1. Introduction
This Privacy Policy describes how AASHVIRA TECH SOLUTIONS LLP ("RemindPaisa", "we", "our", "us") collects, uses, and protects information when you use our payment reminder and collections management platform at remindpaisa.in.
We are a reminder tool — not a data company. We collect only what is necessary to operate the service, and we never sell or rent your data. By creating a RemindPaisa account you agree to this policy. Please read it carefully.
2. Data We Collect
2.1 Business account data
When you sign up, we collect: your name, email address, mobile number, business name, and optionally your GSTIN and business logo. This is needed to operate your account and send reminders with your business name on them.
2.2 Customer data you add
You add your customers' names, mobile numbers, email addresses, due amounts, due dates, and any notes. This data belongs entirely to you. We use it only to send the reminders you configure and to display your collections dashboard. We do not analyse, profile, or use this data for any other purpose.
2.3 Message delivery data
For each reminder sent, we record: the channel used (WhatsApp / SMS / Email), whether the message was delivered and read, and the timestamp. We do not store the content of WhatsApp messages on our servers after delivery confirmation — only the delivery status and timestamp.
2.4 Usage and device data
We log: login timestamps, features you use, your IP address (for security), and your browser type. This helps us detect fraud, debug issues, and understand which features are most useful. We do not build individual advertising profiles.
2.5 Payment and billing data
We record your plan type, wallet balance, and transaction history (top-ups, charges). We do not store your card or bank account details — those are handled directly by our payment gateway provider under their own PCI-DSS compliance.
3. How We Use Your Data
- To operate the reminder service: sending WhatsApp, SMS, and Email messages on your behalf
- To display your real-time collections dashboard (paid, unpaid, overdue, pending verification)
- To process subscription payments and wallet top-ups
- To provide customer support when you contact us
- To send you service notifications (downtime, policy changes, billing receipts)
- To detect and prevent fraud and abuse
- To comply with applicable laws and regulatory obligations
- To improve the service — on our public marketing and blog pages, we use Google Analytics and Microsoft Clarity (a session-replay tool configured with content masking to record page interactions such as clicks and scrolls). We do not intentionally load these tools on your account, dashboard, payment, or customer pages, and they are not used for individual behavioural profiling or advertising
4. WhatsApp Business API — Special Notice
How your customer data flows through WhatsApp
RemindPaisa uses Meta's official WhatsApp Business API. To deliver a WhatsApp reminder, we send your customer's phone number and the approved template content to Meta's servers. This is an unavoidable technical requirement of the API. Meta's handling of this data is governed by Meta's Privacy Policy at facebook.com/privacy/policy.
What we do and do NOT do with WhatsApp data:
- We share customer phone numbers with Meta only for message delivery — not for advertising, audience targeting, or any other purpose
- We do not store WhatsApp message content on our servers beyond delivery-status confirmation
- We do not use WhatsApp-obtained data (delivery status, read receipts) to build advertising profiles
- We do not send free-form bulk messages. All WhatsApp reminders use pre-approved templates only — we comply fully with WhatsApp Business Policy
- We do not share Meta-provided data (delivery/read status) with any third party
- Customers can reply STOP to any WhatsApp reminder to opt out. We honour all opt-outs within minutes
5. With Whom We Share Data
We share data with a minimal set of service providers needed to operate the platform. All share under strict data-processing agreements:
- Meta (WhatsApp Business API): Customer phone numbers and approved template content, for WhatsApp delivery only. Governed by Meta's Privacy Policy at facebook.com/privacy/policy
- Google (Firebase Authentication): Your email address and login metadata, to manage account sign-in securely. Governed by Google's Privacy Policy at policies.google.com/privacy
- SMS gateway / Telecom operators: Customer phone numbers and message text, for SMS delivery only. Our SMS sender IDs are registered with TRAI (Telecom Regulatory Authority of India) under the TCCCPR framework. We do not deliver promotional SMS to numbers registered on the DND (Do Not Disturb) registry
- Email delivery service: Customer email addresses and message content, for email delivery only
- Cloud infrastructure provider: Hosts encrypted copies of all data. No direct access to decrypted data
- Payment gateway: For processing subscription and wallet payments. They handle card data under their own PCI-DSS compliance
- Legal authorities: Only when required by a valid court order, government request, or applicable law — we will notify you where permitted
We never sell, rent, or trade your data with any party for marketing, advertising, or any commercial purpose.
