Privacy Policy

Draft — not yet published

This policy explains what data FILTER collects, why, and how long it is kept. FILTER's core product is phone number validation, so how we handle phone numbers specifically is the most important part of this page — read that section even if you skip the rest.

1. Scope

This policy applies to data collected through the FILTER website, dashboard, and API. It should be read together with our Terms of Service.

2. Your role and ours under the DPDP Act

India's Digital Personal Data Protection Act, 2023 ("DPDP Act") uses the terms Data Fiduciary (the entity that determines the purpose and means of processing personal data) and Data Principal (the individual the data is about).

For your account and billing data, FILTER is the Data Fiduciary and you are the Data Principal.

For the phone numbers you submit to be validated, you are the Data Fiduciary — you determine whose numbers get submitted and why — and FILTER acts as a Data Processor engaged by you to carry out that specific processing activity on your instructions. You remain responsible for having a lawful basis to submit each number; we remain responsible for processing it only for the validation purpose you've instructed. See our Terms of Service, Section 3 (Eligibility and acceptable use).

3. What we collect

Account data: your email address, name, and — only when you make a purchase — billing details including any GSTIN provided.

Phone numbers submitted for validation: the numbers you send to our API to be checked. This is the core input to our product, and we want to be specific about it rather than bury it in a generic data list.

Usage and analytics data: on our marketing website, we use Google Analytics (GA4) for aggregate traffic analysis and, in the authenticated dashboard, PostHog for product analytics. Both are configured to support opt-out; see Section 10.

Technical data: IP address and request metadata, collected for rate limiting, fraud prevention, and abuse detection.

4. Why we collect it, and our legal basis

Account data is used to operate your account, bill you, and contact you about your service — our legal basis is performance of the contract between us (our Terms of Service).

Submitted phone numbers are used solely to perform the validation check you requested and return a result — our legal basis is the instruction you give us as our Customer, as described in Section 2 above.

5. How long we keep phone numbers — the short version

We do not keep them. Every number we process is converted to a one-way SHA-256 hash for logging purposes; the hash cannot be reversed back into a phone number. The raw number itself exists only briefly, in a short-lived cache used to speed up repeat checks, and is discarded when that cache entry expires. There is no persistent, readable database of phone numbers submitted to FILTER.

We consider this a genuine feature of the product, not just a compliance checkbox: if our systems were ever compromised, there is no bulk-readable list of numbers to expose.

6. Data retention, generally

Account data is retained for as long as your account is active, and for a reasonable period after closure to meet accounting, tax, and legal obligations. Hashed lookup logs are retained for product analytics and abuse investigation; raw request logs are retained only as long as needed for operational debugging.

7. Third parties and sub-processors

To perform a validation check, submitted numbers are sent to a sub-processor:

  • HLR-Lookups.com — our telecom data sub-processor, which queries the underlying carrier network on our behalf. This is the only third party that ever receives a raw phone number from us.
  • Razorpay — our payment processor. We do not store full card numbers ourselves.
  • Our infrastructure providers (Vercel, Supabase, Upstash) — used to host the Service; they process data as processors on our behalf under their own data processing terms.

Where any of these providers process data outside India, that transfer is made under that provider's own compliance framework; we will update this section with a specific data-residency statement once our infrastructure region is finalized.

8. Your rights as a Data Principal

Under the DPDP Act, you have the right to:

  • Access a summary of the personal data we hold about you and how it is processed;
  • Correct, complete, or update inaccurate or outdated personal data;
  • Erase personal data that is no longer necessary for the purpose it was collected, subject to our legal retention obligations (e.g., billing records);
  • Withdraw consent at any time, as easily as you gave it — withdrawal doesn't affect processing already carried out lawfully before withdrawal;
  • Nominate another individual to exercise these rights on your behalf in the event of your death or incapacity;
  • Register a grievance with us, and if unresolved, with the Data Protection Board of India.

To exercise any of these rights, contact our Grievance Officer below.

9. Grievance Officer

Parikshram Technologies Private Limited (CIN: U72900KA2021PTC144926), registered office: Flat No B-005, Ground Floor, Saranya Shantiniketan, Hagadur, Whitefield, Bangalore, Karnataka, India - 560066, is the Data Fiduciary for account and billing data under this policy.

In accordance with the DPDP Act and the Information Technology Act, 2000, we will publish the name and contact details of our Grievance Officer here. We aim to acknowledge grievances promptly and resolve them within a reasonable timeframe.

[TO BE CONFIRMED — spec §XVIII blocker #4]

Named Grievance Officer and formal contact channel not yet set.

10. Cookies and analytics choices

Our marketing site uses analytics cookies (GA4) to understand traffic; our dashboard uses PostHog for product analytics. Neither is used to serve third-party advertising. Where required, we present a consent notice on your first visit — see Section 12 for its current status.

[TO BE CONFIRMED — spec §XVIII blocker #7]

DPDP-aligned cookie/tracking consent banner copy is not yet live on the site.

11. Children's data

FILTER is a business-to-business service and is not directed at, or knowingly used to process data about, individuals under the age of 18. If you believe a child's data has reached us, contact us and we will act promptly to remove it.

12. Changes to this policy

We may update this policy from time to time. Material changes will be notified by email or an in-dashboard notice before they take effect.