We use cookies to understand site usage and show relevant ads. See our Cookie Policy.

← Back to myKutir

Privacy Policy

Squadkin Technologies Pvt Ltd ("myKutir") — Effective date: 1 January 2025 · Last updated: 9 June 2026

Plain-language summary: myKutir collects only the personal data necessary to operate a residential society management platform. We do not sell your data. Your data belongs to your society. You have the right to access, correct, and erase your data. For any privacy concern, contact our Grievance Officer at [email protected].

1. About Us

This Privacy Policy is published by Squadkin Technologies Pvt Ltd ("Company", "we", "us", "our"), a company incorporated under the Companies Act 2013, with its principal place of business in Ahmedabad, Gujarat, India. We operate the myKutir residential society management platform, accessible at www.mykutir.in, and via our iOS and Android mobile applications.

This Policy describes how we collect, use, disclose, store, and protect personal data in connection with our platform and services ("Service"). It is published in compliance with:

  • Information Technology Act, 2000 ("IT Act") and the IT (Amendment) Act, 2008
  • Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 ("SPDI Rules")
  • Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 ("IT Rules 2021")
  • Digital Personal Data Protection Act, 2023 ("DPDP Act")
  • Consumer Protection Act, 2019, and Consumer Protection (E-Commerce) Rules, 2020

2. Definitions

"Personal Data":Any data about an individual who is identifiable by or in relation to such data (as defined in the DPDP Act, 2023).
"Sensitive Personal Data or Information (SPDI)":As defined under the SPDI Rules 2011: passwords; financial information; physical, physiological, and mental health information; sexual orientation; medical records and history; and biometric information.
"Data Fiduciary":An entity that determines the purpose and means of processing personal data. Squadkin Technologies Pvt Ltd is the Data Fiduciary for platform-level data. For society-specific data (resident records, complaints, etc.), the Society (acting through its elected committee) is the Data Fiduciary and myKutir acts as a Data Processor.
"Data Principal":The individual whose personal data is being processed — in this case, you (Society Admin, Resident, Committee Member, Staff, or Security Guard).
"Processing":Any operation performed on personal data — including collection, storage, use, disclosure, deletion, or sharing.
"Consent":Free, specific, informed, unconditional, and unambiguous indication of your agreement to the processing of your personal data.

3. Personal Data We Collect

3.1 Identity and Contact Data

  • Full name, email address, and mobile phone number (provided at registration or invitation)
  • Profile photograph (optional, voluntarily uploaded)
  • Flat/unit number, block/tower, and residential society details
  • Role within the society (Owner, Tenant, Committee Member, Staff, Security Guard)

3.2 Sensitive Personal Data or Information (SPDI)

  • Passwords: stored as bcrypt hash with random salt; your plaintext password is never stored or transmitted
  • Financial information: maintenance payment records, Razorpay transaction IDs, payment method type (UPI/card/bank transfer); we do not store card numbers or CVVs — these are handled entirely by Razorpay
  • Biometric preference flag: a boolean value (true/false) indicating whether you have enabled biometric login on your device. Your actual biometric data (fingerprint, face geometry) never leaves your device and is processed solely by your device's operating system
  • Staff facial recognition data (only for societies that enable this feature): with the staff member's explicit recorded consent, we store a facial photograph and a facial feature descriptor (a numeric representation of facial geometry, used to verify identity — not a viewable image of the face) on our servers, used solely to verify attendance punches. A liveness-check selfie is also captured and stored at each attendance punch to prevent buddy-punching. This is distinct from the device-local biometric login described above.

