Privacy Policy
Last updated: 10 August 2026
1. Introduction and Scope
Foamly ("we", "our", or "us") provides a vehicle wash and detailing management platform to businesses in India. This Privacy Policy explains what personal data we handle, why, on what basis, how long we keep it, and the rights available to you.
This policy is written to align with the Digital Personal Data Protection Act, 2023 ("DPDP Act") and the Information Technology Act, 2000, together with rules made under them. Where this policy uses the terms Data Principal, Data Fiduciary, and Data Processor, they carry the meanings given in the DPDP Act.
This policy covers our website at foamly.in, our web applications, and our mobile applications. It does not cover the independent practices of the shops that use Foamly, or of the third-party services listed in section 7.
2. Two Different Roles, and Why the Difference Matters
Foamly handles personal data in two distinct capacities. Which one applies determines who is accountable to you and who you should approach first.
2.1 Where Foamly is the Data Fiduciary
For the people who hold a Foamly account, meaning shop owners, managers, cashiers, washers, and anyone we invite into the platform, and for visitors to our website and people who send us an enquiry, Foamly determines the purpose and means of processing. In these cases Foamly is the Data Fiduciary and is directly accountable to you under the DPDP Act.
2.2 Where Foamly is only the Data Processor
A shop using Foamly enters information about its own customers: names, phone numbers, vehicle registration numbers, service history, invoices, loyalty balances, and photographs of vehicles. That data belongs to the relationship between the shop and its customer. The shop decides what to collect, what to send, and how long to keep it.
For that data the shop is the Data Fiduciary and Foamly is only its Data Processor. We process it on the shop's documented instructions, which are given through the actions the shop takes in the product, and we do not use it for our own purposes. We do not sell it, we do not use it to advertise to those customers, and we do not use it to train any model.
If you are the customer of a shop that uses Foamly and you want to access, correct, or delete your information, please contact that shop directly. It controls that data and can act on it immediately. If you cannot reach the shop, write to us at support@foamly.in and we will help route the request, though we are not permitted to act on our own initiative on data another business controls.
3. Information We Collect
3.1 Account and Business Information
- Identity and contact: Your name, mobile number, and where you provide it, your email address. Your mobile number is your login identity and cannot be changed by you once the account exists, because it is the key that ties your account and its history together.
- Business details: Shop name, branch addresses, working hours, GSTIN and state code where you supply them, and the service catalogue and pricing you configure.
- Staff records: Where a shop uses our staff features, the records it enters about its employees, including attendance, shifts, leave, and salary periods.
- Profile photograph: If you upload one.
We do not collect Aadhaar numbers or PAN, and the platform has no field for them. Please do not enter them into free-text fields.
3.2 Information Collected Automatically When You Use Foamly
- Technical data: IP address, browser or app version, operating system, device model, and language preference.
- Device records: For mobile sign-ins, a device identifier, an installation identifier, and a push notification token, so we can deliver notifications and let you see and revoke your signed-in devices.
- Session records: When you sign in, we store a hashed session token together with the IP address, device fingerprint, and browser or app identifier of that sign-in, so that a stolen session can be detected and revoked.
- Security and audit logs: A record of actions taken in the platform, including who did what, when, from which IP address, and against which record. These logs are append-only and cannot be edited or deleted, including by us.
3.3 Enquiry Information
When you send us an enquiry about using Foamly, we record the name, shop name, city, mobile number, and any email address you provide. Alongside that submission we also record technical information supplied by your browser or app and by our network provider: your IP address, an approximate location derived from that IP address (country, region, city, postal area, and approximate coordinates), your network operator and its identifier, your browser or app identifier, language preference, device model, operating system version, app version, installation identifier, and the referring page.
We collect this to route the enquiry, to prevent automated abuse of the form, and to understand where genuine interest is coming from. The approximate location is derived from your network address and is not precise GPS location.
3.4 Records of Agreement to These Documents
When you sign in, you are asked to confirm that you have read and agree to our Terms of Service and this Privacy Policy. When you confirm and then complete sign-in, we permanently record: your user identity, your mobile number at that moment, the date and time, the IP address the confirmation came from, the application you used, and the exact version and content fingerprint of the two documents you were shown.
We keep these records permanently and do not delete them when an account is closed. They exist so that both you and we can establish precisely which version of these documents applied, which protects you as much as it protects us. This is the one category of data that survives account deletion, and it is retained for the establishment and exercise of legal claims.