Cross-border data transfers
Some of our service providers — including Meta (WhatsApp Business API), Google (Firebase Authentication), and email and SMS delivery providers — operate servers outside India. Your data may be transferred to and processed in countries outside India when we use these services. All such transfers are governed by data-processing agreements requiring data protections equivalent to Indian law. Under the DPDP Act 2023, the Government of India may restrict transfers to specific countries; we will update this section and notify you if such restrictions affect our operations.
A note for end-customers of businesses using RemindPaisa
If you are a customer of a business that uses RemindPaisa to send you payment reminders — and you wish to access, correct, or request deletion of your personal data — your primary contact is the business that added you to their account. They are the data fiduciary for your data. If you cannot reach them or believe your data is being misused, you may contact us at security@remindpaisa.com and we will assist in directing your request appropriately. To stop receiving reminders, reply STOP to any WhatsApp or SMS message — your opt-out will be honoured within minutes.
6. Data Retention
- Business account data: Retained for the duration of your active account, plus 90 days after deletion to allow recovery or legal compliance. Then permanently deleted.
- Customer data you add: Retained until you delete it or close your account. Deleted within 30 days of account closure.
- Message delivery logs: 12-month rolling window. Automatically purged after 12 months.
- Usage and login logs: 6-month rolling window for security review, then deleted.
- Payment and billing records: 7 years, as required by applicable Indian tax and financial laws (GST Act, Income Tax Act).
7. Security
- All data is encrypted in transit using TLS (HTTPS)
- Data at rest is protected with infrastructure-level security safeguards
- Role-based access controls — support staff cannot access your account data without your explicit consent
- HTTPS enforced with HSTS on all domains
- Sign-in secured through Firebase Authentication, with Google sign-in supported
- Ongoing security review of the application and infrastructure
- Documented incident response plan — see section 9 of our DPDP compliance page for breach notification
No system is 100% secure. If you suspect unauthorised access to your account, contact us immediately at security@remindpaisa.com.
8. Your Rights Under the DPDP Act 2023
India's Digital Personal Data Protection Act 2023 gives you the following rights over your personal data:
- Right to information (Section 11): Know what personal data we hold about you, the purposes for which we process it, and the identities of third parties with whom we share it.
- Right to correction and erasure (Section 12): Request correction of inaccurate personal data. Request erasure of personal data that is no longer needed for the purpose for which it was collected (subject to legal retention obligations).
- Right to grievance redressal (Section 13): File a complaint with our Grievance Officer if you believe your data has been mishandled. We will respond within 30 days.
- Right to nominate (Section 14): Nominate another individual to exercise these rights on your behalf in the event of your death or incapacity.
To exercise any of these rights, email security@remindpaisa.com with your registered email address, the specific right you wish to exercise, and any supporting details. We will verify your identity and respond within 30 days.
Withdrawing consent: Where our processing is based on your consent, you may withdraw that consent at any time by emailing security@remindpaisa.com. Withdrawal does not affect the lawfulness of processing carried out before withdrawal. Note that withdrawing consent for data processing essential to operating your account (such as storing your login credentials) means we will be unable to continue providing the service — in that case, your account will be closed.
For a full explanation of your DPDP Act rights and how to exercise them, see our dedicated DPDP Act Compliance page.
9. Cookies
RemindPaisa uses a minimal number of cookies:
- Session cookies: To keep you logged in. Expire when you close the browser or after 30 days of inactivity.
- Preference cookies: To remember your UI preferences (e.g., theme). Expire after 1 year.
- Analytics cookies (public pages only): On our public marketing and blog pages, Google Analytics and Microsoft Clarity set cookies to measure usage and record masked page interactions. These tools are not intentionally loaded on your account, dashboard, payment, or customer pages.
We do not use advertising cookies or any cookies that profile your behaviour across other websites for marketing.
10. Children's Data
RemindPaisa is a business tool intended for use by adults operating legitimate businesses. We do not knowingly collect personal data from individuals under 18 years of age. If you believe a minor has created an account, contact us immediately at security@remindpaisa.com.
11. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email (to your registered address) at least 15 days before the changes take effect. Continued use of RemindPaisa after that date constitutes acceptance of the updated policy. The "last updated" date at the top of this page always reflects the current version.
12. Contact Us & Grievance Officer
For any privacy questions, data requests, or complaints, contact our Grievance Officer:
Ashok Kumar
Founder & Designated Grievance Officer
AASHVIRA TECH SOLUTIONS LLP
Bengaluru, Karnataka, India
Email: security@remindpaisa.com
General enquiries: hello@remindpaisa.com
Response time: Within 30 days as required by the DPDP Act 2023