Privacy Policy

Last updated: January 11, 2026

At Steamz (operated by Mavels Tech), we take your privacy seriously. This Privacy Policy explains how we collect, use, disclose, and safeguard your information in compliance with the Digital Personal Data Protection Act, 2023 (DPDP Act).

1. Information We Collect

  • Personal Data: Name, email address, phone number when you register.
  • Billing Address: Address including city, state, and pincode for GST compliance and tax invoice generation.
  • Verification Data: Aadhaar, PAN, or other identity documents for tutor verification (stored securely and encrypted).
  • Payment Data: Financial information is processed by our secure payment partners (Razorpay); we do not store full card details.
  • Tax Information: GSTIN (for GST-registered tutors), PAN for TDS compliance.

2. How We Use Your Information

  • Facilitate tuition bookings and communication between verified tutors and parents.
  • Process payments and generate tax-compliant invoices.
  • Verify the identity of tutors to ensure platform safety.
  • Send important service updates, payment confirmations, and safety notifications.
  • Comply with tax regulations (GST, TDS, TCS) as required by law.

3. Data Retention

  • Tax Records: Retained for 7 years as required by Income Tax Act and GST regulations.
  • Account Data: Retained until account deletion, then archived for legal compliance period.
  • Verification Documents: Securely deleted 90 days after verification unless legally required.

4. Data Storage Location

Your data is stored in India

All personal data is stored on servers located in India (Google Cloud Platform - asia-south1 region) in compliance with DPDP Act requirements.

5. Your Rights (DPDP Act)

Under the Digital Personal Data Protection Act, 2023, you have the following rights:

Right to Access

You can request a summary of your personal data we hold.

Right to Data Portability

Download your data in a machine-readable format from Settings → Privacy.

Right to Erasure

Request deletion of your account with a 30-day grace period. Note: Tax records are retained as legally required.

Right to Correction

Update inaccurate personal data from your account settings.

6. Data Security

  • All data is encrypted in transit (TLS 1.3) and at rest (AES-256).
  • PAN, Aadhaar, and bank details are stored with field-level encryption.
  • We implement role-based access controls and audit logging.
  • Regular security assessments and vulnerability testing.

7. Consent

By using our services, you consent to the collection and processing of your personal data as described in this policy. You can withdraw consent at any time by deleting your account, subject to legal retention requirements for tax records.

8. Data Protection Officer

Contact our Data Protection Officer

For privacy-related queries or to exercise your data rights, contact:
Email: hello@mavelstech.in
Response Time: Within 7 business days

9. Contact Us

For general questions about this Privacy Policy, please contact:
Mavels Tech
Email: hello@mavelstech.in
Data Protection Officer: hello@mavelstech.in