← Back to home

Privacy Policy

Last updated: 1 August 2026

Seller
Depositvapsi
Trading name
DepositVapsi
Country
India
Contact
support@depositvapsi.com
Website
https://depositvapsi.com

1. Introduction

Depositvapsi, trading as DepositVapsi, provides an AI-assisted rental inspection documentation service at depositvapsi.com. The Service helps tenants and landlords record the condition of a rental property through guided inspections, photo and video evidence, automated damage detection, and shareable condition reports.

Depositvapsi is the controller of the personal data described in this policy. This policy explains what we collect, why we collect it, who we share it with, and the rights you have over your data.

2. Information we collect

  • Account information — name, email address, password credentials or social sign-in identifiers, and plan status.
  • Inspection data — inspection type (move-in / move-out), room lists, condition notes, checklists, signatures and acknowledgement records.
  • Property information — property address, unit details, landlord contact details you enter, and tenancy dates.
  • Photos — images you capture or upload as inspection evidence, including embedded EXIF metadata.
  • Videos — video walkthroughs you capture or upload as inspection evidence.
  • GPS coordinates — approximate capture location, where you permit location access, to prove where evidence was recorded.
  • Timestamps — capture and upload times used to establish the chronology of evidence.
  • Device metadata — device and browser type, operating system, screen size, language, and IP address.
  • Support communications — messages, attachments and correspondence you send us.
  • Payment information — processed by Paddle. We receive only limited transaction metadata such as plan, amount, currency, country and the last four digits of the card.
  • Analytics — pages viewed, features used, and aggregate performance and error data.
  • Cookies — as described in our Cookie Policy.

3. How we use information

  • Provide the Service — create your account, run guided inspections, and store your evidence (legal basis: performance of a contract).
  • Generate inspection reports — compile evidence into PDF condition reports and comparisons (contract).
  • Secure evidence — hash, timestamp and audit evidence so its integrity can be demonstrated (contract and legitimate interests).
  • Improve AI — evaluate and improve the accuracy of damage detection and report drafting (legitimate interests). We do not use your evidence to train third-party public models.
  • Fraud prevention — detect abuse, tampering, and unauthorised access (legitimate interests).
  • Customer support — answer your questions and resolve issues (contract).
  • Legal compliance — meet accounting, tax and other legal obligations (legal obligation).
  • Payment processing — enable subscription purchases, renewals and refunds through Paddle (contract).

4. Payment processing

Payments are securely processed by Paddle (Paddle.com Market Limited), our Merchant of Record.

Paddle manages:

  • payment processing
  • tax calculation
  • invoicing
  • refunds
  • fraud prevention

DepositVapsi does not store payment card information. Card details are entered directly into Paddle's checkout and never reach our servers. Paddle acts as an independent controller for the payment data it collects; see Paddle's privacy notice.

5. Third-party processors

We share personal data with the following categories of recipients:

  • Paddle — Merchant of Record for subscription sales, billing, tax, invoicing and refunds.
  • Supabase — managed database, authentication and object storage for your account and evidence.
  • Cloudflare — content delivery, edge hosting and network security.
  • Storage providers — encrypted cloud object storage for photos, videos and generated reports.
  • OpenAI and Google (Gemini) — AI providers that process inspection images and text to detect damage and draft reports, where those features are used.
  • Resend — transactional email delivery (acknowledgement links, account and billing notices), where enabled.
  • Google Analytics and product analytics — aggregate usage measurement, where enabled.
  • Error monitoring — crash and error reporting to keep the Service reliable.
  • Professional advisers and authorities — legal or accounting advisers, and authorities where required by law.

We do not sell your personal data.

Some processors operate outside your country of residence. Where personal data is transferred internationally we rely on appropriate safeguards such as Standard Contractual Clauses or adequacy decisions.

6. Cookies

  • Necessary — sign-in, session and security cookies required for the Service to function.
  • Analytics — help us understand which features are used.
  • Performance — measure load times and errors so we can improve reliability.
  • Marketing — measure the effectiveness of our campaigns, where enabled.

Full details, including how to manage your preferences, are in our Cookie Policy.

7. Data retention

Inspection evidence is retained until you delete it, or for as long as required by law. Deleting a property or inspection schedules the associated photos, videos and reports for permanent deletion. Account data is kept while your account is active and for a limited period afterwards to meet legal, tax and audit obligations, after which it is deleted or anonymised. Billing records held by Paddle are retained under Paddle's own retention rules.

8. Your rights

  • Access — request a copy of the personal data we hold about you.
  • Correction — have inaccurate data corrected.
  • Deletion — request deletion of your data and account.
  • Export — receive your data, including your reports, in a portable format.
  • Withdraw consent — withdraw consent where processing relies on it, and object to processing based on legitimate interests.

To exercise any right, email privacy@depositvapsi.com. We respond within one month. Users in the EU/UK may also complain to their local supervisory authority.

9. Security

  • Encryption — data is encrypted in transit (TLS) and at rest in our storage providers.
  • Access controls — least-privilege, row-level database policies restrict data to its owner.
  • Secure cloud storage — evidence is stored in private buckets that are not publicly listable.
  • Authentication — password and social sign-in with session management and password recovery.
  • Audit logs — cryptographic hashes and timeline events record when evidence and reports were created or changed.

No system is perfectly secure, but we use appropriate technical and organisational measures to protect your data and review them regularly.

10. Changes and contact

We may update this policy from time to time; material changes are communicated in-app or by email. For any privacy question, contact support@depositvapsi.com.