Overview
Streakzy ("we", "us", "our") is a milestone-based loyalty platform that helps local businesses reward their regular customers. We are committed to protecting the personal data of consumers and business owners who interact with our platform.
This Privacy Policy is published in compliance with the Digital Personal Data Protection Act, 2023 (DPDP Act) and applies to all personal data processed by Streakzy, whether collected through our website, mobile application, or partner store interactions.
We do not sell your personal data. We do not share it with advertisers. We collect only what is necessary to operate the service.
Data We Collect
From consumers (waitlist sign-ups and app users):
- Name
- Mobile phone number
- City / location (city-level, not precise GPS unless explicitly permitted)
- UPI ID (only when required for cashback processing)
- Visit and transaction data at partner stores (aggregates visible to the business; full detail visible only to you)
From business owners (store registration):
- Owner name
- Store name and category
- Mobile phone number
- City
- Bank / UPI details (only for reward disbursement; collected at onboarding, not on this website)
Automatically collected (website visitors):
- Browser and device type
- Pages visited, time on page, scroll depth (via analytics tools)
- Referring URL and UTM parameters
- IP address (for fraud prevention only; not stored long-term)
How We Use It
- To manage waitlist registration โ contact you when Streakzy launches in your city
- To operate the loyalty programme โ track visit and spend milestones, issue and process voucher redemptions
- To onboard and support business partners โ set up store accounts, configure milestones, provide dashboard access
- To send service communications โ transactional messages about your milestones or account (no promotional spam without consent)
- To improve the platform โ aggregate, anonymised analytics on feature usage
- To prevent fraud and abuse โ detect suspicious redemption patterns
We do not use your data for behavioural advertising, profiling for third-party benefit, or any purpose beyond what is listed here.
Sharing & Disclosure
We do not sell or rent personal data. We share data only in these circumstances:
- With partner stores โ store dashboards show aggregate customer activity (visit counts, spend bands). Individual names and phone numbers are not shown to store owners unless you have opted in.
- With service providers โ cloud hosting, SMS/OTP delivery, and payment processing. These providers process data only on our instructions.
- Legal requirements โ if required by a court order, government authority, or applicable law.
- Business transfers โ in the event of a merger or acquisition, we will notify affected users before data becomes subject to a different privacy policy.
Cookies & Analytics
- Essential cookies โ theme preference (dark/light mode). No consent required.
- Analytics (Google Analytics 4) โ page views and session data. IP addresses are not stored. Opt out via Google's opt-out tool.
- Session recording (Microsoft Clarity) โ heatmaps and session recordings to improve UX. Clarity does not capture form input data.
We do not use advertising cookies or share cookie data with ad networks.
Retention
- Waitlist data โ until the service launches and you are onboarded, or until you request deletion
- Active account data โ for the duration of your account plus 12 months after deletion
- Transaction and milestone data โ 3 years from the date of transaction (for dispute resolution)
- Analytics data โ 14 months (Google Analytics default; Clarity: 13 months)
Your Rights
Under the DPDP Act 2023, you have the following rights as a Data Principal:
- Right to access โ request a summary of what personal data we hold about you
- Right to correction โ request correction of inaccurate or incomplete data
- Right to erasure โ request deletion of your personal data (subject to legal retention obligations)
- Right to grievance redressal โ raise a complaint with our Grievance Officer and receive a response within 48 hours
- Right to nominate โ nominate another individual to exercise rights on your behalf
To exercise any of these rights, email privacy@streakzy.com with the subject line "Data Rights Request". We will respond within 72 hours and resolve requests within 30 days.
Security
- Encryption in transit (TLS 1.2+) and at rest (AES-256)
- Access controls โ data accessible only to authorised personnel on a need-to-know basis
- Regular security reviews of infrastructure and code
- OTP-based authentication for all account access
If you become aware of a security issue involving your data, please notify us at security@streakzy.com.
Children
Streakzy is not directed at children under the age of 18. We do not knowingly collect personal data from minors. If you believe we have inadvertently collected data from a minor, contact privacy@streakzy.com and we will delete it promptly.
Policy Changes
Material changes will be notified via email or via a prominent notice on our website at least 7 days before the change takes effect. Continued use of Streakzy after a policy update constitutes acceptance of the revised terms.
Grievance Officer, Streakzy
Email: privacy@streakzy.com
Response time: within 72 hours
Resolution time: within 30 days of receipt
If you are not satisfied with our response, you may escalate to the Data Protection Board of India once constituted under the DPDP Act, 2023.