Privacy Policy

Last updated: 3 June 2026 · Effective: 3 June 2026

1. Who we are

This Privacy Policy applies to GizmoFox, an online repair booking platform operated by Tejas Communication (GSTIN: 09AWYPY1058Q1Z3), located at 298, Kalyanpur Kala, Purana Shivali Road, Near Shatrughan Singh Balika Inter College, Kalyanpur, Kanpur – 208017, UP.

When this policy says "we", "us", or "our", it means Tejas Communication. When it says "you", it means the person using this website or booking a repair.

Questions about this policy? Email us at info[at]gizmofox[dot]in or call +91 70818 83344.

2. What personal information we collect

We only collect what is necessary to provide the repair service.

Information you give us when booking

  • Your name — to address you and for the technician to identify your device.
  • Your WhatsApp number — to send booking confirmation, repair status updates, and payment receipts.
  • Your pickup address(Pick & Drop bookings only) — to send our driver to the correct location.
  • Device details (type, brand, model) and problem description — so the technician can prepare for the repair.
  • Discount code (if used) — to apply the correct discount at checkout.

Location information (optional)

If you tap "Use my current location" on the booking form, your device sends us your GPS coordinates. We use this only to:

  • Check whether you are within our 5km service area.
  • Auto-fill your pickup address from the coordinates.

Location access is entirely optional. You can type your address instead. We do not track your location at any other time.

Usage analytics (no personal data)

We use PostHog (EU-hosted, GDPR-compliant) to understand how people use our website — which pages they visit, where they drop off in the booking form, and which features are most used. PostHog does not store your name, phone number, or any information that could identify you personally. Analytics can be blocked with a standard browser content blocker.

Information we do not collect

  • We do not collect payment card details. All payments are cash or UPI — we never see card numbers.
  • We do not access your device contents, photos, or files during or after repair.

Device unlock credential (optional — repairs only)

For certain repairs (such as screen replacement, water damage, and battery replacement), our technician must boot and test your device after the repair is complete. If you choose to share your device unlock credential (PIN, swipe pattern, or password), we collect it solely for this purpose.

Sharing this is entirely optional. If you prefer not to, you can share it directly with the technician. See Section 2a below for full details of how it is stored and deleted.

2a. Device unlock credential — Data Processing Notice

This section is a specific data processing notice under the Digital Personal Data Protection Act, 2023 (DPDP Act), Section 6 (Consent) and Section 8 (Obligations of Data Fiduciary).

Data Fiduciary: Tejas Communication, 298, Kalyanpur Kala, Purana Shivali Road, Near Shatrughan Singh Balika Inter College, Kalyanpur, Kanpur – 208017, UP. GSTIN: 09AWYPY1058Q1Z3.

What we collect

Your device unlock credential — PIN, swipe pattern, or password — when you voluntarily share it during booking for a repair that requires device access.

Why we collect it

Solely to test your device after the repair is complete and confirm it is working correctly before returning it to you. It is used for no other purpose.

How it is stored

Your credential is encrypted using AES-256-GCM encryption the moment it is submitted. The encryption key is stored separately and never alongside your data. It cannot be read by our driver, our delivery system, or any automated process.

Who can access it

Only the authorised repair technician at our workshop. Every instance of access is logged with the date, time, and identity of the person who viewed it. Your driver never sees it. It is never sent via WhatsApp, SMS, or email.

How long we keep it

Your credential is permanently and automatically deleted the moment your device is marked as delivered in our system. This deletion is enforced at the database level — it cannot be overridden. You will be notified of this deletion via WhatsApp and on your repair tracking page.

The record that you gave consent (date and time only — not the credential itself) is retained as required by the DPDP Act 2023 to prove that processing was lawful.

