Privacy Policy
Effective date: 7 May 2026
Zoma Living ("we", "us", or "our") operates ZomaLinks, a software-as-a-service product accessible at zomalinks.com. This Privacy Policy explains what personal data we collect, how we use it, with whom we share it, how long we keep it, and the rights you have under the Digital Personal Data Protection Act, 2023 (DPDP) and other applicable laws.
By using ZomaLinks you agree to this policy. If you do not agree, do not use the service.
1. Who We Are
We are Zoma Living, based in India with its principal office at Sector 57, Gurugram, Haryana, India. For privacy queries write to support@zomalinks.com.
2. Personal Data We Collect
2.1. Data you provide: (a) email address (required for OTP login); (b) full name and display name; (c) profile photo; (d) business details such as RERA registration number, brokerage name, locations served, and listing details; (e) custom links, biography text, and content blocks you publish to your public profile; (f) communications you send to support@zomalinks.com; (g) inquiries that visitors submit to your profile, which we display in your dashboard.
2.2. Data we collect automatically: (a) IP address, device type, browser, operating system, and approximate location (city level) for security and analytics; (b) page-view events on your public profile (anonymous to the visitor; only aggregated counts are shown to you); (c) cookies and similar technologies as described in Section 7.
2.3. Data from payments: (a) when you start a Pro subscription, our payment processor Razorpay Software Private Limited collects your card or UPI details directly. We do not see, store, or process your full card number, UPI PIN, or CVV. We receive only metadata: a Razorpay subscription identifier, payment status, charge amount, last four digits of the card or UPI handle, and timestamps.
2.4. We do not knowingly collect personal data of children under 18. If you believe a child has provided us data, write to support@zomalinks.com and we will delete it.
3. Why We Process Your Data (Purposes and Lawful Bases)
We process personal data only for the purposes below and only on a lawful basis under the DPDP Act: (a) operating the service (consent and contractual necessity): account creation, public profile rendering, dashboard, lead capture; (b) processing payments (contractual necessity): subscription billing via Razorpay; (c) sending transactional email (consent and contractual necessity): OTPs, payment receipts, account notices, security alerts; (d) analytics and product improvement (legitimate interests): aggregate page-view counts, dashboard analytics shown only to you; (e) safety and fraud prevention (legitimate interests and legal obligation): rate-limiting OTP requests, blocking abusive accounts, complying with court orders; (f) marketing (separate consent): we do not send marketing email by default. If you opt in, you can opt out from any marketing email or by writing to support@zomalinks.com.
4. With Whom We Share Your Data
We share data only with the parties below and only as necessary: (a) Razorpay Software Private Limited (payment processing). Razorpay's privacy policy applies to data they collect directly. See razorpay.com/privacy. (b) Resend Inc. (transactional email delivery). See resend.com/legal/privacy-policy. (c) Appwrite Inc. (database, authentication, file storage). See appwrite.io/privacy. (d) Netlify Inc. (web application hosting and edge delivery). See netlify.com/privacy. (e) law enforcement, courts, regulators, or other government authorities when legally compelled by valid order issued under Indian law or the law of a competent jurisdiction. (f) successors in interest in the event of a merger, acquisition, or sale of assets, subject to the acquirer agreeing to honour this policy.
We do not sell, rent, or trade your personal data.
5. International Data Transfers
Some of our service providers process data outside India (typically in the United States or European Union). Where data leaves India, we rely on standard contractual safeguards offered by those providers. The DPDP Act and Government of India notifications determine which countries data may be transferred to. We comply with such notifications when issued.
6. Data Retention
(a) Account data is retained while your account is active. (b) After account deletion, we delete personal data within 30 days. Backups are deleted within 90 days. (c) Payment records and tax invoices are retained for 8 years to comply with the Income-tax Act, 1961 and the Central Goods and Services Tax Act, 2017. (d) Server access logs are retained for 30 days. (e) OTP codes are deleted within 10 minutes of generation or 24 hours of last verification attempt, whichever is earlier.
7. Cookies and Similar Technologies
7.1. We use only strictly-necessary first-party cookies for session management and CSRF protection. We do not set advertising or third-party tracking cookies by default.
7.2. The page-view counter on your public profile uses a privacy-respecting first-party event log. No third-party analytics SDK is loaded by default.
8. Your Rights Under the DPDP Act
8.1. You have the right to: (a) access the personal data we hold about you; (b) correct inaccurate or incomplete data; (c) request erasure of your personal data, subject to lawful retention; (d) withdraw consent for processing where consent is the basis (note that withdrawal does not affect lawfulness of processing before withdrawal); (e) nominate another individual to exercise your rights in case of your death or incapacity; (f) lodge a complaint with the Data Protection Board of India.
8.2. To exercise any right, write to support@zomalinks.com from your registered email. We will verify your identity and respond within 30 days, or sooner where required by law.
9. Security
We use industry-standard security measures including encryption in transit (TLS 1.2 or higher), encryption at rest at the database layer, OTP-based authentication, restricted admin access, and routine security review. No system is perfectly secure. You should choose a unique email password and never share OTPs.
10. Data Breach Notification
If we become aware of a personal data breach affecting your data we will notify you and the Data Protection Board of India as required by the DPDP Act and applicable rules, without undue delay.
11. Grievance Officer
In compliance with the IT Act, 2000 and the Intermediary Rules, 2021, the contact for privacy and content grievances is:
Email: support@zomalinks.com Address: Sector 57, Gurugram, Haryana, India Hours: Monday to Friday, 10:00 to 18:00 IST
We acknowledge grievances within 24 hours and resolve them within 15 days where feasible.
12. Changes to This Policy
We may update this Privacy Policy. The effective date at the top reflects the latest version. Material changes will be communicated by email at least 14 days in advance. Continued use after the effective date constitutes acceptance.