FVFindVault
Privacy-first, honest policy

FindVault shows only owner-approved recovery information.

Last updated: 14 July 2026. This policy explains what data FindVault may collect for QR/NFC lost-and-found tags, activation, order requests and public scan pages.

Important clarification

FindVault is a scan-based recovery service, not a live GPS tracker. A verified scan may record time, approximate network region, device category and an anonymous anti-abuse fingerprint. Raw IP is not shown to the owner. Precise GPS is collected only after the finder actively gives browser permission.
No live GPS trackingApproximate network region may be logged, but precise GPS needs explicit finder consent.
Owner-approved public infoPublic scan pages should show only the contact/details chosen during activation.
Secure payment modeRazorpay checkout uses server-created orders and server-side payment verification.
Security basicsFirebase, HTTPS hosting and Firestore rules are used for app security.

Data we may collect

Document verification privacy

Document upload is not required to buy or activate a basic QR/NFC tag. Aadhaar is optional; a suitable alternative identity document may be used. If Aadhaar is voluntarily provided, users should mask its first eight digits.

Purpose, storage and access

Retention and deletion

How we use data

What public scanners can see

A public scanner should only see fields the owner has approved, such as item name/type, display name, phone/WhatsApp if enabled, and optional emergency/safety note. Private dashboard/admin fields should not be shown on the public scan page.

Data sharing

We do not sell user data. We may use service providers such as Firebase/Google services for hosting, authentication, database, analytics or storage. We may share information where required for legal compliance, safety, fraud prevention or user-requested support.

Your choices

India privacy rights and grievance route

FindVault’s privacy process is designed around the Digital Personal Data Protection Act, 2023 and applicable rules as they become effective. Depending on the processing and applicable law, users can request access information, correction, erasure and grievance redressal. Requests are verified before account or tag data is changed.

Designated privacy & grievance contactsupport@findvault.in · +91 93419 34955. Include only your order ID, Tag ID or account email. Never send an OTP or full financial credential.
Children and guardian profilesChild and safety-band profiles should be created and controlled by a parent or lawful guardian. Public pages should contain only recovery information necessary for safe contact.
FindVault does not claim to be a government identity, police, RTO or insurance verification service. Formal compliance roles and notices will be updated as the company’s legal status, scale and applicable government notifications require. Independent legal review is recommended before public launch.

Privacy and breach contact

For access, correction, deletion, grievance, or suspected data-breach reports, contact support@findvault.in or phone/WhatsApp +91 93419 34955. Include only the order/tag reference—never send passwords, OTPs or full financial credentials.

Data retention and location controls

This summary explains the operational defaults used by FindVault.

Scan event logs

Minimal event data such as Tag ID, timestamp, action type and technical security metadata may be retained for up to 90 days, then deleted or aggregated unless a fraud, safety or legal investigation requires a longer hold.

Private recovery cases

Finder contact details and consented precise location are private and scheduled for automatic deletion after 30 days, unless a safety, fraud, dispute or legal hold requires a longer period. A minimal private recovery receipt may be retained for the owner.

Location controls

FindVault does not continuously collect GPS. A coarse city/region label may be inferred from network edge headers during a scan. Precise latitude/longitude is private and stored only when a finder actively enables browser location while creating a recovery case.

Deletion requests

Owners may request account or optional profile-data deletion through the Help Center. Transaction, fraud-prevention or legally required records may be retained for the minimum necessary period.

Public versus private data

Private owner data stays in protected records. Public scan pages receive only the fields and contact mode approved by the owner.

Security

The website uses HTTPS in transit, Firebase access rules and role-based administration. No website can promise absolute security, so sensitive ID, OTP and banking details must never be posted.

Payments

Razorpay handles payment entry and processing. FindVault should store only order/payment references required for confirmation and support, not full card credentials.

Scan Privacy FAQ

Does FindVault track a tag live?
No. A QR/NFC tag is not a GPS tracker and FindVault does not continuously follow its location.
What is a Smart Scan Receipt?
A limited recovery/security event containing Tag ID, time, approximate city/region when available, device category, repeat-scan count and a Low/Medium/High risk label. It is not continuous movement tracking.
What location can be recorded?
A coarse network region may be recorded automatically when the hosting network provides it. Precise GPS requires a clear checkbox plus browser permission, stays inside the private recovery case, and is optional.
Does the owner see my IP address?
No. FindVault stores an anonymous hash for repeat-scan abuse detection and does not display the raw IP address to the owner.
Who sees phone details?
Only according to the owner’s activation preference. WhatsApp, calling, support mediation or Report Found can be enabled separately.

Return to Scan to Recover · Open Safety Center

Privacy policy tells you the rules. Trust Center shows the product in action.See Protection Modes, scan intelligence, verified handover and honest limitations.
Open FindVault Trust Center →