Privacy Policy
Effective date: 7 July 2026 Last updated: 7 July 2026
This Privacy Policy explains how ROCloud ("ROCloud", "we", "us", "our"), collects, uses, shares, and protects personal data in connection with the ROCloud platform available at https://rocloud.in and its subdomains (the "Service"). It is intended to comply with the Digital Personal Data Protection Act, 2023 (DPDP Act) and other applicable Indian law.
By using the Service, you agree to this Policy. If you do not agree, please do not use the Service.
1. Two kinds of data, two different roles
ROCloud is a B2B tool used by water-delivery businesses. It is important to understand the two relationships:
- Subscriber account data — data about the businesses and Authorised Users who register for and use ROCloud. For this data, we are the data fiduciary (controller).
- End Customer data — data that a subscribing business enters about its own customers (names, addresses, mobile numbers, order/delivery/invoice history). For this data, the subscribing business is the data fiduciary (controller) and ROCloud is a data processor, handling the data only on that business's instructions.
If you are an End Customer of a water business that uses ROCloud, please contact that business directly with any privacy request — they control your data. We will assist that business as its processor.
2. Data we collect
From Subscribers and Authorised Users:
- Identity & contact: name, business name, email address, mobile number.
- Account & authentication: password (stored only as a secure hash — never in plain text), login provider (e.g. Google sign-in identifier), role and permissions.
- Billing: plan, subscription status, transaction identifiers, and invoices. Online card/UPI payments are processed by our payment gateway; we do not store your full card number, CVV, or UPI PIN.
- Usage & device: log data such as IP address, browser/device type, timestamps, and actions taken in the Service, used for security, auditing, and support.
From Subscribers about their End Customers (processed on their behalf):
- Customer name, delivery address/area, mobile number(s), order, delivery, inventory, invoice, payment, and service-request records that the Subscriber chooses to store.
3. How and why we use data
We use personal data to:
- create and administer accounts and authenticate users;
- provide, operate, secure, and support the Service;
- process subscription payments and issue billing documents;
- send service, transactional, and account communications (for example, billing reminders, security notices, and subscription-expiry notices);
- maintain audit logs and prevent fraud, abuse, and unauthorised access;
- comply with legal obligations; and
- improve and develop the Service.
We process personal data on the lawful bases available under the DPDP Act, including your consent, performance of our contract with you, and our legitimate/legal obligations.
4. Communications
We send transactional and service messages (billing, security, subscription status) that are necessary to operate your account. Currently, service notifications are delivered primarily by email. Where you or your End Customers receive SMS/WhatsApp messages via the Service, those are sent under the Subscriber's control and consent. You can manage notification preferences within the Service where such controls are provided.
5. Cookies and local storage
The Service uses cookies and browser storage (such as localStorage) that are necessary to keep you
signed in, remember preferences (like language), and keep the Service secure. Because these are
essential to the Service's functionality, disabling them may prevent the Service from working.
6. How we share data
We do not sell personal data. We share data only as needed to run the Service:
- Payment gateway — Razorpay Software Private Limited, to process online payments.
- Infrastructure and email providers — service providers that host the Service and deliver transactional email, bound by confidentiality and data-protection obligations.
- Legal — where required by law, court order, or to protect rights, safety, and the integrity of the Service.
- Business transfer — in connection with a merger, acquisition, or sale of assets, subject to this Policy.
We require our processors/sub-processors to protect personal data and to use it only for the purposes we specify.
7. Data storage, location and security
7.1 We take reasonable technical and organisational measures to protect personal data, including password hashing (BCrypt), role-based access control, tenant data isolation (row-level security), audit logging, encryption in transit (HTTPS/TLS), and security-hardening controls.
7.2 Subscriber Data is hosted on infrastructure we operate for the Service. We aim to store and process data within India where practicable.
7.3 No method of transmission or storage is completely secure. While we work to protect your data, we cannot guarantee absolute security, and you use the Service at your own risk in that respect.
8. Data retention
We keep personal data for as long as your account is active and as needed to provide the Service, and thereafter as required to comply with legal, tax, accounting, or reporting obligations, resolve disputes, and enforce our agreements. When data is no longer needed, we delete or anonymise it. On account closure, Subscriber Data may be deleted after a reasonable retention period — export data you wish to keep beforehand (see the Cancellation Policy).
9. Your rights
Subject to applicable law, you may have the right to:
- access the personal data we hold about you;
- request correction of inaccurate or incomplete data;
- request erasure of your data, subject to legal-retention requirements;
- withdraw consent where processing is based on consent; and
- nominate another individual to exercise your rights in the event of death or incapacity, as provided under the DPDP Act.
To exercise these rights for your Subscriber account, contact us at support@mail.rocloud.in. If your request concerns End Customer data, please contact the relevant subscribing business, which controls that data.
10. Grievance Officer
In accordance with applicable Indian law, you may contact our Grievance Officer for any complaint or concern about the handling of your personal data:
Grievance Officer, ROCloud Email: support@mail.rocloud.in Address: Kothariya, Wadhwan, Surendranagar, Gujarat, India – 363030
We will acknowledge and address grievances within the timelines required by applicable law.
11. Children
The Service is intended for use by businesses and is not directed at children. We do not knowingly collect personal data of children except where a subscribing business records such data as part of its own customer records, in which case that business is responsible for obtaining any required consents.
12. Changes to this Policy
We may update this Policy from time to time. We will revise the "Last updated" date and, for material changes, provide reasonable notice. Your continued use of the Service after changes take effect constitutes acceptance of the revised Policy.
13. Contact us
ROCloud Email: support@mail.rocloud.in Phone: +91 88499 27914 Address: Kothariya, Wadhwan, Surendranagar, Gujarat, India – 363030
See our full Contact page for more ways to reach us.