Short version: Your data lives on your device. We do not sell it, share it, or store it on our servers unless you explicitly enable cloud backup. You are always in control.
1. Who we are
Family Handover is a mobile application built to help Indian families organise financial and personal records. Our registered contact address is [email protected]. When this policy says "we", "us", or "our", it refers to the team operating Family Handover at familyhandover.in.
2. Scope of this policy
This policy applies to:
- The Family Handover mobile application (iOS and Android)
- The Family Handover website at familyhandover.in
- Any communications between you and our support team
This policy does not apply to third-party services you may use alongside Family Handover, such as Google Sign-In or Apple Sign-In.
3. Applicable law
We operate in accordance with India's Digital Personal Data Protection Act 2023 (DPDP Act) and its associated rules. Where you are located outside India, we also respect internationally recognised privacy principles.
Under the DPDP Act, we act as a Data Fiduciary. You are the Data Principal — meaning you have rights over your personal data.
4. What data we collect
4.1 Data you give us directly
- Account information: Your name and email address when you sign in with Google or Apple. We do not store your sign-in password — that stays with Google or Apple.
- Family records: Bank account details, insurance policy information, property records, and investment details that you add inside the app. This data is stored on your device, not our servers.
- Support messages: If you email us for help, we retain those messages to resolve your issue.
4.2 Data collected automatically
- Crash reports: If the app crashes, we may receive an anonymised crash report (device type, OS version, app version). This does not include any of your family records.
- App usage analytics: We use privacy-respecting analytics to understand which features are used most. No personal or family record data is included.
- Website cookies: Our website uses only essential cookies required to serve the page correctly. We do not use advertising cookies or tracking pixels.
4.3 Data we do not collect
- We do not collect your Aadhaar number, PAN, or bank account PINs or passwords.
- We do not read or access the financial records stored in your vault unless you contact support and explicitly share them.
- We do not sell any data to third parties — ever.
5. How we use your data
| Purpose | Data used | Legal basis (DPDP Act) |
|---|---|---|
| Providing the app service | Name, email | Consent |
| Improving stability | Anonymised crash data | Legitimate use |
| Customer support | Support email contents | Consent |
| Sending important updates | Email address | Consent |
6. Where your data is stored
Family records (bank accounts, insurance, property, investments) are stored and secured only on your device. They are protected by your 12 recovery words. We cannot access or recover them for you if you lose your device and your recovery words.
If you enable optional cloud backup, your records are uploaded to secure servers located in India. The backup is secured so that only someone with your 12 recovery words can read it — not our team.
Your account information (name and email) is stored on our servers to identify your account. We retain this for as long as your account remains active, plus 12 months after deletion.
7. Sharing your data
We do not sell your data. We share it only in these limited circumstances:
- Service providers: We use trusted partners for crash reporting and analytics. They act under data processing agreements and cannot use your data for their own purposes.
- Legal obligations: If required by a valid court order or law, we may disclose account information (not vault contents) to authorities.
- Business transfer: If Family Handover is acquired or merged, we will notify you before your data moves to any new owner, and you may delete your account.
8. Your rights under the DPDP Act 2023
As a Data Principal, you have the following rights:
- Right to access: Ask us what personal data we hold about you.
- Right to correction: Ask us to fix inaccurate data.
- Right to erasure: Ask us to delete your account and associated data.
- Right to grievance redressal: Raise a complaint with us and receive a response within 30 days.
- Right to nominate: Nominate another person to exercise your rights in the event of your death or incapacity (as permitted under the DPDP Act).
To exercise any of these rights, email us at [email protected]. We will respond within 30 days.
9. Data retention
- Account information: Retained while your account is active. Deleted 12 months after account closure.
- Cloud backup (if enabled): Deleted immediately when you disable backup or delete your account.
- Crash and analytics data: Aggregated and retained for 24 months, then deleted.
- Support emails: Retained for 36 months, then deleted.
10. Children's privacy
Family Handover is not intended for use by persons under 18 years of age. We do not knowingly collect personal data from minors. If you believe a minor has registered, please contact us and we will delete the account promptly.
11. Security
We take security seriously. Your vault records are protected by your 12 recovery words — a unique phrase that only you know. Without it, nobody — including our team — can read your records. We recommend writing your recovery words down and storing them in a physically safe location, separate from your phone.
Our servers use industry-standard security practices. However, no system is entirely risk-free. We encourage you to use a strong device passcode and keep your app updated.
12. Changes to this policy
We may update this policy from time to time. If we make material changes, we will notify you via the app or email at least 14 days before the changes take effect. Your continued use of Family Handover after that date means you accept the updated policy.
13. Contact and grievances
For any privacy concerns or to exercise your rights:
- Email: [email protected]
- Response time: We aim to respond within 5 business days, and no later than 30 days for formal rights requests.
If you are not satisfied with our response, you may contact the Data Protection Board of India once it is established under the DPDP Act 2023.