1. Overview
Stayvora Technologies ("Stayvora", "we", "us") operates a multi-tenant software platform used by Digital Seva Kendra, CSC, Grama One, and Cyber Center operators ("Centers") across India to manage service applications, customer queues, billing, and document workflows. This policy explains what information we collect through the platform at digital.stayvoratech.com, how it's used, and the choices available to Centers and their customers.
Each Center is the data controller for the customer information it collects through the platform (its own customers' applications, documents, and payments). Stayvora acts as the data processor providing the software those Centers use.
2. Information We Collect
Depending on how the platform is used, we may collect:
- Account information: name, mobile number, email, and login credentials for Center staff and Super Admin accounts.
- Customer application data: information Center customers submit for government service applications (e.g. Aadhaar enrolment/update, PAN, Passport, GST, Income Tax filings) — this may include names, dates of birth, addresses, and government ID numbers, entered by the customer or Center operator and used solely to process the requested service.
- Documents: identity/address proof and other documents uploaded for a service application.
- Payment information: transaction records for service fees processed via Razorpay or PhonePe; we do not store full card or UPI credentials — these are handled directly by our payment gateway partners.
- Communication data: messages sent and received via WhatsApp Business messaging, SMS, or email for OTPs, application status updates, and notifications.
- Usage data: log data such as IP address, browser type, and pages visited, used for security and platform reliability.
3. How We Use Information
Information collected through the platform is used to:
- Operate and maintain the Center management platform (applications, queue tokens, billing, printing, reports).
- Verify identity and process the government service applications a customer has requested.
- Send OTPs, application status updates, payment receipts, and service notifications via WhatsApp, SMS, or email.
- Provide customer support and respond to inquiries.
- Maintain security, detect fraud, and comply with applicable law.
- Improve platform features and reliability.
4. How We Share Information
We do not sell personal information. Information may be shared with:
- The Center a customer applied through — who needs the submitted details to process the service.
- Payment processors (Razorpay, PhonePe) to complete transactions.
- Communication providers (Meta/WhatsApp Business Platform, SMS gateways, email providers) solely to deliver the messages a Center or the platform sends.
- Government service portals, where a service application genuinely requires submission to a government authority (e.g. UIDAI for Aadhaar), as part of fulfilling that service.
- Law enforcement or regulators, only where required by applicable law.
5. WhatsApp Business Messaging
Centers on our platform may connect their own WhatsApp Business Account (via Meta's WhatsApp Business Platform) to send customers OTPs, application status updates, and payment receipts. When a Center connects their WhatsApp number:
- Messages are sent using Meta's WhatsApp Business Cloud API, subject to WhatsApp's own Business Messaging Policy.
- We store the phone number ID, WhatsApp Business Account ID, and an access token needed to send messages on the Center's behalf — the access token is encrypted at rest.
- Message content and delivery status are logged to support delivery troubleshooting and are visible only to that Center's authorized staff.
- A Center may disconnect their WhatsApp number at any time from their account settings, which revokes our platform's access.
6. Data Retention
We retain application, payment, and communication records for as long as a Center's account remains active, and thereafter for the period required to meet legal, tax, and regulatory obligations. Centers may request deletion of specific customer records, subject to any retention required by applicable law (e.g. financial record-keeping requirements).
7. Security
We use industry-standard measures to protect information, including encrypted storage of sensitive credentials (such as payment gateway keys and messaging access tokens), access controls scoped to each Center's own data, and secure transmission (HTTPS) across the platform. No method of storage or transmission is 100% secure, and we continuously work to improve our safeguards.
8. Your Rights
Depending on your relationship to the platform:
- Center customers should contact the Center they applied through to access, correct, or request deletion of their submitted information.
- Center staff/owners can access and manage their account information directly within the platform, or by contacting support below.
Questions about this Privacy Policy or how your information is handled can be sent to:
Email: support@stayvoratech.com