1.Introduction
This Privacy Policy explains how Maurya Group (“we”, “us”, “our”, or the “Data Fiduciary”), a residential rental business operating from Amethi, Uttar Pradesh, India, collects, uses, stores, shares, and protects personal information about you (“you”, “the user”, or the “Data Principal”) when you access or use the Maurya OS lease-management platform (the “Platform”), including the websites hosted at mauryagrp.com, maurya-lease.yaarmedia.workers.dev, and any related mobile or desktop interfaces.
Maurya OS is used by our team to manage properties, applications, leases, tenants, cosigners, rent collection, maintenance requests, and other operational aspects of a residential rental business. Depending on how you interact with us, you may be a prospective tenant applying for a room, a current or former tenant, a cosigner or guarantor, an employer contact, an emergency contact, a landlord team member, a housekeeper, or a general visitor to our public pages.
This document is a plain-English summary of our practices, written to comply with the Digital Personal Data Protection Act, 2023 (DPDP Act) of India, and drafted with reference to the European Union General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA) so that users outside India have parallel comfort. Where the DPDP Act and other laws differ, DPDP applies to Indian residents.
Summary — the 30-second version:
- We collect only what we need to run a legal, safe rental business.
- We never sell your data. Ever.
- We share data with a small number of infrastructure providers (Google Firebase, Cloudflare, Resend) strictly to run the Platform.
- We keep records for up to 10 years after your lease ends because the Income Tax Act, 1961 requires us to be able to substantiate rental income and TDS filings during an audit.
- You can access, correct, or request deletion of your data at any time — subject to the retention obligations above.
- Questions? Write to our Grievance Officer at yaarmedia@gmail.com.
2.Information We Collect
We collect the following categories of personal information. Not every user provides every category — what we collect depends on your relationship with us.
2.1 Identity Information
- Full legal name and preferred name
- Date of birth and age
- Gender (optional)
- Nationality and marital status (where relevant to a lease application)
- Photograph (for tenant identification, key handover records, and lease packet)
2.2 Contact Information
- Email address (primary and secondary)
- Phone numbers (mobile and alternative)
- Current residential address and prior addresses (for rental history)
- Emergency contact name, relationship, and phone number
2.3 Government-Issued Identification
For legally required tenant verification we may collect one or more of the following. You choose which ID you submit; we do not require all of them.
- Aadhaar Number (masked to last 4 digits at rest; UIDAI compliance)
- PAN (Permanent Account Number) — required for TDS filings above Income Tax Act thresholds
- Voter ID (EPIC)
- Passport
- Driving Licence
- Company / employer ID card (for corporate housing arrangements)
2.4 Financial Information
- Monthly income and employer name
- Bank name and last four digits of account (for rent collection reconciliation)
- UPI ID (for payment references)
- Rent payment history, deposit amount, arrears, refunds, and adjustments
- Cosigner / guarantor financial declarations, if applicable
We do not currently process card payments or store card numbers, CVVs, or full bank credentials on the Platform.
2.5 Housing & Application Information
- Preferred move-in date, preferred property or room, budget
- Occupancy (self / couple / family / bachelor(s)), number of occupants
- Pets, dietary preferences, vehicle details (for parking)
- Reason for moving, notice period at prior residence, prior landlord references
- Application status, notes from screening interviews, screening decisions and reasons
- Lease terms, house rules acknowledgements, e-signature timestamps and IP addresses
2.6 Photographs and Documents You Upload
- Photos of your ID (front and back)
- Selfie or profile photo
- Salary slips, offer letters, employer verification letters
- Move-in / move-out condition photos of the room
- Maintenance issue photos you submit through the tenant portal
2.7 Cosigner and Third-Party Information
If your application includes a cosigner or guarantor, we collect their name, contact information, relationship to you, address, ID, income, and e-signature. We collect this only when the primary applicant has represented that the cosigner has consented to being named.
