A.1 About this Privacy Policy
This Privacy Policy explains how Onetap Labs ("Onetap", "we", "our", "us") collects, uses, discloses, retains, transfers, and protects personal data in connection with the Onetap R-series presence-verification system, the Onetap Dashboard, the Onetap mobile applications for teachers, students, and parents (each an "App", together the "Apps"), and our websites at onetaplabs.com and any subdomains (together the "Service").
This Policy is published pursuant to the Digital Personal Data Protection Act, 2023 read with the Digital Personal Data Protection Rules, 2025 (together, the "DPDP Framework"), the Information Technology Act, 2000 and the rules made thereunder including the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and the App Store Review Guidelines of Apple Inc.
A summary of our data collection practices, formatted in accordance with Apple's Privacy Nutrition Label requirements, is available on the App Store product page for each App. Those disclosures are kept consistent with this Policy; this Policy is authoritative in the event of any inconsistency.
Onetap Sentinel is out of scope of this Policy. Sentinel uses event-triggered cameras, is restricted to adult users, and is governed by a separate privacy policy at onetaplabs.com/sentinel/privacy.
A.2 Who we are
Onetap Labs Light House Hill Road, Hampankatta Mangaluru, Karnataka 575001 India
General contact: hello@onetaplabs.com
Privacy contact: privacy@onetaplabs.com
Grievance redressal: grievance@onetaplabs.com
A.3 Our role under the DPDP Framework
A.3.1 — School-deployed accounts. All institutional uses of the Service operate on a Data Processor model. The school, college, university, or other institutional customer is the Data Fiduciary. Onetap is the Data Processor. We process personal data only on the documented instructions of the institution, recorded in the institutional customer agreement and the accompanying Data Processing Addendum.
The institution is responsible for the legal basis for processing. Onetap supports the institution in obtaining verifiable parental consent by operating the DigiLocker-based consent workflow described in section A.6.
A.3.2 — Marketing site visitors. For any person who interacts with our marketing site without creating an account, Onetap is the Data Fiduciary for the limited personal data we receive — typically an IP address, device type, and any information voluntarily submitted through a contact form.
A.3.3 — No direct-to-consumer accounts. Onetap does not offer direct-to-consumer subscriptions, in-app purchases, or any product where a parent, student, or other individual contracts with Onetap independently of an institution. The Apps are free to download; access is provisioned by the institution that has licensed the Service.
A.4 Personal data we process
We collect the minimum personal data required to operate the Service.
A.4.1 Account data
- Full name
- Work, school-issued, or personal email address used for sign-in
- Mobile phone number, for one-time-password sign-in and account recovery
- Role within the institution — administrator, teacher, parent, student
- The institution you belong to and, where applicable, your class, section, or department
- The NFC card identifier issued to you, which is a non-personal token until linked to your name
A.4.2 Presence event data
Records produced when an NFC tap is registered and the radar confirms physical presence in the room. Each record contains:
- The user's account identifier
- The room or sensor identifier
- A timestamp
- The classification of the event — present, absent, late, exited early
- The radar reading that confirmed presence, which is a derived numerical signal and not an image, audio, or biometric data
A.4.3 Device and technical data
- Device model and operating system version
- App version and a unique installation identifier
- Anonymised crash reports and diagnostic traces
- IP address used to connect to our backend
- Logs of API requests issued by your account
A.4.4 Consent verification data
Data generated by the DigiLocker-based parental-consent workflow in section A.6:
- The parent or lawful guardian's name and DigiLocker-issued verifiable credential
- A timestamp recording when consent was given
- The categories of processing to which consent was given
- A reference to the child whose data the consent authorises
A.4.5 Payment data
Institutional billing only:
- The name of the institution and the contact person on the payment instrument
- A masked card number and last four digits, where paid by card
- Transaction amount, currency, and timestamp
We do not store full card numbers or CVV codes; card data is handled by our payment processors under PCI-DSS requirements. We do not collect payment data from parents, students, or individual users.
A.4.6 Support and communications data
Records of correspondence with our support team, including content, timestamps, and any files you attach.
A.4.7 What we do not collect
In connection with the R-series, the Dashboard, and the Apps, the Service:
- does not collect, store, or transmit any image, video, or facial data. The R-series hardware contains no camera. The Apps do not capture images or video. Where an App invokes the device camera incidentally — for example, to read a QR code during firmware provisioning — the frame is processed locally for the code only and discarded immediately. No image is collected, stored, or transmitted.
- does not use microphones and collects no audio
- does not collect biometric data of any kind
- does not collect precise GPS location from your device
- does not collect the Apple Identifier for Advertisers or any equivalent advertising identifier
- does not request the App Tracking Transparency permission
- does not offer in-app purchases or collect payment data from individual users
- does not sell personal data, and does not share personal data with data brokers
The radar component of the R-series hardware is a millimetre-wave sensor that detects human presence in a defined volume of space. It produces a numerical occupancy signal. It does not produce, transmit, or store any signal from which a specific person could be visually or biometrically identified.
