T
Trovro

Privacy Policy

Effective: 14 July 2026  ·  Last updated: 14 July 2026

The short version

This summary is for convenience only. The full Policy below is what legally applies.

1. Who we are

1.1 Trovro (“Trovro”, “we”, “us”, “our”) is a local-services marketplace mobile application operated by Om Kumbhar, sole proprietor trading as “Trovro”, having its place of business at Mumbai, India.

1.2 For the purposes of the Digital Personal Data Protection Act, 2023 (“DPDP Act”), Trovro is the Data Fiduciary in respect of the personal data described in this Policy, and you are the Data Principal.

1.3 This Policy is published in accordance with the DPDP Act, the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021.

2. Scope and consent

2.1 This Policy applies to the Trovro mobile application and any related services (together, the “Platform”).

2.2 By creating an account, you confirm that you have read this Policy and that you consent to the collection and processing of your personal data as described here. Where we rely on your consent, that consent is free, specific, informed, unconditional and unambiguous, and you may withdraw it at any time (see Clause 12).

2.3 If you do not agree with this Policy, please do not use the Platform.

3. Definitions

  • “Customer” — a user who searches for and books services.
  • “Provider” — an independent service professional (electrician, plumber, cleaner, tutor and similar) who offers services through the Platform.
  • “Personal Data” — any data about an individual who is identifiable by or in relation to such data.
  • “Processing” — any operation performed on Personal Data, including collection, storage, use, sharing, disclosure and erasure.

4. Information we collect

4.1 Information you give us

DataWhen we collect it
Full name, email address, mobile number, passwordWhen you create an account
Profile photoIf you choose to upload one
Service address — area, flat/house number, floor, landmarkWhen you add an address (Customers)
Service categories, service areas, headline, bio, years of experience, expected pricesWhen you build your profile (Providers)
Payout details — UPI ID, UPI QR image, or “cash on delivery” preferenceWhen you set up payouts (Providers)
Identity documentsWhen you apply for verification (Providers) — see Clause 5
Booking details, offered price, chosen time slotWhen you send or accept a booking
Chat messages between Customer and ProviderWhen you use in-app messaging
Ratings and written reviewsWhen you rate a completed job
Support requestsWhen you contact us through the app

4.2 Information collected automatically

  • Approximate or precise location — only if you grant location permission, and only to show you nearby Providers or set your service area. You may decline and enter your address manually instead.
  • Device and technical data — device model, operating system version, app version, crash logs and diagnostic data, collected through Google Firebase.

4.3 Information from third parties

If you sign in with Google, we receive your name, email address and profile picture from Google. We do not receive your Google password.

5. Identity documents (sensitive personal data)

5.1 Providers who apply for the “Verified” badge are asked to upload images of a government-issued identity document. This is Sensitive Personal Data or Information under the SPDI Rules, 2011 and is treated with additional care.

5.2 These images are used solely to confirm that a Provider is a real, identifiable person. They are:

  • reviewed manually by our authorised verification team;
  • never shown to Customers or to any other user;
  • never used for any purpose other than verification;
  • permanently deleted as soon as a verification decision (approved or rejected) is made.
Aadhaar notice. We do not store, display or publish your Aadhaar number, and we do not perform Aadhaar authentication or e-KYC with UIDAI. You are advised to submit a masked Aadhaar (in which only the last four digits are visible) or an alternative identity document. Do not share your Aadhaar number, OTP or password with anyone claiming to represent Trovro — we will never ask for them.

5.3 Uploading an identity document is optional. You may use Trovro as a Provider without verification; you simply will not receive the “Verified” badge.

6. How and why we use your data

PurposeData used
Create and secure your account; verify your email and mobile number by link and SMS OTPName, email, phone, password
Match Customers with Providers by service category and areaLocation, address, service areas, categories
Display public profiles so users can choose whom to work withName, photo, headline, bio, ratings, jobs completed, verification status, prices
Enable bookings, acceptance, completion and ratingBooking details, offered price, address, ratings
Enable direct communication between the two partiesChat messages, phone number
Build trust and reduce fraud (verification badge, ratings)Identity documents, ratings, job history
Respond to your support requests and grievancesSupport messages, account details
Keep the Platform working, fix crashes and improve itDevice and diagnostic data
Comply with law and enforce our TermsAny of the above, as strictly required

6.1 We process your data on the basis of your consent, and for the legitimate uses permitted under the DPDP Act (including compliance with law and responding to your requests).

7. When we share your data

We share your data only in the following situations.

7.1 With the other party to a booking. This is the core function of a marketplace. When you book a Provider, or a Customer books you:

  • The Provider sees the Customer’s name, profile photo, service address, chosen time and offered price.
  • The Customer sees the Provider’s name, photo, headline, bio, service categories and areas, prices, ratings, reviews, number of jobs completed and verification status.
  • Both parties can see the messages they exchange.

7.2 Publicly on the Platform. A Provider’s profile (name, photo, headline, bio, categories, areas, prices, ratings, reviews, jobs completed, verification status) is visible to Customers browsing the app. Reviews you write are visible to other users along with your first name and photo. Do not include private information in a review.

7.3 With service providers who process data on our behalf. We use Google Firebase and Google Cloud Platform (Google LLC and its affiliates) for authentication, database, hosting, SMS OTP delivery and crash reporting. They process data strictly on our instructions.

