Privacy Policy
KARVM is a rental-management platform for Indian landlords and their tenants. This policy explains what data we collect, why, how long we keep it, who we share it with, and what you can ask us to do with it.
KARVM is built to align with India's Digital Personal Data Protection Act 2023 (DPDP Act) and safer Aadhaar-handling practices. Production providers encrypt data in transit and at rest. These are engineering controls and programme goals, not a compliance certification.
1 · Who we are
KARVM is operated by Utkarsh Singh, a sole proprietor based in Bangalore, Karnataka, India. The service is reached at karvm.com and karvm.in. For any question about this policy or your data, write to legal@karvm.com.
Because KARVM is a sole-proprietor operation during early access, Utkarsh Singh is also the Grievance Officerfor the purposes of the DPDP Act and India's IT Rules 2021. Grievance contact and response timelines are set out in Section 13.
2 · What we mean by “data”
For clarity, throughout this policy:
- Landlord data — data about the person who owns or manages the rental (the account holder in the landlord app).
- Tenant data — data about the person renting the property, collected by the landlord and made visible to the tenant in the tenant portal.
- Personal data, data principal, data fiduciary, and consent have the meanings given to them by the DPDP Act 2023.
KARVM is the data fiduciary in most contexts. Where a landlord uploads or enters data about a tenant, the landlord is also independently responsible for the lawful basis and accuracy of that data — we act as a processor for the landlord in that specific respect.
3 · What we collect
From landlords (collected when you sign up and use the landlord app):
- Name, email address, mobile number.
- Property details you add — address, unit configuration, rent amounts, due dates, electricity meter numbers.
- Payment records you enter or upload (UPI reference IDs, dates, amounts).
- Legal-notice inputs — the facts you supply when drafting a notice (arrears amount, dates, tenant conduct facts).
- Documents you upload — signed rental agreements, meter photos, tenant KYC scans, PAN cards, and other files the product asks you for.
From tenants (collected via the tenant portal, or entered on your behalf by your landlord):
- Name, mobile number (used to send the OTP for sign-in).
- Full Aadhaar number (12 digits) — required for registered rental agreements and for KYC on the tenant side. See Section 5 for exactly how this is handled.
- Employer / income documentation if the landlord asks for it as part of tenant onboarding.
- Repair-request messages and photos you send through the tenant portal.
Automatic technical data: server logs of your requests (IP address, timestamp, endpoint), your browser user-agent, and error traces. We do not use third-party analytics or advertising trackers. See Section 11.
4 · Why we collect it (purpose & lawful basis)
Every category above has a specific purpose. We do not collect “in case” data.
- Account & identity data — to authenticate you and to identify who owes what to whom.
- Property & tenancy data — to render rent ledgers, generate agreements and notices, split utility bills.
- Payment records — to produce receipts, track dues, and give both parties a shared record.
- Aadhaar — to include the number where Indian law requires it inside registered rental agreements and legal notices (courts and Sub-Registrar offices expect the full number in specific fields).
- Server logs — to keep the service running, debug issues, and defend against abuse.
Our lawful basis is your consent (given by signing up and accepting this policy), contract performance (we need this data to deliver the service you asked for), and compliance with a legal obligation (specifically for Aadhaar in registered agreements and for tax invoices).
5 · Aadhaar handling
Because Aadhaar is one of the most sensitive identifiers KARVM touches, we spell out exactly what happens to it.
- Storage: the full 12-digit Aadhaar number is stored encrypted at rest inside our Supabase database (see Section 6). It never appears in plain text on disk.
- Display in the app UI: the number is always masked — only the last four digits are shown on any dashboard screen, receipt, or exportable CSV.
- Display in generated documents: the full number appears only inside legal documents that Indian law expects it to appear in — specifically registered rental agreements, notices issued under state Rent Acts, and the tenant KYC file that some registration authorities require. These documents are generated on demand, never emailed to third parties automatically, and always passed back through you first.
- No Aadhaar authentication: KARVM does not perform Aadhaar-based authentication (no OTP, biometric, or offline eKYC against UIDAI systems). We only store what the landlord or tenant typed or uploaded to us.
- Deletion: on request, we permanently erase the Aadhaar record from the database and any generated documents that still live in our storage buckets. See Section 12.
6 · Where the data lives
KARVM's primary database and file storage are hosted by Supabase, Inc. in the AWS Asia Pacific (Mumbai) — ap-south-1 region. Serverless functions run in the same region. Data does not leave India as part of normal application storage.
Data may transit outside India when specific features run. Section 7 lists those subprocessors, the data involved, and where each service operates. We review these transfers against applicable Indian law.
Access to landlord data is restricted with database row-level security(RLS). These policies are designed to prevent one account from reading another landlord's rows; we also review application queries and service-role access separately.
