Welcome to Lit Loop. We are committed to protecting your personal information and your right to privacy.
This Privacy Policy explains how we collect, use, and safeguard your information when you use our mobile
app.
1. Information We Collect
We collect information you provide directly to us:
- Account information: your name, email address, and phone number.
- Profile and authentication: password (stored as a secure hash), or Google OAuth tokens if you
sign in with Google.
- Delivery information: your delivery address, including location coordinates when you choose home
delivery.
- Payment information: When you choose to pay via UPI, we collect the UPI Transaction Reference
(UTR) number and an optional payment screenshot you upload. We generate a UPI QR code that
encodes the exact rental amount and order ID — we do NOT collect, process, or store your bank
account number, card details, UPI PIN, or any sensitive banking credentials. Cash payment
selections are recorded but no financial data is collected.
- Rental history: books you have rented, rental status, and dates.
- Communications: messages you send us via email.
We also collect certain information automatically:
- Device push notification token (for sending you order and rental updates).
- IP address and basic device info (for rate limiting and fraud prevention).
- Usage analytics: general app interaction data to improve the service.
2. How We Use Your Information
We use the information we collect to:
- Create and manage your account.
- Process book rental requests and coordinate delivery and pickup.
- Verify payments and prevent fraudulent transactions.
- Send you push notifications about your rental status, payments, and book availability.
- Respond to your customer support enquiries.
- Improve and personalise the app experience.
- Comply with applicable legal obligations.
3. Location Data
If you choose home delivery, we request access to your device location to help you set your delivery
address accurately via Google Maps. We only use your location at the time of address selection and
do not track your location in the background.
4. How We Share Your Information
We do not sell, trade, or rent your personal information to third parties. We may share limited
information with:
- Google (for authentication via Google Sign-In and Maps services).
- Expo (for push notification delivery via Expo Push Notification service).
- Convex (our backend infrastructure provider), who processes data on our behalf under a data
processing agreement.
All third-party providers are required to keep your data secure and confidential.
5. Data Retention
We retain your account data for as long as your account is active. Rental records are retained for a
minimum of 2 years for compliance purposes. You may request deletion of your personal data by
contacting us or using the Delete Account feature in the app.
5a. UPI Payment Data Handling
When you pay using UPI QR:
- We generate a UPI QR code that encodes only: our UPI ID, the rental amount, and your order ID.
- You complete the transaction in your own UPI app (e.g. GPay, PhonePe, Paytm). We never see your
UPI PIN or bank credentials.
- You voluntarily share the UTR (transaction reference ID) so we can verify the payment. This is a
reference number only, not banking data.
- Optional screenshots you upload are stored securely and used only for payment dispute
resolution.
- We do NOT auto-confirm UPI payments. All payments are manually verified by our team.
- UPI payments are collected through our registered UPI ID and are for physical book rental
services only — not for digital goods or in-app credits.
6. Data Security
We implement industry-standard security measures including:
- Passwords are hashed using PBKDF2 with a unique salt and are never stored in plain text.
- Authentication uses short-lived access tokens (JWT) and rotated refresh tokens.
- All data is transmitted over HTTPS/TLS.
Despite our efforts, no method of transmission over the internet is 100% secure. We cannot guarantee
absolute security.
7. Children's Privacy
Lit Loop is not intended for users under the age of 13. We do not knowingly collect personal
information from children. If you believe we have inadvertently collected such data, please contact
us immediately.
8. Your Rights
You have the right to:
- Access the personal data we hold about you.
- Correct inaccurate data.
- Request deletion of your account and associated data.
- Withdraw consent for push notifications at any time via your device settings.
To exercise these rights, contact us at litloopbooks@gmail.com.
9. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes via
in-app notification or email. Continued use of the app after changes constitutes your acceptance of
the updated policy.