Legal

Privacy Policy

How we collect, use, share, and protect personal data across the vidhi app, dashboard, and website.

Last updated 25 August 2026

The short version

Account identity
Yes — your name, work email, and optional phone number, so you can sign in and your team knows who did what.
Photos
Yes — photos you take or attach as evidence of work. Never your camera roll at large.
Device location
No. The app never requests or collects GPS or device location.
Analytics or advertising
None. No analytics SDK, no ad network, no advertising identifier, no tracking across apps.
Sold to anyone
Never. We do not sell or rent personal data, and we never use your content to train AI models.
Encrypted in transit
Yes — HTTPS/TLS on every connection.

The sections below are the full, binding detail. Where the two ever appear to differ, the detailed sections govern.

1. Who is responsible for your data

ZENCRAFTLABS FZ-LLC is the data controller for personal data processed through vidhi — the mobile app, the manager dashboard, and this website (together, the Service). In this policy, “vidhi”, “we”, “us”, and “our” mean ZENCRAFTLABS FZ-LLC.

ZENCRAFTLABS FZ-LLCFDRK0490Compass Building, Al Shohada Road,AL Hamra Industrial Zone-FZ,Ras Al Khaimah, United Arab Emirates

For any privacy question, correction, or complaint, write to app@vidhi.team. A real person reads it, and we aim to reply within five business days.

2. vidhi is workplace software

vidhi is bought by a business and used by its team. If you sign in with an account your employer created, your employer decides what work you record, which locations you are assigned to, and who inside the organisation can see it. Your employer administers that account and can view the work you submit through it — including the photos you attach.

That is the nature of the product, and it is worth being direct about: vidhi is not a private space. Work you record is visible to managers and administrators in your organisation. Requests about data your employer controls may need to go to your employer, and we will help you reach the right person.

3. What we collect

Account and profile

Your name, work email address, and — if provided — phone number. Alongside these we store your role, job title, assigned locations, timezone, notification preferences, and interface preferences. We record when you last signed in and keep a throttled activity timestamp so the dashboard can show who is currently active. Passwords are stored only as a salted Argon2 hash; we never keep the password itself and cannot recover it.

Photos and files you attach

The app asks for camera access so you can photograph work — a completed checklist step, a fault, an asset tag — and for photo library access so you can attach a picture you already took. We receive only the images you actively choose to attach. The app does not scan, browse, index, or upload your photo library.

The work you record

Checklist submissions, tasks, audits, work orders, asset records, announcements, comments, and the timestamps attached to them. This is your employer’s operational data, and it is the reason the Service exists.

Technical data

Our servers log the IP address, timestamp, and request details of connections, which we use to keep the Service running and to investigate abuse or faults. This website infers your country from your IP address so it can show prices in your local currency, and stores that country code in a short-lived v_country cookie. That is a country, not a position — it is not device location, and it is not used to identify you.

4. What we do not collect

Device location. The vidhi app does not request the location permission, contains no geolocation code, and never collects GPS or device location — neither in the foreground nor in the background. Where you see the word “location” in vidhi, it means one of your business’s sites — a store, branch, or facility your organisation set up and assigned you to. It never means where your phone is.

Analytics and advertising. There is no analytics SDK, no advertising network, no advertising identifier, no pixel, and no cross-app or cross-site tracking anywhere in the app. We do not build advertising profiles and we do not participate in ad auctions.

Sensitive categories. We do not ask for government identifiers, health data, biometrics, precise financial account details, or any special-category data.

5. How we use data

To operate the Service and keep you signed in; to show your team the work that has been done; to send operational email and notifications you have opted into; to provide support you ask for; to keep the Service secure and investigate abuse; and to bill the customer organisation. That is the whole list.

We do not use your content to train AI models — ours or anyone else’s — and our AI sub-processor is contractually bound not to train on it either.

