PRIVACY POLICY
Lumina Hospitality Private Limited (“NAZR”, “we”, “us”, or “our”) is committed to protecting the user’s privacy and ensuring the security of the personal information the user shares with us through our application, website, and related services (collectively, the “Services”).
Where required by applicable law, we seek your consent before collecting or processing your personal data. By creating an account and providing the permissions requested within the application, you consent to the processing described in this Privacy Policy.
Table of Contents
1. Company Information
Name: Lumina Hospitality Private Limited
Registered Address: 802, Harshvardhan, Opp. Saki Vihar Telephone Exchange, Mumbai – 400076
Registration Number: U56201MH2024PTC428005
Email: support@nazrco.in
2. Collection of Information
We collect information that helps us provide safety, emergency communication, and platform functionality. Some information, such as a user’s guardians’ contact details, is provided to us by the user on their behalf rather than by them directly. By submitting a guardian’s information, the user confirms that they are authorised to provide it, for the purpose of enabling NAZR’s emergency response features.
3. Legal Basis for Processing
We process personal information on the following bases: with the user’s consent, to provide the safety and platform services requested; and to comply with our legal obligations, including responding to lawful requests from authorities and taking necessary action during emergencies to protect life.
4. Account Information
When the user creates or uses a NAZR account, we may collect:
- Full name
- Mobile number
- Email address
- Date of birth (optional at sign-up, verified as part of identity verification below)
- Account credentials
- Profile information voluntarily provided by the user
5. Identity Verification (KYC)
Before a new account can access Shield Mode, SOS, or any other safety feature, we verify the user’s identity using a government-issued ID (Aadhaar, PAN, Driving Licence, or Passport). This review is conducted by our safety team and typically takes 24–48 hours.
We use this process, among other things, to confirm that account holders meet our minimum age requirement. Accounts that do not meet this or our other verification criteria will not be approved for use of the Services. KYC documents are not used for marketing, profiling, or any purpose unrelated to identity verification and platform security.
6. Location Data
NAZR is a personal safety application that relies on location information to provide emergency response, SOS functionality, journey tracking, and safety-related features.
With the user’s permission, NAZR may collect location data only while Shield Mode or SOS is actively engaged — that is, during a monitored journey or an active emergency alert, not as continuous background tracking at other times.
- Precise location data during an active Shield Mode session or SOS.
- Real-time location updates during active SOS sessions, refreshed approximately every 10 seconds.
- The user’s city, so their guardians know where to direct help if the user is in a different location than they are.
Location tracking is always started manually by the user, within the app, by activating Shield Mode or SOS; NAZR never begins a new session automatically or without the user’s action. Once a Shield Mode session is active, however, an SOS may be triggered within that session either by a guardian, or automatically by the app, as described in Emergency Safety Features below.
Once the session has been started, location tracking continues even if the app is minimised, the screen is locked, or the user switches to another app, so that the journey remains monitored without the user needing to keep the app open. This is what the device refers to as “background” location access. Tracking runs only for the duration of that active session and stops automatically when the session ends — by the user marking themselves safe, completing the journey, or manually deactivating Shield Mode.
Location information may be used to:
- Trigger SOS alerts
- Enable live location sharing with designated guardians
- Facilitate emergency response and safety monitoring
- Improve platform functionality and safety-related features
Users may withdraw location permissions at any time through device settings. Certain safety features may become unavailable if location permissions are disabled.
7. Trusted Guardian & Emergency Contact Information
To support emergency response features, we collect the following about the members of the user’s Trusted Circle, provided by the user on their behalf:
- Guardian name
- Guardian phone number
- Relationship to the user
- City, so a guardian in a different city knows to direct help locally
- Email address (optional)
- Photo (optional)
Because this information is provided to us by the user rather than directly by the guardian, a guardian may contact support@nazrco.in directly to request that their information be removed. Doing so will remove them from the user’s Trusted Circle going forward; it will not alter the historical record of any past emergency in which they were already alerted.
