1. What we collect
Information you give us
When your society signs up, we collect the society or federation name, its registered address and registration number where you provide them, and the name, mobile number and email of the committee member setting it up. We only ask for what the product genuinely needs.
Information we collect automatically
When you use the console or the member app we record basic usage data: IP address, browser and device information, and which pages and actions you use. We use this to find faults and to understand which parts of the product are working. We do not build advertising profiles.
Society data
This is the important category. Everything your committee enters — member and unit records, family members, documents and KYC proofs, maintenance bills, payments, complaints, meeting minutes, notices, visitor entries and accounting records — belongs to your society. It lives in a database schema reserved for your society alone. We do not access, analyse, mine or monetise it.
2. How we use it
We use your information to:
- Run the console, the member app and the gate register
- Authenticate you and keep your session secure
- Send transactional messages you have asked for — OTPs, bill notices, payment receipts, complaint updates, meeting notices
- Answer support requests and contact you about your account
- Improve the product from aggregate usage patterns, never individual tracking
- Detect and prevent abuse, fraud and security incidents
- Meet our legal and tax obligations
What we do not do
We do not sell your data. We do not show advertising. We do not share member information with marketing partners. We do not use your society's data to train AI models.
3. One schema per society
HouseFederation uses a schema-per-tenant architecture in PostgreSQL. Every society's data lives in its own database schema, separated from every other society on the same infrastructure, and each society is reached on its own subdomain.
What that means in practice:
- One society's member register cannot be read from another society's session
- Isolation is enforced at the database level, not only in application code
- Deleted records are held behind a row-level security policy so that a mistake can be undone, and are removed permanently when the trash is emptied
- When a society leaves, we drop its schema — nothing is left behind in shared tables
We chose this because the data a housing society handles — addresses, identity proofs, family details, financial records — deserves the strongest separation we can give it.
4. Storage and security
How we protect it
- All connections are encrypted in transit with TLS
- Passwords are hashed; sign-in is by one-time password to your mobile or email, or by Google
- Sessions use short-lived access tokens with refresh rotation, and sign-in attempts are rate limited
- Permission-based roles apply to every request — what a secretary can see is not what a guard can see
- Uploaded documents are held in per-society storage and served only to authorised sessions
- Automated backups, with old backups rotated out on a fixed schedule
We will confirm the hosting region and the backup retention window for your society in writing on request.
5. Third parties we use
We keep this list short and we are specific about each one:
- Razorpay — to collect maintenance payments. Each society connects its own Razorpay account, and money settles to that society directly. Card details are handled by Razorpay in a PCI-compliant environment and never reach us
- MSG91 — to send SMS and one-time passwords. We pass the recipient's number and the message text
- An SMTP relay — to send email notices and receipts. We pass the recipient's address and the message
- Meta WhatsApp Business API — only if your society connects a WhatsApp number. We store the access token encrypted and send messages on your behalf. Meta processes delivery and retains message metadata under its own policy
- Google — only if a user chooses "Sign in with Google", in which case Google receives the sign-in request
We do not use Google Analytics, advertising pixels or any advertising-related tracker.
6. Your rights
You have the right to:
- Access the personal data we hold about you
- Correct anything inaccurate or incomplete
- Have your data deleted
- Export your society's data in standard formats
- Withdraw consent for non-essential messages at any time
- Ask us to restrict how we process your data in specific situations
To exercise any of these, email [email protected]. We respond within 7 business days.
7. How long we keep it
- Active societies: data is kept for as long as the society uses the platform
- Closed societies: the society's schema is deleted permanently after the notice period in our Terms
- Backups: deleted data may persist in encrypted backups until those backups rotate out
- Tax records: invoices and transaction records are kept for as long as Indian tax law requires
- Legal holds: if a court or a regulator requires it, specific data may be kept longer, and we will tell you if that applies to you
8. Children's data
A member record may name family members, including children, where a committee records them as part of the household. That information is entered by committee members, not by children. We do not knowingly collect personal information directly from a child.
The society is the entity deciding what to record about its residents. It is responsible for collecting that information lawfully and for having a basis to record family details, under the Digital Personal Data Protection Act, 2023 and any other applicable law.
9. Changes to this policy
We may update this policy. When we do, we update the date at the top of this page and email active administrators about anything material. Significant changes come with advance notice and a plain explanation of what changed and why.
10. Contact and grievances
Questions about this policy, your data, or a privacy concern? Email [email protected]. We reply within 7 business days.
Grievance Officer
Under the Digital Personal Data Protection Act, 2023 you can reach our Grievance Officer about how we handle personal data:
- Grievance Officer, Nextyug Technologies Private Limited
- Email: [email protected]
We acknowledge every grievance and work to resolve it within the timelines the law requires.
Nextyug Technologies Private Limited
Flat No. 1005, C1, Eden Garden (Building C3), Tathawade, Pimpri-Chinchwad, Pune, Maharashtra 411033, India GSTIN: 27AAKCN2107N1Z8
This page is a plain-language summary of a binding agreement. If anything here is unclear, ask us before you rely on it — get in touch.