Maurya Group
Privacy Policy
← Home
Legal · Maurya OS Platform

Privacy Policy

How Maurya Group collects, uses, stores, and protects your personal information when you use the Maurya OS lease-management platform.

⚠ Template — Have your lawyer review before relying on it

This is a template Privacy Policy provided for convenience. It reflects our current practices in good faith, but it has not been reviewed by qualified legal counsel. Before you rely on this document — or before we publish it as final — please have a lawyer familiar with India's Digital Personal Data Protection Act 2023 (DPDP) and applicable state rules review and customise it for your circumstances.

Data FiduciaryMaurya Group, Amethi, Uttar Pradesh, India
PlatformMaurya OS (lease-management SaaS)
Effective Date1 July 2026
Last Updated1 July 2026
Grievance Officeryaarmedia@gmail.com
Supportsupport@mauryagrp.com · +91 7007661386

1.Introduction

This Privacy Policy explains how Maurya Group (“we”, “us”, “our”, or the “Data Fiduciary”), a residential rental business operating from Amethi, Uttar Pradesh, India, collects, uses, stores, shares, and protects personal information about you (“you”, “the user”, or the “Data Principal”) when you access or use the Maurya OS lease-management platform (the “Platform”), including the websites hosted at mauryagrp.com, maurya-lease.yaarmedia.workers.dev, and any related mobile or desktop interfaces.

Maurya OS is used by our team to manage properties, applications, leases, tenants, cosigners, rent collection, maintenance requests, and other operational aspects of a residential rental business. Depending on how you interact with us, you may be a prospective tenant applying for a room, a current or former tenant, a cosigner or guarantor, an employer contact, an emergency contact, a landlord team member, a housekeeper, or a general visitor to our public pages.

This document is a plain-English summary of our practices, written to comply with the Digital Personal Data Protection Act, 2023 (DPDP Act) of India, and drafted with reference to the European Union General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA) so that users outside India have parallel comfort. Where the DPDP Act and other laws differ, DPDP applies to Indian residents.

Summary — the 30-second version:

  • We collect only what we need to run a legal, safe rental business.
  • We never sell your data. Ever.
  • We share data with a small number of infrastructure providers (Google Firebase, Cloudflare, Resend) strictly to run the Platform.
  • We keep records for up to 10 years after your lease ends because the Income Tax Act, 1961 requires us to be able to substantiate rental income and TDS filings during an audit.
  • You can access, correct, or request deletion of your data at any time — subject to the retention obligations above.
  • Questions? Write to our Grievance Officer at yaarmedia@gmail.com.

2.Information We Collect

We collect the following categories of personal information. Not every user provides every category — what we collect depends on your relationship with us.

2.1 Identity Information

  • Full legal name and preferred name
  • Date of birth and age
  • Gender (optional)
  • Nationality and marital status (where relevant to a lease application)
  • Photograph (for tenant identification, key handover records, and lease packet)

2.2 Contact Information

  • Email address (primary and secondary)
  • Phone numbers (mobile and alternative)
  • Current residential address and prior addresses (for rental history)
  • Emergency contact name, relationship, and phone number

2.3 Government-Issued Identification

For legally required tenant verification we may collect one or more of the following. You choose which ID you submit; we do not require all of them.

  • Aadhaar Number (masked to last 4 digits at rest; UIDAI compliance)
  • PAN (Permanent Account Number) — required for TDS filings above Income Tax Act thresholds
  • Voter ID (EPIC)
  • Passport
  • Driving Licence
  • Company / employer ID card (for corporate housing arrangements)
Aadhaar handling: Full Aadhaar numbers, where collected, are stored server-side under Firestore security rules that restrict read access to authenticated owners. Applications, exports, and printed documents display only the last four digits. We do not use Aadhaar for authentication (we use email OTP + Firebase Phone Auth).

2.4 Financial Information

  • Monthly income and employer name
  • Bank name and last four digits of account (for rent collection reconciliation)
  • UPI ID (for payment references)
  • Rent payment history, deposit amount, arrears, refunds, and adjustments
  • Cosigner / guarantor financial declarations, if applicable

We do not currently process card payments or store card numbers, CVVs, or full bank credentials on the Platform.

