Privacy Policy
Last updated: August 15, 2026
1. Introduction
This Privacy Policy describes how DIGISETU SERVICES PRIVATE LIMITED ("we", "us", or "our"), operating under the trade name Digi SetuSeva, collects, uses, stores, and protects information through the Digi SetuSeva platform ("Service").
Digi SetuSeva is a cloud-based government-services management platform designed for Aadhaar Seva Kendra and Aaple Seva Kendra operators ("Operators"). Operators use the Service to manage citizen service applications, documents, and billing on behalf of the citizens they serve. The Service runs as a web application in any modern browser and stores data in a secure, encrypted cloud database.
In this context, Operators are the primary users and data controllers for the citizen data they manage. Digi SetuSeva acts as a data processor, providing the tools and infrastructure for Operators to process citizen information securely.
By accessing or using the Service, you agree to the terms of this Privacy Policy. If you do not agree, please do not use the Service.
2. Information We Collect
2.1 Operator Account Information
When you create an account, we collect:
- Email address
- Password (stored as a one-way PBKDF2-HMAC-SHA512 hash with a per-user random salt and 600,000 iterations; we never store your plaintext password)
- Phone number
- User identifier and assigned role
- Registration, prepaid wallet, and billing status
- WebAuthn/passkey credentials (for passwordless login, if enabled)
- Multi-factor authentication secrets (encrypted)
- Recovery PIN (stored as a one-way hash)
2.2 Google Account Data
If you choose to sign in with Google, we receive:
- Your name, email address, and profile picture URL
- OAuth scopes requested: openid, userinfo.email, and userinfo.profile
If you enable Google Drive backup, we request the drive.file scope, which grants access only to files created by Digi SetuSeva within your Google Drive. We do not access, read, or modify any other files in your Drive.
We do NOT access your Gmail, Google Calendar, Google Contacts, or any other Google service data.
Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
2.3 Family and Citizen Data
Operators enter and manage the following citizen data through the Service. It is held in our managed Supabase (PostgreSQL) database, which is encrypted at rest by the provider, and Row-Level Security restricts each record to the Operator who created it:
- Full name
- Date of birth
- Gender
- Phone number
- Address — state, district, taluka, village
- Aadhaar number — we store only the last four digits, used to tell two people with the same name apart. The full 12-digit Aadhaar number is not stored.
- Operator notes and remarks
2.4 Application and Service Data
- Government service application details and status
- Uploaded documents (encrypted with AES-256-GCM under a unique per-document key before they are stored)
- Bill and payment transaction records
- Receipts and financial summaries
2.5 Technical Data
- Session tokens stored in httpOnly cookies (never in localStorage)
- CSRF tokens for request verification
- Device name, platform, and application version (for sync and audit)
- IP address and user agent (recorded in audit logs only)
We use Google Analytics 4 to understand how our website and application are used — pages visited, approximate location, device and browser type, and anonymous interaction events such as sign-ups, logins, and receipts generated. Google Analytics sets first-party cookies and processes this usage data on our behalf; IP addresses are anonymised by Google and are not stored by us. We never send personally identifiable information — names, Aadhaar numbers, phone numbers, email addresses, or any citizen data — to Google Analytics, and we technically strip such values before any event is sent. We do not use advertising SDKs, advertising pixels, or behavioural-targeting providers.
You can opt out of Google Analytics with the Google Analytics Opt-out Browser Add-on or by blocking analytics cookies in your browser. See Google's Privacy Policy for how Google processes this data.
3. How We Use Your Information
We use the information we collect to:
- Process and manage government service applications on behalf of Operators
- Authenticate Operators and manage role-based access control
- Process registration payments, prepaid wallet top-ups, and usage billing
- Provide secure access to Operator data from any device
- Generate bills, receipts, and financial records
- Perform encrypted document backup (to Google Drive or cloud storage, when enabled)
- Maintain audit logs for security and compliance purposes
- Communicate important service updates and notifications
We do NOT use your data for advertising, user profiling, behavioral targeting, or selling to third parties.
3.1 Legal Basis for Processing
- Operator data: Processed under contractual necessity — to provide and maintain the Service you have subscribed to
- Citizen data: Operators are the data controllers for citizen information. The Company processes citizen data solely as a data processor under the Operator's instructions, as required to deliver the Service
- Audit and security data: Processed under legitimate interest — to protect the security and integrity of the Service and comply with legal obligations
You may withdraw your consent at any time by discontinuing use of the Service and requesting account deletion. Withdrawal of consent does not affect the lawfulness of processing performed prior to withdrawal.
4. Data Storage and Security
4.1 Cloud-Based Architecture
Digi SetuSeva is a cloud-based service. Structured records are stored in a managed Supabase (PostgreSQL) database hosted in the Mumbai, India region, encrypted at rest by the provider and isolated per Operator by Row-Level Security. Uploaded documents and generated receipts are encrypted by us before being written to Cloudflare R2 object storage (see Section 4.2). The Service requires an active internet connection, and data is backed up automatically so it is protected against the loss of any individual device.
