Data Protection & Privacy Policy

Privacy Policy

Last updated: October 2026 · Committed to user privacy, transparent records, and zero data monetization.

Our Core Privacy Commitments

No Financial or Banking Data Collected

Because Chitti is purely an informational record-keeping ledger without in-app transactions, we never ask for, process, or store credit/debit card numbers, bank account passwords, or UPI PINs.

We Never Sell or Rent Your Data

Your group information and member lists are strictly used to render your administrative dashboard. We do not sell data to brokers, advertising networks, or third-party marketers.

1. Information We Collect

To provide the record-keeping and group administration service, Chitti processes the following categories of information:

  • Authentication Data: Email address, cryptographically hashed passwords, and system authorization roles (administrator, collection agent, member).
  • Ledger & Member Records: Information entered directly by group administrators, such as member full name, phone number, residential or business city/state, postal pincode, assigned member code, and optional administrative notes.
  • Group & Bidding Configuration: Group name, group code, monthly installment amounts, total cycle counts, auction frequency, minimum ghata rules, commission rates, and collection schedules.
  • Administrative Payment Logs: Manual status logs indicating whether a member has cleared an offline installment, recorded date, payment mode reference text (e.g. “Cash” or “UPI ref: 12345”), and collector name.
  • Device & Preference Data: Selected interface language (English, Hindi, Hinglish, Kannada), local UI settings, and standard server connection logs (IP address, browser type).

2. Explicit Non-Collection of Financial Credentials

Because Chitti is strictly a record-keeping ledger without in-app monetary transactions:

  • We do NOT collect, transmit, or store credit or debit card numbers, CVVs, or expiration dates.
  • We do NOT collect bank account internet banking passwords or OTPs.
  • We do NOT collect UPI MPINs or biometric payment authorizations.
  • We do NOT hold or manage user wallet balances or bank balances.

3. How We Use Collected Information

We use your information exclusively to provide and maintain the software service:

  • To display group dashboards, cycle payment tallies, and member contribution histories.
  • To compute transparent mathematical calculations for auction dividend savings, ghata splits, and net payouts based on user-entered rules.
  • To enable administrators to issue member invitation links, login credentials, and digital receipt summaries.
  • To assist users in generating templated WhatsApp or SMS reminder texts (triggered directly by the user from their own device).
  • To maintain system stability, troubleshoot application bugs, and prevent unauthorized intrusion or abuse.

4. Data Sharing & Non-Disclosure

We do NOT sell, lease, or monetize your personal information or member lists to third parties for marketing or advertising purposes.

Information is only shared under the following limited conditions:

  • Within Your Group: Members of an enrolled committee group can see authorized ledger entries (such as group schedules, winner announcements, and payment status) according to their assigned role.
  • Infrastructure Service Providers: Trusted cloud infrastructure vendors (e.g. Supabase for database hosting, Vercel for web hosting) that process data under strict data privacy and security obligations.
  • Legal Requirements: If compelled by an official court order, law enforcement subpoena, or applicable statutory mandate under governing law.

5. Security, Row Level Security & Encryption

We implement rigorous technical and organizational measures to safeguard your records:

  • HTTPS / TLS Encryption: All communications between your web browser or mobile device and our servers are encrypted using modern Transport Layer Security (TLS/HTTPS).
  • PostgreSQL Row Level Security (RLS): Our database employs granular database-level Row Level Security policies ensuring that users can only view or modify records belonging to groups they are authorized to access.
  • Hashed Authentication: Passwords are protected using one-way cryptographic hashing algorithms and are never stored in plaintext.

6. Third-Party Messaging & Notifications

When an organizer triggers a “Send Receipt via WhatsApp” or “Payment Reminder” action, Chitti formats a pre-filled message URL that launches your installed messaging app (e.g. WhatsApp or SMS). Chitti does not directly read your private chat messages or inspect your external messaging contacts.

7. Data Retention & Account Deletion

Ledger records are retained for as long as the group account remains active so organizers and members can audit completed cycles.

Right to Deletion: Group administrators may delete groups or member records at any time from the settings or group management panels. You may also contact our support team to request permanent deletion of your account and associated database records.

8. Contact & Grievance Redressal

For questions regarding this Privacy Policy, your personal data, or to exercise your privacy rights, please reach out to:

Chitti Privacy & Data Protection

Email: privacy@chitti.app

General Support: support@chitti.app

Platform: https://chitti.app