Effective date: 11 September 2026  |  Version 2.0

Your information should help deliver the service—not become the product.

This policy explains how MobileSutra collects, uses, shares, retains and protects personal data across MetroPark+, TempleKiosk, NGOSutra, our websites, mobile applications and WhatsApp-enabled services.

Our core commitmentsWe do not sell personal data. Parking sharing is voluntary. Payment credentials are handled by the payment gateway.
Purpose-led collectionWe collect data needed to provide, secure and improve the requested service.
Member controlNo member parking space is offered or shared automatically.
Clear choicesYou may withdraw optional consent or request access, correction or deletion, subject to law.

1. Scope and who is responsible

This Privacy Policy applies when you use a MobileSutra website, application, WhatsApp assistant or related service, or when you interact with a customer organisation using one of our products.

MobileSutra acting on its own behalf

MobileSutra determines why and how data is used for website enquiries, demonstrations, account administration, customer support, service security, billing and product improvement.

MobileSutra providing a service to an organisation

A housing society, venue, banquet hall, institute, corporate office, restaurant, valet or Pay & Park operator, temple or NGO may decide what information is entered or uploaded and who may access it. In that situation, the organisation is responsible for its collection instructions and notices, while MobileSutra processes the information to provide the contracted service.

If an organisation invited you to MetroPark+, TempleKiosk or NGOSutra, you may contact that organisation first about its records. You may also contact MobileSutra using the details at the end of this policy.

2. Personal data we may collect

ContextExamples of dataWhy it is needed
Website, demo, account and supportName, mobile number, email address, organisation, city, role, enquiry, support messages, account identifiers, IP address, browser/device information and service logs.To respond, administer accounts, provide support, operate and secure our services, and understand product performance.
MetroPark+ members and authorised usersName, mobile number, email, society or facility, flat/unit/member reference, role, vehicle number, parking-slot details, availability or sharing response, consent/preferences and authorised-user activity.To onboard the property, identify authorised users, map parking capacity, request voluntary sharing and manage visitor or event parking.
MetroPark+ guests and eventsGuest name where provided, mobile number, vehicle number/type, host and event reference, parking allocation, digital pass, arrival/departure or check-in/check-out time, gate/security status and relevant WhatsApp responses.To plan capacity, issue a parking pass and navigation, inform security, manage entry/exit and prepare event parking-utilisation reports.
Valet and Pay & ParkVehicle number, ticket/pass number, parking facility or bay, entry/exit time, operator activity, tariff, payment status and transaction reference.To manage vehicle custody or parking, calculate fees, record movement, reconcile payments and resolve operational queries.
TempleKioskDevotee contact details, selected services or bookings, donation/payment status, receipt details, preferences and transaction evidence voluntarily submitted for verification.To process bookings or donations, verify transactions, send confirmations or receipts and provide authorised reports to the temple.
NGOSutraDonor, volunteer or authorised staff contact details, selected project, donation/payment status, receipt details and operational records entered by the NGO.To manage donations, volunteers or projects, send receipts and provide authorised operational and financial reports.
Payments and billingAmount, order/invoice number, payment status, payment-method category, gateway transaction reference, refund status and billing/tax details.To initiate and reconcile payments, issue invoices or receipts, manage refunds and maintain required financial records.

We ask customers and users not to upload personal data that is unnecessary for the relevant service.

3. How we receive personal data

  • Directly from you: when you submit a form, create an account, contact support, use WhatsApp, provide event or vehicle information, make a payment or use an app.
  • From a customer organisation: for example, when an authorised society administrator uploads an onboarding spreadsheet containing member details or a venue configures its operators.
  • From a host or authorised user: when an event host uploads or enters a guest list to arrange parking.
  • Automatically: through necessary cookies, device information, access logs, delivery/status events and security monitoring.
  • From providers: such as payment status from a payment gateway or message-delivery status from a communications provider.
If you provide another person’s information, such as a guest’s mobile or vehicle number, you must be authorised to do so and should tell that person why their information is being provided.

4. How we use personal data

Depending on the service and your relationship with us, we may use personal data to:

  • provide, configure and administer the requested product or service;
  • authenticate users and apply role-based access;
  • send operational WhatsApp messages, email reports, passes, receipts, alerts and service notifications;
  • allocate parking, guide vehicles, support gate or valet operations, and record check-in and check-out;
  • process and reconcile payments, refunds, fees and, where enabled, parking-sharing payouts;
  • generate utilisation, operational, donation, booking or financial reports for authorised recipients;
  • provide support and resolve disputes or technical problems;
  • protect users and services, prevent misuse or fraud, monitor reliability and maintain audit logs;
  • improve features using aggregated or appropriately de-identified insights where practical; and
  • comply with applicable law, enforce our terms and respond to lawful requests.

Where consent is the appropriate basis, we request it through a clear affirmative action. In other cases, processing may be needed to provide a requested service, carry out a customer organisation’s instructions or meet a legal obligation, as permitted by applicable law.

5. MetroPark+ event and visitor parking

Member onboarding and parking sharing

An authorised society or facility administrator may upload member contact and parking information. MetroPark+ may then send an invitation asking the member whether they wish to participate. Participation and parking-slot sharing are voluntary. A member’s parking space is not offered to a visitor or event unless the member or authorised property user takes the relevant affirmative action.

Guest parking

An authorised host may provide a guest’s contact and vehicle details for a specific event or visit. MetroPark+ may contact the guest on WhatsApp to complete vehicle details, deliver a digital parking pass, provide navigation or arrival instructions, and send service-related updates.

Security, valet and operator access

Authorised security, valet or parking personnel may see only the information needed for their workflow, such as expected vehicle number, parking allocation, pass validity and check-in/check-out status. The customer organisation is responsible for granting and removing its authorised-user access.

Event parking-utilisation report

After an event, MetroPark+ may email authorised recipients a report containing event-level statistics and operational records, such as invited/registered vehicles, allocated and used spaces, shared-space participation, arrivals, departures, overflow and payment information where applicable. Reports are not intended for public distribution and should be handled securely.

Members may withdraw from optional collaborative parking for future events using the preference or opt-out method provided, through their society or facility administrator, or by contacting MobileSutra. Withdrawal does not invalidate processing already completed for an event or prevent retention required for security, disputes, accounting or law.

6. WhatsApp communications

Some MobileSutra products use WhatsApp as a service interface. Messages may include onboarding invitations, consent or preference requests, guest vehicle-detail collection, parking passes, navigation, entry/exit updates, receipts, booking confirmations and support responses.

To deliver these messages, relevant data and message metadata are processed through WhatsApp/Meta and an authorised WhatsApp Business solution provider. Their processing is also governed by their applicable terms and privacy notices.

  • Operational messages are sent for a requested or authorised service.
  • Promotional communications, if any, will be managed separately and may be stopped using the method provided in the message or by contacting us.
  • Do not send sensitive or unnecessary information through WhatsApp.

7. Payments

Payments may be facilitated by third-party gateways such as Razorpay, Cashfree or another gateway identified at checkout. The gateway collects and processes payment credentials under its own privacy policy and security obligations.

MobileSutra does not receive or store your complete card number, card security code, online-banking password or UPI PIN. We may receive limited transaction information—such as order number, amount, status, payment-method category, gateway reference, refund status and webhook records—to confirm payment, issue a receipt, reconcile accounts and resolve disputes.

Where member earnings, revenue sharing, refunds or payouts are enabled, additional identity, bank or UPI-related information may be collected by an authorised payment/payout provider as needed for that transaction and applicable compliance checks.

8. When we share personal data

We do not sell personal data. We may disclose limited information only as needed to:

  • Customer organisations and authorised users: such as a society administrator, host, venue manager, security team, valet, parking operator, temple trustee or NGO administrator, according to role.
  • Service providers: cloud/database providers, WhatsApp/communications providers, email delivery services, payment gateways, analytics, monitoring, support and security vendors.
  • Professional advisers: auditors, accountants, lawyers or insurers where reasonably necessary and subject to confidentiality duties.
  • Authorities or legal parties: where required by law, legal process, a valid government request, or to protect rights, safety and service integrity.
  • Business transaction participants: in a merger, financing, restructuring or transfer of business, subject to confidentiality and lawful processing requirements.