3.3 Society Operations Data

  • Maintenance bills, payment history, outstanding dues, and ledger entries
  • Complaint details, descriptions, photographs, and resolution history
  • Visitor entry and exit records including visitor name, purpose, vehicle number, and host flat
  • Gate access logs including timestamps and security guard identity
  • Event booking details (venue, date, time, requester)
  • Domestic worker and regular visitor registry entries (name, mobile, type)
  • Documents uploaded to the platform (notices, meeting minutes, society rules, insurance policies)
  • Staff attendance records and leave applications

3.4 Device and Technical Data

  • Device model, operating system, and app version (for compatibility and error tracking)
  • Expo push notification token and Firebase Cloud Messaging (FCM) token (for delivering in-app alerts; not used for advertising)
  • IP address and browser type (for security logging and fraud prevention)
  • Session tokens (stored in device secure storage; used to maintain login state)

3.5 Location Data (Security Guards only)

The myKutir mobile app includes a security guard patrol feature. When a Security Guard uses this feature, the app requests foreground location permission and records GPS coordinates at patrol checkpoint log entries. This data is:

  • Collected only from Security Guard accounts using the patrol feature — never from Residents or Society Admins
  • Used solely to verify and log patrol route completion within the society premises
  • Stored as part of the society's security records and subject to the same 12-month security log retention policy (Section 9)
  • Never shared with third parties or used for any purpose other than society security management

3.6 Data We Do Not Collect

  • We do not collect Aadhaar numbers, PAN numbers, or government identity document details
  • We do not collect location data from Residents, Society Admins, Committee Members, or Accountants
  • We do not collect health or medical information
  • We do not collect data from social media platforms
  • We do not use advertising cookies or cross-site tracking technologies

4. How We Collect Personal Data

  • Directly from you when you register, accept an invitation, or use the platform
  • From your Society Admin when they create your account or update your profile
  • Automatically from your device when you log in or use platform features
  • From Razorpay, our payment partner, when payment transactions are completed
  • From security guards who log visitor entries at your society gate

5. Legal Basis for Processing

We process personal data on the following lawful bases under the DPDP Act 2023 and SPDI Rules 2011:

PurposeLegal Basis
Account creation and platform accessConsent (at registration / acceptance of invite)
Maintenance billing and payment processingContractual necessity (subscription agreement)
Delivering push notifications and SMS alertsConsent (notification opt-in)
Security and visitor managementLegitimate interest (physical security of residents)
Security guard patrol location trackingLegitimate interest (verifying patrol routes for society safety)
Financial record-keeping and reportingLegal obligation (accounting, tax records)
Error tracking and platform improvementLegitimate interest (platform security and stability)
Compliance with court orders or legal processLegal obligation

6. How We Use Your Personal Data

  • To create and manage your account and authenticate your identity
  • To provide all features of the myKutir platform (maintenance billing, complaints, gate management, bookings, etc.)
  • To send you transactional communications: bill reminders, payment receipts, complaint updates, notice publications, visitor alerts
  • To process and record maintenance payments and generate financial reports for your society
  • To display visitor logs and security information relevant to your role
  • To enable real-time community chat within your society
  • To generate AI-assisted drafts for complaints and notices (your input is processed by an AI model; see Section 13)
  • To monitor platform health, detect errors, and improve the Service
  • To comply with applicable Indian laws and respond to lawful government requests

7. Disclosure and Sharing of Your Personal Data

We do not sell, rent, or trade your personal data to any third party. We disclose data only in the following circumstances:

7.1 Within Your Society

Society Admins and authorised Committee Members can view data relevant to their role — for example, payment records for their society, complaint assignments, and resident directories. Data from one society is never accessible to another society.

7.2 Service Providers (Data Processors)

ProviderPurposeData Shared
RazorpayPayment processingName, email, phone, transaction amount
Expo / Firebase (Google)Push notificationsNotification token only; no message content stored
Twilio / MSG91SMS and WhatsApp alertsPhone number, message content
SentryError trackingAnonymised error logs; no personal identifiers
Anthropic (Claude AI)AI-assisted draftsInput text only; not used for training; see Section 13
Hetzner CloudApplication hosting, database, file storageAll platform data — encrypted at rest (AES-256)

All service providers are contractually bound to process your data only for the stated purpose and to maintain appropriate security standards.

7.3 Legal Disclosure

We may disclose personal data to government authorities, law enforcement, or courts when required to do so by a valid order, warrant, or applicable Indian law (including the IT Act 2000 and DPDP Act 2023). We will endeavour to notify the affected Data Principal prior to disclosure unless prohibited by law.

