Privacy Policy

Last updated · 18 August 2026

Thinam is subscription-delivery software for local businesses in Chennai — milk rounds, tiffin services, water cans, vegetable boxes. This page explains what the system holds about the people it serves, why it holds it, and what can and cannot be removed.

Who holds your data, and who processes it

Two organisations are involved and they are not interchangeable.

  • The business you buy from — the dairy, the tiffin service — decides what to collect and why. They gathered your phone number, they know your door, and the account is theirs.
  • SaaSForest Infotech builds and runs Thinam, the software that business uses. We process that data on their instructions and do not sell it, rent it, or use it to advertise anything.

If you want your data changed or removed, either route works — ask the business directly, or write to us and we will act on their instruction. See the data deletion page.

What the system holds

A delivery round is a physical thing, and the record of one is more specific than most software. The complete inventory:

Your name
Held once in Latin script and, where the business entered one, once in Tamil script so a rider reads the right name at the door.
Where you live
Block, flat number, and a free-text address line. Optionally a map pin for the door.
A second map pin, per delivery
Recorded only at the moment a rider marks a delivery at your door — never in the background, and never while the app is closed.
Your phone numbers
A household may have several. Each carries the date consent was recorded, how it was recorded, and the name of the person at the business who attested it.
Opt-out, if you make one
The date you withdrew consent and how. The original consent date is kept alongside it — that record is what shows the messages sent before you opted out were lawful.
Photographs
A rider may photograph a doorstep when a delivery could not be completed, as evidence of what happened.
Your deliveries and your money
Every delivery, every charge, every payment and every cash collection, with the date and the rider.
Messages sent to you
The exact text of every WhatsApp message the system sent you, kept so that "what did you send me" has an answer.
Your device
A cookie identifier, a short description of the browser or phone, and when it was last used — so the account can be signed out of a device that is lost.

The system does not track location in the background, does not read your messages, does not use advertising trackers, and holds no payment card or bank details.

Why

Each item above exists to answer a question somebody actually asks: what am I owed, what did I pay, was it delivered, and why not. Nothing is collected speculatively for analysis later.

WhatsApp

Messages are sent over the WhatsApp Business Platform, which means Meta Platforms processes your phone number and the message in order to deliver it.

No message is ever sent to a number with no consent recorded against it. This is enforced in the sending code itself, not merely in a screen somebody could bypass.

The system deliberately sends few messages: a bill at month end, a reminder if it goes unpaid, a notice if a delivery failed, a confirmation when you change something, and a sign-in code. There is no per-delivery confirmation and no marketing.

You can withdraw consent at any time, from the app or by telling the business. It takes effect immediately.

What cannot be deleted, and why

Three kinds of record — deliveries, money movements and cash collections — can be added to but never edited or removed, by anyone, including us. A correction is a new entry that opposes the old one, so both remain visible.

This is deliberate and it protects you as much as the business. These records are the evidence that settles a disagreement about a bill. A ledger that can be quietly rewritten cannot settle anything, and the party who would be harmed by a silent edit is usually the customer.

It does mean a deletion request cannot empty them. What we can do is remove the identifying information attached to them, so the entries survive as figures without naming you. The data deletion page explains what this means in practice.

How long

Retention periods are set by the business you buy from, within these limits:

Delivery and billing records
Retained as long as required by the business's own accounting and tax obligations. Period: [TO BE CONFIRMED]
Doorstep photographs
Kept only as long as the delivery they evidence can still be disputed. Period: [TO BE CONFIRMED]
Message log
Period: [TO BE CONFIRMED]
Device records
A device sign-in expires by itself and is removed when it does.

Who can see it

Access is narrow by construction rather than by policy.

  • One business can never read another's records. This is enforced at the data layer and there is a test that fails the build if it stops being true.
  • A rider sees only the stops on his own round for that day — names, doors and quantities. He cannot see anyone's balance or billing history.
  • You see only your own household.
  • A small number of SaaSForest staff can access records across businesses in order to run and support the platform. That access requires two-factor authentication.

Where it is stored

On servers in Mumbai, India. Photographs are held in object storage. Messages pass through Meta's infrastructure in order to reach WhatsApp.

Your choices

You can ask to see what is held about you, correct anything wrong, withdraw messaging consent, or request deletion. Write to privacy@saasforest.com, or ask the business you buy from.

Changes to this page

If this policy changes materially, the date at the top changes with it.