Privacy Policy
Effective date: 16 July 2026
Linswing ("we", "us", or "our") operates the platform accessible at https://linswing.com, associated subdomains, and our Linswing mobile applications for Android and iOS (collectively, the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service. We process personal data in accordance with applicable Indian law, including the Digital Personal Data Protection Act, 2023 ("DPDP Act"). Please read it carefully.
1. Information We Collect
We collect information in the following ways:
a) Information you provide directly
- Account registration: Name, email address, mobile number, organisation name, and password when you create a workspace.
- Billing information: Legal entity name, billing email, GSTIN, and postal address. Payment card details are processed directly by Razorpay and are not stored on our servers.
- Profile information: Details about your facility management company or residential community, including number of units and staff count.
- Communications: Messages you send us through the contact form or by email.
- Staff KYC / identity documents: Facility-management and society administrators may upload identity and verification documents for their on-ground staff (for example Aadhaar, PAN, passport, driving licence, police verification, address proof, or offer letters), along with a staff photograph. This is sensitive personal data and is described further in Section 2.
- Other photos and documents: Images and files you upload — such as photos attached to maintenance tickets and incident reports, visitor photos, patrol checkpoint photos, and photographs of vendor invoices. Invoice photos are processed by an AI model via our cloud provider (Amazon Bedrock) to extract details such as the vendor name, amount, and date for your review before you approve them.
b) Information collected automatically
- Usage data: Pages visited, features used, time spent, actions taken within the platform, and error logs.
- Device and browser data: IP address, browser type and version, operating system, device identifiers, and referring URLs.
- Cookies and similar technologies: Session cookies necessary for authentication, and analytics cookies to understand how users interact with the Service.
c) Information collected through our mobile apps
- Location data (precise and background): With your permission, our mobile apps monitor your device's location to detect when on-shift field staff (such as security guards or facility staff) cross the boundary of their assigned site. Monitoring runs only while you are signed in and on duty, and stops when you go off shift or sign out. We record boundary-crossing events — including approximate coordinates and the time — so that site administrators can be alerted if staff leave the premises. We do not track continuous location or keep movement history, and location is never collected for residents, committee members, or when you are signed out.
- Camera: With your permission, the apps use the camera to capture staff KYC documents, staff and attendance photos, visitor passes, patrol checkpoints, and invoice photos. The camera is used only when you actively choose to capture an image.
- Push notification tokens: Device tokens issued by Apple Push Notification service (APNs) and Google Firebase Cloud Messaging (FCM), used to deliver alerts such as visitor arrivals, approvals, and operational notifications.
- Crash and diagnostic data: If the app crashes or misbehaves, we collect crash reports and performance diagnostics (via Sentry) to fix problems and improve stability.
2. Sensitive Personal Data — Staff KYC & Identity Documents
To help facility-management companies and residential societies verify the people working at their sites, authorised administrators may upload staff identity documents (including government-issued IDs such as Aadhaar or a similar national identity document). Because these are sensitive, we apply heightened protections:
- Purpose limitation. Identity documents are used solely to verify a staff member's identity and eligibility to work at a site. We do not use them for any other purpose, and we do not sell them or share them with third parties, except our infrastructure provider (AWS) for secure storage on our behalf.
- Access control. Only authorised administrators of the relevant workspace can view or manage these documents. Residents, other tenants, and unauthorised staff cannot access them. Access is enforced by role-based permission checks on every request.
- Encryption & secure access. Documents are encrypted in transit (HTTPS/TLS enforced) and at rest, stored in access-restricted storage that blocks all public access in the AWS Asia Pacific (Mumbai /
ap-south-1) region, and are only ever served through short-lived, individually-signed links — never public or shareable URLs. - Retention & deletion. Identity documents and staff photos are retained only while the staff member is active on your roster. When a staff member is removed, or when you delete an individual document, the underlying files are permanently and irreversibly purged within 30 days.
- Aadhaar and national IDs. Where an administrator chooses to upload an Aadhaar or other national identity document, handling is subject to applicable Indian law and UIDAI guidelines. We do not use Aadhaar for authentication and do not disclose it to any third party. We encourage administrators to collect only the minimum documents necessary.
- Administrator responsibility & consent. If you upload another person's identity documents, you confirm that you have informed them and have a lawful basis and their consent to collect, store, and process those documents through the Service.
3. How We Use Your Information
We use the information we collect to:
- Create, maintain, and secure your account and workspace.
- Verify the identity of staff members using the KYC documents you upload (Section 2).
- Process payments and issue GST-compliant invoices through Razorpay.
- Provide, operate, and improve the Service.
- Send transactional communications: account setup, payment receipts, trial reminders, and password resets.
- Deliver push notifications and operational alerts — including alerting site administrators when on-shift field staff cross their assigned site boundary.
- Respond to support requests and enquiries.
- Detect, investigate, and prevent fraudulent or unauthorised activity.
- Comply with legal obligations applicable in India, including GST laws and data protection requirements.
- Analyse aggregate usage patterns to improve product features — this analysis uses anonymised or aggregated data where possible.
4. Sharing of Information
We do not sell your personal information. We share data only in these circumstances:
- Service providers: Amazon Web Services (cloud infrastructure, storage, email via SES, and AI-assisted document processing via Amazon Bedrock), Razorpay (payment processing), Apple (APNs) and Google (Firebase Cloud Messaging) for push-notification delivery, Sentry (crash and performance diagnostics), and other vendors who process data on our behalf under appropriate data processing agreements.
- Within your organisation: Administrators of your workspace may view member information within that workspace, subject to the access controls described in Section 2 for identity documents.
- Legal compliance: When required by applicable Indian law, court order, or regulatory authority.
- Business transfers: In connection with a merger, acquisition, or sale of assets, with notice provided to affected users.
5. Data Retention
We retain your data for as long as your account is active. If you cancel your subscription, your workspace data is retained for 90 days to allow recovery, after which it is deleted.
Staff KYC / identity documents and staff photos are retained only while the staff member is active on your roster. When a staff member is removed, or when an individual document is deleted, the underlying files are permanently purged within 30 days (our storage is versioned, and an automatic lifecycle rule erases the retained copies at the 30-day mark).
Billing records and invoices are retained for 7 years as required by Indian GST regulations. You may request deletion of your personal data by contacting us at admin@linswing.com.
6. Cookies
We use strictly necessary cookies for authentication and session management. We also use analytics cookies to understand how the Service is used. You can control cookies through your browser settings; however, disabling necessary cookies may affect Service functionality.
7. Security
We implement industry-standard security measures, including:
- TLS encryption for all data in transit, with non-HTTPS access to stored files explicitly denied.
- Server-side encryption of stored files at rest.
- Storage buckets configured to block all public access, with sensitive documents served only through short-lived, individually-signed links.
- Strict role-based access controls enforced on every request.
- Versioned storage with automatic retention limits, and regular security reviews.
Our infrastructure runs in the AWS Asia Pacific (Mumbai / ap-south-1) region. No method of transmission over the internet is 100% secure, and we cannot guarantee absolute security; however, we work continuously to protect your information using the measures above.
8. Your Rights
Under the DPDP Act and applicable law, you have the right to:
- Access: Request a copy of the personal data we hold about you.
- Correction: Request correction of inaccurate or incomplete data.
- Deletion: Request deletion of your personal data, subject to legal retention requirements.
- Portability: Request your data in a structured, machine-readable format.
- Grievance redressal: Raise a concern about how your data is handled and have it addressed.
To exercise any of these rights, email us at admin@linswing.com. We will respond within 30 days.
9. Third-Party Payment Processing
Payments are processed by Razorpay Software Private Limited. When you make a payment, you are subject to Razorpay's privacy policy and terms in addition to ours. We share only the information necessary (billing name, email, and order details) with Razorpay to process your transaction. Card and UPI details are handled entirely by Razorpay and never reach our servers.
10. Children's Privacy
The Service is intended for use by businesses and is not directed at individuals under 18 years of age. We do not knowingly collect personal information from minors.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by email or by posting a prominent notice on the Service at least 14 days before the changes take effect. Your continued use of the Service after the effective date constitutes acceptance of the revised policy.
12. Contact Us
If you have questions or concerns about this Privacy Policy, please contact: