NirmanMetry is a product of Plusteams IT Services LLP ("we", "our", "us", "the Company"). This Privacy Policy describes how we collect, use, store, share, and protect your personal information, project data, financial records, and contacts when you use the NirmanMetry mobile application (the "App") and our cloud database, storage, and backend services (the "Services").
Please read this Privacy Policy carefully. By downloading, accessing, or using the App and Services, you acknowledge that you have read, understood, and consent to the data practices described in this document.
1. Information We Collect
To provide construction and interior project management, expense tracking, payment reconciliation, and team collaboration, we collect the following categories of information:
A. Personal Identifiable Information (PII)
- Phone Number: Collected during sign-up for account creation and secure One-Time Password (SMS OTP) authentication.
- Full Name & Email Address: Provided by you during profile setup to identify you to other collaborators on shared projects and for transactional support communications.
- Profile Image: Optionally uploaded by you and stored in our secure avatars storage bucket (
avatars/$userId/avatar.jpg). - Role & Locale Preferences: Your specified trade/site role (e.g., Project Manager, Site Engineer, Contractor, Interior Designer, Builder), preferred language (English, Hindi, Telugu, Tamil, Kannada, Malayalam), currency preference, and country code are stored to customize your dashboard layout and reporting outputs.
B. Project, Expense & Financial Data
- Project Details: Project codes/IDs, titles, allocated budgets, project statuses (Active, Completed), start/end dates, and physical construction or site locations.
- Expense Records: Transaction amount, transaction date, project association, category, subcategory, detailed notes, and remarks. The App supports 13 master categories across Construction and Interior Design (Materials, Equipment, Labor, Permits, Others, Furniture, Woodwork, Electrical & Lighting, Soft Furnishing, Decor & Accessories, Kitchen, Paint & Finishing, Professional Services) as well as custom user-created categories.
- Payment Records & Allocations: Payment amount, payment date, payment method (Cash, UPI, Bank Transfer, Cheque, Other), subcategory payment allocations, linked expense IDs, recipient contact associations, and transaction notes.
- Invoice, Bill & Payment Proof Uploads: Scanned or photographed receipts, bills, invoices, and payment confirmation vouchers uploaded by you. These are stored in our secure storage buckets (
bills/$userId/$projectId/bill_$ts.jpg) and analyzed for file size to enforce storage tiers (100 MB for Free accounts, 1 GB for Premium accounts). - Vendor & Contractor Directory Data: Contractor, supplier, dealer, and labor profile records created or imported by you, including contact names, phone numbers, trade classifications, business/site addresses, notes, and running balance data (total spent, total paid, and balance due).
- To-Do & Task Management Records: Task titles, priorities (Normal, High), statuses (Pending, Completed), due dates, reminder dates/times, and project linkage.
- Custom Categories & Subcategories: Custom category names, assigned icons, color codes, and subcategories defined by you to adapt the App to your workflow.
C. Technical Data & Local Storage
- Local Cache: We cache user preferences, profile details, localized language translations, currency formatting rules, and active tab states on your device via local shared storage (
SharedPreferences) to enable instant app loading, responsive interactions, and offline view capabilities. - Local Notification Schedules: When you set a task reminder, scheduling metadata is stored on your device via the local notification system to ensure reminder alerts trigger accurately at the specified local time.
- Transactional Logs: Operational logs containing timestamps of billing records, project updates, member invitations, and in-app notifications are stored securely in our database.
D. Error & Crash Diagnostics
- Sanitized Error Logs: When the App encounters an unexpected error, we automatically log the error type, a sanitized error message, the screen name where the error occurred, your device platform (Android/iOS/Web), and a timestamp. These logs are stored in our database and are used solely for diagnosing bugs and improving App stability. Personally identifiable information (such as phone numbers, personal names, and payment specifics) is automatically stripped and filtered out before storage.
- No Third-Party Analytics: We do not integrate third-party advertising or behavioral tracking SDKs (such as Google Analytics, Firebase Analytics, or Meta Pixel). All diagnostic data is stored exclusively on our own managed infrastructure.
2. Device Permissions
NirmanMetry requests specific device permissions to enable core functionality. In accordance with Apple App Store and Google Play Developer policies, each permission is requested at the point of use — never silently or at app installation — and you may deny or revoke any permission at any time.
A. Camera Permission (CAMERA)
- Why we ask: To allow you to take real-time photos of physical bills, receipts, invoices, delivery notes, payment vouchers, and your profile picture directly within the App.
- What we do with it: When you tap "Take Photo" in the bill uploader or profile editor, the App activates your device camera. The resulting image is compressed on-device, validated (JPG/JPEG/PNG format, max 3 MB), and uploaded to our access-controlled cloud storage.
- What we do NOT do: We never access your camera in the background. The camera is activated solely when you explicitly tap the photo capture button. We do not record video, do not perform facial recognition or biometric analysis, and do not share raw camera streams with any third party.
B. Photo Library (Gallery) Permission (READ_MEDIA_IMAGES / Photo Library)
- Why we ask: To allow you to select existing receipts, invoice images, or profile photos from your device gallery.
- What we do with it: When you tap "Choose from Gallery", the App opens your device's photo picker. Only the specific image file you manually select is read by the App.
- What we do NOT do: We do not scan, index, or bulk-access your photo album. We do not read or extract metadata (such as EXIF, camera model, or GPS coordinates) from your photo library, and we do not upload any photo other than the one you explicitly select.
C. Contacts Permission (READ_CONTACTS / NSContactsUsageDescription)
- Why we ask: To allow you to quickly import contractor, supplier, dealer, or worker details directly into the App's Contact directory without having to manually retype names and 10-digit phone numbers.
- What we do with it: When you tap "Import from Phone Contacts" on the Add Contact screen, the App requests permission and opens your device's native contact picker. Only the single contact that you explicitly select is read by the App to pre-fill the name and mobile number fields in the form.
- What we do NOT do:
- We do NOT copy, scan, upload, sync, or harvest your entire address book.
- We do NOT access your contacts in the background.
- No contact information from your phone book is transmitted to our servers until you explicitly review, edit, and tap Save Contact.
- We never sell, rent, or share your contact data with third-party advertisers, data brokers, or marketing networks.
D. Notification Permission (POST_NOTIFICATIONS / Remote & Local)
- Why we ask: To deliver timely operational updates regarding team collaboration, budget limits, and your scheduled task reminders.
- What we do with it: When granted, notifications are used for:
- Project Collaboration: In-app and push notifications when you are invited to a project, when an invitation is accepted, or when a member role changes.
- Budget Alerts: Automated warnings when project spending approaches or exceeds critical budget thresholds (e.g., reaching 85% or 100% of budget).
- Scheduled Task Reminders: On-device local reminders for scheduled To-Do task due dates and times set by you.
- Subscription Alerts: In-app notices regarding subscription renewal, expiration, or tier changes.
- What we do NOT do: We do not use notifications for marketing, advertising, cross-promotions, or spam. Notification tokens are never sold or shared with third parties.
E. Revoking Permissions
You can modify or revoke any granted permission at any time through your device's operating system settings:
- Android: Settings > Apps > NirmanMetry > Permissions
- iOS: Settings > NirmanMetry
Revoking a permission will disable only the corresponding optional capability (e.g., revoking camera access prevents capturing photos directly, but you can still select files or use other features) and will not affect any previously saved data.
3. How We Use Your Information
We process and use collected data strictly for legitimate operational purposes:
- Account Authentication & Security: Dispatching SMS OTP codes, validating session tokens, preventing unauthorized logins, and verifying account ownership.
- Core Project & Expense Operations: Recording project budgets, logging itemized expenses, categorizing costs, calculating monthly spending trends, and monitoring real-time budget utilization.
- Payment & Ledger Reconciliation: Tracking payments across multiple payment methods (Cash, UPI, Bank Transfer, Cheque, Other), allocating payments to specific subcategories, linking payments to expenses and contacts, and computing outstanding balances (total spent, total paid, total due).
- Vendor & Contact Directory: Managing supplier and contractor profiles, associating transactions with specific dealers, and maintaining clear ledger records.
- Task & To-Do Scheduling: Tracking site tasks, flagging high-priority action items, displaying overdue task alerts, and triggering scheduled local reminders.
- Collaborative Project Sharing: Connecting team members across projects. Entering a collaborator's phone number links them to the project or queues a pending invitation that resolves upon their registration.
- Reporting Services: Generating comprehensive expense and payment reports in PDF and Excel formats based on your chosen date ranges, project filters, and categories.
- Digital Receipt Card Sharing: Generating formatted, branded digital receipt cards for individual expenses and payments when you initiate sharing via WhatsApp or external messaging platforms.
- Subscription & Entitlement Management: Validating Pro tier access (unlimited projects, unlimited expenses/payments, custom subcategories, advanced report filtering, receipt card sharing) via RevenueCat.
- Application Diagnostics & Support: Resolving reported issues, fixing crashes, and providing customer support via our dedicated support channels.
4. Sharing and Disclosure of Information
We do not sell, rent, or trade your personal, project, or financial data to third parties. We disclose data only in the following limited circumstances:
A. Collaboration & Peer Visibility (Within Shared Projects)
- Project Members: When you create or join a shared project, your Full Name and Phone Number are visible to the project owner and fellow project members. This peer-to-peer transparency is essential on construction sites so collaborators know who logged an expense, recorded a payment, or updated a task.
- Invitations: When a project owner invites you by phone number, their name and project title are displayed in your in-app invitation.
B. User-Initiated External Sharing
When you use the Share feature (such as sharing an expense receipt, payment voucher, or exported PDF/Excel report via WhatsApp, email, or messaging apps), the App generates the document or image card and passes it directly to your device's native system share sheet. We do not access, monitor, or store messages sent through third-party messaging services.
C. Third-Party Service Providers
We partner with trusted cloud infrastructure providers who process data strictly under our direction and subject to confidentiality obligations:
- Supabase, Inc.: Cloud-hosted PostgreSQL database, encrypted cloud storage (bill images, payment receipts, avatars), and secure SMS OTP authentication dispatch.
