🔐 FinWorkar Privacy Policy

Effective date: 2 May 2025 | Last updated: 10 May 2026

Login options: Google Sign-In or Email + Password (verified via email). Phone-number OTP login is disabled.
We never read your SIM contacts; any phone no. used during payments goes only to Razorpay for receipts.

📘1. Introduction

FinWorkar (operated by Rajkumar Lahare) (“FinWorkar”, “we”, “us”) provides the FinWorkar mobile application (“App”). This policy explains what personal data we collect, why, how we store/share it, how long we keep it, and the rights you have—fully aligned with Google Play’s Data Safety requirements, GDPR, CCPA, and India’s DPDP Act 2023.

📥2. Data We Collect

CategorySpecific dataHow we obtain it
Account & ProfileName, email, profile photoProvided by you (Google Sign-In or email sign-up)
AuthenticationFirebase UID, hashed password (email sign-up), FCM device tokenGenerated automatically
LocationPrecise & coarse coordinatesVia Android Location permission
User ContentPost photos, descriptions, comments, call summariesYou create in-app
AudioMicrophone input for live VoIP calls (never recorded)Captured only during a call
Files & MediaImages you pick via gallery or cameraUser-initiated
Payments & WalletOrder ID, phone no., amount, status, wallet balance, UPI intent resultVia Razorpay SDK + backend webhook (during top-ups / memberships)
Usage & DiagnosticsCrash logs, ANRs, network performanceSent by Firebase & tooling
AdvertisingAd ID, impressions, clicksCollected by Google AdMob SDK
Deleted Account InfoEmail, Firebase UID, deletion timestampSaved on account deletion

We do NOT collect contacts, SMS, clipboard, or biometric templates.

⚙️3. Why We Use Your Data

Legal bases (GDPR): Contract | Legitimate Interests | Consent.

🤝4. Third-Party Service Providers

ProviderPurposeData shared
Google FirebaseAuth, hosting, Firestore, push, Analytics / Crash ReportingAccount data, device tokens, posts, crash logs
Google Sign-InFederated loginID token, name, email, photo
Google AdMobAds monetisationAdvertising ID, coarse location
RazorpayPayments & refundsOrder ID, phone no., amount, email, status
Agora RTCReal-time voice transportEphemeral audio packets
Google Maps APIGeocoding & suggestionsLat/long you provide

📈5. Advertising & Analytics

We request EU user consent for personalised ads at first launch. Change anytime in Settings → Ads Preferences.

No behavioural analytics—only anonymised crash/ANR metrics.

🔑6. Android Permissions We Request

PermissionPurpose
INTERNET, ACCESS_NETWORK_STATEBackend connectivity
ACCESS_FINE_LOCATIONNearby job discovery & tagging
RECORD_AUDIOVoice calls
POST_NOTIFICATIONSAlerts (calls, payments)
FOREGROUND_SERVICE_MICROPHONE, USE_FULL_SCREEN_INTENTIncoming-call UI
CAMERATake photos while posting
READ_EXTERNAL_STORAGE (≤ API 28)Select images from gallery
WRITE_EXTERNAL_STORAGE (maxSdkVersion = 28)Legacy write support
WAKE_LOCK, VIBRATEKeep screen awake, vibrate alerts

From Android 10 onward we use scoped storage; only files you pick are accessed.

🔄7. How We Share Data

We never sell your personal information.

🗄️8. Data Retention

DataRetention period
Account & profileUntil deletion or 24-months inactivity
Posts & imagesDeleted immediately on user request
Wallet & payment logs5 years (statutory)
Call metadata12 months
Crash logs90 days
Deleted Account InfoKept only to block abuse; purged when no longer needed

🧑‍⚖️9. Your Rights & Choices

Access, correct, port, or delete your data any time via Settings → Privacy or email us. We respond within 30 days. EU/UK users may complain to their local DPA.

🗑️10. Delete Account Procedure

Delete your account in-app (Profile → Navigation Drawer → Delete Account) or via this page. Most data is erased instantly and irreversibly; we retain only payment records (5 yrs) and a minimal “deletedAccounts” entry (email & UID) to prevent benefit abuse.

📞11. Voice Calling Disclaimer

VoIP calls are provided via Agora RTC. Audio is transmitted in real-time and never stored. We do not access your SIM call logs or contacts.

🛡️12. Security

No system is 100 % secure—protect your credentials.

🚫13. Children’s Privacy

The App is not intended for children under 13. If we discover such data, we delete it promptly.

🌍14. International Transfers

Data is stored on Google Cloud (Mumbai & US-Central). EU transfers rely on SCCs; DPDP Act 2023 compliance in India.

🔔15. Changes to This Policy

Material changes will be announced 30 days in advance via in-app notice or email.

📬16. Contact Us

Email: finworkar@gmail.com

Address: Singhansara, Sakti, District Sakti, Chhattisgarh 495689, India

Website: fin-workar.web.app

🧾Support Ticket Steps

  1. Open the FinWorkar app
  2. Tap ProfileHelp & Support
  3. Fill subject & description → Submit
  4. Or email us directly

Support hours: Mon–Sat, 10 AM – 6 PM IST (24–48 h response).

📄17. Google Play “Data Safety” Snapshot

Photos may be uploaded from camera or gallery; both are optional and user-triggered.

Data typeCollectedShared withEncrypted in transitUser can delete?
Name, email, photo✔︎Google LLC✔︎✔︎
Hashed password (email users)✔︎✔︎Delete account
Precise location✔︎✔︎✔︎
Audio (mic)✔︎✔︎ (real-time)N/A
Financial info✔︎Razorpay✔︎Statement / delete acct
Ad IDs & analytics✔︎Google AdMob✔︎Opt-out Ads
Crash logs✔︎Firebase✔︎— (anon.)
Deleted Account Info✔︎✔︎— (retained to block abuse)