Last updated: 2026-09-10
Privacy Notice & Consent
Compliant with the DPDP Act 2023. This notice explains what Cformly collects, where it is stored, and the rights you hold over it.
What We Collect
Cformly collects the minimum data needed to file Form C / Form III (foreigner registration) on behalf of your guests:
- Guest passport data: full name, surname, given names, sex, date of birth, nationality, passport number, place/date of issue, expiry. Read from the passport's MRZ line by on-device open-source OCR — never uploaded to any server.
- Guest visa data: visa number, type, place/date of issue, expiry. Read from the visa by the same on-device OCR — never uploaded.
- Guest photo: captured and resized to portal limits, stored encrypted on-device.
- Host/property profile: establishment name, address, FRRO office jurisdiction, contact details. Entered once, reused across filings.
Where Data Is Stored
- On-device encrypted SQLite database (key in iOS Keychain / Android Keystore, hardware-backed where available). Never in plaintext, never in cloud backups.
- Backend (India region): pseudonymous host account and billing/provider/order identifiers only. No guest documents or extracted fields — passport/visa images, guest photos, signatures, and extracted fields never reach Cformly servers. Payment credentials are collected only by the hosted payment provider or app store; Cformly never receives raw card or UPI credentials.
When enabled, Cloudflare Turnstile protects sign-in from automated abuse using technical connection and browser signals. We do not send your email address, session credentials, or guest records to the verification widget. See Cloudflare’s Turnstile Privacy Addendum.
Turnstile’s technical signals may be processed outside India, as described in Cloudflare’s Turnstile Privacy Addendum.
Optional service notifications
Optional service alerts, separate from local filing reminders. Cformly keeps your account ID, language and an encrypted push token. Registration expires after 30 days without renewal; expired entries are removed by the next cleanup run. Expo, Apple or Google deliver generic notices, without guest data. Turning this off requests deletion from Cformly; failed requests retry after reconnecting. Already queued alerts may still arrive.
How We Use It
- To pre-fill Form C / Form III fields for review and filing.
- To send reviewed Form III fields and the selected sanitized guest photo directly from the app to the official FRRO portal during a host-initiated filing; Cformly servers do not receive them.
- To auto-fill the official FRRO portal through the in-app filing view or free desktop extension; the host reviews the form, solves the CAPTCHA, and presses Save.
Your Rights (DPDP Act 2023)
- Access: view your guest records on-device in the app; no guest record export is provided.
- Correction: edit any guest field on the Review screen before filing.
- Erasure: Settings > Delete Account removes all local PII, keys, and triggers server-side deletion. You receive a confirmation when complete.
- Grievance: contact contact@cformly.com for any privacy concern or data request.
Data Retention
- Unacknowledged Draft and Ready-to-file records expire 24 hours after creation with all details and photos. Editing does not restart the 24-hour period. Cformly deletes them while the app is active or at its next authorized opening; deletion is not guaranteed while closed.
- After filing is acknowledged, Cformly deletes every local passport, visa, and guest photo. Filed particulars and the Application ID remain encrypted on the device until that record is deleted. The property must separately establish its statutory record and photograph retention process outside Cformly and the official FRRO portal. Delete Account wipes the local store. Billing identifiers and billing events may be retained for the legally required accounting and dispute period after ordinary account-preference deletion. This exception does not retain guest data on Cformly servers.
Cross-Border Processing
Capture and OCR run entirely on the phone. Guest passport, visa, photos, and extracted fields remain on the device except during a user-initiated filing directly to the official FRRO portal through the in-app filing view or desktop extension, with manual transcription as the fallback. Cformly does not relay or store guest data.
Consent
By using Cformly, you consent to this data processing. You can withdraw consent at any time by deleting your account. Withdrawal does not affect filings already submitted to the FRRO (those are governed by the FRRO's own policies).
Contact
- Privacy and grievance: contact@cformly.com
- Security reports: security@cformly.com
- General support: support@cformly.com