TRECASA LEADS · POLICIES
Privacy policy
What we collect, why we use it, and how to raise a question about it.
1. Who is responsible
- Display brand
- Trecasa Leads
- Legal and invoice entity
- Trecasa Infra Pvt Ltd
- Business address
- Trecasa Interiors, SHOP NO C2, H.NO 7-31, Phase 2, Jaya Prakash Narayan Nagar, Miyapur, Hyderabad, Telangana 500049
- Support email
- admin@trecasa.in
- Support phone
- 9059784422 (provisional; final confirmation pending)
- Complaints contact
- Prem Yeligati
Direct complaints contact details — awaiting owner confirmation.
This notice describes the current Trecasa Leads product. The owner supplied the operator and contact details above. Registration verification, retention periods, the formal complaints route and privacy-request response timelines remain pending. Hosting is on Render in Singapore; the account email provider has not been enabled.
2. Information collected
- Homeowner enquiries: name, mobile number, locality, property and possession details, work required, budget range, timeline, optional brief, and contact-sharing consent with its recorded version and time.
- Studio interest forms: studio/contact name, mobile, email, service areas, project preferences, optional portfolio URL and optional future-membership interest. Portfolio links are stored as text and not fetched automatically.
- Accounts and security: name, email, salted password hash, email-verification status, session-token hashes and expiry, verification/reset-token hashes and expiry, and bounded request-throttling records. Passwords and raw verification tokens are not stored in plaintext by the app.
- Marketplace operations: manually recorded verification/consent notes, appointment details and confirmations, lead assignments, order amounts and term snapshots, provider references, refund status, support requests, follow-up notes and audit events.
- Contact requests: the name, reply email, topic, optional reference, message, consent version/time and review status you submit.
- Attribution and abuse prevention: allowlisted campaign tags attached to enquiry links and temporary network-address request counters. No advertising pixels or browsing analytics are installed in this build.
Avoid submitting full home addresses, identity documents, health information, card data, passwords or OTPs in free-text fields.
3. Purposes and contact sharing
We use enquiry information to understand a project and contact the homeowner for qualification. With explicit consent, Trecasa Leads may share the homeowner contact and project details with one purchasing designer. That designer may contact the homeowner by phone or WhatsApp solely about that interior project. This consent does not permit unrelated marketing. This scope applies only where the matching consent was actually recorded; older records do not gain this consent merely because the wording changed. The form’s consent wording remains visible before submission. Public project summaries exclude the dedicated private contact fields; the operator must also keep personal contact details out of the public brief.
Account/security data supports sign-in, verification, recovery and access control. Orders and payment references support allocation, reconciliation and support. A designer’s follow-up notes are restricted to that studio’s purchased connection. Contact messages are used to review and respond to the stated request; support consent is separate from homeowner lead-sharing consent.
4. Who may receive information
The operator can inspect submitted records for manual administration. One purchasing designer receives the homeowner contact and project details only with the required recorded consent and after the eligible payment and assignment are verified. Phone or WhatsApp contact must be solely about that interior project; this is not permission for unrelated marketing. Both leads and appointments are limited to one buyer per underlying opportunity through Trecasa Leads. This does not prevent the homeowner from sharing information independently with another firm.
When configured, the selected email provider receives the recipient address and verification/reset email content. Razorpay receives payment-order data and may receive a studio name/email to prefill checkout. Trecasa Leads does not collect full card credentials or OTPs through its forms, and homeowner contact details are not included in payment-order notes.
Render hosts the application and its SQLite databases on a persistent disk in Singapore. Email delivery and payments are currently disabled. The selected email provider, any additional recipients and applicable vendor/data-transfer arrangements need review before those services are enabled. No international-transfer guarantee is made by this draft.
6. Storage and safeguards
The hosted service stores records in SQLite databases on its Render persistent disk in Singapore. The application is configured to create daily database backups on that same disk and retain the seven most recent completed backup sets. These are not copies on a separate service: off-service backups and a restoration drill have not been configured or verified. A same-disk backup does not protect against loss of that disk. Role checks, CSRF/origin checks, private contact projections, password hashing and hashed expiring tokens restrict application access. These measures are not a guarantee against all access, misuse or loss.
The build does not claim application-managed database encryption at rest, a completed production security audit or a deployed breach-response process. Hosted access permissions, backup monitoring and recovery, vendor terms and incident handling still need operational review before public launch. The backup-set count is an operational setting, not a complete customer-data retention or deletion policy.
7. Retention and deletion
Retention periods, deletion triggers, backup treatment and required transaction-record retention — awaiting owner confirmation.
Technical token/session expiry does not mean all related database records are automatically erased. No general automatic customer-data deletion schedule or self-service export/deletion tool is implemented. Deletion from an active database does not itself remove existing backups. A confirmed retention policy must match the actual operational process and applicable obligations.
8. Your questions, corrections and withdrawal
Use Contact and choose Privacy or consent to request clarification, correction, access, withdrawal or deletion. You can also email admin@trecasa.in for general privacy/support requests. Include enough context to find the record, but do not submit identity documents in the initial message. The operator checks your identity and processes the request.
On processing a confirmed withdrawal, the operator stops future sharing and asks the purchasing designer to stop project contact. Information already seen cannot be retracted. The form records a request for manual review; it does not itself erase a record, change consent or automatically notify a designer. Designer notification requires operator action. Detailed deletion handling and privacy-response timelines still need confirmation. The direct complaints contact route is awaiting owner confirmation; the published support email can be used for general questions. This notice does not restrict rights that apply under law or claim those operational procedures are already complete.
9. Changes and special cases
This service is not designed to collect children’s information; no age-verification or parental-consent mechanism is implemented. Contact the operator through the form if such information has been submitted. The owner must confirm an appropriate eligibility and handling policy before launch.
Changes to the service, vendors or data practices require this notice to be updated with an approved version and effective date. The draft status above should not be interpreted as a completed legal review.