Citivo Privacy Policy
This document is an electronic record under the Information Technology Act, 2000. It does not require any physical or digital signature.
This Privacy Policy explains what personal data Citivo collects, why, who we share it with, how long we keep it, and what you can do about it. It forms part of our Terms of Use.
In short
- We collect what we need to run Citivo — your mobile number to sign you in, what you tell us about anything you publish — a business, an event, an item for sale, a job, an influencer profile — and how you use the app.
- We never sell your personal data. Not to anyone, for any purpose.
- We do not track your location in the background. We use it only while you are using the app and only when you do something that needs it.
- You can delete your account yourself, in the app or at citivo.in/delete-your-account, without contacting us — see §8.
- You can ask us what we hold about you, correct it, or complain — see §10 and §12.
This summary is here to help. The sections below are what actually applies.
1. Who we are
1.1 Citivo is operated by Velynt Technologies Private Limited, CIN U58200KA2026PTC216918, registered office Flat No. 312, NCN Srivari Apartments, Hadosiddapura of Sarjapur, Carmelram, Bangalore South, Bengaluru – 560035, Karnataka, India. We are the Data Fiduciary for the personal data described in this policy.
1.2 Privacy queries: support@citivo.in
1.3 Grievance Officer — see §12.
2. Who and what this policy covers
2.1 It covers the Citivo mobile app, our website at citivo.in, and our business-facing interfaces.
2.2 It applies to everyone who uses Citivo.
(a) People searching and browsing — "App Users" in our Terms of Use.
(b) Anyone who publishes anything — "Business Users" in our Terms of Use. That term is not limited to businesses. It covers a shop, a service provider, an office, a religious place, a public service, a job listing, an event organiser, someone selling a single item on the Marketplace, an influencer, and anyone who buys an advertisement — including a personal one such as a greeting or an announcement. See clause 1.5 of the Terms of Use.
(c) Anyone who receives another user's personal data through Citivo — for example, a business receiving an enquiry, a seller receiving a buyer's number, or an employer receiving a job application. Clause 10 of the Terms of Use sets out what you may do with it, and §6.5 of this policy explains our part.
You will often be more than one of these at the same time. Where something applies to only one group, we say so.
2.3 It also covers people who never signed up. Citivo is a directory, so we hold information about people and businesses who have never used the Platform themselves:
(a) a business we listed, or that someone else listed, without it having an account with us;
(b) a person named, shown or referred to in something another user published — for example someone in a photograph, or the subject of a greeting or a tribute in an advertisement;
(c) a person whose contact details appear on an entry that they did not create.
You have the same rights over that information as anyone else, whether or not you have a Citivo account, and §10 explains how to use them. If you are listed and you would rather not be, tell us and we will take it down — write to support@citivo.in, or to our Grievance Officer in §12. You do not need an account to ask.
2.4 Once you send your details to a business, this policy stops applying to them. If you make an enquiry, respond to a job listing, or contact a seller, what you send goes to that person or business, and what they do with it is governed by their own privacy practices, not by this policy. Clause 10 of our Terms of Use sets out the rules we impose on them — use it only for your enquiry, no marketing, no passing it on, delete it when it is no longer needed — and §6.5 of this policy explains our part. But we cannot control what someone does once they hold your number, so decide what to share on that basis.
2.5 It does not cover other people's services. When you follow a link from Citivo to a business's own website, a mapping service, a social media page, or a payment page, you are on someone else's service, governed by their privacy policy, not this one.
That includes WhatsApp groups, even ones we run. A group runs on WhatsApp, under WhatsApp's own terms and privacy policy. If you join one, your number and profile become visible to every other member, and we cannot change that or take it back — see §7.5, and clause 11.5 of the Terms of Use.
2.6 Our own people, as employees, are outside this policy. Personal data we hold about someone because they work for us — rather than because they use Citivo — is not covered here. Where a member of our staff also has a Citivo account, this policy covers them in exactly the same way as anyone else, and §8.8 explains the one difference that applies to an administrative role.
3. What we collect
3.1 What you give us
- To create your account: your mobile number. We verify it with a one-time code sent to that number — by SMS, WhatsApp or another channel bound to it (Terms of Use clause 11.4).
- Your profile: your name, email address if you give us one, and a profile picture if you set one.
- Your age: a confirmation that you are 18 or older, given when you sign up. We do not ask for your date of birth, though you may add a year of birth to your profile if you want to. Citivo is for adults only (§9).
- Your preferences: your city, your language, and your notification settings.
- If you publish an entry — a Listing (a business, shop, service provider, office, religious place, public service or job), an Event, an Offer, a Marketplace Item, a Catalogue, an Advertisement or an Influencer Profile: its name or title, description, address and location, category, tags and facets, opening hours or dates, prices or amounts, contact numbers, WhatsApp numbers and email addresses, websites and other links, social media handles, images, video and audio, and anything else that entry asks for.
- If you publish an Influencer Profile: also any follower, reach or engagement figures you give us. We do not verify them (Terms of Use clause 9.9).
- If you submit documents for verification: whatever we ask for to verify that particular entry. What we ask for depends on what is being verified, and it changes — it commonly includes a PAN, a GST certificate, Udyam or MSME registration, a certificate of incorporation, a shop or trade licence, a sector-specific licence or professional registration, proof of address, or something showing you are authorised to act for the business, and it may include documents not listed here. Please send only what we have asked for, and if a document shows something we do not need, you may cover that up before sending it. See §3.5.
- If you post on the Marketplace: the contact details you choose to publish there.
- What you post: reviews, ratings, images and other content.
- If you buy a Featured Placement: your billing name, and your GSTIN if we ask for one and you give it. We are not currently registered for GST and do not collect GSTINs today — see Terms of Use clause 12.3.
- If you contact support: whatever you write to us, and our replies. This includes a support ticket you raise in the app — its subject, what you describe, and the messages exchanged on it afterwards.
- If you register interest with us — asking us to bring Citivo to your city, to list your business, or to partner with us: the message you write, and the name, email address and telephone number you give us on that form, which need not be the ones on your account.
We do not have a password. You sign in with a code sent to your mobile number, so there is no password for us to store or for anyone to steal.
Sign-in is by mobile number only. We do not currently offer sign-in through Google, Facebook, Instagram or any other social account, and we do not collect data from those services.
3.2 What we collect automatically
- Your device. Your app sends us an identifier for your installation with each request, so we can tell one device from another. We record the device model, the app version, when we first and last saw it, and roughly how often it is used.
We start this the first time a device contacts us — before anyone signs in. If you browse Citivo without an account, we still have a device record. It is not attached to a person, because we do not know who you are.
When you sign in, that device record becomes attached to your account — including the part from before you signed in. So the browsing we recorded against the device while you were signed out becomes associated with you at that point. If you never sign in, it stays unattached.
- Your sign-ins: when you signed in, from what device, and the IP address of the session while it is active.
- Your location. When you do something that needs it — searching near you, or letting us detect your city — your app sends us your position, and we keep the most recent one. We do not keep a trail of where you have been: each new position replaces the last. We do not collect your location when you are not using the app.
- Your country, worked out from your IP address. We do this on our own servers using a local database — your IP address is not sent to any outside service for this. We store the country, not your IP.
- What you look at: which cities you browse, when you first and last visited each, how many times, and how you got there — a search, a notification, or a shared link. We use this to decide what to show you.
- What you save: listings you like or add to your favourites.
- What we count, and what we do not. We count how many times a listing, offer, event or advertisement was shown, viewed, shared, or had its contact or directions button tapped. These are totals for that listing in that city. They are not tied to you — we can tell a business that its listing was viewed four thousand times, and we cannot tell it, or ourselves, who those people were.
- What you search for is not stored. We use what you type to run the search, and we do not keep it.
- Notifications: which we sent you and which you have read.
3.3 What we get from others
- Referrals: we give you your own referral code, and if you joined using someone else's, we record which account referred which — their account, yours, the code used, and the dates you signed up and first published something. That is personal data about both of you.
- From our payment processor, after a payment, sent to us by the processor rather than by you:
- the last four digits of a card, its network, issuing bank, and the wallet or bank used;
- for a UPI payment, the UPI ID you paid from — which often contains a name or a mobile number;
- the email address and mobile number you gave the payment processor at checkout. These come to us inside the confirmation message it sends, and they may not be the ones on your Citivo account.
