Legal

Privacy Policy

Effective date: 7 July 2026

Business information

Legal entity
Web Tech Digital Work (a sole proprietorship)
Trade name
Voroa
GSTIN
27ATFPT3932L1Z6
Registered office
Commercial Office No. 605, Freedom Towers, CTS No. 15184, Near Akashwani, Chhatrapati Sambhajinagar, Maharashtra 431001
Contact / Grievance Officer
legal@getvoroa.com

1. Who we are

Voroa is operated by Web Tech Digital Work, registered at Commercial Office No. 605, Freedom Towers, CTS No. 15184, Near Akashwani, Chhatrapati Sambhajinagar, Maharashtra 431001. This policy explains how we handle data collected through the Voroa platform and the getvoroa.com website. We are committed to handling personal data in accordance with the Digital Personal Data Protection Act, 2023 (DPDP Act) and other applicable Indian law.

2. What we collect

Account data: your email address, and the password you set (stored only as a secure hash).

Deployment and configuration data: the repositories, branches, and build settings you connect, along with your application's logs and deploy history, so we can build and run your app and show you its status.

Environment variables: we store only the *names* of the environment variables you configure, for display in your dashboard. We do not store the secret *values* of your environment variables in our own systems; those are held securely in the platform runtime and are treated as write-only.

Payment data: if you subscribe to a paid plan, your payment is handled by our payment provider. We receive confirmation of payment and subscription status. We do not store raw card or UPI credentials.

Usage, logs, and diagnostics: technical data such as IP address, browser and device type, timestamps, server access logs, and error reports, used for security, debugging, and reliability, and retained for a limited period.

3. Your data and your application's data

There are two different kinds of data on Voroa, and our role differs for each:

  • Your account data — the information you give us to open and run your Voroa account (above). For this data, Voroa is the entity that decides how and why it is processed.
  • The data your deployed application processes — the information your own application collects from its end users. For this data, you decide how and why it is processed, and Voroa only stores and runs it on your instructions as part of hosting your application. You are responsible for providing notice to, and obtaining any required consent from, your application's end users, and for complying with the law that applies to that data.

4. How we use your data

To provide, operate, and maintain the platform; to build, deploy, and run your applications; to authenticate you and protect your account and the platform; to send service-related communications such as billing, support, and critical updates; to comply with legal and tax obligations; and to improve the platform based on usage patterns and error reports.

5. Legal basis and consent (DPDP Act)

We process your personal data on these grounds:

  • Consent — you agree to this policy and our Terms when you create an account. You can withdraw consent at any time by closing your account or by contacting us (see Section 12). Withdrawing consent may mean we can no longer provide the service.
  • Performance of the contract — to deliver the service you have signed up for.
  • Legal obligation — for example, retaining tax and GST records.

6. Data sharing

We do not sell or rent your data. We share it only with the service providers needed to run the platform, each operating under its own privacy and data-processing terms:

  • Cloud hosting — Amazon Web Services, in the Mumbai region (ap-south-1), where your data is hosted and your applications run.
  • Payment processing — our payment provider, used only if you subscribe to a paid plan, to take payment and issue receipts.
  • Transactional email and error monitoring — used to send service emails and to detect and fix faults.

We can provide our current list of these service providers on request. We also disclose data to government or regulatory authorities only when required by law.

7. Data residency and cross-border processing

Your data is hosted in India, in the AWS Mumbai region (ap-south-1). Some service providers listed above may process limited data (such as email delivery or error reports) outside India in order to deliver the service. In every such case, data is encrypted in transit and shared only to the extent needed to operate the platform, in accordance with the DPDP Act.

8. Data retention and deletion

We retain your account and application data for as long as your account is active. After you close your account or request deletion, we delete or anonymise your personal data within a reasonable period (ordinarily within 30 days), except where we are required to keep certain records — such as GST and tax invoices — for the period mandated by applicable tax law. You may request an export or deletion of your data at any time by contacting legal@getvoroa.com.

9. Security

We use reasonable security safeguards to protect your data, including encryption in transit (HTTPS), hashed passwords, token-based authentication, isolation of each tenant's account and resources, access controls on our systems, and regular backups. No system is completely secure, so we encourage you to use a strong, unique password and to keep your credentials confidential.

10. Your rights (DPDP Act, 2023)

Under the Digital Personal Data Protection Act, 2023 you have the right to:

  • access the personal data we hold about you;
  • correct inaccurate or incomplete data;
  • erase your data, subject to legal retention requirements;
  • withdraw consent at any time;
  • nominate another person to exercise your rights on your behalf; and
  • grievance redressal — raise a concern with our Grievance Officer (Section 12).

To exercise any of these rights, contact legal@getvoroa.com.

11. Data breach notification

In the event of a personal data breach affecting your data, we will, in line with the Digital Personal Data Protection Act, 2023, notify the Data Protection Board of India and each affected user without undue delay — describing the nature of the breach, the data affected, the likely consequences, and the steps we are taking to address it and mitigate harm.

12. Grievance Officer and how to reach us

In compliance with the Digital Personal Data Protection Act, 2023 and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, our Grievance Officer is:

Name
Sagar Tayde
Designation
Proprietor / Authorised Representative
Entity
Web Tech Digital Work (trade name: Voroa)
Email
legal@getvoroa.com

For any privacy-related concern or to exercise your rights, write to legal@getvoroa.com with the subject "Grievance — Privacy". We will acknowledge your request within 24 hours and aim to resolve it within 15 days.

13. Children

The Service is not directed to, and we do not knowingly collect personal data from, individuals under the age of 18.

14. Cookies and local storage

The getvoroa.com website does not use tracking or advertising cookies. The Voroa application stores an authentication token in your browser to keep you signed in. No third-party advertising cookies are set on either surface.

15. Changes to this policy

We may update this policy. The effective date above is updated when changes are made, and material changes will be communicated by email at least 7 days before they take effect. Continued use of the platform constitutes acceptance of the revised policy.