2.5 Housing & Application Information

  • Preferred move-in date, preferred property or room, budget
  • Occupancy (self / couple / family / bachelor(s)), number of occupants
  • Pets, dietary preferences, vehicle details (for parking)
  • Reason for moving, notice period at prior residence, prior landlord references
  • Application status, notes from screening interviews, screening decisions and reasons
  • Lease terms, house rules acknowledgements, e-signature timestamps and IP addresses

2.6 Photographs and Documents You Upload

  • Photos of your ID (front and back)
  • Selfie or profile photo
  • Salary slips, offer letters, employer verification letters
  • Move-in / move-out condition photos of the room
  • Maintenance issue photos you submit through the tenant portal

2.7 Cosigner and Third-Party Information

If your application includes a cosigner or guarantor, we collect their name, contact information, relationship to you, address, ID, income, and e-signature. We collect this only when the primary applicant has represented that the cosigner has consented to being named.

2.8 Technical Information (Automatic)

  • IP address (for security, rate-limiting, and fraud prevention)
  • Browser type, version, operating system, screen resolution
  • Pages visited, features used, session duration (via first-party logs only)
  • Cookies and localStorage entries (see Section 10)
  • Uploaded-file hashes and antivirus scan results (VirusTotal)

2.9 Communications

  • Messages you send us via WhatsApp, email, SMS, in-app chat, or phone (call notes)
  • Notices and receipts we send you (retained for legal record)

3.How We Use Your Information

We use the information we collect for the following purposes. Each purpose is described together with the DPDP-recognised lawful basis on which we rely.

PurposeExamplesBasis
Property & Tenancy Management Maintain records of who lives in which room; issue tenant IDs; assign move-in dates; track deposits. Performance of contract
Lease Generation & Signing Auto-generate a printable lease agreement from application data; capture e-signatures. Performance of contract
Rent Collection & Accounting Log payments, generate receipts, reconcile against bank statements, produce ledgers. Performance of contract + Legal obligation (Income Tax Act)
Communications with You Send rent reminders, receipts, notices, maintenance updates, policy notifications. Performance of contract + Legitimate interest
Legal & Regulatory Compliance File TDS returns, respond to police tenant-verification requests, respond to court orders. Legal obligation
Fraud Prevention & Security Rate-limit abusive requests; scan uploaded files with VirusTotal; verify identity via OTP; challenge bots via Turnstile. Legitimate interest
Analytics & Product Improvement Understand which features are used to prioritise improvements. First-party logs only — no third-party trackers. Legitimate interest
Dispute Resolution Reconstruct what happened when a tenant, cosigner, or vendor disputes a fact. Legitimate interest + Legal claim

What we do not do: We do not use your information to build advertising profiles. We do not run behavioural advertising. We do not sell or rent your information to data brokers. We do not train large language models on your personal data.

4.How We Share Your Information

We share personal information only with the small number of infrastructure providers necessary to operate the Platform, and with government authorities when legally compelled to do so.

4.1 Infrastructure Providers (Data Processors)

ProviderPurposeData Shared
Google Firebase (Firestore, Firebase Auth, Cloud Storage) Primary application database, authentication, uploaded file storage. All Platform data. Stored in Google Cloud US region (see Section 9).
Cloudflare (Workers, KV, static hosting) Serve the Platform, cache static assets, run edge APIs, rate-limit abuse. IP address, request logs, ephemeral OTP hashes (KV, TTL < 15 min).
Cloudflare Turnstile Bot / CAPTCHA challenge on public forms (Apply, Cosign). IP, browser fingerprint at challenge time. Not correlated to identity.
Resend (transactional email) Send OTPs, receipts, notices, and password-reset emails. Recipient email address and message body.
VirusTotal Scan uploaded documents / photos for malware. SHA-256 hash of the uploaded file (not the file itself).

Each of these providers is contractually or by their public terms bound to process data only on our instructions and only for the purposes we specify.

4.2 Government Authorities

We disclose personal information to Indian government or law-enforcement authorities only when we receive a lawful, specific written request — for example, a police tenant-verification requisition, a court order, an Income Tax Department notice, or a summons under the Code of Criminal Procedure. Where the law permits, we will notify you of the request; where the law prohibits notification, we will document the request internally.

4.3 Successors and Advisers

We may share information with our accountants, chartered accountants, lawyers, and auditors under professional confidentiality obligations. If the Maurya Group business is transferred to a successor entity, records may be transferred as part of the business, subject to the same privacy commitments.

4.4 What We Never Do

We never sell your personal information. We never share your information with advertising networks, data brokers, list brokers, or marketing partners. We never share tenant lists with real-estate agents, brokers, or other landlords.

