Legal
Privacy Policy
This policy explains what Tharavadu collects on the web console, the mobile app and this website, why, and how to have it deleted.
Status:this policy is drafted from Tharavadu's actual technical data practices — every data type, purpose, and third party named below is real, not a placeholder. It has not yet had a final legal sign-off for India's Digital Personal Data Protection Act, 2023 (grievance-officer designation, statutory notice language, jurisdiction). Treat the practices described here as accurate; treat the legal phrasing as pending review.
Effective 15 September 2026
Who this is for
Tharavadu is community-management software used by residential societies and apartment associations ("tenants") and the people who live in, manage, or work for them — residents, committee members, and on-site staff. This policy covers the Tharavadu web console and the Tharavadu mobile app, both operated by the Tharavadu platform team.
What we collect
Account information
Name, email address, phone number, unit/flat label, and role, provided by your society's admin when your account is created, or by you if you sign in with Google. Committee members additionally have their permissions and role assignments.
Notifications from your community
Your community's notices, bills, visitor alerts, helpdesk updates and similar notifications are sent to you by email and, where they're switched on, by SMS and WhatsApp to the phone number on your account.
WhatsApp messages only reach you if you've agreed. You can turn "WhatsApp updates" on or off in your profile, on the web or in the app, or tell your committee, who can record that you agreed. We keep a record of when and how you agreed, the number, and the wording you saw, because WhatsApp requires businesses to hold it. You can stop at any time — in your profile, by asking your committee, or by replying STOP to any of these messages. Two exceptions: an SOS or critical-incident alert reaches your number on WhatsApp whether or not you've turned updates on, because it's about safety; and a password-reset link only ever goes by SMS or WhatsApp to a number you confirmed yourself.
For each message we keep a delivery record for 90 days: which notification it was, the channel, whether it was delivered, and a shortened form of your email address or number.
Enquiries through this website
When you use the Get Started, Contact or app-notification forms, we receive what you type — your name, email, and optionally phone number, role, community name, city, approximate number of units and message — together with the page you sent it from, the time, your browser type, and a one-way salted hash of your IP address (used only to stop spam; the address itself is not stored). We also record whether you ticked either optional box — to receive product updates, or to hear about your enquiry on WhatsApp — and which version of that wording you saw. Enquiries go to Tharavadu's own sales and support team through the Tharavadu web console; no third-party CRM receives them.
Tharavadu Vazhikatti, our website guide
Vazhikatti is an automated guide, not a person, and it doesn't use artificial intelligence: it answers from Tharavadu's own published product information. To follow the conversation it keeps what you type, with a random identifier stored in a cookie and in your browser tab, for as long as that tab is open — and deletes the conversation when you close the tab (or, if your browser can't tell us, within a few minutes of it going quiet). If you choose to share your details with our team, the conversation is saved with your enquiry so the person who contacts you has the context, and it's then kept and deleted the same way as any other enquiry. Questions it couldn't answer are kept separately, with email addresses and phone numbers removed, so we can improve our information.
If you tick the WhatsApp box, we may send a message about your enquiry to the phone number you gave, through WhatsApp. That message, and your number, pass through WhatsApp's service (Meta), and through the company that connects us to WhatsApp (currently AiSensy), so it can be delivered. We don't use WhatsApp for marketing, and we don't send anything there unless you tick the box.
Location
When staff use the mobile app to check in or out of a shift, we request the device's location only while the app is in use — never in the background — to confirm the check-in happened at the right site. We do not track location at any other time.
Photos
The mobile app captures a photo for two features: visitor gate check-in, and staff shift check-in/check-out. Where a site has enabled face verification for staff check-in, the app also compares the new photo against a stored reference photo — that comparison runs on the device, but both the reference photo and each check-in photo are uploaded and stored so your society can review check-in records.
Device sign-in (Face ID / fingerprint)
If you turn on Face ID or fingerprint unlock, your phone's own operating system handles the biometric match — Tharavadu never receives or stores a fingerprint or face template. We only receive a yes/no result telling the app to unlock.
Push notification tokens & device info
To deliver notices, alerts, and SOS pushes, the app registers your device with Expo's push notification service and stores the resulting token, your device type, and platform (iOS/Android).
Sign-in & activity history
We keep a record of sign-in attempts (time, method, approximate device/IP) for account security, and records tied to your use of the platform — bills, incidents you report, meeting RSVPs, helpdesk tickets, and similar — which belong to your society's own operational records.
Cookies & session storage
The web console uses a single, essential, httpOnly session cookie to keep you signed in. This website sets one first-party cookie that remembers how you first found us and how you most recently arrived — the campaign name from a link you followed, or the website that linked to us, and the page you landed on. It contains no identifier, is read only by this website when you send a form, and expires after 90 days. We don't use advertising or cross-site tracking cookies.
Why we collect it
- To operate your account and let your society manage its own residents, staff, and records.
- To run the safety features you use — SOS alerts, incident escalation, gate and shift check-in.
- To send the notices, bills, and alerts your society sends through the platform.
- To keep accounts secure and investigate misuse.
We do not sell personal data, and we do not use it for advertising.
Who we share it with
Data stays within your society's own account, visible only to the roles your society grants access, plus:
- Expo (exp.host) — delivers push notifications; receives only your device's push token, not your personal data.
- Google — if you choose "Continue with Google", Google verifies your identity; we receive only your verified email and name.
- WhatsApp (Meta), and our WhatsApp provider (currently AiSensy) — deliver a WhatsApp message about an enquiry you asked us to reply to there, or an urgent alert your society sends by WhatsApp; they receive your phone number, your name and the message.
- MSG91 — delivers the SMS messages your society sends; receives your phone number, your name and the message.
- Your hosting/database provider, who stores the data on our behalf and does not use it for their own purposes.
How long we keep it
We keep account data for as long as your account is active. If you delete your account, your name, email, phone, and login are removed immediately; records that your society is required to keep for its own accounting or governance history (e.g. a bill or an incident report) are retained but are no longer linked to you personally — the same way a company keeps its financial records after an employee leaves.
Website enquiries from people who don't become customers are anonymised 24 months after our last contact with them.
Marketing emails
We only send product updates and offers to people who ticked the optional box on one of our forms; the box is never pre-ticked, and leaving it unticked doesn't affect your enquiry. Every marketing email includes an unsubscribe link, and supports your email app's own unsubscribe button. You can also manage your preferences at any time at our.tharavadu.life/unsubscribe, or withdraw your consent by emailing privacy@tharavadu.life. Unsubscribing never affects emails about your account, your community's billing or an enquiry you made.
Deleting your account
You can delete your account and personal data yourself, at any time — from the mobile app (Profile → Delete my account) or from the web console (My profile → Delete account), without needing to contact anyone. This works even if you've uninstalled the app, as long as you can sign in to the web console once to confirm.
Your rights
You can ask to see, correct, or delete your personal data, or ask how it's used, at any time — most of this you can already do yourself in-app; for anything else, contact your society's admin or reach us at the address below.
Security
Passwords are one-way hashed and never stored or visible in plain text. Data in transit is encrypted (HTTPS/TLS). Access to your society's data is scoped to that society and the roles your admins assign.
Children
Tharavadu is intended for adult residents, committee members, and staff, and is not directed at children.
Changes to this policy
If this policy changes materially, we'll update the effective date above and, where required, notify you in-app.
Contact
Questions about this policy, or a request about your data: reach your society's admin, or email privacy@tharavadu.life.
