Privacy Policy
1. Introduction
This Privacy Policy explains how personal data is collected, processed, stored, and protected when you access or use the Choruss platform ("Platform").
By using the Platform, you acknowledge that your personal data will be handled in accordance with this Privacy Policy and applicable Indian laws, including the Digital Personal Data Protection Act, 2023 ("DPDP Act").
2. Our Platform Model (Important Disclosure)
Choruss is a software platform that enables organizer-led group activities, payment coordination, expense tracking, and balance computation.
The Company:
- Does not operate as a bank, escrow, or financial institution
- Does not operate stored-value accounts, prepaid wallets, or e-money. Any "wallet", "balance", or "credit" shown in the Platform is a ledger/accounting reference only and is not funds held by the Company
- Does not hold custody of user funds for organizer-participant transactions
- Does not store card numbers, CVV, UPI PINs, bank passwords, or similar financial authentication credentials
Payments are processed through third-party regulated payment service providers. Settlement timelines and financial processing are governed by those providers.
3. Our Role Under Data Protection Law
For personal data relating to user account creation and platform usage, the Company acts as a Data Fiduciary under applicable law.
For participant data uploaded by organizers (for example, phone numbers for invitations), the organizer determines the purpose of collection and sharing. The Company processes such data to provide Platform functionality and security.
Organizers are responsible for ensuring that they have a lawful basis (including notice and consent where required) before sharing participant data through the Platform.
4. Categories of Personal Data We Process
Depending on how you use the Platform, we may process:
a) Account Information
- Name
- Phone number
- Optional email address
- Login credentials (stored securely in hashed form)
b) Profile and Participation Data
- Group memberships
- Organizer roles
- Activity participation details
c) Event and Ledger Data
- Payment status
- Expense entries
- Balance or refund computations (ledger references only)
- Payment proof images (such as UPI screenshots) uploaded by users
- Receipt or bill images uploaded for expense tracking
d) Invitation Data
- Contact details entered by organizers for sending invitations
e) Technical and Usage Data
- Device or browser type
- IP address and network metadata
- App logs and timestamps
- Diagnostic and security-related information
- Push notification subscription details (where enabled)
- Analytics events (where analytics is enabled)
5. Data We Do Not Intentionally Collect
We do not intentionally collect:
- Card numbers, CVV, UPI PINs, bank passwords
- Biometric data
- Sensitive personal data unrelated to platform functionality
- Stored-value wallet credentials
If such data is inadvertently shared, we may delete or restrict it.
6. Purposes of Processing
We process personal data to:
- Create and manage user accounts
- Enable group activities and invitations
- Display payment status and ledger-style balances
- Detect fraud, abuse, or misuse
- Maintain platform security and integrity
- Provide user support
- Comply with legal and regulatory obligations
We may also use aggregated or anonymized data for analytics and platform improvement.
7. Legal Basis for Processing
Where applicable under Indian law, processing is based on one or more of:
- User consent
- Performance of services requested by the user
- Legitimate uses permitted under applicable law
- Compliance with legal obligations
Where consent is required, users may withdraw consent subject to lawful limitations.
8. Data Sharing
We do not sell personal data for unrelated third-party marketing.
We may share personal data on a need-to-know basis with:
- Hosting and cloud infrastructure providers
- Communication and notification service providers
- Payment processors (for payment-related flows)
- Fraud detection and security service providers
- Professional advisors (legal, compliance, audit)
- Government authorities or law enforcement where legally required
All such sharing is subject to appropriate contractual or legal safeguards.
9. Third-Party Services
The Platform may integrate with third-party services such as payment gateways, authentication providers, cloud hosting, analytics, and communication providers (for example, services such as Razorpay, Firebase, Google Cloud, and Google Analytics where configured).
Their processing of personal data is governed by their own privacy policies and terms in addition to this Policy.
We encourage users to review those policies where relevant.
10. Data Retention
We retain personal data only as long as necessary for:
- Platform functionality
- Security and fraud prevention
- Dispute handling
- Legal, regulatory, or tax compliance
Retention periods vary depending on the nature of data and legal requirements.
Data may be deleted or anonymized when no longer required, subject to lawful retention obligations.
11. Security Measures
We implement commercially reasonable technical and organizational safeguards, including:
- Encryption in transit where applicable
- Access controls
- Secure infrastructure practices
- Monitoring and logging
- Fraud and abuse detection mechanisms
However, no system is completely secure. Users are responsible for maintaining account confidentiality and promptly reporting unauthorized access.
12. Personal Data Breach
In the event of a personal data breach that is required to be notified under applicable law, we will take steps consistent with legal obligations, including notifying relevant authorities and affected users where required.
13. Cross-Border Processing
We may process or store personal data using service providers located outside your immediate jurisdiction, including outside India.
Where such transfers occur, we take reasonable steps to ensure lawful safeguards and contractual protections in accordance with applicable law.
14. Business Transfers
In the event of a merger, acquisition, restructuring, financing transaction, or asset sale, personal data may be transferred as part of such transaction, subject to confidentiality and legal safeguards.
15. User Rights
Subject to applicable law, you may request:
- Access to your personal data
- Correction of inaccurate data
- Deletion of personal data (where legally permissible)
- Withdrawal of consent (where processing is consent-based)
- Grievance redressal
Requests may be submitted using the contact details below.
We may retain certain data where required by law or for legitimate operational purposes.
16. Children's Data
The Platform is intended for legally competent users (generally 18 years or older).
If we become aware that personal data of a child has been collected without required authorization, we may restrict or delete such data as required by law.
17. Cookies and Similar Technologies
The Platform may use essential cookies, local storage, or session mechanisms for:
- Authentication
- Security
- Basic functionality
Where configured, the Platform may also use analytics tools (such as Google Analytics) to understand usage and improve the service. This Policy will be updated if additional non-essential tracking is introduced.
18. Monitoring and Fraud Prevention
To protect users and platform integrity, we may monitor usage patterns, transaction metadata, and system logs to detect fraud, abuse, security threats, or violations of applicable laws and platform policies.
19. Grievances and Complaints
If you have concerns regarding privacy or data handling, contact Choruss Support (Privacy & Grievance) at Choruss.works@gmail.com with subject "Grievance" or "Privacy request". Include your registered phone number, a short description of the issue, and what you want us to do. We aim to acknowledge within 3 business days and will make reasonable efforts to review and respond within applicable legal timelines.
20. Policy Updates
We may update this Privacy Policy to reflect legal, technical, or business changes.
Updated versions will be posted with a revised "Last Updated" date. Continued use of the Platform after updates constitutes acceptance of the revised Policy.
Contact Details
Platform: www.choruss.com
Legal Entity: K2M SERVICES LLP
Registered Address: 1-10-126, Gurazala, 522415
Privacy / Legal Email: Choruss.works@gmail.com
Support Email: Choruss.works@gmail.com
Grievance / Privacy contact: Choruss Support (Privacy & Grievance)
Grievance Email: Choruss.works@gmail.com
How to raise a grievance or privacy request: Email Choruss.works@gmail.com with subject "Grievance" or "Privacy request". Include your registered phone number, a short description of the issue, and what you want us to do. We aim to acknowledge within 3 business days.