This Privacy Policy explains how MakanVastu.com collects, uses, stores, shares and protects digital personal data. It is intended to support obligations under applicable Indian information technology, data protection and consumer laws, including the Digital Personal Data Protection Act, 2023 and rules brought into force from time to time.
We process data to create and secure accounts; generate and deliver reports; administer subscriptions and payments; provide requested service enquiries; maintain consent and audit evidence; prevent fraud; respond to support and legal requests; improve reliability; comply with law; and send necessary transactional communications. We will seek consent where consent is the applicable basis and provide a clear notice describing the data and purpose.
Registration requires express acceptance of the Terms and Privacy Policy. Checkout separately records acceptance of relevant payment/refund terms. Service requests require contact consent. Consent may be withdrawn for future processing by contacting the grievance channel, but withdrawal will not invalidate lawful processing already undertaken and may make certain requested services unavailable.
The platform is intended for persons legally competent to contract. We do not knowingly permit children to independently purchase services. Where applicable law requires verifiable parental consent or restricts tracking/targeted advertising involving children, such processing must not be undertaken without required safeguards.
Data may be shared only as reasonably necessary with payment gateways, hosting/database providers, communication/support vendors, professional/service partners, auditors/advisers, and government or law-enforcement authorities where legally required. For a map-category purchase, checkout separately asks for consent to the exclusive partner-enquiry workflow. Before a partner purchases the enquiry, approved partners receive only the customer name and selected map category; the customer phone and email are not included in that marketplace response. After one approved partner pays the recorded unlock price through the MakanVastu Credits, contact details are disclosed only to that partner and the enquiry is removed from availability for all other partners. Partners must use the contact only for the stated service follow-up and must not resell, redistribute or use it for unrelated marketing.
Partner documents are not publicly listed. They are accessible only to the submitting Partner, authorised personnel and service providers or authorities with a lawful need. Files may be used for identity, licence, fraud, risk, complaint and re-verification purposes. Partners should submit masked identifiers where full identifiers are unnecessary and must not upload an unmasked Aadhaar number, passwords, OTP, CVV or payment PIN.
For an active supported project, the Partner may upload work photos/videos, written notes, precise latitude/longitude, location accuracy, device capture time, file name/type/size, cryptographic hash, IP address and browser/device metadata. This information is used for project timelines, customer review, fraud prevention, milestone decisions, complaints and legal compliance. It is visible only to the project Customer, assigned Partner and authorised personnel/service providers. Camera and GPS metadata are integrity aids and not conclusive proof of identity, location, quality or completion.
Partners must obtain any necessary permission before recording workers, neighbours or private property and must avoid capturing unrelated personal information. The platform applies an evidence-retention period and should securely delete or anonymise data when it is no longer required, subject to dispute, accounting and legal retention duties.
Technology vendors may process data in locations permitted under applicable law and contractual safeguards. MakanVastu.com reviews vendor locations and applicable government restrictions before production deployment.
Data is retained only for as long as reasonably necessary for the stated purpose, contractual service, dispute handling, accounting/tax, fraud prevention, statutory limitation and legal compliance. Illustrative production schedules should be formally approved by the business: active account/project records during the relationship; transaction/tax records for the legally required period; security logs for a proportionate period; and consent/legal acceptance evidence for the applicable claim/limitation period.
The application uses password hashing, secure sessions, CSRF controls, rate limiting, security headers, role-based access, audit logging and encryption for configured gateway secrets. No system is absolutely secure. Users should use unique passwords and promptly report suspected compromise. The production operator must maintain backups, access review, vulnerability patching, incident response and vendor security governance.
Where a personal data breach occurs, MakanVastu.com will assess, contain, document and notify affected persons and the competent authority/board as required by applicable law and prescribed timelines/content.
Subject to applicable law and verification, you may request access to a summary of your personal data and processing, correction/completion/update, erasure where retention is no longer required, withdrawal of consent, grievance redressal and nomination where applicable. Requests may be declined or limited where retention/processing is required by law, fraud prevention, contract, dispute or other lawful grounds.
Essential session cookies are used to authenticate users, protect forms and maintain security. Non-essential analytics/advertising cookies should not be activated in production without an appropriate notice/consent mechanism where required.
Privacy requests may be submitted through the contact form. They may also be sent to grievance@makanvastu.com. Grievance Officer: Ananya Mukherjee. Phone: 011 6965 6883. Corporate office: Sector 15 Part 2, Gurugram, Haryana 122007, India. We may request reasonable information to verify identity before acting on a request.
Changes will be published with a revised version and date. Where legally required, a fresh notice or consent will be obtained.
Partner profile information selected for public display may include business name, category, description, service areas, city/state, logo and optional contact details. Private KYC and verification documents are not published. Customer directory enquiries are shared with the selected listed provider only for responding to the stated requirement, platform safety, dispute handling and lawful compliance. Listing data must not be scraped, sold or used for unrelated marketing.
On first use, the platform may ask the user to choose whether to allow general device location, save a manual state/district/city preference, or continue without device location. General browsing is available after a choice is recorded. IP address and basic request metadata may be processed automatically for security, abuse prevention and audit logs. Precise GPS and current-camera evidence are requested separately only for disclosed partner-onboarding or project-site verification workflows and require express consent.
Current partner photographs, coordinates, accuracy, hash, IP and device metadata are restricted verification evidence. They are not public profile content. Access is limited to authorised personnel and service providers with a need to know. Disclosure to police, courts, regulators or another authority is made only where required or permitted by applicable law, a valid legal request, or a documented fraud/safety investigation.
Directory results may be prioritised using a user-selected location, partner-approved district, service radius, service categories and active sponsored campaign. Sponsored placement is labelled. Location data is not sold to partners. A sponsored campaign does not authorise unrelated marketing or remove the partner's duty to use customer data only for the stated enquiry.
The website assistant uses a limited, platform-specific rules and content library to answer questions about MakanVastu.com. The deterministic menu remains available without an external AI service. Where the optional Google Gemini fallback is enabled, a general question may be sent from our server to Google after high-risk secret screening and sanitisation of common email, mobile and identity-number patterns. We do not intentionally send chatbot history, KYC files, precise GPS, private dashboard records, quotation documents or payment credentials to Gemini. Automated screening is not perfect, so users must not enter passwords, OTPs, PINs, CVV, API keys, bank/card details, Aadhaar/PAN details or unnecessary personal information in the assistant. When a conversation requires human support, the assistant may collect the minimum contact details and create a support request only after the user confirms contact and ticket-processing consent. A limited conversation summary may be attached to that request. The assistant is not a legal, structural, architectural, financial or government-approval adviser.
For Partner accounts, we may keep the accepted Partner Agreement version, acceptance time, IP address, device information, membership reference, quotation versions, customer dashboard decisions, category/coverage requests, advertising requests, Business Listing change requests, current and proposed data snapshots, supporting proofs, Admin decisions and related notifications. These records support account security, traceability, service administration, complaint handling, fraud prevention and lawful audit. A customer quotation decision is shown in the dashboard and does not cause the quotation to be emailed by the platform.
Where the Partner-only security control is enabled, correct credentials are followed by a separate current-location notice and consent. We may record latitude, longitude, accuracy, timestamp, IP address, user-agent and whether the location step was accepted. This data is used for account-security investigation and audit; it is not treated as proof of identity, attendance or service delivery. An authorised Admin may record a time-limited exemption and reason. General customer login is not subject to this requirement.
Partner KYC, category, address and listing proofs are not public. Supported uploads are encrypted at rest, integrity-hashed and served with private/no-store controls. Authorised Admin reviewers may open and manually read a document, record a structured summary and decide pending, verified or rejected status. The review is an internal platform check and not government authentication or legal certification. If a document is rejected, a corrected replacement may be uploaded. The prior version may remain marked as replaced for audit, complaint, fraud-prevention and legal-retention purposes until retention review.
Current-camera evidence is used for Partner onboarding and safety review after express consent. The system checks allowed image-file content and integrity. An authorised reviewer records only whether one clear human face is present, no face is present, multiple faces appear or the image is unclear. We do not infer or record whether the person is a man or woman, and this workflow does not perform biometric face matching. Current-camera evidence is private and is not used as a public profile photograph unless a separate lawful upload and display choice exists.
We use proportionate technical and organisational safeguards such as access control, password hashing, encryption for supported private files, integrity hashes, audit logs, rate limits and restricted review. No online system can guarantee that a breach will never occur. Suspected incidents are assessed, contained, logged and reported or notified where applicable law requires it. Users should upload only necessary information, use masked identity documents where suitable, protect credentials and promptly report suspected misuse.
This Policy is governed by applicable Indian law. Subject to mandatory consumer forums, statutory authorities and other non-waivable rights, platform disputes are subject to courts of competent jurisdiction at Patna, Bihar. This clause does not restrict a data principal's right to use any regulator, Board, court or grievance channel available under applicable law.