Bloco
Smart Society App
Login Register Society
Legal

Privacy Policy

📅 Effective: 1 August 2026 🔄 Last updated: 1 August 2026

📋 Table of Contents

Contents

1. Who We Are 2. Data We Collect 3. How We Use Your Data 4. Data Sharing 5. Storage & Security 6. Data Retention 7. Your Rights 8. Cookies & Tracking 9. Children's Privacy 10. Policy Changes 11. Contact & Grievance
Summary: Bloco acts as a Data Fiduciary under the Digital Personal Data Protection Act, 2023 (DPDP Act) for all personal data processed on our platform and mobile app. We collect only what we need, store everything securely in India, never sell your data, and never show ads.

Bloco Inc. | Registered in India | support@bloco.in | +91-XXXXX-XXXXX

01 Who We Are

Bloco ("Bloco", "we", "us", "our") is a society management platform provided by Bloco Inc., a company registered in India. Our platform includes the Bloco web dashboard, the Bloco resident mobile app (iOS and Android), the Bloco security guard app, and all related services.

This Privacy Policy explains how we collect, use, store, and protect personal data when you use any part of our platform — whether you are a society committee member, a resident, a security guard, or a visitor whose entry is recorded at the gate.


02 Data We Collect

2.1 Data You Provide Directly

  • Account registration: Name, flat number, wing, society name, mobile number, email address
  • Vehicle registration: Vehicle number, type (two-wheeler / four-wheeler), colour — stored exactly as provided by you or your committee; Bloco does not scrape RTO records or track your vehicle outside society premises
  • Society committee accounts: Name, designation, and bank details required for payment gateway setup (collected by our payment processor — Bloco does not store raw bank credentials)
  • Visitor pre-approvals: Visitor name, phone, expected arrival date/time, purpose of visit — entered by the resident granting approval
  • Maintenance billing: Flat area, billing category, due amount — as configured by your committee
  • Complaint & helpdesk: Issue title, description, photos, category, priority — submitted by residents
  • Amenity bookings: Amenity name, preferred date/time, number of persons — submitted by residents
  • Payment information: UPI ID or card details — processed entirely by our PCI-DSS compliant payment partner; Bloco never stores raw card numbers
  • Demo requests & inquiries: Name, phone, email, society details, role

2.2 Data Collected Automatically

  • Device type, operating system version, app version, and IP address
  • App usage patterns — which features you use and how often (used only to improve the product)
  • Crash reports and error logs (anonymised where possible)
  • Push notification tokens for delivery of alerts, visitor approvals, and billing reminders
  • Location data — collected only once during society onboarding to geo-tag the building on the map, with your explicit permission. We do not track your real-time location.

2.3 Data from Third Parties

  • Payment status and transaction reference IDs from our payment gateway
  • OTP delivery confirmation from our SMS/telecom partner
  • Firebase Cloud Messaging tokens for push notifications (Google Firebase)

03 How We Use Your Data

We use your data only for the specific purposes listed below. Our legal bases under the DPDP Act 2023 are: consent, legitimate use, and legal obligation.

  • To create and manage your account and verify your identity via OTP
  • To provide society management features — visitor gate management, maintenance billing, complaints, notice board, amenity booking, vehicle tracking, and community marketplace
  • To process maintenance payments and issue digital receipts to residents
  • To send transactional push notifications — visitor alerts, payment confirmations, complaint status updates, society notices
  • To allow security guards to verify pre-approved visitors via OTP or QR code
  • To provide customer support and resolve disputes
  • To detect, prevent, and respond to fraud or unauthorised access attempts
  • To comply with legal and regulatory obligations under Indian law
  • To improve the platform using anonymised, aggregate usage analytics
  • To send product updates or relevant offers — only with your opt-in consent; you can unsubscribe at any time
What we will never do: We will never sell, rent, or trade your personal data to advertisers, data brokers, or any third party. We do not display ads in the app. We do not use cross-site tracking, advertising pixels, or mobile ad identifiers (IDFA/GAID). Your community data stays private.

04 Data Sharing

We share your data only in the limited circumstances below. We never sell data.