7.4 Business Transfers

If Squadkin Technologies Pvt Ltd undergoes a merger, acquisition, or sale of assets, personal data held by us may be transferred to the acquiring entity, subject to the same privacy protections described in this Policy. We will notify Society Admins by email before any such transfer.

8. Cross-Border Data Transfers

myKutir's primary infrastructure — including our application servers and database — is hosted on Hetzner Online GmbH (Germany, European Union), a Hetzner Cloud instance. Some of our other service providers are also located outside India (including the United States). When your data is transferred internationally, it is protected by contractual data processing agreements that require the recipient to apply standards equivalent to or greater than those required under Indian law, and consistent with the DPDP Act 2023 provisions on cross-border transfers.

We do not transfer personal data to countries that are blacklisted under the DPDP Act or by order of the Central Government of India. The primary data processors receiving data outside India are: Hetzner Online GmbH (Germany — primary application and database hosting), Anthropic, Inc. (USA — AI processing), Sentry, Inc. (USA — error logging), and Expo/Firebase (USA — push notifications). All data is encrypted in transit (TLS 1.3) and at rest (AES-256) regardless of processing location.

9. Data Retention

  • Active accounts: data is retained for as long as your society's subscription is active and your account exists
  • After account deletion request: personal identifiers (name, email, phone, profile photo) are deleted or anonymised within 30 days of the confirmed request. You can submit a deletion request via the Delete my account option in the mobile app (Profile screen) or by emailing [email protected].
  • After subscription termination: all society data is retained for 90 days to allow data export, then permanently deleted
  • Financial records (payment receipts, invoices): retained for 7 years to comply with Indian accounting and tax laws (Companies Act 2013, GST Act 2017)
  • Visitor and gate records: personal details of visitors (name, phone, photo, vehicle number) are automatically anonymised 180 days after the visit by default. Your society may configure a shorter or longer window. The visit record is retained for security statistics but no longer identifies the individual.
  • Security logs and access logs: retained for 12 months for fraud detection and security audit purposes
  • AI assist session data: not retained beyond the current session; no conversation logs are stored on our servers
  • Staff facial recognition data: facial descriptors and enrollment photos are deleted within 30 days of a staff member's exit or withdrawal of consent. Attendance liveness selfies are retained for 12 months for audit purposes, then deleted.

10. Security of Your Personal Data

We implement reasonable security practices and procedures as required under Rule 8 of the SPDI Rules 2011, including:

  • TLS 1.3 encryption for all data in transit between your device and our servers
  • AES-256 encryption at rest for sensitive fields (API keys, payment credentials)
  • bcrypt hashing with random salt for all passwords
  • Role-based access control (RBAC) — every user can only access data permitted for their role and society
  • Server-level firewalls and DDoS protection
  • Automated daily database backups with off-site storage
  • Session tokens stored in device hardware-backed secure storage (Keychain on iOS, Keystore on Android)
  • Multi-factor authentication available for Society Admin accounts
  • Regular security audits and vulnerability assessments

Despite these measures, no internet transmission is completely secure. We cannot guarantee absolute security but commit to responding to any breach promptly, notifying affected Data Principals and the relevant authority as required under the DPDP Act 2023.

11. Your Rights as a Data Principal

Under the Digital Personal Data Protection Act 2023 and IT (SPDI) Rules 2011, you have the following rights:

Right to Access

You may request a summary of the personal data we hold about you and how it is being processed.

Right to Correction and Erasure

You may request correction of inaccurate personal data, or erasure of data that is no longer necessary for the purpose it was collected. To delete your account and personal data, tap Delete my account in the myKutir mobile app (Profile screen) — this sends a deletion request to our support team. We will complete deletion within 30 days. Note: financial records (bills, receipts) are retained for 7 years as required by Indian law (GST Act / Companies Act) and cannot be erased.

Right to Grievance Redressal

You have the right to raise a grievance with our Grievance Officer (see Section 17) if you believe your personal data has been processed in violation of applicable law.

Right to Nominate

Under the DPDP Act 2023, you may nominate another individual to exercise your data rights on your behalf in the event of your death or incapacity. Contact our Grievance Officer to register a nominee.

