redressal

  • Complaints resolved within 30 days under Consumer Protection Act 2019.
  • Frivolous complaints may result in account suspension.

Last updated: June 16, 2025