6. Who we share data with

We do not sell, rent, or trade personal data, and we do not share it for anyone else’s advertising. We use a small set of sub-processors to run the Service, each bound by contract to protect the data and use it only on our instructions:

WhoWhat they handle
Cloud hosting & databaseRuns the service and stores your account and work records.
Object storage (Amazon S3 or S3-compatible)Stores the photos and files you attach to work.
AnthropicOnly if enabledAI photo comparison: when your organisation turns the feature on, the photo attached to a step and that step’s reference image are sent for automated comparison.
Email delivery (SMTP provider)Sends sign-in, password-reset, and notification email.
RazorpayBilling onlyProcesses card and UPI payments for Indian customers. Card details go to Razorpay directly — we never receive or store them.
Zoho BooksBilling onlyGenerates invoices from your billing details.
CalendlyWebsite onlyHandles demo bookings made on this website. Not part of the app.

We also disclose data where the law requires it — a valid legal order, or to establish or defend legal claims — and to a successor entity if the business is ever sold or merged, in which case this policy continues to apply until you are told otherwise.

A specific note on the AI photo feature

Some organisations enable AI photo comparison, which checks a photo submitted against a reference image for a checklist step and flags apparent deviations. Where it is switched on, the submitted photo and the reference image are transmitted to Anthropic for automated analysis and a written result is returned to your organisation. No account identifiers are sent with the images, the result is advisory rather than a decision about any person, and the images are not used to train models. If your organisation has not enabled the feature, no photo ever leaves our own storage.

7. How we protect data

Every connection to the Service uses HTTPS/TLS, so data is encrypted in transit. Passwords are stored as salted Argon2 hashes. Attachments are served through short-lived signed URLs rather than public links. Access inside vidhi is limited to staff who need it to run and support the Service. No system is perfectly secure, but if a breach ever affects your personal data we will notify you and the relevant authority as required by law.

8. How long we keep data

We keep your account and the work recorded under it for as long as your organisation’s account is active, because that record is what the Service is for. When an organisation closes its account, we delete or irreversibly anonymise the associated personal data within 90 days, except where we must keep something longer to meet a legal, tax, or accounting obligation — invoices being the usual example. Password-reset tokens expire within an hour. Server logs are kept only as long as they are useful for security and troubleshooting.

9. Your rights

Depending on where you live, you may have the right to access the personal data we hold about you, correct it, delete it, object to or restrict how we use it, receive a copy in a portable format, and complain to your data protection authority. Exercise any of these by writing to app@vidhi.team. We do not charge for this and we will not treat you differently for asking.

Because vidhi is workplace software, some of this data belongs to your employer’s account. Where we cannot act without their instruction, we will tell you so promptly and point you to the right contact rather than leaving the request unanswered.

10. Deleting your account and your data

To request deletion of your vidhi account and the personal data associated with it, email app@vidhi.team from your account address with the subject “Delete my account”. We will verify the request, tell you what will be removed and what must be retained for legal reasons, and complete the deletion within 30 days.

If your account was created by an employer, deleting it may require your administrator’s involvement, since the work records belong to their organisation. We will coordinate that and keep you informed.

11. International transfers

ZENCRAFTLABS FZ-LLC is established in the United Arab Emirates, and our sub-processors operate in several countries. Running the Service therefore involves transferring personal data across borders. Where the law requires a safeguard for such a transfer, we put an appropriate one in place — standard contractual clauses or an equivalent mechanism — before the transfer happens.

12. Children

vidhi is workplace software intended for adults in employment. It is not directed at children, and we do not knowingly collect personal data from anyone under 16. If we learn that we have, we delete it.

13. Changes to this policy

We will update this page when our practices change, and the date at the top will always show when. If a change materially affects how we handle your personal data, we will give notice in the app or by email before it takes effect rather than changing it quietly.

14. Contact us

Questions, requests, or complaints about privacy go to app@vidhi.team, or by post to ZENCRAFTLABS FZ-LLC at the address in section 1. If you are in the EEA or UK and believe we have not resolved your concern, you may complain to your local supervisory authority.