Legal
Privacy Policy
In plain language
- We collect your phone number, name, location, date of birth and skills — because the app cannot match you to nearby work without them.
- Your phone number is not public. It is shared with the other person only when an application is accepted, and withdrawn when the work is finished.
- We never sell your data, and we do not use it for third-party advertising.
- We will never ask for your OTP, password or bank details.
- You can ask us to correct or delete your data at any time.
Contents
1. Who this policy is from 2. What this policy covers 3. What we collect, and why 4. Location, specifically 5. Who can see what 6. Why we are allowed to process it 7. Who else processes it 8. Notifications 9. Team member details 10. Messages and support 11. How long we keep it 12. Security 13. Your rights 14. Children 15. The website 16. What we do not do 17. Changes to this policy 18. Contact and grievances01Who this policy is from
This policy explains how the operator of UpadhiSetu ("UpadhiSetu", "we", "us") handles personal data. For the purposes of India's Digital Personal Data Protection Act, 2023, we are the Data Fiduciary for the data described here, and you are the Data Principal.
| Data Fiduciary | UpadhiSetu |
|---|---|
| Correspondence address | UpadhiSetu, Bengaluru, Karnataka, India |
| Privacy contact | upadhisetu@gmail.com |
| Phone | +91 8559889888 |
02What this policy covers
The UpadhiSetu mobile application, the website at upadhisetu.com, and our support channels. It does not cover what another user does with information you choose to share with them directly, or what a third-party app does after you leave ours.
03What we collect, and why
We collect what the app needs to work, and we have tried to keep the list short. Each item below corresponds to something the app actually stores.
| Data | Why we need it |
|---|---|
| Mobile number | Your identity on the Platform. Verified by a one-time SMS code — this is how you sign in, and it is what lets the other side know an account is real. |
| Name | Shown on your profile, your Work Posts and your applications, so the other person knows who they are dealing with. |
| Profile photograph (optional) | Helps a Hirer recognise the person arriving for work. You can use the app without one. |
| Date of birth | To confirm you are 18 or over. Checked on our servers, not only in the app. |
| Village or town, district | To show you work near you, and to tell a Worker roughly where a job is. |
| Approximate GPS coordinates | Stored once when you set your location, and for each Work Post, so distance can be calculated. See clause 4. |
| Skills / work categories | To match you to relevant Work Posts and to decide who is notified about a new one. |
| Current role (looking for work / posting work) | Determines which version of the app you see. |
| Work Post details — title, description, wage, dates, times, location, landmark, number of people, what is provided, photographs | This is the listing itself. Visible to Workers who can see the post. |
| Applications and hiring decisions, including a reason given when an application is declined | To run the hiring flow and to show each side the current status. |
| Messages exchanged in the app | To deliver the conversation to the other participant and to investigate reports of abuse. |
| Ratings and review counts | To show reputation to the other side before they commit. |
| Notification token | To deliver push notifications to your device. See clause 8. |
| Device and diagnostic data — app version, device model, operating system, crash reports, anonymous usage events | To find and fix crashes and to understand which parts of the app are used. Not used to identify you personally. |
| Sign-in security records — including IP address and browser or device identifier at the time of certain sign-ins | Kept as an audit trail so unusual account access can be investigated. |
We do not collect Aadhaar numbers, PAN, bank or UPI details, biometrics, contact lists, photo galleries, call logs, SMS contents, or continuous background location.
04Location, specifically
- Location is used to answer one question: how far is this work from this person?
- We ask for location permission when you set your profile location or post work. If you refuse, you can type your village or town instead, and we will look up approximate coordinates from that text.
- We store a coarse coordinate pair and a rounded area code, not a continuous trail. We do not track you in the background and we do not record your movements over time.
- Other users are shown a distance and an area name — never your exact coordinates.
05Who can see what
This is the part most people care about, so it is set out explicitly.
| Information | Who can see it |
|---|---|
| Your name, photograph, area, skills and rating | Other users, in the context of a Work Post or an application |
| Your mobile number | Not public. Shared with the other party only once an application is accepted, so the two of you can arrange the work — and withdrawn again once the work is marked complete |
| Your exact GPS coordinates | No other user. Used only to compute distance |
| Your date of birth | No other user. Used only for the 18+ check |
| Your messages | The other participant, and UpadhiSetu support where needed to help or to investigate a report |
| Team member details submitted by a Group Lead | Held privately and never shown to other users through the app. See clause 9 |
06Why we are allowed to process it
We process your data because you have given consent at signup for a clearly stated purpose, and because it is necessary to provide the service you asked for. Where we retain records to meet a legal obligation or to investigate abuse, we rely on those grounds instead. You may withdraw consent at any time (clause 13), though doing so will usually mean the account can no longer function.
