Privacy Policy
KARVM is a rental-management platform for Indian landlords and their tenants. This policy explains what data we collect, why, how long we keep it, who we share it with, and what you can ask us to do with it.
KARVM is built to align with India's Digital Personal Data Protection Act 2023 (DPDP Act), UIDAI guidelines for Aadhaar handling, and bank-grade encryptionstandards for data in transit and at rest. This isn't marketing language — every claim in this policy is grounded in an architectural choice you can hold us to.
1 · Who we are
KARVM is operated by Utkarsh Singh, a sole proprietor based in Bangalore, Karnataka, India. The service is reached at karvm.com and karvm.in. For any question about this policy or your data, write to legal@karvm.com.
Because KARVM is a sole-proprietor operation during early access, Utkarsh Singh is also the Grievance Officerfor the purposes of the DPDP Act and India's IT Rules 2021. Grievance contact and response timelines are set out in Section 13.
2 · What we mean by “data”
For clarity, throughout this policy:
- Landlord data — data about the person who owns or manages the rental (the account holder in the landlord app).
- Tenant data — data about the person renting the property, collected by the landlord and made visible to the tenant in the tenant portal.
- Personal data, data principal, data fiduciary, and consent have the meanings given to them by the DPDP Act 2023.
KARVM is the data fiduciary in most contexts. Where a landlord uploads or enters data about a tenant, the landlord is also independently responsible for the lawful basis and accuracy of that data — we act as a processor for the landlord in that specific respect.
3 · What we collect
From landlords (collected when you sign up and use the landlord app):
- Name, email address, mobile number.
- Property details you add — address, unit configuration, rent amounts, due dates, electricity meter numbers.
- Payment records you enter or upload (UPI reference IDs, dates, amounts).
- Legal-notice inputs — the facts you supply when drafting a notice (arrears amount, dates, tenant conduct facts).
- Documents you upload — signed rental agreements, meter photos, tenant KYC scans, PAN cards, and other files the product asks you for.
From tenants (collected via the tenant portal, or entered on your behalf by your landlord):
- Name, mobile number (used to send the OTP for sign-in).
- Full Aadhaar number (12 digits) — required for registered rental agreements and for KYC on the tenant side. See Section 5 for exactly how this is handled.
- Employer / income documentation if the landlord asks for it as part of tenant onboarding.
- Repair-request messages and photos you send through the tenant portal.
Automatic technical data: server logs of your requests (IP address, timestamp, endpoint), your browser user-agent, and error traces. We do not use third-party analytics or advertising trackers. See Section 11.
4 · Why we collect it (purpose & lawful basis)
Every category above has a specific purpose. We do not collect “in case” data.
- Account & identity data — to authenticate you and to identify who owes what to whom.
- Property & tenancy data — to render rent ledgers, generate agreements and notices, split utility bills.
- Payment records — to produce receipts, track dues, and give both parties a shared record.
- Aadhaar — to include the number where Indian law requires it inside registered rental agreements and legal notices (courts and Sub-Registrar offices expect the full number in specific fields).
- Server logs — to keep the service running, debug issues, and defend against abuse.
Our lawful basis is your consent (given by signing up and accepting this policy), contract performance (we need this data to deliver the service you asked for), and compliance with a legal obligation (specifically for Aadhaar in registered agreements and for tax invoices).
5 · Aadhaar handling
Because Aadhaar is one of the most sensitive identifiers KARVM touches, we spell out exactly what happens to it.
- Storage: the full 12-digit Aadhaar number is stored encrypted at rest inside our Supabase database (see Section 6). It never appears in plain text on disk.
- Display in the app UI: the number is always masked — only the last four digits are shown on any dashboard screen, receipt, or exportable CSV.
- Display in generated documents: the full number appears only inside legal documents that Indian law expects it to appear in — specifically registered rental agreements, notices issued under state Rent Acts, and the tenant KYC file that some registration authorities require. These documents are generated on demand, never emailed to third parties automatically, and always passed back through you first.
- No Aadhaar authentication: KARVM does not perform Aadhaar-based authentication (no OTP, biometric, or offline eKYC against UIDAI systems). We only store what the landlord or tenant typed or uploaded to us.
- Deletion: on request, we permanently erase the Aadhaar record from the database and any generated documents that still live in our storage buckets. See Section 12.
6 · Where the data lives
KARVM's primary database and file storage are hosted by Supabase, Inc. in the AWS Asia Pacific (Mumbai) — ap-south-1 region. Serverless functions run in the same region. Data does not leave India as part of normal application storage.
Data may transit outside India transiently when specific features run — see Section 7 for the exact subprocessor list, what they see, and why. Where any subprocessor sits outside India, that is a necessary international transfer under Section 16 of the DPDP Act.
Every database row is walled off by row-level security (RLS) enforced by the database itself. This is architectural, not policy: another landlord literally cannot construct a query that returns your rows.
