TechGlobe Consultancy Services LLP ("we," "our," or "us") operates the Policy Pilots mobile application (the "App"). TechGlobe Consultancy Services LLP is the Data Fiduciary under the Digital Personal Data Protection (DPDP) Act, 2023 for user account data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our App.
This application is not affiliated with, endorsed by, or operated by any insurance company including LIC of India. It is an independent third-party productivity tool for insurance professionals.
By using the App and accepting the Disclaimer & Terms of Use, you provide clear and informed consent to the collection and processing of your information in accordance with this policy. If you do not agree, please do not use the App.
1. Information We Collect
1.1 Information You Provide
- Account Information: Name, email address, phone number, date of birth, gender, profile photo, user code, branch, organization, and password when you register or log in.
- Visiting Card Data: If you create a digital visiting card, additional details you choose to add: alternate mobile number, WhatsApp number, designation, tagline, list of services, LIC/agent code, and postal address (address line, city, pincode). Your organization's logo image may also be included if your admin has uploaded one.
- Payment & Subscription Data: When you submit a manual subscription payment, we collect the UTR/bank transaction reference number you enter, an optional note, an optional screenshot of your payment as proof, and any referral code applied. We do not collect your card, UPI, or bank login credentials — only the reference number and proof you choose to submit for manual verification.
- Referral Program Data: If you use or share a referral code, we record the referral code, the referral relationship (who referred whom) and its status, and any resulting reward (extension days or commission) credited to your account.
- Lead Data: Customer names, phone numbers, email addresses, age, occupation, annual income, lead source, interest level, and other details you enter while managing leads.
- Proposal Data: Extensive customer details including date of birth, place of birth, gender, education, nationality, PAN number, Aadhaar number, address, family details (father's name, mother's name, spouse details), employment details, nominee information, bank account number, IFSC code, health history, and lifestyle information (smoker/alcoholic status, height, weight). This data is collected solely to generate insurance proposals as required by the insurer.
- Documents: Files you upload such as identity documents (PAN, Aadhaar, etc.), photos, and PDFs related to leads and prospective agents.
- Prospective Customer Data: Customer names, mobile numbers, categories, remarks, and interest levels that you enter for prospective customer management.
- Recruitment Data: Prospective agent information including name, mobile, email, age, occupation, education, segment, source, and remarks.
- Task Plans: Customer names, planned dates, work nature, and remarks you create for daily planning.
- Notes, Follow-ups & Conversations: Notes, follow-up dates, conversation history, and support messages you create within the App.
- Competition Entries: Images you upload for competitions, and your interactions (views, likes, dislikes).
- Training Data: Exam attempts, scores, and completion status.
1.2 Information Collected Automatically
- Device Information: Device model, brand, operating system version, and unique device identifiers (Android ID or iOS vendor identifier) for device binding and push notifications.
- Push Notification Tokens: Firebase Cloud Messaging (FCM) tokens to deliver notifications to your device.
- Device Security Status: Whether your device is rooted/jailbroken or running on an emulator, for security purposes.
- Usage Data: App interaction data, feature usage patterns, audit logs of user actions, and error logs to improve app performance.
- Last Active Timestamp: When you last used the App, for account management purposes.
1.3 Information Accessed from Your Device
- Contacts (Single Selection): When you tap the contacts icon, the App opens your device’s built-in contact picker. Only the single contact you select (name and phone number) is returned to the App. The App does not read, access, or store your full contact list. No contacts permission is required — access is granted by the operating system only for the contact you explicitly choose.
- Location (Staff Attendance Only): If your organization uses the staff attendance feature, the App captures your device’s GPS coordinates (latitude, longitude, and the reading’s accuracy) at the single moment you scan your office QR code to check in or check out. This is used only to confirm you are physically present at your assigned office, by comparing your position against that office’s registered location and permitted radius.
- Location is read only at the instant of a scan, triggered by your explicit action. The App does not poll, track, or record your location in the background, while the App is closed, or at any other time.
- Your check-in and check-out coordinates are stored with the corresponding attendance record.
- If a scan is rejected (for example, you are outside the permitted radius, or you scanned another office’s code), the App records the attempt — including the coordinates reported at that moment — and notifies your manager, so that attendance can be reviewed. Your manager is shown only the distance in metres from the office, the reason for rejection, and the time of the attempt — never your raw coordinates.
- Location is used solely for attendance verification. It is never used for advertising, profiling, analytics, or continuous monitoring of staff movement.
- This feature applies only to Staff and Manager accounts using office attendance. If you decline the location permission, you can continue to use every other part of the App; you will only be unable to record attendance by QR scan.
