CitySave.in
Legal

Privacy Policy

Last updated: May 21, 2026

Our promise in one line: we collect the minimum personal data we need to run CitySave, we never sell it, and we let you delete it whenever you want.

1. Who we are

This Privacy Policy applies to CitySave.in (the "Platform"), operated by the CitySave team from Jaipur, Rajasthan, India ("we", "us", "our"). For purposes of India's Digital Personal Data Protection Act, 2023 ("DPDPA"), we act as the Data Fiduciary for personal data submitted by Users on the Platform.

2. Personal data we collect

We collect only what we genuinely need to operate CitySave:

  • Identity & contact: your mobile number (mandatory, used for OTP login), your name (optional), and your email (optional, used for receipts).
  • Transaction data: coupons you have purchased, redeemed, refunded, or disputed; the booking fees paid; the Merchants and Deals involved.
  • Device & usage data: IP address, browser/user-agent string, pages viewed, deals favourited, search queries on the Platform. We use this to operate, debug and improve the service.
  • Communications: the contents of emails, WhatsApp messages, or support tickets you send to us.

We do not collect Aadhaar, PAN, biometrics, bank account, card numbers or passwords directly. All payments are processed by Razorpay; we receive only the payment status and a transaction ID.

3. Why we use your data (purposes)

  • To authenticate you on the Platform via phone OTP.
  • To issue, redeem, refund and dispute Coupons you purchase.
  • To send transaction confirmations, refund updates, and coupon-expiry reminders.
  • To communicate with you regarding queries, disputes, complaints and feedback.
  • To detect and prevent fraud, abuse and misuse of the Platform.
  • To comply with our legal obligations under Indian law, including tax, GST and accounting rules.
  • To improve the Platform — analytics, debugging, A/B testing — using aggregated and pseudonymised data.

4. Lawful basis (DPDPA)

Under the DPDPA, we process your personal data based on:

  • Your consent, granted when you sign up and continue to use the Platform.
  • Performance of a contract with you (issuing Coupons, processing refunds).
  • Legal obligation, such as record-keeping for tax authorities.
  • Legitimate use, such as detecting fraud or responding to a Merchant dispute.

5. Who we share data with

We share the minimum necessary data with the following carefully chosen partners:

  • Razorpay — to process your booking fee payment. Your mobile number, email (if provided) and the amount are passed; card numbers stay with Razorpay.
  • The Merchant whose Coupon you purchased — receives your masked phone (last 2 digits visible), your name (if provided), and your coupon code so they can verify redemption in-store.
  • OTP & email providers — to deliver login codes, receipts and reminders. They process the recipient identifier only.
  • Government or regulatory authorities, where we are legally required to disclose (court order, tax notice, valid law-enforcement request).

We never sell your personal data to advertisers, data brokers, or any third party.

6. Cookies and similar technologies

We use first-party cookies for session login (your JWT), language/city preference, and basic security (CSRF protection). We do not use third-party advertising cookies. We do not run cross-site tracking pixels.

7. Data retention

We retain your personal data only as long as it serves a legitimate purpose:

  • Active accounts: as long as your account is open.
  • Coupon and payment records: 7 years from the date of the transaction (mandated by Indian tax law).
  • Support tickets: 2 years from closure.
  • Inactive accounts (no login for 24 months): anonymised, with transaction history retained for legal compliance.

8. Your rights

Under the DPDPA, you have the right to:

  • Access the personal data we hold about you.
  • Correct or update inaccurate or incomplete data.
  • Erase your data (subject to legal retention obligations).
  • Withdraw consent at any time. Once withdrawn, we will stop further processing, though prior lawful processing remains valid.
  • Nominate another person to exercise these rights on your behalf in case of incapacity or death.
  • Lodge a grievance with us, and (if unresolved) escalate to the Data Protection Board of India.

To exercise any of these rights, write to privacy@citysave.in. We will respond within 30 days.

9. How we protect your data

  • HTTPS / TLS encryption everywhere on the Platform.
  • Hashed and salted session tokens.
  • Database access restricted to authenticated, audited operators only.
  • No card numbers ever stored on our servers — Razorpay is PCI-DSS Level 1 certified.
  • Daily encrypted backups, retained in Indian data-centres.

No internet service is 100% secure. If we detect a breach affecting your personal data, we will notify you and the Data Protection Board within 72 hours, as required by DPDPA.

10. Children

CitySave is intended for users aged 18 and above. We do not knowingly collect personal data from minors. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.

11. Data location and international transfers

Your personal data is stored on servers physically located in India. We may use service providers (e.g. email delivery) that process data in other jurisdictions, but only where appropriate contractual safeguards are in place. We do not transfer data to any country that the Indian government has restricted under the DPDPA.

12. Changes to this Policy

We may update this Privacy Policy from time to time. We will post the updated version on this page and (for material changes) notify you via email or in-app banner. Continued use of the Platform after the update means you accept the revised Policy.

13. Contact and grievance redressal

For any privacy-related question, complaint or right-request:

Data Protection / Grievance Officer: Surendra Bhilwal
Postal address: Studio 204, Geejgarh Tower, C-Scheme, Jaipur — 302001, Rajasthan, India
Response time: within 15 working days; complex requests within 30 days.