1. Data Controller
CheckMyWarranty is operated by CheckMyWarranty Private Limited. For the purposes of applicable data protection laws, including the General Data Protection Regulation (GDPR) and the Digital Personal Data Protection Act (DPDPA), CheckMyWarranty Private Limited acts as the Data Controller for personal information processed through the Service.
- Address: Shivalik Shilp 2, 313, Judges Bunglow Rd, Suryapooja Block B, Satellite, Ahmedabad, Gujarat 380015, India
Privacy enquiries: privacy@checkmywarranty.app
General support: support@checkmywarranty.app
2. Introduction
At CheckMyWarranty Private Limited ("we", "our", "us"), we are committed to protecting your privacy and personal data. This Privacy Policy explains how we collect, use, and share your personal information when you use the CheckMyWarranty application ("the App").
We are committed to processing personal information in accordance with applicable privacy and data protection laws, including the GDPR where applicable and India's Digital Personal Data Protection Act (DPDPA).
Data Fiduciary (DPDPA 2023): For the purposes of the Digital Personal Data Protection Act 2023, CheckMyWarranty Private Limited is the Data Fiduciary responsible for determining the purposes and means of processing your personal data. Our designated Grievance Officer acts as the primary point of contact for all data-related concerns (see Section 12).
Data Controller (GDPR): For EU residents, CheckMyWarranty Private Limited is the Data Controller under the General Data Protection Regulation. You may contact us regarding EU data rights at privacy@checkmywarranty.app.
3. Information We Collect
We collect and process the following categories of data:
- Account Information: Email address, phone number, and display name used to authenticate you.
- Warranty & Vault Data: Details of products, expiry dates, purchase prices, serial numbers, document notes, and uploaded receipt images or PDFs.
- Special Category & Sensitive Personal Data: When you voluntarily store identity documents (such as passports, Aadhaar cards, or PAN cards) in the Vault, these may contain biometric data (photographs) and national identifiers that constitute Special Category Data under GDPR (Art. 9) and Sensitive Personal Data under DPDPA 2023. We process this data only with your explicit consent, which you provide at the point of uploading each document. All identity documents are encrypted at rest using AES-256 encryption within Supabase's secure infrastructure. Storing identity documents in the Vault is entirely optional.
- Usage Data: Crash reports and interaction analytics (only if Analytics Consent is granted).
4. How We Use Your Information
We use your data primarily to provide the service (Contract Performance under GDPR Art. 6(1)(b)):
- To store and sync your warranties across devices.
- To send you reminders about upcoming warranty expirations (via push or email).
- To extract text from your receipts using AI (only if AI Processing Consent is granted).
- To improve app stability via crash reports (only if Analytics Consent is granted).
5. Third-Party Processors
We do not sell your personal data. We use trusted third-party service providers (Data Processors) to help operate our App. We have Data Processing Agreements (DPAs) in place with:
- Supabase: For secure cloud database storage and authentication.
- MSG91: For delivering OTP (One Time Password) SMS messages.
- Sentry: For crash reporting and performance monitoring (anonymous data only).
- Groq / Google Gemini: When AI-powered document extraction is enabled, document images may be transmitted to these trusted providers solely to perform the requested extraction. We configure our providers not to use submitted content for model training where such controls are available. We do not intentionally use your uploaded documents to train AI models.
6. Cross-Border Data Transfers
Your data is primarily hosted on secure servers managed by Supabase, located in the European Union (EU) and India.
When you explicitly opt in to optional services like AI Document Processing or Analytics, limited data (e.g., anonymized crash logs or stateless document images) may be transferred to subprocessors in the United States (e.g., Groq, Sentry, Google).
When personal information is transferred outside your jurisdiction, we take reasonable steps to ensure appropriate safeguards are in place, including contractual protections and other legally recognized transfer mechanisms where required. You may review our sub-processors and their locations in the Sub-processors Registry.
7. Cookies & Local Storage
The App uses local storage (e.g., AsyncStorage/SQLite) on your device to cache your warranty data for offline access, and to store your consent preferences and session tokens. These are strictly necessary for the App to function.