5.Data Retention

We keep personal information only for as long as we have a lawful reason to do so. Our default retention schedule is as follows.

CategoryRetention PeriodReason
Lease agreements, tenant identity docs, rent ledgers, receipts, TDS records 10 years from lease end The Income Tax Act, 1961 audit window and stamp-duty / rental-income substantiation. We must be able to defend the return we filed while you were a tenant, and the department can reopen assessments for up to 10 assessment years in serious cases.
Rejected application data 3 years from rejection Discrimination-complaint window and appeal reconstruction. After 3 years we delete identity fields but keep anonymised aggregate counts for equal-treatment analysis.
Communications (WhatsApp / email / call notes) 5 years Dispute resolution and evidence of notice.
Audit logs (who did what in the Platform) 7 years Data-integrity and internal investigation.
Marketing / mailing-list subscriptions (if any) Until you unsubscribe + 30 days Suppression list management.
Server access logs, security logs 90 days (hot) / 1 year (cold) Security investigation.
OTPs, ephemeral tokens < 15 minutes Anti-replay only. Never persisted.
The 10-year rule, explained: If your lease ends on 30 June 2027, we will retain your lease agreement, ID copies, and rent ledger until at least 30 June 2037. After that, unless we are otherwise required to keep it, we securely delete it. This is not about tracking you — it is about being able to prove to the tax department, ten years later, that we correctly reported the rent we received and deducted TDS where required.

When the retention period ends, we securely delete the record from Firestore, from Google Cloud Storage, and from any backups within the following backup-cycle. Some technical logs may persist in aggregated, non-identifiable form beyond these periods.

6.Data Security

We take reasonable technical and organisational measures to protect your personal information, appropriate to the sensitivity of the information and the risk of harm.

6.1 In Transit

  • TLS 1.3 encryption on every connection to the Platform, enforced by Cloudflare's edge.
  • HSTS with a long max-age to prevent downgrade attacks.
  • Strict Content Security Policy, X-Frame-Options DENY, and frame-ancestors none to prevent clickjacking.

6.2 At Rest

  • Google Firestore encrypts data at rest using AES-256 keys managed by Google.
  • Google Cloud Storage encrypts uploaded files at rest.
  • Cloudflare KV encrypts values at rest.

6.3 Access Control

  • Firestore Security Rules restrict read and write access to authenticated owner accounts by default. Applicant, tenant, and cosigner data is written by short-lived service-account-mediated Workers routes, not by clients.
  • Firebase Authentication is our identity backbone. Owner sign-in uses Google OAuth with the option to enrol multi-factor authentication (SMS or authenticator app).
  • Owner allowlist: Only email addresses on our internal owner allowlist can read the full owner dashboard.
  • Session timeout: Owner sessions auto-logout after a period of inactivity.

6.4 Application-Layer Protections

  • Server-side rate-limiting on sensitive routes (login, OTP send / verify, apply, cosign).
  • Cloudflare Turnstile bot-challenge on public forms.
  • Uploaded files are scanned via VirusTotal before being made available for download.
  • Constant-time comparison of OTPs to prevent timing attacks.
  • Full audit trail of privileged owner actions (create / edit / delete leases, override rent, adjust deposits).

6.5 Personnel

Only Sant Lal Maurya and Devkali Maurya (owners), together with the yaarmedia technical contact acting under a data-processing arrangement, have administrative access to the Platform's production data. All access is logged.

6.6 Incident Response

If we discover a personal data breach that is likely to result in significant harm to affected Data Principals, we will notify the Data Protection Board of India in accordance with the DPDP Act, and we will notify affected Data Principals as soon as reasonably practicable at the email address on file, together with information about the nature of the breach and steps you can take to protect yourself.

No system is perfectly secure. We commit to doing what is reasonable; we cannot guarantee that a determined attacker will never succeed.

7.Your Rights

Under the DPDP Act you (as a Data Principal) have specific rights over your personal data. We honour these rights globally, so users in the EU (GDPR) and California (CCPA) receive comparable treatment.

7.1 Right to Access & Portability

You can request a copy of the personal information we hold about you. For tenants and applicants, most of this is already visible in the Platform:

For anything not visible in the UI, email support@mauryagrp.com. We will respond within 30 days.

7.2 Right to Correction

You can correct your personal information at /tenant-profile and /account. If a field is read-only (e.g. your legal name once a lease is executed) email us with the correction and evidence and we will update it.

7.3 Right to Erasure / Deletion

You can request deletion of your personal information by emailing support@mauryagrp.com with the subject line “Delete my data”. We will delete records that are not subject to a legal retention obligation (see Section 5). For records subject to the 10-year Income Tax Act retention, we will delete non-essential fields and retain only what the law requires until the retention window closes.

7.4 Right to Withdraw Consent

Where we process your data on the basis of consent (e.g. marketing communications, optional analytics), you can withdraw consent at any time. Withdrawal does not affect the lawfulness of processing performed before withdrawal.

7.5 Right to Grievance Redressal

If you are unhappy with how we have handled your personal information, you may raise a grievance with our Grievance Officer:

Grievance Officer
Name: designated owner, Maurya Group
Email: yaarmedia@gmail.com
Response commitment: within 30 days of receipt

If you remain unsatisfied, you may escalate to the Data Protection Board of India constituted under the DPDP Act.

7.6 Right to Nominate

You may nominate another individual to exercise your rights on your behalf in the event of your death or incapacity. Send the nomination in writing to the Grievance Officer.

7.7 GDPR / CCPA Parallel Rights

  • GDPR: Right to object, right to restrict processing, right to lodge a complaint with a supervisory authority in your EU Member State.
  • CCPA: Right to know, right to delete, right to opt out of sale (we do not sell), right to non-discrimination for exercising your rights.

8.Children's Privacy

The Platform is intended for adults aged 18 years or older. We do not knowingly collect personal information directly from children under 18.

Minors may be listed on a lease as dependents (e.g. a tenant's child living in the room), in which case we collect only the minor's name, date of birth, and relationship to the tenant, provided by the parent or legal guardian. We do not create Platform accounts for minors and we do not send communications directly to them.

If you believe we have inadvertently collected personal information from a child under 18, email support@mauryagrp.com and we will delete it promptly.

9.Cross-Border Data Transfers

Maurya Group operates from India. Our primary data-processing infrastructure (Google Firebase / Firestore) is hosted in Google Cloud regions located in the United States. Cloudflare's edge network is global; static assets and rate-limiting logic may be served from a region close to you.

By using the Platform you consent to your personal information being transferred to and processed in these regions. India, at the time of publication, has not restricted transfers to the United States under the DPDP Act; if the Central Government designates the United States as a restricted country, we will migrate data to an approved region within the notice period specified by the Government.

Google and Cloudflare are certified under widely recognised international security standards (ISO 27001, SOC 2 Type II) and our data-processing arrangements with them include appropriate contractual safeguards.

10.Cookies & Local Storage

The Platform uses a small, deliberate set of client-side storage entries. We do not use third-party advertising cookies, retargeting pixels, session-replay tools, or cross-site tracking of any kind.

ItemTypePurposeDuration
Firebase Auth session localStorage Keep you signed in. Until you sign out.
Theme preference localStorage Remember light / dark preference. Until you clear browser data.
Form drafts (auto-save) localStorage Save your typing so you don't lose it if you reload. Until submission or clear.
OTP anti-replay flag localStorage Prevent double-submission of the same OTP. 15 minutes.
Turnstile challenge cookie Cookie (Cloudflare) Confirm you passed a bot challenge; scoped to Turnstile only. Per challenge (short).

You can clear these at any time via your browser's clear-site-data controls. Clearing them will sign you out and remove your saved drafts.

11.Updates to This Policy

We may update this Privacy Policy from time to time — for example when we add a new feature that changes how we process data, when a new law is enacted, or when we correct an error.

When we make a material change, we will:

  • Post the updated policy at /privacy with a new “Last Updated” date;
  • Show an in-app banner announcing the change on the next sign-in;
  • Send an email notification to every registered user at the email address on file at least 15 days before the change takes effect, where the change is material.

Your continued use of the Platform after the effective date of the updated policy constitutes acceptance of the updated policy. If you do not agree, you may close your account (subject to the retention obligations in Section 5).

12.Contact Us

For any question about this Privacy Policy or about how we handle your personal information, please contact us using any of the following channels.

ChannelContactBest for
Support Email support@mauryagrp.com Access, correction, and deletion requests; general privacy questions.
Grievance Officer yaarmedia@gmail.com Formal grievances and unresolved complaints.
Phone / WhatsApp +91 7007661386 Urgent issues; available Mon–Sat 9am–6pm IST.
Postal Maurya Group, Amethi, Uttar Pradesh, India Written correspondence, legal notices.

We will acknowledge your enquiry within 3 business days and respond substantively within 30 days.

↑ Back to top