Policies
Privacy Policy
Last updated:
What the Synckube apps collect from customers, shop owners and delivery partners, why we collect it, who sees it, and how you stay in control.
1. Who we are and what this covers
This Privacy Policy explains how Affy Cloud Solution Pvt Ltd ("Synckube", "we", "us") collects, uses, shares and protects personal data when you use:
- the Synckube app, used by customers and by shop owners (one app with a customer mode and a shop mode);
- the Synckube Delivery app, used by delivery partners; and
- this website.
We are the data fiduciary for the personal data described here under the Digital Personal Data Protection Act, 2023 ("DPDP Act"), and we follow the Information Technology Act, 2000 and the rules made under it. Our registered office is at 13, 40 Quarter, Ahmedabad Palace Road, Kohefiza, Bhopal, Madhya Pradesh 462001, India.
Shops on Synckube are independent businesses. They receive some of your details so they can fulfil your orders (see section 6). If a shop uses your details for its own purposes outside Synckube, that shop is responsible for that use.
2. The short version
- You sign in with your mobile number and a one-time password (OTP) sent by SMS. There are no passwords.
- With your permission, we use your location to show shops near you and to deliver orders. Delivery partners share their location while they are on duty.
- The shop you order from, and the delivery partner carrying your order, receive what they need to complete it: such as your name, phone number and delivery address.
- Delivery partners' identity documents and bank details are used only to verify them and pay them. They are never shown to customers or shops.
- We do not sell personal data, and we do not share it for third-party advertising.
- You can delete your Synckube account from the Profile screen in the app.
3. Information we collect
Everyone who uses the apps
- Mobile number. It identifies your account. To sign you in we send a one-time password to it through an SMS service provider. The code expires within minutes and is deleted once it is used, or after too many wrong attempts.
- Profile details you choose to add: first and last name, email address, gender, date of birth and profile photo.
- Notification details: the Firebase Cloud Messaging token that lets us send push notifications to your device, the device platform (Android or iOS), which of our apps it is, and a record of the notifications we sent you and whether you have read them in the app.
- Technical data: when the app contacts our servers, they receive your IP address, the time of the request and the technical details needed to respond and to diagnose errors.
Customers
- Location. If you allow it, your device's location while you use the app, to sort shops by distance, check whether we deliver to you and place your address on a map. You can skip this and choose a city or type your address instead.
- Delivery addresses: the name for the address, mobile number, email address, house or flat and street, city, state, pincode, country, a label (Home, Work or Other) and the map pin (latitude and longitude).
- Shops you connect with. When you scan a shop's QR code, we record which shop and when, so it appears in your list.
- Orders: your cart, the items, quantities and prices you ordered, totals, order and payment status, the delivery address used, cancellations, invoices, and the time of each status change.
- Repeat deliveries: the product and pack, quantity, frequency (daily, weekly or monthly), amount per delivery, start date, next scheduled date, status, and a payment record for each cycle.
- Voice search. If you search by speaking, your phone's built-in speech recognition service (provided by Google on Android and by Apple on iOS) turns your speech into text under that provider's terms. We receive only the text of the search, not the recording.
Shop owners
- Registration details: your first and last name, mobile number, email address, shop name, business type, shop address (street, city, state, pincode, country), GST number, PAN, and the map location of your shop.
- Shop content: categories, sub-categories, products, packs, prices, stock levels, discounts, product photos and storefront banners.
- Opening hours and closures, including the reason you choose. If you write your own note for a closure, customers can see it.
- Your plan, its validity and your usage against its limits.
- Business activity: orders you receive, the customers who order from you or take repeat deliveries, and reports you export.
Delivery partners
- Identity: full name, date of birth and a profile photo.
- KYC documents: Aadhaar number and photos of the front and back of your Aadhaar card; PAN and a photo of your PAN card; driving licence number, photos of its front and back, and its expiry date; vehicle type, registration number and a photo of the registration certificate (RC).
- Bank details for payouts: account holder name, account number, IFSC, bank name and, if you provide it, a photo of your passbook or a cancelled cheque.
- Verification status: whether your submission is incomplete, under review, approved or rejected, the review dates, and any reason we give for a rejection.
- Duty status and location: whether you are on duty; your device location while you are on duty, to offer you orders near you; and while you are carrying an order, your location at regular intervals (roughly every 30 seconds when you have moved) so the customer can see where the delivery has reached. We keep your last known position.
- Trips: the offers you accept, the updates you make (arrived at the shop, picked up, out for delivery, delivered) and their times, the distances involved, and what you earned for each trip.
This website
This website has no sign-in and no forms, and does not use cookies for analytics or advertising. Our hosting provider may keep standard server logs (IP address, browser type and the pages requested) for security and to keep the site running.
4. Permissions the apps ask for
Each permission is requested when a feature first needs it. You can refuse, or withdraw it later in your phone's settings; the last column says what changes if you do.
| Permission | App | Used for | If you say no |
|---|---|---|---|
| Location | Synckube | Shops near you, whether we deliver to you, placing your address on the map | Choose a city and type your address |
| Location | Synckube Delivery | Offering trips near you while on duty; showing progress while delivering | You cannot receive or run trips |
| Camera | Synckube | Scanning shop QR codes; taking product and profile photos | Find shops on the map; add photos from your gallery |
| Camera | Synckube Delivery | Photographing your KYC documents | Choose document photos from your gallery |
| Photos and media | Both | Attaching product, profile or document images you pick | Use the camera instead, or skip optional photos |
| Microphone and speech recognition | Synckube | Searching by voice | Type your search |
| Notifications | Both | Order updates, new orders for shops, trip offers for delivery partners | Check the app for updates yourself |
5. How we use your information
- To create your account, verify your mobile number and keep your account secure.
