Privacy Policy
Last Updated: October 24, 2026
Plain English TL;DR
By explicitly opting in, you agree to our privacy practices. We comply with strict data protection laws like the DPDP Act and GDPR.
1. Introduction & Explicit Consent
Cyber Drift Solutions Private Limited ('we', 'our', or 'us') respects your privacy and is strictly committed to protecting your personal data. This Privacy Policy governs the data collection, processing, and storage practices for the CyberTap website, mobile application, and NFC smart cards.
By creating an account and explicitly opting in, you provide your free, specific, informed, and unambiguous consent to the collection and use of your data as outlined here. This document complies with the Digital Personal Data Protection (DPDP) Act, 2023, the IT Act, 2000 (India), and global standards like GDPR.
2. Information We Collect
We collect specific categories of data to engineer a seamless hardware and software networking experience:
When you register an account or purchase a card, we collect your name, email, phone, and shipping/billing addresses. Financial transactions are processed via PCI-DSS compliant gateways; we never store full credit card numbers.
Information you voluntarily upload to be shared upon tapping. The CyberTap app may request Camera and Photo Library permissions strictly for the purpose of uploading your profile images, company logos, and custom banners.
If you enable 'Lead Capture Mode', the contact information submitted by your prospects is securely stored on our servers. We process this data to provide you with visual analytics, dashboards, and (in the future) direct Third-Party CRM integrations. You act as the 'Data Fiduciary' responsible for how you use those leads.
CyberTap will offer an opt-in feature to discover professionals around you at cafes, coworking spaces, and events. With your explicit permission, we will process your real-time Location/GPS data to make your professional profile discoverable to nearby founders, creators, and investors for real-world connections.
3. Advanced App Features & Sharing
CyberTap operates a rich mobile and hardware ecosystem that utilizes specific technologies:
We facilitate the immediate download of VCF (Virtual Contact File) cards upon tapping or scanning. Our app does not require read/write access to your personal phonebook to perform this action. We also utilize Bluetooth, WiFi, and App Clips for frictionless offline sharing.
To ensure you never miss a connection, CyberTap temporarily queues offline tap data (such as contact exchanges in internet dead-zones) and securely syncs it to your analytics dashboard once connectivity is restored.
We plan to offer tiered rewards, enabling discounts at selected QSRs, cafes, and e-commerce partners based on your networking activity. If you participate, we may share anonymized validation tokens with partner brands strictly to process your redemptions securely within the app.
4. Free Accounts & Third-Party Advertising
If you choose to use a free CyberTap digital profile (without purchasing a physical card), we may display third-party advertisements on your public digital profile when it is shared with others.
We partner with established advertising networks (e.g., Google AdSense) to serve these ads. When someone views your free profile, these networks may collect basic, anonymized diagnostic data (like browser type and IP address) to serve relevant advertisements.
You can permanently remove all advertisements from your digital profile by purchasing a CyberTap physical card.
6. How We Use Your Information
We utilize your data strictly to operate and optimize your networking ecosystem. This includes:
- Authenticating access to your dashboard.
- Rendering your digital landing page rapidly upon a tap.
- Processing anonymized usage and crash reports to identify bugs.
- Sending transactional emails and Push Notifications (e.g., 'Someone tapped your card!').
Regarding AI Automations: We do not use your private personal data to train public or third-party Large Language Models (LLMs) without your explicit, separate opt-in consent.
7. Data Sharing & Disclosure
We do not sell, rent, or trade your personal data. We only share data with vetted third-party vendors (e.g., shipping partners, secure cloud hosts) under strict confidentiality agreements.
Data Localization: Our primary secure cloud servers are located in AWS Mumbai, India. If data is processed internationally, we ensure it is protected by standard contractual clauses and DPDP cross-border transfer compliance.
8. Data Security & Breach Protocol
We implement enterprise-grade encryption (TLS/SSL in transit, encrypted at rest) and strict Role-Based Access Control (RBAC).
Breach Notification: In the highly unlikely event of a personal data breach, CyberTap will notify the Data Protection Board of India (DPB) and all affected users within the timeframe mandated by the DPDP Act, providing details of the breach and mitigation steps taken.
9. Your DPDP Data Rights
You maintain absolute authority over your digital presence:
- Right to Access/Rectification: Edit your profile directly via the app.
- Right to Withdraw Consent: You may withdraw your consent for data processing at any time via your dashboard, understanding this will deactivate your NFC hardware.
- Right to Erasure: Request permanent deletion of your account and data.
- Right to Nominate: In compliance with the DPDP Act, you may nominate a trusted individual to exercise your data rights (e.g., delete your profile) in the event of your death or incapacity.
10. Data Retention
We retain your personal data only for as long as your CyberTap account remains active.
Upon requesting account deletion, your public profile is immediately purged, and your NFC card is permanently deactivated. All associated personal data will be wiped from our active databases within 30 days. Transactional/tax records are kept securely for the statutory period required by Indian law.
11. Minors & Children's Privacy
The CyberTap Ecosystem is intended strictly for professionals and individuals aged 18 and older.
In compliance with the DPDP Act, we do not knowingly collect personal data from, or conduct behavioral tracking on, children under 18 without verifiable parental consent. If we discover data from a minor has been collected unlawfully, it will be immediately deleted.
12. Contact & Grievance Officer
In accordance with the DPDP Act, 2023, we have appointed a designated Grievance Officer to address your data concerns. We will respond to all legitimate requests within 30 days.
Grievance Officer: Shail Patel
Designation: Data Protection Officer
Email: privacy@cyberdriftsolutions.tech
Address: Cyber Drift Solutions Private Limited, Vadodara, Gujarat, India.