Privacy Policy

How DAASIL collects, uses, and protects information — including data used to publish to connected social media accounts.

Last updated:August 18, 2026
Encrypted, always
AES-256 at rest, TLS/HTTPS in transit — including biometric descriptors and access tokens.
Zero ad tracking
No ad SDKs, no advertising ID, and we never sell data to brokers.
You're in control
Access, export, or delete your data — or withdraw consent — at any time.
DPDP Act aligned
Built around India's Digital Personal Data Protection Act, 2023.

Introduction

This Privacy Policy explains how DAASIL ("we", "us", "the Platform") collects, uses, stores, and protects information across our web dashboard and our Android/iOS app when a business ("Customer") and that Customer's own end-customers, staff, and members use DAASIL. If you are a Customer's member, staff member, or end-customer, your business's own privacy practices apply in addition to this policy — DAASIL acts as a data processor on the Customer's behalf for records they create in the Platform.

Information We Collect

We collect the following categories of information to run the Platform:

  • Account data: Name, email, phone, password (hashed), business/organization details, and role.
  • Member & customer records: Contact details, membership/plan history, attendance, payments, and health/fitness notes a Customer enters, where applicable.
  • Biometric data: Face-recognition descriptors, only where a Customer explicitly enables Face Attendance — see "Biometric Data & Face Attendance" below.
  • Payment data: Transaction references and status from our payment gateway partner; we never store full card, UPI, or bank account numbers.
  • Device & diagnostic data: Device model, OS version, app version, a push-notification subscription ID, IP address, and log data, collected automatically for security, reliability, and notification delivery.
  • Uploaded media: Images, videos, and documents a Customer or their staff uploads (profile photos, invoices, marketing content, etc.).
  • Communications content: The body and delivery status of email, SMS, WhatsApp, and push messages a Customer sends to their own members through the Platform.

Biometric Data & Face Attendance

DAASIL's mobile app requests the Camera permission solely to support Face Attendance — an optional check-in feature a Customer can turn on for their business location. When enabled, the app captures a live camera frame and converts it into a mathematical face descriptor used to match a member at check-in.

  • We do not permanently store the raw camera image, and the feature never uses the microphone.
  • Opt-in per Customer — a business that never enables Face Attendance never triggers a camera prompt, and a member can always check in another way (PIN, card, or manual entry) instead.
  • Face descriptors are encrypted at rest, used only for attendance matching within that Customer’s account, and are never used for advertising, sold, or shared with any third party.
  • A Customer can disable Face Attendance at any time, which stops new captures; anyone can request deletion of stored face descriptors via privacy@daasil.com or our Data Deletion Instructions.

Mobile App Permissions

The DAASIL Android app requests only the permissions it needs to function:

  • Camera: used exclusively for the optional Face Attendance feature described above.
  • Notifications: delivers renewal reminders, alerts, and messages a Customer configures, via our push provider (see "Push Notifications" below).
  • Internet / network state: required for the app to talk to our servers, always over encrypted HTTPS/TLS connections.

We do not request, and cannot access, your device's location, contacts, microphone, call logs, SMS inbox, or photo/media library. Camera and Notification permissions can be reviewed or revoked at any time from Settings > Apps > DAASIL > Permissions.

Social Media Integrations (Facebook & Instagram)

If a Customer connects a Facebook Page and/or linked Instagram Business account through DAASIL's Social Media Manager, we access only what is required to publish content on that Customer's behalf:

  • The Page’s name, ID, and profile picture.
  • The linked Instagram Business account’s ID, username, and profile picture.
  • A Page access token, used solely to publish the posts the Customer creates in DAASIL.

We never read, store, or use a Customer's personal Facebook profile data, friends list, or posts made outside DAASIL. Access tokens are encrypted at rest, are never sent to the browser, and are deleted immediately when a Customer disconnects an account — which they can do at any time from Marketing > Social Media. See our Data Deletion Instructions for how to request removal of this data.

How We Use Information

We use collected information to:

  • Provide and maintain the Platform’s features — member management, billing, communication, reporting, marketing, and social media publishing.
  • Match members at check-in when a Customer enables Face Attendance.
  • Process payments Customers collect from their members.
  • Send transactional notifications — renewal reminders, receipts, OTPs — via email, SMS, WhatsApp, or push, as configured by the Customer.
  • Publish content to a Customer’s connected social accounts, strictly at that Customer’s direction.
  • Diagnose crashes and improve app reliability.
  • Comply with legal obligations.

We do not use any of this information to build advertising profiles.

Push Notifications

DAASIL uses OneSignal, a third-party push notification service, to deliver the notifications described above. To do this, OneSignal assigns your device a push-subscription identifier and processes limited device/network information (such as device type and IP address) needed to route notifications — governed by OneSignal's own privacy policy. You can stop receiving push notifications at any time by disabling notifications for DAASIL in your device settings, or by declining the notification permission prompt.

Payment Processing

Payments a Customer collects from their members are processed through Razorpay, a licensed payment gateway regulated by the Reserve Bank of India. Razorpay handles cardholder and payment-instrument data directly under PCI-DSS standards — DAASIL never sees or stores full card numbers, UPI IDs, or bank account details, and retains only transaction references, amounts, and status for invoicing and reporting.

Data Sharing & Third-Party Service Providers

We do not sell personal data. We share data only as needed to run the Platform, with providers bound by contract to use it solely for the service they perform:

  • Razorpay: payment processing.
  • OneSignal: push notification delivery.
  • Meta Platforms, Inc.: publishing content a Customer authored to their own connected Facebook Page or Instagram account.
  • AWS: our cloud hosting infrastructure, where the Platform and its data are hosted.
  • Email / SMS / WhatsApp delivery providers: used to send the messages a Customer configures.

