TownPlotter
PrivacyTermsRefundsCancellation

Legal document

Privacy Policy

This policy explains how MoveTez Private Limited handles personal data when builders, channel partners, buyers and website visitors use TownPlotter.

Last updated: 5 September 2026

1. Who we are

TownPlotter is a venture of MoveTez Private Limited (CIN: U63032RJ2021PTC078601), having its registered address at A-92 Sundar Nagar, 200 Feet Bypass, Jaipur, Rajasthan, India. In this policy, “TownPlotter”, “MoveTez”, “we”, “our” and “us” refer to MoveTez Private Limited.

For personal data processed to operate TownPlotter, MoveTez Private Limited acts as the Data Fiduciary to the extent applicable under the Digital Personal Data Protection Act, 2023 and rules brought into force under it. A builder may separately determine why personal data contained in its own project content is processed.

2. Personal data we collect and why

Builder and platform accounts

We process account name, email address, phone number, role, account status and authentication information to create accounts, authenticate users, provide the builder or administration console, secure access and maintain an audit trail. Account passwords are handled by Google Firebase Authentication. Our application does not store or display plaintext account passwords.

Project and location information

Builders and our onboarding team may provide township layouts, plot details, project branding, inventory information, GPS coordinates and location details. We use this information to build, host and operate the project's interactive 2D, 3D and Location Map experiences. The Location Map feature may use Google Maps Platform Places and Routes services to find places and calculate routes requested by an authorised user.

The builder or developer controls whether its project remains publicly available and may disable the project or hide it from public view through its authorised controls. Separate visibility settings allow the builder to hide public plot-status or inventory information without removing the complete project experience.

Channel-partner referrals

When a channel partner chooses to create a client-referral link, we collect the partner's name and phone or WhatsApp number. We use it to resolve the correct contact for that referral, prevent duplicate referral records, let the builder manage partner access and measure aggregate and unique project views attributed to the referral. Phone numbers are not placed in referral URLs; the link uses an opaque referral identifier.

Password-protected inventory visibility

A builder may protect plot status information with a project-level password. That password is processed using scrypt with a random salt and server-side pepper and is never stored in plaintext. Successful verification creates a signed, HttpOnly session cookie valid for up to 24 hours. Changing, disabling or locking the password version invalidates existing unlock sessions. For failed-attempt rate limiting, the application stores a one-way hashed network fingerprint rather than the raw IP address.

Enquiries and communications

If you request information through the website, we process your name, company name, phone number, email address, project location and project details to respond, qualify the enquiry and discuss a possible service engagement. Required fields are identified in the form. Commercial discussions, quotations, invoices and payments take place manually outside the website; TownPlotter has no online payment gateway.

First-party usage and security information

TownPlotter records limited first-party project-view information so a builder can see total and unique showroom views and referral performance. The browser creates a random visitor identifier in local storage; the server stores only a one-way hash derived from that identifier for deduplication. The view counter does not ask for or attach the visitor's name, mobile number, email address or account identity, and neither MoveTez nor the builder can use the counter by itself to identify who the visitor is. Session storage prevents the same browser tab from repeatedly recording the same view.

This anonymous or pseudonymous counting information is used only for aggregate measurement and referral performance. We still protect it as privacy-relevant technical data because whether an online identifier is legally personal data can depend on whether it is reasonably capable of being related to an identifiable person. We also process technical request, device, security and audit information needed to prevent abuse, diagnose failures and protect accounts.

The current website does not integrate Google Analytics, Meta Pixel, Hotjar, Mixpanel or another third-party advertising or behavioural analytics SDK. We do not sell personal data or use it for cross-site behavioural advertising.

3. Consent and other permitted processing

Where consent is required, we ask for clear affirmative action and use the data for the purpose described at collection. You may withdraw consent by contacting the Grievance Officer below. Withdrawal does not make prior lawful processing invalid, and it may prevent us from providing a feature that requires the relevant data. We may also process data where necessary to provide a service you requested, comply with law, protect the platform or for another legitimate use permitted by applicable law.

4. Cookies and browser storage

  • Firebase Authentication uses browser storage needed to keep authorised users signed in.
  • The inventory-status unlock uses a signed, secure and HttpOnly cookie for up to 24 hours.
  • A random first-party visitor identifier remains in local storage until site data is cleared.
  • A per-tab view marker remains only for the browser session.

These technologies support authentication, security, preference and first-party view-count functions. They are not third-party advertising cookies.

