Privacy Policy

How We Handle Your Data

Clearflow Digital Private Limited ("Clearflow", "we", "us", or "our") is committed to protecting your privacy. This policy describes our practices regarding the collection, use, and protection of personal data across our corporate websites, backend services, and native applications - including Spendly.

Effective: July 8, 2026 DPDP Act 2023 Compliant
1. Corporate Scope 2. Data Processing Principles 3. Data We Collect 3.4. Advertising Data 4. Legal Grounds 5. Why We Process 6. Storage & Retention 7. Third Parties 8. Your Rights 9. Grievance Redressal 10. Children's Privacy 11. Policy Updates

1. Introduction and Corporate Scope

Clearflow Digital Private Limited ("Clearflow", "we", "us", or "our"), incorporated under the laws of India, operates various technology products and services, including the flagship application Spendly.

We are committed to processing your digitised personal data in accordance with the Digital Personal Data Protection (DPDP) Act 2023 of India and other applicable global standards for transparency and security.

2. Data Processing Principles

Clearflow adheres to the following principles for all data processing activities:

  • Lawfulness and Fairness: Data is only processed for legitimate purposes defined at the time of collection.
  • Transparency: We maintain clear channels for users to understand how their data is being handled.
  • Data Minimization: Our products, particularly Spendly, are designed with a "minimal server-side footprint" philosophy.
  • Purpose Limitation: Data collected for one product (e.g., support) is not misused for unrelated corporate purposes.
  • Integrity: We use robust technical measures to prevent unauthorized access or loss.

3. Categories of Personal Data Collected

3.1. Contact and Inquiry Information

We collect your name, email address, and any professional details you provide when using our corporate contact forms or seeking support for our products.

3.2. Spend Signal Data Handling - Transactional UPI Messages Only

Spendly is an automated expense tracker designed to help users manage their finances without manual entry. The core feature of the app is the real-time detection and categorisation of financial transactions (UPI, Bank Debits, Credit Cards) via SMS alerts. Without the READ_SMS and RECEIVE_SMS permissions, the app's primary purpose — providing automated spending insights — would be impossible to achieve.

Spendly operates by reading UPI transaction confirmations sent to your device by your bank or payment processor. The app requests the Android READ_SMS and RECEIVE_SMS permissions solely to identify and parse inbound UPI payment confirmation messages and bank debit/credit alerts.

Spendly only reads messages that match transactional patterns. Messages containing standard bank notification keywords ("debited", "credited", "UPI", "IMPS", "NEFT") from bank spend signal sender IDs. It never reads:

  • Personal conversations or chat messages
  • OTPs (one-time passwords) of any kind
  • Non-financial messages, promotional messages, or spam
  • Messages from unknown or non-bank senders

Privacy Assurance: Raw SMS text is processed locally on your device and never uploaded to our servers — it is never synced to the cloud. Only the extracted transaction metadata (amount, date, merchant category) is synced to provide cloud backup when you explicitly opt in. We do not share this data with any third-party advertisers.

On-device processing: All spend signal parsing and transaction categorisation happens locally on your device. Raw spend signal text is never transmitted to our servers. Only structured, anonymised metadata — transaction amount, inferred merchant category, date, and UPI app used — is optionally backed up to our secure Firebase / Firestore cloud infrastructure, and only when you have explicitly opted in to Cloud Backup.

No raw spend signal content is ever stored on Clearflow Digital's servers. You may revoke the SMS and Notification Listener permissions at any time through your device settings.

3.3. Usage and Technical Intelligence

To secure our backend infrastructure, we collect technical metadata, including hashed IP addresses, device identifiers, and operational logs. This data is used to prevent DDoS attacks, fraud, and service interruptions.

3.4. Advertising Data (Google AdMob)

We use Google AdMob to serve ads. Google may use the Advertising ID from your device to serve personalised ads. AdMob may automatically collect the following information to deliver and measure ads:

  • Device Identifier (Advertising ID): A resettable, user-controlled identifier provided by your device's operating system, used for frequency capping, attribution, and serving relevant ads.
  • IP Address: Used for approximate location determination to serve geographically relevant advertising and for performance analytics.

This data is processed by Google AdMob under their own privacy policy. It is used for personalised advertising (where you have consented) and ad performance analytics. You may reset your Advertising ID or opt out of personalised advertising at any time through your device settings. You can learn more about how Google uses data here: https://policies.google.com/technologies/ads.

4. Legal Grounds for Processing

In alignment with the DPDP Act 2023, Clearflow processes data based on:

  • Specified Consent: Explicit permission granted by users for product features.
  • Legitimate Interests: Necessary processing for system security and operational integrity.
  • Legal Obligations: Compliance with statutory requirements in India.

5. Why We Process Your Data

  • Service Delivery: To operate our software-as-a-service platforms and provide user-requested insights.
  • Research and Development: To improve our proprietary algorithms and user interface designs.
  • Security and Fraud Prevention: Protecting our infrastructure and users from cyber threats.
  • Customer Relations: Responding to support tickets and business inquiries.

6. Data Storage, Retention, and Deletion

Your data is stored securely in encrypted cloud environments provided by Google Cloud Platform (Cloud Firestore, Firebase Authentication). We retain your information only as long as necessary to fulfill the purposes for which it was collected.

Account Deletion: You may delete your account and all associated data at any time through your account settings page. Deletion is immediate and irreversible. Backup data is purged within 30 days.

Data Portability: You may request a machine-readable export of your processed data (spend patterns, categories, and metadata) by contacting us. We will fulfil export requests within 14 calendar days of identity verification.

7. Third-Party Partners and Transfers

Clearflow does not sell user data. We engage third-party processors only for essential operations:

  • Infrastructure: Firebase (Google LLC).
  • Payments: Google Play Billing for Spendly in-app subscriptions.
  • AI Services: Google Gemini API for customer support chatbot.
  • Advertising: Google AdMob for serving and measuring in-app advertisements.

8. Your Rights Under DPDP Act 2023

As a Data Principal under Indian law, you have the right to:

  • Access a summary of your personal data being processed.
  • Correct or update inaccurate or incomplete data.
  • Withdraw consent for future processing.
  • Request erasure of your personal data.
  • Nominate a person to exercise your rights in the event of death or incapacity.
  • Lodge a grievance with our designated officer.
To exercise any of these rights, please contact our Grievance Officer. We will respond within 14 business days of identity verification.

9. Grievance Redressal

In compliance with Section 10 of the DPDP Act, we have designated a Grievance Officer to address your concerns:

Grievance Officer: Samar Pratap Singh Sisodia
Entity: Clearflow Digital Private Limited
Email: support@clearflowdigital.in

10. Children's Privacy

Our products are not directed at children under 18. In compliance with the DPDP Act 2023, we do not knowingly collect or process personal data of children without verifiable parental consent. If we become aware that data from a child has been collected without such consent, we will delete it promptly. Guardians may contact our Grievance Officer to report any concerns.

11. Updates to this Policy

We may modify this Policy as our services evolve. The "Effective" date at the top indicates the latest version. We encourage you to review this page periodically. Material changes will be communicated via email or through our services.

Cookie preferences

We use cookies for essential site features and optional analytics.