Privacy Policy

Last updated: 13 May 2026

SmartPilot ("we", "us", "our") is operated from Bengaluru, India. This Privacy Policy explains how we collect, use, disclose and protect information when you use smartpilot.live, our web application, and related services (the "Service").

1. Information we collect

  • Account data: name, email, phone, business name, password hash.
  • Business data: appointments, customers, staff, services, invoices, queue tokens you create in SmartPilot.
  • Customer data you upload: names and contact details of your end-customers (you are the data controller; we are the processor).
  • Payment data: when you subscribe to a paid plan, payments are processed by Razorpay. We never see or store your full card number, CVV or UPI PIN. Razorpay shares with us only a transaction ID, amount, status and the last 4 digits of the instrument.
  • Usage data: log files, IP address, browser, device, pages visited, via Google Analytics (GA4).
  • Cookies: session cookies for login, analytics cookies, and a preference cookie to dismiss banners.

2. How we use information

  • To provide and operate the Service.
  • To process payments and send invoices via Razorpay.
  • To send transactional email and WhatsApp messages (booking confirmations, reminders, receipts).
  • To improve the product, debug and prevent abuse.
  • To comply with applicable Indian law (including the Digital Personal Data Protection Act, 2023).

3. Payments & Razorpay

All online payments on SmartPilot are processed by Razorpay Software Private Limited, a PCI-DSS Level 1 certified payment gateway. When you pay, you are redirected to or interacting with Razorpay's secure checkout. Card, netbanking, UPI and wallet credentials are submitted directly to Razorpay and are governed by Razorpay's privacy policy.

We retain limited transaction metadata (order ID, payment ID, amount, currency, status, timestamp, instrument type and last 4 digits) for accounting, GST compliance and dispute resolution.

4. Sharing of information

We do not sell your data. We share data only with:

  • Razorpay — to process payments.
  • Cloud infrastructure providers — to host the Service (servers and database hosted in India / EU).
  • Email & WhatsApp delivery partners — to send transactional messages on your behalf.
  • Law enforcement — only when required by a valid Indian legal order.

5. Data retention

We retain account and business data for as long as your account is active. Payment and invoice records are retained for at least 8 years to meet Indian tax and accounting requirements. On account deletion, personal data is deleted or anonymised within 30 days, except where law requires longer retention.

6. Your rights

Under the DPDP Act, 2023 you have the right to access, correct, update, or request deletion of your personal data, and to nominate a person to exercise these rights on your behalf. Email teams@smartpilot.live to make a request.

7. Security

Data is encrypted in transit (TLS 1.2+) and at rest. Passwords are hashed. Database access is protected by row-level security. We never store sensitive payment credentials.

8. Children

SmartPilot is not directed at users under 18. We do not knowingly collect data from minors.

9. International transfers

Some sub-processors (e.g. Google Analytics) may process data outside India. By using SmartPilot you consent to such transfers under appropriate safeguards.

10. Changes to this policy

We may update this policy. Material changes will be notified by email or in-app notice at least 7 days before taking effect.

11. Contact

SmartPilot
WeWork Roshni Tech Hub, Bengaluru, India
Email: teams@smartpilot.live
Phone: +91 72040 29387