Legal & Data Policy
Consolidated Legal, Data Collection, Cookie, Retention and Deletion policies applicable to the Fender Platform.
This Legal & Data Policy ("Policy") explains certain legal, data collection, cookie, retention and deletion practices applicable to Fender, including FenderApp.com, the Fender web application, mobile applications and related services (collectively, the "Fender Platform"). The Fender Platform is owned and operated by Iradium Automobiles Private Limited, Pune, Maharashtra, India.
This Policy should be read together with the Fender Privacy Policy and Terms of Use. India's current data-protection framework includes the Digital Personal Data Protection Rules, 2025, while electronic records and transactions are also governed by the Information Technology Act, 2000.
1. Purpose of this Policy
This Policy consolidates Fender's policies concerning:
- Collection of data
- Cookies and similar technologies
- Storage of information
- Data retention
- Data deletion
- Account closure
- Backups
- Local and offline storage
- Legal records
- User responsibilities concerning uploaded information
- Requests relating to stored data
Part A — Data Collection Policy
2. Data We Collect
Fender processes information required to provide garage and workshop management functionality. Depending on the features used, this may include the following.
2.1 Workshop Information
- Garage or workshop name
- Owner or authorised contact name
- Mobile number
- WhatsApp number
- Business address
- City
- State
- PIN code
- GSTIN
- Workshop logo
- Branch information
- Workshop settings
2.2 User Information
- Name
- Mobile number
- Role
- Branch
- Preferred language
- Login and authentication details
- Device information
- User status
- Usage activity
2.3 Workshop Customer Information
- Customer name
- Mobile number
- WhatsApp number
- Email address
- Address, City, State
- GSTIN, where applicable
- Service history
- Workshop notes
The workshop is responsible for ensuring that it is authorised to collect and enter such information into Fender.
2.4 Vehicle Information
- Registration number
- Make, Model, Variant, Fuel type
- VIN or chassis number
- Engine number
- Manufacturing year
- Odometer
- Fuel level
- Vehicle condition
- Service history
- Insurance information (where entered)
- Vehicle photographs
- Scratch, dent and inspection photographs
2.5 Workshop Operational Information
- Appointments
- Job Cards
- Customer complaints
- Service advisor findings
- Repair tasks
- Mechanic assignments
- Parts requirements
- Parts issued
- Estimates
- Invoices
- Payments
- Gate Passes
- Inventory records
- Purchases
- Inward records
- Purchase returns
- Counter sales
- Future suggested work
- Delivery records
2.6 Spare Parts Enquiries
When a workshop uses "Submit Enquiry to SparesHub", Fender may collect and process workshop details, Job Card number, vehicle details, VIN where available, part name and number, quantity, description, required date, urgency, photographs and relevant enquiry notes. This information may be made available to authorised SparesHub personnel for responding to the enquiry and facilitating potential spare-parts supply.
2.7 Technical Information
- IP address
- Browser
- Device type
- Operating system
- App version
- Login history
- Session information
- Error logs
- Sync logs
- Connectivity status
- Pages and modules used
- Feature usage
- Security events
- Date and time of activity
3. Why We Collect Data
Information may be collected and processed to create and manage Fender accounts, operate workshop management functionality, maintain customer and vehicle histories, generate Job Cards, schedule appointments, generate estimates, manage spare-parts inventory, generate invoices and Gate Passes, record payments, provide customer support, synchronise data between devices, maintain security, prevent fraud and misuse, improve Fender, understand platform usage, identify and facilitate spare-parts requirements, respond to SparesHub parts enquiries, maintain legally or commercially necessary records and comply with applicable law.
4. Data Minimisation
Users should enter only information reasonably necessary for workshop operations. Users should not use Fender to store unnecessary information such as banking passwords, UPI PINs, card PINs, full payment-card authentication data, personal passwords, medical information unrelated to workshop activities, Aadhaar information unless genuinely necessary and legally permitted, unrelated sensitive personal documents or information unrelated to legitimate workshop operations.
5. Data Entered by Workshops
Workshops are responsible for ensuring that information they enter into Fender is collected lawfully. The workshop is responsible for providing required notices to its customers, obtaining consent where legally required, ensuring information is relevant, keeping records reasonably accurate, avoiding unnecessary collection and responding appropriately to customer requests concerning information originally collected by that workshop.
6. Administrative Access
Authorised personnel of Iradium Automobiles Private Limited may access Fender data where reasonably necessary for platform administration, support, technical troubleshooting, security, synchronisation, compliance, spare-parts enquiries, demand analysis and product improvement. Access should be based on internal roles and business need. Not every Fender or SparesHub employee should have unrestricted access to all workshop information.
Part B — Cookie Policy
7. What Are Cookies?
Cookies are small files or similar browser technologies used to store or retrieve information when a user accesses a website or web application. FenderApp.com and the Fender web application may use cookies and similar technologies to support application functionality.