Service providers are permitted to process data for the services they provide and must protect it under their contracts and applicable law.

9. How long we retain data

We retain personal data only for as long as needed for the original purpose, the customer’s documented service requirements and applicable legal, accounting, security and dispute-resolution obligations. Retention therefore varies by data type rather than following one period for every record.

  • Event and visitor records: long enough to operate the visit/event, provide the utilisation report, investigate issues and meet configured or lawful record-keeping needs.
  • Account and configuration data: while the relationship is active and for a reasonable period afterwards for support, reactivation, audit or disputes.
  • Payment and billing records: for reconciliation and the period required by tax, accounting and other applicable laws.
  • Consent, preference and security logs: as reasonably needed to demonstrate choices, prevent misuse, investigate incidents and comply with law.
  • Backups: deleted or overwritten through the normal backup lifecycle; access is restricted and restored backups remain subject to deletion controls.

When data is no longer required, we delete it, anonymise it or place it beyond ordinary use, unless continued retention is permitted or required by law.

10. How we protect personal data

We use reasonable technical and organisational safeguards appropriate to the service. These may include encryption in transit, access controls, role-based permissions, authentication, logging, monitoring, backups, limited administrative access and contractual safeguards with providers.

No online service can be guaranteed completely secure. Users and customer organisations must protect credentials, restrict administrative access, remove former staff promptly and avoid exporting or sharing reports unnecessarily.

If we become aware of a personal-data breach, we will investigate, take reasonable containment and remediation steps, and provide notifications where required by applicable law.

11. Your choices and privacy rights

Subject to applicable law, including India’s Digital Personal Data Protection Act, 2023 and the rules brought into force under it, and verification of identity and authority, you may ask to:

  • receive information about personal data being processed and relevant disclosures;
  • correct, complete or update inaccurate or incomplete data;
  • delete data that is no longer needed or withdraw consent where processing relies on consent;
  • stop optional promotional communications;
  • withdraw from future voluntary parking-sharing requests; and
  • raise a grievance about our handling of your information.

Some requests may be handled by the society, venue, temple, NGO or other customer organisation that supplied or controls the record. We may route your request to that organisation and assist it. We may retain information where deletion would conflict with a legal obligation, active transaction, security requirement or legal claim.

We will not discriminate against you for making a privacy request, although withdrawing information necessary for a service may prevent continuation of that service.

12. Children’s data

Our services are intended for adults and authorised organisational users and are not designed for independent use by children. A parent or lawful guardian should provide or authorise personal data relating to a person under 18 where required. Organisations and hosts should avoid adding a child’s contact details unless necessary and lawfully authorised.

If you believe a child’s data was provided without appropriate authorisation, please contact us so we can investigate and take suitable action.

13. Data storage and locations

MobileSutra and its providers may process or store information in India or in other countries where they operate. Where personal data is transferred or made accessible across borders, we use contractual, technical and organisational safeguards and follow transfer restrictions applicable under Indian law.

Third-party websites, WhatsApp, app stores and payment gateways operate under their own privacy notices. We encourage you to review those notices when using their services.

14. Changes to this policy

We may update this policy when our products, providers or legal obligations change. We will post the revised policy with a new effective date. If a change materially affects registered users, we will provide an additional notice through the website, application, email, WhatsApp or another appropriate channel.

15. Contact and grievance requests

For a privacy question, access/correction/deletion request, consent withdrawal or grievance, contact:

Privacy Contact — MobileSutra
Email: sanjayathavale@mobilesutra.com
Website: www.mobilesutra.com

Please identify the relevant product, society/venue/temple/NGO, your relationship to the record and the request you want us to handle. We may ask for reasonable verification before acting and will respond within the period required by applicable law.