Your Privacy Matters to Us
We are committed to protecting your personal information and being transparent about how we use it.
Last updated: March 2026 · Version 1.1
Summary: iSmartSociety collects only the information necessary to operate our society management platform. We never sell your data. Your data is encrypted, secured, and governed by strict role-based access. You can request deletion or export of your data at any time.
1. Information We Collect
We collect information you provide directly to us and information generated through your use of the iSmartSociety platform.
Information you provide:
Identity information: Full name, email address, mobile number, and profile photo.
Society information: Society name, address, flat/unit number, and resident type (owner/tenant).
Communications: Messages, notices, complaints, and other content you post on the platform.
Financial information: Bill payment status records (we do not store payment card details).
Information collected automatically:
Device information: Device type, operating system, and app version.
Usage data: Features accessed, screens viewed, and session duration.
Location data: Approximate location used for society discovery during registration (with your permission).
Log data: IP address, browser type, and access timestamps for security monitoring.
2. How We Use Your Information
We use the information we collect for the following purposes:
Platform operation: To provide, maintain, and improve iSmartSociety services, including sending OTP verification and enabling member authentication.
Society management: To enable billing, visitor logs, notices, complaint tracking, and communication features within your society.
Communications: To send push notifications, service updates, and support communications. You can manage notification preferences in-app.
Security: To detect, prevent, and investigate fraud, abuse, and security incidents.
Legal compliance: To comply with applicable laws, regulations, and legal processes.
Analytics: To understand how our platform is used and improve features — using aggregated, anonymised data only.
3. Information Sharing
We do not sell, rent, or trade your personal information. We may share your information in limited circumstances:
Within your society: Member information (name, flat number, contact) is visible to other members and admins within your society as per your role and permissions.
Service providers: We work with trusted third-party service providers for cloud hosting (AWS), SMS delivery, push notifications (Firebase), and analytics. These providers process data only as instructed by us.
Legal requirements: We may disclose information if required by law, court order, or to protect the rights and safety of iSmartSociety, our users, or the public.
Business transfers: In the event of a merger or acquisition, your information may be transferred as part of that transaction, with appropriate privacy protections maintained.
4. Data Security
We implement industry-standard security measures to protect your personal information:
All data transmissions are encrypted using HTTPS/TLS 1.2 or higher.
Sensitive data (phone numbers, email addresses) is encrypted at rest.
Authentication is secured via OTP with 5-minute expiry and 3-attempt lockout.
JWT tokens with expiration and refresh mechanisms manage session security.
Access to your data is governed by role-based access control (RBAC) at every API endpoint.
Automated daily backups with 30-day retention protect against data loss.
No security system is impenetrable. If you believe your account has been compromised, please contact us immediately at security@ismartsociety.in.
6. Your Rights
Depending on your location and applicable law, you may have the following rights regarding your personal data:
Access: Request a copy of the personal data we hold about you.
Correction: Request correction of inaccurate or incomplete data.
Deletion: Request deletion of your personal data, subject to legal obligations.
Portability: Request your data in a machine-readable format.
Objection: Object to processing of your data for specific purposes.
Withdrawal of consent: Withdraw consent for processing where consent is the legal basis.
To exercise these rights, contact us at privacy@ismartsociety.in. We will respond within 30 days. We may need to verify your identity before processing your request.
7. Data Retention
We retain personal data for as long as your account is active or as needed to provide services. Specifically:
Active user data is retained for the duration of your society's subscription.
After account deactivation, data is retained for 90 days before permanent deletion, allowing reactivation.
Financial records and billing history are retained for 7 years to comply with Indian accounting regulations.
All deleted records use soft-delete (flagged, not physically removed) to maintain audit integrity, before permanent deletion per our retention schedule.
8. Children's Privacy
iSmartSociety is not directed to children under the age of 18. We do not knowingly collect personal information from minors. If you believe we have collected information from a child, please contact us at privacy@ismartsociety.in and we will promptly delete such information.
9. Changes to This Policy
We may update this Privacy Policy periodically to reflect changes in our practices, technology, or applicable law. We will notify you of significant changes via:
In-app notification or push notification
Email to your registered address
Prominent notice on our website
Your continued use of iSmartSociety after the effective date of changes constitutes your acceptance of the updated Privacy Policy.
10. Contact Us
If you have questions, concerns, or requests related to this Privacy Policy or our data practices, please contact our Privacy Team:
**Email:** privacy@ismartsociety.in
**Phone:** +91 99990 00000
**Address:** iSmartSociety, Ahmedabad, Gujarat, India — 380015
For security-related concerns, please email security@ismartsociety.in directly.
Also see: Terms of Service · Contact Us