Privacy Policy
Effective 25 September 2026 · Last updated 25 September 2026
LetzPay Locker ("we", "us", "our") provides the LetzPay Locker Android application and the LetzPay Locker dashboard hosted at https://letzpaylocker.info (together, the "Service"). This Privacy Policy explains what personal data the Service collects, why we collect it, how it is shared and protected, and the choices you have.
Please also read our Terms & Conditions. For any privacy question, request or complaint, contact emi.letzshop1@gmail.com.
1. Who this policy applies to
The Service is used by two groups of people:
- Dashboard users — administrators, dealers and retailers/resellers who create an account, record customers and EMI plans, and control enrolled devices.
- Customers (buyers) — people who buy a product on finance and install the LetzPay Locker app on their Android phone so the seller can enforce the payment schedule.
2. Information we collect
2.1 Account information (dashboard users)
- Username, display name, shop name and shop owner's name
- Your password, stored only as a salted scrypt hash — we never store or view your plain password
- Phone number, email address and shop address (optional, except where required for sign-in)
- Dealer code and/or retailer code, used to sign in and to link a phone to your shop
- Optional profile picture and optional shop payment QR / UPI id shown to your customers
- Account status (active / deactivated) and sign-in activity
2.2 Customer and plan information you enter
- Customer name, phone number, email and address
- An optional customer photo (JPEG or PNG) shown beside the name in your customer list
- IMEI and device model — optional; they are not required to create a customer
- Sale price, down payment, interest rate, tenure, EMI amount, due dates and grace period
- Payment link (pay URL) and support phone number shown to your customers
- Enrolment codes and unlock codes issued to a customer
- Records of payments marked paid, reminders sent and control actions taken
2.3 Information the enrolled device reports
When the app is installed on a customer's phone and linked to a shop, the device reports:
- Android ID, device brand, manufacturer, model and Android OS version
- IMEI(s) and the phone numbers / carrier of the SIM slots (read best-effort; unavailable fields are simply omitted)
- Device state (active / grace / locked / released), the lock deadline the phone is enforcing, last-seen time and battery-independent sync status
- The Google account address, only if the user taps "Grant Google account access" on the setup screen — used solely to verify Factory Reset Protection
- An FCM push token, so commands and updates reach the phone quickly
- The list of installed apps, used only to apply the app-blocking control if the seller switches it on
- The result of any dashboard command the phone carried out (location fix, lock-screen password set/cleared, reboot, warning tone, wallpaper, FRP arming)
- The consent the buyer ticked on the linking screen, with its timestamp
2.4 Location
Latitude, longitude, accuracy, source (GPS / network / last known) and timestamp are collected only when someone presses "Get Location" on the dashboard for that device. Each fix is stored against the device and shown on the dashboard map as history. The app does not track the device continuously or in the background.
2.5 Reminders and activity records
- Reminders sent to your phone by SMS or WhatsApp through our delivery providers (Twilio and GreenAPI): your number and the reminder text
- An activity timeline on the server (device linked, state changed, payment marked, control toggled, lock applied) kept as an audit trail
2.6 Technical and log data
- IP address, request time, response status and user agent in server logs
- Health-check and error information used to keep the Service running
2.7 What we do not collect
- No card numbers, UPI PINs or bank credentials. Payments happen on your payment provider's own page opened from the app — we never see or store them.
- We do not read your SMS inbox, contacts, call log, photos or files on the enrolled phone.
- We do not sell personal data to anyone.
3. How we use the information
- To provide, operate and support the Service and your account
- To record the financing arrangement and calculate/display the EMI schedule
- To send payment reminders and due-date notifications
- To keep the enrolled phone in line with the schedule (grace period, lock screen, restrictions) and to protect the device against reset or tampering while it is financed
- To show dashboards, device details and location history to the party responsible for the finance
- To detect abuse, secure the Service and keep an audit trail of actions
- To comply with legal obligations and respond to lawful requests
4. Device administration — what the app does to the phone
The app runs as Android's Device Owner (a device-policy controller). During the financing term it may:
- Block factory reset, safe boot, date/time changes (so the payment clock cannot be wound back), new user creation, USB debugging and USB file transfer
- Suspend the phone's Settings launcher and, if the seller enables it, other chosen apps while the device is locked
- Disable the camera and restrict outgoing calls, if those controls are switched on
- Show a full-screen lock with the seller's message and wallpaper, plus an optional warning tone
- Set or clear the lock-screen password (always through Android's own confirmation dialog), reboot the device, and open Android's "add a Google account" screen to arm Factory Reset Protection
- Block its own uninstall until the device is released by the seller
The app also uses an Accessibility service that watches only which app comes to the foreground while the device is locked, so the lock screen can be raised again. It does not read your messages, keystrokes, browsing or anything on your screen, and it never interferes with the dialler.
