Privacy Policy
If you are a customer using the Serckl consumer app, a separate Privacy Policy applies at serckl.com/privacy.
1. Who we are
Serckl Business is operated by Aurtrio LLP (LLPIN: ACZ-3570) ("we", "us", "our"). We are responsible for the personal data processed through the merchant app and the business.serckl.com surfaces.
| Legal name | Aurtrio LLP (LLPIN: ACZ-3570) |
| Registered address | 64/A Tharayil Kuttikkavil House, Choppankkavu, Kadalundi Nagaram, Malappuram 673314, Kerala |
| Data queries | [email protected] |
| Grievance Officer | Lidhish C |
| Grievance Officer email | [email protected] |
| Grievance SLA | 48 hours (acknowledgement); 30 days (resolution) |
2. Scope
This policy explains the personal data we collect from you as a business owner, authorised representative or employee of a merchant registered on Serckl. It applies to:
- the Serckl Business mobile app (Android and iOS),
- the merchant web surfaces on business.serckl.com,
- support interactions via [email protected] or the in-app Help Centre.
This policy does not cover personal data of end customers using the Serckl consumer app, or data you handle about your own customers offline — you are solely responsible for that data.
3. What personal data we collect
We only collect data we need to run the service. We do not collect your contacts, call logs, SMS, browsing history, health data or biometric data.
3.1 Given by you during signup and onboarding
| Category | Examples | Where captured |
|---|---|---|
| Phone number | Indian mobile (+91), used for Firebase phone-OTP authentication | Phone entry screen |
| Business identity | Business name, email, category, GSTIN (optional) | Basic business info screen |
| Branch details | Branch name, address, geo-coordinates, opening hours, delivery range, WhatsApp contact | Branch location + operations screens |
| Verification media | Photos of premises, business licence / GST document uploads | Verification screen |
| Employee accounts | Name, role, phone number (added by the business owner) | Employee management |
3.2 Collected automatically
| Category | Examples | Purpose |
|---|---|---|
| Device data | OS, model, app version, language, timezone | Support, compatibility |
| Authentication tokens | Firebase ID token, refresh token, session cookies | Keeping you signed in |
| Diagnostic data | Non-personal error traces (only if you opt in via Settings → Privacy) | Fixing crashes and bugs |
| Approximate location | One-shot capture during branch setup and location-tied features | Setting the branch pin |
3.3 Generated as you use the service
| Category | Examples | Purpose |
|---|---|---|
| Deal and event content | Deal name, discount, images, schedule, terms | Publishing to consumers |
| Claim and redemption records | Order codes, claim status timeline, actor uid per state change | Fulfilment tracking, dispute resolution |
| Support correspondence | Messages you send to us | Answering your questions |
4. Why we process your data
We process your data only for specific purposes and on one of the following grounds:
| Activity | Lawful basis |
|---|---|
| Creating and running your merchant account | Necessary to perform our contract with you |
| Publishing your deals, events and branch information to customers | Consent (given during onboarding) |
| Verifying your business (licence, GST, premises photos) | Necessary to perform our contract; fraud prevention |
| Recording claim/redemption events and actor uid | Necessary to perform our contract; dispute resolution |
| Sending transactional notifications | Necessary to perform our contract |
| Sending product updates or marketing offers | Consent — separate opt-in in Settings, off by default |
| Diagnostics / crash reporting | Consent — separate opt-in in Settings, off by default |
| Tax and invoicing records | Legal obligation (Goods and Services Tax Act, 2017) |
| Responding to government or court orders | Legal obligation |
We do not sell your data or use it for purposes beyond what is described here.
4.1 How we obtain and record consent
Where consent is the lawful basis, we obtain it through a clear affirmative action — a checkbox or an explicit tap — before that processing begins. Pre-ticked boxes are never used. Consent is granular: we ask separately for each distinct purpose (publishing your listing publicly, sending marketing communications, enabling diagnostics and analytics). We log the timestamp, the version of this policy in force at that moment, and the specific action taken. That record can be produced on request.
You may withdraw any consent at any time from Settings → Privacy. Withdrawal stops the relevant processing going forward but does not affect the lawfulness of processing already carried out. Withdrawing consent for a purpose that is strictly necessary to run a core feature (for example, consent to publish your listing) may mean you can no longer use that feature.
5. Third parties that process data on our behalf
We share personal data only with the following processors, each bound by a Data Processing Agreement:
| Processor | What they process | Where they process |
|---|---|---|
| Google Firebase | Phone OTP, session tokens, uploaded media | Google Cloud infrastructure, may include regions outside India |
| Google Maps / Places | Geocoding of branch address | Google Cloud infrastructure |
| Payment gateway | Payout details, transaction records | Servers in India [processor name to be inserted before payments go live] |
| Diagnostics provider | Crash traces and device metadata (only if you opt in) | To be named before diagnostics is enabled |
| Analytics provider | Aggregated usage events (only if you opt in) | To be named before analytics is enabled |
We do not sell your personal data to any third party. We do not share your data with advertising networks.
6. Cross-border data transfers
Some of the processors above operate infrastructure outside India. We work only with globally recognised providers who maintain strong data protection standards, and we do not transfer your data to countries with inadequate data protection.
7. Your choices in the app
The Settings → Privacy area of the app lets you:
- View and revoke each consent you have given.
- Turn transactional notifications, product updates and marketing offers on or off independently.
- Turn diagnostics and analytics on or off.
- Request a copy of your data.
- Delete your account.
Withdrawing a consent stops that particular processing going forward. Processing done before withdrawal remains lawful. Withdrawing consent that is strictly necessary to run the service may mean you can no longer use the affected feature.
8. How long we keep your data
| Data | Retention |
|---|---|
| Account profile (business, branch, employee) | While account is active, plus 90 days after deletion |
| Deal and event content | While account is active, plus 90 days after deletion |
| Claim and redemption records | 90 days after terminal state, then archived for the tax retention period |
| Billing, invoicing and payout records | 7 years (GST Act, 2017) |
| Verification documents | Duration of account plus 90 days after deletion |
| Support correspondence | 3 years from last message |
| Diagnostic and crash traces | 30 days |
| Analytics events | 14 months maximum |
| Consent records (timestamps, versions, actions) | 3 years from withdrawal or account deletion |
After the retention period ends we delete or anonymise the data, unless a longer period is required by law.
9. Your rights
You have the following rights over your personal data. Exercise any of them in-app or by writing to [email protected]. We will respond within 48 hours and complete the request within 30 days.
Right to access
Request a summary of the personal data we hold about you and the processing we carry out. Use Settings → Privacy → Download my data or email us.
Right to correction and erasure
Correct inaccurate data or ask us to erase data we no longer need. Most fields are directly editable in Settings; for erasure use Settings → Privacy → Delete my account or email us. Some data may be retained where the law requires it (for example GST records for 7 years). When you delete your account: all branches, deals and events are removed; any claim a customer had already made must be honoured by you directly; Serckl will share affected customers' contact details with you before full removal; you remain responsible for any refund or compensation owed.
Right to grievance redressal
Raise a complaint with our Grievance Officer at [email protected]. We will acknowledge within 24 hours and resolve within 15 days.
Right to nominate
Nominate a person to exercise your rights in case of death or incapacity. Email [email protected] with the nominee's name and contact.
Exercising any of these rights will not, on its own, cause us to discriminate against you or degrade the service, except where the data is strictly necessary for the service to work.
10. Children
Serckl Business is intended for users aged 18 or above. Merchant accounts may only be registered by an adult authorised to act for the business. We do not knowingly process personal data of anyone under 18. We do not use children's data for behavioural tracking or targeted advertising. If we learn a child has provided personal data through the app, we will delete it promptly. Please contact [email protected] if you believe this has happened.
11. Security
We apply technical and organisational safeguards appropriate to the sensitivity of the data:
- TLS 1.2+ for all data in transit between the app and our servers.
- Firebase security rules and per-branch access controls on the backend.
- Authentication tokens kept in the iOS Keychain / Android Keystore; other local state stored in MMKV with device-level encryption.
- Employee access to production data limited to the minimum number of people needed and is logged.
No system is completely secure. If we detect a personal data breach, we will notify affected users promptly by in-app notification and/or email and take immediate steps to contain and investigate the incident.
11A. Our data protection obligations
We commit to the following data protection principles:
- Purpose limitation. We will not use your personal data for any purpose incompatible with the one for which it was collected, without obtaining fresh consent from you.
- Data minimisation. We collect only what is necessary. We do not access your contacts, call logs, SMS messages, browsing history, health data or biometrics.
- Accuracy. We take reasonable steps to keep personal data accurate and up to date. You can correct your information at any time in Settings.
- Security. We apply the technical and organisational safeguards described in Section 11.
- Data breach notification. If a personal data breach occurs, we will inform affected users promptly by in-app notification and/or email and take immediate steps to contain the incident.
- Policy updates. If our data processing practices change materially, we will update this policy and notify you before the changes take effect.
12. Changes to this policy
We may update this policy from time to time. When we make a material change we will update the "Effective date" and "Version" above, show an in-app notice the next time you open the app, and ask you to re-accept before continuing to use features affected by the change. Non-material changes (typos, clarifications) will be posted here without a notice.
13. Contact
- Data queries and rights requests: [email protected]
- Grievance Officer: Lidhish C, [email protected]
- Postal address: 64/A Tharayil Kuttikkavil House, Choppankkavu, Kadalundi Nagaram, Malappuram 673314, Kerala