- To show shops and products available where you are, and to check that we deliver there.
- To place, route and deliver orders, run repeat deliveries, and produce invoices.
- To let shop owners manage their inventory, hours, orders, customers, subscribers and reports.
- To verify delivery partners, offer them trips, calculate their earnings and pay them.
- To send notifications about your orders, your shop or your trips. If we ever want to send you promotional messages, we will ask first, and you can stop them at any time.
- To answer support requests and grievances, and to resolve disputes between customers, shops and delivery partners.
- To prevent fraud and misuse, keep people safe, and meet our legal obligations, including tax and law enforcement requests.
- To understand, in aggregate, how the service is used so we can improve it.
We process personal data on the basis of your consent, which you give when you sign up and when you grant a permission, and for the legitimate uses the DPDP Act allows, such as complying with the law or using details you have voluntarily given us for the purpose you gave them. You can withdraw consent at any time (see section 9); this does not affect processing already done.
7. Aadhaar, PAN and other KYC documents
We ask delivery partners for identity, licence, vehicle and bank documents for four reasons only:
- to confirm that you are who you say you are;
- to confirm that you are allowed to drive the vehicle you will deliver on;
- to pay your earnings into an account in your name; and
- to prevent fraud and meet legal requirements.
A person on our team reviews your documents. We do not perform Aadhaar authentication with UIDAI, and we do not use your Aadhaar number for anything other than this verification. Access to KYC documents is limited to the staff who review applications and handle payouts or disputes. They are never shown to customers or shops.
If your application is rejected, we tell you the reason so you can correct and resubmit it. We keep KYC documents while your account is active. After it is closed we keep them only for as long as the law requires, or while a dispute about your trips is open, and then delete them.
8. How long we keep it
- Account and profile: until you delete your account.
- One-time passwords: a few minutes; deleted when used or after too many wrong attempts.
- Orders, invoices and payment records: for as long as tax and accounting laws require, even after an account is deleted. These records are kept only for that purpose.
- Delivery partner KYC documents: as described in section 7.
- Location: a delivery partner's live position is overwritten by each new update. The pickup and drop points of a delivery are kept with that delivery's record.
- Notification tokens: deactivated when you sign out, or when Firebase reports that the token no longer works.
- Server logs: for a limited period, for security and troubleshooting.
9. Your rights and choices
Under the DPDP Act you have the right to:
- access a summary of the personal data we hold about you and how we use it;
- correct and update it. Most details, such as your profile and saved addresses, can be edited in the app;
- erase it, by deleting your account (section 10) or writing to us;
- withdraw consent, by turning off a permission in your phone's settings or deleting your account;
- nominate another person to exercise these rights if you die or become unable to; and
- have your grievance addressed by our Grievance Officer, and then approach the Data Protection Board of India if you are not satisfied.
To use any of these rights, write to support@synckube.com from, or mentioning, your registered mobile number. We may need to confirm it is you before acting, and we will respond within the time the law requires.
10. Deleting your account
In the Synckube app, open Profile and choose Delete account. Delivery partners, and anyone who cannot use the app, can ask us by writing to support@synckube.com.
Deleting your account removes your profile, saved addresses, notification tokens and, for shop owners, your shop listing. Please let any order that is on its way finish first. Records we must keep by law, such as invoices for completed orders, are retained only as section 8 describes.
11. How we protect it
- The apps talk to our servers over encrypted HTTPS connections.
- Signing in uses short-lived one-time passwords, with a limit on wrong attempts.
- Access to KYC documents and bank details is restricted to the staff who need it.
- Each person on Synckube sees only the details needed for their part of an order.
No system is completely secure. If we become aware of a breach affecting your personal data, we will inform you and the Data Protection Board of India as the law requires. Never share your OTP with anyone; we will never ask you for it. If you think someone has accessed your account, contact us straight away.
12. Children
Synckube is meant for people aged 18 and over. We do not knowingly collect personal data from children. If you believe a child has created an account, write to support@synckube.com and we will delete it.
13. Where your data is processed
Our servers are located in India. Some service providers, such as Google Firebase, may process data outside India. Such transfers are made in line with the DPDP Act, which permits them except to countries the Government of India restricts.
14. Changes to this policy
If we change this policy, we will update the date at the top of this page. If a change significantly affects how we use your personal data, we will tell you in the app before it takes effect and, where the law requires, ask for your consent again.
15. Contact and Grievance Officer
For questions or requests about your personal data, write to support@synckube.com.
If you are not satisfied with our response, contact our Grievance Officer at info@affyclouditsolutions.com, or by post at Affy Cloud Solution Pvt Ltd, 13, 40 Quarter, Ahmedabad Palace Road, Kohefiza, Bhopal, Madhya Pradesh 462001, India. See how complaints are handled.