CloudMessYour mess. Simple. मराठी Send “Hii”
CloudMess
Just send “Hii” on WhatsApp

Your data

CloudMess Privacy Policy

  • Effective date 2026-09-26
  • Last updated 2026-09-26
What changed on 2026-09-26

We rewrote this policy so that it describes exactly what CloudMess does today. It now explains who is responsible for which data (your mess owner for the records your mess keeps about you, and us for your CloudMess account), lists the kinds of service providers we use, what each receives and where, and states plainly which deletions we do by hand. We also named our Grievance Officer, added the complaint timelines the IT Rules require, and added our website and our support channels. We collect nothing new.

CloudMess is made and run by INFIWORKS TECHNOLOGIES PRIVATE LIMITED (CIN U62090ME2026PTC476551; registered office: At 438, Shidod, Shidode, Bid, Beed – 431122, Maharashtra, India), “InfiWorks”, “we”, “us”. This policy covers the CloudMess apps — CM Owner, for mess owners, and the CloudMess member app — and our website, cloudmess.in.

It is written for India’s Information Technology Act, 2000 and its rules (the 2011 rules on sensitive personal data and the 2021 Intermediary Rules), and for the Digital Personal Data Protection Act, 2023 (“DPDP Act”) and its rules, whose duties for businesses begin on 13 May 2027. This policy applies them already. For any question or request, write to our Grievance Officer (§11).


Responsibility

1. Who is responsible for your data

Two parties are responsible for different parts of your data.

  • Your mess owner decides what to record about you in CloudMess, and why: your membership, meal scans, daily survey answers, tiffin, parcel and leave records, payments and dues, and any notes. For these records your mess owner is the “Data Fiduciary” (the one responsible under Indian data-protection law), and we process them on the owner’s behalf, as the owner’s “Data Processor”, under our Terms of Service.
  • We (InfiWorks) are responsible for your CloudMess account (how you sign in, and your consent and age confirmation), notifications, crash reports and security records, our website, our support conversations, and mess owners’ subscriptions with us. For these we are the Data Fiduciary.

You can bring any question or request to us, whichever part it concerns. If it is about records your mess keeps, we deal with it together with your mess owner.


Collection

2. What we collect

CategoryWhatWhy
Sign-in (members)Your Indian mobile number (+91), and an internal sign-in IDTo sign you in with a one-time code sent by SMS
Sign-in (mess owners)Your email address, and your password stored only as a scrambled hash (see §7)To sign you in
ProfileName, gender, and your language and time-format choicesSo your mess can identify you, and to show the app the way you want
Consent recordsWhen you agreed to these terms and confirmed you are 18 or older; for members an owner adds, when the owner confirmed you are 18 or older and agreed to be addedTo show that you agreed, and when
Membership (recorded by your mess)Plan, diet type, start and end dates, monthly fee, meals used, pauses and leave, and any reason given for themTo run your membership
Meals (recorded by your mess)QR scans, daily survey answers, tiffin and parcel records (including the name of a friend who collects a parcel for you), and missed mealsSo your mess knows how much to cook and can count your meals correctly
Payments and dues (recorded by your mess)Amounts, dates, UPI transaction references and any note the owner addsTo keep your mess’s accounts and settle disputes
Owner’s notesFree-text notes a mess owner writes on a member’s record, which only the owner seesFor the owner’s own service notes
Join requestsThe name, phone number and gender you send when you ask to join a messSo the owner can accept you
Mess details (mess owners)Mess name and code, city, address, capacity, contact number, the mess’s UPI ID, notices to members, and the settings the owner choosesTo run the mess on CloudMess, and to let members pay the mess by UPI
NotificationsThe notifications we send you, kept for your in-app inboxSo you can read them again
Technical and security dataYour device’s notification token; the IP address of each login-code request and of each sign-in session, with the device type; crash reports (see §5)To deliver notifications, prevent misuse and fix crashes

We do not:

  • run analytics of any kind (no screen tracking, feature-usage events or profiling). If we ever add analytics, we will ask for your consent first;
  • access your location, contacts or microphone. The member app uses the camera only when you open the scanner, and we store no photos;
  • collect members’ own bank, card or UPI details. We store only the mess’s UPI ID, so that members can pay the mess;
  • collect data about you from anywhere else, apart from what your mess owner records.

Notes and reasons are free text. Mess owners must not record health details (such as allergies), religion or caste, bank or card details, or passwords in them, and members should not include such details either.


Use

3. How we use it, and on what legal basis

We use personal data only to:

  1. 1Run your account — sign you in (members with a one-time code, mess owners with an email address and password) and keep your settings.
  2. 2Run your mess’s service — record meals, run the daily survey, handle tiffins, parcels and leave, and track dues, on your mess owner’s behalf.
  3. 3Tell you what you need to know — push notifications and your in-app inbox. SMS is used only to send login codes.
  4. 4Keep CloudMess safe — prevent misuse, fix faults and crashes, and keep a record of sensitive actions.
  5. 5Meet legal duties — answer lawful orders and keep the records the law requires.

We never use your data for advertising, and we never sell it.

Legal basis

ProcessingBasis
Your CloudMess account, notifications and crash reports (members)Your consent: you tap I Agree & Continue and confirm you are 18 or older when you first sign in
Mess-owner accountsYour consent: when we set up your account, we ask you to confirm in writing (by email or WhatsApp) that you accept these terms, including our holding your password as a hash. The 2011 rules treat passwords as sensitive data
Records your mess keeps about youYour mess owner’s basis: you gave your details to the mess to run your membership (DPDP Act, section 7(a)). Your mess owner is responsible for telling you how the mess uses CloudMess
Records the law makes us keep, and answers to lawful ordersLegal obligation

When a member signs in for the first time, we create the account with their phone number just before showing the consent screen. If you do not agree, we use that account for nothing else, and we delete it when you ask; see Delete your account.


Access

4. Who can see your data

  • Your mess owner can see everything your mess records about you (the table in §2), including notes, leave and pause reasons, parcel pickup names, the notifications sent to you, and your sign-up and consent dates — for the mess you are currently a member of.
  • You can see your own data. You cannot see other members’ data, or the notes your owner writes about you. To learn what those notes say, ask us (§11) and we will tell you.
  • Owners of other messes cannot see your data.
  • At InfiWorks, only our founder has access, and uses it only where needed: to run the service, fix faults, answer your requests (including deletion), reset an owner’s password at their request, suspend a mess that breaks our terms, or meet a legal duty. Actions taken in our admin console, including viewing a mess, are written to a permanent log.

When you switch from one mess to another (Settings → Switch mess), your records stay with the old mess for its accounts, hidden from the new mess and from you. Our servers enforce this, whatever app is used.


Providers

5. Service providers, and where your data is processed

ProviderWhat it receivesWhere
Cloud database provider: our database, sign-in and server functionsAll app dataThe database is in India (Mumbai). Its logs, support and some of its own providers may be outside India
SMS providers: send login codesYour phone number and the login codeMay be outside India
Google Firebase Cloud Messaging: delivers push notificationsYour device’s notification token, and each notification’s title and text, which can include your name and amountsOutside India, including the United States
Google Firebase Crashlytics: crash reportsWhat the app was doing when it crashed (which can include the text of an error), your device model and system, and an ID for your app installation. Not linked to your name or phone number. Kept for 90 daysOutside India, including the United States
Website hosting and security provider: delivers our website, cloudmess.inThe data every browser sends (see §10)Outside India, including the United States and Europe

Our database provider and Google process this data for us under data-processing terms. Some providers also use limited technical data for their own purposes under their own policies, for example to run and secure their networks. If you ask, we will tell you the names of our providers. Google Play, which installs the apps, is run by Google under Google’s own privacy policy; it is not our provider.

The DPDP Act allows personal data to be processed outside India, except in countries the Government restricts (section 16). No such restriction applies to these providers today.


Retention

6. How long we keep it

DataHow long
Login-code requests, with their IP addressDeleted automatically after 24 hours
Your CloudMess account: sign-in details, profile and consent recordsWhile your account is open. After you close it, 180 days, as the IT Rules require, then deleted
Records your mess keeps about you (membership, meals, payments, notes, join requests)For as long as your mess keeps them on CloudMess. Your mess owner decides, within the law. If you ask us to delete your data, we remove your name and phone number from them, unless your mess must keep them by law (for example, payment records for its accounts)
A mess’s records, when the mess leaves CloudMessWe give the owner a copy if they ask, then delete the records within 90 days, except what the law requires us to keep
Your in-app notificationsWhile your account is open
Your notification tokenUntil your phone replaces it, or your account is closed
Sign-in session records (IP address, device type)Kept by our database provider while the session exists
Crash reports90 days, at Google
Our admin console log (for example, when we create or suspend a mess, including the email address an owner account was created with)Permanently, as our accountability record
Mess owners’ subscription payments to us (kept in our own accounts)8 years, as Indian tax law requires

Today we do most deletion by hand, within the times above. From 13 May 2027, the DPDP rules also require personal data and records of its processing to be kept for at least one year, so nothing will be deleted sooner than that.


