Official Compliance Document

Feb40 Privacy Policy

Application: Feb40 Developer / Entity: Feb40 Technologies Last Updated: September 4, 2026
📑 Table of Contents

01. Introduction

Welcome to Feb40 ("we," "our," "us," or "Feb40"). Feb40 is operated by Feb40 Technologies. We are committed to protecting your privacy, handling your personal data responsibly, and maintaining transparency about how your data is collected and processed.

This Privacy Policy applies to the Feb40 Android application published on Google Play by Feb40 Technologies, and also governs the Feb40 mobile application (available on Google Play Store and iOS App Store), our official website at https://feb40.com, and all associated services, platforms, APIs, and tools provided by Feb40 Technologies (collectively, the "Services").

This policy is designed to comply with applicable data protection legislation and the Google Play Developer Program Policies (specifically the User Data Policy). By accessing, installing, registering with, or using the Feb40 application or website, you acknowledge that you have read and understood the practices described in this Privacy Policy.

02. Information We Collect

We only collect personal information that is necessary to deliver, operate, secure, and improve our services, fulfill user requests and orders, and provide technical support. We adhere to strict data minimization principles.

Depending on your usage of Feb40, we collect the following types of information:

  • Directly Provided Data: Information you provide when registering an account, updating your profile, placing an order, submitting inquiries, or communicating with our support team.
  • Authentication Data: Login credentials, phone numbers, and identity tokens processed via Google Sign-In or Firebase Authentication.
  • Order & Transaction Records: Details regarding requested products, services, delivery items, timestamps, order amounts, and fulfillment status.
  • Location Information: Foreground device location data (precise or approximate) provided with your explicit operating system permission to enable address discovery, nearby store/service mapping, and order delivery.
  • Automatically Collected Technical Data: Device diagnostics, app performance metrics, crash logs, and network status necessary for security and app reliability.

Data Minimization Principle: We do NOT collect or request sensitive personal records such as biometric data, political or religious affiliations, or unrelated private files from your device storage.

03. Account Information

When you register for or manage an account on Feb40, we collect the following account information:

  • Full Name & Display Name: To identify your account, personalize your app experience, and address you during customer service interactions.
  • Email Address: To verify your account identity, send transaction confirmations, account recovery alerts, and critical security notices.
  • Phone Number: To authenticate your account via SMS One-Time Password (OTP) verification, coordinate order deliveries, and provide direct customer support.
  • Profile Picture: Optional user photo (uploaded by you or imported via Google Sign-In) to display within your in-app profile.
  • Saved Delivery Addresses: Street address, landmark, city, postal code, and delivery instructions saved by you for convenient order checkout.

04. Google Sign-In / Authentication Data

To make signing in quick and secure, Feb40 supports industry-standard authentication methods:

  • Google Sign-In: If you choose to authenticate using your Google Account, we use Google OAuth APIs to retrieve basic, authorized profile attributes:
    • Your verified Google email address
    • Your Google display name
    • Your public Google profile image URL
    • A secure unique user identification token (UID)
  • No Access to Private Google Data: We do NOT access your Google password, contacts, Google Drive files, search history, or any other private Google account content.
  • Phone & SMS OTP Authentication: If you choose phone-based authentication, a verification code is delivered via SMS to confirm phone number ownership.
  • Authentication Infrastructure: Authentication tokens and cryptographic sessions are managed through Google Firebase Authentication to ensure high-grade security and prevent unauthorized session tampering.

05. Information Automatically Collected

When you interact with the Feb40 mobile app or website, certain interaction information is collected automatically to maintain system performance, stability, and security:

  • App Usage & Activity: Screen transitions, buttons clicked, feature interactions, and session timestamps collected in aggregate to improve user workflows.
  • Network Information: IP address, network connection type (Wi-Fi, 4G, 5G), mobile carrier name, and approximate geographical region determined from IP.
  • Performance Metrics: Network request response times, app load durations, and API latency measurements.

