Privacy Policy
Effective 2026-08-11
We wrote this to be read, not just filed away. It covers what we collect, why we collect it, and what you can do about it. If anything here is unclear, just email us and we’ll explain it like a person.
NamoID is operated by PolyMindsLabs Pvt. Ltd. For this website and for NamoID customer accounts, PolyMindsLabs Pvt. Ltd. is the Data Fiduciary.
Two kinds of user
If you signed up at namoid.in to use NamoID for your own application, you're a customer and we're your Data Fiduciary.
If you signed into someone else's app via NamoID, you're an end-user. The controlling privacy policy is the one published by that app. We process your data on their behalf.
What we collect
From customers: account email, full name, hashed password, MFA enrolment metadata, your org / project / OAuth-client configurations, login history, audit events.
From end-users signing into customer apps: identifiers (email/phone), profile fields the customer asked for, authentication credentials (WebAuthn public keys, encrypted TOTP secrets, backup-code hashes), provider links (encrypted upstream tokens), OAuth resource grants, and session metadata.
The current Aadhaar offline-XML verification endpoint validates submitted signed data and returns the parsed result without creating a persistent verification record. This is not a claim that NamoID is an approved UIDAI authentication provider.
Why we collect it (§5)
We process each category of personal data for a specific, limited purpose:
| Data | Purpose |
|---|---|
| Email, name, password hash | Authenticate you and secure your account. |
| MFA / passkey credentials | Provide strong, phishing-resistant sign-in. |
| Org / project / client config | Run the service you set up. |
| Login history, audit events | Security, fraud investigation, and DPDP audit obligations. |
| End-user identifiers + profile fields | Sign users into the customer app they chose. |
| OAuth resource grants | Record and revoke the resource scopes a user approved. |
| Demo-booking / enquiry details | Respond to your request and follow up. |
Where the data lives
NamoID’s primary production identity infrastructure runs in AWS Mumbai. Product analytics uses PostHog Cloud in its EU region; optional website analytics uses Google Analytics 4 only after you give analytics-cookie consent. Some processing reaches servers outside India, in each case limited to what the feature needs:
- Social login. Clicking "Continue with Google / GitHub / LinkedIn" sends the OAuth handshake to their (US-based) servers; the profile returns in-country.
- OTP & phone verification. Depending on the channel your customer enables (SMS, WhatsApp, or Truecaller), message delivery and number lookup may use providers located outside India.
- Booking a demo. Opens Calendly (US-based), which processes the name, email, and scheduling details you enter.
- Analytics. Pseudonymous product events and masked session replays are processed by PostHog in its EU region. Inputs, visible text, identifiers, secrets, and full URLs are removed or masked before transmission. Aggregate marketing-site events are processed by Google Analytics under the public-site consent controls.
We transfer personal data outside India only as permitted under §16 of the DPDP Act and only to deliver the feature you or your customer chose.
Who we share with
- The customer whose app you signed into: the fields you consented to at sign-in.
- Cloud hosting (in-country region).
- Managed transactional email + SMS providers, for sending OTPs.
- PostHog (EU region), for pseudonymous product analytics and masked session replay.
- Google Analytics, for aggregate public-site usage.
- Upstream OAuth providers: only what you authorise at their consent screen.
- DigiLocker or UIDAI services only when the relevant customer integration is configured and you initiate that flow.
- Calendly (US), if you book a demo: it receives the contact and scheduling details you submit on their booking page, under their own privacy policy.
- Law enforcement, when compelled by valid Indian legal process.
We don't sell your data, ever, and run no advertising or cross-site tracking. Signed-in Console analytics uses a pseudonymous browser identifier and never receives your email, NamoID user ID, tenant ID, form values, or secrets. Google Analytics is limited to aggregate marketing-site usage, with cookies and richer measurement requiring consent (details below).
Cookies
We set a small number of strictly-necessary cookies so the dashboard and hosted-login flow can sign you in: an HttpOnly session cookie, a CSRF token, and a hosted-flow state cookie that lives for the duration of an OAuth handshake. None of these are used for tracking; all are first-party.
For signed-in Console product analytics we use PostHog Cloud in its EU region. Console events are enabled without an additional consent popup because they measure use of the authenticated product and are described in this notice. We use pseudonymous browser profiles, automatic pageviews, click autocapture, and session replay. Replay masks all visible text and inputs; event processing removes email addresses, account and tenant identifiers, API keys, form values, full URLs, and user IDs. Root-tenant administration and automatic exception capture remain excluded. On the public marketing site, Google Analytics 4 does not load until you accept analytics cookies. We disable advertising signals and personalization. Allowlisted UTM campaign values are retained in temporary first-party session storage to preserve attribution while you navigate, and are discarded when the tab session ends.
How long we keep it
- Cookie-consent choice: in your browser until you clear it.
- Server / access logs: up to 90 days, then deleted.
- PostHog analytics events: up to 12 months, then purged from the EU-region project.
- Google Analytics measurement data: up to 14 months, subject to Google’s retention controls.
- Demo-booking and email enquiries: until the enquiry is resolved, or 24 months, whichever comes first.
- Grievance correspondence: 3 years, for regulatory record-keeping.
- Customer and end-user account data: for the life of the account. The current automated workflow marks the account deleted and records a tombstone event; it does not promise a statutory 30-day hard-deletion period. Contact us for erasure requests that require review across additional data stores or processors.
Children's data (§9)
We do not knowingly collect personal data from anyone under 18, except where a customer has enabled NamoID's parental-consent gate. Where that gate is enabled, we process a child's data only after verifiable parental consent (for example, via a DigiLocker-verified guardian). We do not carry out behavioural tracking, profiling, or targeted advertising on any user identified as a child, consistent with §9 of the DPDP Act.
Data breach notification (§8(6))
If a personal data breach affects your data, we will notify the Data Protection Board of India and the affected individuals without undue delay and in the manner prescribed by the Board, consistent with §8(6) of the DPDP Act. For breaches affecting an end-user of a customer's app, we notify the customer (the Data Fiduciary) so they can inform their users.
Your rights (DPDP §§11–14)
- Access (§11): ask what personal data we hold about you and how we use it.
- Correction & erasure (§12): correct, complete, or delete your data. We review requests across the relevant NamoID systems and processors. Some security, legal, and tombstone records may be retained where required or permitted.
- Grievance redressal (§13): raise a complaint with our grievance officer (below).
- Nomination (§14): nominate another person to exercise these rights on your behalf in the event of your death or incapacity. To register a nomination, email hello@namoid.in.
To exercise any of these, email hello@namoid.in. We acknowledge within 7 business days and aim to resolve within 30 days. If you signed into a customer's app, send rights requests to that customer; we'll help them fulfil it.
If your complaint is not resolved to your satisfaction, you may escalate it to the Data Protection Board of India, the statutory authority under the DPDP Act.
Grievance officer
Uddeshya Vijayvergiya, Grievance Officer, PolyMindsLabs Pvt. Ltd.
PolyMindsLabs Pvt. Ltd., Jaipur, Rajasthan 302020, India
Email: hello@namoid.in
Office hours: Mon–Fri 10:00–18:00 IST
Acknowledgement SLA: 7 business days · Resolution target: 30 days.
Changes to this policy
We will notify registered customers by email at least 30 days before a material change takes effect. If you have accepted analytics cookies and the policy changes materially, we will ask for your consent again.