Privacy Policy
Last updated: 25 August 2026
1. Introduction
FNOLAB ("we", "us", "our") operates the FNOLAB platform. This Privacy Policy explains how we collect, use, and protect your personal information when you use our Service.
2. Information We Collect
Account Information:
- Email address (required for registration)
- Name (optional)
- Phone number (optional, for contact purposes)
Payment & Subscription Information:
- Payment details (card, UPI, netbanking) are collected and tokenised by Razorpay, our PCI-DSS compliant payment gateway. We never store your card numbers, CVV, UPI IDs, bank account numbers, or mandate credentials on our servers.
- We store the following subscription metadata: plan selected, subscription ID, billing cycle dates, charge attempt history (success / failure / retry), cancellation date, and Razorpay payment IDs — required for service delivery, dispute resolution, and tax records.
- For approved refunds, Razorpay processes the credit back to the original payment method; we store only the refund reference ID.
Usage Data:
- Pages visited, features used, and session duration.
- Browser type, device information, and IP address for security and analytics.
3. How We Use Your Information
- To provide and maintain the Service (account management, signal delivery).
- To process payments and manage subscriptions.
- To communicate important updates about the Service.
- To respond to support inquiries.
- To improve the Service based on usage patterns.
- To comply with legal obligations.
4. Data Sharing
We do not sell, trade, or rent your personal information. We share data only with:
- Razorpay — our payment gateway, for processing subscriptions, mandates, and refunds. Razorpay's privacy policy governs their handling of payment data.
- Email service providers — to send transactional and service emails (subscription confirmation, charge failures, cancellation notices).
- Legal authorities — when required by law, regulation, court order, or in response to valid legal process.
5. Data Security
- All data is transmitted over HTTPS (TLS encryption).
- Passwords are hashed and never stored in plain text.
- Access to user data is restricted to authorized personnel.
- We use JWT-based authentication with token rotation.
While we implement commercially reasonable security measures, no system is 100% secure. You are responsible for keeping your login credentials confidential.
6. Cookies & Local Storage
- We use browser local storage to maintain your login session (JWT tokens).
- We do not use third-party advertising cookies.
- Essential cookies may be used for security and preference settings.
7. Data Retention
- Account data is retained as long as your account is active.
- Upon account deletion, personal data is removed within 30 days.
- Payment and subscription records (invoices, charge history, refund references) are retained for at least 8 years as required by Indian tax, accounting, and consumer protection regulations.
8. Your Rights
You have the right to:
- Access and download your personal data.
- Correct inaccurate information via your profile page.
- Request deletion of your account and associated data.
- Opt out of non-essential communications.
To exercise these rights, contact us at our contact page.
9. Children's Privacy
The Service is not intended for individuals under 18 years of age. We do not knowingly collect personal information from minors.
10. Changes to This Policy
We may update this policy from time to time. Material changes will be communicated via email or in-app notification. Continued use after changes constitutes acceptance.
11. Grievance Officer
In accordance with the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 and the Digital Personal Data Protection Act, 2023, the Grievance Officer for FNOLAB can be reached at:
Grievances related to personal data or privacy will be acknowledged within 48 hours and resolved within 30 days of receipt.
12. Contact
For privacy-related inquiries, please use the contact form.