What we will never do with it

  • Share it with any third party
  • Send it via WhatsApp, SMS, or email
  • Use it for profiling, analytics, or marketing
  • Retain it beyond the completion of your repair

Your rights as a Data Principal (DPDP Act 2023, §12–14)

  • Withdraw consent — call or WhatsApp us at +91 70818 83344 before your repair begins. We will delete the credential immediately.
  • Access — request confirmation of what data we hold about you.
  • Erasure — request deletion of your data (subject to legal retention obligations).
  • Grievance — raise a concern at info[at]gizmofox[dot]in or +91 70818 83344. We will respond within 72 hours.

3. How we use your information

How we use your information and the legal basis for each purpose
PurposeLegal basis (DPDP Act 2023)
Send booking confirmation and repair updates via WhatsAppConsent (you provide your number for this purpose)
Send our driver to your address (Pick & Drop only)Contract performance
Generate GST invoice (legally required)Legal obligation
Resolve disputes about device condition at handoffLegitimate interest
Improve our service via anonymous analyticsLegitimate interest (no personal data)

We never sell your personal information to anyone. We never use it for advertising or share it with marketing companies.

4. Who can see your information

  • Our technicians — see your name, device details, and problem description to complete the repair.
  • Our driver(Pick & Drop only) — sees your name and pickup address for the job.
  • Meta (WhatsApp) — we send messages through the WhatsApp Business API. Meta processes your phone number to deliver messages. See WhatsApp's Privacy Policy(opens in new tab).
  • Supabase — our database provider (EU region). Stores your booking data securely. Supabase Privacy Policy(opens in new tab).

No other third party receives your personal information. We do not use Google Analytics, Facebook Pixel, or any advertising trackers.

5. How long we keep your information

How long we keep each type of personal data and why
DataRetention periodWhy
Booking and repair details7 yearsGST record-keeping requirement (Income Tax Act)
WhatsApp messages sent2 yearsDispute resolution and warranty queries
Location coordinatesDeleted after job completionOnly needed for delivery
Anonymous analytics events1 year (PostHog default)Product improvement

6. Your rights under the DPDP Act 2023

Under India's Digital Personal Data Protection Act 2023, you have the right to:

  • Access — request a copy of the personal data we hold about you.
  • Correct — ask us to fix inaccurate information.
  • Erase — ask us to delete your data, subject to legal retention requirements (e.g. GST records).
  • Withdraw consent — stop receiving WhatsApp messages from us at any time by replying STOP.
  • Grievance — raise a complaint with our grievance officer (contact details below).

To exercise any right, email info[at]gizmofox[dot]in with the subject line "Data Request — [your name]". We will respond within 30 days.

7. Grievance officer

As required by Rule 5(9) of the IT (Reasonable Security Practices) Rules 2011:

Grievance Officer: Sohit Yadav

Organisation: Tejas Communication

Address: 298, Kalyanpur Kala, Purana Shivali Road, Near Shatrughan Singh Balika Inter College, Kalyanpur, Kanpur – 208017, UP

Email: info[at]gizmofox[dot]in

Phone: +91 70818 83344

Response time: Within 30 days of receipt

8. How we protect your information

  • All data is transmitted over HTTPS (TLS 1.2+).
  • Database access is protected by row-level security — our technicians can only see jobs assigned to them.
  • We do not store payment card numbers. UPI transactions go directly through your payment app.
  • API keys and service credentials are stored as server-side environment variables — never in client-side code.

9. Cookies and local storage

We use minimal browser storage:

  • Session cookie — if you log in with your phone number, we store a session token to keep you signed in.
  • PostHog cookie — a random anonymous ID to count unique visitors (no personal data).

We do not use advertising cookies or third-party tracking pixels.

10. Changes to this policy

We may update this policy when our practices change. We will update the "Last updated" date at the top. For significant changes that affect your rights, we will send a notification via WhatsApp if you are an existing customer.

Continued use of the service after changes constitutes acceptance of the updated policy.

11. Contact us

If you have any questions about this Privacy Policy or how we handle your data: