← Back to Kunji

Privacy Policy

What we collect, why we hold it, who else can see it, and how to get it back or deleted.

Effective 17 August 2026 · Kunji Technologies Private Limited

1. Two kinds of data, two different roles

This distinction decides everything else in this policy, so it comes first.

Your data. Your name, email, phone number and billing details. You gave them to us directly, and for these we are the data fiduciary: we decide why they are held, and this policy governs them.

Your clients’ data. The buyers, sellers and tenants you record as leads. You collected these and you decide what happens to them. For this data you are the data fiduciary and we are only a data processor: we store and process it on your instructions and for no purpose of our own.

A practical consequence: if a buyer in your CRM asks to be deleted, that request is for you to action, not us. You can delete the lead yourself at any moment. We will help if you ask, but we will not act on a stranger’s instruction to change your records.

2. What we collect

From you, when you sign up

  • Name, email address, phone number, username and a hashed password.
  • Your firm’s name, type and city.
  • Billing details. Card numbers are handled entirely by Razorpay and never reach our servers; we keep only a payment reference and the last four digits.

What you put in

  • Leads, properties, follow-ups, notes, tags and uploaded photos or video.

Automatically, from using the service

  • Sign-in timestamps, IP address and browser user agent, used for security.
  • Server logs of requests. These are for diagnosing faults and abuse, and are not used to build a profile of you.
  • A label for each browser you mark as trusted (for example “Chrome on Windows”), so you can recognise and revoke it.

We do not use advertising or analytics trackers in the application, and we set no third-party cookies. The only browser storage we use keeps you signed in and remembers a device you chose to trust.

3. Why we hold it

  • To run the service you asked us for. This is contractual necessity.
  • To keep accounts secure: sign-in codes, suspicious activity, abuse.
  • To take payment and meet tax and accounting obligations.
  • To support you when you report a problem, including the time-limited support sessions described below.

We do not sell personal data. We do not share it with advertisers. We do not use your records, or your clients’ records, to train machine learning models.

4. When our staff can see your data

Being straightforward about this matters more than sounding reassuring. Our staff can open a support session that signs in as your administrator, to reproduce a problem you have reported. The controls on it are real and enforced by the software, not by policy alone:

  • Every session is written to an audit log that no one can edit or delete.
  • It expires after 30 minutes and cannot extend itself.
  • It cannot change a password, alter billing, or delete an agent.
  • A banner is displayed in your application for the whole session, so you can always see that one is open.

Separately, a small number of engineers can access production infrastructure for maintenance and incident response.

5. Who else processes it

We use these sub-processors. Each is bound by contract to protect the data and use it only to provide their service to us.

WhoWhat forWhere
Amazon Web Services (AWS)Servers and file storageMumbai, India (ap-south-1)
MongoDB AtlasThe databaseIndia
RazorpayPayments and subscription mandatesIndia
Google (Gmail SMTP)Transactional email: sign-in codes, verification, receiptsGlobal

We may also disclose data where we are legally required to, for example under a valid order from an Indian court or authority. Where we are permitted to tell you, we will.

6. Where it is stored

Your records and uploaded files are stored in India. Email delivery is handled by a global provider, so the contents of transactional emails, such as a sign-in code, may be processed outside India.

7. How it is protected

  • All traffic is encrypted in transit with TLS.
  • Passwords are stored as bcrypt hashes and are never recoverable, by anyone, including us.
  • Administrator sign-in requires a second factor sent by email. Device trust tokens are stored only as hashes.
  • Each organisation’s records are isolated at the database query level, not merely hidden in the interface.
  • Shared listing links are unguessable, can expire, and never expose an owner’s contact details.
  • Uploaded files are served from private storage through time-limited links.

No system is perfectly secure. If a breach affects your data we will notify you and the relevant authority as required by law, without undue delay.

8. How long we keep it

  • While your account is open, until you delete the record.
  • After cancellation, 30 days, then deletion. Export first if you want a copy.
  • Invoices and tax records for as long as Indian tax law requires.
  • Security and audit logs for up to 12 months.

9. Your rights

Under the Digital Personal Data Protection Act, 2023, you may:

  • Ask what personal data of yours we hold and why.
  • Have inaccurate data corrected. Most of it you can edit yourself in Profile.
  • Ask for your data to be deleted, subject to records we must keep by law.
  • Nominate someone to exercise these rights if you die or become incapacitated.
  • Complain, first to us and then to the Data Protection Board of India.

Write to privacy@kunji.io. We respond within 30 days.

10. Children

Kunji is a tool for businesses and is not directed at anyone under 18. We do not knowingly create accounts for children.

11. Grievance officer

As required by the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021:

[Full name]
Kunji Technologies Private Limited
[Registered office address, with PIN code]
grievance@kunji.io
Monday to Friday, 10am to 7pm IST

12. Changes

If we change this policy in a way that materially affects you, we will email account administrators before it takes effect. The effective date at the top of this page always reflects the current version.

Questions about this page? Write to support@kunji.io.