Security

7. Security

  • All traffic between the apps and our servers is encrypted.
  • Our servers enforce who can read what, so no one can read data that is not theirs, even with a changed app.
  • Login codes are stored only as a scrambled hash and deleted after 24 hours. The code itself goes only to your phone, through our SMS provider.
  • Mess-owner passwords are stored only as a scrambled hash. We set your first password with you at your setup visit and keep no copy of it. To change it, ask us and we will set a new one with you.
  • Sign-in sessions use signed tokens that expire and are refreshed.
  • Sensitive actions, such as payments being recorded or corrected, member changes and mess switches, are recorded in an activity log that your mess owner can see.
  • We never ask for your login code, password or UPI PIN.

If we ever discover a breach that affects your personal data, we will:

  • tell you without delay, in plain language: what happened, which of your data was involved, what we have done and what you can do; and tell your mess owner where it involves the mess’s records;
  • report it to the Data Protection Board of India, first without delay and then in detail within 72 hours of becoming aware of it, as the DPDP rules require from 13 May 2027;
  • report it to CERT-In, India’s national cyber-incident agency, within 6 hours of noticing it, as directions under the IT Act require.

Your rights

8. Your rights

The DPDP Act gives you these rights from 13 May 2027, and we honour them already. You can ask us to:

  • show you your data — a summary of what we hold about you, how it is used, and who it has been shared with;
  • correct it — you can change your name and gender yourself in Settings. For anything else, ask your mess owner, or ask us;
  • delete it — see Delete your account for how, and §6 for what the law makes us keep;
  • stop using it — turn off notifications in your phone’s settings for CloudMess (login codes and your in-app inbox still work), or withdraw your consent by asking us to delete your account. Withdrawing does not affect what was done before;
  • record a nominee — someone who can use these rights for you if you die or become unable to act. Send us their name and phone number;
  • resolve a complaint about how your data is handled.

To use any of these, email, WhatsApp or write to our Grievance Officer (§11). Give the mobile number you sign in with (members) or write from the email address you sign in with (mess owners), so that we can find your account. We may ask you to confirm the request is yours. It costs nothing.

  • Requests (a copy of your data, a correction, a deletion, a nominee): we answer within 30 days.
  • Complaints: we acknowledge within 24 hours and resolve within 7 days. The IT Rules set faster times for some content complaints; see our Terms §12.

If you are not satisfied, you can appeal to the Grievance Appellate Committee (gac.gov.in) within 30 days of our decision, and, from 13 May 2027, complain to the Data Protection Board of India. The DPDP Act asks you to use our process first.


Children

9. Children

CloudMess is for people aged 18 and over. Members confirm their age when they first sign in, and owners confirm it for each member they add.

If you are under 18, please do not create an account. A parent or guardian using the app “on your behalf” does not change this. Ask your mess owner to handle your membership without an app account. Mess owners must not add anyone under 18 to CloudMess.

If we learn that CloudMess holds a child’s data, we will delete it and tell the mess owner. We never track children or show them advertising.


Our website

10. Our website, cloudmess.in

  • Our website hosting provider receives the data every browser sends: your IP address, the page you asked for, the time, and your browser type and language. It uses this to deliver the pages and protect the website. We do not receive these records.
  • There are no cookies, no analytics, no advertising and no tracking. Fonts and images come from the website itself.
  • If a page fails to load, your browser may send our hosting provider a short error report so that it can find network faults. The provider says these reports do not identify you.
  • Our WhatsApp buttons start your message with a short tag, such as “(Web)”, so that we know you came from our website. You can edit or delete it before you send.
  • The Google Play button takes you to Google Play, which is run under Google’s own privacy policy.
  • When you follow a link to another website, your browser tells it only that you came from cloudmess.in, not which page.

Contact

11. Contact and Grievance Officer

Grievance Officer
Sujit Kadam, Founder
Email
contact@infiworks.co.in
Phone and WhatsApp
+91 74834 01547
Post
INFIWORKS TECHNOLOGIES PRIVATE LIMITED, At 438, Shidod, Shidode, Bid, Beed – 431122, Maharashtra, India
CIN
U62090ME2026PTC476551

Our Grievance Officer answers questions about how we handle personal data and handles requests and complaints, within the times in §8. We are not a Significant Data Fiduciary under section 10 of the DPDP Act, so the law does not require us to appoint a Data Protection Officer; our Grievance Officer answers for us, as section 8(9) requires.

What we do with the messages, calls and emails you send us is explained in the InfiWorks privacy policy, www.infiworks.co.in/privacy. If you would like this policy explained in Marathi or Hindi, contact us and we will help.


Changes

12. Changes to this policy

When we change this policy, we update the dates at the top and summarise what changed in a note below them. The current version is always at cloudmess.in/privacy. The copy inside the apps (Settings → Privacy Policy) is updated with each app release.

Where the law requires your fresh consent for a change, we will ask for it before the change applies to you.

This policy is binding on us. If it conflicts with anything we have said elsewhere, such as in marketing or support messages, this policy wins.

Back to the top