4.2 Encryption
We protect data with the following measures:
- Documents at rest: uploaded documents and generated receipts are encrypted with AES-256-GCM under a unique per-document key before they are written to Cloudflare R2. The per-document key is itself encrypted with a separate wrapping key, so the object store never holds a usable key
- Database at rest: the Supabase (PostgreSQL) database is encrypted at rest by the provider, and Row-Level Security ensures an Operator can read only their own records
- Passwords: hashed with PBKDF2-HMAC-SHA512 — 600,000 iterations and a 32-byte random per-user salt — never stored in plaintext
- Aadhaar: only the last four digits are retained; the full number is not stored
- In transit: all communication is encrypted over HTTPS/TLS
4.3 Cloud Storage
Your data is stored across the following managed services:
- Supabase (PostgreSQL, Mumbai region) — structured data with Row-Level Security policies ensuring Operators can only access their own data
- Cloudflare R2 — document and receipt file storage; all files are encrypted by us before upload
4.4 Transport and Application Security
- HTTPS encryption for all network communication
- CSRF protection using the double-submit cookie pattern
- Rate limiting on authentication and sensitive endpoints
- SQL injection filtering and input sanitization
- XSS protection via Helmet.js security headers and content sanitization
- Row-Level Security enforced on all cloud database tables
5. Third-Party Services
We use the following third-party services to operate Digi SetuSeva. Each service receives only the minimum data necessary for its function:
| Service | Purpose | Data Shared |
|---|---|---|
| Google OAuth | Operator authentication | Email, name, profile (received from Google) |
| Google Drive | Optional document backup | Encrypted backup files only (drive.file scope) |
| Supabase | Cloud database and authentication | Operator and citizen records (encrypted at rest, Mumbai/India region) |
| Cloudflare R2 | Document and receipt storage | Encrypted document and receipt files only |
| Email (Gmail API) | Transactional email — sign-in codes, password reset, account notices | Operator email address |
| Sentry | Error monitoring and reliability | Diagnostic error reports. Aadhaar-shaped and phone-number patterns are redacted before any report is sent, and personally identifying request data is switched off. Never used for advertising, profiling, or marketing |
| OpenStreetMap / Nominatim | Map display and address lookup on the Operator's public mini-site | The address or map location the Operator enters for their center |
| Razorpay | Payment processing (registration and wallet top-ups) | Billing details for payment processing |
| WhatsApp / Meta | Sending receipts and service notifications to citizens (see section 5.1) | Citizen's mobile number, name, the service name, the receipt or reference number, and the receipt PDF. Never the Aadhaar number |
| Google Analytics 4 | Website & product usage analytics | Anonymous usage data only — page paths, device/browser, interaction events; never names, Aadhaar, phone, email, or citizen data |
No data is shared with advertising networks or data brokers. The only analytics provider we use is Google Analytics 4, which receives anonymous usage data only (as described above) — never personally identifiable or citizen information.
5.1 WhatsApp Messages to Citizens
Where a citizen has given their mobile number at the center, Digi SetuSeva may send them WhatsApp messages about the service they came for. This section explains exactly what is sent, what reaches Meta, and how to stop it.
Who the message comes from
All messages are sent from a single Digi SetuSeva WhatsApp number on behalf of the center the citizen visited. WhatsApp will therefore show the sender as Digi Setu Seva rather than the center's own name, which is why the center is named inside every message.
What we send
| Message | When | Basis |
|---|---|---|
| Payment receipt, with the receipt PDF attached | When a bill is issued | The transaction the citizen made |
| Documents still needed to complete the work | When the center recorded missing paperwork | The transaction the citizen made |
| Application or document ready to collect | When the application is marked ready | The transaction the citizen made |
| Record of the visit | After a visit | The transaction the citizen made |
| Government scheme and service updates | Only if separately agreed | Explicit consent — never sent without it |
The first four are service messages about work the citizen asked the center to do. The last is promotional and is sent only to citizens who have separately agreed to receive it. Visiting a center is not by itself agreement to receive promotional messages, and we do not treat it as such.
What reaches Meta
To deliver a WhatsApp message, Meta Platforms necessarily receives the citizen's mobile number and the contents of the message: their name, the center's name, the service name, the receipt or reference number, and — for receipts — the PDF itself. Meta's handling of that data is governed by WhatsApp's Privacy Policy.
An Aadhaar number is never included in a WhatsApp message, in the body or in any attachment. For Aadhaar services the message asks the citizen to keep the acknowledgement slip the center gave them, precisely so that no Aadhaar-linked reference has to be transmitted at all.
Receipt PDFs are uploaded to Meta for each individual message and referenced by an internal identifier. They are not published at a public web address.
How to stop the messages
A citizen can reply STOP (or बंद) to any message at any time. This is recorded immediately and stops all further WhatsApp messages from Digi SetuSeva, including service messages. An instruction to stop always overrides any earlier agreement to receive updates. To start again, reply START.
What we keep
For each message we store the recipient's number, which message was sent, its delivery status, and the identifier WhatsApp returns for it — so that a citizen or operator asking "was this actually delivered?" can be answered, and so that requests to stop can be honored and evidenced. We record when consent to receive updates was given and how it was obtained. We do not use WhatsApp data for advertising or profiling, and we do not sell it or share it with anyone beyond what delivery requires.
6. Cookies and Local Storage
We use a minimal set of cookies and local storage, strictly for functionality:
- Authentication token — httpOnly, secure (in production), sameSite: lax. Used to maintain your login session
- CSRF token — double-submit cookie for request verification
- OAuth state nonce — short-lived (10-minute expiry), used during Google sign-in to prevent replay attacks
- localStorage — theme preference and UI state only (no personal data is stored in localStorage)
- Google Analytics cookies (
_ga,_ga_<id>) — first-party analytics cookies set by Google Analytics 4 to measure aggregate website and product usage. They hold a randomly-generated identifier, never your personal information
We do not use advertising cookies or cross-site tracking cookies of any kind. Analytics cookies are limited to Google Analytics as described above; you can block them in your browser without affecting core functionality.
7. Data Retention
- Active accounts: Data is retained for as long as your account is active and you continue to use the Service
- Deleted data: When you delete a family record, the system performs a cascading soft-delete of the family, all members, documents, service applications, and associated notes. Soft-deleted data is permanently purged after 90 days or upon account termination, whichever comes first
- Audit logs: Retained for 24 months from the date of creation for security and compliance purposes, after which they are automatically purged
- Authentication tokens: JWT tokens are short-lived with configurable expiry; refresh tokens have a limited lifetime
- OAuth nonces: Automatically purged after 10 minutes
- Wallet balance: Your account is never locked and your data is never deleted for balance reasons; a low or negative wallet balance only restricts non-essential features until you top up
8. Your Rights
As an Operator, you have the following rights regarding your data:
- Access: You can view all data stored in your account at any time through the application interface
- Correction: You can edit and update family and member records directly within the Service
- Deletion: You can delete family records (cascading deletion of all associated data). To delete your entire account, see how to delete your account & data for the in-app self-service path and the email fallback
- Data Export: You can generate and download your data from within the application
- Withdraw Google Consent: You can disconnect your Google account and revoke Google Drive access at any time through Operator Settings. Upon disconnection, we stop accessing your Google data. Previously backed-up files remain in your Google Drive under your control
- Account Deletion: Upon account deletion, all your data — including any Google account data (name, email, profile picture) — is permanently removed from our systems. Google Drive backup files remain in your Google Drive under your control. See the deletion instructions page for the full step-by-step procedure, what is retained for statutory reasons, and timelines
To exercise any of these rights, contact us at [email protected], or visit our contact page.
9. Children's Privacy
Digi SetuSeva is a business tool designed for government-service Operators. The Service is not directed at individuals under the age of 18. We do not knowingly collect personal information directly from children.
Operators may enter data for minor family members as part of processing government service applications. Such data is protected with the same encryption standards applied to all citizen data within the Service.
10. International Data Transfers
Digi SetuSeva stores Operator and citizen data with managed cloud service providers (including Supabase / PostgreSQL and Cloudflare R2). Depending on the provider's region, data may be processed in data centers located outside India.
All citizen data is encrypted before being transmitted to any cloud service. The encryption keys remain under the Operator's control and are never shared with cloud providers in plaintext.
11. Data Breach Notification
In the event of a personal data breach that may affect your data or the citizen data you manage, we will:
- Notify affected Operators without unreasonable delay upon becoming aware of the breach
- Notify the Data Protection Board of India as required under the Digital Personal Data Protection Act, 2023
- Provide a description of the nature of the breach, the categories of data affected, and the measures taken or proposed to address the breach
- Cooperate with Operators and regulatory authorities in any investigation related to the breach
As data controllers, Operators are responsible for notifying their own data subjects (citizens) of any breach affecting their personal data, in accordance with applicable law.
12. Payment Data
Digi SetuSeva does not store, process, or have access to your payment card details. All payment processing is handled securely by Razorpay, our authorized payment processor, in compliance with applicable payment security standards. Your payment information is subject to Razorpay's Privacy Policy.
13. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or for legal, operational, or regulatory reasons. When we make material changes, we will notify you through the application and update the "Last updated" date at the top of this page.
Your continued use of the Service after any changes constitutes acceptance of the updated Privacy Policy.
14. Grievance Redressal
In accordance with the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, we have appointed a Grievance Officer to address your concerns regarding data processing:
Grievance Officer: Mahesh Rameshrao Tambe
Email: [email protected]
We will acknowledge your grievance within 24 hours and endeavour to resolve it within 30 days of receipt.
15. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or your data, please contact us:
DIGISETU SERVICES PRIVATE LIMITED
Milkat No. 723, Near Jilha M Bank, Paithan, Vihamandwa,
Chhatrapati Sambhajinagar, Maharashtra 431137, India
Email: [email protected]