Privacy Policy
How DAASIL collects, uses, and protects information — including data used to publish to connected social media accounts.
Introduction
This Privacy Policy explains how DAASIL ("we", "us", "the Platform") collects, uses, stores, and protects information across our web dashboard and our Android/iOS app when a business ("Customer") and that Customer's own end-customers, staff, and members use DAASIL. If you are a Customer's member, staff member, or end-customer, your business's own privacy practices apply in addition to this policy — DAASIL acts as a data processor on the Customer's behalf for records they create in the Platform.
Information We Collect
We collect the following categories of information to run the Platform:
- Account data: Name, email, phone, password (hashed), business/organization details, and role.
- Member & customer records: Contact details, membership/plan history, attendance, payments, and health/fitness notes a Customer enters, where applicable.
- Biometric data: Face-recognition descriptors, only where a Customer explicitly enables Face Attendance — see "Biometric Data & Face Attendance" below.
- Payment data: Transaction references and status from our payment gateway partner; we never store full card, UPI, or bank account numbers.
- Device & diagnostic data: Device model, OS version, app version, a push-notification subscription ID, IP address, and log data, collected automatically for security, reliability, and notification delivery.
- Uploaded media: Images, videos, and documents a Customer or their staff uploads (profile photos, invoices, marketing content, etc.).
- Communications content: The body and delivery status of email, SMS, WhatsApp, and push messages a Customer sends to their own members through the Platform.
Biometric Data & Face Attendance
DAASIL's mobile app requests the Camera permission solely to support Face Attendance — an optional check-in feature a Customer can turn on for their business location. When enabled, the app captures a live camera frame and converts it into a mathematical face descriptor used to match a member at check-in.
- We do not permanently store the raw camera image, and the feature never uses the microphone.
- Opt-in per Customer — a business that never enables Face Attendance never triggers a camera prompt, and a member can always check in another way (PIN, card, or manual entry) instead.
- Face descriptors are encrypted at rest, used only for attendance matching within that Customer’s account, and are never used for advertising, sold, or shared with any third party.
- A Customer can disable Face Attendance at any time, which stops new captures; anyone can request deletion of stored face descriptors via privacy@daasil.com or our Data Deletion Instructions.
Mobile App Permissions
The DAASIL Android app requests only the permissions it needs to function:
- Camera: used exclusively for the optional Face Attendance feature described above.
- Notifications: delivers renewal reminders, alerts, and messages a Customer configures, via our push provider (see "Push Notifications" below).
- Internet / network state: required for the app to talk to our servers, always over encrypted HTTPS/TLS connections.
We do not request, and cannot access, your device's location, contacts, microphone, call logs, SMS inbox, or photo/media library. Camera and Notification permissions can be reviewed or revoked at any time from Settings > Apps > DAASIL > Permissions.
How We Use Information
We use collected information to:
- Provide and maintain the Platform’s features — member management, billing, communication, reporting, marketing, and social media publishing.
- Match members at check-in when a Customer enables Face Attendance.
- Process payments Customers collect from their members.
- Send transactional notifications — renewal reminders, receipts, OTPs — via email, SMS, WhatsApp, or push, as configured by the Customer.
- Publish content to a Customer’s connected social accounts, strictly at that Customer’s direction.
- Diagnose crashes and improve app reliability.
- Comply with legal obligations.
We do not use any of this information to build advertising profiles.
Push Notifications
DAASIL uses OneSignal, a third-party push notification service, to deliver the notifications described above. To do this, OneSignal assigns your device a push-subscription identifier and processes limited device/network information (such as device type and IP address) needed to route notifications — governed by OneSignal's own privacy policy. You can stop receiving push notifications at any time by disabling notifications for DAASIL in your device settings, or by declining the notification permission prompt.
Payment Processing
Payments a Customer collects from their members are processed through Razorpay, a licensed payment gateway regulated by the Reserve Bank of India. Razorpay handles cardholder and payment-instrument data directly under PCI-DSS standards — DAASIL never sees or stores full card numbers, UPI IDs, or bank account details, and retains only transaction references, amounts, and status for invoicing and reporting.
Data Sharing & Third-Party Service Providers
We do not sell personal data. We share data only as needed to run the Platform, with providers bound by contract to use it solely for the service they perform:
- Razorpay: payment processing.
- OneSignal: push notification delivery.
- Meta Platforms, Inc.: publishing content a Customer authored to their own connected Facebook Page or Instagram account.
- AWS: our cloud hosting infrastructure, where the Platform and its data are hosted.
- Email / SMS / WhatsApp delivery providers: used to send the messages a Customer configures.
We may also disclose data to law enforcement or regulators where legally required. Each Customer's data is logically isolated by organization — one Customer can never access another Customer's records, media, or connected social/payment accounts.
Data Security
We protect data with:
- Encryption in transit — TLS/HTTPS; the mobile app blocks all unencrypted cleartext traffic.
- Encryption at rest for sensitive fields, including OAuth/social media access tokens (AES-256-GCM) and biometric face descriptors.
- Access controls — production data access is restricted to authorized personnel and scoped by organization, so Customers can never access each other’s data.
While we work hard to protect information, no method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
Data Retention
We keep data only as long as necessary for the purposes described in this policy:
- Account & business records: retained while a subscription is active, plus up to 90 days after, to allow reactivation and support, unless earlier deletion is requested.
- Financial, invoice & payment records: retained for up to 8 years, as required under India's Income Tax Act, 1961 and applicable GST regulations.
- Social media access tokens: deleted immediately (within minutes) on disconnect.
- Biometric face descriptors: deleted within 30 days of disabling Face Attendance or removing the member record, or immediately on a verified deletion request.
- Server & diagnostic logs: retained for up to 12 months for security and troubleshooting, then deleted or anonymized.
A Customer may request earlier deletion of any of the above at any time — see "Account & Data Deletion" below and our Data Deletion Instructions.
International Data Transfers
DAASIL primarily hosts and processes data on cloud infrastructure serving Indian customers. Where a sub-processor listed above (such as OneSignal or Meta) processes data outside India as part of delivering its service, we rely on that provider's own compliance safeguards. We take steps to align our practices with India's Digital Personal Data Protection Act, 2023 (DPDP Act) as it comes into force.
Your Rights & Choices
Subject to applicable law, you may:
- Request access to, correction of, deletion of, or export of your personal data.
- Withdraw consent for optional features like Face Attendance at any time.
Customers can manage most member/staff data directly within DAASIL. For account-level requests, or if you are an individual whose data was entered by a Customer, contact us at privacy@daasil.com and we will coordinate with the relevant Customer as needed.
Consent Withdrawal & Grievance Redressal
You may withdraw consent for any optional processing — such as Face Attendance, marketing messages, or a connected social media integration — at any time, as easily as you gave it; withdrawal takes effect going forward and does not affect processing already carried out.
Under India's Digital Personal Data Protection Act, 2023, you also have the right to nominate another individual to exercise your rights under this policy on your behalf in the event of your death or incapacity — contact privacy@daasil.com to register a nominee.
If your grievance is not adequately resolved by our Grievance Officer (below) within the stated timeline, you may escalate your complaint to the Data Protection Board of India once constituted under the DPDP Act, or to any other competent authority under applicable law.
Grievance Officer
In accordance with Rule 5(9) of the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 and Section 13 of the Digital Personal Data Protection Act, 2023, DAASIL has designated a Grievance Officer to address complaints regarding the processing of your personal data, including sensitive personal data such as biometric face descriptors.
- Officer
- DAASIL Privacy Team
- privacy@daasil.com
- Address
- DAASIL HQ, Bengaluru, Karnataka, India
- Response time
- Acknowledged within 24 hours, resolved within 30 days
Account & Data Deletion
A business Owner can permanently delete their DAASIL account and its data at any time:
- From the app: Settings > Danger Zone.
- By email: send privacy@daasil.com from your registered email address with the subject "Data Deletion Request".
This includes any data received via connected Facebook/Instagram accounts. We confirm the request and complete deletion within 30 days, except for records we are legally required to retain (e.g., financial/tax records — see "Data Retention" above). Full steps, including how to revoke DAASIL's access from your Facebook account directly, are on our Data Deletion Instructions page.
Children's Privacy
DAASIL is a business tool intended for use by adults operating a business, and the app is not directed at children. We do not knowingly collect personal data directly from children. Where a Customer (e.g., a sports academy) enters a minor's information as part of managing their own membership records, that Customer is responsible for obtaining appropriate parental/guardian consent under applicable law. See also our Child Safety Standards page.
Advertising & Analytics
DAASIL does not display third-party ads, does not integrate any advertising SDK, and does not use the Google Advertising ID or any similar identifier for ad tracking. We do not sell personal data to advertisers or data brokers.
Google Play Data Safety Summary
This section summarizes our data practices for reference when reviewing Google Play Console's Data Safety form. It's a convenience mapping, not a substitute for the sections above — if the two ever disagree, the detailed sections and the live Play Console form control. "Shared" means sent to a named third-party processor solely for the stated purpose; we never sell data.
- Collected
- Yes
- Shared
- Not shared
- Required
- Yes
- Collected
- Yes
- Shared
- Razorpay
- Required
- For paid features
- Collected
- Yes
- Shared
- Not shared
- Required
- Optional
- Collected
- Only if a Customer opts in
- Shared
- Not shared
- Required
- Optional
- Collected
- Yes
- Shared
- OneSignal
- Required
- Optional — notifications can be disabled
- Collected
- Yes
- Shared
- Not shared
- Required
- Yes
- Collected
- Yes
- Shared
- Delivery providers
- Required
- For messaging features
Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated through the Platform or via email. Continued use of DAASIL after changes take effect constitutes acceptance of the revised policy.
Contact Us
Questions about this Privacy Policy or your data can be directed to privacy@daasil.com or through our Contact Us page. We aim to respond to privacy inquiries within 7 business days.
Want your data deleted?
See our Data Deletion Instructions for how to request removal of your data, including anything connected through Facebook or Instagram.
Data Deletion Instructions
Social Media Integrations (Facebook & Instagram)
If a Customer connects a Facebook Page and/or linked Instagram Business account through DAASIL's Social Media Manager, we access only what is required to publish content on that Customer's behalf:
We never read, store, or use a Customer's personal Facebook profile data, friends list, or posts made outside DAASIL. Access tokens are encrypted at rest, are never sent to the browser, and are deleted immediately when a Customer disconnects an account — which they can do at any time from Marketing > Social Media. See our Data Deletion Instructions for how to request removal of this data.