8. Audio Information
Microphone access is used only during an active SOS session to record emergency audio. NAZR does not access or record audio during normal app usage or outside an active SOS. Audio recordings are securely shared with the user’s designated guardians or emergency contacts and retained for approximately 2 years.
Please note that a recording made during an emergency may include the voices of people other than the user. Responsibility for the lawful use of any such recording rests with the user as the account holder; NAZR facilitates capture and secure sharing only with the user’s own designated guardians.
9. Device Information
We may collect:
- Device model
- Device identifiers
- Operating system version
- Language preferences
- Network information
10. Vehicle & Trip Information
If the user uses Shield Mode’s journey tracking, they may optionally provide a vehicle number and vehicle photo, along with their destination and preferred check-in frequency. This information is shared only with the guardians selected by the user for that specific trip.
11. Usage & Diagnostic Information
We automatically collect crash reports, error logs, performance data, and usage statistics through Firebase Analytics, Firebase Crashlytics, and Firebase Performance Monitoring, to help us detect issues and improve the Services.
12. Notification Information
We process information necessary to send emergency alerts, push notifications, guardian notifications, and service communications, such as account, verification, and safety-related updates. The user may also receive optional promotional communications, which they can opt out of at any time.
13. How We Use Information
We may use the user’s information to:
- Create and manage user accounts
- Verify the user’s identity
- Deliver personal safety services
- Trigger and manage SOS alerts
- Verify and manage guardian relationships
- Monitor platform performance, detect fraud, abuse, or unauthorized use
- Comply with legal obligations
- Respond to support requests
14. Emergency Safety Features
When the user activates an SOS alert, the application may access their current location, continuously update location information during the emergency, notify their designated guardians, share emergency-related information with them, record and share audio evidence where enabled, and deliver alerts through applicable communication channels. Such processing is undertaken solely for safety and emergency response purposes.
An SOS may also be triggered without the user’s direct action in two circumstances. First, a guardian who believes something may be wrong can trigger SOS on the user’s behalf. Second, if the user misses a Shield Mode check-in and no guardian responds within 5 minutes — or no guardian is selected for that session — the app automatically triggers SOS. The first time a user activates Shield Mode, a one-time in-app notice explains both of these possibilities before the feature is used.
During an active SOS, the user’s live location, audio stream, and audio recordings are shared with all verified guardians in the user’s Trusted Circle in real time, through a secure web link, without requiring guardians to install the app. Guardians can view the user’s live location on a map, listen to live and recorded audio, and see the status of other guardians who have been alerted. This sharing continues for the duration of the active SOS and stops once the user marks themselves safe or the session is otherwise resolved.
15. App Permissions
- Location Permission — used for SOS alerts, live location sharing, guardian tracking, and emergency monitoring. Used in the foreground while the user is actively using the app, and in the background once the user has manually started Shield Mode or SOS, for the duration of that session only.
- Microphone Permission — used for emergency audio recording and safety evidence collection. Accessed only while an SOS is active; never used to record or monitor audio at any other time.
- Notification Permission — used for emergency alerts, safety notifications, and service communications.
- Camera Permission (if enabled) — used for user-initiated safety documentation and evidence collection, including capturing a photo for KYC verification, a guardian’s photo, or a vehicle’s photo.
- Photo Library / Media Permission (if enabled) — used to let the user select and upload an existing photo or document from their device’s gallery, for KYC document upload, guardian photo, or vehicle photo.
NAZR requests access to permissions only when necessary for specific features. By granting a permission, the user consents to the processing described in this Policy. The user may modify or withdraw permissions at any time through device settings; doing so may affect the availability of the dependent feature.