- RevenueCat, Inc.: In-app subscription status verification, receipt validation, and entitlement synchronization. Your Supabase user ID is mapped to RevenueCat to associate your Pro status.
- Apple App Store & Google Play Store: In-app purchase payment processing and subscription billing management. All payment card and billing transactions are handled exclusively by Apple or Google.
D. Legal & Regulatory Compliance
We may disclose information if required by applicable Indian law, court order, regulatory mandate, or governmental authority, or where necessary to prevent fraud, protect project security, or defend our legal rights.
5. Account Deletion and Data Retention Policies
We uphold your right to complete data ownership and erasure:
A. Retention While Account is Active
All active user profiles, projects, expense logs, payment records, vendor contacts, to-dos, and uploaded bill images are retained for as long as your account remains active.
B. Self-Service Account Deletion
You can initiate permanent account deletion at any time directly within the App:
- Navigate to Settings > Delete Account.
- Request and verify identity using a 6-digit SMS OTP sent to your registered phone number (up to 3 attempts allowed).
- Upon verification, your account is immediately suspended, active session tokens are invalidated, and you are logged out.
C. 30-Day Permanent Data Purge
Within 30 calendar days of your deletion request, all personal content is permanently erased and purged from our active databases and cloud storage buckets:
- User profile metadata (name, phone number, email address, role, profile avatar).
- All projects owned by you, including all associated expense entries, payment records, allocations, bill photos, payment receipts, and project media.
- All vendor and contractor contacts created by you.
- All To-Do tasks and reminders created by you.
- All custom categories and subcategories created by you.
- Authentication credentials in our auth directory (
auth.users).
Shared Projects Exception: If you participated as an Editor or Viewer on a project owned by another user, your membership record and contact info are removed from that project upon deletion. The project owner retains the project and its transactional audit history.
D. Legally Required Archives
As required by applicable Indian laws (such as the Information Technology Act, 2000 and financial compliance regulations), non-identifying payment transaction records, subscription billing logs, and security audit logs may be retained in isolated, access-restricted archives for statutory audit periods before permanent destruction.
For full information on data and account deletion options and policies, visit our Delete Account page.
6. Security of Your Data
We employ comprehensive administrative, technical, and physical safeguards:
- Row Level Security (RLS): Access to all database tables (projects, expenses, payments, contacts, to-dos, categories) is governed by PostgreSQL Row Level Security. Users can strictly query or modify data belonging to projects where they are verified owners, editors, or viewers.
- Storage Access Controls: Uploaded bill receipts and payment vouchers are stored in access-controlled storage buckets accessible only to authenticated project members.
- Encrypted Transmission: All communication between the App and our backend servers is encrypted in transit using industry-standard HTTPS/TLS 1.3.
- Principle of Least Privilege: Backend service operations (such as subscription webhook processing) use isolated, encrypted service-role credentials inaccessible to client devices.
7. Cookies and Tracking Technologies
- The NirmanMetry mobile App does not use cookies, tracking pixels, device fingerprinting, or web beacons.
- We do not engage in behavioral profiling, cross-app tracking, or targeted advertising.
- We do not collect or transmit advertising identifiers (IDFA, GAID).
- Local storage is limited to
SharedPreferenceson your device, used solely for caching functional preferences (language, currency, theme, onboarding state) and authentication session tokens.
8. Children's Privacy
NirmanMetry is intended strictly for professional, commercial, and business use by individuals who are at least 18 years of age. We do not knowingly collect personal information from minors. If we learn that an account has been created by an individual under 18, we will promptly delete all associated data and revoke account access.
9. International Data Transfers & User Rights
- Cloud Hosting: Our cloud infrastructure is hosted in secure data centers managed by Supabase and cloud infrastructure partners. If you access the App from outside India, your information may be processed and stored in jurisdictions with differing data protection laws. By using the Services, you consent to this transfer.
- Right to Access & Rectify: You may view and edit your profile, projects, expenses, payments, contacts, and tasks directly within the App at any time.
- Right to Data Portability: You can export your expense and payment records into portable PDF and Excel formats directly through the Reports feature.
- Right to Erasure: You can delete individual records (expenses, payments, contacts, tasks, projects) or permanently delete your entire account through Settings > Delete Account.
10. Updates to This Privacy Policy
We may update this Privacy Policy from time to time to reflect new features, regulatory requirements, or changes in our operational practices. When updates are published, the "Last Updated" and "Effective Date" at the top of this document will be revised. For material changes, we will provide prominent notice through an in-app banner, notification, or email. Your continued use of the App following the posting of revisions signifies your acceptance of the updated policy.
11. Grievance Officer & Contact Information
In compliance with the Information Technology Act, 2000 and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, the designated Grievance Officer for NirmanMetry is:
- Company: Plusteams IT Services LLP
- Designation: Grievance Officer
- Registered Address: 1-7-177/D4/2, Church compound, Suryapet 508213, Telangana, India
- Support Email: support@NirmanMetry.com
- Grievance Email: grievance@NirmanMetry.com
- Response Timeline: Grievances will be acknowledged within 24 hours and resolved within 15 business days of receipt.