This policy explains what personal data Vmitr collects through the Vmitr mobile application and the vmitr.in website, why we collect it, who we share it with, and the choices you have. It applies to every Vmitr member.
The short version. Vmitr is an invite-only professional network. We collect the profile details you give us and the messages and referrals you exchange with other members. We do not sell your data, we do not run advertising, and we do not use third-party analytics or tracking SDKs. You can permanently delete your account and all of its data from inside the app at any time.
1. Who we are
Vmitr (“Vmitr”, “we”, “us”) operates the Vmitr professional referral network. For the purposes of applicable data protection law, including India's Digital Personal Data Protection Act, 2023, Vmitr is the data fiduciary (controller) of the personal data described below.
Legal entity: Arun Dabral (sole proprietor, operating as Vmitr)
Registered address: C 2/9, Rohini Sector 11, New Delhi, Delhi, India
Email: support@vmitr.in
2. What we collect
We only collect data that you or another member provides. Vmitr does not collect your location, your contacts, your camera roll, your microphone, your device advertising ID, or your activity in other apps.
| Category | Specific data | Source |
|---|---|---|
| Account | Email address, password (stored only as a salted hash), account status and role, two-factor authentication enrolment | You, or the administrator who invited you |
| Profile | Full name, phone number, company name, designation, office address, website, profile photo, and links to your LinkedIn, Instagram, Facebook and X profiles | You |
| Content you create | Direct messages, business referrals, products and services you list, and meetings you schedule | You |
| Content about you | Messages other members send you, referrals they direct to you, and reports other members file about your conduct | Other members |
| Safety | Members you have blocked, members who have blocked you, and content reports you submit | You and other members |
| Technical | Authentication session tokens, and server-side logs of API requests kept by our hosting provider (which include IP address and timestamp) | Automatic |
No advertising or analytics. The Vmitr app contains no advertising SDK, no analytics SDK, and no cross-app or cross-site tracking. We do not build advertising profiles and we do not sell or rent personal data to anyone, for any purpose.
3. Why we collect it
- To operate your account — authenticating you, enforcing two-factor authentication, and keeping you signed in.
- To provide the service — showing your profile in the member directory, delivering your messages, matching referrals, and scheduling meetings.
- To keep members safe — acting on blocks and reviewing content reports.
- To communicate with you — sending password reset emails and in-app notifications that relate to your account and your activity.
- To meet legal obligations — responding to lawful requests and retaining records where the law requires it.
Where the law requires a lawful basis, we rely on the performance of our contract with you (operating the network you joined), our legitimate interests in keeping the network safe and secure, your consent where you volunteer optional profile details, and legal obligation where applicable.
4. Who we share it with
Other members
Vmitr is a network. Your name, company, designation, office address, website, profile photo, social links, and the products and services you list are visible to every other signed-in Vmitr member. Do not put anything in your profile that you would not want the whole network to read. Your email address, phone number and password are not shown in the directory unless you add them to a visible profile field yourself.
Direct messages are visible to you and the member you sent them to. Vmitr administrators can access message content when investigating a content report or a legal request.
Service providers
| Provider | What they process | Where |
|---|---|---|
| Supabase, Inc. | Database, authentication, file storage and server logs — that is, all of the data in the table above | Cloud infrastructure in the region configured for our project |
| Google LLC (Google Play) | App distribution and crash reporting for the Android app | United States and other locations |
| Supabase (built-in Auth email) | Delivery of transactional email such as password reset links | United States |
These providers act on our instructions under contract. They may not use your data for their own purposes.
Legal disclosure
We may disclose personal data where we are legally compelled to, where it is necessary to investigate a violation of our Terms of Service, or where it is necessary to protect the safety of a member or the public.
5. How long we keep it
We keep your account data for as long as your account exists. When you delete your account, the data described in section 6 is erased immediately. Server-side request logs held by our hosting provider are retained on their standard schedule and then automatically discarded. Where the law requires us to keep a record — for example, of a content report we acted upon — we retain the minimum necessary for the required period.
6. Deleting your account
You can permanently delete your Vmitr account and its data at any time:
- In the app — open Profile, scroll to Delete Account, and confirm. This is immediate and irreversible.
- On the web — use the account deletion request page.
Deleting your account permanently erases:
- your login credentials and two-factor authentication enrolment;
- your profile, including your photo, contact details and social links;
- every direct message you sent and every direct message you received;
- the products and services you listed;
- the referrals you posted, the meetings you scheduled or attended, and the notifications you received;
- your block list and the blocks other members placed on you;
- the content reports you filed.
Three things survive deletion, with your identity stripped from them, because they form part of another member's records rather than only your own:
- a referral that another member posted and that you accepted stays in their history, no longer attributed to you;
- a notification you sent to another member stays in their notification list, no longer attributed to you;
- a content report that another member filed about your conduct is retained with your identifier removed, so that deleting an account cannot erase a safety record.
The Vmitr gallery is curated by administrators, not by members, so it holds no personal data of yours and is unaffected by deletion.
7. How we protect it
- All traffic between the app and our servers is encrypted with TLS. The Android app forbids unencrypted connections outright.
- Passwords are never stored. Only a salted hash is kept.
- Your session token is stored in the Android Keystore or the iOS Keychain, not in ordinary app storage.
- Members may enrol two-factor authentication (TOTP). Where a member has enrolled, our database refuses to return any of that member's data to a session that has not completed the second factor — the check is enforced on the server, not merely in the app.
- Row-level security policies in our database restrict every member to the rows they are entitled to read.
No system is perfectly secure. If we become aware of a personal data breach affecting you, we will notify you and the relevant authority as required by law.
8. Your rights
Subject to your local law, you may ask us to:
- Access the personal data we hold about you, and receive a copy.
- Correct data that is inaccurate or incomplete — most of it you can edit yourself under Profile.
- Erase your data, as described in section 6.
- Restrict or object to processing that relies on our legitimate interests.
- Withdraw consent you previously gave, without affecting processing already carried out.
- Nominate another individual to exercise these rights on your behalf in the event of your death or incapacity, as provided under India's Digital Personal Data Protection Act, 2023.
- Complain to your data protection authority.
Write to support@vmitr.in and we will respond within 30 days. We may ask you to verify your identity first.
9. Children
Vmitr is a professional network for adults. It is not directed to children, and we do not knowingly collect personal data from anyone under 18. Accounts are created only by administrators, by invitation. If you believe a child has an account, write to support@vmitr.in and we will delete it.
10. Changes to this policy
We will post any change on this page and update the date at the top. If a change materially affects your rights, we will notify you in the app or by email before it takes effect.
11. Grievance Officer
In accordance with the Information Technology Act, 2000 and the rules made under it, and the Digital Personal Data Protection Act, 2023, the contact details of our Grievance Officer are:
Name: Arun Dabral
Designation: Grievance Officer, Vmitr
Email: grievance@vmitr.in
Address: C 2/9, Rohini Sector 11, New Delhi, Delhi, India
The Grievance Officer acknowledges complaints within 24 hours and resolves them within 15 days.
12. Contact us
Questions about this policy, or about the data we hold on you, go to support@vmitr.in.