Privacy Policy — दृष्टि (Drishti)
Effective date: 10 September 2026 Last updated: 10 September 2026
Drishti is operated by Fostron ("Fostron", "we", "us"), a sole proprietorship of Shashi Patel, registered at 18, Vrajvas Society, College Road, Nadiad, Gujarat, India.
This policy explains what personal data we handle, why, and what rights you have. It covers two different groups of people, and our obligations differ for each:
| You are | We are | Section |
|---|---|---|
| A merchant using Drishti | The Data Fiduciary for your account data | §2, §3 |
| A customer of a merchant, leaving feedback | The Data Processor, acting on that merchant's instructions | §4 |
1. Summary
- We do not sell personal data. Ever.
- We do not use customer feedback for advertising.
- Google data is used only to show merchants their own reviews and to let them reply. See §5, which is the section a Google reviewer should read first.
- Customers can leave feedback without an account, and without giving us a name or a phone number.
- You can withdraw consent, request a copy of your data, or request deletion.
2. Merchant data we collect
| Data | Why | Basis |
|---|---|---|
| Name, mobile number, email | Account identity, login, support | Contract |
| Business name, category, address, location coordinates | To create the business page and QR | Contract |
| Business WhatsApp number, phone | Customer contact actions on the page | Contract |
| Login PIN (hashed) | Authentication | Contract |
| Recovery code (hashed) | Account recovery | Contract |
| Payment records, invoices | Billing, statutory records | Legal obligation |
| Usage and diagnostic logs | Operating and securing the service | Legitimate use |
| Support correspondence | Resolving your issues | Contract |
We do not store card details. Payments are handled by our payment gateway.
3. How we use merchant data
To provide the service; authenticate you; send operational messages about your account; provide support; bill you; detect abuse and fraud; comply with law; and improve the product using aggregate, non-identifying analysis.
We do not send marketing messages to merchants who have opted out, and we never use customer contact data for marketing (§4.4).
4. Customer data — feedback left by a merchant's customers
When someone scans a merchant's QR code and leaves feedback, the merchant decides why that data is collected. We process it on their behalf.
4.1 What is collected
| Data | Required? | Notes |
|---|---|---|
| Rating and category selections | Yes | The feedback itself |
| Free-text comment | No | In any language |
| Contact number | No — optional, and only offered on low ratings | So the merchant can put things right |
| Name | No | Only where the merchant has enabled it |
| Approximate device type, browser, language, referrer | Automatic | For analytics |
| Truncated network address | Automatic | Truncated before storage, then hashed. We do not store your full IP address alongside your feedback |
No account, login, cookie consent wall or app install is required to leave feedback.
4.2 Notice and consent
Before any contact detail is requested, we show a plain-language notice explaining who receives it and why. Providing it is optional; skipping it is equally easy and does not change your feedback. We record the fact, time, purpose and version of notice for each consent.
4.3 How it is used
To show the merchant what their customers said; to let the merchant contact you only if you gave a number, and only to resolve your experience; to generate sentiment and topic analysis for that merchant; and, in aggregate and non-identifiable form, to produce category benchmarks (§4.5).
4.4 How it is not used
- Not for advertising or marketing, by us or by the merchant.
- Not sold, rented or licensed to anyone.
- Not used to build a profile of you across different businesses. Your feedback to one merchant is not linked to your feedback to another.
- Not shared with any merchant other than the one you gave it to.
4.5 Aggregate benchmarks
We produce comparisons such as "restaurants in this city average 4.3 stars". These are computed from aggregates only, require a minimum number of businesses before they are shown, contain nothing that identifies a person or a single business, and merchants may opt out.
4.6 Third parties named in feedback
If feedback mentions another person by name, we store it so the merchant can act on it, but we do not include named individuals in any AI-generated public review text, or in any aggregate output.
5. Google user data
This section describes our use of Google user data and our compliance with the Google API Services User Data Policy, including the Limited Use requirements.
5.1 What we access, and only with the merchant's explicit consent
A merchant may choose to connect their Google Business Profile. Nothing happens until they complete Google's own consent screen. We then access:
| Data | Purpose |
|---|---|
| The list of business locations they manage | So they can choose which location to connect |
| Reviews on the connected location — rating, text, reviewer display name, timestamps | To display them in the merchant's dashboard alongside private feedback, and to produce sentiment and topic analysis for that merchant |
| The location's aggregate rating and review count | To show rating history |
| The ability to publish a reply to a review | Only when the merchant writes or approves a reply and explicitly chooses to publish it |
5.2 How we store it
Google reviews are stored in our database so the merchant can search their own history and see trends over time. OAuth access and refresh tokens are encrypted at rest using managed keys and are never logged. See §7.1 for where that database physically sits.
5.3 What we never do
- We never post a review. Drishti cannot and does not create reviews.
- We never modify or delete a merchant's reviews or ratings.
