Releck

Privacy Policy

Last Updated: June 2026  |  Effective Date: June 2026

Your privacy is important to us. This Privacy Policy explains how Releck ("we", "us", "our") collects, uses, stores, and protects your personal information when you use the Releck mobile application and associated services. By using Releck, you consent to the practices described in this Policy.

This Policy is published in accordance with the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 ("SPDI Rules"), and the Digital Personal Data Protection Act, 2023 ("DPDPA").


1. Who We Are

Releck is a circular economy platform operated by Releck Technologies Private Limited (hereinafter "Company"), a company incorporated under the Companies Act, 2013 with its registered office in India. Releck facilitates repair, recycling, and re-commerce services for electronic devices.

  • Data Fiduciary (Controller): Releck Technologies Private Limited
  • Country of Operation: India
  • Contact: privacy@releck.com

2. Information We Collect

2.1 Information You Provide

  • Account Information: Full name, email address, mobile number, and password (stored in hashed form).
  • Profile Information: Profile picture, preferred contact details.
  • Service Information: Device details (brand, model, condition), repair descriptions, item photographs, pickup/drop-off address.
  • Payment Information: We do not store card or bank details directly. Payments are processed by Razorpay Software Private Limited, a PCI-DSS compliant payment gateway. Razorpay's privacy policy governs their data handling.
  • Communications: Messages or feedback you send us.

2.2 Sensitive Personal Data or Information (SPDI)

Under Rule 3 of the SPDI Rules, 2011, the following categories of data we may collect are classified as sensitive:

  • Password (stored as a secure hash never in plain text)
  • Financial information relating to payment transactions (processed via Razorpay)

We collect SPDI only with your explicit consent and solely for the purposes described in this Policy.

2.3 Automatically Collected Information

  • Device Information: Device type, operating system, unique device identifiers (used for push notifications).
  • App Usage Data: Features used, screens visited, error logs (collected via crash reporting tools).
  • Network Information: IP address, connectivity status.

2.4 Permissions We Request

  • Camera / Photo Library: To let you photograph devices for repair, recycling, or sale listings. We do not access your photos without your action.
  • Push Notifications: To send you service status updates and offers. You may revoke this permission at any time in your device settings.
  • Face ID (iOS): For biometric authentication. Biometric data is processed entirely on-device by Apple and is never transmitted to our servers.

3. How We Use Your Information

  • To create and manage your Releck account.
  • To provide repair, recycling, re-commerce, and wallet services.
  • To process payments through Razorpay and maintain transaction records.
  • To send order confirmations, service updates, and support communications.
  • To credit and manage your Releck Coins (reward points).
  • To improve app performance and diagnose technical issues.
  • To comply with applicable laws, regulations, and legal obligations.
  • To prevent fraud, abuse, and unauthorised access.

We do not sell, rent, or trade your personal information to third parties for their marketing purposes.


4. Legal Basis for Processing

Under the DPDPA 2023, we process your personal data on the following bases:

  • Consent: You provide consent when you agree to this Policy and create an account. You may withdraw consent at any time (see Section 8).
  • Contract: Processing necessary to deliver the services you have requested.
  • Legal Obligation: Where required to comply with applicable Indian laws (e.g., GST, anti-money-laundering regulations).
  • Legitimate Interests: To maintain security, prevent fraud, and improve our services.

5. Sharing of Information

We share your personal data only in the following circumstances:

  • Razorpay: Payment gateway for processing transactions. Razorpay is a registered payment aggregator under RBI guidelines.
  • Firebase (Google): Cloud messaging for push notifications and crash analytics.
  • Sentry: Crash reporting and error monitoring. Error reports are anonymised where possible and do not include passwords or payment details.
  • Service Partners: Authorised repair technicians or recycling partners who need your device details to fulfil your service request. They are bound by confidentiality obligations.
  • Legal Authorities: When required by law, court order, or government directive under applicable Indian law.

All third-party service providers are required to maintain the security of your personal data and are prohibited from using it for any other purpose.


6. Data Retention

  • Account data: Retained for the duration of your account and for up to 5 years after deletion (as required for tax and legal compliance).
  • Transaction records: Retained for 7 years as required under Indian tax laws.
  • Crash/error logs: Retained for 90 days.
  • Device photographs: Retained until the associated service request is closed, then deleted within 30 days.

7. Data Security

We implement reasonable security practices and procedures as required under Rule 8 of the SPDI Rules, 2011 and the DPDPA 2023, including:

  • HTTPS/TLS encryption for all data in transit.
  • Passwords stored as salted cryptographic hashes (never in plain text).
  • JWT-based authentication with short-lived access tokens.
  • Authentication credentials stored in the device's secure enclave (iOS Keychain / Android Keystore) via expo-secure-store.
  • Access controls limiting employee access to personal data on a need-to-know basis.

No security system is impenetrable. In the event of a data breach that is likely to result in risk to you, we will notify affected users and relevant authorities as required by applicable law.


8. Your Rights as a Data Principal (DPDPA 2023)

Under the Digital Personal Data Protection Act, 2023, you have the following rights:

  • Right to Access: Request a summary of the personal data we hold about you.
  • Right to Correction: Request correction of inaccurate or incomplete personal data.
  • Right to Erasure: Request deletion of your personal data, subject to legal retention requirements.
  • Right to Grievance Redressal: Raise a complaint with our Grievance Officer (see Section 10).
  • Right to Nominate: Nominate an individual to exercise your rights in the event of your death or incapacity.
  • Right to Withdraw Consent: Withdraw your consent at any time. Withdrawal will not affect the lawfulness of processing prior to withdrawal but may limit your ability to use certain features.

To exercise any of these rights, email us at privacy@releck.com. We will respond within 30 days.


9. Children's Privacy

Releck's services are intended for individuals 18 years of age and older. We do not knowingly collect personal data from minors. Under the DPDPA 2023, processing of data of children (persons under 18) requires verifiable parental consent. If you believe a child has provided us with personal data without parental consent, please contact us immediately at privacy@releck.com and we will delete the information promptly.


10. Cookies and Tracking

The Releck mobile application does not use cookies. We do not engage in cross-application tracking or share your data with advertising networks for targeted advertising. Firebase Analytics collects anonymised, aggregated usage statistics to help us improve the app.


11. Cross-Border Data Transfers

Your personal data is primarily stored and processed in India. Some service providers (Google Firebase, Sentry) may process data outside India. We ensure such transfers comply with applicable data protection laws and that adequate safeguards are in place. Under the DPDPA 2023, we will comply with any data localisation requirements notified by the Central Government.


12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes through the app or via email. Continued use of the app after such notification constitutes your acceptance of the updated Policy. The "Last Updated" date at the top of this document will always reflect the most recent revision.


⚠ Grievance Officer

As required under Rule 5(9) of the SPDI Rules, 2011 and Section 13 of the DPDPA 2023, we have appointed a Grievance Officer to address your concerns:

Name: Grievance Officer, Releck Technologies Private Limited

Email: grievance@releck.com

Address: Releck Technologies Private Limited, India

Response Time: We will acknowledge your complaint within 48 hours and resolve it within 30 days of receipt, as required by law.

If you are not satisfied with our response, you may escalate your complaint to the Data Protection Board of India once it is constituted under the DPDPA 2023.


13. Contact Us

For any privacy-related queries, requests, or concerns, please contact us: