Legal
Privacy policy
What we collect, why we collect it, who sees it, and how to get it back.
Draft pending legal review
This wording is a working draft prepared for the site build. It describes the company's actual practices but has not been reviewed by counsel, and the marked fields are unfilled. Obtain review before publishing, then remove this notice.
- Applies to
- Virashu Global Private Limited and its products
- Last updated
- 19 September 2026
- Grievance officer
- See the escalation route
Who is responsible for your data
Virashu Global Private Limited is the entity that decides how personal data is used on this website and across the Hikkari platform. Where a group entity operates its own service, this policy applies to the group's shared functions, and any additional terms specific to that service will be published with it.
What we collect
| Category | What it includes | Why |
|---|---|---|
| Repair requests | Device model, symptoms you describe, repair category we resolve it to, and the quotes you receive. | To run the diagnosis and the blind auction, and to show you comparable offers. |
| Contact details | Phone number for OTP verification and for coordination once you accept a quote. | To verify you and to connect you with the vendor you select. |
| Photographs | Images you upload of the device, after the redaction steps described below. | To assess visible damage and recommend a repair category. |
| Approximate location | A location used to find vendors within a workable distance. | Matching you to nearby shops. The auction is hyper-local by design. |
| Vendor KYC | Business name, GSTIN, bank account details for penny-drop verification, UPI identifier, and identity documents. | To confirm a repair shop is a real registered business before it can receive leads, and to meet our obligations as a marketplace. |
| Messages | WhatsApp messages exchanged with us or, for vendors, with the bidding system. | To deliver notifications, bids and support. |
Photographs and the vision pipeline
A photograph of a damaged phone is also a photograph of whatever was on its screen. We treat that as a privacy problem, not as an implementation detail. Before any image is sent to an external model, the following run on our side:
- Blur detection, so we can tell you to retake an unusable photo rather than guess from it.
- Local optical character recognition, to read on-screen text for context about the fault.
- Face redaction, so people reflected or shown in a photograph are removed before the image leaves our infrastructure.
Only the redacted image is used for defect detection. We do not use photographs of your device to train models, and we do not use them for advertising.
Who can see your data
Vendors participating in your repair request see the device model, the standardised repair category and the redacted photographs. They do not see your phone number until you accept their quote, and they never see another vendor's pricing.
We use external providers for defined functions:
- WhatsApp Cloud API, operated by Meta, for messaging and bid submission.
- Cloud vision providers for defect assessment, receiving only redacted images.
- A KYC provider for GSTIN verification, bank penny-drop and identity checks.
- SMS gateway services for one-time passwords.
We do not sell personal data. We disclose it where the law requires, or where it is necessary to establish or defend a legal claim.
How long we keep it
Retention periods are being finalised against our statutory obligations and are marked for confirmation before launch:
- Repair request and quote history: [to be added]
- Vendor KYC records: [to be added], as required for marketplace compliance.
- Uploaded photographs: retained only as long as needed for the repair assessment and any warranty claim.
- Website server logs: [to be added].
Your rights
Under the Digital Personal Data Protection Act, 2023, you can ask for a summary of the personal data we hold about you, request correction of anything inaccurate, request erasure where we no longer have a lawful reason to keep it, withdraw consent you previously gave, nominate another person to exercise your rights in the event of death or incapacity, and complain to us or to the Data Protection Board of India.
Write to the grievance officer listed on ourgrievance redressal page to exercise any of these. We respond within the timeframes published there.
Children
This website and the Hikkari platform are not directed at children, and we do not knowingly process the personal data of children. If you believe a child has provided us with personal data, contact the grievance officer and we will delete it.
Security
Access to personal data is limited to people who need it for their role. Vendor bank details and identity documents receive additional access restrictions. Webhook traffic from WhatsApp is verified by signature before it is processed, and verification codes are single-use and expiring. No system is perfectly secure, and if a breach affects you we will notify you and the Data Protection Board as required by law.
Cookies and analytics
This website does not set advertising or tracking cookies. If analytics are introduced, this section will be updated first and, where consent is required, it will be requested before any non-essential cookie is set.
Changes
When this policy changes materially, we will revise the date at the top of the page and, where the change affects you significantly, tell you through the channel you normally hear from us on.
Contact
For any privacy question, write to [to be added]or use the contact page.