7 · Who we share data with (subprocessors)
KARVM does not sell data. We use the following third-party services to run the product. Each row lists what they see and where they run.
| Subprocessor | What it sees | Where it runs |
|---|---|---|
| Supabase, Inc. | All persistent data — database rows + uploaded files (encrypted at rest). | Mumbai, India (ap-south-1) |
| Vercel, Inc. | Application hosting and request routing. No persistent user data. | India edge, US control plane |
| Anthropic PBC (Claude API) | The specific facts you enter when drafting a legal notice or agreement — see Section 8. | United States |
| Razorpay Software Pvt Ltd | Payment metadata for landlord invoicing (post early-access). Not tenant rent — rent is paid direct to the landlord. | India |
| Digio (Digital Signatures & Certificates Pvt Ltd) | Documents you send for e-sign (Aadhaar eSign / eStamp). | India |
| MSG91 (Walkover Web Solutions) | Phone numbers, and the WhatsApp / SMS message text (rent reminders, OTP codes). | India |
| Resend, Inc. | Email addresses and the transactional email body (receipts, alerts). | United States |
We keep this list current. When we add or remove a subprocessor we update this section and note the change in the version history at the top of the page.
8 · AI legal drafting
When you ask KARVM to draft a legal notice, a rental agreement, or a reply to a tenant, we send the specific facts you provided (arrears amount, dates, tenant name, jurisdiction, conduct facts) to Anthropic's Claude API, which returns the draft. This is the only time your data leaves India during normal use, and it is a necessary international transfer under the DPDP Act.
- We send only the facts required for that specific draft — not your whole account, not your other tenants, not your payment history.
- We use Anthropic's enterprise data policy (zero training on your data, retention limited to what's required to serve the request).
- Every draft is a draft for your review. KARVM never files, serves, sends, or signs a legal document on your behalf. Nothing leaves your account without you (and, we recommend, your advocate) signing off.
9 · Payments and rent
KARVM is nota payment rail for rent. Tenants pay their landlord directly through the same UPI / bank transfer they already use — KARVM records the payment as an event and generates a receipt, but the money never touches KARVM's systems.
If and when we start invoicing landlords for the paid version of KARVM (post early-access), those payments will be processed by Razorpay, whose privacy policy governs the card and UPI credentials you enter on their form. We do not store card numbers, CVVs, or UPI PINs.
10 · How long we keep data
- Active account data: kept for as long as your account is active.
- Rent ledger & receipts: kept for at least 7 years after each entry — the outer edge of what Indian tax and income-tax authorities can request from a landlord.
- Legal notices & agreements: kept for the same duration for the same reason (they are contract and litigation records).
- Aadhaar records: kept only for as long as an active agreement or open litigation references them. On erasure request, purged immediately (see Section 12).
- Server logs: rotated at 90 days.
- Closed accounts: on account closure, we purge personal data within 30 days, except records we are legally required to keep (see the 7-year rule above).
11 · Cookies and tracking
KARVM uses essential cookies only — session cookies for keeping you signed in, and a preference cookie for your light / dark mode choice. We do not use Google Analytics, Meta Pixel, Segment, Mixpanel, or any advertising trackers. We do not build an advertising profile about you.
12 · Your rights under the DPDP Act
As a data principal you have the following rights over your data held by KARVM. You can exercise any of them by writing to legal@karvm.com from the email or phone number associated with your account.
- Right to access — a copy of the personal data we hold about you, in a machine-readable format.
- Right to correction — to correct or update inaccurate data.
- Right to erasure — to have your data permanently deleted (subject to the retention rules in Section 10 where a legal record must be kept).
- Right to grievance redressal — see Section 13.
- Right to nominate — you can nominate someone to exercise your rights on your behalf in the event of your death or incapacity.
- Right to withdraw consent — you can withdraw consent at any time; this will terminate your account. Data retained under Section 10 will remain in cold storage for the legal retention period, encrypted and inaccessible to the running product.
We aim to respond to any of the above requests within 7 working days and to complete the requested action within 30 days of a valid request.
13 · Grievance officer
14 · Security
Everything on KARVM is encrypted in transit (TLS 1.3) and at rest (AES-256, managed by Supabase). Auth tokens are short-lived. Every database row is walled off by row-level security so that even our own application code cannot accidentally leak one landlord's data to another. We do not store card numbers, CVVs, or UPI PINs.
No system is unhackable, and any provider claiming otherwise is lying. If we discover a security incident that affects your data, we will notify you and the Data Protection Board of India within the timelines the DPDP Act requires.
15 · Children
KARVM is not directed at children. We do not knowingly collect personal data from anyone under 18. If a landlord adds a minor as a tenant (unusual, but possible in guardian arrangements), the landlord confirms that they are the lawful guardian and have the right to enter that data on the minor's behalf.
16 · International data transfers
Necessary international transfers are called out inline where they happen — specifically Anthropic (US) for AI drafting (Section 8) and Resend (US) for transactional email (Section 7). All other user-facing data stays in India. We do not knowingly transfer data to any jurisdiction that has been notified by the Central Government as restricted under Section 16 of the DPDP Act.
17 · Changes to this policy
When we make a material change to this policy, we update the version number and effective date at the top of the page, and — for significant changes — email account holders with a summary.
18 · Contact
For any question about this policy, your data, or how KARVM handles it — write to legal@karvm.com. We read every message.