Emergency calls are always available. The dialler and emergency-call path are never blocked, including while the device is locked.
Every restriction above is cleared when the seller releases the device.
5. Legal basis and consent
- Dashboard users consent to the processing described here by creating an account and using the Service.
- The buyer consents on the phone when they tick the consent checkbox and complete linking, and by installing the app as a device administrator. The retailer is responsible for obtaining that consent and for giving the buyer this policy before enrolment.
- We process personal data in accordance with applicable Indian law, including the Digital Personal Data Protection Act, 2023.
6. When we share information
- With the seller, dealer or administrator who owns the record — the party that financed the device sees the customer, plan, device and location data you entered or that the device reported.
- With service providers who help us run the Service: our hosting provider, Google (Firebase Cloud Messaging / Play services), Twilio (SMS), GreenAPI (WhatsApp) and OpenStreetMap (map tiles).
- With your payment provider — only the details needed to open your payment page; we do not pass on your card or UPI credentials.
- With authorities, when disclosure is required by law or a lawful request.
- In a business transfer, such as a merger or sale of the Service, subject to this policy.
We do not sell personal data, and we do not share it for third-party advertising.
7. Third-party services
The Service relies on third parties that operate under their own privacy policies:
- Google Firebase Cloud Messaging and Google Play services — Google Privacy Policy
- Twilio (SMS delivery) — Twilio Privacy Policy
- GreenAPI (WhatsApp delivery) — green-api.com
- OpenStreetMap (map tiles and links) — OpenStreetMap / OSMF Privacy Policy
8. Retention and deletion
- Account and customer data are kept while your account is active and while the related financing arrangement exists.
- Deleting a customer from the dashboard removes their record, photo, device, actions and stored location history.
- Server logs are kept only for as long as needed for security and operations.
- We retain data longer only where a law or a legitimate dispute requires it; when it is no longer needed we delete or anonymise it.
9. Security
- All traffic travels over HTTPS/TLS.
- Passwords are stored as salted scrypt hashes; sessions use signed tokens.
- Access is role-based: retailers and dealers only reach their own accounts, customers and devices.
- Servers are access-controlled by our hosting provider.
No method of transmission or storage is completely secure, but we work to protect your data against unauthorised access, alteration or loss.
10. Your rights
Subject to applicable law, you can ask us to:
- Give you a copy of the personal data we hold about you
- Correct data that is inaccurate or incomplete
- Delete your personal data
- Withdraw consent you previously gave, or restrict how the data is used
- Redress any grievance in the manner prescribed by law
Send requests to emi.letzshop1@gmail.com; we answer within the period required by applicable law. Customers may also ask the retailer who financed them, and we will act on their instruction together with your request.
About uninstalling: while a device is enrolled and unpaid, the app blocks its own uninstall — this is a disclosed part of the device-administration service. The seller must release the device first; after release the app can be removed normally and stops collecting anything.
11. Children
The Service is intended for adults entering or administering a financing agreement. It is not directed at children, and we do not knowingly collect personal data from anyone under 18.
12. Where data is processed
Your data is stored on servers operated by our hosting provider. By using the Service you consent to that processing. We do not knowingly process data in a way that applicable law does not permit.
13. Changes to this policy
We may update this policy from time to time. The current version and its effective date are always published at https://letzpaylocker.info/privacy-policy. Continuing to use the Service after an update means you accept the revised policy.
14. Contact
LetzPay Locker Privacy questions and data requests: emi.letzshop1@gmail.com Dashboard: https://letzpaylocker.info
LetzPay Locker