Privacy Policy
Plain-English summary first. Operational detail below. Both reflect how Dwize actually handles your data.
1. Plain-English summary
Dwize collects only what is needed to operate your Care Year and respond to your inquiries. We do not sell your data. We do not run third-party advertising networks on Dwize-built surfaces. Your contact details, business details, and project context are visible only to the Dwize operator on your account and our infrastructure providers acting under our instructions.
2. Who we are
DWIZE OFFICE SOLUTION, registered in Bikaner, Rajasthan, India, GSTIN 08FPPPR8719E1Z5. Public-facing operator: Arun Ranga. Contact: [email protected] or WhatsApp +91 96024 85318.
3. What we collect
- Inquiry data — name, contact channel (WhatsApp / email / phone), business name, brief description of what you need. Voluntarily provided when you contact us.
- Care Year data — content, brand assets, login details for any third-party services you ask us to integrate. Strictly for delivering and operating your product.
- Site analytics — anonymized page-view, referrer, and rough geography via Google Analytics 4 (only when configured by the customer or on dwize.in itself). No personal identifiers.
- Server logs — IP address, user agent, request path on dwize.in, retained for 30 days for security and abuse handling.
4. What we do not collect
- Bank account / card details (handled by Razorpay or your payment gateway directly; Dwize never sees them).
- Aadhaar, PAN, or any KYC documents — not needed for product purchase.
- Your customers' personal data (when we operate your Store / Brand, your customer data is yours, stored in your tenant schema; Dwize accesses only as needed for operations under written contract).
- Behavioral data for advertising purposes. We do not run retargeting, fingerprinting, or cross-site tracking.
5. How long we keep it
- Active Care Year customers — for the duration of the year plus 30 days for handover.
- Inquiry data from non-customers — up to 12 months unless you ask us to delete sooner.
- Server logs — 30 days, then automatically purged.
6. Who sees it
Inside Dwize: only the named operator on your account, plus the technical lead. Outside Dwize: our infrastructure providers acting under data-processing terms, listed below.
- Cloudflare (edge delivery, security)
- Supabase (database, hosted in Mumbai region for Indian customers)
- Razorpay (payments, when applicable to your product)
- ZeptoMail (transactional email)
- Upstash (sessions and caching, TLS-encrypted)
- Google Analytics 4 (only when configured)
7. Cookies
dwize.in uses functional cookies for the dark/light theme preference (stored in dwize-color-mode). When Google Analytics 4 is configured, it sets standard GA cookies. No advertising cookies, no cross-site trackers.
8. Your rights
- Access — ask what we have on you. We respond within 7 business days.
- Correction — fix any wrong data we have.
- Deletion — delete inquiry data on request. Active-contract data is deleted within 30 days of contract end (covenant 08).
- Portability — export your Care Year data in a portable format at any time, free.
- Complaint — write to us; if not satisfied, complain to the relevant Indian regulator.
9. Cross-border transfer
Data is primarily stored in India (Mumbai region for Supabase). Cloudflare's edge layer may serve cached static content from non-Indian edges; this never includes personal data. ZeptoMail email content traverses ZeptoMail's infrastructure for delivery. We make reasonable efforts to keep personal data in India.
10. Updates to this policy
We refresh this policy when we materially change how we handle data. The "Last refined" date at the top reflects the current version. Material changes are notified to active Care Year customers by email at least 14 days before they take effect.
11. Contact
Questions or requests on this policy go to [email protected] with subject "Privacy". Acknowledged within 2 business hours per the Care Year covenants.