Privacy policy
Effective 28 September 2026
This policy explains what personal data Maintora collects, why, where it is kept, who it is shared with, and the rights you have over it. It is written for the Digital Personal Data Protection Act, 2023 (the "DPDP Act"), the Digital Personal Data Protection Rules, 2025, and the Information Technology Act, 2000.
Maintora is a service of Rapid Corp ("Maintora", "we", "us").
- Who is responsible for your data
- What we collect
- Why we use it
- Who we share it with
- Where it is stored
- How long we keep it
- How we protect it
- Your rights
- Browser storage and cookies
- Children
- Data breaches
- Grievance officer
- Changes to this policy
1. Who is responsible for your data
Maintora is used by businesses ("customers") to manage their assets, inspections and maintenance. Two roles apply:
- Data in a customer's workspace (their staff, assets, inspections, vendors): the customer decides what is recorded and why, and is the Data Fiduciary. Maintora processes that data on the customer's instructions as a Data Processor, under our data processing terms. If you are a customer's employee or vendor, contact your employer first about your data; we will help them answer you.
- Data about our own customers and website visitors (account holders, billing contacts, people who contact us): Maintora is the Data Fiduciary.
2. What we collect
| Data | From whom | Example |
|---|---|---|
| Account details | Every user | Name, work email, phone number (optional), role, company |
| Sign-in data | Every user | A password stored only as a one-way hash by our authentication provider; session tokens |
| Work records | Users doing the work | Which asset was scanned, when, by whom, checklist answers, readings, notes and photos taken on a check |
| Location at completion | Users completing an inspection, only if they allow it | The phone's GPS position at the moment an inspection is completed. Refusing location does not stop the inspection |
| Activity log | Every user | Actions such as "asset created" or "password reset", with the user and time, kept as the workspace's audit trail |
| Company and billing details | Customer administrators | Company name, address, GSTIN, contact email, logo, plan, payment records |
| Payment details | Customers who pay online | Order and payment reference, amount, status. Card, UPI and bank details are entered on Razorpay's page and never reach Maintora |
| Messages to us | Anyone who contacts us | What you write by email or WhatsApp |
We do not collect sensitive categories such as health, biometric, caste, religion or financial account data, and we do not ask for Aadhaar or PAN of individual users.
3. Why we use it
- To provide the service: sign-in, showing each person the work assigned to them, recording inspections and producing the customer's reports and exports.
- To prove work happened: the scan, time, person and answers are the evidence customers use in audits. This is the core purpose of the product.
- To send service emails: password resets, reminders and summaries a customer has switched on.
- To bill: invoices, receipts and GST records.
- To keep the service secure and working: diagnosing faults and preventing misuse.
- To meet legal obligations, such as tax records.
We do not sell personal data, show advertising, or use workspace data to profile individuals. We process personal data on the basis of consent given when an account is created, or for the legitimate uses the DPDP Act allows, such as performing the contract with the customer and complying with law.
4. Who we share it with
Only with service providers who help us run Maintora, each bound to protect it and to use it only for that job:
| Provider | What for |
|---|---|
| Supabase | Database, file storage and sign-in. Production data is hosted in Mumbai, India |
| Cloudflare | Sending service emails (address, subject and message only) |
| Razorpay | Taking online payments |
| Our hosting provider | Serving the website and app |
Inside a workspace, what each person can see is set by their role: staff see their own work, managers their team's, administrators their company's. No customer can see another customer's data; this is enforced in the database itself.
We disclose data to authorities only when Indian law requires it, and tell the affected customer unless the law forbids that.
5. Where it is stored
Production workspace data is stored in India (Mumbai). Some service providers, such as the email service, may process limited data outside India; we only use providers in countries not restricted under the DPDP Act.
6. How long we keep it
- Workspace data is kept while the customer's subscription is active. Completed inspections cannot be deleted from the app, because they are audit evidence; they can be retired.
- After a subscription ends, the customer can export everything to CSV. We delete the workspace within 90 days of the end of the subscription, unless the customer asks us to delete it sooner or the law requires us to keep something longer.
- Billing and tax records are kept for 8 years, as Indian tax law requires.
- Removed users: their login is deleted, but their name stays on the work they already did, so the audit trail stays true.
7. How we protect it
- Encrypted connections (HTTPS) everywhere.
- Each customer's data is separated by access rules inside the database, not only in the app.
- Passwords are never stored in readable form. Payment details never reach our systems.
- Access to production systems is limited to the people who run the service.
8. Your rights
Under the DPDP Act you can:
- Access a summary of your personal data and how it is processed.
- Correct or update inaccurate data. Most of it you can change yourself in the app.
- Erase data that is no longer needed, subject to the evidence and legal retention above.
- Withdraw consent at any time. This does not affect processing already done, and may mean you can no longer use the service.
- Nominate another person to exercise these rights if you die or become unable to.
- Complain to our grievance officer, and then to the Data Protection Board of India.
Write to the grievance officer below. We reply within 30 days, and in every case within the 90 days the DPDP Rules allow. If your data is in a customer's workspace, we pass your request to that customer and help them answer it.
9. Browser storage and cookies
The app stores your sign-in session and a few display preferences (such as theme and table columns) in your browser's local storage, so you stay signed in and the screens look how you left them. We use no advertising or tracking cookies and no third-party analytics.
10. Children
Maintora is a business tool for adults. We do not knowingly collect data from anyone under 18. If you believe we have, contact us and we will delete it.
11. Data breaches
If a breach affects personal data, we inform affected customers and individuals without delay, and the Data Protection Board of India as the DPDP Rules require, with what happened, what data was affected, and what we are doing about it.
12. Grievance officer
Manish Patel
Rapid Corp
100 Feet Road, Sector 3, Udaipur, Rajasthan
Email: [email protected]
13. Changes to this policy
We will post any change here with a new effective date, and email customer administrators before a change that reduces your rights takes effect.