Minimal event data such as Tag ID, timestamp, action type and technical security metadata may be retained for up to 90 days, then deleted or aggregated unless a fraud, safety or legal investigation requires a longer hold.
FindVault shows only owner-approved recovery information.
Last updated: 14 July 2026. This policy explains what data FindVault may collect for QR/NFC lost-and-found tags, activation, order requests and public scan pages.
Important clarification
Data we may collect
- Activation details: tag ID, item name/type, owner display name, phone/contact choice, optional emergency note.
- Order details: name, phone, city, pincode, address, selected products and order note.
- Verification requests, only when that separate service is selected: document type and number, expiry date, masked identity proof, invoice/RC/ownership or authorization proof, and optional supporting files.
- Scan/report information: tag ID, scan timestamp, approximate network region when available, browser/device category, repeat-scan and risk indicators, optional finder message, and precise location only when explicitly shared.
- Account details if the user signs in: email, user ID and dashboard-related data.
Document verification privacy
Document upload is not required to buy or activate a basic QR/NFC tag. Aadhaar is optional; a suitable alternative identity document may be used. If Aadhaar is voluntarily provided, users should mask its first eight digits.
Purpose, storage and access
- Documents are used only for the selected internal document-consistency review, fraud prevention, support and dispute handling.
- Files are stored in access-controlled Firebase/Google cloud storage. They are not placed in public scan or order-tracking records.
- Access is limited to authorized FindVault reviewers and infrastructure providers that process data on our behalf, or where disclosure is legally required.
- Verification is an internal consistency review—not government KYC, police/RTO verification, notarial attestation, legal certification, or conclusive proof of ownership.
Retention and deletion
- Uploaded verification files are scheduled for deletion within 30 days after approval and within 7 days after rejection or cancellation, unless a fraud investigation, dispute or law requires a longer hold.
- Minimal review outcomes and transaction records may be retained for up to 180 days or the minimum legally required period.
- To request access, correction, deletion, or withdrawal before review, email support@findvault.in with the order ID. We aim to acknowledge privacy requests within 7 days and complete valid requests within 30 days.
How we use data
- To show a safe public scan page for an activated FindVault tag.
- To help a finder contact the owner or submit a found-item report.
- To process order requests, customer support, delivery coordination and fraud prevention.
- To improve reliability, detect misuse and maintain basic audit logs.
What public scanners can see
A public scanner should only see fields the owner has approved, such as item name/type, display name, phone/WhatsApp if enabled, and optional emergency/safety note. Private dashboard/admin fields should not be shown on the public scan page.
Data sharing
We do not sell user data. We may use service providers such as Firebase/Google services for hosting, authentication, database, analytics or storage. We may share information where required for legal compliance, safety, fraud prevention or user-requested support.
Your choices
- Choose whether your phone number is visible on scan page or hidden behind report/support flow.
- Do not add sensitive address, Aadhaar, bank or private ID details to public notes.
- Ask support to correct, hide or delete your tag/contact data where applicable.
India privacy rights and grievance route
FindVault’s privacy process is designed around the Digital Personal Data Protection Act, 2023 and applicable rules as they become effective. Depending on the processing and applicable law, users can request access information, correction, erasure and grievance redressal. Requests are verified before account or tag data is changed.
Privacy and breach contact
For access, correction, deletion, grievance, or suspected data-breach reports, contact support@findvault.in or phone/WhatsApp +91 93419 34955. Include only the order/tag reference—never send passwords, OTPs or full financial credentials.
Data retention and location controls
This summary explains the operational defaults used by FindVault.
Finder contact details and consented precise location are private and scheduled for automatic deletion after 30 days, unless a safety, fraud, dispute or legal hold requires a longer period. A minimal private recovery receipt may be retained for the owner.
FindVault does not continuously collect GPS. A coarse city/region label may be inferred from network edge headers during a scan. Precise latitude/longitude is private and stored only when a finder actively enables browser location while creating a recovery case.
Owners may request account or optional profile-data deletion through the Help Center. Transaction, fraud-prevention or legally required records may be retained for the minimum necessary period.
Private owner data stays in protected records. Public scan pages receive only the fields and contact mode approved by the owner.
The website uses HTTPS in transit, Firebase access rules and role-based administration. No website can promise absolute security, so sensitive ID, OTP and banking details must never be posted.
Razorpay handles payment entry and processing. FindVault should store only order/payment references required for confirmation and support, not full card credentials.
Scan Privacy FAQ
No. A QR/NFC tag is not a GPS tracker and FindVault does not continuously follow its location.
A limited recovery/security event containing Tag ID, time, approximate city/region when available, device category, repeat-scan count and a Low/Medium/High risk label. It is not continuous movement tracking.
A coarse network region may be recorded automatically when the hosting network provides it. Precise GPS requires a clear checkbox plus browser permission, stays inside the private recovery case, and is optional.
No. FindVault stores an anonymous hash for repeat-scan abuse detection and does not display the raw IP address to the owner.
Only according to the owner’s activation preference. WhatsApp, calling, support mediation or Report Found can be enabled separately.