06. Device and App Information

To ensure optimal compatibility across Android and iOS devices, Feb40 collects standard hardware and software diagnostic metrics:

  • Device Identifiers: Anonymous device identifiers (such as Firebase Installation ID or Android ID) used strictly for notification routing and app instance management.
  • Hardware & Operating System: Device model, manufacturer, operating system version (e.g., Android 14, iOS 17), system language, and screen resolution.
  • Crash & Diagnostic Logs: Detailed stack traces, memory state, and error logs collected via Firebase Crashlytics whenever an unexpected crash or exception occurs, allowing our developers to quickly fix software bugs.

07. How We Use Information

We use collected user information exclusively for legitimate operational, service delivery, technical, and legal purposes:

  • Service Delivery: Creating and administering user accounts, processing orders, coordinating deliveries, and maintaining live order status.
  • Customer Support: Resolving user queries, processing refunds or cancellations, and providing technical assistance via email or WhatsApp.
  • Real-Time Notifications: Sending push alerts regarding order status updates, delivery partner arrival, account security alerts, and service notices.
  • Platform Security: Detecting, preventing, and addressing fraud, spam, automated bot attacks, unauthorized logins, and security vulnerabilities.
  • Software Optimization: Identifying software defects, optimizing app responsiveness, and ensuring broad hardware compatibility.
  • Legal & Regulatory Compliance: Fulfilling tax, accounting, dispute resolution, and statutory compliance obligations under applicable law.

08. How Information Is Shared

We respect your privacy and enforce strict data sharing rules:

  • No Sale of Personal Data: We do NOT sell, rent, lease, trade, or monetize your personal information to third parties, advertisers, or data brokers under any circumstances.
  • Fulfillment & Service Partners: When you place an order, necessary fulfillment details (e.g., delivery address, customer name, and contact number) are shared strictly with the assigned delivery partner and merchant during the active order lifecycle to complete the delivery.
  • Infrastructure Service Providers: Trusted cloud infrastructure vendors (e.g., Google Cloud, Firebase) who process data on our behalf under strict data confidentiality and security agreements.
  • Legal & Regulatory Authorities: We may disclose information if required by law, subpoena, court order, or governmental law enforcement authority to protect the legal rights, safety, and security of Feb40, our users, or the public.

09. Third-Party Services

Feb40 integrates with industry-leading third-party SDKs and service providers to support app operations:

  • Google Maps Platform: Used for map rendering, location searching, geocoding, and distance calculations to ensure accurate address pinpointing.
  • Payment Processors (Razorpay / UPI): Digital transactions are processed through RBI-compliant, PCI-DSS certified payment gateways. Feb40 does NOT store or have access to your sensitive card numbers, CVVs, net-banking credentials, or UPI PINs.

All third-party service providers are contractually obligated to safeguard user information in compliance with applicable privacy regulations.

10. Firebase / Google Services

Feb40 relies on Google Firebase cloud infrastructure for reliable and secure backend operations. The specific Firebase services utilized in our project include:

  • Firebase Authentication: Manages secure user sign-in via Google Sign-In, Phone/SMS OTP, and Email, handling cryptographic session tokens.
  • Cloud Firestore: A fully managed NoSQL cloud database used to securely store user profile details, saved addresses, and order history.
  • Firebase Cloud Storage: Secure cloud file storage for user-uploaded media such as profile pictures.
  • Firebase Cloud Messaging (FCM): Delivers instant push notifications for order status updates, delivery alerts, and security messages.
  • Firebase Analytics: Collects aggregated, non-personally identifiable usage statistics to help us understand app adoption and improve user workflows.
  • Firebase Crashlytics: Real-time crash reporting and diagnostic logging to identify, prioritize, and resolve software exceptions.
  • Firebase App Check: Protects backend APIs and database resources from abuse, unauthorized clients, and malicious traffic.

11. Data Storage and Security

We implement rigorous technical, organizational, and physical safeguards to defend your personal information:

  • Encryption in Transit: All data transmitted between the Feb40 mobile app, our website, and cloud servers is encrypted using modern TLS/HTTPS (Transport Layer Security) protocols.
  • Encryption at Rest: Database records and media stored in Cloud Firestore and Firebase Storage are encrypted at rest using enterprise-grade AES-256 encryption.
  • Database Access Rules: Fine-grained Cloud Firestore security rules ensure that users can only view and modify their own authorized data.
  • Access Controls: Server and backend administrative access is restricted to authorized personnel via multi-factor authentication (MFA) and least-privilege principles.

