
Privacypolicy
Last Updated: 07-08-2026
This Privacy Policy describes how Hello Power Private Limited (‘Hello Power’, ‘we’, ‘us’, or ‘our’) collects, uses, stores, shares, and protects your personal data when you use the HelloPower mobile application, website (hellopower.in), and related services.
This notice is available in English. Upon request, we will endeavour to provide this policy in any of the 22 languages listed in the Eighth Schedule of the Constitution of India.
Hello Power Private Limited is the Data Fiduciary as defined under Section 2(i) of the DPDP Act. We determine the purpose and means of processing your digital personal data.
| Field | Detail |
|---|---|
| Registered Name | Hello Power Private Limited |
| CIN | U41000KA2024PTC187175 |
| Registered Address | #26, 1st Floor, Sudarshan Auto Mobile Building, Near Sandal Soap Factory Metro Station, Rajajinagar, Bengaluru, Karnataka 560055 |
| Contact | reachus@hellopower.in 080-23322669 |
| Grievance Officer | see Section 11 |
This policy applies to all users (‘Data Principals’) who:
- Download or use the HelloPower mobile application (Android / iOS).
- Visit or interact with our website at hellopower.in
- Contact us via phone, email, WhatsApp, or any other channel.
- Register as a customer, electrician, vendor, or service partner on our platform.
This policy does not apply to third-party websites or services linked from our platform. We are not responsible for the privacy practices of those entities.
We collect only the personal data necessary for the specified purposes (data minimisation). The following table provides an itemised description as required under Rule 3 of the DPDP Rules, 2025:
| Data Category | Specific Data Points | Legal Basis | Retention Period |
|---|---|---|---|
| Identity Data | Full name, profile photo | Consent (S.6) | Duration of account + 3 years |
| Contact Data | Mobile number, email address | Consent (S.6) | Duration of account + 3 years |
| Location Data | City, pincode, precise GPS (for service matching) | Consent (S.6) | Session-based; aggregate retained 1 year |
| Device Data | Device type, OS version, app version, device ID | Legitimate Use (S.7) | 1 year from last login |
| Booking & Transaction Data | Service bookings, order history, payment status | Legitimate Use (S.7) / Contract | 7 years (GST/accounting compliance) |
| Financial Data | Payment instrument type (NOT card numbers; processed by Razorpay) | Legitimate Use (S.7) | 7 years (statutory requirement) |
| Communication Data | Customer support messages, complaint records | Legitimate Use (S.7) | 3 years from resolution |
| Usage Data | App navigation patterns, feature usage, crash logs | Consent (S.6) | 1 year |
| Vendor / Electrician Data | Trade licence, Aadhaar (verification only), GSTIN, skills | Consent (S.6) + Legal Obligation | Duration of contract + 7 years |
We do not collect Sensitive Personal Data such as biometric data, health records, financial passwords, or political/religious beliefs. Aadhaar numbers collected for electrician verification are processed as per applicable UIDAI guidelines and are not stored in raw form.
We process your personal data strictly for the following specified purposes. We do not use your data for any purpose beyond what is listed here without obtaining fresh consent:
- Account creation, authentication, and profile management.
- Matching customers with qualified electricians and vendors based on location and service type.
- Processing service bookings, orders, payments, and generating GST-compliant invoices.
- Facilitating vendor onboarding, document verification, and KYC compliance.
- Providing real-time delivery and job tracking via in-app features.
- Sending transactional communications (booking confirmations, OTPs, invoices).
- Sending promotional communications — only with your explicit consent, which you may withdraw at any time.
- Detecting and preventing fraud, abuse, and security threats.
- Improving app functionality, fixing bugs, and optimising user experience (using anonymised analytics).
- Resolving customer grievances and providing support.
- Complying with applicable laws, including GST, labour, and consumer protection regulations.
We process your personal data only on two lawful bases as defined under the DPDP Act:
Where we rely on consent, it is obtained through a free, specific, informed, unconditional, and unambiguous affirmative action by you (such as ticking a checkbox or tapping ‘I Agree’). Where processing is based on consent, users may withdraw consent through:
- Account settings.
- Contacting the Grievance Officer
- Other mechanisms provided within the Platform.
Certain processing is carried out on legitimate use grounds without consent, specifically for: performing services you have voluntarily requested, complying with statutory obligations (GST filing, labour law compliance), fraud prevention, and safety of the platform and its users.
We do not sell your personal data. We share personal data only to the extent necessary and only with the following categories of recipients:
| Recipient Category | Purpose of Sharing | Safeguards |
|---|---|---|
| Electricians / Vendors | Fulfilling your booked service (name, address, contact shared only) | Contractual obligation; purpose-limited disclosure |
| Razorpay India Pvt. Ltd. | Payment processing and settlement | PCI-DSS compliant; processes payment data directly |
| Amazon Web Services (AWS) | Cloud infrastructure hosting (EC2, RDS, S3) | Data Processing Agreement; ISO 27001 certified |
| Redis Cloud (Upstash/Redis Labs) | Session management and real-time features | Data Processing Agreement in place |
| Borzo (logistics partner) | Delivery tracking and logistics coordination | Contractual obligation; location data only |
| SMS / Communication Providers | OTP delivery, booking notifications | Purpose-limited; no data retention beyond delivery |
| Government / Regulators | Compliance with court orders, tax authorities, law enforcement | Only as mandated by applicable law |
All third-party data processors are bound by contractual data processing agreements that restrict their use of your data to the stated purpose and require equivalent security standards.
