Skip to main content

Legal / Privacy

Privacy Policy

Effective date: 10 June 2026

This Policy is compliant with the Digital Personal Data Protection Act, 2023 (DPDP Act) and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (SPDI Rules).

1. Data Fiduciary

FLICP TECHNOLOGIES PRIVATE LIMITED ("Flicp", "we", "us") is the Data Fiduciary under the DPDP Act, 2023 in respect of personal data processed through the Platform. Registered office: 4th Floor, Xeno Space, No. 28 & 50, Arunodaya Colony, Madhapur, Hyderabad, Telangana – 500081, India. CIN: U62011TS2026PTC214611.

Contact for privacy matters: help@flicp.com

2. Personal Data We Collect

From Consumers:

  • Identity: name, email address, mobile number
  • Account data: encrypted password hash, login timestamps, device identifiers
  • Transaction data: coupons claimed, redeemed, Flicp Token and Sparks balances, redemption timestamps
  • KYC data (where applicable): government-issued ID type and verification status (raw documents processed by DIDIT, not stored by Flicp beyond legal requirements)
  • Usage data: pages visited, feature interactions, browser/device type, IP address
  • Communications: support tickets, feedback, WhatsApp interaction logs (where WhatsApp is enabled)

From Brand Owners and Employees:

  • Business identity: brand name, GSTIN, PAN, registered address, business category
  • Contact details: name, work email, mobile number
  • Financial data: billing details, payment method tokens (stored by Razorpay, not by Flicp), invoice history
  • Operational data: campaigns created, coupon issuance and redemption records, employee role assignments, audit logs

Automatically collected: cookies, log files, session identifiers. See Section 10 (Cookies).

We do not collect: biometric data, financial account numbers, Aadhaar numbers (only KYC verification status is retained after DIDIT processing).

3. Purposes of Processing and Legal Basis

PurposeLegal Basis (DPDP Act)
Account creation and authenticationConsent (§6) / Contract performance
KYC and identity verificationLegal obligation (§7)
Coupon issuance, tracking, and redemptionContract performance
Payment processing via RazorpayContract performance / Legal obligation
Loyalty programme management (Tokens, Sparks)Consent (§6)
Customer support and grievance resolutionLegitimate use / Legal obligation
Fraud detection and platform securityLegitimate use (§7(f))
Analytics to improve the PlatformConsent (§6) — opt-out available
Marketing communications from FlicpConsent (§6) — opt-out available
Compliance with RBI, SEBI, IT Act, DPDP ActLegal obligation (§7)
WhatsApp business communicationsConsent (§6) — separate opt-in

5. Data Sharing and Disclosure

Flicp shares personal data only as follows:

  • Brands (for Consumer redemption data): Brands receive redemption event data for their own coupons only, limited to the minimum necessary for fulfilment and audit.
  • DIDIT: Identity documents for KYC processing under DIDIT's privacy policy.
  • Razorpay: Payment processing data under Razorpay's privacy policy. Flicp does not store card numbers or bank account details.
  • WhatsApp / Meta: Message content and phone numbers where you have opted in to WhatsApp communications.
  • Cloud / Infrastructure providers: Hosting providers operating under data processing agreements with adequate security controls. Data is hosted in Indian data centres.
  • Legal authorities: Where required by a valid court order, law enforcement request, or statutory obligation under Indian law. Flicp will notify affected users where legally permissible.

Flicp does not sell, rent, or trade personal data to third parties for commercial purposes.

6. Data Retention

Data CategoryRetention Period
Active account dataDuration of account + 3 years
Transaction and redemption records7 years (Income Tax Act requirement)
KYC verification status5 years after last activity
Payment records8 years (GST / accounting records requirement)
Consent logs3 years from consent action
Security and audit logs2 years rolling
Marketing consent / opt-out records3 years or until withdrawn + 1 year
Closed / deleted accountsAnonymised after 90 days; aggregates retained

7. Your Rights as a Data Principal

Under the DPDP Act, 2023, you have the following rights:

  • Right to Access (§11): Request a summary of personal data we hold about you and how it is being processed.
  • Right to Correction and Erasure (§12): Request correction of inaccurate data or erasure of data where processing is no longer necessary, subject to legal retention obligations.
  • Right to Grievance Redressal (§13): Lodge a complaint with our Grievance Officer (Section 11 below). If unresolved within 30 days, escalate to the Data Protection Board of India.
  • Right to Nominate (§14): Nominate an individual to exercise your rights on your behalf in the event of your death or incapacity.
  • Right to Withdraw Consent: Withdraw consent at any time for processing based on consent, without affecting prior lawful processing.

To exercise any of these rights, email help@flicp.com with subject line "Data Principal Request — [Your Name]". We will acknowledge within 24 hours and respond within 30 days.

8. Cross-Border Data Transfers

Flicp primarily stores and processes data in India. Where personal data is transferred to sub-processors outside India (for example, cloud infrastructure providers or DIDIT), Flicp ensures such transfers comply with applicable Indian law and that the recipient provides an equivalent level of data protection.

Flicp will update this section promptly if the Government of India notifies restrictions on cross-border data transfers under the DPDP Act.

9. Security

Flicp implements the following security measures:

  • Passwords hashed using bcrypt (minimum 12 rounds)
  • Private keys encrypted at rest with AES-256
  • TLS 1.2+ for all data in transit
  • Role-based access controls across all internal systems
  • Audit logging of all sensitive data access events
  • Rate limiting and CSRF protection on all authenticated endpoints
  • Regular security reviews and penetration testing (results available to Enterprise customers under NDA)

In the event of a personal data breach that is likely to result in high risk to Data Principals, Flicp will notify the Data Protection Board of India and affected users as required under the DPDP Act and SPDI Rules.

10. Cookies and Tracking

Flicp uses the following categories of cookies:

  • Strictly necessary: Authentication tokens, CSRF protection, session management. Cannot be disabled.
  • Analytics (opt-in): Cloudflare Web Analytics — privacy-first, no cross-site tracking, no fingerprinting. You may opt out via your browser's Do Not Track signal or by contacting us.
  • Preference: Theme selection, language. First-party only.

Flicp does not use third-party advertising cookies or cross-site tracking pixels. Our cookie banner on first visit provides granular controls. Consent is stored in compliance with the DPDP Act.

11. Children's Data

Flicp does not knowingly collect personal data from children under 13 years of age. For users aged 13–17, verifiable parental consent is required before an account is activated. If you believe a child's data has been collected without proper consent, contact help@flicp.com and we will delete the data within 72 hours of verification.

12. Grievance Officer

In accordance with the DPDP Act, 2023 and the IT Act, 2000, Flicp's designated Grievance Officer / Data Protection Manager is:

Name: Mothukuri Praful

Email: help@flicp.com

Address: 4th Floor, Xeno Space, No. 28 & 50, Arunodaya Colony, Madhapur, Hyderabad, Telangana – 500081, India

Working hours: Monday–Friday, 10:00–18:00 IST

Acknowledgement: within 24 hours

Resolution: within 30 days

If your complaint is not resolved to your satisfaction within 30 days, you may contact the Data Protection Board of India once it is constituted under the DPDP Act, 2023.

13. Updates to This Policy

Flicp may update this Privacy Policy to reflect changes in law, technology, or business practices. Material changes will be notified via email and an in-platform notice at least 15 days before the new policy takes effect. The effective date at the top of this page will always reflect the most recent version.