PRIVACY POLICY — SMARTONE360 CONNECT
Effective Date: 2026-10-11
Last Updated: 2026-10-11
Version: 1.7
This Privacy Policy explains how SmartOne360 Connect collects, handles, stores, protects, and retains personal data, and outlines your statutory rights. This policy applies exclusively to SmartOne360 Connect; other products and corporate websites provided by SMARTTECH SOLUTIONS are governed by their respective privacy policies published on our corporate website.
1. Who We Are and Our Respective Roles
SMARTTECH SOLUTIONS, Coimbatore, Tamil Nadu ("SMARTTECH", "we", "us", or "our"), is the provider and operator of SmartOne360 Connect. Under applicable Indian information technology laws and the Digital Personal Data Protection Act, 2023 (DPDPA 2023):
- Business Account Data (Data Fiduciary): For personal data concerning business owners, administrators, authorized team members, and commercial billing details, SMARTTECH acts as a Data Fiduciary. We determine the purpose and means of processing this data and are directly responsible for its lawful handling.
- End-Customer Data: When processing end-customer communications on a business subscriber's documented instructions, SMARTTECH acts as a Data Processor. SMARTTECH acts as a Data Fiduciary for business account management and for processing it determines for platform security, service administration, fraud prevention, and legal compliance. The business subscriber is responsible for determining and documenting the lawful basis for its customer communications and obtaining any consent or permissions required by applicable law. Each party remains responsible for the legal obligations that apply to its role.
- Data Principals: Business users, authorized team members, and end-customers whose personal data is processed are recognized as Data Principals.
2. Categories of Personal Data We Handle
2.1 Business Account and Team Information
- What we handle: Business legal name, trade name, Goods and Services Tax Identification Number (GSTIN), GST registration verification results (registration status, state code, registered principal place of business), city, authorized account owner's full name, mobile number, login email address, role permissions, and records of accepted Terms of Service versions and timestamps.
- Purpose: To verify and onboard business accounts, authenticate user access, maintain platform security, issue tax invoices, provide customer support, and comply with statutory obligations.
2.2 Verification and Authentication Codes
- What we handle: One-time passwords (OTPs) and verification codes sent to the account owner's mobile number via WhatsApp. Plaintext verification codes are not stored permanently; only cryptographic hashes are maintained temporarily during the active authentication session.
- Purpose: To verify mobile number ownership and authenticate account logins.
- Retention: Verification codes are available only for the authentication process and are not intended for ongoing use after the verification window expires. Related records are retained only as needed for authentication, security, and troubleshooting, subject to the applicable retention controls.
2.3 Business's End-Customers and Contacts
- What we handle: Customer phone numbers (stored using AES-256 encryption at rest; a keyed HMAC-SHA256 hash is maintained strictly for database deduplication, and only the last four digits are displayed in administrative dashboards for identification), customer names assigned by the business, WhatsApp profile names supplied by Meta, and custom tags or attributes defined by the business.
- Purpose: To dispatch authorized communications, track delivery status, organize customer segments, and facilitate customer engagement.
2.4 Consent and Opt-Out Records
- What we handle: Timestamps of opt-in, opt-in source mechanism (such as verified QR code or WhatsApp message), cryptographic fingerprint (SHA-256 evidence hash) of the consent notice agreed to, linear hash-chained audit trails, and timestamped opt-out events (such as incoming "STOP" or "UNSUBSCRIBE" messages).
- Purpose: To record consent evidence and opt-out events and support suppression of promotional messaging to contacts who have opted out. Consent events use SHA-256 event hashes linked to preceding events to provide a tamper-evident audit trail.
2.5 Message Content and Transmission Data
- What we handle: WhatsApp message templates utilized, transmission timestamps, delivery receipts, read receipts, delivery error codes, and inbound customer responses alongside outbound agent replies within the shared inbox interface.
- Purpose: To execute messaging campaigns, display performance analytics, and enable customer conversation management.
2.6 Uploaded Contact Lists and Spreadsheets
- What we handle: CSV, Excel, or text files uploaded by the business containing contact numbers and metadata for batch importing.
- Purpose: To parse, validate, deduplicate, and import contacts into the business account.