7.4 For legal reasons. We may disclose data where required by law, court order, or a lawful request from a government or law-enforcement authority, or where necessary to protect the rights, safety or property of Trovro, our users or the public.

7.5 On a business transfer. If Trovro is merged, acquired or its assets are sold, your data may be transferred to the successor entity, which will remain bound by this Policy.

8. What we never do

  • We do not sell your personal data. Ever, to anyone.
  • We do not rent, trade or share your data with data brokers or advertisers.
  • We do not show third-party advertising inside the app.
  • We do not handle, collect, hold or route your money. Payments are made directly by the Customer to the Provider. We charge 0% commission and take no cut.
  • We do not store your card, bank account or UPI PIN details. A Provider’s UPI ID or QR image is stored only so Customers can pay them directly.
  • We do not ask for your password, OTP, or Aadhaar number by phone, email or message.

9. Where your data is stored and transferred

9.1 Your data is stored on Google Firebase / Google Cloud infrastructure. Google operates data centres in multiple countries, and your data may therefore be stored or processed on servers located outside India.

9.2 By using the Platform you consent to such transfer. We transfer data only to countries not restricted by the Central Government under Section 16 of the DPDP Act, and we require our processors to apply appropriate safeguards.

10. Security

10.1 We implement reasonable security practices and procedures as required by Section 43A of the IT Act, 2000 and the SPDI Rules, 2011, including:

  • encryption of data in transit (HTTPS/TLS);
  • authentication managed by Google Firebase Authentication — we never see or store your password in plain text;
  • mandatory email and mobile (SMS OTP) verification for every account;
  • server-side access rules restricting each user to their own data;
  • identity documents accessible only to authorised reviewers, and deleted immediately after review.

10.2 No system is perfectly secure. You are responsible for keeping your password confidential and for all activity on your account. Tell us immediately at trovro01@gmail.com if you suspect unauthorised access.

10.3 In the event of a personal data breach, we will notify the Data Protection Board of India and affected users as required by the DPDP Act.

11. How long we keep your data

DataRetention period
Account and profile dataUntil you delete your account
Identity documentsDeleted immediately once verification is approved or rejected
Booking records, ratings and reviewsRetained after account deletion in a de-identified form, because they form part of the other party’s transaction history and public reputation
Chat messagesRetained for the other party in the conversation
Data we must keep by lawFor the period required by applicable law

We erase personal data once the purpose for which it was collected is no longer being served, in accordance with Section 8(7) of the DPDP Act.

12. Your rights

Under the DPDP Act, you have the right to:

  • Access — obtain a summary of the personal data we hold about you and how we process it.
  • Correction and completion — correct inaccurate or misleading data, and complete incomplete data. Most fields can be edited directly in the app.
  • Erasure — have your personal data deleted (see Clause 13).
  • Withdraw consent — at any time, as easily as you gave it. Withdrawal does not affect processing carried out before withdrawal, and may mean you can no longer use the Platform.
  • Grievance redressal — complain to us first (Clause 17), and escalate to the Data Protection Board of India if unsatisfied.
  • Nominate — nominate another individual to exercise your rights in the event of your death or incapacity.

To exercise any right, email trovro01@gmail.com. We will respond within a reasonable period and in any case within the timelines set out in Clause 17.

Your duties. The DPDP Act requires you not to impersonate another person, not to suppress material information, and not to file false or frivolous grievances.

13. Deleting your account

13.1 You may delete your account at any time, directly in the app: Settings → Delete account. You will be asked to confirm.

13.2 Deletion permanently removes your profile, login credentials and personal data from the Platform. It cannot be undone.

13.3 As explained in Clause 11, bookings, ratings and messages that form part of another user’s history are retained, but are dissociated from your identity where feasible.

13.4 If you cannot access the app, email trovro01@gmail.com from your registered email address and we will delete your account for you.

14. App permissions we request

PermissionWhyOptional?
LocationTo detect your area and show nearby ProvidersYes — you may enter your address manually instead
Photos / mediaTo upload a profile photo, payout QR code or identity documentYes — only used when you tap upload
Internet / networkTo connect to our serversRequired
SMS (read, on some devices)To auto-fill the 6-digit OTP during phone verificationYes — you can type the code manually

You can withdraw any permission at any time in your device settings.

15. Children

15.1 Trovro is strictly for persons aged 18 years and above. We do not knowingly collect personal data from children.

15.2 We do not undertake tracking, behavioural monitoring or targeted advertising directed at children, as prohibited by Section 9 of the DPDP Act.

15.3 If we learn that we have collected data from a person under 18, we will delete it promptly. If you believe a minor has provided us data, contact trovro01@gmail.com.

16. Changes to this Policy

We may update this Policy from time to time. The “Last updated” date at the top will change. If the changes are material, we will notify you in the app or by email before they take effect. Continued use of the Platform after the changes take effect means you accept the revised Policy.

17. Grievance Officer

In accordance with the Information Technology Act, 2000, the Intermediary Guidelines, 2021 and the DPDP Act, 2023, the Grievance Officer for Trovro is:

Grievance Officer: Om Kumbhar
Email: trovro01@gmail.com
Address: Mumbai, India
Hours: Monday to Friday, 10:00 – 18:00 IST

We will acknowledge your complaint within 24 hours and resolve it within 15 days of receipt. Please include your registered email address and a clear description of the issue.

If you are not satisfied with our response, you may escalate your complaint to the Data Protection Board of India.

18. Contact us

Questions about this Policy or your data: