Privacy Policy

Effective Date: September 10, 2025
Last Updated: September 10, 2025
Version: 1.0 (DPDP Act 2023 Compliant)

🛡️ Privacy-First Commitment

In-Hand.in is designed with privacy as a fundamental principle. We employ advanced privacy-preserving technologies including daily-salted visitor fingerprints, immediate IP address disposal, and user-controlled data collection levels. You have complete control over what data we collect about you.

1. Who We Are

In-Hand.in ("we," "us," "our") is operated by the In-Hand.in team as a free salary calculation service for Indian employees. This privacy policy explains how we collect, use, protect, and handle your personal data in compliance with the Digital Personal Data Protection Act, 2023 (DPDP Act) and international privacy standards.

Data Fiduciary Information

Under the DPDP Act 2023, we act as a "Data Fiduciary" for any personal data we process. Our responsibilities include ensuring lawful processing, protecting your data, and respecting your privacy rights.

2. Information We Collect

We operate on a privacy-first, data minimization principle. We only collect data that is necessary for providing our salary calculation service.

2.1 Basic Service Data (Collected for All Users)

Data Category Purpose Privacy Protection
Salary Calculation Inputs
CTC, tax deductions, basic salary mode
Performing salary calculations and showing results Not linked to your identity; used for aggregate statistics only
Device Information
Device type (mobile/desktop), screen size
Optimizing user interface for your device No unique device identification; basic categorization only
Location Data
City, State (derived from IP)
Providing relevant tax information and city-specific features IP address immediately hashed and discarded; only city-level location retained
Session Information
Daily-salted session identifier
Preventing abuse and understanding usage patterns Daily rotation ensures no persistent tracking across days

2.2 Enhanced Experience Data (Optional, Requires Your Consent)

You can choose to enable enhanced features that collect additional data:

  • Account Information: Name, email, company details (if you create an account)
  • Calculation History: Your past calculations for comparison features
  • User Interface Interactions: How you use different features (for improving user experience)
  • Help Usage Data: Which help topics you access (for improving documentation)

2.3 What We DON'T Collect

  • Raw IP Addresses - Immediately hashed and discarded
  • Personal Identifiers - No PAN, Aadhaar, or government IDs
  • Financial Account Information - No bank account or credit card details
  • Browser Fingerprints - No unique device tracking
  • Third-Party Cookies - No advertising or tracking cookies
  • Social Media Data - No integration with social platforms

3. How We Use Your Information

3.1 Primary Purposes (Legitimate Interest)

  • Service Delivery: Calculate your take-home salary from CTC
  • Service Improvement: Understand which features are most useful
  • Security: Prevent abuse and ensure service reliability
  • Compliance: Meet legal obligations under Indian tax and data protection laws

3.2 Enhanced Features (With Your Consent)

  • Personalized Experience: Save your preferences and calculation history
  • Comparison Reports: Compare multiple salary scenarios
  • Usage Analytics: Understand how features are used to improve UX

4. Legal Basis for Processing (DPDP Act 2023)

Processing Activity Legal Basis Your Control
Basic salary calculations Legitimate interests (service provision) Use our privacy-first mode (default)
Account creation and management Consent Opt-in during registration
Enhanced tracking and analytics Consent Enable/disable in privacy settings
Service improvement analytics Legitimate interests Anonymized data only

5. Privacy Levels & User Choice

We offer two distinct privacy levels, giving you complete control:

5.1 Privacy-First Mode (Default)

🛡️ Maximum Privacy Protection

  • Daily-rotated visitor identifiers (no persistent tracking)
  • Immediate IP address hashing and disposal
  • No cross-session data linking
  • Minimal data collection for basic functionality
  • Automatic data expiration

5.2 Enhanced Experience Mode (Opt-in)

⚙️ Additional Features with More Data

  • Account creation and login
  • Calculation history and comparison reports
  • Personalized insights and recommendations
  • Usage analytics for feature improvement
  • Cross-session continuity

You can switch back to Privacy-First mode at any time.

6. Data Storage and Security

6.1 Data Storage Location

Your data is stored on secure servers located in India, ensuring compliance with data localization requirements under Indian law.