We keep these so we can match a payment to a receipt, issue a refund, and answer a dispute. All of it is treated as identifying you, and §8 covers how long we hold it and what happens when you delete your account.
3.4 What we never collect
- No biometric data — no fingerprints, no face data.
- No health or medical records. We list clinics and hospitals; we do not collect anything about your health.
- No background or historical location.
- No card numbers, no PINs, no passwords, no bank logins. You enter those on our payment processor's screens, and they never reach us (§6.2). We could not charge your card again on our own if we wanted to.
- We do not read your contacts, your messages, or your call history.
3.5 Verification documents — how we treat them
3.5.1 These are the most sensitive things we hold. They come only from people who publish an entry on Citivo — a business or shop, a service provider, an office, a religious place, a public service, a job, an Event, a Marketplace Item or an Influencer Profile — and only where verification is offered for that kind of entry. We never ask for them simply to browse or to have an account.
3.5.2 We use them for one purpose: to check that the business, organiser, seller or person behind an entry is who they say they are.
3.5.3 They are never shown to other users. They are visible only to you and to the specific members of our staff whose job is to review them.
3.5.4 They are encrypted at rest, held in private storage that is not publicly reachable, and accessible only through short-lived links issued to authorised reviewers.
3.5.5 We delete them according to the periods in §8.1, and destroy them when your account is deleted (§8.3) — except where a document must be preserved under a legal hold (§8.9).
4. Why we use it
We use your personal data for these purposes and no others:
| Purpose | What we use |
|---|---|
| Creating your account, signing you in, keeping it secure | Mobile number, device and sign-in data |
| Telling devices apart, detecting abuse, and rate-limiting | Device identifier, device model, country, request counts |
| Showing you businesses, places, events, offers, marketplace items, jobs and influencer profiles, and ordering them for you | The city you chose, the cities you browse, and your location while you are using a feature that needs it |
| Letting anyone create and manage what they publish — a Listing, Event, Offer, Marketplace Item, Catalogue, Advertisement or Influencer Profile | The entry data in §3.1 |
| Checking that the business, organiser, seller or person behind an entry is genuine, and issuing a Verification Badge | Verification documents |
| Taking payment for Featured Placements and issuing invoices | Billing name, order and payment records, and GSTIN if we ever collect one (§3, Terms of Use clause 12.3) |
| Sending you the messages described in §7 | Mobile number, device token, notification settings |
| Choosing what to show you, and measuring how it performed | City, browsing and saved items. Advertisements are chosen by city alone — see §6.7(a) |
| Running the referral and Credits programme | Your referral code, the record of who referred whom, Credit ledger |
| Moderating content, and detecting fraud and abuse | Content, usage and device data |
| Meeting our legal obligations, and dealing with disputes and lawful requests | Whatever the obligation or the dispute requires |
| Understanding how Citivo is used, so we can improve it | Usage data, aggregated wherever we can |
We will not use your personal data for a new purpose without telling you and, where consent is the basis, asking you first.
5. Our legal basis
5.1 Mostly, your consent. We ask for it at several points, and we record it where the record is the basis of something:
(a) when you sign up — you confirm you are 18 or older and agree to the Terms of Use and this policy;
(b) when you publish something — we may show you a statement about what you are publishing and ask you to confirm it before it goes live, for example as a tick box. That step is not what obliges you: what you may publish comes from the Terms of Use you already accepted, and from the act of publishing (Terms of Use clause 9.10, and §5.3 below);
(c) when a business confirms a Consent Request authorising a Listing about it;
(d) when you confirm a paid order; and
(e) when you opt in to WhatsApp messages (§7.5).
5.2 Publishing something is also, in itself, a choice to make it public. When you put a telephone number, an address or an image on an entry, you are asking us to show it to other people — that is the whole purpose of publishing it, and we treat it accordingly.
Contact details on an entry are visible to everyone by default, and that is deliberate — an entry nobody can respond to is not much use to you.
You can hide them from public view in the entry's settings, and you can take the entry down altogether at any time. But hiding is something you choose to do; it is not the starting position. Please publish on that basis: assume anything you put on an entry will be seen, saved and used by people you do not know, and clause 6.5 of the Terms of Use sets out the limits we place on them.
