1. Overview
TRIVARTHA CRM ("Trivartha CRM", "the App", "we", "us", "our") is committed to giving you full control over your personal data. This Data Deletion Policy explains what data we delete, how you can request deletion, what may be retained (and why), and how long each step takes.
This policy applies to all TRIVARTHA CRM surfaces — the Android mobile app, the iOS app (when available), the web app, and any associated cloud services such as Firebase, Google Sign-In, and our payment processor.
We comply with the EU General Data Protection Regulation (GDPR), the UK Data Protection Act 2018, the Digital Personal Data Protection Act 2023 (India), the California Consumer Privacy Act (CCPA/CPRA), and Google Play's User Data Policy.
2. Scope
This policy covers deletion of:
- Your TRIVARTHA user account and authentication credentials.
- All on-device CRM data — leads, customers, deals, notes, documents, photos, signatures, location logs.
- All cloud-synced data in Firebase Authentication, Firestore, and Cloud Storage.
- Linked third-party identities (Google Sign-In, Apple ID) — we revoke our access tokens.
- Subscription and billing records held by us (financial records retained per Section 6).
- Analytics, crash reports, and support tickets associated with your account.
3. Data We Collect
Before you delete, you may want to know exactly what we hold. The table below lists every category of data, where it lives, and what happens to it on deletion.
| Category | Examples | Storage | On deletion |
|---|---|---|---|
| Account identity | Name, email, phone, employee ID, role | Firebase Auth + Firestore | Deleted |
| Authentication tokens | Google ID token, refresh token, session cookies | Encrypted device keystore + Firebase | Deleted |
| Customer / lead records | Name, phone, email, PAN, Aadhaar, notes, tags | Encrypted local DB + Firestore | Deleted |
| Documents & media | Visit photos, signatures, cheques, KYC PDFs | Encrypted local storage + Cloud Storage | Deleted |
| Location logs | GPS coordinates of visits, travel distance | Local DB + Firestore | Deleted |
| AI input data | Prompts sent to the on-device Gemma model | Device only — never leaves the device | Deleted |
| Device telemetry | Model, OS, app version, crash logs | Firebase Crashlytics | Anonymized |
| Usage analytics | Feature usage, screen views, session duration | Aggregated counters | Anonymized |
| Subscription record | Plan, period, last 4 of payment instrument, invoices | Google Play Billing + our accounting system | Retained 8 yrs |
| Tax / GST invoices | Name, GSTIN, invoice number, amount, tax | Accounting system (India) | Retained 8 yrs |
| Support correspondence | Emails, chat logs, attachments | Helpdesk mailbox | Deleted 90 days |
| Backup snapshots | Encrypted daily backups of cloud data | Cloud Storage (cold) | Purged ≤ 30 days |
4. How to Request Deletion
You can request deletion through any of the following channels. We honour all of them at no cost.
4.1 From inside the App (fastest)
Open Settings → Privacy & Data → Delete my account. See Section 5 for the full walkthrough.
4.2 By email
Send a deletion request from the email address linked to your account to support@trivartha.com with subject line Data Deletion Request.
4.3 Via web form
Fill in the form at the bottom of this page: request form.
4.4 By post
See the postal address in Section 15. Requests received by post may take 3–5 additional business days to process.
4.5 Through Google (Android only)
If you signed in with Google, you may also revoke TRIVARTHA CRM's access at myaccount.google.com/permissions. This stops future access but does not delete data already stored — you still need to send us a deletion request to complete the process.
5. In-App Self-Deletion (Step-by-Step)
The fastest way to delete everything is from inside the app. The flow takes about 60 seconds.
- Open the App Tap the TRIVARTHA CRM icon on your Android device and unlock it with your PIN or biometrics.
- Go to Settings Tap the gear icon (⚙️) in the top-right corner of the Home screen.
- Open Privacy & Data Scroll down and tap Privacy & Data under the Account section.
- Tap "Delete my account" This is the last option in the screen, shown in red. Tap it.
-
Choose what to delete
Select one of three options:
- Delete account and all data — recommended. Removes everything including cloud sync.
- Delete cloud data only — keeps the on-device data, removes server copy.
- Delete account only — removes login but keeps records (for re-activation later).
- Confirm identity Re-enter your PIN or use biometrics to confirm. We do this to prevent accidental or malicious deletion.
