WWorkQuoraLog In
All Legal Documents

Legal

Privacy Policy

Effective Date: [TO BE FILLED] Last Updated: 2026-07-21

This Privacy Policy explains how WorkQuora ("WorkQuora", "we", "us", "our") collects, uses, stores, shares, and protects personal data when you use the WorkQuora mobile applications (client app and worker app), website, and related services (together, the "Platform").

WorkQuora is operated by [Operator Legal Name — TO BE FILLED], having its registered office at [Registered Office Address — TO BE FILLED] ("Operator"). Note: WorkQuora's payment processing (Razorpay) merchant account is, as of this policy's drafting, registered in the name of a sole proprietor, with a transition to the Operator entity above planned. This section will be updated once that transition completes.

This Policy is drafted with reference to the Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 made under it, the Digital Personal Data Protection Act, 2023 ("DPDP Act"), and the Consumer Protection Act, 2019 (to the extent it governs marketplace disclosures). Where the DPDP Act's operative rules and timelines are notified after this Policy's effective date, this Policy will be updated to reflect them.


1. Who this Policy applies to

This Policy applies to anyone who uses the Platform: clients posting jobs, freelance workers ("workers") accepting and completing jobs, and visitors browsing the Platform before registering. Where this Policy refers to "you," it means whichever of these applies to your use of the Platform.

2. What data we collect

We collect only what is described below — we do not collect categories of data beyond what our Platform's actual features require.

2.1 Account and registration data

When you register, we collect your name, email address, mobile number, username, password (stored as an irreversible cryptographic hash — we cannot see your actual password), gender, and date of birth. If you sign in with Google or Facebook, we receive your name, email address, and profile picture from that provider, and store an identifier linking your account to that provider — we do not receive or store your Google/Facebook password.

As you use the Platform, you may add: a profile photo, a short bio and professional title, skills, an hourly rate (workers), and your coarse service location.

2.2 KYC (identity verification) data — workers

Workers must complete identity verification before accepting jobs. This involves submitting:

  • Your PAN number and a photo of your PAN card
  • Your Aadhaar number and a photo of your Aadhaar card
  • A selfie photograph, used to verify you are the person in the submitted documents
  • Your bank account number, IFSC code, account holder name, and bank name, for receiving payouts

Your PAN number, Aadhaar number, and bank account number are encrypted before storage. Document images (PAN card, Aadhaar card, bank proof, selfie) are stored with a specialized file-storage provider, not directly on our application servers, and are only ever retrievable through time-limited, signed links generated on demand — they are not publicly accessible URLs. Rejected or superseded KYC documents are deleted from that storage, not retained indefinitely.

Clients are not currently required to complete this identity verification to post a job, pay for a job, or message a worker. If this changes, this Policy will be updated.

2.3 Location data

We collect two distinct kinds of location data, and it is important that you understand the difference:

  • Your account's "last known location" (a single coarse point, not a history) — updated only when the app requests it, for example to show you nearby jobs or freelancers. This is stored and used for that matching purpose.
  • Live location during an active job — while a worker has an in-progress job, their device may transmit their live GPS position roughly every 10 seconds so the client can see their approach on a map. This live tracking data is relayed in real time and is not stored in our database. It exists only for the moments it takes to reach the client's screen, and is then discarded. We do not retain a historical trail of a worker's movements during or after a job.
  • A job's own posted location (the address/area the job is at) is stored as long as the job listing exists, as you would expect.

2.4 Device and session information

When you log in, we record technical information about that session: device name, browser, operating system, IP address, a coarse country/city derived from your IP address (not GPS-precise), and your browser's user-agent string. You can view and revoke your own active sessions from the app's settings at any time.

2.5 Chat messages

Messages you exchange with another user through the Platform (scoped to a specific job) are stored, including any files, images, or location pins you share in that chat. Chat messages are not end-to-end encrypted — they are stored as ordinary application data, protected by the same access controls as the rest of your account data, and accessible to WorkQuora for safety, dispute-resolution, and legal-compliance purposes as described in Section 5.

2.6 Payment and financial records

We keep records of your wallet balance, transaction history, escrow deposits and releases, invoices, and payout settlements, including the commission and tax breakdown described in our Refund and Cancellation policies. Payment processing itself is handled by our payment gateway partner, Razorpay; we do not store your card or UPI credentials.

2.7 Communications and support

If you contact us for support or file a grievance, we retain that correspondence and any information you provide in it, to resolve your issue and maintain a record as described in our Grievance Redressal Policy.

3. How we use your data

We use the data described above to: operate your account and authenticate you; connect clients with workers and facilitate job posting, proposals, and completion; process payments, commission, and payouts; verify worker identity as required before they can accept jobs; provide customer support and resolve disputes; detect and prevent fraud, abuse, and policy violations; send you transactional communications (OTPs, receipts, status updates, security alerts); and comply with legal obligations, including recordkeeping requirements described in Section 6.

