Privacy & Data Protection Policy
At Aqua Serve, transparency and security are central to everything we build. This policy outlines how we collect, safeguard, and process information for water delivery suppliers, route staff, and household customers.
Zero Data Selling
We never sell, rent, or trade your personal records, phone numbers, or delivery ledgers to third-party ad networks.
Suppliers Own Their Data
Customer directories, routes, and jar drop counts entered by suppliers remain their exclusive property. We act only as a secure processor.
PCI-DSS Level 1 Billing
All online payments are securely processed by Razorpay. Aqua Serve never captures or stores UPI MPINs, card CVVs, or bank logins.
Full Right to Erasure
Both suppliers and customers can request permanent account and data deletion at any time with a single tap or email.
1. Scope & Ecosystem
Aqua Serve ("we," "us," or "our") operates a specialized mobile and cloud software platform designed for drinking water delivery operations. This Privacy Policy governs two distinct groups of users:
Independent water business operators, agency managers, and field delivery staff who subscribe to manage customer routes, daily jar drops, and payments.
Consumers who download the free Aqua Serve customer app to connect with their local water supplier, receive timestamped drop alerts, track empty jars, and pay via UPI.
2. Information We Collect
We practice strict data minimization. We only collect details essential to delivering water jars and recording balances:
For Suppliers (Business Users):
- Business Profile: Business name, contact phone number, service localities, and password-protected credentials.
- Operational Settings: 20L jar inventory counts, default rates, and Morning / Afternoon delivery route partitions.
- Subscription Billing: Monthly/annual subscription status and Razorpay transaction IDs (card and UPI details are securely handled by Razorpay).
For End-Customers (Households & Offices):
- Connection Details: Customer name, mobile number (used for supplier lookup and login), and delivery address or floor number.
- Delivery & Khata Data: Timestamped jar drops, empty container exchanges, running ledger balances, and payment records.
- Vacation Schedules: User-initiated delivery pause dates to stop unwanted doorstep drops.
3. How We Use Information
Information collected is used strictly for operational logistics, billing transparency, and customer communication:
4. Data Ownership & Enterprise Security
Data Processor Architecture: Aqua Serve acts strictly as a Data Processor. Suppliers retain 100% intellectual property and commercial ownership of their customer directories and jar ledgers. We will never sell, lease, or license this data to competitors, advertisers, or third parties.
Cloud Infrastructure: All platform data is encrypted in transit using TLS 1.3 encryption and stored in secure Google Cloud Firebase data centers with continuous redundancy and automated backups.
Payment Safety: Online card transactions and subscription charges are routed through Razorpay Software Private Limited (certified PCI-DSS Level 1 compliant). Aqua Serve does not store card numbers, CVVs, or UPI banking PINs.
5. Third-Party Disclosures & Integration
We only disclose information in the following strictly limited contexts:
- Between Connected Supplier & Customer: Delivery addresses, jar drop events, and payment receipts are shared transparently between the linked parties.
- Authorized Infrastructure Partners: Cloud hosting (Google Firebase) and payment gateway (Razorpay) under strict confidentiality agreements.
- Statutory & Legal Compliance: In the rare event required by Indian law, judicial summons, or authorized government authorities.
6. User Rights Under the DPDP Act 2023
In accordance with the Digital Personal Data Protection (DPDP) Act 2023 of India, you hold complete control over your data:
7. Data Retention & Account Deletion Policy
We retain user records only as long as necessary to maintain active delivery services. When a supplier or customer requests account deletion:
- All active login sessions are revoked immediately.
- A 30-day settlement buffer is maintained to resolve any outstanding customer dues or regulatory tax requirements.
- Following the 30-day window, all associated personal and operational records are permanently purged from active production servers.
8. Grievance Officer & Contact Information
If you have questions about this policy, suspect unauthorized access, or wish to exercise your statutory privacy rights, please reach out to our Grievance Officer: