iFixpert
Policy

Privacy Policy

Your device holds your life. Here is how we collect, use, and protect your data.

Last updated: 18 May 2026

Data Controller: iFixpert, Gurgaon, Haryana, India
Contact: contact@ifixpert.com | +91 87962 90111
Grievance Officer: contact@ifixpert.com (appointed under the Information Technology Act, 2000)


1. Introduction

iFixpert ("we", "us", "our") operates the website ifixpert.com and related mobile applications. This Privacy Policy explains how we collect, use, store, and protect your personal information when you book a repair service, contact us, or otherwise interact with our platform.

By using our services, you consent to the practices described in this policy. If you do not agree, please do not use our services.

2. Information We Collect

2.1 Information You Provide Directly

Booking Information:

  • Name, phone number, email address (optional), and delivery address
  • Device information: device model, colour, and IMEI or serial number (collected at intake)
  • Service preferences: repair type, parts grade, service mode (doorstep / pickup / carry-in), preferred slot
  • Payment records: method used (cash, UPI, card, netbanking, online), amount paid, transaction reference, and payment status
  • Booking notes or special instructions

Contact Form Submissions:

  • Name, phone number, email (optional), subject, and message body

Account Information:

  • If you book without an email, we create a passwordless account via Better-Auth using a synthetic email address (e.g., phone-XXXXXXXXXX@no-login.ifixpert.local). You will not interact with this email directly; it exists only to link your bookings to a single identity.

2.2 Information Collected Automatically

  • Cookies and similar technologies: We use first-party cookies to maintain your session, remember your preferences, and understand how visitors navigate our site. We do not use third-party advertising cookies.
  • Log data: Our hosting provider (Vercel) and backend platform (Convex) may automatically collect IP addresses, browser type, referring/exit pages, and timestamps for security and operational diagnostics.
  • Email interaction data: Our email service (Zoho ZeptoMail) tracks delivery status, opens, and clicks for transactional emails (booking confirmations, invoices) to ensure reliable delivery.

2.3 Information from Third Parties

We do not purchase or receive personal data from data brokers. The only third-party data we process is:

  • Authentication tokens from Better-Auth when you sign in
  • WhatsApp messages you initiate to our business number

3. Legal Basis for Processing (India & GDPR)

Under Indian law (IT Act 2000/2023) and, where applicable, GDPR, we process your data on the following bases:

  • Performance of a contract: To fulfil your repair booking (schedule, dispatch, invoice, warranty)
  • Consent: For promotional emails and newsletter subscriptions. You may withdraw consent at any time.
  • Legitimate interests: For fraud prevention, service improvement, and legal compliance
  • Legal obligation: To comply with tax, accounting, and consumer protection laws

4. How We Use Your Information

PurposeData Used
Process and schedule repairsName, phone, address, device details, slot preference
Communicate about your bookingPhone, email, WhatsApp
Send transactional emailsEmail, booking details
Process paymentsPayment method, amount, reference
Warranty administrationDevice IMEI, repair history, contact details
Customer supportAll data you provide
Service improvementAggregated usage patterns, feedback
Marketing (with consent)Email, name
Legal complianceAll categories as required

Auto-enrolment notice: If you provide a real email address during booking, we automatically add you to our newsletter subscriber list. You may unsubscribe immediately via the link in any promotional email or by contacting us.

5. Data Sharing and Third-Party Processors

We do not sell your personal data. We share data only with the following categories of processors under strict contractual obligations:

ProcessorPurposeLocation
Convex Inc.Database hosting, backend computation, file storageUnited States
Vercel Inc.Web application hostingUnited States
Zoho Corporation (ZeptoMail)Transactional and promotional email deliveryIndia / United States
Better-Auth (open-source library)Authentication infrastructureSelf-hosted / Convex

All processors are bound by data processing agreements requiring confidentiality and security safeguards.

6. Data Retention

  • Active bookings and customer records: Retained for 24 months from the date of your last booking to support warranty claims and repeat service.
  • Contact form messages: Retained for 12 months unless related to an active dispute.
  • Email logs: Retained for 12 months for deliverability diagnostics and compliance.
  • Newsletter subscribers: Retained until you unsubscribe, or until 24 months of inactivity, after which we delete your record.
  • Financial records: Retained for 7 years as required by Indian tax law.

After the applicable retention period, your personal data is either deleted or anonymised. You may request early deletion under the rights described in Section 8.

7. Data Security

We implement industry-standard measures to protect your data:

  • All data in transit is encrypted using TLS 1.2 or higher
  • Data at rest is encrypted by Convex using AES-256
  • Admin access requires authenticated login with role-based permissions
  • Payment details (card numbers, UPI PINs) are never stored on our servers. If you pay online, the transaction is handled by your chosen payment provider; we record only the method, amount, and reference.

8. Your Rights

Under Indian law and applicable data protection regulations, you have the right to:

  • Access: Request a copy of the personal data we hold about you
  • Correction: Request correction of inaccurate or incomplete data
  • Deletion: Request deletion of your personal data, subject to legal retention requirements
  • Objection: Object to processing for direct marketing purposes
  • Portability: Request your data in a structured, machine-readable format
  • Withdraw consent: Unsubscribe from promotional emails at any time

To exercise these rights, email contact@ifixpert.com. We will respond within 7 business days and complete the request within 30 days where feasible.

9. Cookies

We use the following categories of cookies:

CategoryPurposeDuration
EssentialSession management, booking flow, securitySession
PreferencesRemember your city or device model selection30 days
AnalyticsFirst-party page view analytics to improve UX30 days

You can disable cookies via your browser settings, but this may impair site functionality.

10. Children's Privacy

Our services are not directed at individuals under 18 years of age. We do not knowingly collect data from children. If you believe a child has provided us with personal data, contact us immediately and we will delete it.

11. Cross-Border Data Transfers

Your data is primarily stored on Convex's servers in the United States. By using our services, you consent to this transfer. We rely on standard contractual clauses and Convex's SOC 2 Type II compliance to ensure an adequate level of protection.

12. Changes to This Policy

We may update this Privacy Policy periodically. Material changes will be notified via email or a prominent banner on our website. The "Last updated" date at the top indicates the most recent revision.

13. Contact Us

For privacy-related questions, data requests, or grievances:

  • Email: contact@ifixpert.com
  • Phone: +91 87962 90111
  • WhatsApp: +91 87962 90111
  • Address: Gurgaon, Haryana, India

Grievance Officer: contact@ifixpert.com
Appointed under Section 79 of the Information Technology Act, 2000 and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021.

Chat with us