← Home

Privacy Policy

Last updated: May 13, 2026

This Privacy Policy explains how MilesOrbit, a product of CRM Technologies ("we", "us"), collects, uses, stores, shares, and protects personal data of users ("you") of milesorbit.in and the related services (the "Services"). CRM Technologies is registered in India with its office at Orchid Platina, Sama Savli Road, Vemali, Vadodara, Gujarat — 390008, and complies with the Digital Personal Data Protection Act, 2023 (DPDP Act), the Information Technology Act, 2000 and Rules issued thereunder.

1. Data we collect

  • Identity & contact: name, email address, optionally phone number.
  • Account data: hashed password (Argon2id), authentication-provider IDs, MFA secrets (encrypted at rest).
  • Card portfolio you choose to link: card identifier and point balance you enter — we do not store full card numbers, CVVs, or PINs.
  • Usage data: pages visited, features used, IP address, user-agent, device telemetry.
  • Billing data: handled by Razorpay; we receive only tokenized references and transaction status.

2. Why we use it

  • To provide redemption recommendations, account features, and customer support.
  • To process subscription payments and prevent fraud.
  • To improve product quality and security (aggregated analytics).
  • To comply with applicable law.

3. Sharing

We share data only with processors operating on our behalf under contract: cloud hosting (AWS Mumbai, ap-south-1), email delivery, error monitoring, analytics, and payment processing (Razorpay). We do not sell your personal data. We may disclose data when compelled by valid legal process.

4. International transfers

Primary data is hosted in India. Limited operational data may be processed in other jurisdictions only where the recipient provides equivalent protection consistent with the DPDP Act.

5. Retention

We retain data for as long as your account is active and for a reasonable period thereafter to comply with legal obligations, resolve disputes, and enforce agreements. You may request deletion at any time.

6. Your rights

  • Access and copy your data.
  • Correct inaccuracies.
  • Withdraw consent and erase your account.
  • Nominate another individual to exercise rights on your behalf.
  • Lodge a complaint with our Grievance Officer (see /grievance).

7. Security

Passwords are hashed with Argon2id. Data in transit uses TLS 1.3. Data at rest is encrypted via managed-service envelope encryption. MFA secrets are column-encrypted. Production access is gated by SSO with hardware MFA.

8. Cookies

We use strictly-necessary cookies for authentication and session integrity. Non-essential cookies (analytics) require your prior consent and can be revoked at any time from account settings.

9. Changes

We will notify registered users of material changes via email and through the product, and update the "Last updated" date above. Continued use after changes signifies acceptance.

10. Contact

Email: privacy@milesorbit.in. Grievance Officer details are on /grievance. You may also write to us at: CRM Technologies, Orchid Platina, Sama Savli Road, Vemali, Vadodara, Gujarat — 390008, India.