- We never publish a reply automatically. Every reply is written or approved by the merchant and published only on their explicit action.
- We never filter which customers are invited to review. Every customer sees the same option regardless of how they rated their experience.
- We never share Google user data with any other merchant or third party, except the infrastructure sub-processors in §7 acting on our instructions.
- We never use Google user data for advertising, or to build a profile of any individual reviewer.
- We never sell Google user data.
- We never transfer Google user data except as required by law, or as part of a merger or acquisition in which the acquirer is bound by this policy.
- We do not use Google user data to train generalised artificial intelligence or machine learning models. Where we send review text to an AI provider to analyse it for the merchant, that provider is contractually bound not to retain or train on it (§7).
5.4 Limited Use
Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
5.5 Revoking access
A merchant may disconnect at any time from Drishti Settings, or revoke our access directly from their own Google Account security settings. On revocation we stop all access immediately and delete the stored tokens. Reviews already synced remain in the merchant's own dashboard unless they ask us to delete them.
6. AI processing
We use third-party AI services to analyse feedback and review text — detecting sentiment, extracting topics, summarising, translating and drafting replies for the merchant to approve.
- We use paid service tiers with contractual terms prohibiting the provider from retaining or training on submitted content.
- We never send payment details, login credentials or authentication tokens to an AI provider.
- AI output is presented as analysis, always with the number of responses it is based on, and always linked to the underlying records.
7. Sub-processors
We share data only with service providers acting on our instructions:
| Purpose | Provider | Data |
|---|---|---|
| Cloud hosting and database | Fly.io (Singapore region) | All service data |
| AI analysis | Named on request; bound not to retain or train | Feedback and review text |
| Email delivery | Resend | Email address, message content |
| Payment processing | To be appointed | Billing details — card data goes directly to the gateway, never to us |
| Error monitoring | To be appointed | Diagnostic data, without feedback content |
We do not send SMS or WhatsApp messages, so no mobile number is shared with any messaging provider.
This list is updated when it changes, and the change is reflected here rather than on a separate page.
7.1 Where your data is stored
Our servers and database run in Singapore, on Fly.io. This is a transfer of personal data outside India.
We would rather host in India. Our infrastructure provider withdrew its Mumbai region, and Singapore is the nearest region it still operates. Under the Digital Personal Data Protection Act, 2023, such a transfer is permitted except to countries the Central Government restricts by notification; Singapore is not currently restricted.
If that changes, or once an India region becomes available to us again, we will migrate and say so here. Your rights under §6 are unaffected by where the data sits.
8. Retention
| Data | Retained |
|---|---|
| Merchant account | While the account is active, then 12 months |
| Feedback content | Per the merchant's setting; 3 years by default |
| Customer contact numbers | 12 months from collection |
| Raw scan records | 13 months |
| Aggregated statistics | Indefinitely — contains no personal data |
| Invoices and payment records | As required by tax law |
| Audit logs | 12 months minimum |
Deletion is enforced by automated schedule, not by policy alone.
9. Security
Encryption in transit (HTTPS/TLS) and at rest; encrypted OAuth tokens and contact numbers; hashed PINs and recovery codes; strict tenant isolation so one merchant can never access another's data; role-based access; rate limiting; audit logging; and daily backups with tested restores.
No system is perfectly secure. If a breach affecting your personal data occurs, we will notify you and the relevant authority as required by law.
10. Your rights
Under the Digital Personal Data Protection Act, 2023, you may request access to your personal data; correction of inaccurate data; erasure; withdrawal of consent at any time; and grievance redressal (§11).
Merchants: exercise these from your account settings or by contacting us.
Customers who left feedback: contact us at contact@fostron.in with the business name and approximate date. We will identify your record and act on it. Where you ask us to delete feedback, we delete it, the analysis derived from it, and its contribution to any statistic.
One thing we cannot do: if you posted a review on Google, that review belongs to Google and your Google account, not to us. We can delete our copy, but you must remove the review itself through Google.
11. Grievance Officer
As required under the Digital Personal Data Protection Act, 2023 and applicable Information Technology Rules:
Shashi Patel, Proprietor
Fostron
18, Vrajvas Society, College Road, Nadiad, Gujarat, India
Email: contact@fostron.in
Phone: +91 90333 32878
We acknowledge grievances within 48 hours and aim to resolve within 30 days.
12. Children
Drishti is not directed at children. We do not knowingly collect personal data from anyone under 18. If you believe we have, contact the Grievance Officer and we will delete it.
13. Changes
We will post any change here and update the date above. Where a change materially affects how we use personal data, we will notify merchants directly before it takes effect. Any new use of Google user data will be reflected in this policy before it is implemented.
14. Contact
Fostron · 18, Vrajvas Society, College Road, Nadiad, Gujarat, India · contact@fostron.in · +91 90333 32878