5.3 The obligations do not depend on a particular confirmation being captured. The rules about what you may publish, and what you must be entitled to publish, come from the Terms of Use you accepted when you created your account. They apply to everything you publish, whether or not a particular confirmation screen was shown, completed or recorded — see clause 9.10(g) of the Terms. A confirmation is how we record your agreement at that moment; it is not the source of the obligation.
5.4 Sometimes, other lawful grounds permitted under the Digital Personal Data Protection Act, 2023 — for example where we must process data to comply with a law, to respond to a lawful request from an authority, or to deal with a legal claim.
5.5 You can withdraw your consent at any time — and you do not have to delete your account to do it.
(a) WhatsApp messages — switch them off in your notification settings (§7.5). We stop sending, but you must leave any group you joined yourself; see clause 11.5 of the Terms of Use.
(b) Promotional messages — switch them off in your notification settings (§7.3).
(c) Location — turn off location permission for the app on your device. Anything that needs it, such as searching near you, will stop working.
(d) Contact details on an entry — hide them from public view (§5.2).
(e) Anything you published — take the entry down, at any time, for any reason.
To withdraw completely, delete your account — in the app, or at citivo.in/delete-your-account without signing in, and without contacting us (§8.2). We make it that way round for a reason: the service messages in §7.1 cannot be switched off while you have an account, because they are how the Platform works — a one-time code, a security notice, a message about your own account. Ending those means ending the account.
One thing to know if you delete in order to withdraw. Deletion is not immediate: for 30 days nothing is permanently destroyed, so a deletion made by mistake can be undone. During that window your account and everything you published are restored if you cancel — or simply if you sign in again, which cancels the deletion automatically. So if you deleted your account in order to withdraw your consent, do not sign in again during those 30 days. §8.4 explains this in full.
5.6 Withdrawing is as easy as giving. You consent by receiving a code on your phone and entering it. You withdraw by receiving a code on your phone and entering it. Same act, same effort, and you do not need to be signed in or to ask us.
5.7 If you withdraw consent, we stop the processing that depended on it. Some records survive where the law requires it — §8.5 sets out exactly which, for how long, and why.
7. Messages we send you
7.1 Service messages — you cannot switch these off, because they are how Citivo works: one-time codes, Consent Requests, payment and order confirmations, security alerts, and notices about your account, including notices about deletion.
7.2 Activity messages — you can switch these off: updates about listings you saved, and about your city.
7.3 Promotional messages — you can switch these off, and we only send them if you agreed to receive them: offers, advertisements and new features.
7.4 How to change this: notification settings in the app, per channel. Switching off promotional messages does not affect service messages.
7.5 WhatsApp has its own opt-in requirement in addition to ours. Agreeing to receive WhatsApp messages from us is separate from your other notification settings.
WhatsApp groups and communities. If you have opted in, we may send you an invitation link to a WhatsApp group, community or channel — one we run, or one run by someone else — and we may add you to one directly, using your registered mobile number. Your WhatsApp opt-in is what permits this, and the consent we ask you for says so. You can leave any of them at any time, and you do not have to join or stay in any of them to use Citivo.
What joining one means for your data. A WhatsApp group runs on WhatsApp, not on Citivo. If you join, your mobile number and your WhatsApp profile name and photograph become visible to every other member — including people with no connection to Citivo, who may save them, use them or contact you. We cannot control that and we cannot reverse it. Anything you post in the group is held on WhatsApp and on the devices of its members, outside our systems, and WhatsApp's own privacy policy governs it. Please decide on that basis before you join.
What we post in those groups. We may post updates about Citivo, and we may also post promotional and advertising content — our own, and that of third parties, including businesses that have no listing on Citivo and whose promotion was not bought through the Platform. We may be paid for posting it. Your WhatsApp opt-in covers this. We do not give your contact details to a business because we promoted it to you — but remember that your number is visible to everyone in the group, so an advertiser who is a member of it can see your number like any other member. Terms of Use clause 11.5(e) sets this out in full.
Withdrawing your consent has limits, and we want to be plain about them. You can switch off WhatsApp messages at any time and we will stop sending them. That does not remove you from a group you are already in, and we will not remove you from one — you have to leave it yourself, in WhatsApp. We will not add you to any further group once you have withdrawn, and we will not put you back into one you have left. The same applies if you delete your Citivo account: deleting it does not take you out of a group, and does not remove your number, your profile or your messages from it or from other members' devices. See Terms of Use clause 11.5.
7.6 We limit how much we send. The app enforces a daily cap on push notifications and observes quiet hours.
7.7 SMS: we use it for one-time codes, and nothing else.
The only text messages we send are one-time codes. We use them to sign you in, to verify a contact number added to an entry, and to confirm a request to delete an account — the same code, in each case.
We do not send promotional or marketing SMS, and our system could not. Under India's telecom framework every SMS must match a template registered in advance, and the one template we have registered is the one-time code. There is no free-form SMS.
Our sender ID and that template are registered under the framework operated by the telecom regulator. That is also why a sign-in code still reaches you if you have registered a preference against commercial messages — a one-time code is a transactional message, not a promotional one, and the two are treated differently under that framework.
Promotional messages reach you by push notification or WhatsApp, and only if you have agreed to them (§7.3, §7.5).
8. How long we keep things, and how to delete your account
8.1 How long we keep things
| Data | How long |
|---|---|
| Your account and profile | Until you delete your account (§8.3) |
| In-app notifications | 90 days |
| Sign-in records | 365 days |
| Verification documents — listing closed | 365 days after closure |
| Verification documents — submission rejected | 90 days after rejection |
| Images you delete | Removed from public view at once; destroyed 30 days later |
| Your city and usage history, including what you liked and added to your favourites | While your account is active; erased entirely when you delete it |
| Your device record, including its last known location | While your account exists. Erased when you delete your account. If the device was never signed in, 90 days after its last request |
| Security and audit logs | 180 days |
| Compliance records about verification documents | 365 days, matching how long we keep the document itself |
| The confirmation message from our payment processor | The record of the payment is kept; the message itself, which contains your email address and mobile number, is cleared after 90 days |
| Your UPI ID, card last four digits, network, issuer and bank | Kept with the payment record. Your UPI ID is removed when you delete your account |
| Support tickets you raised | While your account is active. When you delete your account the subject, what you wrote and the messages on the ticket are erased; what remains is a record that a ticket existed and how it was resolved |
| Interest you registered with us — a city, a business, a partnership | While your account is active. When you delete your account the message and the name, email address and telephone number you gave on the form are erased |
| Payment records, invoices and Credit ledger, after deletion | 8 years, unlinked from you (§8.5) |
Security and audit logs are kept for 180 days. Where an entry is relevant to an investigation, a legal claim, or a request from an authority, we keep that entry for as long as that requires and then destroy it (§8.9). When you delete your account, the entries that relate to you stop identifying you — your user identifier and IP address are removed, and what remains is a record that something happened, not a record of who did it.
8.2 How to delete your account
You can delete your Citivo account at any time, in either of two ways:
- In the app — Profile → Delete account.
- On the web, without signing in — https://citivo.in/delete-your-account. Use this if you have already uninstalled the app.
Both require a one-time code sent to the mobile number registered on the account — by SMS, WhatsApp or another channel bound to that number. We verify that code before anything is deleted. This is deliberate: a deletion cannot be started by someone who has picked up your unlocked phone or obtained a stored sign-in, only by someone who can receive a message on your number.
If you no longer have access to your registered number, neither route will work, because both depend on receiving that message. Write to us at support@citivo.in and we will verify who you are another way and delete the account for you.
8.3 What deletion does, and when
Deletion happens in two stages.
Immediately, when you confirm:
- Everything you have published — listings, events, offers, advertisements, marketplace items, catalogue entries and any influencer profile — is taken off public view.
- Every image you have uploaded stops being publicly reachable. The links to them break at once.
- You are signed out on every device, and push notifications to your devices stop.
For the next 30 days, nothing is permanently destroyed. This is a grace period, so that a deletion made by mistake can be undone (§8.4). Your content stays off public view throughout.
After 30 days, permanently and automatically:
- Your name, mobile number, email address, year of birth if you gave us one, and profile photo are erased.