7 · Who we share data with (subprocessors)
KARVM does not sell data. The table distinguishes services used today from planned integrations. Each row lists the data involved if that service is enabled and where it runs.
| Subprocessor | What it sees | Where it runs |
|---|---|---|
| Supabase, Inc. | All persistent data — database rows + uploaded files (encrypted at rest). | Mumbai, India (ap-south-1) |
| Vercel, Inc. | Application hosting and request routing. No persistent user data. | India edge, US control plane |
| Anthropic PBC (Claude API) | The specific facts you enter when drafting a legal notice or agreement — see Section 8. | United States |
| Razorpay Software Pvt Ltd | Planned: payment metadata for landlord invoicing. Not tenant rent — rent is paid direct to the landlord. | India |
| Digio (Digital Signatures & Certificates Pvt Ltd) | Planned: documents deliberately sent for Aadhaar eSign or eStamp. | India |
| MSG91 (Walkover Web Solutions) | Phone OTP delivery today; automated WhatsApp or SMS reminders are planned. | India |
| Resend, Inc. | Email addresses and the transactional email body (receipts, alerts). | United States |
We keep this list current. When we add or remove a subprocessor we update this section and note the change in the version history at the top of the page.
8 · AI legal drafting
When you ask KARVM to draft a legal notice, a rental agreement, or a reply to a tenant, we send the specific facts you provided (arrears amount, dates, tenant name, jurisdiction, conduct facts) to Anthropic's Claude API, which returns the draft. This sends the listed drafting facts to a provider in the United States; email delivery may also involve a US provider as described in Section 7.
- We send only the facts required for that specific draft — not your whole account, not your other tenants, not your payment history.
- We use Anthropic's enterprise data policy (zero training on your data, retention limited to what's required to serve the request).
- Every draft is a draft for your review. KARVM never files, serves, sends, or signs a legal document on your behalf. Nothing leaves your account without you (and, we recommend, your advocate) signing off.
9 · Payments and rent
KARVM is nota payment rail for rent. Tenants pay their landlord directly through the same UPI / bank transfer they already use — KARVM records the payment as an event and generates a receipt, but the money never touches KARVM's systems.
If and when we start invoicing landlords for the paid version of KARVM (post early-access), those payments will be processed by Razorpay, whose privacy policy governs the card and UPI credentials you enter on their form. We do not store card numbers, CVVs, or UPI PINs.
10 · How long we keep data
- Active account data: kept for as long as your account is active.
- Rent ledger & receipts: kept for at least 7 years after each entry — the outer edge of what Indian tax and income-tax authorities can request from a landlord.
- Legal notices & agreements: kept for the same duration for the same reason (they are contract and litigation records).
- Aadhaar records: kept only for as long as an active agreement or open litigation references them. On erasure request, purged immediately (see Section 12).
- Server logs: rotated at 90 days.
- Closed accounts: on account closure, we purge personal data within 30 days, except records we are legally required to keep (see the 7-year rule above).
11 · Cookies and tracking
KARVM uses essential cookies only — session cookies for keeping you signed in, and a preference cookie for your light / dark mode choice. We do not use Google Analytics, Meta Pixel, Segment, Mixpanel, or any advertising trackers. We do not build an advertising profile about you.
12 · Your rights under the DPDP Act
As a data principal you have the following rights over your data held by KARVM. You can exercise any of them by writing to legal@karvm.com from the email or phone number associated with your account.
- Right to access — a copy of the personal data we hold about you, in a machine-readable format.
- Right to correction — to correct or update inaccurate data.
- Right to erasure — to have your data permanently deleted (subject to the retention rules in Section 10 where a legal record must be kept).
- Right to grievance redressal — see Section 13.
- Right to nominate — you can nominate someone to exercise your rights on your behalf in the event of your death or incapacity.
- Right to withdraw consent — you can withdraw consent at any time; this will terminate your account. Data retained under Section 10 will remain in cold storage for the legal retention period, encrypted and inaccessible to the running product.
We aim to respond to any of the above requests within 7 working days and to complete the requested action within 30 days of a valid request.
13 · Grievance officer
14 · Security
KARVM's production providers encrypt data in transit and at rest. Auth tokens are short-lived. Every database row is walled off by row-level security so that even our own application code cannot accidentally leak one landlord's data to another. We do not store card numbers, CVVs, or UPI PINs.
No system is unhackable, and any provider claiming otherwise is lying. If we discover a security incident that affects your data, we will notify you and the Data Protection Board of India within the timelines the DPDP Act requires.
15 · Children
KARVM is not directed at children. We do not knowingly collect personal data from anyone under 18. If a landlord adds a minor as a tenant (unusual, but possible in guardian arrangements), the landlord confirms that they are the lawful guardian and have the right to enter that data on the minor's behalf.
16 · International data transfers
International transfers are called out inline where they happen — including Anthropic (US) for AI drafting and Resend (US) for transactional email. Hosting control planes may also process request metadata outside India as listed in Section 7. We review provider locations and any government restrictions before enabling a service.
17 · Changes to this policy
When we make a material change to this policy, we update the version number and effective date at the top of the page, and — for significant changes — email account holders with a summary.
18 · Contact
For any question about this policy, your data, or how KARVM handles it — write to legal@karvm.com. We read every message.