3.5 Photographs and Location
Shops may photograph vehicles as part of a job, for example to record condition on arrival. Those photographs are the shop's data and Foamly stores them on the shop's behalf.
Location is not attached to photographs by default. A shop can switch on geotagging, and only then will the coordinates and accuracy at the moment of capture be stored with the photograph. If you take photographs using a shop's device, ask the shop whether it has enabled this.
3.6 Website Analytics
Our public website uses Google Analytics 4 to understand how visitors find and move through the site. It records pages visited, approximate location at country or city level, device and browser type, referral source, and interactions with page elements. Google may process this data in accordance with its Privacy Policy. You can opt out using the Google Analytics Opt-out Browser Add-on.
Analytics runs on our marketing website only. The signed-in Foamly applications do not carry Google Analytics.
4. Why We Process Your Information
We process personal data for the following specified purposes, and not for others:
- To provide the service you signed up for: creating and running your account, billing, invoicing, and the features you use.
- To authenticate you: sending one-time passcodes and maintaining your session. We do not use passwords, so we never store one.
- To keep the platform secure: detecting and preventing abuse, fraud, and unauthorised access, including rate limiting and bot checks.
- To support you: answering your questions and investigating problems you report.
- To meet legal obligations: tax and accounting records, and responding to lawful requests.
- To establish or defend legal claims: including the agreement records described in section 3.4.
- To improve the product: understanding which features are used, in aggregate.
We do not sell personal data. We do not use your data, or your customers' data, to train machine learning models. We do not use it for advertising.
5. Consent, and How to Withdraw It
Where we rely on your consent, you may withdraw it at any time by writing to support@foamly.in. Withdrawing consent is as easy as giving it, and we will act on the request without asking you to justify it.
Withdrawal is not retrospective: it does not undo processing already carried out lawfully. Some processing does not depend on consent and will continue regardless, specifically the retention of records we are required by law to keep, and the agreement records in section 3.4 which exist for legal claims. If withdrawing consent means we can no longer provide the service, we will tell you, and the practical consequence is that the account is closed.
Where a shop sends messages to its own customers over SMS or WhatsApp through Foamly, the shop is responsible for obtaining and honouring that customer's consent. Customers can opt out by telling the shop, or by replying STOP to a WhatsApp message.
6. Sharing Your Information
We do not sell personal data. We share it only as follows:
- With the service providers listed in section 7, strictly to operate the platform.
- Within your shop: other users of your shop's account see the business data appropriate to their role.
- When the law requires it: in response to a valid legal demand from a court or authority with jurisdiction. We will tell you unless we are legally prohibited from doing so.
- To protect people: where we reasonably believe disclosure is necessary to prevent serious harm.
- On a business transfer: if Foamly is merged, acquired, or its assets sold, data may transfer to the successor, which will remain bound by commitments no weaker than these. We will give notice before your data becomes subject to a different policy.
7. Service Providers We Rely On
These providers process personal data on our behalf so that Foamly can function. Each is bound by its own contractual and legal obligations.
- Cloudflare: hosting, storage, content delivery, and bot protection. Substantially all platform data is stored on Cloudflare infrastructure.
- MSG91: delivery of one-time passcodes and transactional SMS in India. Receives the destination mobile number and message content.
- Meta Platforms (WhatsApp Business Cloud API): delivery of WhatsApp messages, where used. Receives the destination mobile number and message content, and processes it under the WhatsApp Privacy Policy.
- Google (Firebase): push notification delivery to mobile devices, and app integrity checks that confirm requests come from a genuine copy of our app. Receives device and notification tokens.
- Razorpay: subscription and payment processing. Card and bank details are handled by Razorpay directly and are never stored by Foamly.
- Zoho (ZeptoMail): transactional email delivery. Receives the destination email address and message content.
- Google Analytics: marketing website analytics only, as described in section 3.6.
8. Transfers Outside India
Some of the providers in section 7 operate globally, so your data may be processed on infrastructure located outside India. Where that happens we rely on the provider's contractual commitments to protect the data to a standard consistent with this policy.
We do not transfer personal data to any country that the Central Government has restricted under section 16 of the DPDP Act. If such a restriction is introduced covering a provider we use, we will move that processing or stop using the provider.
9. How Long We Keep Data
We keep personal data only as long as the purpose it was collected for remains, or as long as the law requires, whichever is longer.