1.4 Information We Do NOT Collect
- Background or continuous location — the App never accesses your location while it is closed or in the background, and never tracks your movement between scans (see Section 1.3)
- Call logs or SMS messages
- Browsing history
- Credit/debit card numbers, UPI PINs, or bank login credentials — we never collect or process card/bank credentials directly. For manual subscription payments, we only collect the bank transaction reference (UTR) number and an optional payment screenshot you submit for verification (see Section 1.1)
- Biometric data (biometric authentication is processed locally on your device only)
2. How We Use Your Information
We use the collected information for the following purposes:
- Provide Services: To operate and maintain the App’s core functionality — lead management, proposal creation, policy tracking, document management, prospective customer/agent management, task planning, and follow-up scheduling.
- Authentication & Security: To verify your identity, secure your account, bind your device, and detect compromised (rooted/jailbroken) devices.
- Notifications: To send push notifications about lead assignments, document uploads, follow-up reminders, competition updates, and other relevant updates.
- Communication: To facilitate WhatsApp, SMS, and email communication between agents and customers (initiated by you).
- PDF Generation & Sharing: To generate proposal PDFs, lead reports, and digital visiting cards (image and vCard format) that you can share via your device’s share functionality.
- Payment Verification: To manually verify subscription payments using the UTR/reference number and optional screenshot you submit, and to activate your subscription plan once verified.
- Referral Tracking & Rewards: To track referral codes and relationships, and to credit extension-day or commission rewards to the referring manager's account per your organization's configured referral settings.
- Staff Attendance: To verify, at the moment you scan your office QR code, that you are physically present at your assigned office, and to record your check-in and check-out times for your organization’s attendance records.
- Audit & Compliance: To maintain audit logs of user actions for organizational compliance.
- Training: To deliver training content and track exam completion.
- Improvement: To analyze usage patterns and improve app performance, features, and user experience.
3. Data Sharing & Disclosure
We do not sell, trade, or rent your personal information to third parties. We may share information only in the following circumstances:
- Within Your Organization: Lead, proposal, policy, and recruitment data is shared between agents and managers within the same organization as part of the App's core functionality. For staff attendance, your manager can see your check-in and check-out times, your assigned office, and — for rejected scans — the reason and your distance in metres from the office, but never your raw GPS coordinates. Your profile photo and the fact that today is your birthday (name and photo only, not your date of birth) may also be shown to co-workers within your organization, for example on the leaderboard or a dashboard highlight.
- User-Initiated Sharing: When you choose to share PDFs (proposals, lead reports, pamphlets), digital visiting cards (image or vCard), or send WhatsApp messages, the data is shared through your device’s native sharing mechanism to your chosen recipient. Once shared this way, we have no control over further use or redistribution by the recipient.
- Service Providers: We use trusted third-party services to operate the App:
- Google Firebase — for push notifications (Cloud Messaging)
- Cloudflare (R2 Storage) — for secure storage of payment-proof screenshots and subscription QR codes
- Cloud Hosting Providers — for secure data storage and API hosting
- Legal Requirements: If required by law, regulation, legal process, or governmental request.
- Protection of Rights: To protect our rights, privacy, safety, or property, and that of our users.
4. Sensitive Data
The App processes sensitive personal information as part of insurance proposal management, including:
- Government IDs: PAN number, Aadhaar number
- Financial Information: Bank account number, IFSC code, annual/monthly income
- Health Information: Family health history, existing diseases, lifestyle habits (smoking, alcohol)
This data is collected solely for the purpose of preparing insurance proposals and is transmitted and stored securely. You are responsible for ensuring you have the customer's consent before entering their sensitive information.
Data Roles: For your own account data (name, email, phone), TechGlobe Consultancy Services LLP acts as the Data Fiduciary under the DPDP Act. For customer data entered by agents (lead details, proposal data, documents), TechGlobe Consultancy Services LLP acts as a Data Processor. The agent and their insurer are responsible as Data Fiduciaries for obtaining customer consent before entering their personal data into the App.
5. Data Storage & Security
- All data is transmitted over HTTPS (TLS encryption).
- Passwords are stored using industry-standard hashing algorithms and are never stored in plain text.
- Authentication tokens are stored in AES-encrypted secure storage (OS keystore) on your device.
- Local API response cache is encrypted using AES-256 with keys stored in secure storage.
- Uploaded documents are stored on secure cloud storage with access controls.
- Biometric authentication (fingerprint/face) is processed entirely on your device — biometric data never leaves your phone.
- The App supports screenshot and screen recording prevention for sensitive screens.
- The App blocks access on rooted/jailbroken devices and emulators for security.
