Skip to content
Legal

Privacy Policy

Operated by Aurtrio LLP (LLPIN: ACZ-3570). Effective date: 2026-08-15 — Version 1.0

1. Who We Are

Legal name
Aurtrio LLP  (LLPIN: ACZ-3570)
Registered address
64/A Tharayil Kuttikkavil House, Choppankkavu, Kadalundi Nagaram, Malappuram 673314, Kerala, India
Data privacy email
privacy@serckl.com
General contact
hello@serckl.com

Grievance Officer

Name: Lidhish C  ·  Designation: Grievance Officer, Aurtrio LLP
Email: privacy@serckl.com  ·  Response time: within 48 hours of receipt

If you are not satisfied with our Grievance Officer's response, you may escalate your complaint to the Data Protection Board of India (DPBI) once it becomes operational. We will publish the DPBI's contact details on this page when available.

2. Scope of This Policy

This Privacy Policy applies to:

  • The Serckl consumer mobile app (Android and iOS)
  • The Serckl website (serckl.com and its sub-domains)

It does not apply to third-party websites or services linked from our app or website. Please review the privacy policies of those third parties separately.

3. Data We Collect and Why

We only collect personal data that is necessary for the purposes described below. We do not collect your contacts, call logs, or SMS messages.

3.1 Account and Identity Data

Data Purpose Legal basis
Full name Displaying your public profile; community identification Consent (provided at sign-up)
Date of birth Age verification (18+); personalisation Consent
Gender Personalisation of content Consent
Profile photo Displaying your avatar in the app Consent
Phone number Firebase authentication (OTP-based login); account recovery Consent

3.2 Location Data

Data Purpose Legal basis
Precise device location (real-time, while using the app) Discovering deals and events near you; distance-based filtering Consent (location permission prompt at runtime)

We do not store your precise location on our servers beyond the duration of a session request. Location is used in-memory to return nearby results and is not retained in our database.

3.3 Device and Technical Data

Data Purpose Legal basis
FCM / push notification token Delivering push notifications about deals, events, and alerts you have opted into Consent (notification permission prompt)
Device OS and version Ensuring app compatibility; crash diagnostics Legitimate use (security and diagnostics)
Crash reports and diagnostic data Identifying and fixing app crashes Legitimate use (protecting service integrity)

3.4 Usage and Analytics Data

Data Purpose Legal basis
Deals and events viewed, saved, or claimed Personalising your feed; improving recommendations Consent (marketing analytics); Legitimate use (core service delivery)
Search queries within the app Improving search relevance Consent
App session data (screens visited, feature usage, session duration) Understanding how the app is used; improving product Consent (marketing/analytics consent at sign-up)

3.5 Transaction Data (when applicable)

Data Purpose Legal basis
Subscription and billing records Processing your subscription; GST compliance Legitimate use (contract performance; legal obligation)

4. How We Use Your Data

We use your personal data only for the purposes stated in Section 3. We will not use your data for a new, incompatible purpose without obtaining fresh consent from you first.

  • We do not sell your personal data to any third party.
  • We do not use your personal data to display targeted advertising from third parties within the Serckl app.
  • We do not process your personal data for behavioural tracking or profiling for advertising purposes.
  • We do not make fully automated decisions that have a legal or similarly significant effect on you.

5. Consent

5.1 How we obtain consent

We obtain your consent through explicit, affirmative actions:

  • Account sign-up: before completing onboarding, you must check a box confirming you have read and agree to this Privacy Policy and our Terms of Use.
  • Location permission: your device's operating system presents a permission dialog. We access your location only if you grant permission.
  • Push notifications: your device's operating system presents a permission dialog. We send notifications only if you grant permission.
  • Marketing consent: a separate, optional checkbox at sign-up. Declining does not affect your ability to use the core service.

Bundled or pre-ticked consent is not used.

5.2 Withdrawing consent

You can withdraw your consent at any time:

  • Location: disable location permission for Serckl in your device's Settings app.
  • Push notifications: disable notification permission for Serckl in your device's Settings app, or turn off individual notification categories in the Serckl app under Profile → Settings.
  • Marketing consent: email privacy@serckl.com with subject "Withdraw marketing consent" (in-app toggle coming in a future update).
  • Full account / data erasure: see Section 8.3 below.

Withdrawing consent does not affect the legality of any processing carried out before withdrawal. However, withdrawing location permission will mean you can no longer use location-based deal discovery; withdrawing notification permission will mean you no longer receive deal or event alerts.

6. Legal Bases for Processing

We process your personal data on the following legal bases under the Digital Personal Data Protection Act, 2023 (DPDP Act):

Processing activity Legal basis
Account creation and management Consent (Section 6)
Location-based deal/event discovery Consent
Push notification delivery Consent
Marketing analytics and recommendations Consent
Crash reporting and diagnostics Legitimate use — protecting the vital interests of users and the service (Section 7(d))
Compliance with government/court orders Legitimate use — compliance with legal obligation (Section 7(a))
Billing and subscription management Legitimate use — necessary to perform the contract (Section 7(b)); legal obligation (GST)

Note: The DPDP Act does not recognise a general "legitimate interest" ground equivalent to GDPR Article 6(1)(f). We rely on the specific legitimate use categories in Section 7 of the Act, not on a general balancing test.

7. Data Retention

We retain personal data only for as long as necessary for the stated purpose or as required by law.

