This Privacy Policy explains how FinoHomes ("we", "us", "our"), the operator of the FinoHomes application and related services (the "Service"), collects, uses, stores, shares, and protects your personal data. We are committed to handling your information in accordance with the Digital Personal Data Protection Act, 2023 (the "DPDP Act"), the Information Technology Act, 2000, and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 ("SPDI Rules").
By creating an account and using the Service, you acknowledge that you have read and understood this Policy. Where the law requires consent, we collect it separately and you may withdraw it at any time (see "Your Rights").
For personal data we determine the purpose and means of processing, FinoHomes is the Data Fiduciary. You can reach us, or our Grievance Officer, using the contact details at the end of this Policy.
Important: FinoHomes is a business tool used by property owners and managers (our "Business Users") to run their rental operations. When a Business User records guest or staff information in the app, that Business User is the Data Fiduciary for that information and we act as a Data Processor on their behalf. See "Data you enter about other people".
We collect the following categories of personal data:
We use Google Firebase Analytics to understand how the app is used (for example, which screens are opened) and Google Firebase Crashlytics to diagnose crashes and errors. We do NOT use third-party advertising SDKs, we do not build advertising profiles, and we do not sell your data.
We process your personal data on the basis of your consent, obtained at sign-up, and for the legitimate purpose of providing a service you have requested. Consent we rely on is free, specific, informed, unconditional, and unambiguous. We record the version of this Policy you accepted and the date you accepted it. You can withdraw your consent as easily as you gave it, directly from the Profile screen. Because we provide the Service on the basis of your consent, withdrawing it will close your account and delete your personal data; withdrawal does not affect processing carried out before withdrawal.
Guest identity documents are sensitive information under the SPDI Rules. They are collected only when a Business User chooses to record them for guest verification, are visible only to authorised members of that organisation, and are transmitted over encrypted connections (HTTPS/TLS) and stored with our storage provider (Cloudflare R2).
If you upload identity documents you must have a lawful reason and the guest's consent to do so, and you should collect only what is necessary. Do not upload identity documents where the law does not permit it.
The Service lets you record data about guests and staff. When you do this, you are the Data Fiduciary for that data and are responsible for having a valid legal basis and any required consent from those individuals, for collecting only what is necessary, and for responding to their requests. We process such data only to provide the Service to you and on your instructions.
We do not sell your personal data. We share it only as needed to run the Service, with the following categories of processors and recipients:
Our infrastructure providers (Google, Cloudflare, Vercel) may process and store data on servers located outside India. Where data is transferred internationally, we rely on providers that offer appropriate security safeguards and contractual protections, consistent with applicable Indian law.
We keep personal data only for as long as it is needed for the purpose it was collected, after which it is deleted or de-identified. Indicative retention periods are:
You can delete individual records and uploaded files within the app at any time. When you delete your account, we delete or de-identify the personal data associated with it, except where retention is required by law or for legitimate business records (such as an organisation's financial history that other members rely on).
We implement reasonable security practices proportionate to the sensitivity of the data, including:
No method of transmission or storage is completely secure, but we work to protect your data and to address any incident promptly.
Subject to applicable law, you have the right to:
Several of these rights are built into the app. From the Profile screen you can update your name, download a copy of your personal data ("Download my data"), withdraw your consent, and delete your account. For any other request, contact our Grievance Officer (details below).
The Service is intended for business use by adults and is not directed to children. You must be at least 18 years old to create an account, and you confirm this when you sign up. We do not knowingly collect the personal data of children or undertake tracking, behavioural monitoring, or targeted advertising directed at children. If you believe a child's data has been provided to us, contact us so we can remove it.
In the event of a personal-data breach that is likely to affect you, we will take prompt remedial action and notify affected users and the Data Protection Board of India (and any other authority) in the manner and within the timelines required by the DPDP Act and other applicable law.
We may update this Policy from time to time. When we make material changes, we will update the effective date and, where appropriate, notify you in the app. Continued use of the Service after changes take effect constitutes acceptance of the updated Policy.
In accordance with the DPDP Act and the Information Technology Act, 2000 and rules thereunder, the contact details of our Grievance Officer are:
We will acknowledge grievances within 72 hours and endeavour to resolve them within a reasonable period, and in any case within the timelines required by applicable law.