- Review the summary A final screen lists exactly what will be deleted and what we must retain by law. Tap I understand, continue.
- Wait for confirmation You will see a progress screen and receive an email within 72 hours confirming completion. Until then, you can tap Undo to cancel.
6. What Gets Deleted vs Retained
6.1 Deleted immediately
- Profile, contact info, and authentication credentials.
- All CRM records: leads, customers, deals, tasks, notes.
- All uploaded documents, photos, signatures, and KYC files.
- Location logs and visit history.
- Cloud sync data (Firestore & Cloud Storage objects).
- Active sessions, refresh tokens, and device authorizations.
- Linked third-party identity grants (Google, Apple).
- Subscription linkage to your account (so you stop being billed).
- Support tickets and chat history (after 90 days).
6.2 Retained for legal / legitimate reasons
Some data we must keep even after account deletion. We keep the minimum necessary, isolate it from your profile, and delete it when the legal clock expires.
| What | Why | Retention period |
|---|---|---|
| Tax invoices / GST records | Income Tax Act 1961, GST Act 2017 | 8 years from invoice date |
| Subscription payment record | Google Play Billing terms, RBI KYC | 7 years |
| Refund & chargeback records | Anti-fraud, banking partner requirements | 5 years |
| Aggregated, anonymized analytics | Legitimate interest to improve product | Indefinitely (no PII) |
| Security / abuse logs | Investigate incidents, legal defence | 1 year |
| Backups of cloud data | Operational resilience | ≤ 30 days, then purged |
7. Deletion Timeline
We commit to the following Service Level Objectives (SLOs) from the moment your request is verified.
| Stage | What happens | SLO |
|---|---|---|
| Acknowledgement | We email you a ticket ID and confirm receipt | ≤ 24 hours |
| Identity verification | We verify you are the account holder | ≤ 48 hours |
| Live systems purge | Account, cloud sync, live DB rows, storage objects | ≤ 72 hours |
| Edge cache purge | CDN, backups, analytics roll-ups | ≤ 30 days |
| Confirmation email | Final deletion certificate with timestamp | ≤ 30 days |
8. Third-Party Data Deletion
When you use TRIVARTHA CRM, data is also processed by trusted sub-processors. On deletion, we instruct each of them to delete the relevant data.
| Sub-processor | What they hold | Deletion action |
|---|---|---|
| Google Firebase Authentication | UID, email, hashed password, sign-in provider | Account deleted via Firebase Admin SDK |
| Google Firestore | CRM records, profile data | All documents in your user subtree deleted |
| Google Cloud Storage | Photos, signatures, PDFs | Objects & versions deleted; CDN invalidated |
| Google Sign-In | OAuth grant, ID token | Grant revoked via Google People API |
| Google Play Billing | Subscription ID, purchase token | Subscription voided; future charges stopped |
| Firebase Crashlytics | Crash logs | User identifier reset; logs expire in 90 days |
| Apple App Store (iOS, when applicable) | Receipt validation | Refund processed if applicable; receipt invalidated |
9. Identity Verification
To prevent unauthorized deletion, we verify the requester is the legitimate account holder. We use the least-intrusive method that works.
- In-app: PIN or biometric — already verified by device.
- Email request: we only act on requests sent from the email address on file. If you no longer have access, see "Lost email" below.
- Web form: we send a signed magic link to your registered email.
- Post: we may ask for a government-issued ID copy, redacted to show only name and photo.
Lost email or 2FA device (account recovery path)
If you can no longer access the registered email or second factor, send the deletion request from any email and include:
- Your full name and registered phone number.
- Last 4 characters of your employee ID (if applicable).
- Approximate date of registration.
- Government ID (Aadhaar / PAN / Passport) — we will accept a redacted copy.
Verification takes 3–5 business days in this case.
10. Confirmation & Proof of Deletion
When deletion is complete, we email a Deletion Certificate containing:
- Your account identifier (UID, redacted).
- Timestamp of completion (UTC).
- List of data categories deleted.
- List of data categories retained and the legal basis.
- Contact details for follow-up questions.
You can request a PDF copy of this certificate at any time within 2 years of deletion by writing to support@trivartha.com.
11. Recovery & Reactivation
To restore:
- Open the app and sign in with the same account within 14 days.
- Tap the Restore my account banner that appears.
- Confirm with PIN/biometrics.