2.8 Technical Information (Automatic)
- IP address (for security, rate-limiting, and fraud prevention)
- Browser type, version, operating system, screen resolution
- Pages visited, features used, session duration (via first-party logs only)
- Cookies and
localStorageentries (see Section 10) - Uploaded-file hashes and antivirus scan results (VirusTotal)
2.9 Communications
- Messages you send us via WhatsApp, email, SMS, in-app chat, or phone (call notes)
- Notices and receipts we send you (retained for legal record)
3.How We Use Your Information
We use the information we collect for the following purposes. Each purpose is described together with the DPDP-recognised lawful basis on which we rely.
| Purpose | Examples | Basis |
|---|---|---|
| Property & Tenancy Management | Maintain records of who lives in which room; issue tenant IDs; assign move-in dates; track deposits. | Performance of contract |
| Lease Generation & Signing | Auto-generate a printable lease agreement from application data; capture e-signatures. | Performance of contract |
| Rent Collection & Accounting | Log payments, generate receipts, reconcile against bank statements, produce ledgers. | Performance of contract + Legal obligation (Income Tax Act) |
| Communications with You | Send rent reminders, receipts, notices, maintenance updates, policy notifications. | Performance of contract + Legitimate interest |
| Legal & Regulatory Compliance | File TDS returns, respond to police tenant-verification requests, respond to court orders. | Legal obligation |
| Fraud Prevention & Security | Rate-limit abusive requests; scan uploaded files with VirusTotal; verify identity via OTP; challenge bots via Turnstile. | Legitimate interest |
| Analytics & Product Improvement | Understand which features are used to prioritise improvements. First-party logs only — no third-party trackers. | Legitimate interest |
| Dispute Resolution | Reconstruct what happened when a tenant, cosigner, or vendor disputes a fact. | Legitimate interest + Legal claim |
What we do not do: We do not use your information to build advertising profiles. We do not run behavioural advertising. We do not sell or rent your information to data brokers. We do not train large language models on your personal data.
4.How We Share Your Information
We share personal information only with the small number of infrastructure providers necessary to operate the Platform, and with government authorities when legally compelled to do so.
4.1 Infrastructure Providers (Data Processors)
| Provider | Purpose | Data Shared |
|---|---|---|
| Google Firebase (Firestore, Firebase Auth, Cloud Storage) | Primary application database, authentication, uploaded file storage. | All Platform data. Stored in Google Cloud US region (see Section 9). |
| Cloudflare (Workers, KV, static hosting) | Serve the Platform, cache static assets, run edge APIs, rate-limit abuse. | IP address, request logs, ephemeral OTP hashes (KV, TTL < 15 min). |
| Cloudflare Turnstile | Bot / CAPTCHA challenge on public forms (Apply, Cosign). | IP, browser fingerprint at challenge time. Not correlated to identity. |
| Resend (transactional email) | Send OTPs, receipts, notices, and password-reset emails. | Recipient email address and message body. |
| VirusTotal | Scan uploaded documents / photos for malware. | SHA-256 hash of the uploaded file (not the file itself). |
Each of these providers is contractually or by their public terms bound to process data only on our instructions and only for the purposes we specify.
4.2 Government Authorities
We disclose personal information to Indian government or law-enforcement authorities only when we receive a lawful, specific written request — for example, a police tenant-verification requisition, a court order, an Income Tax Department notice, or a summons under the Code of Criminal Procedure. Where the law permits, we will notify you of the request; where the law prohibits notification, we will document the request internally.
4.3 Successors and Advisers
We may share information with our accountants, chartered accountants, lawyers, and auditors under professional confidentiality obligations. If the Maurya Group business is transferred to a successor entity, records may be transferred as part of the business, subject to the same privacy commitments.
4.4 What We Never Do
We never sell your personal information. We never share your information with advertising networks, data brokers, list brokers, or marketing partners. We never share tenant lists with real-estate agents, brokers, or other landlords.