6.2 Security Measures

  • Encryption: All data encrypted in transit (HTTPS) and at rest
  • Access Controls: Strict access controls with regular audits
  • IP Protection: SHA-256 hashing of IP addresses before storage
  • Session Security: Secure session management with CSRF protection
  • Regular Updates: Continuous security monitoring and updates

6.3 Data Retention Periods

Data Type Retention Period Reason
Basic calculation data (anonymous) 90 days Service improvement and abuse prevention
Account information Until account deletion Account management and service provision
Usage analytics (anonymized) 2 years Long-term service improvement
Error logs (no personal data) 30 days Technical debugging and security

7. Your Rights Under DPDP Act 2023

As a data principal under the DPDP Act 2023, you have the following rights:

  • 🔍 Right to Information
    Know what personal data we have about you and how it's being used.
  • ✏️ Right to Correction
    Request correction of inaccurate or incomplete personal data.
  • 🗑️ Right to Erasure
    Request deletion of your personal data when it's no longer needed.
  • ⚙️ Right to Data Portability
    Receive your data in a structured, machine-readable format.
  • 🛑 Right to Withdraw Consent
    Withdraw consent for enhanced tracking at any time.
  • 📢 Right to Grievance Redressal
    File complaints about data processing practices.

How to Exercise Your Rights

You can exercise these rights by:

  • Using the privacy controls in our calculator interface
  • Sending an email to our Data Protection Officer (details below)
  • Using the account settings if you have created an account

We will respond to your requests within 30 days as required by the DPDP Act.

8. Data Sharing and Third Parties

🚫 We Do Not Share Your Personal Data

We do not sell, rent, or share your personal data with third parties for marketing purposes.

Limited Data Sharing (Only When Required by Law)

We may share data only in these specific circumstances:

  • Legal Compliance: When required by Indian courts or regulatory authorities
  • Service Providers: Essential service providers (hosting, security) under strict data processing agreements
  • Business Continuity: In case of business transfer, with user notification

No International Transfers

Your data remains within India. We do not transfer personal data to other countries.

9. Children's Privacy

Our service is intended for employed adults. We do not knowingly collect data from children under 18. In compliance with the DPDP Act 2023:

  • We do not process children's data without verifiable parental consent
  • We do not engage in behavioral monitoring of children
  • We do not serve targeted advertisements to children
  • If we become aware of child data, we delete it immediately

10. Data Breach Notification

In the unlikely event of a data breach:

  • We will notify the Data Protection Board within 72 hours
  • Affected users will be notified promptly if there's a risk to their rights
  • We will provide clear information about the breach and remedial actions
  • We maintain incident response procedures to minimize impact

11. Cookies and Tracking Technologies

Essential Cookies Only

We use minimal, essential cookies for:

  • Session Management: Maintaining your calculator session
  • Security: CSRF protection and security measures
  • Privacy Preferences: Remembering your privacy choices

We do not use:

  • ❌ Advertising cookies
  • ❌ Social media tracking pixels
  • ❌ Third-party analytics cookies
  • ❌ Cross-site tracking

12. Updates to This Privacy Policy

We may update this privacy policy to reflect:

  • Changes in Indian data protection laws
  • New features or services
  • Improved privacy practices
  • User feedback and recommendations

We will notify you of significant changes by:

  • Updating the effective date at the top of this policy
  • Showing a notification in our calculator interface
  • Emailing registered users (if applicable)

13. Contact Information

Data Protection Officer

Email: guru@in-hand.in
Response Time: Within 30 days as per DPDP Act 2023

General Inquiries

Email: guru@in-hand.in
Website: https://www.in-hand.in

Grievance Redressal

For complaints about data processing practices:
Email: guru@in-hand.in
Subject Line: "DPDP Act Grievance - [Your Concern]"

Postal Address

In-Hand.in Privacy Team
[To be updated with actual business address]
India

14. Compliance Statement

This privacy policy is designed to comply with:

  • Digital Personal Data Protection Act, 2023 (India)
  • Information Technology Act, 2000 (India)
  • International privacy standards including GDPR principles
  • Industry best practices for financial data protection

By using In-Hand.in, you acknowledge that you have read, understood, and agree to this Privacy Policy and our commitment to protecting your personal data.