Who this policy covers
This policy applies to the Crosbyte website, customer and worker applications, and support services. Crosbyte is the data fiduciary for personal data used to provide these services.
Personal data we collect
Depending on your use, we may collect account and contact details, worker profiles, identity and verification documents, location, transactions, searches, favourites, enquiries, reviews, support messages, device information, security logs and notification tokens. Crosbyte does not store complete card, UPI PIN or banking credentials.
Why we use personal data
We use data to create and secure accounts, verify workers, publish profiles, match nearby services, create consented enquiries, process recharges and verification fees, deliver notifications, provide support, prevent fraud, meet legal duties and improve the platform. We do not sell personal data.
Consent, permissions and choices
Collection notices explain the requested data and purpose. You may decline optional location, camera, photo or notification permissions, though related features may be unavailable. You may withdraw consent, subject to records we must retain for security, disputes or law.
When we share data
We share only necessary information with customers and workers for service interactions; providers supporting SMS, maps, notifications, payments, verification, hosting and support; authorities and advisers when legally required; and protected business transferees during a transaction. Payments may be processed by PhonePe or another approved payment provider. Crosbyte does not receive or store your UPI PIN, card PIN or complete payment credentials.
Retention and deletion
We keep data only for its purpose, an active account, disputes, fraud prevention, audit or law. When no longer needed, it is deleted, anonymized or isolated. Limited backup and legally required transaction, consent, security or complaint records may remain.
Security and incidents
Crosbyte uses access controls, password hashing, encryption in transit, restricted administration, audit logs, backups and monitoring. No system is completely secure; suspected breaches are investigated and notifications are made when required by law.
Your rights and grievance process
Subject to applicable law, you may request access, correction, completion or erasure of data, withdraw consent, seek grievance redressal, or nominate another person for applicable rights. Requests may be submitted through your account, support or Contact Us, and identity may be verified.
Children’s data
Crosbyte is intended for adults able to enter service arrangements. Children must not create worker accounts or submit verification documents. Data collected without required consent or authorization will be restricted and deleted as required.
Policy updates and legal references
We may update this policy when services, providers or legal requirements change and will communicate material changes. It is designed with reference to India’s Digital Personal Data Protection Act, 2023 and Digital Personal Data Protection Rules, 2025, including phased commencement.
