Last updated: 31 July 2026
Version: 1.0
This Privacy Policy explains how CSS Associates ("ScoutFix", "we", "us", "our"), with registered office at 215, Amar Vihar, Jagadhri, Yamunanagar, 135003, collects, uses, shares, stores, and protects personal data when you use the ScoutFix platform, website at scoutfix.ai, and related services (together, the "Platform").
This Policy is intended to align with the Information Technology Act, 2000 and applicable rules thereunder, and the Digital Personal Data Protection Act, 2023 ("DPDP Act"), as amended and as notified from time to time. Where we determine the purpose and means of processing your personal data, we act as a Data Fiduciary. Where you connect or upload data (including limited guest or operational data held in your systems) and instruct us to process it for diagnosis, matching, or benchmarking, we act as a Data Processor on your documented instructions for that processing.
By creating an account or using the Platform, you acknowledge this Policy. Where the DPDP Act or other applicable law requires consent, we will obtain it (including through in-product notices and controls) before the relevant processing.
1. Who this applies to
This Policy applies to:
- Owners — hotels, resorts, and other hospitality businesses (and their authorised representatives) who use the Platform to diagnose issues and find Vendors;
- Vendors — service providers and agencies (and their authorised representatives) who list on or use the Platform to receive matched leads;
- Team members and invitees added to an Owner or Vendor account; and
- Website visitors who browse scoutfix.ai without an account.
The Platform is for businesses. It is not intended for individual consumers acting in a personal capacity, and not for anyone under 18 (see Section 13).
2. Data we collect
Depending on how you use the Platform, we may collect:
a. Account and profile data — name, business name, email, phone and/or WhatsApp number, role/title, city or region, logo, profile copy, and authentication identifiers (including via our auth provider).
b. Verification and business data (mainly Vendors) — GSTIN, PAN, TAN, CIN/LLPIN, incorporation documents, bank details for payouts or verification, LinkedIn or professional page URLs, team size, year started, client counts, certificates, case studies, and evidence of results.
c. Commercial and listing settings — services offered, bottleneck tags, capacity, commercials, reveal preferences, and related profile settings.
d. Connected and uploaded Owner data — where you connect or upload sources such as website analytics, booking engines, property management systems (PMS), OTA extranets, review profiles, CSVs, or similar sources, we access the data reasonably needed to produce your diagnosis, benchmarks, and matches. This may include operational and booking metrics and, in some cases, limited personal data of guests or end customers held in those systems.
e. Transaction and billing data — Wallet top-ups, reveal / lead fees, invoices, tax identifiers where required, payment status, and payment instructions. Full card or UPI instrument details are handled by our payment partners; we do not store full card numbers.
f. Communications — messages exchanged on the Platform (including Inbox), support correspondence, and related metadata.
g. Contracts and e-sign data — where contract generation or e-signature is used, contract content, signer names and emails, signature status, and related audit metadata from our e-sign partner.
h. Usage and device data — log data, IP address, device and browser information, approximate location derived from IP, referral URLs, and interactions with the Platform, collected automatically including via cookies and similar technologies (Section 10).
i. AI processing inputs and outputs — prompts, uploaded files, connected metrics, diagnosis text, classification results, match rationales, and generated contract drafts produced by or with AI systems we use to operate the Platform.
We do not intentionally collect special-category or sensitive personal data beyond what is needed for verification, payments, or legal compliance, and we ask you not to submit such data unless necessary.
3. How we use data and lawful grounds
We process personal data for the purposes below. Under the DPDP Act, we rely on consent and/or legitimate uses as permitted by law (including processing necessary to provide a service you have requested, or to comply with law). Where a row refers to "service you requested," that means processing needed to perform the Platform features you chose to use.
| Purpose | Ground (indicative) |
|---|---|
| Create and manage accounts; authenticate users; provide the Platform | Consent / service you requested |
| Verify Vendors and issue, withhold, or revoke the Verified badge | Consent / service you requested |
| Produce diagnoses, classifications, matches, rankings, benchmarks, and scores (including via AI) | Consent / service you requested |
| Process Wallet top-ups, lead fees, invoices, and engagement-related payments | Consent / service you requested |
| Facilitate communication between matched Owners and Vendors after contact is unlocked | Consent / service you requested |
| Generate contracts and facilitate e-signature | Consent / service you requested |
| Detect fraud, abuse, fee circumvention, and secure the Platform | Legitimate use / legal obligation / service integrity |
| Comply with tax, accounting, KYC, and other legal requirements | Legal obligation |
| Send transactional / service messages | Service you requested |
| Send marketing communications | Consent (you may withdraw anytime) |
| Improve the Platform using anonymised or aggregated analysis | Legitimate use / consent where required |
| Enforce our Terms, investigate violations, and handle disputes | Legitimate use / legal obligation |
Where we rely on consent, you may withdraw it at any time (Section 9). Withdrawal does not affect processing already completed and may limit or disable related Platform features.
4. How identity sharing and lead charging work
4.1 Vendor masking. Before a Vendor unlocks a lead, a Vendor's identifying details (such as legal name, brand name, logo, website, and direct contact details) may remain masked to Owners. Owners see capability, proof, and fit signals — not necessarily who the Vendor is.
4.2 Owner outreach / match contact. An Owner may express interest in or request contact with a matched Vendor through the Platform.
4.3 Vendor unlock (charge event). A lead fee is charged to the Vendor when the Vendor responds and unlocks the Owner's identity and contact details (or completes the equivalent in-product unlock step shown at the time). Upon unlock:
- we disclose relevant Owner identity and contact details to that Vendor; and
- we disclose the Vendor's identity and contact details to that Owner,
so the parties can communicate and evaluate an engagement.
4.4 Fees. Lead fees are charged to the Vendor from the Vendor's Wallet (or other billing method shown in-product), in Indian Rupees (INR), on the terms in our Terms & Conditions. Owners do not pay reveal or lead fees.
4.5 For more detail on processors used for a specific feature, contact [email protected].
5. Connected data, guest data, and anonymised aggregates
5.1 For connected or uploaded Owner data, we process that data on your instructions to generate diagnoses, benchmarks, matches, and related Platform features. You are responsible for having a lawful basis to share that data with us and for any notices or consents required from your guests, customers, or other individuals.
5.2 You must not connect or upload data you are not authorised to share.
5.3 We may create anonymised and aggregated insights and benchmarks (for example, category or regional averages) that do not identify you or any individual. Anonymised aggregated data is not personal data and may be retained and used to operate and improve the Platform.
5.4 AI systems. We use third-party AI providers (currently including Google Gemini or successor models we configure) to analyse metrics, classify needs, generate diagnoses, assist matching explanations, and draft contracts. Inputs you provide or connect may be sent to those providers for those purposes. We configure and instruct providers not to use your personal data to train their general models where the provider offers that control; where a provider's terms differ, those terms also apply. Do not submit data you are not authorised to process.
6. How we share data
We share personal data only as described below:
- Matched counterparties — after a Vendor unlocks a lead, Owner and Vendor identity/contact details as needed to enable the engagement.
- Service providers / processors — companies that help us operate the Platform, under confidentiality and data-protection obligations, including for example:
- cloud hosting and databases;
- authentication and file storage (e.g. Firebase);
- AI / model providers (e.g. Google Gemini);
- payments (Razorpay);
- e-signature (SignWell);
- communications (email and, if enabled, WhatsApp/SMS providers);
- analytics, error monitoring, and customer support tools;
- verification or KYC partners, where used.
- Legal and safety — where required by law, regulation, court order, or to protect rights, safety, and the integrity of the Platform.
- Business transfers — in connection with a merger, acquisition, financing, or sale of assets, subject to this Policy or a successor policy with equivalent protections.
We do not sell your personal data. We do not allow third-party advertisers to pay to target you with ads inside the Platform based on your ScoutFix profile.
For a current list of material processors relevant to your use of the Platform, contact [email protected].