07Who else processes it
We do not sell your data and we do not share it for third-party advertising. We do use service providers who process data on our instructions:
| Provider | What it does for us |
|---|---|
| Google Firebase Authentication | Sends the SMS code and manages sign-in |
| Google Cloud Firestore | Stores profiles, Work Posts, applications, messages, ratings |
| Google Cloud Storage | Stores profile and Work Post photographs |
| Google Cloud Functions | Runs the server-side logic that creates accounts and posts |
| Firebase Cloud Messaging | Delivers push notifications |
| Firebase Crashlytics | Reports crashes so we can fix them |
| Google Analytics for Firebase | Anonymous usage measurement |
| Firebase App Check | Blocks requests from tampered or fake clients |
| Geocoding services on your device | Turns a typed place name into approximate coordinates, and coordinates into a place name |
These providers may process and store data on servers outside India. We rely on their contractual data-protection commitments for such transfers.
We may also disclose data where required by law, by a court, or by a lawful request from a government authority, and where necessary to protect someone's safety or to investigate fraud or abuse.
08Notifications
We send notifications about things that concern you — work matching your skills, an application received or decided, a new message, a prompt to rate someone, and occasional announcements from UpadhiSetu about the app.
Permission is requested after you finish signing up, not before you have seen the app. You can refuse, and you can turn notifications off later in your device settings; the app continues to work without them.
09Team member details
A Group Lead applying on behalf of a team may enter each member's name, mobile number, address and date of birth. This is treated as especially sensitive:
- it is stored in a private area that other users cannot read through the app;
- it is used only to tell the Hirer who is coming to do the work;
- the Group Lead is required to have each member's consent before entering their details.
If you have been listed as a team member without your consent, contact us and we will remove the record.
10Messages and support
Messages are stored so the other participant can read them and so the conversation survives reinstalling the app. UpadhiSetu support may read a conversation and post in it when helping with a problem or investigating a report — support messages are clearly labelled as coming from UpadhiSetu Support. We do not read conversations for advertising and we do not use their contents to profile you.
11How long we keep it
- Profile data — while your account is open.
- Work Posts, applications, ratings — kept after completion so both sides keep an accurate history and reputation.
- Messages — kept while the related account exists, unless deleted earlier.
- Crash and diagnostic data — kept for a limited period by our providers and then deleted or aggregated.
- Sign-in security records — kept for a limited period for investigation.
When you ask us to delete your account, we delete or irreversibly anonymise your personal data, except where we must retain something to comply with the law or to resolve an open dispute or investigation.
12Security
Data is transmitted over encrypted connections and stored with access rules that restrict each user to their own records. Privileged operations run on our servers rather than in the app, so a modified app cannot bypass them. App Check rejects requests from clients we cannot recognise.
No system is perfectly secure. Protect your own account by keeping your phone locked and never sharing a one-time code — including with anyone claiming to be from UpadhiSetu.
13Your rights
Under the Digital Personal Data Protection Act, 2023 you may:
- access a summary of the personal data we hold about you and how it is processed;
- correct or complete inaccurate data — most of this you can do yourself in the app under Profile;
- request erasure of your data and deletion of your account;
- withdraw consent for processing;
- nominate another person to exercise your rights in the event of death or incapacity;
- complain to us, and thereafter to the Data Protection Board of India.
To exercise any of these, contact us using the details in clause 18. We will respond within 30 days. We may need to confirm control of your registered mobile number before acting, so that nobody else can delete your account.
14Children
UpadhiSetu is for adults only. Date of birth is collected at signup and the 18+ requirement is enforced on our servers, so accounts for children cannot be created. We do not knowingly process the data of anyone under 18. If you believe a child has an account, tell us and we will remove it.
15The website
upadhisetu.com is a plain informational site. It sets no advertising or tracking cookies, loads no third-party fonts, scripts or trackers, and does not build a profile of visitors. Standard server logs may record your IP address and the page requested, for security and reliability.
16What we do not do
- We do not sell or rent your personal data.
- We do not share it with advertisers or data brokers.
- We do not use your messages, photographs or ratings to target advertising.
- We do not ask for, store or process your bank, UPI or card details.
- We do not track your location in the background.
17Changes to this policy
If we change this policy we will update the "Last updated" date above and, where the change is significant, tell you in the app before it takes effect.
18Contact and grievances
For any question about this policy, or to exercise a right under clause 13, write to our privacy contact. No separate Data Protection Officer has been appointed; privacy requests are handled at the address below.
| Privacy contact | upadhisetu@gmail.com Put "Privacy request" in the subject line. |
|---|---|
| Grievance Officer | Mahesh Boya, Grievance Officer · upadhisetu@gmail.com |
| Address | UpadhiSetu, Bengaluru, Karnataka, India |
| Phone | +91 8559889888 |
| Response time | Acknowledgement within 24 hours; resolution within 7 working days |
| Support hours | Monday to Saturday, 9:00 AM – 6:00 PM IST |
If you are not satisfied with our response, you may complain to the Data Protection Board of India.