Legal & Safety

Privacy Policy

This Privacy Policy explains how VistarX may collect, use, protect, and manage information in connection with applications, websites, and services published or operated under the VistarX brand.

VISTARX Solutions Pvt. Ltd.

Privacy Policy

1. Scope

Scope of this policy

This Privacy Policy may apply to VistarX mobile applications, associated websites, web services, APIs, backend services, and future applications released under the VistarX brand. The specific data practices of a given application may differ depending on the features enabled in that application or service. Where necessary, additional notices or product-specific disclosures may apply.

2. Information We Collect

Information we may collect

VistarX may collect information when users interact with an application, website, or service, depending on the functionality enabled and the user’s choices. Information collected may include standard account details, profile information, location-related data, complaint or survey submissions, media uploads, messaging data, technical information, and records needed for service administration, security, and support. Not every application collects every category of information listed below.

3. Account & Profile Information

Account and profile information

Where applicable, an application may collect account and profile information that users provide directly or that is required for account setup, login, authentication, or service delivery. This may include name, phone number, date of birth or age, gender, voter ID, profile information, account identifiers, and other information necessary to support the relevant application. These categories are only collected when required by the application or voluntarily provided by the user.

4. Location & Constituency Information

Location and constituency information

Where applicable, VistarX applications may process information related to state, district, taluk, constituency, ward, booth, and other location hierarchy information. This may be used to provide location-specific services, constituency-based functionality, service mapping, or role-based access within the relevant application. The precise location information used varies based on the functionality enabled in a given product.

6. Complaints & User Submissions

Complaints and user submissions

Applications with complaint, reporting, or submission functionality may process complaint titles, descriptions, categories, location details, images, videos, voice notes, uploaded media, and related account or user information. Submission timestamps and any metadata required to investigate or resolve a report may also be processed in accordance with the application’s functionality and applicable operational requirements.

7. Surveys & Feedback

Surveys and feedback

Where enabled, applications may collect survey questions, survey responses, user feedback, submission timestamps, user or account identifiers, and relevant location information when such information is necessary to support a survey, quality review, service improvement, or operational research process. These features are optional and may not be available in every application.

8. Media & Profile Images

Media and profile images

VistarX applications may collect or process profile photographs, images, videos, voice recordings, voice notes, and other media uploaded through supported features. The collection of such media depends on application functionality, user decisions, and the purposes for which the feature is used. Media may be used to support profile management, complaint handling, communication, or service-specific workflows where applicable.

9. Notifications & Messaging

Notifications and messaging

VistarX applications may use push notifications, in-app messaging, and communication services to deliver alerts, updates, service messages, or operational notices. Where applicable, technical services such as Firebase Cloud Messaging may be used. The specific messaging or push services used depend on the application, feature set, and technical configuration.

11. Payments

Payments

Where an application provides payment or checkout functionality, payment processing may be handled by an external payment provider, payment gateway, or web checkout service. Third-party payment providers may have their own terms, privacy policies, and security practices. VistarX does not assume responsibility for those third-party services beyond the services and integrations it is directly responsible for managing.

12. How We Use Information

How we use information

VistarX may use information for legitimate product and service purposes, including account functionality, authentication, complaint handling, survey and feedback processing, notifications, administration, analytics, security, fraud and abuse prevention where applicable, service improvement, application functionality, customer or user support, technical troubleshooting, and related business operations. The exact use depends on the application, the user’s interaction with the service, and the specific functionality enabled.

13. Data Sharing & Service Providers

Data sharing and service providers

Depending on the application and enabled functionality, VistarX may use third-party infrastructure and service providers to support hosting, analytics, messaging, authentication, media services, integrations, or backend operations. This may include providers such as Supabase, Firebase Cloud Messaging, MSG91, WhatsApp integrations, Meta APIs, and Facebook or Instagram integrations. VistarX uses such providers only where required for the relevant functionality or service, and only in accordance with applicable contracts and operational requirements.

14. Data Security

Data security

VistarX uses reasonable technical and organizational safeguards to protect information processed through its applications and services. The platform architecture may include authentication, access control, PostgreSQL Row Level Security, tenant-level data isolation, server-side APIs and functions, and controlled administrative access. While these controls are designed to reduce risk, no digital system can be guaranteed to be completely secure. VistarX therefore applies appropriate safeguards and reviews them as technology and risk conditions change.

15. Multi-Tenant Architecture

Multi-tenant architecture

Because VistarX applications may operate in a multi-tenant SaaS environment, different organizations or constituencies may operate as separate logical tenants. Tenant-specific information is intended to be isolated using application-level and database-level controls. Tenant IDs and access controls may be used to restrict access to relevant information and ensure that users only see data appropriate to their authorized scope. The specific implementation details may vary by application.

16. Data Retention

Data retention

VistarX may retain information for as long as reasonably necessary to provide services, meet legal obligations, support security and dispute resolution, maintain operational continuity, and carry out legitimate business or product purposes. Actual retention periods may vary depending on the type of information, application functionality, and applicable requirements. VistarX does not apply a single universal retention period to every category of information.

17. User Rights & Choices

User rights and choices

Depending on the application, the legal context, and the nature of the service, users may have options relating to access to information, correction or updating of personal or account data, deletion or account closure where applicable, and other requests permitted by applicable law. VistarX may provide or support such options through the official VistarX support or privacy contact process. Any user request is subject to applicable legal requirements, operational feasibility, and the specific product or service involved.

18. Children’s Privacy

Children’s privacy

VistarX takes child safety and privacy seriously. Applications may have different age requirements depending on their purpose, functionality, and applicable legal requirements. Users should not provide children’s personal information unless the relevant application permits it and any necessary authorization or consent exists where required. VistarX does not intend to enable unlawful collection or exploitation of children’s information. For broader guidance and child-safety standards, please read our Child Safety Standards.

19. Changes to This Privacy Policy

Changes to this Privacy Policy

VistarX may update this Privacy Policy as applications evolve, services change, legal requirements change, or security and privacy practices improve. Continued use of the relevant application or service after an update constitutes acceptance of the updated policy where applicable.

20. Contact Us

Contact and support

For questions about this Privacy Policy, data handling, service-specific notices, or request handling, please use the official VistarX contact information available on the website or application. If a dedicated privacy contact is later added by VistarX, that official contact method should be used in preference to any older or informal route.

Note
Content should be reviewed and approved by VistarX/legal counsel before publication.