Category Retention period
Account and profile data While your account is active + 30 days after deletion (to allow recovery), then permanently deleted
Location data (session) Not stored beyond the API call that uses it
Push notification tokens While your account is active; deleted upon account deletion
Crash logs (Sentry) 30 days
Analytics data (GA4) 14 months (our GA4 data retention limit)
Billing and transaction records 7 years (GST compliance requirement)
Consent records 7 years (audit trail for DPDP compliance)

8. Your Rights Under the DPDP Act

8.1 Right to access information (Section 11)

You can request a summary of the personal data we hold about you and how we process it.
How: Email privacy@serckl.com with subject "Data Access Request" from your registered email or phone number. We will respond within 30 days.

8.2 Right to correction (Section 12)

You can update most of your personal data directly within the app (Profile → Edit Profile). For data you cannot edit yourself, email privacy@serckl.com.

8.3 Right to erasure (Section 12)

You can request deletion of your account and personal data.
How: Profile → Settings → Delete Account (in-app), or email privacy@serckl.com with subject "Account Deletion Request".
SLA: We will complete deletion within 30 days of your request.
What cannot be erased: Billing and transaction records legally required to be retained for 7 years under GST law, and aggregated/anonymised analytics data that cannot be attributed back to you.

8.4 Right to grievance redressal (Section 13)

If you have a complaint about how we handle your personal data, contact our Grievance Officer at privacy@serckl.com. We will respond within 48 hours. If you are not satisfied with our response, you may escalate to the Data Protection Board of India (DPBI).

8.5 Right to nominate (Section 14)

You may nominate another individual to exercise your data rights on your behalf in the event of your death or incapacity.
How: Email privacy@serckl.com with subject "Nomination — Data Rights" with the nominee's name and contact details.

8.6 Non-discrimination

Exercising any of the above rights will not result in service degradation, denial of service, or any other penalty, except where the data you request to delete is strictly necessary to provide the specific service you are using.

9. Data Processors (Third Parties)

We engage third-party service providers (Data Processors) to operate and deliver the Service. These include providers of cloud infrastructure, authentication, push notifications, analytics, crash reporting, and payment processing — including but not limited to services offered by Google, Amazon Web Services (AWS), Microsoft Azure, and similar globally recognised cloud platforms.

Each processor is engaged under their respective terms of service and/or data processing agreements, which require them to:

  • Process personal data only to the extent necessary to provide their services
  • Maintain appropriate technical and organisational security measures
  • Not sell or use your personal data for their own advertising or commercial purposes

Payment processing is handled entirely by a licensed, RBI-regulated payment aggregator. Serckl does not store, process, or transmit payment card numbers, UPI credentials, or banking details. Aurtrio is not liable for any failure, fraud, or data breach occurring at the payment processor level.

Authentication is provided by a third-party identity platform. Phone OTP delivery, token issuance, and session management are performed by that provider. Aurtrio is not liable for OTP delivery failures, authentication outages, or security incidents originating within the provider's infrastructure.

Crash and diagnostic data is processed by a third-party monitoring platform. Only anonymised technical data (stack traces, device OS, app version) is sent — no personal identifiers such as name, phone number, or location are included in crash reports.

We do not sell or rent personal data to any third party for their own marketing or commercial purposes.

10. Cross-Border Data Transfers (Section 16)

Some of our third-party service providers are headquartered outside India and may process your personal data on servers located outside India (including in the United States and the European Union). These providers operate under internationally recognised data protection frameworks (such as GDPR, SOC 2, ISO 27001, or PCI-DSS).

Such transfers are permitted under the DPDP Act unless the Central Government of India notifies a restriction on transfers to a particular country. We will monitor the restricted-country list when published and update our practices accordingly.

By using Serckl, you acknowledge that your personal data may be transferred to and processed in countries outside India by our service providers. Such transfers comply with applicable Indian law.

11. Children's Data (Section 9)

Serckl is not intended for users under 18 years of age.

We do not knowingly collect personal data from children. At sign-up, you must confirm that you are 18 years of age or older. If we discover that we have inadvertently collected data from a user under 18, we will delete that data promptly.

We do not process children's data for behavioural tracking or targeted advertising, and we do not serve targeted advertisements to children.

12. Security

We take reasonable technical and organisational measures to protect your personal data, including:

  • All data in transit is encrypted using HTTPS/TLS.
  • Passwords are not used — authentication is phone OTP-based via Firebase Auth.
  • Firebase Security Rules restrict database access to authenticated users.
  • Access to production systems is restricted to authorised Aurtrio personnel.
  • Crash and diagnostic data (Sentry) is kept separate from production data.

Data breach notification: In the event of a personal data breach, we will notify the Data Protection Board of India and affected Data Principals as prescribed by the Rules under the DPDP Act (within 72 hours for the DPBI; affected users will be notified promptly by in-app notification and/or email).

13. Significant Data Fiduciary

Serckl is not currently notified as a Significant Data Fiduciary (SDF) under Section 10 of the DPDP Act. If the Government of India classifies Serckl as an SDF in the future, we will conduct Data Protection Impact Assessments (DPIA), appoint a Data Protection Officer (DPO), conduct periodic data audits, and integrate with the Consent Manager framework as required. We will update this Privacy Policy promptly if we are classified as an SDF.

14. Changes to This Policy

If we make a material change to this Privacy Policy, we will notify you via an in-app notification before the change takes effect. Continued use of the app after the effective date constitutes acceptance of the updated policy. For non-material changes (e.g., formatting, clarifications), we will update the effective date without a separate notification.

15. Contact Us

Privacy questions?

Contact our Grievance Officer — we respond within 48 hours.

Post: 64/A Tharayil Kuttikkavil House, Choppankkavu, Kadalundi Nagaram, Malappuram 673314, Kerala, India

This Privacy Policy is drafted in accordance with the Digital Personal Data Protection Act, 2023 (India). Rules under the Act are yet to be fully notified as of 2026-08-15 — this policy will be updated when Rules are published. Review by a qualified data protection lawyer is recommended before publication.