Privacy Policy

Last updated: 8 April 2026

Amazia Technologies (OPC) Private Limited("Pagevala," "we," "us," or "our") is committed to protecting your personal information. This Privacy Policy explains what data we collect, how we use it, with whom we share it, and the rights you have over it, in accordance with:

  • Digital Personal Data Protection Act, 2023 (DPDP Act) — India
  • Information Technology Act, 2000 and rules made thereunder, including IT Rules 2021
  • General Data Protection Regulation (GDPR) — for users in the European Economic Area
  • Reserve Bank of India (RBI) guidelines for Payment Aggregators
  • Consumer Protection (E-Commerce) Rules, 2020

1. Information We Collect

1.1 Information You Provide

We collect information you voluntarily give us when you use Pagevala:

  • Business details — name, description, address, city, product/menu items, timings, contact information
  • WhatsApp number — for page ownership, editing, and customer communication
  • 4-digit PIN — stored as a salted SHA-256 hash, used to access the "My Pages" dashboard
  • Photos and logos — optional uploads used to generate your business page
  • Voice recordings — transient only; sent to our AI models for transcription and discarded immediately
  • Support messages — content of any chat, email, or WhatsApp support conversation
  • Feature votes and Founding Member reservations — WhatsApp number, optional name, optional notes

1.2 Information Collected Automatically

  • Device and browser data — user-agent, operating system, screen size, language preference
  • IP address — used for rate limiting, fraud prevention, approximate city-level geolocation
  • Usage data — pages visited, buttons clicked, time on page, session duration
  • Analytics identifiers — anonymous session IDs, UTM parameters from inbound links
  • Cookies and similar technologies — see our Cookie Policy

1.3 Information from Third Parties

  • Payment processors — when you subscribe to Pro or reserve a Founding Member spot, our PCI-DSS compliant payment partner (Razorpay or equivalent) shares limited transaction metadata with us (transaction ID, amount, payment method type). We do not receive or store your full card number, CVV, or UPI PIN.
  • Google / Microsoft / Meta — if you arrive via advertising or search, we receive the standard referral headers and any UTM parameters.

1.4 What We Do NOT Collect

  • Aadhaar, PAN, or other government IDs
  • Biometric data (fingerprints, facial scans)
  • Financial account numbers or credit card details (these go directly to the PCI-DSS payment processor)
  • Health, religious, political, or sexual orientation data
  • Data from users under the age of 13 (we require users to be at least 13 years old per DPDP Act 2023, Section 9)

2. How We Use Your Information

  1. Provide the core service — generate your AI landing page, host it, let you edit it, and deliver it to visitors
  2. Authenticate you — the WhatsApp + PIN flow uses your number as a login identifier
  3. Process payments and manage subscriptions — for Pro and Founding Member purchases
  4. Improve our AI models — aggregated and anonymized usage patterns help us tune text and image generation
  5. Communicate with you — service updates, security alerts, feature announcements, and responses to your support queries
  6. Prevent abuse and fraud — rate limiting, content scanning, cost-cap enforcement, blocking of spam/scam/illegal content
  7. Comply with legal obligations — respond to lawful requests from law enforcement, tax authorities, and regulators
  8. Enforce our Terms of Service — investigate violations and take remedial action

3. How We Share Your Information

We share your data only with trusted service providers under strict data-processing agreements, and only to the minimum extent necessary:

RecipientPurposeLocation
Razorpay / Cashfree / PhonePePayment processing, subscription billingIndia (PCI-DSS compliant)
Google Cloud / MongoDB AtlasDatabase hosting, infrastructureIndia / Singapore
Google Gemini APIAI text and image generationGlobal (Google Cloud)
CloudinaryImage hosting and deliveryUSA (GDPR compliant)
Vercel / DigitalOcean / HetznerWebsite hosting, serverless functionsIndia / EU
Google Analytics + Microsoft ClarityAnonymous usage analytics (opt-out available)Global

We do not sell, rent, or trade your personal information to any third party for marketing purposes.

4. Data Security

  • TLS 1.3 encryption for all data in transit
  • Encryption at rest for sensitive fields
  • Salted SHA-256 hashing for PINs
  • Rate limiting on all authentication and generation endpoints
  • Content scanning of every AI-generated page
  • Least-privilege access controls — audited via logs
  • Regular security reviews and dependency patching

In the unlikely event of a personal-data breach affecting more than 50 users or high-risk data, we will notify affected users and the Indian CERT-In within 6 hours of discovery, as required by CERT-In Directions 2022.

5. Data Retention

Data CategoryRetention Period
Published page content (HTML, images, text)While your account is active; 30 days after deletion
Voice recordingsNot retained — discarded immediately after transcription
Generation logs365 days for cost/quality/fraud analysis; then anonymized
Support conversations2 years from last message
Payment transaction records8 years (Income Tax Act and GST rules)
Anonymous analytics26 months (Google Analytics default)
Feature requests + Founding reservationsUntil Pro ships, then 365 days

Upon verified account deletion request, we remove all personally identifiable information within 30 days, except data we are legally required to retain.

6. Your Rights

Under the DPDP Act 2023, IT Rules 2021, and GDPR (for EU users), you have the following rights:

  • Access — get a copy of the data we hold about you
  • Correction — update inaccurate or outdated information
  • Erasure (deletion) — remove your personal data
  • Portability — receive your data in a machine-readable format
  • Withdraw consent — stop marketing / non-essential processing
  • Restrict processing — pause certain uses of your data
  • Object to processing — object to uses based on legitimate interest
  • Lodge a complaint with a supervisory authority (Data Protection Board of India)

To exercise any of these rights, email pagewala.in@gmail.com. We will respond within 15 working days (DPDP Act) or 30 days (GDPR).

7. Cookies

See our separate Cookie Policy for the full breakdown.

8. Children's Privacy

Pagevala is intended for users aged 13 years or older, per Section 9 of the DPDP Act 2023. We do not knowingly collect data from children under 13. For users aged 13–18, data processing requires verifiable parental consent per DPDP Act Section 9(1). If a parent or guardian becomes aware that a child under 13 has created an account, please contact pagewala.in@gmail.com and we will delete the account and all associated data within 7 working days.

9. International Data Transfers

Some of our service providers (Google Cloud, Cloudinary, MongoDB Atlas) operate servers outside India. When data is transferred internationally, we ensure the receiving party is bound by appropriate safeguards including Standard Contractual Clauses (GDPR Article 46), adequacy agreements, data processing agreements, and encryption in transit and at rest.

10. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be announced via email or in-app banner with at least 14 days' notice. Continued use of Pagevala after the change takes effect constitutes acceptance of the updated policy.

11. Grievance Officer

NameSupport Team
DesignationSupport Team, Amazia Technologies (OPC) Private Limited
Emailpagewala.in@gmail.com
Address180, Gurgaon, Haryana, India – 122018
AcknowledgementWithin 24 hours of receipt
ResolutionWithin 15 working days

Questions about this policy?

Email us at pagewala.in@gmail.com.

Amazia Technologies (OPC) Private Limited · 180, Gurgaon, Haryana, India – 122018