We do not use your data to serve third-party advertising, and — as described in our Cookie Policy — we do not run any third-party analytics or advertising trackers on our website today.

4. Legal basis for processing

We process your personal data on the following bases, consistent with the DPDP Act: (a) your consent, given at registration and reaffirmed where you take a specific action (such as submitting KYC documents or accepting a Term update); (b) performance of a contract with you, to provide the marketplace, matching, messaging, and payment services you sign up for; and (c) legal obligation, principally for financial recordkeeping (Section 6) and responding to lawful government or law-enforcement requests.

5. Who we share your data with

We do not sell your personal data. We share it only in the following circumstances:

  • With the other party to a job. A client and the worker assigned to (or proposing on) their job can see each other's name, profile, and — once connected — can message each other. A worker's KYC verification status (verified/not verified) may be visible to a client evaluating their proposal; the underlying documents and numbers (Aadhaar, PAN, bank details) are never shared with the other party.
  • With service providers who process data on our behalf, under obligations consistent with this Policy: Cloudinary (file/document storage), Razorpay (payment processing), our email provider (transactional emails — OTPs, receipts, alerts), and our cloud hosting and database providers. These providers are only given the data necessary to perform their function.
  • With Google or Facebook, only to the extent necessary to authenticate you if you choose to sign in using one of those providers.
  • For legal reasons — if required by applicable law, a valid court order, or a lawful request from a government or law-enforcement authority, or to protect the rights, safety, or property of WorkQuora, our users, or the public.
  • In a business transfer — if WorkQuora is involved in a merger, acquisition, or sale of assets, your data may be transferred as part of that transaction, subject to this Policy (or a successor policy you are notified of).

6. How long we keep your data

  • Financial and KYC records are retained for seven (7) years, consistent with standard Indian financial recordkeeping practice, even after you delete your account, for legal, tax, and audit purposes.
  • Chat messages tied to a job are retained for dispute-resolution purposes. Once a job is completed or cancelled, the conversation becomes read-only and, on the worker's side, is removed from their active list after 24 hours — but the underlying message data is not deleted from our systems at that point. We have not yet defined a fixed database deletion period for chat data; this Policy will be updated once that is finalized, and in the meantime such data is retained no longer than necessary for dispute resolution and legal compliance.
  • Account data, once you delete your account (Section 8), is anonymized rather than erased outright — see Section 8 for exactly what that means and why.
  • Audit and security logs (login history, account-change history, admin actions taken on your account) are retained for security, fraud-prevention, and dispute-evidence purposes for as long as reasonably necessary for those purposes.

7. Your rights

Subject to applicable law (including the DPDP Act once its provisions are in force), you have the right to: access the personal data we hold about you; request correction of inaccurate data; withdraw consent for processing that relies on consent (which may limit your ability to use certain features); and request erasure of your data, subject to the retention obligations in Section 6 (we cannot erase data we are legally required to keep, such as financial records within their retention period).

To exercise these rights, contact us using the details in our Grievance Redressal Policy. A dedicated self-service data export tool does not exist in the Platform today — requests are handled manually by our support team until one is built.

8. Deleting your account

You can request account deletion from within the app (Settings → Delete Account, available in both the client and worker apps). Here is exactly what happens when you do:

  • We will not process the deletion while you have an open or in-progress job — complete or cancel it first.
  • Your account is deactivated and your personal profile fields are anonymized: your name is replaced with a generic placeholder, your email is replaced with an internal placeholder address, and your mobile number, bio, and skills are cleared. You will no longer be able to log in.
  • Your job history, transaction and payment records, and chat messages are not deleted. They remain associated with your (now-anonymized) account, because deleting them would compromise the transaction and dispute history of the other party you interacted with, and because we are required to retain financial records for the period described in Section 6.
  • This means account deletion should be understood as "deactivate and anonymize my profile," not "erase all data associated with me." We describe it this way deliberately, so you can make an informed decision before requesting it.

9. Security measures

We apply access controls, encryption for the specific sensitive fields described in Section 2.2 (PAN, Aadhaar, and bank account numbers), password hashing, session management with revocable sessions, and audit logging of account-affecting actions. No online platform can guarantee absolute security, and we encourage you to use a strong, unique password and to review your active sessions periodically.

10. Children's data

The Platform is intended for users who are at least 18 years old (workers must be 18+ to be legally engaged as independent contractors and to complete financial KYC). We do not knowingly collect data from anyone under 18.

11. Changes to this Policy

We may update this Policy from time to time. Material changes will be notified to you in-app or by email before they take effect, and continued use of the Platform after that point constitutes acceptance of the updated Policy.

12. Contact us

For privacy questions, data requests, or complaints, see our Grievance Redressal Policy for contact details.


This Policy should be read together with our Terms & Conditions, Cookie Policy, and — for workers and clients respectively — the Worker Agreement and Client Agreement.