4.1 Within the Platform

  • Society committees: Can view resident flat details, payment status, visitor logs, and complaint assignments for their own society only
  • Security guards: See only visitor pre-approval status, resident name/flat, and gate entry QR codes — nothing else
  • Residents: Can see their own billing history, visitor log, and complaint status; cannot see other residents' payment details

4.2 Service Providers (Data Processors)

  • Cloud infrastructure: Amazon Web Services (AWS Mumbai — ap-south-1 region) — all data stored within India
  • Payment processing: RBI-regulated, PCI-DSS compliant India-based payment gateway
  • SMS & OTP: Used strictly for account registration, login verification, and visitor OTP delivery
  • Push notifications: Google Firebase Cloud Messaging — for visitor alerts, payment reminders, and society notices
  • Analytics: Anonymised, aggregate usage data only — no personal identifiers shared

4.3 Legal Requirements

We may disclose data if required by Indian law, a court order, or a competent government authority. We will notify you where legally permitted to do so.

4.4 Business Transfers

In the event of a merger, acquisition, or sale of business assets, personal data may be transferred to the acquiring entity. We will notify all affected users in advance.


05 Data Storage & Security

  • Location: All data stored on AWS Mumbai (ap-south-1) servers within India. No data is transferred outside India without your explicit consent.
  • Encryption in transit: TLS 1.3 for all data moving between the app, your browser, and our servers
  • Encryption at rest: AES-256 encryption for all stored data
  • Access controls: Role-based access control (RBAC) ensures staff can only see data relevant to their role. All access is logged and audited.
  • Authentication: Multi-factor authentication (MFA) for all admin and committee accounts
  • Backups: Automated daily backups with 30-day retention; disaster recovery tested regularly
  • Security reviews: Annual third-party security assessments
  • Incident response: We notify affected users and regulators within required timelines in the event of a breach

06 Data Retention

  • Active accounts: Retained while your account is active and for 2 years after deactivation
  • Financial records: Billing and payment data retained for 7 years as required by Indian tax law (Income Tax Act)
  • Visitor logs: Gate entry records retained for 1 year, then anonymised or permanently deleted
  • Complaint records: Retained for 2 years for quality assurance and dispute resolution
  • Deleted accounts: All personal data purged within 30 days of your deletion request, except where retention is required by law
  • Anonymised analytics: Retained indefinitely — no personal identifiers included

07 Your Rights

Under the DPDP Act 2023, you have the following rights regarding your personal data:

  • Right to access: Request a copy of the personal data we hold about you
  • Right to correction: Request correction of inaccurate or incomplete data
  • Right to erasure: Request deletion of your data (subject to legal retention requirements)
  • Right to withdraw consent: Withdraw consent for any data processing based on consent at any time
  • Right to grievance redressal: Raise a complaint with our Data Protection Officer (details in Section 11)
  • Right to nominate: Nominate another individual to exercise your rights in case of death or incapacity

To exercise any of these rights, email us at privacy@bloco.in from your registered email address. We will respond within 30 days.


08 Cookies & Tracking

Our web dashboard uses strictly necessary cookies for authentication sessions. We do not use advertising cookies, cross-site tracking pixels, or third-party analytics cookies that track your identity across websites.

The Bloco mobile app does not use browser cookies. We use device-level tokens (push notification tokens) only for delivering notifications you have opted into.


09 Children's Privacy

Bloco is intended for use by adults aged 18 and above. We do not knowingly collect personal data from children under 18. If you believe a child's data has been submitted without appropriate consent, please contact us immediately at privacy@bloco.in and we will delete it promptly.


10 Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you via:

  • An in-app notification in the Bloco resident and admin apps
  • An email to your registered email address
  • A prominent notice on our website at bloco.in

The updated policy will be effective from the date displayed at the top of this page. Continued use of the platform after that date constitutes acceptance of the revised policy.


11 Contact & Grievance

Data Protection Officer (Grievance Officer)
Bloco Inc.
Email: privacy@bloco.in
Support: support@bloco.in
Response time: Within 30 days of receiving your request

If you are not satisfied with our response, you may escalate your grievance to India's Data Protection Board of India once constituted under the DPDP Act 2023.

Read our Terms of Service →

© 2026 Bloco Inc. All rights reserved.

Privacy Policy Terms of Service ← Back to Home