Z
Zuvon
Data Protection & Privacy Policy

Privacy Policy & DPDP Act Compliance

Effective Date: October 2026 • Governing Law: Republic of India (Digital Personal Data Protection Act, 2023 & Information Technology Act, 2000)

Important Platform & Regulatory Disclosures

Not a Financial Institution: This platform is strictly a promotional rewards marketplace. We are not a bank, lender, credit broker, insurer, or financial advisor. We do not provide financial, investment, or credit advice.

Provider Discretion & Approval: All external offers, applications, accounts, or services are provided exclusively by independent third-party providers. The third-party provider alone determines eligibility, underwriting, credit approval, and terms of service.

Promotional Rewards Policy: Rewards are conditional promotional incentives issued exclusively upon successful manual verification of submitted proof or automated provider postbacks in strict compliance with platform terms. Rewards are not guaranteed and may be withheld or reversed if terms are violated.

1Scope, Identity & Platform Role

Zuvon ("we", "us", or "our") operates as an independent promotional rewards and campaign discovery marketplace. We connect consumers with third-party software, applications, services, and promotional opportunities.

Zuvon is not a bank, Non-Banking Financial Company (NBFC), lender, insurer, credit broker, or financial advisor. We do not offer banking products, deposit accounts, credit cards, or loans. This Privacy Policy informs Data Principals (our users) of how we collect, use, process, store, protect, and delete personal data in accordance with the Digital Personal Data Protection Act, 2023 ("DPDP Act"), the Information Technology Act, 2000, and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.

2Data Collection & Purpose Limitation Matrix

In strict compliance with the purpose limitation principle under Section 4 and Section 6 of the DPDP Act 2023, Zuvon collects only the minimum personal data strictly necessary to operate the rewards marketplace:

Data ElementPurpose LimitationStorage & Security
Account Identity (Name, Email)User authentication, session security, transactional email alerts, and ledger account binding.Encrypted database (PostgreSQL with Row-Level Security).
Verification Proof (Screenshots)Manual & automated verification that an external offer requirement was satisfied.Private cloud storage (S3) with zero public access. Accessed solely via short-lived signed URLs.
Cryptographic Hash (SHA-256)Deduplication and anti-fraud enforcement (prevents submission of identical images across accounts).Stored as 64-character hexadecimal digest. Irreversible one-way mathematical function.
Network Forensics (Salted IP Hash)Distributed rate limiting, bot protection, and click-fraud detection.Raw IP addresses are never persisted. Hashed with a server-side cryptographic salt.
Payout Credentials (UPI ID / Bank details)Disbursal of cleared user rewards upon requested withdrawal.Encrypted at rest using authenticated AES-256-GCM encryption.

3. Strict Prohibition of Sensitive Personal Credentials in Proof Uploads

When submitting proof of completion for third-party offers, users are strictly prohibited from uploading screenshots containing sensitive personal, financial, or confidential information, including:

  • Aadhaar numbers or Government identity card numbers
  • Permanent Account Numbers (PAN)
  • Bank account passwords, NetBanking credentials, or UPI/ATM PINs
  • Credit / Debit card CVVs, full 16-digit card numbers, or card expiry dates
  • One-Time Passwords (OTPs) or two-factor authentication recovery codes

Mandatory Redaction: You must crop, black out, or redact any sensitive personal identifiers prior to uploading. Submissions containing visible sensitive personal credentials will be automatically rejected to protect your privacy.

4Lawful Basis for Data Processing

Under Section 4 and Section 6 of the DPDP Act 2023, Zuvon processes personal data based on:

  • Affirmative Informed Consent: Expressly provided by the Data Principal at registration and proof submission.
  • Legitimate Uses (Section 7 DPDP Act): For verifying transactions, preventing cyber incidents, enforcing distributed rate limits, and investigating fraudulent behavior.
  • Compliance with Legal & Statutory Obligations: Meeting statutory financial accounting and audit requirements under applicable Indian legislation.

5Third-Party Sub-Processors & Data Infrastructure

To deliver reliable, secure infrastructure, Zuvon utilizes verified third-party technology providers bound by strict confidentiality and security commitments:

  • Supabase Inc.: Managed relational database (PostgreSQL) and user authentication service with Row-Level Security (RLS) enforcement.
  • Amazon Web Services (AWS S3): Encrypted private cloud storage for proof screenshots with short-lived pre-signed URL access.
  • Upstash Inc.: Serverless Redis used for high-speed distributed rate limiting, concurrent withdrawal locks, and brute-force mitigation.
  • Resend Inc.: Transactional email infrastructure for delivering security alerts, withdrawal receipts, and account notifications.
  • Google LLC (Google Identity): OAuth 2.0 single sign-on provider.

We never sell, rent, lease, or monetize your personal data to data brokers or cross-context behavioral advertising networks.

6Cookies & Tracking Mechanics

Zuvon utilizes first-party cookies strictly required for security, session persistence, and offer conversion attribution:

  • Session Authentication Cookies: Cryptographically signed session tokens ensuring authorized access (marked HttpOnly, Secure, SameSite=Lax).
  • Attribution Cookies (ref_clk_*): Short-lived tracking identifiers generated when you click an offer link, enabling us to match your proof submission to your click session.

We do not deploy invasive third-party tracking pixels (e.g. Facebook/Meta Pixel or TikTok tracking scripts).

7Data Retention & Statutory Accounting Obligations

Zuvon maintains clear separation between operational data and statutory financial records:

  • Operational Verification Data: Proof submissions and click attribution records are retained for the duration of the offer verification, review, and dispute window.
  • Statutory Financial Ledger: In accordance with Section 128 of the Indian Companies Act, 2013 and Section 44AA of the Income Tax Act, 1961, books of accounts, reward records, and double-entry transaction ledgers must be retained for at least eight (8) financial years. If an account is deleted under data privacy provisions, personal identifiers are anonymized while preserving ledger reconciliation consistency.

8Rights of Data Principals (DPDP Act, 2023)

Under Chapter III of the DPDP Act 2023, you are entitled to exercise the following rights regarding your personal data:

Right to Access & Portability

You can download a machine-readable JSON copy of your profile, clicks, proofs, and ledger history via our self-serve data export endpoint at /api/user/export-data.

Right to Correction & Rectification

Update your name, contact phone, or marketing preferences at any time directly through your account profile settings.

Right to Erasure / Deletion

Initiate account deletion via /api/user/delete-account. Your personal credentials are permanently anonymized, subject only to statutory ledger retention requirements.

Right of Grievance Redressal

Lodge complaints or grievances directly with our designated Grievance Officer in accordance with statutory response timelines.

9. Designated Grievance Officer & Statutory Redressal Mechanism

In compliance with Rule 3(2) of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 and Section 10 of the DPDP Act, 2023, the details of our designated Grievance Officer are set forth below:

Designation: Grievance Officer & Compliance Lead

Entity: Zuvon Technologies

Email for Grievances: grievance@zuvon.in

General Inquiries: support@zuvon.in

Jurisdiction / Location: Bengaluru, Karnataka, India

• Acknowledgment SLA: Within 48 hours of ticket receipt.

• Resolution SLA: Within 30 calendar days from the date of receipt.

Have questions regarding our privacy practices? Reach our compliance desk at Contact Support.