5.Data Retention
We keep personal information only for as long as we have a lawful reason to do so. Our default retention schedule is as follows.
| Category | Retention Period | Reason |
|---|---|---|
| Lease agreements, tenant identity docs, rent ledgers, receipts, TDS records | 10 years from lease end | The Income Tax Act, 1961 audit window and stamp-duty / rental-income substantiation. We must be able to defend the return we filed while you were a tenant, and the department can reopen assessments for up to 10 assessment years in serious cases. |
| Rejected application data | 3 years from rejection | Discrimination-complaint window and appeal reconstruction. After 3 years we delete identity fields but keep anonymised aggregate counts for equal-treatment analysis. |
| Communications (WhatsApp / email / call notes) | 5 years | Dispute resolution and evidence of notice. |
| Audit logs (who did what in the Platform) | 7 years | Data-integrity and internal investigation. |
| Marketing / mailing-list subscriptions (if any) | Until you unsubscribe + 30 days | Suppression list management. |
| Server access logs, security logs | 90 days (hot) / 1 year (cold) | Security investigation. |
| OTPs, ephemeral tokens | < 15 minutes | Anti-replay only. Never persisted. |
When the retention period ends, we securely delete the record from Firestore, from Google Cloud Storage, and from any backups within the following backup-cycle. Some technical logs may persist in aggregated, non-identifiable form beyond these periods.
6.Data Security
We take reasonable technical and organisational measures to protect your personal information, appropriate to the sensitivity of the information and the risk of harm.
6.1 In Transit
- TLS 1.3 encryption on every connection to the Platform, enforced by Cloudflare's edge.
- HSTS with a long
max-ageto prevent downgrade attacks. - Strict Content Security Policy, X-Frame-Options DENY, and frame-ancestors none to prevent clickjacking.
6.2 At Rest
- Google Firestore encrypts data at rest using AES-256 keys managed by Google.
- Google Cloud Storage encrypts uploaded files at rest.
- Cloudflare KV encrypts values at rest.
6.3 Access Control
- Firestore Security Rules restrict read and write access to authenticated owner accounts by default. Applicant, tenant, and cosigner data is written by short-lived service-account-mediated Workers routes, not by clients.
- Firebase Authentication is our identity backbone. Owner sign-in uses Google OAuth with the option to enrol multi-factor authentication (SMS or authenticator app).
- Owner allowlist: Only email addresses on our internal owner allowlist can read the full owner dashboard.
- Session timeout: Owner sessions auto-logout after a period of inactivity.
6.4 Application-Layer Protections
- Server-side rate-limiting on sensitive routes (login, OTP send / verify, apply, cosign).
- Cloudflare Turnstile bot-challenge on public forms.
- Uploaded files are scanned via VirusTotal before being made available for download.
- Constant-time comparison of OTPs to prevent timing attacks.
- Full audit trail of privileged owner actions (create / edit / delete leases, override rent, adjust deposits).
6.5 Personnel
Only Sant Lal Maurya and Devkali Maurya (owners), together with the yaarmedia technical contact acting under a data-processing arrangement, have administrative access to the Platform's production data. All access is logged.
6.6 Incident Response
If we discover a personal data breach that is likely to result in significant harm to affected Data Principals, we will notify the Data Protection Board of India in accordance with the DPDP Act, and we will notify affected Data Principals as soon as reasonably practicable at the email address on file, together with information about the nature of the breach and steps you can take to protect yourself.
No system is perfectly secure. We commit to doing what is reasonable; we cannot guarantee that a determined attacker will never succeed.
7.Your Rights
Under the DPDP Act you (as a Data Principal) have specific rights over your personal data. We honour these rights globally, so users in the EU (GDPR) and California (CCPA) receive comparable treatment.
7.1 Right to Access & Portability
You can request a copy of the personal information we hold about you. For tenants and applicants, most of this is already visible in the Platform:
- Personal profile → /tenant-profile
- Account overview → /account
- Your lease → /lease-detail
- Your payment history → /my-ledger
For anything not visible in the UI, email support@mauryagrp.com. We will respond within 30 days.
7.2 Right to Correction
You can correct your personal information at /tenant-profile and /account. If a field is read-only (e.g. your legal name once a lease is executed) email us with the correction and evidence and we will update it.
7.3 Right to Erasure / Deletion
You can request deletion of your personal information by emailing support@mauryagrp.com with the subject line “Delete my data”. We will delete records that are not subject to a legal retention obligation (see Section 5). For records subject to the 10-year Income Tax Act retention, we will delete non-essential fields and retain only what the law requires until the retention window closes.
7.4 Right to Withdraw Consent
Where we process your data on the basis of consent (e.g. marketing communications, optional analytics), you can withdraw consent at any time. Withdrawal does not affect the lawfulness of processing performed before withdrawal.