While we implement commercially reasonable security measures, no method of electronic storage or transmission is 100% secure. We cannot guarantee absolute security.
Data Breach Notification: In the event of a personal data breach, we will notify the Data Protection Board of India and affected Data Principals (users) as required under Section 8(6) of the DPDP Act, 2023, without unreasonable delay.
6. Data Retention
- Your data is retained as long as your account is active and as necessary to provide our services.
- When you log out, locally cached data is cleared from your device.
- Archived leads and prospective agents are retained but hidden from active views until permanently deleted.
- If you wish to delete your account and all associated data, please contact us at the email provided below. Account deletion requests will be processed within 30 days.
- After account deletion, we may retain audit logs and anonymized data for up to 3 years as required for legal compliance, dispute resolution, and fraud prevention.
- Customer data entered by agents (lead/proposal data) is retained as long as the organization's account is active. Upon organization account termination, all associated data will be erased within 90 days unless retention is required by law.
- Staff attendance records, including the location captured at each scan, are retained for as long as your organization's account is active, as they form part of your organization's attendance and payroll records. They are erased along with your other data on account deletion, subject to the legal-compliance retention noted above.
- Data will be erased once the purpose for which it was collected has been fulfilled, in accordance with Section 8(7) of the DPDP Act.
7. Your Rights
You have the following rights regarding your data:
- Access: You can view your personal data within the App at any time.
- Correction: You can update your profile information through the App.
- Deletion: You can request deletion of your account and data by contacting us. Requests will be processed within 30 days.
- Nomination: Under Section 14 of the DPDP Act, you may nominate another person to exercise your data rights in the event of your death or incapacity. To register a nominee, contact us at the email provided below.
- Grievance Redressal: If you have any grievance regarding the processing of your personal data, you may contact our Grievance Officer at admin@techglobe.in. We will acknowledge your grievance within 48 hours and resolve it within 30 days. If you are not satisfied with our response, you may file a complaint with the Data Protection Board of India.
- Notification Preferences: You can disable push notifications through your device settings at any time.
- Contact Access: The App uses your device’s native contact picker — it never accesses your full contact list. Only the contact you explicitly select is shared with the App.
- Withdraw Consent: You may withdraw your consent at any time by deleting your account or contacting us. Withdrawal of consent will not affect the lawfulness of processing done prior to withdrawal.
8. Children's Privacy
The App is not intended for use by anyone under the age of 18. We do not knowingly collect personal information from children. If we discover that a child under 18 has provided us with personal data, we will delete it immediately.
9. Third-Party Services
The App may contain links or integrations with third-party services. These services have their own privacy policies, and we are not responsible for their practices. We encourage you to review their privacy policies.
Third-party services used:
- Google Firebase — Cloud Messaging (push notifications)
- Cloudflare — R2 object storage (payment-proof screenshots, subscription QR codes)
- WhatsApp — Messaging (user-initiated only, via URL scheme)
- YouTube — Training videos (opened in browser/app)
10. Permissions
The App requests the following device permissions:
- Internet: Required to communicate with our servers.
- Camera/Photos: To capture or select documents and images for upload, and to scan your office QR code when recording staff attendance.
- Location (Fine & Coarse): Used only by the staff attendance feature, to confirm you are at your assigned office at the moment you scan the office QR code to check in or check out. Location is read only at that instant, in response to your explicit action, and only while the App is open and in the foreground.
- Notifications: To receive push notifications and follow-up reminders.
- Biometric: For optional app lock feature (processed locally).
- Exact Alarm: To schedule follow-up reminder notifications at the correct time.
- Boot Completed: To restore scheduled notification reminders after device restart.
Note: The App does not request the READ_CONTACTS permission. Contact selection uses the device's built-in contact picker, which requires no special permission.
Note on Location: The App does not request the ACCESS_BACKGROUND_LOCATION permission and has no ability to access your location while it is closed or running in the background. Declining the location permission does not restrict any feature other than QR-based attendance check-in and check-out.
11. Data Localization
The App is designed for use in India. All scheduled notifications use Indian Standard Time (IST). The App is available in English, Hindi, and Marathi.
Data Storage Location: Application data is stored on cloud servers. Where data is processed or stored outside India, we ensure it is only transferred to jurisdictions permitted under Section 16 of the DPDP Act, 2023 or as notified by the Central Government.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by updating the "Last Updated" date at the top of this page and notifying you through the App. For any material changes to how we process your personal data, we will seek fresh consent as required under the DPDP Act. Continued use of the App after non-material changes constitutes acceptance of the updated policy.
13. Contact Us