Rebota LogoRebota
Features Pricing Intelligence Center About Contact
Login Start Free Trial
Features Pricing Intelligence Center About Contact
Login Free Trial
Legal

Privacy Policy

Last updated: 21 June 2026 · Aligned to the Digital Personal Data Protection Act, 2023
On this page
  1. Data Fiduciary & Data Processor Roles
  2. Information We Collect
  3. How We Use Your Information
  4. Payment & Billing Data
  5. Sharing & Sub-processors
  6. Cookies & Session Data
  7. Data Security
  8. Where Your Data Is Stored
  9. Regulatory Record-Keeping (CERT-In)
  10. Data Retention & Deletion
  11. Data Breach Notification
  12. Your Rights as a Data Principal
  13. Children's Privacy
  14. Changes to this Policy
  15. Grievance Officer & Contact

Rebota ("Rebota", "we", "us", "our") provides a construction project-management, cost and billing platform ("Service") to contractors and construction businesses through the website rebota.in. This Privacy Policy explains what information we collect, how we use it, and the rights available to you under the Digital Personal Data Protection Act, 2023 ("DPDP Act") and the Information Technology Act, 2000. By creating an account or using the Service, you agree to the collection and use of information as described here.

1. Data Fiduciary & Data Processor Roles

Under the DPDP Act, the role your data plays depends on who entered it:

  • If you run a business on Rebota, you are the Data Fiduciary for the personal data of your own employees, site workers, vendors and clients that you enter into the platform — you decide what is collected and why, and Rebota processes it on your behalf as your Data Processor, under our Data Processing Agreement.
  • For your own account data (your name, email, phone, login activity, billing history), Rebota is itself the Data Fiduciary and you are the Data Principal — the rest of this policy covers that relationship directly.

If you are a worker, vendor or client whose data was entered into Rebota by a business you work with (not by you directly), that business is the Data Fiduciary responsible for your data — please contact them first with any request; we will assist them as their Processor.

2. Information We Collect

a) Information you give us directly

  • Account information: name, email address, phone number, company/firm name, and a securely hashed password.
  • Project & business data: project names, contract values, client details, activities, daily site logs, labour and material entries, measurement book entries, bills/invoices, inventory records and any notes you add.
  • Vendor & worker data: vendor GSTIN/PAN/bank account/IFSC (bank account, IFSC and PAN are encrypted at rest, in addition to encryption in transit) and worker trade/wage/attendance details. Only the last 4 digits of a worker's Aadhaar number are ever stored — never the full number.
  • Site photographs: images you upload against a daily site log entry for progress documentation.
  • Support communication: any information you share when you contact us for support.

b) Information collected automatically

  • Login timestamps, session identifiers and basic device/browser information, used to keep your account secure and improve the Service.
  • Standard web server logs (IP address, pages requested, date/time) collected for security and abuse prevention, and retained as described in Section 9 (CERT-In).

3. How We Use Your Information

We use the information we collect to:

  • Create and manage your account and authenticate you when you log in;
  • Provide the core functionality of the Service — storing and displaying your projects, site logs, progress, cost, billing, inventory and measurement book data back to you;
  • Generate the reports you request from within the dashboard;
  • Process subscription payments and send related receipts/notifications;
  • Send important account, billing or security notices, and — where you've opted in — WhatsApp/SMS notifications;
  • Respond to support requests;
  • Monitor, secure and improve the Service, and prevent fraud or misuse;
  • Meet our own legal obligations, including the record-keeping described in Sections 9–10.

We do not sell your personal data or your project/business data to third parties, and we do not use your construction project data to train external advertising or AI models.

4. Payment & Billing Data

Subscription payments on Rebota are processed by Razorpay, an RBI-authorised payment aggregator. When you make a payment, your card, UPI or net-banking details are entered directly on Razorpay's secure payment page and are processed and stored by Razorpay in accordance with applicable RBI guidelines and PCI-DSS standards.

Rebota does not receive or store your full card number, CVV or net-banking credentials on our servers. We only receive a payment confirmation, transaction reference ID, amount and status from Razorpay, which we use to activate or extend your subscription and to maintain your billing history inside your account.

5. Sharing & Sub-processors

We share information only with the service providers below, each engaged under terms requiring them to protect the data and use it only to provide their service to us:

  • Razorpay — subscription payment processing.
  • Meta Platforms (WhatsApp Business Cloud API) — OTP and notification delivery, where WhatsApp notifications are enabled.
  • Hosting provider — infrastructure hosting (India region) for running the application and database.
  • SMS gateway — OTP/SMS delivery, where configured.

Beyond these, we share information only: (a) if required by law, court order, or a valid request from a government or regulatory authority (including CERT-In); (b) if Rebota is involved in a merger, acquisition or sale of assets, subject to confidentiality commitments; or (c) with your explicit consent.

6. Cookies & Session Data

We use a session cookie strictly necessary to keep you logged in while using the dashboard. This cookie is marked HttpOnly and SameSite=Lax and is deleted when you log out or your session expires. We do not currently use third-party advertising or tracking cookies on the application.

7. Data Security

In line with "reasonable security practices" under Rule 8 of the IT (Reasonable Security Practices and Sensitive Personal Data or Information) Rules, 2011, we maintain:

  • HTTPS/TLS encryption for all data in transit;
  • Application-layer AES-256-GCM encryption at rest for the most sensitive fields — vendor bank account number, IFSC and PAN;
  • Passwords stored using one-way, salted industry-standard hashing — never in plain text or reversible encryption;
  • Role-based access control, so a teammate only sees the projects and modules they've been granted;
  • Restricted server-side database access and security headers on every page;
  • A documented incident-response process, including CERT-In notification within the statutory window (Section 9).

No method of transmission or storage is 100% secure, and while we work hard to protect your data, we cannot guarantee absolute security.

8. Where Your Data Is Stored

Primary hosting and database infrastructure is located in India. Where a sub-processor (e.g. Meta/WhatsApp) processes data outside India as part of message delivery, that transfer is limited to what is necessary for the service and is subject to that provider's own security commitments. We do not otherwise transfer your personal data outside India.

9. Regulatory Record-Keeping (CERT-In)

Under the CERT-In Directions of 28 April 2022, we maintain ICT/security logs for a minimum of 180 days, stored within India, and will report qualifying cyber security incidents to CERT-In within 6 hours of detection.

10. Data Retention & Deletion

We retain your account and project data for as long as your account is active, so that your dashboard and historical reports remain available to you. If you wish to permanently delete your account and associated data, write to us at support@rebota.in from your registered email address. We will action verified deletion requests within a reasonable time, except where we are required by law to retain certain records — see our full Data Retention & Deletion Policy for the schedule, including GST records (6 years) and company books of account (8 years).

11. Data Breach Notification

If a personal data breach is likely to result in harm to you, we will notify affected users and the Data Protection Board of India without undue delay, in the form and manner prescribed under the DPDP Act, in addition to meeting our separate CERT-In reporting obligation described in Section 9.

12. Your Rights as a Data Principal

Subject to verification of your identity and applicable law, you have the right to:

  • Access — review the personal information we hold about you (most of this is already visible inside your Settings page);
  • Correction & completion — fix inaccurate or incomplete information (via Settings, or by writing to us);
  • Erasure — request deletion of your account and data, as described in Section 10;
  • Grievance redressal — raise a complaint with our Grievance Officer (Section 15) and, if unresolved, with the Data Protection Board of India;
  • Nominate — nominate another individual to exercise these rights on your behalf in the event of death or incapacity;
  • Withdraw consent for non-essential processing (e.g. WhatsApp notifications), where applicable.

13. Children's Privacy

Rebota is a business tool intended for use by contractors, engineers and construction businesses. It is not directed at, and we do not knowingly collect personal information from, individuals under the age of 18.

14. Changes to this Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or for legal/regulatory reasons. Material changes will be notified in-app or by email at least 15 days before they take effect. We will post the updated policy on this page with a revised "Last updated" date. Continued use of the Service after changes take effect constitutes acceptance of the revised policy.

15. Grievance Officer & Contact

In accordance with the Information Technology Act, 2000, the IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, and the Digital Personal Data Protection Act, 2023, the contact details of the Grievance Officer are:

Grievance Officer
Pratik Tanpure
Email
grievance@rebota.in
Business / Entity
Rebota Technologies
Address
Narhe, Pune, Maharashtra - 411041, India
GSTIN
27ABMFR8964M1Z3

We aim to acknowledge grievances within 24 hours and resolve them within 15 days. For any privacy-related questions, also see our Data Processing Agreement (for business customers) and Data Retention & Deletion Policy.

Rebota

Construction Progress, Cost & Billing Dashboard for Indian contractors managing ₹25L–50Cr projects.

Product

Features How it Works Pricing Intelligence Center Blog Compare Rebota Start Free Trial

Company

About Us Contact Us Login

Legal

Security System Status Privacy Policy Terms & Conditions Cancellation & Refund Policy Shipping & Delivery Policy Data Processing Agreement Data Retention Policy
© 2026 Rebota Technologies  ·  GSTIN: 27ABMFR8964M1Z3. Built for Indian contractors.
support@rebota.in  ·  +91 84591 40080
We use essential cookies to keep you signed in and secure your session. See our Privacy Policy for details.