After the 14-day grace window, signed-in state is fully wiped. You can always create a new account, but the old CRM data and documents will not be linked to it.
12. Your Rights
Regardless of which deletion path you choose, you retain the following rights under GDPR, DPDP Act, and CCPA:
- Right of access — ask what we hold about you.
- Right of rectification — correct inaccurate data.
- Right to erasure — request deletion (this policy).
- Right to restrict processing — pause data use without deletion.
- Right to data portability — receive a machine-readable export.
- Right to object — to legitimate-interest processing.
- Right to lodge a complaint — with your supervisory authority.
We respond to all valid requests within 30 calendar days at no cost.
13. Frequently Asked Questions
Will deleting my TRIVARTHA CRM account cancel my subscription?
Yes. Deleting your account voids your subscription and stops future charges. If you are on an annual plan, you may be eligible for a pro-rated refund per our Refund Policy. Past invoices are retained for tax purposes (Section 6.2).
I uninstalled the app — is my data deleted?
Uninstalling removes on-device data only. Any cloud-synced data remains in our systems until you explicitly request deletion or until 90 days after subscription cancellation, whichever comes first. To be safe, send a deletion request before uninstalling.
What happens to my customers' data when I delete my account?
Your customers' personal data that you entered into the CRM (names, phone numbers, documents, etc.) is deleted with your account. If your employer organization has separate accounts, that data is unaffected.
Can I delete just one lead or customer without deleting my whole account?
Yes. From the lead or customer profile, tap the three-dot menu → Delete record. This removes only that record and its associated documents. The audit log entry is retained for 90 days.
How do I delete data stored by Google on my behalf?
Visit myaccount.google.com/permissions, find TRIVARTHA CRM, and click Remove access. This revokes our permission to access your Google account. Then submit a deletion request to us to remove the data we already received.
Does TRIVARTHA CRM sell my data?
No. We never sell, rent, or trade personal data. See our Privacy Policy for the full list of who we share with.
What happens if I delete my account while on a free trial?
Your trial ends immediately and no charge is made. No further record is retained beyond aggregated, anonymized analytics.
How long do backups and cached data take to be deleted?
Live systems are purged within 72 hours. Cold backups and CDN caches are purged within 30 days. Retained tax records (invoices) are kept for 8 years as required by Indian law.
I'm an EU / UK user — do I have additional rights?
Yes. You can lodge a complaint with your national data protection authority. The EU list of authorities is at edpb.europa.eu. The UK ICO is at ico.org.uk.
Can my organization delete my account on my behalf?
Yes. If your organization is the data controller (e.g., a bank that licensed TRIVARTHA CRM for its RMs), the org admin can request deletion on your behalf. The DPO will verify the request with the org's authorized signatory.
Will deletion affect my Play Store subscription refund?
No. Refunds are handled by Google Play under their own policy. Deleting your account does not waive or forfeit any refund you may be entitled to.
14. Changes to This Policy
We may update this Data Deletion Policy from time to time. When we do, we will:
- Revise the Last updated date at the top of this page.
- Notify you in-app and via email at least 14 days before material changes take effect.
- Maintain an archive of previous versions at
/legal/data-deletion-archive.html.
15. Contact
For any questions, complaints, or requests related to this policy, please contact:
16. Request Data Deletion
To request deletion of your TRIVARTHA CRM account and data, please send us an email at
support@trivartha.com
from the email address registered with your account. Use the subject line Data Deletion Request.
16.1 Please include the following in your email
- Send from your registered email address We only act on requests sent from the email on file with your TRIVARTHA CRM account. This protects you from unauthorized deletion.
- Provide your full name and phone number Helps us locate your account quickly and reach you if we have verification questions.
-
State what you want deleted
Choose one:
- Delete account and all data — recommended. Removes everything including cloud sync.
- Delete cloud data only — keeps on-device data, removes server copy.
- Delete account only — removes login but keeps records (for re-activation later).
- Delete specific records only — describe which leads, customers, or documents.
- Optional: explain your reason Helps us improve the product. Not required.
- You email support@trivartha.com with the details above.
- We send you a confirmation email with a ticket ID within 24 hours.
- We verify your identity (≤ 48 hours).
- Live systems are purged within 72 hours.
- You receive a final Deletion Certificate within 30 days.
- You have 14 days from the live-purge step to undo the deletion.