7. Cross-border transfers
Some service providers may process personal data outside India (including in the United States and other jurisdictions where our processors operate). Where they do, we take steps designed to ensure appropriate safeguards and to comply with applicable transfer restrictions and any Government of India notifications under the DPDP Act. You may contact our Grievance Officer for more information about transfers relevant to your account.
8. Data retention and security
8.1 Retention. We keep personal data only as long as needed for the purposes in this Policy, or longer where required by law (for example, tax and accounting records). Indicative periods:
| Category | Typical retention |
|---|---|
| Account and profile data | For the life of the account, then deletion or anonymisation within 90 days after account closure (subject to legal holds) |
| Verification / KYC documents | For the life of the Vendor relationship plus 7 years, or as required by law |
| Transaction, invoice, and tax records | 8 years, or as required under applicable tax law |
| Diagnosis runs, connected-data extracts, and AI outputs | For the life of the account or project, then deletion/anonymisation on our standard schedule (or earlier on verified erasure request where legally permitted) |
| Messages and support correspondence | For the life of the account plus up to 3 years, unless needed longer for disputes |
| Security and server logs | Typically 12 months, unless needed longer for security or legal reasons |
| Anonymised aggregates | May be retained indefinitely |
Deleting content or closing your account triggers removal of associated personal data on our standard schedule, subject to legal-retention requirements, dispute holds, and backup cycles.
8.2 Security. We use reasonable technical and organisational measures (including access controls, encryption in transit, and least-privilege access) to protect personal data. No system is perfectly secure; we cannot guarantee absolute security. We will notify affected individuals and authorities of a personal-data breach as required by applicable law.
9. Your rights
Subject to the DPDP Act and other applicable law, you may:
- Access and obtain a summary of the personal data we process about you;
- Correct, complete, or update inaccurate or incomplete data;
- Erase personal data that is no longer needed for a stated purpose, or where consent is withdrawn and no other lawful ground applies;
- Withdraw consent where processing is based on consent;
- Nominate another person to exercise your rights in the event of your death or incapacity, where the DPDP Act so provides;
- Seek grievance redressal with us before approaching the Data Protection Board of India.
To exercise these rights, contact our Grievance Officer (Section 12). We will respond within the timelines required by law. We may need to verify your identity. Some data may be retained where law requires or for establishing, exercising, or defending legal claims.
10. Cookies and similar technologies
We use:
- Necessary cookies — required to run and secure the Platform;
- Analytics / functional cookies — to understand usage and improve the product, used with consent where required.
You can manage cookies through your browser settings and any in-product cookie controls we provide. Disabling some cookies may affect functionality.
11. Automated analysis
The Platform uses automated and AI-assisted analysis to classify needs, estimate performance or revenue leakage, and rank or match Vendors. These outputs are decision-support tools for business users; they are not sole determinations of legal rights or eligibility for essential services. You may contact us to seek correction of inaccurate personal data that affects your profile.
12. Grievance Officer and Data Protection contact
In accordance with applicable IT rules and the DPDP Act, our contact for privacy queries, consent withdrawal, rights requests, and complaints is:
Grievance Officer: Nikhil Pal
CSS Associates
215, Amar Vihar, Jagadhri, Yamunanagar, 135003
Email: [email protected]
General enquiries / support: [email protected] · [email protected]
We aim to acknowledge grievances promptly and resolve them within the period required by applicable law.
If ScoutFix is notified as a Significant Data Fiduciary under the DPDP Act, we will appoint a Data Protection Officer as required and update this section.
13. Children
The Platform is for businesses and is not intended for anyone under 18. We do not knowingly process children's personal data. If you believe we have, contact us and we will delete it.
14. Changes to this Policy
We may update this Policy prospectively. For material changes, we will provide notice (for example by email or in-product notice) and update the "Last updated" date. Where changes require fresh consent under applicable law, we will ask for it before relying on the new processing. Continued use after non-material changes take effect constitutes acknowledgement of the updated Policy.
15. Contact
Questions about this Policy or your data:
[email protected] · [email protected]
Grievances: [email protected]