- Your sign-in credentials are destroyed.
- Your uploaded images are permanently destroyed from our storage.
- Any verification documents you uploaded are permanently destroyed from our storage, except where a document is subject to a legal hold (§8.9).
- Your unused Credits are cancelled (§8.7).
This final stage runs automatically. You do not have to do anything further, and you do not have to remain reachable, for your deletion to complete.
8.4 Cancelling a deletion — including a cancellation you did not intend
Signing in again cancels it. During the 30 days, signing in to your Citivo account automatically cancels the deletion and restores everything exactly as it was — your account, and everything you published.
That is the only way to cancel, and there is nothing else to press. Asking us to delete your account signs you out on every device, so there is no Cancel button to return to. Signing back in is the cancellation.
We tell you when this has happened, both in the app and in a notification you can go back and read.
If you have asked us to delete your account and you did not mean to reverse that, do not sign in again. If you do sign in and still want the account deleted, request the deletion again — a new 30-day period starts from the new request.
8.5 What we keep after your account is deleted, and why
Some records survive deletion. Where they do, they no longer identify you — they are attached to a meaningless internal identifier, not to your name or number (§8.6).
| What we keep | For how long | Why |
|---|---|---|
| Payment records, receipts, invoices and Credit-ledger entries | 8 years | Indian tax and company law require financial records to be kept. |
| Records showing that permission or confirmation was given — that a business owner authorised us to publish a Listing, that whoever published any entry confirmed it was accurate and lawful, and that a customer authorised a paid order | 8 years, unlinked from you | These are our evidence if someone later says a listing was published without their permission, or disputes a payment they authorised. |
| The record of who referred whom (§3.3) | 8 years, unlinked from you | The Credit-ledger entries above record credits earned through a referral, and this is the record they refer to. After deletion it connects two internal identifiers, not two people. |
| Audit logs of actions taken on the platform | 180 days | Security, fraud investigation and accountability. Your user identifier and IP address are removed when your account is deleted, so what remains records that something happened, not who did it (§8.6). |
| Reviews you wrote — of a business, event, marketplace item, influencer profile or anything else | Kept, shown as written by a deleted user | See below. |
| Any document subject to a legal hold | Until the hold is lifted | §8.9 |
Reviews you wrote stay visible. The text of a review you left — of a business, an event, a marketplace item, an influencer profile or anything else — remains on that entry's page, but it is no longer shown as yours — the author appears as a deleted user. We keep the text because removing it would silently change that business's rating and mislead everyone who reads it afterwards. If you want a particular review taken down, delete it before you delete your account. You can also ask us afterwards, using the contact details in §16, and we will consider your request — including where the review itself contains information that identifies you.
8.6 What "deletion" means
When your account is deleted we erase your personal data; we do not delete the underlying record. The record remains, attached to a meaningless identifier, because other records we are required to keep — invoices, audit logs, reviews of businesses — refer to it, and removing it outright would corrupt them.
We keep no way of linking that record back to you. We do not retain your mobile number, or a copy, code or hash of it, or any other key that would let us or anyone else reconnect the remaining record to you.
One practical consequence: your mobile number becomes free to register again. If you or anyone else later signs up with that number, the result is a completely new account that shares nothing with the old one — no content, no Credits, no history.
8.7 What you give up when you delete
- Any unused Credits are cancelled. They are not refunded and cannot be exchanged for money.
- Any Featured Placement still running stops, and the unused part is not refunded.
- What you saved goes with it — your favourites, the entries you liked, and the cities you follow.
- Your support tickets, and any interest you registered with us, stop being readable as yours. The record that you contacted us survives; what you wrote does not (§8.1).
We show you the Credits and the placement before you confirm, in the app and on the web page.
8.8 Records of actions taken by our staff
This paragraph applies only to people who hold an administrative role on the Citivo platform — our own staff. It does not apply to ordinary users of the app.
An administrative role also carries a second factor. Someone holding one signs in with an authenticator app as well as the one-time code, and we hold the credential for that — encrypted — for as long as the role lasts. It is destroyed, along with the backup codes that go with it, when the account is deleted.