17. Third-Party Service Providers
We engage third-party providers to support the Services, including Google Maps Platform, Google Play Services, Firebase (Authentication, Cloud Messaging, Analytics, Crashlytics, Performance Monitoring), ZeptoMail (Zoho), Airtel SMS Platform, MarketBuzzer Teleservices, Cashfree Payments, Shopify, and cloud storage providers, covering cloud hosting, analytics, mapping and location services, push notifications, payments, and communication and security services. Such providers process information solely to support and enable the Services, subject to appropriate confidentiality and security obligations.
18. International Data Transfers
Our core infrastructure (including account data, location data, and KYC documents) is hosted in India. One exception: purchases of On Me and Sip Check are processed through Shopify, a platform based outside India, meaning order information for physical product purchases may be processed outside the country. We implement appropriate technical and organizational measures to protect information against unauthorized access, misuse, alteration, or destruction, including encryption in transit, encryption at rest, role-based access controls, authentication safeguards, and audit logging where applicable. Where any information is processed outside India, we take appropriate contractual and technical safeguards to ensure it receives an appropriate level of protection.
19. Data Retention
We retain personal information only for as long as necessary to provide and maintain the Services, deliver emergency and safety-related features, comply with legal obligations, resolve fraud and disputes, and enforce our agreements. In particular:
- KYC documents: retained while the user’s account is active, deleted within 30 days of an account deletion request
- SOS audio recordings: approximately 2 years from the date of recording unless a longer retention period is required by law or to establish, exercise or defend legal claims
- SOS incident records (location trail, guardian delivery log, nearest-help data): approximately 2 years from the incident
- Routine location history and check-in logs where no SOS occurred: 90 days
- Guardian contact details: until removed by the user, or by the guardian’s own request
20. Account Deletion
The user may request account deletion directly through Profile → Settings → Delete Account, or by emailing support@nazrco.in.
Upon a valid deletion request, the user’s KYC documents and personal identifying information are deleted within 30 days. Non-identifying usage history and any records tied to a past safety incident are retained for approximately 2 years from the relevant event, so that incident history remains available if needed even after the user’s account is closed.
21. User Rights
Subject to applicable law, the user has the right to access personal information, correct inaccurate information, request deletion of information, withdraw consent where applicable, and request information regarding how their data is processed.
The user may also have the right to file a complaint with the Data Protection Board of India. Requests may be submitted to: support@nazrco.in
22. Data Security
We implement appropriate technical and organizational measures to protect information against unauthorized access, misuse, alteration, or destruction, including encryption in transit, encryption at rest, role-based access controls, authentication safeguards, and audit logging where applicable.
23. Children’s Privacy
NAZR is not intended for individuals under 18 years of age. We verify age as part of our mandatory identity verification (KYC) process before any account is approved for use, and we do not knowingly approve accounts for individuals under 18.
24. Consent
Where we rely on the user’s consent — for example, location, microphone, or notification permissions, or identity verification during onboarding — we ask for it clearly and specifically at the relevant point in the app. The user may withdraw consent at any time through their device’s permission settings or by deleting their account; withdrawing consent for a permission will deactivate the feature that depends on it. Where the user opts in to promotional communications, they may withdraw this consent at any time without affecting their access to safety-related features.
Where the user withdraws consent, this may prevent us from providing safety features that depend on the relevant data, such as SOS or Shield Mode. Withdrawing consent does not affect the lawfulness of any processing carried out before the withdrawal.
25. Data Breach Notification
In the event of a personal data breach affecting the user’s information, we will notify affected users and the Data Protection Board of India without undue delay, as required by applicable law.
26. Grievance Officer
Name: Atul
Designation: Grievance Officer, NAZR
Email: support@nazrco.in
We will acknowledge complaints within 48 hours and endeavour to resolve them within 30 days of receipt.
27. Changes to this Policy
We may update this Privacy Policy from time to time. Updated versions will be posted on the application and website.
28. Contact Us
For privacy-related questions or concerns, please contact:
Email: support@nazrco.in
Lumina Hospitality Private Limited, 802, Harshvardhan, Opp. Saki Vihar Telephone Exchange, Mumbai – 400076