- Account and business data: for as long as your account is active. On closure, deleted or anonymised within 90 days, except where an item below applies.
- Financial and tax records, including invoices and payment records: retained for the periods Indian law requires, which for GST records is currently 72 months from the due date of the relevant annual return, and for company books is currently 8 years.
- Security and audit logs: 3 years from the event.
- Agreement records described in section 3.4: retained permanently. These are not deleted on account closure.
- Enquiries that do not become accounts: up to 24 months from last contact.
- Session and device records: deleted when the session expires or you revoke the device, and in any case within 30 days of expiry.
- Backups: deletion propagates to backups on their normal rotation, which may lag live deletion by up to 90 days.
When a shop closes its account, the data it entered about its own customers is deleted or anonymised on the same schedule. We will give reasonable opportunity to export before deletion.
10. Security
We take reasonable security safeguards to prevent personal data breaches. Rather than list generalities, here is what is actually in place:
- Data is encrypted in transit and encrypted at rest by our infrastructure provider.
- There are no passwords to steal. Sign-in is by one-time passcode, rate limited, with lockout after repeated failures.
- Session cookies are restricted to our own domain, are not readable by scripts, and are not sent on cross-site requests.
- Each shop's data is isolated from every other shop's data at the database layer, and that isolation is verified automatically on every change we ship, so that a mistake in new code cannot quietly expose another shop's records.
- Actions in the platform are written to an append-only audit log that cannot be edited or deleted.
- Access to production systems is limited to personnel who need it.
- Mobile requests carry an app integrity check, so requests from tampered or cloned apps can be rejected.
No system can be guaranteed completely secure, and we do not claim otherwise. If a personal data breach occurs, we will notify the Data Protection Board of India and affected Data Principals as required by the DPDP Act, without undue delay.
11. Your Rights
As a Data Principal you have the right to:
- Access: obtain a summary of the personal data we hold about you and how it is processed, and the identities of those it has been shared with.
- Correction and completion: have inaccurate or misleading data corrected, incomplete data completed, and data updated.
- Erasure: have your personal data deleted, except where we are required to keep it under section 9.
- Withdraw consent: as described in section 5.
- Grievance redressal: raise a complaint with us, as described in section 12.
- Nomination: nominate another individual to exercise these rights on your behalf in the event of your death or incapacity.
Write to support@foamly.in to exercise any of these. We will respond within 30 days. We may need to verify your identity first, which for account holders normally means confirming control of the registered mobile number.
You also have duties under section 15 of the DPDP Act, including not raising false or frivolous complaints and not providing false particulars when exercising the right to correction.
12. Grievance Redressal
If you are unhappy with how we have handled your personal data or a request about it, contact our Grievance Officer:
Anshad Ali KM
Grievance Officer, Foamly
Email: grievances@foamly.in
We will acknowledge your grievance within 72 hours and resolve it within 30 days.
If you remain unsatisfied after exhausting this route, you may complain to the Data Protection Board of India.
13. Children
Foamly is a business tool and is not directed at children. We do not knowingly create accounts for anyone under 18, and account holders confirm they are 18 or older. We do not carry out tracking, behavioural monitoring, or targeted advertising directed at children.
If you believe a child's personal data has reached us, write to support@foamly.in and we will delete it.
14. Cookies and Similar Technologies
Inside the signed-in applications we use only cookies that are strictly necessary to run the service: a session cookie and a refresh cookie that keep you signed in. These are restricted to our own domain, are not readable by scripts, and are not used for advertising or profiling. Blocking them makes sign-in impossible.
Our public marketing website additionally uses Google Analytics cookies as described in section 3.6. You can block or delete these through your browser settings or the opt-out add-on, with no effect on your ability to use Foamly.
15. Changes to This Policy
When we change this policy we publish it as a new, dated version. Previous versions are never edited after publication and remain permanently available at their own web address, so the exact wording that applied on any past date can always be produced.
Account holders are asked to confirm agreement to the current version when signing in, and that confirmation is recorded as described in section 3.4. For material changes we will give notice in the product or by email before the new version takes effect.
16. Contact Us
For any question about this Privacy Policy, your personal data, or to exercise a right described above:
Foamly
Email: support@foamly.in
Grievance Officer: Anshad Ali KM, grievances@foamly.in
Location: Kochi, Kerala, India