7.5 Right to Grievance Redressal
If you are unhappy with how we have handled your personal information, you may raise a grievance with our Grievance Officer:
Name: designated owner, Maurya Group
Email: yaarmedia@gmail.com
Response commitment: within 30 days of receipt
If you remain unsatisfied, you may escalate to the Data Protection Board of India constituted under the DPDP Act.
7.6 Right to Nominate
You may nominate another individual to exercise your rights on your behalf in the event of your death or incapacity. Send the nomination in writing to the Grievance Officer.
7.7 GDPR / CCPA Parallel Rights
- GDPR: Right to object, right to restrict processing, right to lodge a complaint with a supervisory authority in your EU Member State.
- CCPA: Right to know, right to delete, right to opt out of sale (we do not sell), right to non-discrimination for exercising your rights.
8.Children's Privacy
The Platform is intended for adults aged 18 years or older. We do not knowingly collect personal information directly from children under 18.
Minors may be listed on a lease as dependents (e.g. a tenant's child living in the room), in which case we collect only the minor's name, date of birth, and relationship to the tenant, provided by the parent or legal guardian. We do not create Platform accounts for minors and we do not send communications directly to them.
If you believe we have inadvertently collected personal information from a child under 18, email support@mauryagrp.com and we will delete it promptly.
9.Cross-Border Data Transfers
Maurya Group operates from India. Our primary data-processing infrastructure (Google Firebase / Firestore) is hosted in Google Cloud regions located in the United States. Cloudflare's edge network is global; static assets and rate-limiting logic may be served from a region close to you.
By using the Platform you consent to your personal information being transferred to and processed in these regions. India, at the time of publication, has not restricted transfers to the United States under the DPDP Act; if the Central Government designates the United States as a restricted country, we will migrate data to an approved region within the notice period specified by the Government.
Google and Cloudflare are certified under widely recognised international security standards (ISO 27001, SOC 2 Type II) and our data-processing arrangements with them include appropriate contractual safeguards.
10.Cookies & Local Storage
The Platform uses a small, deliberate set of client-side storage entries. We do not use third-party advertising cookies, retargeting pixels, session-replay tools, or cross-site tracking of any kind.
| Item | Type | Purpose | Duration |
|---|---|---|---|
| Firebase Auth session | localStorage | Keep you signed in. | Until you sign out. |
| Theme preference | localStorage | Remember light / dark preference. | Until you clear browser data. |
| Form drafts (auto-save) | localStorage | Save your typing so you don't lose it if you reload. | Until submission or clear. |
| OTP anti-replay flag | localStorage | Prevent double-submission of the same OTP. | 15 minutes. |
| Turnstile challenge cookie | Cookie (Cloudflare) | Confirm you passed a bot challenge; scoped to Turnstile only. | Per challenge (short). |
You can clear these at any time via your browser's clear-site-data controls. Clearing them will sign you out and remove your saved drafts.
11.Updates to This Policy
We may update this Privacy Policy from time to time — for example when we add a new feature that changes how we process data, when a new law is enacted, or when we correct an error.
When we make a material change, we will:
- Post the updated policy at
/privacywith a new “Last Updated” date; - Show an in-app banner announcing the change on the next sign-in;
- Send an email notification to every registered user at the email address on file at least 15 days before the change takes effect, where the change is material.
Your continued use of the Platform after the effective date of the updated policy constitutes acceptance of the updated policy. If you do not agree, you may close your account (subject to the retention obligations in Section 5).
12.Contact Us
For any question about this Privacy Policy or about how we handle your personal information, please contact us using any of the following channels.
| Channel | Contact | Best for |
|---|---|---|
| Support Email | support@mauryagrp.com | Access, correction, and deletion requests; general privacy questions. |
| Grievance Officer | yaarmedia@gmail.com | Formal grievances and unresolved complaints. |
| Phone / WhatsApp | +91 7007661386 | Urgent issues; available Mon–Sat 9am–6pm IST. |
| Postal | Maurya Group, Amethi, Uttar Pradesh, India | Written correspondence, legal notices. |
We will acknowledge your enquiry within 3 business days and respond substantively within 30 days.