An account that holds an active administrative role cannot be deleted by the person holding it; the role must first be removed by another administrator. And where a member of staff has taken an action on the platform — approving a listing, accepting a verification document — the record of who took that action is kept after their account is deleted. We have to be able to say which member of staff made a decision. This is a record of who acted on behalf of the company, and we keep it for that reason.
8.9 Legal hold
Where a document or record must be preserved because of litigation, a regulatory demand, or another legal obligation, we keep it until that obligation ends, even if your account has been deleted. Everything else about your deletion proceeds normally.
8.10 The public deletion page does not reveal whether an account exists
Anyone can enter any mobile number on our public deletion page. The page responds in the same way whether or not that number has a Citivo account, and a code is only actually sent if an account exists. We never confirm or deny that a particular number is registered with us — so the page cannot be used to check whether someone has a Citivo account.
9. Citivo is for adults
9.1 You must be 18 or older to use Citivo. When you sign up, the only age question we ask is a confirmation that you are 18 or older — it is part of the same tick box as agreeing to our Terms of Use and this policy. We do not ask for your date of birth, and we do not ask for proof of age.
If you later choose to add a year of birth to your profile, we keep that instead. You do not have to.
We rely on what you tell us. We have no practical way to verify anyone's age, and clause 2.2 of the Terms of Use says so plainly.
9.2 We do not knowingly collect personal data from anyone under 18, we do not profile them, and we do not direct advertising at them.
9.3 If we learn that an account belongs to someone under 18, we will suspend it and delete the personal data we hold, unless the law requires us to keep something.
9.4 If you are a parent or guardian and believe your child has an account, write to us at support@citivo.in and we will act.
10. Your rights
Under the Digital Personal Data Protection Act, 2023 you have the following rights.
10.1 To know what we hold. You can ask us for a summary of the personal data we process about you and what we do with it.
10.2 To correct it. You can ask us to correct anything inaccurate, complete anything incomplete, or update anything out of date. Most of this you can do yourself in the app.
10.3 To erase it. You can delete your account yourself, at any time, without asking us — §8.2. Some records survive, and §8.5 tells you exactly which and why.
10.4 To withdraw consent — §5.5.
10.5 To nominate someone. You can nominate another person to exercise these rights on your behalf if you die or become unable to exercise them yourself.
How to nominate, for now. Write to us at support@citivo.in from the email or mobile number registered on your account, telling us who you nominate and how to reach them. We will record it against your account and confirm it to you. We are building a way to do this in the app; until then, writing to us is the route.
What a nominee can do. Exercise the rights in this §10 on your behalf — ask what we hold, ask us to correct it, and ask us to delete the account. A nomination is also what we will follow where a Citivo Listing has to be dealt with after a death (Terms of Use clause 9.14(e)).
Changing or cancelling it. Write to us the same way. A nomination has no effect while you are able to act for yourself.
10.6 To complain — §12.
10.7 How to exercise these rights. Write to us at support@citivo.in. Tell us the mobile number registered on your account, and which right you are exercising.
We will then verify it is you, by sending a one-time code to that number and asking you to confirm it — the same check we use to sign you in, and the same one that protects account deletion (§8.2). We cannot act on a request until that is done. An email on its own does not tell us who sent it, and acting on it would make a privacy request a way to attack someone else's account (§10.8).
We will respond within 30 days of verifying who you are. Usually it will be much sooner — most requests take minutes to deal with — but 30 days is the outside limit we hold ourselves to. If a request is complicated and we need longer, we will tell you before the 30 days are up, explain why, and give you a new date.
If you cannot receive a code on that number — you have changed it, or lost access — write to us anyway and say so. There is another way to confirm who you are, set out in §8.2.
If you have no account with us at all — because you were listed by someone else, or appear in something another user published (§2.3) — you can still write to us, and the same 30 days apply once we have established who you are. You do not need an account to ask.
10.8 We will check who you are first. Before we act on a request about an account, we verify that it comes from the person who holds it. This protects you: without it, a privacy request would be a way to take over or destroy someone else's account.
11. How we protect your data
11.1 We use encryption in transit, and encryption at rest for verification documents and other sensitive material.
11.2 There is no password on your account, so there is no password to be leaked or reused. Sign-in is by a one-time code, and destructive actions need a fresh one. An account holding an administrative role carries a second factor in addition (§8.8).