5. Service providers and disclosures

We disclose data only as needed to operate the service, including to:

  • Google Firebase for Authentication, Firestore database services and Cloud Storage.
  • Google Cloud Platform for App Hosting/Cloud Run, background processing, Cloud Tasks, logs and related infrastructure.
  • Google Maps Platform when an authorised user uses Places or Routes features in a project's Location Map.
  • Resend to deliver a submitted marketing enquiry to the TownPlotter team by email.
  • Professional advisers, regulators, courts, law-enforcement bodies or a successor organisation where disclosure is legally required or reasonably necessary to protect rights and complete a lawful business transaction.

A WhatsApp wa.me link is a navigation initiated by the user. TownPlotter does not send the enquiry or project data to Meta or WhatsApp through an API merely because that link is displayed. If you choose to open or send a WhatsApp message, your interaction is governed by WhatsApp's own terms and privacy practices.

6. International processing

TownPlotter's production Google Cloud and Firebase infrastructure includes processing and storage in a United States Google Cloud region, including the multi-region identified as nam5. Personal data may therefore be transferred to and processed outside India. We use contractual, organisational and technical safeguards offered through our service-provider arrangements and will comply with any transfer restriction notified under applicable Indian law.

7. Retention

We apply the following standard retention periods:

  • Active account data is retained while the account is active and for 30 days after account closure.
  • Channel-partner and referral records are retained for 3 years.
  • Security and audit logs are retained for 3 years.
  • Marketing lead submissions that do not convert to customers are retained for 12 months.
  • Security and rate-limit records containing hashed network identifiers or failed-access information are retained for 12 months.
  • Inventory unlock cookies expire after 24 hours and may be invalidated sooner by the builder.
  • The local visitor identifier remains until the visitor clears the browser's site data.

Following the effective cancellation date stated in MoveTez's written confirmation, the customer has 24 hours to export or request its project data. Customer project data is permanently deleted 30 days after that export window closes. We may retain a limited record longer where required by tax, accounting, fraud-prevention, security, litigation hold or other applicable law. Provider-managed backups or replicas may remain for a limited infrastructure lifecycle period before deletion.

8. Security

We use role-based access controls, multi-factor authentication for platform accounts, server-only database boundaries for sensitive records, encryption provided by our infrastructure providers, salted password hashing, signed cookies, opaque referral tokens, rate limiting and audit logging. No internet service can guarantee absolute security. Please notify us promptly if you suspect unauthorised access.

9. Your rights and choices

Subject to applicable law, a Data Principal may request a summary of personal data and processing, correction or completion of inaccurate data, erasure of data no longer necessary, withdrawal of consent, grievance redressal and nomination of another person to exercise rights in the event of death or incapacity. You may also clear local browser storage and cookies through your browser.

Send a request to the Grievance Officer with enough information to locate the relevant account, enquiry, project or referral. We may verify identity and authority before acting. We may refuse or limit a request where retention or processing is required by law, needed to establish or defend legal claims, or concerns another person's rights. If dissatisfied, you may use the remedies available under applicable data-protection law after first giving us an opportunity to address the grievance.

10. Children

TownPlotter is a business service for real-estate developers and is not directed to children. Do not submit a child's personal data through the platform unless you have a lawful basis and all permissions required by applicable law.

11. Contact and grievance redressal

Grievance Officer: Deepak

MoveTez Private Limited / TownPlotter

A-92 Sundar Nagar, 200 Feet Bypass, Jaipur, Rajasthan, India

Email: townplotters@gmail.com

Phone: +91 96678 86100

Please use the subject “Privacy Request” or “Privacy Grievance” and describe the requested action. We will acknowledge and handle the request in accordance with the period prescribed by applicable law.

12. Governing law and Jaipur jurisdiction

This policy is governed by Indian law. Privacy complaints should first be submitted through the grievance process above. This clause does not prevent a person from approaching the Data Protection Board of India or another mandatory statutory forum where applicable. Subject to those non-excludable remedies and jurisdictions, any court proceeding arising from this policy shall be instituted and conducted exclusively before the competent courts at Jaipur, Rajasthan.

13. Changes to this policy

We may update this policy when the product, law or our service providers change. The revised version will show a new “Last updated” date. Where a material change requires fresh consent, we will seek it before relying on that consent for the new purpose.

© 2026 MoveTez Private LimitedCIN: U63032RJ2021PTC078601