- Retention: Contact files are processed for the import workflow and are removed from temporary processing locations when that workflow completes, subject to the storage and cleanup controls applicable to the import method. Files that fail validation or are abandoned are subject to the applicable cleanup process.
2.7 WhatsApp Business Connection Credentials
- What we handle: Encrypted Meta WhatsApp Cloud API access tokens, System User tokens, WhatsApp Business Account (WABA) IDs, phone number IDs, verified display names, quality ratings, and messaging tier/billing statuses retrieved from Meta.
- Purpose: To establish secure API connectivity with Meta and execute messaging operations on the business's behalf.
2.8 Payments, Invoices, and Billing Data
- What we handle: Subscription plans, payment transaction IDs, invoice generation records, tax breakdowns, wallet balances, and credit recharge transactions.
- Important Note: We do not collect, process, or store sensitive payment card details, CVVs, net banking credentials, or UPI PINs. When online payments are enabled, all transactions are processed through Payment Card Industry Data Security Standard (PCI-DSS) compliant, Reserve Bank of India (RBI) authorized payment gateways.
2.9 Technical, Diagnostic, and Log Data
- What we handle: Append-only system audit logs (action performed, actor user ID, timestamps) and cryptographic event hashes (SHA-256 event keys) of Meta webhook delivery notifications.
- Privacy Assurance: Raw webhook request payloads containing unredacted customer data are not stored in webhook event logs.
- Payment Gateway Event Records: When online payments are enabled, signed payment-gateway notifications (which may include transaction identifiers, payment status, and amount) may be retained as append-only records for auditability and to help prevent duplicate transaction processing.
2.10 Cookies and Local Storage
- What we handle: Strictly necessary session authentication tokens stored in the browser's local storage, which keep you signed in.
- Purpose: We do not deploy third-party advertising, cross-site behavioral tracking, or data-broker cookies on the SmartOne360 Connect platform.
We do not sell, rent, or trade personal data. We never use a business's customer contact details or customer message data for our own marketing or advertising.
3. Lawful Grounds and How We Use Data
We process personal data only when a lawful basis exists under applicable Indian data protection law, specifically:
- Consent: Where the Data Principal has given clear, specific, informed, and unconditional consent for the specified purpose (e.g., end-customers opting into WhatsApp updates from a business, or business owners subscribing to the service).
- Contractual Performance: To deliver core functionality of SmartOne360 Connect, manage subscriptions, process transactions, and provide technical assistance.
- Legitimate Uses & Legal Compliance: To verify GST registration, comply with applicable tax, accounting, and regulatory mandates, respond to judicial or statutory directives, detect and prevent fraud, mitigate cybersecurity threats, and enforce our service terms.
4. Third Parties and Sub-Processors
We share personal data only with trusted infrastructure providers and sub-processors bound by strict confidentiality and data protection obligations:
- Meta Platforms (WhatsApp Cloud API): Acts as the messaging network to deliver outbound WhatsApp messages, ingest incoming replies, and relay delivery webhooks. Meta's processing is governed by Meta's Commercial Terms, WhatsApp Business Terms of Service, and Meta Data Policy. Data may be routed through Meta's secure global infrastructure.
- Supabase Inc. (Database and Authentication): Provides managed PostgreSQL database hosting, authentication, and serverless compute functions. Our development and production database environments are hosted in Mumbai, India.
- Cloudflare Inc. (Network & CDN): Hosts and delivers the web application and provides network protection and SSL/TLS encryption in transit. Cloudflare may cache public web assets; it does not host the application's primary business database.
- Payment Gateway Aggregators: When online payment modules are active, authorized payment gateway partners (such as RBI-licensed, PCI-DSS Level 1 payment aggregators) process subscription and wallet transactions.
- Statutory and Verification Service Providers: For GSTIN validation, verified government portal APIs or licensed GST Suvidha Providers (GSPs) may be utilized. Pending automated provider activation, records are verified by authorized SMARTTECH personnel.
- Email Service: Account emails, such as sign-up confirmation messages, are sent through the configured transactional email service.
Legal Disclosures and Business Reorganization
We may disclose personal data if required to do so by applicable law, regulation, court order, or formal request from law enforcement agencies or regulatory authorities in India. In the event of a merger, acquisition, corporate restructuring, or transfer of business assets, personal data will continue to be governed by the protections set forth in this policy.
5. Where Data Is Stored and How It Is Protected
- Data Residency: The SmartOne360 Connect development and production database environments are hosted in Mumbai, India. Certain service providers, including Meta Platforms, may process or route information through infrastructure in other countries.
- Encryption in Transit: Connections to the application and its integrated services use HTTPS/TLS where supported by the relevant endpoint and service configuration.
- Encryption at Rest: Application-level encryption is used for stored end-customer telephone numbers and sensitive WhatsApp connection credentials, using AES-GCM with 256-bit keys. Infrastructure-level storage protections may also apply. Access to encryption keys is restricted to the components and personnel that require them for service operation.
- Multi-Tenant Isolation: SmartOne360 Connect uses tenant-scoped access controls and PostgreSQL Row-Level Security (RLS) policies to isolate business subscribers' records. Access to tenant data is subject to the applicable database policies and application authorization controls.
- Access Control: Access to systems and personal data is restricted according to assigned roles and operational needs. Administrative access is intended to follow least-privilege practices, with multi-factor authentication applied where configured for the relevant systems.
- Personal Data Breach Management: SMARTTECH maintains procedures to assess and respond to suspected personal data breaches. Where a breach occurs, SMARTTECH will make notifications required by applicable law in the applicable form, manner, and timeframe.
6. Data Retention and Erasure Schedules
We retain personal data only for the duration necessary to satisfy the specific purposes outlined in this policy, unless a longer retention period is mandated by law:
- Verification & OTP Codes: Retained only as needed for the authentication process, security, and troubleshooting. Expired and completed verification records are subject to the applicable cleanup controls.
- Temporary Upload Staging Files: Retained only for processing the contact import and removed from temporary processing locations when the relevant workflow and cleanup process complete.
- Meta Webhook Event Records: Webhook idempotency records (SHA-256 event keys) are retained for 30 days for diagnostic verification and transmission auditing, after which they are systematically purged.
- Active Business Accounts & Messaging Records: Account records, customer contacts, and message logs are retained while the account is active, subject to the purposes described in this policy and applicable law. Following account termination or closure, eligible records may be retained for up to 90 days to support authorized data export or account recovery. Records may be retained longer where required by law or for documented security, dispute-resolution, or compliance purposes. Deletion from active production systems may not immediately remove copies from backups or other systems with separate retention cycles.
- Tax, Invoicing, and Statutory Records: Retained for the period applicable to each record under relevant tax, accounting, corporate, and other laws. Different record categories may have different statutory retention periods.
- Backups and Deployment Artifacts: Deleted records may remain in backups, disaster-recovery systems, logs, or deployment artifacts until the applicable retention cycle expires. Access to these copies is restricted, and restored data remains subject to applicable access controls and deletion or suppression requirements. Retention periods may vary by system and service provider.
- Opt-Out & Suppression Handling: When an end-customer opts out by sending "STOP" or "UNSUBSCRIBE", the opt-out event is recorded in the consent ledger and used to suppress applicable promotional messaging. The opt-out status is applied through the contact and campaign workflows supported by the service. Promotional messaging should not resume unless the contact's eligibility has been validly restored in accordance with applicable requirements.
7. Rights of Data Principals
Under the Digital Personal Data Protection Act, 2023 and applicable Indian regulations, Data Principals enjoy statutory rights, exercisable in accordance with rules notified by the Central Government:
- Right to Access Information: You have the right to request a summary of the personal data held about you, the processing activities carried out, and the identities of other Data Fiduciaries and Processors with whom the data has been shared.
- Right to Correction and Erasure: You have the right to request correction of inaccurate or misleading data, completion of incomplete data, updating of outdated data, and erasure of personal data that is no longer necessary for the purpose for which it was processed.
- Withdrawal of Consent: Where processing is based on consent, a Data Principal may withdraw consent in accordance with applicable law. The process for withdrawal will be made accessible, subject to the applicable requirements. Withdrawal does not retrospectively affect the lawfulness of processing undertaken before withdrawal. Certain records may still be retained where required by law or where another lawful ground applies.
- Right of Grievance Redressal: You have the right to accessible and prompt grievance redressal through our designated Grievance Officer.
