Owner and legal review
Interim privacy notice
This interim notice describes the current product design. It must be reviewed and replaced or approved by Kappaa's owner and legal adviser before a production launch. It does not claim compliance with any law.
Information the current service can use
The current application can store account contact details, saved addresses, service-request details, payment and invoice records, support disputes, ratings, and device notification tokens. Staff records and worker records are also used to coordinate booked services.
A support dispute may include photos supplied by the customer. Authentication records can include a phone number, one-time code, expiry time, and use status. The application does not ask a customer to send an OTP, password, or payment credential to support.
Why it is used
These records support authentication, booking and dispatch, customer communication, payment records, safety and dispute handling, and operation of the service. Before launch, each provider integration must be reviewed and configured to limit shared information to its approved purpose.
Providers and communication channels
Depending on production configuration, Kappaa may use service providers for OTP delivery, push notifications, image storage, location or pincode lookup, WhatsApp communication, and payment or UPI hand-off. A production provider list, contract review, processing location review, and deletion procedure remain launch gates.
Current retention status
An OTP is valid for ten minutes, but expiry is not the same as database deletion. The application does not yet run an approved automatic purge for expired OTP records, inactive accounts, addresses, notification tokens, bookings, invoices, payments, ratings, disputes, dispute photos, logs, or backups.
Production retention periods are pending owner, accounting, and legal approval. Until those decisions are recorded, an authorized operator must review each request so open bookings, disputes, fraud or security investigations, financial records, and other required records are not removed unsafely. Approved deletion may therefore mean deleting some data, anonymizing some records, and retaining a limited record under a documented hold.
Privacy request channel is not yet operational
You can edit supported current profile details in your dashboard. Historical booking, address, invoice, payment, and dispute records require a separate reviewed correction process. A dedicated, access-controlled channel for access, correction, deletion, anonymization, objection, grievance, and account-closure requests has not yet been configured or delivery-tested. This blocks production launch.
Do not send privacy requests through generic email or WhatsApp.
The owner must publish a verified request channel, named grievance/privacy contact, response process, and identity-verification method before launch. Support must never request an OTP, password, card detail, UPI PIN, or payment credential. An unverified message cannot authorize disclosure or deletion.
Questions and unresolved launch approvals
The final notice, verified request channel, retention schedule, response timelines, grievance contact, age policy, and deletion or anonymization procedure require owner and legal approval before production launch.
Account closure does not by itself settle an open booking, payment, invoice, commission, or dispute. See the interim terms for the current service position.