While we apply industry-standard security protocols, no method of digital transmission or storage is 100% immune from external risks. We advise users to maintain the confidentiality of their devices and login credentials.

12. Data Retention

We retain personal data only for as long as necessary to fulfill the purposes described in this Privacy Policy:

  • Active Account Data: User profiles, addresses, and account settings are retained as long as your account remains open and active.
  • Order & Financial Records: Order records and invoice details are retained for a legally mandated period to comply with statutory taxation, accounting, audit, and dispute resolution requirements under Indian law.
  • Crash & Diagnostic Logs: Diagnostic telemetry and crash reports are retained on a rolling cycle (typically 90 days) and automatically purged or anonymized.

13. User Rights

As a user of Feb40, you retain full control over your personal data:

  • Right to Access: You can view your personal profile, past orders, and saved addresses anytime directly in the app.
  • Right to Rectification: You can update or correct your name, email, phone number, and delivery addresses via the in-app profile settings.
  • Right to Withdraw Consent: You can revoke device permissions (Location, Notifications, Camera) at any time through your device Operating System settings.
  • Right to Revoke Google Access: If you authenticated using Google Sign-In, you can revoke Feb40's access anytime in your Google Account Security Settings.
  • Right to Erasure (Data Deletion): You have the right to request complete account and personal data deletion as detailed in Section 14 below.

14. Data Deletion

Feb40 respects your right to be forgotten. Users can request the permanent deletion of their account, personal identifiers, and associated data through either of the following verified channels:

📱 Method 1: Instant In-App Account Deletion

You can delete your account directly inside the Feb40 mobile application:

  • Open the Feb40 App on your device.
  • Navigate to Profile or Settings.
  • Scroll to Delete Account.
  • Review the deletion terms and tap Confirm Delete Account.

✉️ Method 2: Direct Support Email Request

If you cannot access the mobile application, you can submit a manual deletion request:

  • Send an email from your registered email address to: feb402025@gmail.com
  • Use the Subject Line: Account Deletion Request - Feb40
  • Include your registered mobile phone number and full name for identity verification.

Deletion Timeline & Processing: Upon receiving and verifying your request, we will permanently purge your user profile, authentication credentials, delivery addresses, and personal identifiers from our active databases within 30 days. Historical financial/tax transaction records will be retained in anonymized format solely as required by applicable statutory taxation laws.

15. Children's Privacy

The Feb40 application is designed and intended for general audiences who are at least 18 years of age (or the legal age of majority in their jurisdiction), or who use the service under the direct supervision of a parent or legal guardian.

We do not knowingly collect, solicit, or maintain personal information from children under the age of 13. If we become aware that we have inadvertently received personal data from a child under 13 without verified parental consent, we will promptly take steps to delete such information from our records. If you believe that a child under 13 has provided us with personal data, please contact us immediately at feb402025@gmail.com.

16. Changes to This Privacy Policy

We may update or revise this Privacy Policy periodically to reflect changes in our service offerings, technical infrastructure, industry practices, or applicable laws.

When modifications are made, we will update the "Last Updated" date at the top of this Privacy Policy. For material changes, we will provide prominent notification within the mobile app or via email prior to the changes taking effect. We encourage you to review this page periodically to stay informed about our data protection practices.

17. Contact Us

If you have any questions, feedback, inquiries, or requests regarding this Privacy Policy or our data protection practices, please contact our Data Support Team:

Company / Entity: Feb40 Technologies

Application: Feb40

Official Support Email: feb402025@gmail.com

Phone / WhatsApp Support: +91 7708559698 / +91 7708559698

Registered Office Address: Hari Complex, Public Office Rd, Velippalayam, Nagapattinam, Tamil Nadu 611001, India

Official Website: https://feb40.com