8. Business Transfers & Corporate Changes
In the event that CheckMyWarranty Private Limited is involved in a merger, acquisition, sale of business assets, or bankruptcy, your personal information may be transferred as part of that transaction.
We will notify you via email and/or a prominent notice within the App of any change in ownership or uses of your personal information, as well as any choices you may have regarding your personal information. The new entity will be required to honor the commitments made in this Privacy Policy.
9. Your Rights
Under GDPR (Art. 15–22) and DPDPA 2023, you have the following rights regarding your personal data:
- Right of Access: View all personal data we hold about you via Settings → Privacy Center → Download My Data.
- Right to Data Portability (GDPR Art. 20): Export your warranties, reminders, vault metadata, and consent records in JSON format — a structured, machine-readable format — from Settings → Privacy Center → Download My Data.
- Right to Rectification: Correct inaccurate data directly in the App by editing any warranty, reminder, or profile field.
- Right to Erasure (Right to be Forgotten): Delete your account and all associated data from Settings → Privacy Center → Delete Account. See Section 10 for retention timelines.
- Right to Withdraw Consent: Withdraw consent for AI Processing, Analytics, Push Notifications, or Marketing at any time from Settings → Privacy Center. Withdrawal does not affect the lawfulness of processing before withdrawal.
- Right to Restriction: Request that we restrict processing of your data in certain circumstances by contacting privacy@checkmywarranty.app.
- Right to Object: Object to processing based on legitimate interest by contacting privacy@checkmywarranty.app.
- Right to Complain (EU): If you are an EU resident and believe we are processing your data unlawfully, you have the right to lodge a complaint with your local data protection supervisory authority without prejudice to any other remedy.
- Right to Complain (India): Indian users may escalate complaints to the Data Protection Board of India under DPDPA 2023.
You can exercise most of these rights directly within the App via Settings → Privacy Center without needing to contact us.
10. Data Retention
We retain your data only for as long as necessary for the purposes for which it was collected, in accordance with GDPR Art. 5(1)(e) — Storage Limitation.
Stage 1 — 30-day grace period: When you request account deletion, your account is immediately suspended and all active sessions are revoked. Your data is soft-deleted (hidden from the App) but not yet permanently removed. You may cancel the deletion within 30 days.
Stage 2 — Permanent erasure: After the 30-day grace period, your personal data is anonymised and your authentication record is removed. Any residual soft-deleted records are permanently purged from our systems within 365 days of soft-deletion as part of scheduled database maintenance.
What is retained after deletion: Consent records are retained for 7 years in anonymised form (no PII) to demonstrate legal compliance under GDPR Art. 7. No other personal data is retained after permanent erasure.
Please refer to our full Data Retention Policy for detailed timelines per data type.
11. Changes to this Policy
We may update this Privacy Policy periodically. If we make significant material changes, you will be prompted to re-review and re-consent to the updated policy within the App before continuing to use it.
12. Children's Privacy
The Service is not directed to children under the age required by applicable law to provide independent consent. We do not knowingly collect personal information from children.
If you believe a child has provided personal information to us, please contact us at privacy@checkmywarranty.app and we will take appropriate steps to remove such information.
13. Grievance Redressal (DPDPA)
In accordance with the Digital Personal Data Protection Act 2023 (DPDPA), if you have any grievances regarding the processing of your personal data, you may contact our designated Grievance Officer:
- Name: Tiksha Talati
- Designation: Data Protection & Grievance Officer
- Address: Shivalik Shilp 2, 313, Judges Bunglow Rd, Suryapooja Block B, Satellite, Ahmedabad, Gujarat 380015, India
- Email: grievance@checkmywarranty.app
We will acknowledge your complaint within 48 hours of receipt (excluding public holidays) and endeavour to resolve it within 30 days. If your complaint is not resolved to your satisfaction within 30 days, you may escalate it to the Data Protection Board of India once it becomes operational under the DPDPA 2023.
For GDPR complaints (EU residents only), you also have the right to lodge a complaint with your local data protection supervisory authority without prejudice to any other administrative or judicial remedy.
14. Contact Us
For general privacy questions, please email: privacy@checkmywarranty.app