Privacy Policy

Last updated: July 22, 2026

ReachBoost is a multi-tenant lead capture platform operated by Agreem Technologies that helps stores turn QR scans into WhatsApp conversations. This Privacy Policy explains what information we collect, how we use and protect it, how long we keep it, what happens in the unlikely event of a data breach, and the rights available to you under applicable law — including the (Indian) Digital Personal Data Protection Act, 2023, the Information Technology Act, 2000 and its rules, and, where applicable, the EU General Data Protection Regulation. In short: we collect only what the service needs, we keep it secure, and we never sell or share your personal information with third parties for their own purposes.

1. Scope and Who We Are

This policy applies to the ReachBoost website, web application, store capture pages, and related services (together, the "Service"). The Service is developed and operated by Agreem Technologies, Ahmedabad, Gujarat, India ("ReachBoost", "we", "us", "our").

This policy covers three groups of people:

  • Store users — owners, admins, and staff who hold ReachBoost accounts;
  • Leads / end customers — individuals who submit their details through a store's QR capture page;
  • Visitors — anyone browsing our public website.

By using the Service you acknowledge this policy. If you do not agree with it, please do not use the Service.

2. Definitions

  • Personal Data — any data about an individual who is identifiable by or in relation to such data (e.g., name, phone number, email address).
  • Data Fiduciary / Controller — the entity that determines the purpose and means of processing personal data.
  • Data Processor — an entity that processes personal data on behalf of a Data Fiduciary/Controller.
  • Data Principal / Data Subject — the individual to whom personal data relates.
  • DPDP Act — the (Indian) Digital Personal Data Protection Act, 2023.
  • IT Act — the (Indian) Information Technology Act, 2000, including the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 ("SPDI Rules").
  • GDPR — the EU General Data Protection Regulation (EU) 2016/679, where applicable to users in the European Economic Area or the UK.

3. Our Role: Fiduciary and Processor

Our role differs depending on whose data is involved:

  • For store account data (your name, email, password, store settings), ReachBoost acts as the Data Fiduciary / Controller.
  • For lead data submitted through a store's capture page (a customer's name and phone number), the store is the Data Fiduciary / Controller — it determines why and how that data is used — and ReachBoost acts as a Data Processor, processing the data solely to deliver the lead to that store and display it in that store's dashboard.

Stores are contractually required (see our Terms of Use) to use lead data lawfully, obtain any required consent, and honor deletion and opt-out requests.

4. Information We Collect

  • Account information — name, email address, and password when a store owner or team member creates an account. Passwords are never stored in plain text.
  • Store configuration — store name, branding (logo, colors, content), and the WhatsApp number leads should be delivered to.
  • Lead information — the name and phone number a customer enters on a store's QR capture page, together with the store it was submitted to and the time of submission.
  • Usage and technical data — log data such as IP address, browser and device type, pages viewed, and timestamps, used for security, debugging, and service improvement.

We do not collect sensitive personal data (such as financial information, health data, biometric data, caste, religious beliefs, or government identifiers) and ask that you do not submit such data through the Service.

5. Purposes and Legal Bases for Processing

We process personal data only for the following purposes:

  • Delivering the Service — routing captured leads to the correct store's WhatsApp and dashboard (basis: consent of the lead at the point of submission; performance of contract with the store).
  • Account management — authentication, role-based access, and team administration (basis: performance of contract).
  • Security and integrity — preventing fraud, abuse, and unauthorized access (basis: legitimate interest / legitimate uses under the DPDP Act).
  • Service communications — messages about your account, security, or material changes to the Service (basis: performance of contract / legitimate interest).
  • Legal compliance — meeting obligations under applicable law (basis: legal obligation).

We do not use personal data for third-party advertising, automated decision-making with legal effects, or profiling, and we do not process it for purposes incompatible with those listed above.

6. Data Security

We implement reasonable security practices and procedures as required by Section 43A of the IT Act and the SPDI Rules, and technical and organisational measures consistent with the DPDP Act and, where applicable, Article 32 of the GDPR. These include:

  • Encryption in transit — all data exchanged with ReachBoost is encrypted using HTTPS/TLS.
  • Password protection — account passwords are hashed with Argon2, a modern industry-standard algorithm, and are never stored or transmitted in plain text.
  • Tenant isolation — ReachBoost is multi-tenant by design; every query is scoped to a single store, so one store can never access another store's leads, settings, or team data.
  • Role-based access control — team members can only see the data their role requires; administrative access within our own team is restricted on a need-to-know basis.
  • Data minimisation — we collect only the minimum information needed to operate the Service.
  • Secure development and operations — dependency updates, environment separation, secrets management, and logging/monitoring to detect anomalous activity.
  • Backups — periodic backups with restricted access, to protect against data loss.

No method of transmission or storage is 100% secure, and we cannot guarantee absolute security; however, we continuously review and improve our safeguards.

7. Data Breach Notification and Incident Response

We maintain an incident response process for suspected or actual personal data breaches:

  • Detection and containment — on becoming aware of a suspected breach we promptly investigate, contain the incident, and preserve evidence.
  • Assessment — we assess the nature and scope of the breach, the categories and approximate number of individuals affected, and the likely consequences.
  • Regulatory notification — where required, we will report the incident to the Indian Computer Emergency Response Team (CERT-In) within the timelines prescribed under the CERT-In directions issued under Section 70B of the IT Act, and notify the Data Protection Board of India as required by the DPDP Act. For users subject to the GDPR, we will notify the competent supervisory authority within 72 hours where the breach is likely to result in a risk to individuals' rights.
  • User notification — we will notify affected users (and, for lead data, the affected stores) without undue delay, describing the nature of the breach, the data involved, the likely impact, the measures taken, and steps individuals can take to protect themselves.
  • Remediation — we perform a post-incident review and implement corrective measures to prevent recurrence.

8. We Do Not Sell or Share Your Data

We will never sell, rent, or trade your personal information. Lead details submitted through a capture page are shared only with the store whose QR code the customer scanned — that is the entire purpose of the submission. Beyond that, we disclose information only:

  • to trusted infrastructure providers (such as hosting, database, and messaging services) strictly so they can operate the Service on our behalf, under contractual confidentiality and data protection obligations;
  • when required by law, regulation, court order, or a lawful request by a government or law enforcement authority with jurisdiction, including under the IT Act;
  • to protect the rights, property, safety, or security of ReachBoost, our users, or the public; or
  • in connection with a merger, acquisition, or asset sale, in which case the successor remains bound by commitments at least as protective as this policy and affected users will be notified.

Third parties never receive your data for their own marketing or any independent use.

9. International Data Transfers

Our primary operations and data storage are in India. If personal data is transferred to or processed in another country (for example, where an infrastructure provider operates data centres abroad), we ensure the transfer complies with applicable law — including any restrictions notified by the Central Government under the DPDP Act, and, for GDPR-covered data, appropriate safeguards such as standard contractual clauses.

10. Data Retention and Deletion

  • Account data is retained while the account remains active and for a short administrative period after closure.
  • Lead data is retained while the associated store account is active so the store can access its lead history, or until the store or the lead requests its deletion.
  • Log and technical data is retained for a limited period consistent with security needs and applicable CERT-In log retention requirements.

When retention is no longer required — because the purpose is served, consent is withdrawn, or an account is deleted — personal data is deleted or anonymised from active systems within a reasonable period, and from backups on their normal expiry cycle, except where a longer retention is required by law.

11. Your Rights

Subject to applicable law (including the DPDP Act and, where applicable, the GDPR), you have the right to:

  • Access — obtain a summary of the personal data we process about you and the processing activities involved;
  • Correction and completion — have inaccurate or incomplete data corrected or updated;
  • Erasure — request deletion of your personal data;
  • Withdraw consent — withdraw previously given consent at any time, with effect for the future;
  • Grievance redressal — raise a complaint with us and receive a timely response (see Section 14);
  • Nominate — under the DPDP Act, nominate another individual to exercise your rights in the event of death or incapacity;
  • GDPR-specific rights — where the GDPR applies: data portability, restriction of processing, objection to processing, and the right to lodge a complaint with a supervisory authority.

To exercise any of these rights, email us at info@agreemtech.com. We may need to verify your identity before acting on a request. If you submitted your details through a store's capture page, you may also contact that store directly, as it controls the leads it collects; we will assist the store in fulfilling your request. If you remain unsatisfied, you may complain to the Data Protection Board of India (or your local supervisory authority under the GDPR).

12. Cookies and Local Storage

ReachBoost uses only essential browser storage (such as an authentication token) to keep you signed in and the Service working. We do not use third-party advertising or tracking cookies. You can clear stored data through your browser settings, though this will sign you out.

13. Children's Privacy

The Service is intended for business use and is not directed at children. We do not knowingly collect personal data from children under 18 (the age of majority under the DPDP Act) without verifiable parental consent, and we do not undertake tracking, behavioural monitoring, or targeted advertising directed at children. If you believe a child has provided us personal data, contact us and we will delete it.

14. Grievance Officer

In accordance with the IT Act, the SPDI Rules, and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, grievances relating to this policy or the handling of personal data may be addressed to our Grievance Officer:

  • Grievance Officer — Agreem Technologies, Ahmedabad, Gujarat, India
  • Email info@agreemtech.com

We acknowledge grievances promptly and aim to resolve them within the timelines prescribed by applicable law.

15. Changes to This Policy

We may update this policy from time to time to reflect changes in the Service or in applicable law. When we do, we will revise the "Last updated" date above and, for material changes, provide additional notice through the Service. Continued use of the Service after changes take effect constitutes acceptance of the updated policy.

16. Governing Law and Jurisdiction

This policy is governed by the laws of India, including the IT Act and the DPDP Act. Subject to any mandatory rights you have under the data protection law of your place of residence, the courts at Ahmedabad, Gujarat, India shall have exclusive jurisdiction over disputes arising out of or relating to this policy.

17. Contact Us

Questions about this policy or how we handle your data? Email us at info@agreemtech.com. You can also review our Terms of Use.