We may also disclose data to law enforcement or regulators where legally required. Each Customer's data is logically isolated by organization — one Customer can never access another Customer's records, media, or connected social/payment accounts.

Data Security

We protect data with:

  • Encryption in transit — TLS/HTTPS; the mobile app blocks all unencrypted cleartext traffic.
  • Encryption at rest for sensitive fields, including OAuth/social media access tokens (AES-256-GCM) and biometric face descriptors.
  • Access controls — production data access is restricted to authorized personnel and scoped by organization, so Customers can never access each other’s data.

While we work hard to protect information, no method of transmission or storage is 100% secure, and we cannot guarantee absolute security.

Data Retention

We keep data only as long as necessary for the purposes described in this policy:

  • Account & business records: retained while a subscription is active, plus up to 90 days after, to allow reactivation and support, unless earlier deletion is requested.
  • Financial, invoice & payment records: retained for up to 8 years, as required under India's Income Tax Act, 1961 and applicable GST regulations.
  • Social media access tokens: deleted immediately (within minutes) on disconnect.
  • Biometric face descriptors: deleted within 30 days of disabling Face Attendance or removing the member record, or immediately on a verified deletion request.
  • Server & diagnostic logs: retained for up to 12 months for security and troubleshooting, then deleted or anonymized.

A Customer may request earlier deletion of any of the above at any time — see "Account & Data Deletion" below and our Data Deletion Instructions.

International Data Transfers

DAASIL primarily hosts and processes data on cloud infrastructure serving Indian customers. Where a sub-processor listed above (such as OneSignal or Meta) processes data outside India as part of delivering its service, we rely on that provider's own compliance safeguards. We take steps to align our practices with India's Digital Personal Data Protection Act, 2023 (DPDP Act) as it comes into force.

Your Rights & Choices

Subject to applicable law, you may:

  • Request access to, correction of, deletion of, or export of your personal data.
  • Withdraw consent for optional features like Face Attendance at any time.

Customers can manage most member/staff data directly within DAASIL. For account-level requests, or if you are an individual whose data was entered by a Customer, contact us at privacy@daasil.com and we will coordinate with the relevant Customer as needed.

Grievance Officer

In accordance with Rule 5(9) of the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 and Section 13 of the Digital Personal Data Protection Act, 2023, DAASIL has designated a Grievance Officer to address complaints regarding the processing of your personal data, including sensitive personal data such as biometric face descriptors.

Officer
DAASIL Privacy Team
Address
DAASIL HQ, Bengaluru, Karnataka, India
Response time
Acknowledged within 24 hours, resolved within 30 days

Account & Data Deletion

A business Owner can permanently delete their DAASIL account and its data at any time:

  • From the app: Settings > Danger Zone.
  • By email: send privacy@daasil.com from your registered email address with the subject "Data Deletion Request".

This includes any data received via connected Facebook/Instagram accounts. We confirm the request and complete deletion within 30 days, except for records we are legally required to retain (e.g., financial/tax records — see "Data Retention" above). Full steps, including how to revoke DAASIL's access from your Facebook account directly, are on our Data Deletion Instructions page.

Children's Privacy

DAASIL is a business tool intended for use by adults operating a business, and the app is not directed at children. We do not knowingly collect personal data directly from children. Where a Customer (e.g., a sports academy) enters a minor's information as part of managing their own membership records, that Customer is responsible for obtaining appropriate parental/guardian consent under applicable law. See also our Child Safety Standards page.

Advertising & Analytics

DAASIL does not display third-party ads, does not integrate any advertising SDK, and does not use the Google Advertising ID or any similar identifier for ad tracking. We do not sell personal data to advertisers or data brokers.

Google Play Data Safety Summary

This section summarizes our data practices for reference when reviewing Google Play Console's Data Safety form. It's a convenience mapping, not a substitute for the sections above — if the two ever disagree, the detailed sections and the live Play Console form control. "Shared" means sent to a named third-party processor solely for the stated purpose; we never sell data.

What we collect
Name, email, phone number
Collected
Yes
Shared
Not shared
Required
Yes
Account creation & communication
Financial info (transaction ref., amount, status)
Collected
Yes
Shared
Razorpay
Required
For paid features
Payment processing
Photos & videos (profile photos, uploads)
Collected
Yes
Shared
Not shared
Required
Optional
Business records & marketing content
Face descriptor (camera-derived, Face Attendance)
Collected
Only if a Customer opts in
Shared
Not shared
Required
Optional
Member check-in matching
Device / other IDs (push ID, device model, app version)
Collected
Yes
Shared
OneSignal
Required
Optional — notifications can be disabled
Push notification delivery
App activity & performance (crash/diagnostic logs)
Collected
Yes
Shared
Not shared
Required
Yes
Stability, security, bug fixing
Message content (email/SMS/WhatsApp/push you send)
Collected
Yes
Shared
Delivery providers
Required
For messaging features
Sending the messages you configure
What we never collect
Precise or approximate location
Contacts
Microphone / audio
SMS inbox / call logs

Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated through the Platform or via email. Continued use of DAASIL after changes take effect constitutes acceptance of the revised policy.

Contact Us

Questions about this Privacy Policy or your data can be directed to privacy@daasil.com or through our Contact Us page. We aim to respond to privacy inquiries within 7 business days.

Want your data deleted?

See our Data Deletion Instructions for how to request removal of your data, including anything connected through Facebook or Instagram.

Data Deletion Instructions
SparklesSparkles iconTRANSFORM YOUR BUSINESS TODAY

Ready to grow your business?

Start using DAASIL today and manage your entire business from one intelligent platform.

Explore Pricing Plans