Information we collect
Depending on how you use Nivara, we may process: name and email; optional phone if you type it into a profile or form; profile photo if you upload one; society or village registration details and creator designation; society membership, wing, flat, and occupancy relationship; vehicles and parking assignments; visitor and guest records; seller, provider, food, service, and product listings; farmer and village information; property listings, contact entitlements, and unlock metadata; Buy & Sell listing information, images, category, price, location, and listing status; Farm Fresh requirements and admin/farmer workflow data; in-app conversation metadata, message content, participants, and timestamps; Nivara Assistant queries used to interpret intent and retrieve authorized records; orders, complaints, fraud, listing, and price reports; anti-bypass detection results and moderation or audit events; advertising requests; support tickets; payment reconciliation metadata; and security logs. We do not invent extra categories. If you never use a feature, we do not collect that feature’s data.
Nivara does not currently collect precise device GPS location.
Authentication
Nivara stores your account email and authentication information. Sign-in uses email and password, and may use Google as an identity provider when that provider is configured. We process the email address you submit or that Google shares for sign-in, a password you choose for email accounts (stored by the authentication provider, not in Nivara application tables as plaintext), optional Google display name and avatar metadata, and the resulting session cookies. Nivara does not currently send authentication emails, confirmation emails, or password-reset emails. Society administrators cannot see or set a password.
Google Sign-In authenticates your Nivara account. Society membership and role access are still controlled by Nivara's existing membership and authorization process. Google name, email, or profile photo is identity metadata only. It is not proof of residence, flat ownership, society administration, farmer verification, village authority, or Super Admin status. Nivara does not currently use phone OTP or SMS authentication.
Payment data
Card and bank credentials, when a payment provider is configured, are processed by that provider (for example Razorpay). Nivara retains internal transaction identifiers, amounts, currency, status, timestamps, transaction type, provider order/payment/subscription IDs, and failure metadata needed to reconcile payments. Nivara does not claim to store full card numbers or CVV. Live payments are off until production keys and webhooks are configured. Sellers and farmers may optionally publish a UPI ID, payment display name, payment instructions, and a QR image they upload. Those fields are seller- or farmer-provided payment information, not Nivara-verified bank details.
Society and role-based access
Society data is scoped by society and role. A resident of Society A cannot read Society B’s private records. Wing administrators are limited to their assigned wing. Security staff receive only information needed for gate operations. They should not see marketplace finances, property contact details, or private resident profiles. Society administrators do not automatically see every private field a resident stores. Protected seller and property contacts remain server-side until an authorized unlock or fulfilment need applies.
Visitor and security data
Visitor name, optional visitor mobile, visitor type, purpose, vehicle number if entered, wing, flat, entry timestamps, approval/rejection/auto-approval state, and the security user who recorded the request may be processed so a society can operate its gate. Resident display name and a permitted phone number for the selected flat may be shown to assigned Security for operational calling. We do not expose marketplace, property, Farm Fresh, or unrelated profile data through the Security desk. In-app gate notifications may include visitor and flat details. A sound or browser notification is attempted only where the device permits it; the in-app approval request still appears if sound is blocked. Operational visitor-entry records are retained for the current and previous calendar month. Eligible older operational entries are cleaned on the 10th of each month. Audit records that must be kept are not deleted by that cleanup.
Messaging and contact protection
In-app messages are stored with the conversation they belong to so participants can continue the thread and so Nivara can operate safety, moderation, and security workflows. We do not invent a fixed deletion date for every message. Protected owner, seller, and farmer contact details are disclosed only where platform rules permit, such as an active property contact entitlement, a seller-enabled Buy & Sell contact, or a farmer who chose to publish a public farm mobile. A listing by itself does not make private phone, email, or UPI details public.
Nivara Assistant
If you use Nivara Assistant, we process the text you submit so the product can interpret intent and retrieve authorized Nivara information you are already allowed to see. The Assistant follows the same access controls as the rest of Nivara. It does not reveal hidden phone numbers, email addresses, UPI IDs, or private society or farmer records. Nivara does not use private chat or Assistant queries to train a public general-purpose AI model.
Voice
If you use voice input, audio is processed to produce a transcript and then discarded. Nivara does not keep a permanent archive of raw voice recordings by default. We may store short metadata such as language, intent, status, and duration so we can operate rate limits and reliability. Voice is another interface to the same Assistant and the same authorization rules. Core Nivara voice does not require a paid AI API. Nivara does not claim that voice is used to train models, and we do not train models on Nivara user conversations.
How we use information
We use information to authenticate you; manage societies and verification; operate Gate and visitors; run marketplace, Food, Services, Farm Fresh, property discovery, Buy & Sell, and advertising; operate authorized in-app messaging and Nivara Assistant; process or reconcile payments; handle complaints, fraud, and support; send in-app or browser notifications you enable; keep audit trails; and improve reliability. We do not sell resident directories as a data product. We do not currently send outbound email or SMS.
Sharing
We share information only as needed: with society or wing administrators for membership and operations; with security for gate tasks; with sellers, providers, or farmers to fulfil an order or pre-order you placed; with payment and hosting providers; and with authorities when legally required. We do not currently use an email-delivery provider. We do not claim that every resident record is visible to every society admin.
Retention
Retention varies by record type. Transaction, complaint, and audit records may be kept for reconciliation and legal reasons. Operational food or service catalogue items may expire according to the catalogue model. We do not promise deletion of records we must retain.
Security
We use role-based access, authenticated sessions, and database row-level security. No platform can promise absolute security.
Your rights
You may request access or correction of your profile, close optional listings, and use in-app Support. You may withdraw optional consents that are not required to operate the service. Account closure does not erase payment or audit records that must be kept. Mandatory Terms acceptance is required to use Nivara; it is not a marketing opt-in.
Cookies and local storage
Nivara uses cookies and similar storage for the signed-in session (Supabase auth) and, if you install the PWA, for the service worker and optional notification permission. We do not use those technologies as a hidden advertising tracker.
Children
Nivara is built for society operations and adult users of those societies. It is not offered as an independent service for children. A specific minimum age is not invented here.
Changes
We may update this policy. The version and date appear at the top of the page.
Contact
Use Support after you sign in, or the public Contact page. A dedicated privacy email will be published when the operating entity finalizes it. Do not treat a missing email as a public inbox we have already announced.
Home