Privacy Policy
Last updated: 11 October 2026
This policy explains what personal data mbiz.online collects from the businesses that use it and from their customers, why we collect it, who we share it with, and the choices and rights you have.
1. Who is responsible for your data
mbiz.online handles two kinds of personal data, and our role is different for each:
- Business owners and staff. When you sign up to run a business on mbiz.online, we decide how your account data is used. We are the “data fiduciary” for it under India’s Digital Personal Data Protection Act, 2023.
- Customers who book an appointment. When you book with a salon or clinic, that business is responsible for your details. We store and process them on the business’s behalf, only to run its booking system. For questions about how a business uses your data, contact the business first; its privacy notice is linked from its booking page.
2. What we collect
From business owners and staff
- Name, email address and password (stored only in hashed form), or your Google account name and email if you sign in with Google.
- Business profile: name, category, address, phone and WhatsApp numbers, email, links, logo, photos, opening hours, services and prices.
- Your business UPI ID, so customers can pay you directly.
- Subscription records: plan, dates and the UPI reference numbers (UTRs) you submit for payments to us.
From customers making a booking
- Name, WhatsApp number, email address (optional) and any note you add.
- Booking details: service, date, time, booking code and status.
- If you pay online, the amount and the UPI reference number (UTR) you enter. Payments happen in your own UPI app; we never see your bank account, card or UPI PIN.
Automatically
- Technical data needed to deliver and secure the service, such as IP address, browser type and request logs kept by our hosting provider.
- Whether service emails were delivered.
We do not collect medical history or health records. Clinics are told not to enter them, and booking forms for clinics ask only for name, phone, email and a short note.
3. How we use it
- To create and secure accounts and let you sign in.
- To publish business pages and booking pages.
- To take bookings, check slot availability, and show booking status pages.
- To send service emails: booking confirmations, changes and cancellations, appointment reminders, and a request to review the business after a completed visit (at most one per customer every 30 days).
- To manage subscriptions, verify payments to us and send renewal reminders.
- To prevent fraud and abuse, fix problems and keep the service secure.
- To meet legal obligations, such as tax records.
4. What we don’t do
- We do not sell personal data.
- We do not show ads or use advertising trackers.
- We do not use a business’s customer list for our own marketing, or share it with other businesses on mbiz.online.
5. Consent and legal basis
Business owners give consent when they create an account; customers give consent when they confirm a booking. We process data only for the purposes above. You can withdraw consent at any time (see “Your rights”). Withdrawing it may mean we can no longer provide the service, for example a business cannot keep a booking without a way to contact the customer.
7. Where data is stored
Our service providers may store or process data on servers outside India. Where they do, it is protected by their security measures and contracts, and we transfer it only as permitted under Indian law.
9. How long we keep it
- Business account data is kept while the account is open.
- Booking records are kept while the business’s account is open, so the business can see customer history, unless the business deletes them earlier.
- When an account is closed, we delete its data within 30 days. Copies in backups are removed as backups expire, within a further 30 days.
- Billing records for payments to us are kept for 8 years, as Indian tax law requires.
10. Security
Data is encrypted in transit (HTTPS). Database access rules ensure each business can see only its own data. Passwords are hashed and never stored in plain text. No system is perfectly secure; if a breach affects your personal data, we will notify you and the authorities as Indian law requires.
11. Your rights
Under the Digital Personal Data Protection Act, 2023, you can:
- ask for a summary of the personal data we hold about you and who we have shared it with;
- ask us to correct, complete or update it;
- ask us to delete it, or withdraw your consent;
- nominate someone to exercise these rights on your behalf if you die or become unable to; and
- raise a grievance with us, and then with the Data Protection Board of India if you are not satisfied.
Business owners can edit most details directly in the dashboard. For anything else, email therajavee@gmail.com. Customers asking about a booking may be referred to the business, since it controls that data; we will help it respond. We reply within 30 days.
12. Children
Business accounts are for adults only. Bookings for a child should be made by a parent or guardian. We do not knowingly collect children’s data except as part of a booking made by a parent or guardian, and we never use it for tracking or targeted advertising.
13. Changes to this policy
If we change this policy, we will update the “last updated” date above and, for significant changes, email account holders before they take effect.
14. Contact and grievance officer
For privacy questions or requests, email therajavee@gmail.com. For complaints, write to our Grievance Officer at therajavee@gmail.com, mbiz.online, Chennai, Tamil Nadu, India. We acknowledge complaints within 48 hours and resolve them within 30 days.