11.3 Access by our staff is limited by role, given only where the job requires it, and recorded.
11.4 Uploaded files. We limit what can be uploaded by file type and by size. Verification documents are held in private storage that is not publicly reachable, released only through short-lived links (§3.5.4), and some content is held for review before it appears — clause 5.5 of the Terms of Use sets out which. We do not currently scan uploaded files for malware. We are building that, and we will say so here once it is running rather than claim it beforehand.
11.5 If there is a personal data breach, we will notify the Data Protection Board of India and affected users as the law requires, and tell you what happened, what it affects, and what you should do.
11.6 Security logs, and reporting an incident.
We keep logs of system and security events, and we keep them in India. How long depends on the log — §8.1 sets out each period, and the shortest is 180 days, which is what the law requires of an intermediary.
We report cyber-security incidents to CERT-In, the Indian Computer Emergency Response Team, where we are required to and within the time the law specifies. That obligation applies whether or not anyone complains, and it is not something you have to ask us for.
A security log can outlive your account. Where a log entry exists about activity on your account, it is not deleted when your account is — but your user identifier and IP address are removed from it, so what remains records that something happened rather than who did it (§8.5, §8.6). That is the one exception to "everything is erased" in §8.3, and we state it here rather than leave it implicit.
11.7 No system is completely secure. We do what is reasonable, but we cannot guarantee absolute security, and we do not treat an attack on our systems as an excuse for failing to protect your data.
11.8 Your part. Keep control of your registered mobile number and of the device that receives codes. Anyone who can receive your codes can reach your account.
12. Complaints
12.1 If you are unhappy with how we have handled your personal data, contact our Grievance Officer:
Name: Aditi Sagar Sontakke
Designation: Chief Executive Officer
Address: Flat No. 312, NCN Srivari Apartments, Hadosiddapura of Sarjapur, Carmelram, Bangalore South, Bengaluru – 560035, Karnataka, India
Email: support@citivo.in
Any other contact details for our Grievance Officer — including a telephone number, where we publish one — are at https://www.citivo.in/contact. We record and act on complaints from what reaches us in writing, so please put yours in writing even if you have spoken to us: a call on its own leaves no record of what was said or when, and writing is what starts the timelines in §12.2.
12.2 We will acknowledge your complaint within 24 hours, with a reference number and an expected resolution date, and resolve it within 15 days. If we need longer, we will tell you why and give you a new date.
12.3 If you are not satisfied with our decision, you can appeal to the Grievance Appellate Committee established under the Information Technology (Intermediary Guidelines) Rules, 2021, within 30 days of receiving it. See Terms of Use §14.7.
12.4 On personal data specifically, you may also complain to the Data Protection Board of India.
12.5 We will never ask you for your one-time code, and we will never ask you to install a remote-access app or make a payment to protect your account. If someone contacts you claiming to be from Citivo and asks for any of those, it is not us — see Terms of Use §3.5.
14. Other people's services
14.1 Citivo links to services we do not control — business websites, mapping services, social media pages, our payment processor's pages, and any WhatsApp group or community we invite you to join (§7.5).
14.2 We are not responsible for what they do with your data. Read their privacy policies before giving them anything.
15. Changes to this policy
15.1 If we change this policy, we will update the version and effective date above and publish the new version.
15.2 For minor changes, we will notify you in the app, or by another channel we use to reach you (§7).
15.3 For material changes — a new purpose, a new category of recipient, a longer retention period — we will tell you and ask you to accept the change before we rely on it, rather than treating your continued use as agreement.
16. Contact us
Velynt Technologies Private Limited
Flat No. 312, NCN Srivari Apartments, Hadosiddapura of Sarjapur, Carmelram, Bangalore South, Bengaluru – 560035, Karnataka, India
CIN: U58200KA2026PTC216918
Privacy queries: support@citivo.in
Grievance Officer: §12
General support: support@citivo.in
Changelog
| Version | Date | Change |
|---|---|---|
| 1.1 | 21 September 2026 | First version in force. Numbered 1.1 so that the Terms of Use, this policy and the Refund and Cancellation Policy always share one version number. |