These representations apply to the R-series. For Onetap Sentinel, which uses event-triggered cameras, refer to onetaplabs.com/sentinel/privacy.
A.5 Why we process personal data, and on what legal basis
| Purpose | Data | Lawful ground |
|---|---|---|
| Provide the presence-verification service | Account, presence event, device, consent verification data | Performance of the contract with the institution (Sec. 7(a)) |
| Authenticate users and secure accounts | Account, device data | Performance of contract; legitimate uses (Sec. 7(b)) |
| Communicate about the Service | Account, communications data | Performance of contract |
| Charge institutions | Payment, account data | Performance of contract |
| Detect and prevent fraud, abuse, misuse | Device, account, aggregate presence data | Legitimate uses (Sec. 7(g)) |
| Comply with law and lawful requests | Any category | Compliance with law (Sec. 7(c)) |
| Improve the Service through aggregated, de-identified analysis | Device data; de-identified presence events | Contract / consent |
We do not process personal data for behavioural advertising.
Language of notices. Notices required under the DPDP Framework, including the notice given before processing begins and any consent-withdrawal form, are available in Kannada and English. On written request to privacy@onetaplabs.com, we will provide the notice in any other language listed in the Eighth Schedule to the Constitution of India.
A.6 Children's data
Most people whose presence the R-series records are children — persons under eighteen under the DPDP Framework. Section 9 of the Act imposes specific requirements; Rule 10 of the DPDP Rules, 2025 prescribes how verifiable consent must be obtained.
A.6.1 Verifiable parental consent — DigiLocker
Before personal data of any child is processed, verifiable consent of a parent or lawful guardian is obtained through DigiLocker, the digital identity platform operated by the Ministry of Electronics and Information Technology, Government of India.
- When an institution provisions a student account, Onetap sends a consent request to the parent or lawful guardian named in the institution's enrolment record, by email or SMS.
- The parent opens the request and is redirected to DigiLocker for authentication.
- DigiLocker verifies the parent's identity against Government of India records and confirms the parent–child relationship through linked credentials.
- The parent grants consent to the specific categories of processing in section A.5.
- Onetap records the verifiable credential, the timestamp, and the scope of consent.
- No personal data of the child is processed until consent is recorded.
The school remains the Data Fiduciary and is contractually responsible for accurate enrolment data, accurate parent contact details, and the ongoing fitness of the consent. Onetap provides the technical means by which consent is captured.
Where DigiLocker is unavailable to a particular parent or guardian, Onetap provides an equivalent verification pathway through another identity platform recognised by the Central Government under Rule 10 of the DPDP Rules, 2025. No paper or unverified declaration is treated as verifiable consent.
A.6.2 No targeted advertising to children
Onetap does not engage in tracking, behavioural monitoring, or targeted advertising directed at children. This is a permanent commitment of the product, not a configuration setting.
A.6.3 No detrimental processing
We do not process children's data in any manner likely to cause a detrimental effect on the well-being of a child.
A.6.4 Withdrawal of consent
A parent or lawful guardian may withdraw consent at any time by writing to privacy@onetaplabs.com or through the withdrawal flow in the parent App. Withdrawal ends processing prospectively and triggers the deletion process in section A.9. Where law requires retention of certain records, those are kept for the period required and then deleted.
A.6.5 Age verification
Before any account begins processing personal data, Onetap determines whether the user is a child.
- Accounts provisioned by an institutional customer. Age status is verified against the enrolment records the institution provides at provisioning. Onetap relies on those records as the source of truth; the institution warrants their accuracy in the Data Processing Addendum.
- Parent-facing accounts. Age status is determined through the parent's DigiLocker-issued verifiable credential, which establishes both the parent's identity and the parent–child relationship.
Processing does not commence until age status is confirmed. Where the user is a child, processing does not commence until verifiable parental consent has been obtained under section A.6.1 and recorded.
Notices presented during the consent flow are displayed in Kannada and English by default, with the option to switch to any language listed in the Eighth Schedule to the Constitution of India.
A.7 Sub-processors
Each sub-processor is bound by a written agreement obligating it to process personal data only on our instructions and to maintain security standards no lower than ours.
| Sub-processor | Purpose | Where processing occurs |
|---|---|---|
| Supabase Inc. | Primary database, authentication, file storage | India (where supported) / United States |
| Vercel Inc. | Application hosting and delivery | United States / global edge |
| Cloudflare, Inc. | Authoritative DNS and inbound email routing | United States / global edge |
| Stripe Inc. | International card payments — institutional billing | United States; India where supported |
| Razorpay Software Pvt. Ltd. | India-domestic payments and UPI — institutional billing | India |
| DigiLocker (NeGD, Government of India) | Parental consent verification | India |
| MSG91 (Walkover Web Solutions Pvt. Ltd.) | One-time-password SMS to Indian numbers | India |
| Twilio Inc. | International SMS and voice fallback | United States |
| ZeptoMail (Zoho Corporation Pvt. Ltd.) | Transactional email | India |
| Apple Inc. | App Store distribution, push notification (APNs) | Apple-operated infrastructure |
The current list is maintained at onetaplabs.com/trust/sub-processors. Institutional customers receive at least 30 days' written notice before any addition or replacement, with a right to object as set out in the Data Processing Addendum.
A.8 Cross-border transfers
Some sub-processors operate from outside India. Where personal data is transferred outside India, we rely on the absence of any restriction notified by the Central Government under section 16 of the DPDP Act in respect of the destination, appropriate contractual safeguards with each sub-processor, and the technical measures in section A.10.
We do not transfer personal data to any jurisdiction the Central Government of India has placed under restriction.
A.9 Retention
We keep personal data only as long as necessary for the purpose for which it was collected, after which it is deleted or irreversibly anonymised.
| Category | Retention period |
|---|---|
| Active account profile | While the account is active |
| Account profile after deletion request | Removed from production within 30 days |
| Presence event data — live | Current academic year plus 24 months |
| Presence event data — archived | As required by the institution's contract or by law, whichever is longer; not exceeding 7 years total absent explicit instruction |
| Consent verification records | Duration of consent plus 24 months after withdrawal, as evidence of lawful processing |
| Payment records — institutional | 8 years, per Indian tax and accounting law |
| Support correspondence | 24 months from ticket closure |
| System and security logs | 90 days |
| Database backups | Rolling 30 days; production deletions are purged from backups within 30 days |
Where data is retained longer because law requires it, it is held in restricted-access archive storage and is not used for any other purpose.
A.10 Security
We maintain administrative, technical, and physical safeguards designed to protect personal data against unauthorised access, alteration, disclosure, or destruction:
- Encryption in transit (TLS 1.2 or higher) and at rest (AES-256)
- Role-based access controls with multi-factor authentication for staff with production access
- Network segmentation between production, staging, and corporate environments
- Logging and monitoring of access to systems containing personal data
- Annual review of vendor security postures
- A vulnerability disclosure address at
security@onetaplabs.com
No system is impervious, and we do not represent that the Service is unbreachable. Where a breach occurs that is likely to cause harm, we act under section A.12.
A.11 Your rights as a Data Principal
A.11.1 — Access. Obtain a summary of the personal data we process about you and our processing activities.
A.11.2 — Correction. Request correction of inaccurate or misleading data, completion of incomplete data, or updating of outdated data.
A.11.3 — Erasure. Request erasure of personal data no longer needed for the purpose for which it was collected, subject to any law requiring retention.
A.11.4 — Grievance redressal. Submit a grievance by writing to grievance@onetaplabs.com. We respond within 90 days of receipt.
A.11.5 — Nomination. Nominate another individual to exercise your rights in the event of your death or incapacity.
A.11.6 — Withdrawal of consent. Where processing is based on consent, withdraw it at any time, without prejudice to the lawfulness of processing before withdrawal.
A.11.7 — How to exercise. Write to privacy@onetaplabs.com with your name, the account email, and a description of your request. We verify your identity before acting. If your account was provisioned by your school, we may direct you to the school as Data Fiduciary. We respond to a verified request within 90 days of receipt.
A.11.8 — Complaints. You may complain to the Data Protection Board of India if you believe we have processed your personal data in contravention of the DPDP Framework.
A.12 Personal data breach notification
Where we become aware of a personal data breach likely to result in harm to a Data Principal, we will:
- Notify the Data Protection Board of India within 72 hours of becoming aware of the breach, or within such shorter or longer period as prescribed by the DPDP Rules, 2025, in the prescribed form;
- Notify affected Data Principals promptly thereafter with the categories and approximate quantity of data affected, the brief facts, the mitigation measures taken, the steps the Data Principal can take, and a contact point for further information, as required under those Rules;
- Maintain a written record of the breach and the response, available for inspection by the Board.
Where the breach affects data processed on behalf of an institutional customer, we notify the institution without undue delay so it can discharge its own obligations as Data Fiduciary.
A.13 Cookies and similar technologies
The Onetap marketing website uses a small number of strictly necessary cookies. We do not use third-party advertising cookies or cross-site tracking pixels on the marketing site or in the Apps.
The Apps use a single anonymous installation identifier to attribute crash reports to an installation. It is not linked to your Apple ID or any advertising profile.
A.14 Apple App Tracking Transparency
Because Onetap does not track users across apps or websites owned by other companies and does not access the IDFA, the Apps do not present the App Tracking Transparency prompt. If this changes, we will update this Policy, present the prompt as Apple requires, and honour any "Ask App Not to Track" response.
A.15 Changes to this Privacy Policy
We may update this Policy. When we do, we change the "Last Updated" date and post the new version at the same URL. For material changes we additionally notify account holders by email and, where appropriate, by in-app notice at least 30 days before the change takes effect.
Continued use after the change takes effect constitutes acceptance. If you do not accept a change, you may close your account under section B.16.