Right to Withdraw Consent

Where processing is based on your consent, you may withdraw consent at any time by contacting us at [email protected]. Withdrawal does not affect the lawfulness of processing before withdrawal. It may result in certain platform features becoming unavailable.

Right to Data Portability

You may request your personal data in a machine-readable format (CSV/JSON). Society Admins can export their society data directly from Society Settings.

To exercise any of the above rights: (1) for account deletion, use the Delete my account button in the myKutir mobile app (Profile screen), or (2) email [email protected] with: (a) your full name; (b) registered email/phone; (c) society name; (d) description of your request. We will acknowledge within 24 hours and respond within 30 days.

12. Cookies and Browser Storage

Our web platform uses cookies and browser local storage to maintain your session and preferences. We use only strictly necessary and functional storage; we do not use advertising or retargeting cookies. For full details, see our Cookie Policy.

13. AI Features and Data Processing

myKutir includes AI-assisted features for complaint drafting, notice writing, and document search ("AI Assist"). When you use these features, your input text is sent to Anthropic, Inc. (USA) for processing by the Claude AI model.

  • Your input data is processed solely to generate a response for your current session
  • Input data is NOT used to train AI models
  • We do not retain AI conversation logs beyond the current session
  • Sensitive information (payment details, personal identifiers of third parties) should not be entered into AI Assist fields
  • AI-generated outputs are suggestions only and do not constitute legal, financial, or professional advice

The first time you use any AI Assist feature, we show an explicit consent prompt describing this data transfer before your input is sent — your consent is recorded and you may withdraw it at any time from Profile → Privacy. Once recorded, your consent covers data transfer to Anthropic, Inc. under their Privacy Policy and as described in our cross-border transfer provisions (Section 8).

14. Third-Party Links

The Platform may contain links to third-party websites (e.g., Razorpay payment pages, government portals). We are not responsible for the privacy practices of those websites. We recommend reviewing their privacy policies before providing any personal data to them.

15. Children's Privacy

myKutir is not intended for use by individuals under the age of 18. We do not knowingly collect personal data from minors. If you believe a minor's data has been registered on our platform, please notify us at [email protected] and we will take prompt corrective action.

Under the DPDP Act 2023, processing personal data of children (under 18 years) requires verifiable parental consent. Society Admins must obtain parental/guardian consent before registering a minor as a resident or platform user.

16. Changes to This Privacy Policy

We may update this Privacy Policy periodically to reflect changes in our practices, platform features, or applicable law. Material changes will be notified to Society Admins by email and to all users via an in-app notice at least 15 days before the change takes effect. The "Last updated" date at the top of this page indicates when the Policy was last revised.

Continued use of the Platform after the effective date of a revised Policy constitutes your acceptance of the updated terms.

17. Grievance Redressal

In accordance with the Information Technology Act 2000, IT (Intermediary Guidelines and Digital Media Ethics Code) Rules 2021, and the Digital Personal Data Protection Act 2023, we have appointed a Grievance Officer:

Grievance Officer — Squadkin Technologies Pvt Ltd

Name: Ajay Sikarwar

Designation: Founder & Grievance Officer

Company: Squadkin Technologies Pvt Ltd

Email: [email protected]

Address: Squadkin Technologies Pvt Ltd, Ahmedabad, Gujarat — 380 001, India

Response time: Acknowledgement within 24 hours of receipt. Resolution within 30 days. If you are not satisfied with our resolution, you may approach the Data Protection Board of India (once operational under the DPDP Act 2023), or the relevant Consumer Disputes Redressal Commission under the Consumer Protection Act 2019.

18. Contact Us

Squadkin Technologies Pvt Ltd

Platform: myKutir — www.mykutir.in

General: [email protected]

Privacy / Data requests: [email protected]

Grievance Officer: [email protected]

Phone: +91 96347 85585 (Mon–Sat, 10 AM – 6 PM IST)

Terms of ServiceRefund PolicyCookie Policy© 2026 Squadkin Technologies Pvt Ltd. All rights reserved.