Legal

Privacy Policy

Effective: 10 July 2026 · Version 1.0
Draft for advocate review · v1.0. This policy is a good-faith working draft. Before we sign anyone up who relies on it (paid customers, or landlords entering real tenant data at scale), it will be reviewed by a qualified Indian data-protection advocate and updated if their read of DPDP / IT Rules differs from ours. If you are reading this and something looks wrong or overreaches, write to us at the address below — we will fix it.

KARVM is a rental-management platform for Indian landlords and their tenants. This policy explains what data we collect, why, how long we keep it, who we share it with, and what you can ask us to do with it.

KARVM is built to align with India's Digital Personal Data Protection Act 2023 (DPDP Act), UIDAI guidelines for Aadhaar handling, and bank-grade encryptionstandards for data in transit and at rest. This isn't marketing language — every claim in this policy is grounded in an architectural choice you can hold us to.

1 · Who we are

KARVM is operated by Utkarsh Singh, a sole proprietor based in Bangalore, Karnataka, India. The service is reached at karvm.com and karvm.in. For any question about this policy or your data, write to legal@karvm.com.

Because KARVM is a sole-proprietor operation during early access, Utkarsh Singh is also the Grievance Officerfor the purposes of the DPDP Act and India's IT Rules 2021. Grievance contact and response timelines are set out in Section 13.

2 · What we mean by “data”

For clarity, throughout this policy:

KARVM is the data fiduciary in most contexts. Where a landlord uploads or enters data about a tenant, the landlord is also independently responsible for the lawful basis and accuracy of that data — we act as a processor for the landlord in that specific respect.

3 · What we collect

From landlords (collected when you sign up and use the landlord app):

From tenants (collected via the tenant portal, or entered on your behalf by your landlord):

Automatic technical data: server logs of your requests (IP address, timestamp, endpoint), your browser user-agent, and error traces. We do not use third-party analytics or advertising trackers. See Section 11.

4 · Why we collect it (purpose & lawful basis)

Every category above has a specific purpose. We do not collect “in case” data.

Our lawful basis is your consent (given by signing up and accepting this policy), contract performance (we need this data to deliver the service you asked for), and compliance with a legal obligation (specifically for Aadhaar in registered agreements and for tax invoices).

5 · Aadhaar handling

Because Aadhaar is one of the most sensitive identifiers KARVM touches, we spell out exactly what happens to it.

6 · Where the data lives

KARVM's primary database and file storage are hosted by Supabase, Inc. in the AWS Asia Pacific (Mumbai) — ap-south-1 region. Serverless functions run in the same region. Data does not leave India as part of normal application storage.

Data may transit outside India transiently when specific features run — see Section 7 for the exact subprocessor list, what they see, and why. Where any subprocessor sits outside India, that is a necessary international transfer under Section 16 of the DPDP Act.

Every database row is walled off by row-level security (RLS) enforced by the database itself. This is architectural, not policy: another landlord literally cannot construct a query that returns your rows.

7 · Who we share data with (subprocessors)

KARVM does not sell data. We use the following third-party services to run the product. Each row lists what they see and where they run.

SubprocessorWhat it seesWhere it runs
Supabase, Inc.All persistent data — database rows + uploaded files (encrypted at rest).Mumbai, India (ap-south-1)
Vercel, Inc.Application hosting and request routing. No persistent user data.India edge, US control plane
Anthropic PBC (Claude API)The specific facts you enter when drafting a legal notice or agreement — see Section 8.United States
Razorpay Software Pvt LtdPayment metadata for landlord invoicing (post early-access). Not tenant rent — rent is paid direct to the landlord.India
Digio (Digital Signatures & Certificates Pvt Ltd)Documents you send for e-sign (Aadhaar eSign / eStamp).India
MSG91 (Walkover Web Solutions)Phone numbers, and the WhatsApp / SMS message text (rent reminders, OTP codes).India
Resend, Inc.Email addresses and the transactional email body (receipts, alerts).United States

We keep this list current. When we add or remove a subprocessor we update this section and note the change in the version history at the top of the page.

8 · AI legal drafting

When you ask KARVM to draft a legal notice, a rental agreement, or a reply to a tenant, we send the specific facts you provided (arrears amount, dates, tenant name, jurisdiction, conduct facts) to Anthropic's Claude API, which returns the draft. This is the only time your data leaves India during normal use, and it is a necessary international transfer under the DPDP Act.

9 · Payments and rent

KARVM is nota payment rail for rent. Tenants pay their landlord directly through the same UPI / bank transfer they already use — KARVM records the payment as an event and generates a receipt, but the money never touches KARVM's systems.

If and when we start invoicing landlords for the paid version of KARVM (post early-access), those payments will be processed by Razorpay, whose privacy policy governs the card and UPI credentials you enter on their form. We do not store card numbers, CVVs, or UPI PINs.

10 · How long we keep data

11 · Cookies and tracking

KARVM uses essential cookies only — session cookies for keeping you signed in, and a preference cookie for your light / dark mode choice. We do not use Google Analytics, Meta Pixel, Segment, Mixpanel, or any advertising trackers. We do not build an advertising profile about you.

12 · Your rights under the DPDP Act

As a data principal you have the following rights over your data held by KARVM. You can exercise any of them by writing to legal@karvm.com from the email or phone number associated with your account.

We aim to respond to any of the above requests within 7 working days and to complete the requested action within 30 days of a valid request.

13 · Grievance officer

Grievance Officer
Utkarsh Singh
KARVM
Bangalore, Karnataka, India
Email: legal@karvm.com
We acknowledge grievances within 48 hours and aim to resolve them within 30 days, per Rule 3(2) of the IT Rules 2021 and Section 8(10) of the DPDP Act.

14 · Security

Everything on KARVM is encrypted in transit (TLS 1.3) and at rest (AES-256, managed by Supabase). Auth tokens are short-lived. Every database row is walled off by row-level security so that even our own application code cannot accidentally leak one landlord's data to another. We do not store card numbers, CVVs, or UPI PINs.

No system is unhackable, and any provider claiming otherwise is lying. If we discover a security incident that affects your data, we will notify you and the Data Protection Board of India within the timelines the DPDP Act requires.

15 · Children

KARVM is not directed at children. We do not knowingly collect personal data from anyone under 18. If a landlord adds a minor as a tenant (unusual, but possible in guardian arrangements), the landlord confirms that they are the lawful guardian and have the right to enter that data on the minor's behalf.

16 · International data transfers

Necessary international transfers are called out inline where they happen — specifically Anthropic (US) for AI drafting (Section 8) and Resend (US) for transactional email (Section 7). All other user-facing data stays in India. We do not knowingly transfer data to any jurisdiction that has been notified by the Central Government as restricted under Section 16 of the DPDP Act.

17 · Changes to this policy

When we make a material change to this policy, we update the version number and effective date at the top of the page, and — for significant changes — email account holders with a summary.

18 · Contact

For any question about this policy, your data, or how KARVM handles it — write to legal@karvm.com. We read every message.

A note on how we wrote this. Most Indian privacy policies are copy-pasted from a generic template that names no one, hides subprocessors, and calls everything “industry-standard.” This one names the frameworks (DPDP Act 2023, UIDAI, IT Rules 2021), the subprocessors (Supabase, Anthropic, Razorpay, Digio, MSG91, Resend, Vercel), the actual data flows (Aadhaar, AI drafting), and the retention windows (7 years for legal records, 90 days for logs, 30 days for closed accounts). If we ever add a subprocessor, we'll list it here.