Our primary servers are located in India (AWS Mumbai region). Certain service components — including cloud infrastructure (AWS), Redis Cloud, and communication providers — may involve processing outside India. Such transfers are conducted only to countries and entities not restricted by the Central Government under Section 16 of the DPDP Act, and subject to data processing agreements incorporating appropriate safeguards. Personal data may be processed by service providers located outside India.
Where cross-border transfers occur, HelloPower shall implement appropriate contractual, organizational, and technical safeguards to ensure that personal data receives protection consistent with applicable Indian law.
Cross-border transfers shall not be undertaken to jurisdictions restricted by the Government of India.
We retain personal data only for as long as necessary to fulfil the specified purpose or as required by applicable law. Specific retention periods are specified in Section 3 of this policy.
- Account deletion request by you.
- Withdrawal of consent (data erased within 30 days of withdrawal).
- Expiry of the retention period.
- Reasonable determination that you are no longer an active user (i.e., no interaction for 3 years).
As required under the DPDP Rules 2025, we will notify you at least 48 hours before erasing your personal data on grounds of inactivity, giving you the opportunity to resume use of the platform.
Under Chapter III of the DPDP Act, you have the following rights. We will respond to all requests within 30 days:
| Right | What It Means | How to Exercise | Timeline |
|---|---|---|---|
| Right to Access (S.11) | Know what personal data we hold about you and its purpose | Email grievance officer; request data summary | Within 30 days |
| Right to Correct (S.12) | Correct inaccurate or incomplete personal data | Email with corrected details and supporting docs | Within 30 days |
| Right to Erase (S.12) | Delete your account and associated personal data | Request via app Settings > Delete Account or email | Within 30 days |
| Right to Withdraw Consent (S.13) | Withdraw consent for processing at any time | Email grievance officer; automatic erasure triggered | Immediately; data erased within 30 days |
| Right to Grievance Redressal (S.13) | Raise a complaint about data handling | Contact Grievance Officer (Section 11) | Response within 30 days |
| Right to Nominate (S.14) | Nominate a person to exercise rights in case of death/incapacity | Submit nomination form via email | Processed within 30 days |
To exercise any of these rights, contact our Grievance Officer as described in Section 11. We may verify your identity before processing your request to prevent misuse.
Our services are intended for users who are 18 years of age or older. We do not knowingly collect personal data from children (individuals under 18 years of age).
In compliance with Section 9 of the DPDP Act:
- We will not process the personal data of a child without verifiable consent from a parent or legal guardian.
- We will not process personal data in a manner that may cause harm to a child.
- We do not engage in behavioral monitoring, tracking, or targeted advertising directed at children.
If you believe a child has provided us with personal data without parental consent, please contact our Grievance Officer immediately. We will delete such data promptly upon verification.
In accordance with Section 8(9) and Section 8(10) of the DPDP Act, we have designated a Grievance Officer responsible for addressing Data Principal concerns:
| Field | Detail |
|---|---|
| Designation | Grievance Officer — HelloPower Privacy |
| Contact Email | reachus@hellopower.in |
| Phone | 080-23322669 |
| Mailing Address | #26, 1st Floor, Sudarshan Auto Mobile Building, Near Sandal Soap Factory Metro Station, Rajajinagar, Bengaluru, Karnataka 560055 |
| Response Timeframe | Within 30 days of receipt of complaint |
If you remain dissatisfied after completion of HelloPower’s grievance process, you may seek remedies available under applicable law, including filing complaints with competent authorities designated under the Digital Personal Data Protection Act, 2023.
We implement a layered combination of administrative, technical, and physical security measures to protect your personal data against unauthorised access, disclosure, alteration, or destruction. These include:
- Encryption of data in transit (TLS 1.2+) and at rest (AES-256).
- Access controls and role-based permissions for all internal staff.
- Secure cloud infrastructure on AWS (Mumbai region) with VPC isolation.
- Regular security assessments and vulnerability scanning.
- Incident response procedures aligned with the DPDP Act breach notification obligations.
In the event of a personal data breach, we will, as required under Section 8(6) of the DPDP Act:
- Notify the Data Protection Board of India within 72 hours of becoming aware of the breach.
- Notify affected Data Principals promptly, describing the nature of the breach, likely consequences, and remedial measures taken.
- Contain and mitigate the breach and conduct a post-incident audit.
Our mobile app does not use browser cookies. Our website hellopower.in uses the following:
| Cookie Type | Purpose | Mandatory |
|---|---|---|
| Essential Cookies | Authentication, security, session management | Yes |
| Analytics Cookies | Usage analytics and performance monitoring | No |
| Marketing Cookies | Personalized marketing and advertising | No |
You may manage your cookie preferences through the cookie settings banner displayed on first visit to our website, or by adjusting your browser settings.
We may update this Privacy Policy from time to time to reflect changes in our practices, the services we offer, or applicable law. When we make material changes:
- We will notify you via in-app notification and/or email at least 30 days before the changes take effect.
- The updated policy will be posted on hellopower.in/privacypolicy/ with the revised effective date.
- Continued use of our services after the effective date constitutes acceptance of the updated policy
For material changes that affect your rights or the basis of processing, we will seek fresh consent where required under the DPDP Act.
This Privacy Policy is drafted in compliance with and in reference to:
- Digital Personal Data Protection Act, 2023 (No. 22 of 2023).
- Digital Personal Data Protection Rules, 2025 (notified November 13, 2025).
- Information Technology Act, 2000 and IT (Amendment) Act, 2008.
- Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.
- Consumer Protection Act, 2019.
- Goods and Services Tax Act, 2017 (for data retention obligations).
