Privacy Policy
Compliance Desk · DPDP Act 2023
1Scope & Acceptance
PHS Cleaning Company ('PHS', 'Firm', 'we', 'our', or 'us') values your privacy. This Privacy Policy details the types of personal data we collect, process, store, and share when you access our website, mobile application, or book our doorstep services. By registering, creating a profile, completing payments, or booking a service, you explicitly consent to the data collection and processing activities detailed in this policy.
2Data Fiduciary Information
PHS Cleaning Company is a Sole Proprietorship organized under the laws of India, acting as the Data Fiduciary under the Digital Personal Data Protection (DPDP) Act, 2023.
- Sole Proprietor & Data Representative: Pavan Kumar
- Registered Business Address: C1-40, Gulmohar Vihar, Near Shivaji Pulia, Naubasta, Kanpur, Uttar Pradesh - 208014, India
- Grievance Inbox: phscustomercare15@gmail.com
- Helpline Phone: +91 7408702019
3Direct Service Data Flow
We directly manage service delivery. We do not transfer your personal information to third-party marketplaces for bidding. All data flows securely from the customer booking portal to our internal operations desk, which then shares strictly necessary operational details (name, phone, address, slot) with the assigned service professional to facilitate doorstep service fulfillment.
4Categories of Data Collected
We collect personal data that is essential for service delivery, secure payments, and account administration:
A. Personally Identifiable Information (PII)
- Full Name
- Contact Mobile Number
- Active Email Address
- Complete Service Address (including Landmarks and Pincodes)
B. Service & Transaction Data
- Booked service categories and pricing
- Historical scheduling records
- Payment status (Success/Failure/Pending)
- UPI or bank transaction references
- Internal booking logs
C. Device & Technical Identifiers
- IP Address
- Device make and model
- Browser type
- Access timestamps
- App crash reports and analytics logs
We do not collect or store sensitive credit/debit card credentials, Net Banking PINs, or CVV codes. All payments are processed through secure, RBI-authorized third-party payment gateways.
5Purpose of Data Processing
We process your personal data under the lawful grounds of consent and legitimate business interests:
Operational Fulfillment
- Creating your account profile
- Verifying service eligibility in your pincode
- Scheduling and assigning service professionals
- Fulfilling quality re-cleans
Communications & Alerts
- Dispatching automated booking confirmations
- Sending OTPs for login and verification
- Communicating technician arrival times
- Issuing service feedback requests
Platform Security & Compliance
- Detecting and preventing fraudulent bookings
- Enforcing Terms & Conditions
- Complying with statutory tax mandates
- Responding to legal orders from law enforcement
6Security of Payment Operations
All checkout transactions are encrypted using Industry-standard SSL technology. In compliance with PCI-DSS standards and RBI guidelines, we do not store your complete payment card details or net banking credentials. Third-party processors collect, verify, and complete transactions, governed by their respective privacy terms and compliance certificates.
7Role-Based Access Control (RBAC)
To guarantee data isolation, the database schema implements Row Level Security (RLS) policies based on user roles:
Customer Access Boundary
- Customers can read and write only their own profiles, transaction entries, saved addresses, and outbound referrals.
Professional Access Boundary
- Service professionals can access only operational data (e.g. customer name, phone, address, and scheduled slot) assigned specifically to them by the admin.
Administrator Access Boundary
- Administrators retain operational access to configure settings, verify user records, audit bookings, and resolve support requests.
We enforce strict database query constraints to prevent unauthorized cross-role data exposure.
8Information Sharing & Disclosures
We do not trade, sell, or rent your personal information. Your data is disclosed only under the following operational guidelines:
With Service Professionals
- Shared strictly to enable physical access and complete doorstep cleaning or repair tasks.
With Technical Service Providers
- Shared with cloud database hosts (Supabase), SMS/OTP gateways (Twilio), push notification services, and payment gateways to run platform services.
Legal Mandates
- Disclosed to regulatory authorities, court officers, or police desks when required to comply with a judicial proceeding or statutory audit.
9Data Retention & Erasure Timeline
We store your personal data only as long as your account remains active or as required to fulfill our legal, accounting, tax, and dispute resolution duties. Upon an explicit account deletion request, we will deactivate your account and wipe all personally identifiable information from our active databases within 30 days, unless required to retain specific transactions for legal audits.
10Administrative & Technical Safeguards
We maintain appropriate technical, physical, and administrative controls (including firewalls, data encryption, and authorized access keys) to safeguard data against accidental loss, unauthorized alteration, or malicious exposure. However, because internet transmissions are never entirely secure, we cannot guarantee absolute security. You are advised to safeguard your mobile device and log credentials.
11Your Statutory Data Rights
Under the DPDP Act 2023, you hold the following rights regarding your personal data:
- Right to Access: Request a summary of the personal data we process and the reasons for processing.
- Right to Correction: Request correction, completion, or updates to inaccurate or outdated personal data.
- Right to Erasure: Request deletion of your personal data when it is no longer necessary for the purpose collected.
- Right to Withdraw Consent: Revoke consent at any time, which will immediately restrict further processing (though historical transactions will remain for legal compliance).
12Minor Data Restrictions
Our services are directed to adults capable of entering into legal contracts. We do not intentionally compile or request information from minors. If we discover that a minor under 18 has submitted personal information, we will verify the claim and delete the data from our records immediately.
13External Hyperlinks
Our applications and websites may feature links to external payment gateways, mapping services, or social portals. We do not oversee or endorse their privacy guidelines, cookies, or data safety policies. You should inspect their respective policies independently.
14Cookies & Session Analytics
We use essential cookies, browser storage, and analytics tokens to persist your login state, remember service selections in your cart, track user navigation flow, and diagnose loading times. You can disable cookies in your browser, but some features of the Platform may cease to function correctly.
15Updates to This Policy
We may update this Privacy Policy to reflect changing business standards or compliance changes. Any modifications will be posted here with an updated revision date. Your continued utilization of our services after updates are published signifies your acceptance of the revised terms.
16Contact Details & Privacy Officer
If you have questions, concerns, complaints, or requests regarding this Privacy Policy, your rights under the DPDP Act 2023, or the handling of your personal information, please contact our Grievance Desk: