Policy
Privacy Policy
Last updated 12 August 2026
This policy is published under the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and is written to align with the Digital Personal Data Protection Act, 2023 as its provisions come into force.
Who we are
Pakka is a sole proprietorship registered in India (an Udyam-registered micro enterprise), operated by Apoorv Saraogee.
Two kinds of people
Pakka handles information about two groups, and the relationship is different for each.
Businesses that subscribe to Pakka
We are the data fiduciary. We decide what is collected and why.
Customers of those businesses
We are a data processor acting on the instructions of the business. The business decides what is collected and is responsible for informing its own customers. If you are a customer of a business using Pakka, contact that business first; we will also act on a request sent directly to us.
What we collect
| Information | Why |
|---|---|
| WhatsApp phone number | To identify who is booking and send the confirmation |
| Name, where given | So the business can recognise the booking |
| Message content | To understand the booking request and reply to it |
| Booking details — date, time, service, resource, amount | To operate the calendar and generate the payment link |
| Payment reference | To match an advance to a booking. We never see card, bank, or UPI credentials. |
| Subscriber contact and billing details | To run and invoice the subscription |
We do not collect location, contacts, photos, or device identifiers. We do not knowingly collect information about children. We do not buy personal information from anyone.
What we never touch
Payments made by a customer go directly to the business's own UPI ID. Pakka does not receive, hold, or route funds, and never has access to a UPI PIN, card number, bank login, or any other payment credential.
Who else sees it
- WhatsApp / Meta — messages are delivered over the WhatsApp Business Platform and are subject to Meta's own terms.
- Our hosting provider — data is stored on servers we rent.
- A language processing provider — message text may be sent to a third-party model to interpret a booking request written in Hindi or Hinglish.
- Our payment gateway — for subscription billing only.
We do not sell personal information, and we do not share it for advertising. Information is disclosed to a government authority only where the law requires it.
How long we keep it
Booking and message records are retained for 36 months from the date of the booking, then deleted. Invoices and payment records are kept for 8 years, which is the period the Income Tax Act requires. Records are deleted sooner on a valid erasure request.
Your rights
- Ask what we hold about you
- Have it corrected
- Have it erased
- Withdraw consent, which stops further processing
- Complain to the Grievance Officer, and to the Data Protection Board of India once it is constituted
To exercise any of these, email apoorv@outlook.com from the address or number on the account, or send MITAO (मिटाओ) on WhatsApp to the business you booked with. We acknowledge within 48 hours and complete the request within 30 days.
Erasure removes your name, phone number, and message content. A booking record may be retained in anonymised form where the business needs it for its own accounts.
Security
Data is transmitted over TLS and stored on access-controlled servers. Access is limited to the proprietor. We will notify affected users and the relevant authority of any personal data breach without undue delay.
Changes
Material changes to this policy are notified to subscribers by email at least 14 days before they take effect. The date at the top of this page always reflects the current version.
Grievance Officer
Apoorv Saraogee
Grievance Officer, Pakka
apoorv@outlook.com