- Right to Nominate: In accordance with Section 14 of the DPDPA 2023, a Data Principal has the right to nominate an individual who shall, in the event of death or incapacity of the Data Principal, exercise the rights of the Data Principal, subject to procedures prescribed under the Act.
- Right to Approach Regulatory Authorities: If a grievance is not resolved to your satisfaction through our internal grievance redressal mechanism, or if you believe there has been a statutory violation of your data rights, you have the right to register a complaint with the Data Protection Board of India (DPBI) once its complaint filing procedures are operationalized.
How to Exercise Your Rights:
- For End-Customers of a Business Subscriber: Because the business subscriber is the primary Data Fiduciary determining how your data is used, please submit your request (for access, correction, or erasure) directly to that business. If you contact SMARTTECH directly, we will coordinate with and notify the respective business subscriber to fulfill your request.
- To Opt Out of WhatsApp Messages: Reply with STOP or UNSUBSCRIBE to a promotional WhatsApp message you receive. The opt-out request is recorded in the consent ledger and used to suppress applicable automated promotional messaging.
- For Business Account Users: Submit your written request to our Grievance Officer at the contact details provided below.
7.1 Data Connected to Meta Sign-Up
When a business owner or authorized team member connects a WhatsApp account through Meta's sign-up flow, SmartOne360 Connect receives account and WhatsApp identifiers needed to connect the selected business WhatsApp account, along with access credentials used to provide the service. Sensitive WhatsApp connection credentials are stored using application-level encryption.
To request deletion of personal data associated with your Meta sign-up or connected WhatsApp account, email the Grievance Officer listed in Section 11 with the subject "Data deletion request". Include the business name and, where possible, the email address used with SmartOne360 Connect and enough information to identify the connection. Do not send passwords, access tokens, or other secret credentials in your request.
We will review the request, verify that you are authorized to make it, and explain any information needed to complete it. Where deletion is appropriate, we will remove or disconnect the relevant account credentials and identifiers from active service records, subject to technical feasibility and applicable legal obligations. Business-owned messages, contacts, consent records, invoices, and payment records may be subject to the retention and deletion rules described in Section 6. Copies in backups may remain until their applicable retention cycle expires. You may also remove the app from your Facebook settings; however, this policy does not promise that such removal automatically triggers deletion in SmartOne360 Connect.
8. Children and Minors
SmartOne360 Connect is a business-to-business (B2B) communications application and is not intended for, marketed to, or directed at children (defined under the DPDPA 2023 as an individual who has not completed 18 years of age).
Business subscribers are strictly prohibited from using SmartOne360 Connect to collect or process the personal data of children, or undertaking tracking, behavioral monitoring, or targeted advertising directed at children. If you become aware that personal data of a child has been processed without verifiable parental or guardian consent, please contact our Grievance Officer immediately so that prompt corrective action can be taken.
9. Cross-Border Data Transfers
The development and production database environments are hosted in India. Certain service providers, including Meta Platforms, may process or route data through infrastructure in other countries. Any international transfer is handled in accordance with applicable Indian law and the terms governing the relevant service providers. The exact locations and safeguards may differ by provider and service.
10. Updates to This Privacy Policy
We may update this Privacy Policy periodically to reflect changes in our operational practices, technological enhancements, or statutory requirements. When modifications are made:
- We will update the "Last Updated" date at the top of this document.
- In the case of material changes, we will provide prominent notice to business account owners via the SmartOne360 Connect dashboard, email notification, or WhatsApp communication prior to the change taking effect.
- Continued use of SmartOne360 Connect after the updated policy becomes effective constitutes acknowledgment of the revised terms.
11. Grievance Redressal and Contact Information
For privacy and data protection inquiries, SMARTTECH has designated the following contact as its Grievance Officer.
- Grievance Officer: SELVARAJ
- Company Name: SMARTTECH SOLUTIONS
- Registered Address: 2/40, Murugan Kovil Street, New Palathurai Village, Madukkarai, Coimbatore, Tamil Nadu 641105, India
- GSTIN: 33JJFPS4758N1ZB
- Email: info@smarttechsolutionscbe.in
- Telephone / WhatsApp: +91 6379461815
- Redressal Timelines: We aim to acknowledge grievances as promptly as practicable and make reasonable efforts to resolve them within thirty (30) days, or within any different mandatory timeline prescribed by applicable law.