Privacy Policy
Last updated: March 30, 2026
This Privacy Policy explains how KVA Labs (“Company”, “we”, “us”) collects, uses, stores, and protects your information when you use the TimeIt360 platform (“Service”). This policy is published in compliance with the Information Technology Act, 2000, the IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and the Digital Personal Data Protection Act, 2023 (“DPDPA”).
By using the Service, you consent to the collection and use of your information as described in this policy.
1. Information We Collect
Account Information
- Name and email address of the school administrator
- School name, address, and contact details
- Phone number (optional, for payment prefill)
- Password (stored in hashed form, never in plain text)
School Operational Data
- Teacher names and availability schedules
- Subject names and configurations
- Grade and section information
- Bell schedule timings and working days
- Timetable configurations and generated timetables
Important: We do not collect individual student names, student personal data, student academic records, or any other student-identifiable information. The Service only processes grade and section labels (e.g., “Grade 7A”) for timetable generation.
Payment Information
- Transaction records (amount, date, plan type, payment status)
- Razorpay payment IDs and order IDs
We do not store credit card numbers, bank account details, or UPI IDs. All payment processing is handled by Razorpay, which is PCI-DSS compliant. Please refer to Razorpay's Privacy Policy for how they handle payment data.
Automatically Collected Information
- Browser type and version
- IP address
- Pages visited and features used within the Service
- Error logs for debugging and improving the Service
2. How We Use Your Information
We use your information to:
- Provide the Service: Generate timetables, manage school data, process payments, and deliver core functionality
- Communicate with you: Send account notifications, payment receipts, subscription reminders, and support responses
- Improve the Service: Analyze usage patterns (in aggregate) to improve features, fix bugs, and enhance performance
- AI Features: Process anonymized operational queries through our AI chat assistant to help you manage your timetable
- Legal compliance: Meet our obligations under applicable Indian law, including tax regulations
We do not use your data for advertising, profiling, or selling to third parties.
3. Data Sharing
We share your data only with the following parties, and only to the extent necessary:
| Third Party | Purpose | Data Shared |
|---|---|---|
| Supabase | Database hosting and authentication | All account and school data (encrypted at rest) |
| Razorpay | Payment processing | School name, email, phone, payment amount |
| Google (Gemini AI) | AI chat assistant | Anonymized timetable queries (no personal data) |
| Vercel | Application hosting | Server logs, IP addresses |
| Sentry | Error monitoring | Error logs, stack traces (no personal data) |
We do not sell, rent, or trade your personal information to any third party.
4. Data Storage and Security
- Location: Your data is stored on Supabase cloud servers in the Asia Pacific (Mumbai, ap-south-1) region.
- Encryption: All data is encrypted in transit (TLS 1.2+) and at rest (AES-256).
- Access control: We use Row Level Security (RLS) policies to ensure complete data isolation between schools. No school can access another school's data.
- Authentication: We use JWT-based authentication with secure, httpOnly cookies.
- Backups: Automatic daily backups are maintained by our database provider.
5. Cookies
We use essential cookies only for authentication and session management. We do not use third-party advertising or tracking cookies.
| Cookie | Purpose | Duration |
|---|---|---|
sb-* | Supabase authentication (JWT tokens) | Session / 7 days |
6. Your Rights (under DPDPA 2023)
As a data principal, you have the right to:
- Access: Request a summary of your personal data we hold
- Correction: Request correction of inaccurate or incomplete data
- Erasure: Request deletion of your personal data (subject to legal retention requirements)
- Grievance redressal: File a complaint with our Grievance Officer
- Withdraw consent: Withdraw your consent for data processing at any time (this may affect your ability to use the Service)
To exercise any of these rights, contact us at support@kvalabs.com. We will respond within 48 hours and fulfill your request within 30 days.
7. Data Retention
- Active accounts: Data is retained for the duration of your subscription.
- After cancellation: Data is retained for 30 days to allow for reactivation or export, then permanently deleted.
- Payment records: Transaction records are retained for 8 years as required by Indian tax law (Income Tax Act, GST Act).
- Server logs: Automatically deleted after 30 days.
8. Children's Data
TimeIt360 is designed for use by school administrators and teachers, not by children. We do not knowingly collect personal data from children under 18. The Service processes only grade/section labels and teacher/subject information — not individual student data.
If you believe we have inadvertently collected data from a minor, please contact us immediately and we will delete it.
9. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes via email or through the Service at least 15 days before the changes take effect. Your continued use of the Service after the updated policy takes effect constitutes acceptance.
10. Grievance Officer
In accordance with the Information Technology Act, 2000 and the DPDPA 2023, the Grievance Officer for the purpose of this Privacy Policy is:
Name: Vishal Amler
Email: support@kvalabs.com
Response time: Acknowledgment within 48 hours, resolution within 30 days.
11. Contact
If you have any questions about this Privacy Policy or how we handle your data, please contact us at support@kvalabs.com.