8. Types of Cookies We May Use
8.1 Strictly Necessary Cookies
These may be required for login, authentication, session management, security, fraud prevention, language selection, maintaining application state and core Fender functionality. Disabling these cookies may prevent parts of Fender from functioning correctly.
8.2 Preference Cookies
These may remember settings such as selected language, branch, display preferences, calendar view and other user preferences.
8.3 Performance and Analytics Cookies
Where enabled, these may help us understand which pages are used, which features are used, application performance, errors, navigation patterns and general usage trends.
8.4 Marketing Cookies
Fender may use marketing or advertising cookies only where such tools are implemented and where their use is permitted under applicable law. Such tools may include advertising or conversion-measurement technologies used on Fender's public website.
9. Cookie Consent
Where applicable law requires consent for non-essential cookies, Fender may provide a cookie banner or consent-management mechanism. Users may be given options such as Accept All, Reject Non-Essential or Manage Preferences. Strictly necessary cookies may remain active because they are required for essential platform functionality.
10. Managing Cookies
Users may also manage or delete cookies through their browser settings. Restricting cookies may affect login, saved preferences, session continuity and other website or application functions.
11. Mobile Applications
Native Fender mobile applications may use technologies similar to cookies, including local application storage, device identifiers, secure authentication tokens, cached application data, notification tokens and analytics identifiers where enabled. These technologies are governed by the same general principles described in this Policy.
Part C — Data Storage and Retention Policy
12. General Retention Principle
We retain information only for as long as reasonably required for providing Fender, maintaining workshop records, supporting users, security, fraud prevention, resolving disputes, fulfilling contractual obligations, meeting legal and regulatory requirements, maintaining audit records, defending legal claims and legitimate business record-keeping. The DPDP Rules, 2025 form part of India's current regulatory framework for digital personal-data processing.
13. Indicative Retention Categories
Different records may be retained for different periods depending on their nature and legal requirements.
13.1 Active Workshop Account Data
Normally retained while the workshop account remains active. This includes workshop profile, users, customers, vehicles, Job Cards, estimates, invoices, inventory, appointments, Gate Passes and operational history.
13.2 Transactional and Business Records
Records such as invoices, payment records, purchase records, Gate Passes, commercial documents and relevant supporting records may be retained for the period reasonably required under applicable taxation, company, commercial or other legal requirements. Where legal requirements prescribe a longer retention period, the legally required period will prevail.
13.3 Security and Audit Records
We may retain login history, admin-access records, audit logs, sync logs, security events, account changes and relevant technical logs for a reasonable period for security, investigation and compliance purposes.
13.4 Support Information
Support cases and related communication may be retained for a reasonable period after resolution to maintain service history, identify recurring problems, resolve disputes and improve support.
13.5 Spare-Parts Enquiry Records
Enquiries submitted to SparesHub and related commercial records may be retained for follow-up, sales history, dispute resolution, business analytics, product-demand analysis and applicable legal record-keeping.
14. Dormant Accounts
Where an account remains inactive for an extended period, we may notify the workshop, restrict access, archive information, deactivate the account or delete eligible information, subject to applicable legal, contractual and operational requirements.
15. Local Device Storage
Because Fender is designed to work under weak or intermittent internet connectivity, information may temporarily remain stored on a user's device. Local information may include customer records, vehicle records, Job Card drafts, estimates, inspection information, parts records, payment entries, photographs, notes and pending synchronisation records. Once internet connectivity becomes available, Fender may synchronise this information with its servers.
16. Cached Data
Fender may retain cached copies of information to improve application speed, support offline operation, avoid blank screens, maintain recent records during connectivity failure and reduce data usage. Cached data may remain on a device until the application removes it, the user clears eligible cached data, the application is uninstalled or device-level storage is cleared. Users should protect devices containing Fender data using appropriate security controls.
17. Backups
Fender may maintain backups for disaster recovery, data restoration, security, business continuity and technical resilience. Information deleted from active systems may remain temporarily in backups until backup cycles expire. Backup copies are not normally used for ordinary business processing after deletion from active systems.
Part D — Data Deletion Policy
18. User Requests for Deletion
Subject to applicable law, an eligible person may request deletion or erasure of personal information. Requests may be sent to contact@fenderapp.com. The request should contain sufficient information to identify the requester, the relevant workshop or account, the information concerned and the nature of the requested action. We may verify identity before acting on a deletion request.
19. Workshop Account Deletion
A Garage Owner or other authorised person may request closure of the workshop's Fender account. Before account closure, workshops are encouraged to export records they are required to retain. Following a valid account-closure request, Fender may disable access, preserve data temporarily to allow resolution of outstanding issues, delete eligible active data, retain legally required records and remove or anonymise remaining eligible information according to applicable retention schedules.
20. Information That May Not Be Deleted Immediately
Certain information may need to be retained even after a deletion request, including where necessary for tax compliance, company-law requirements, legal proceedings, fraud prevention, security investigations, contract enforcement, outstanding payments, dispute resolution, audit obligations, regulatory requests or establishing, exercising or defending legal claims. Deletion rights are therefore not necessarily absolute.
21. Workshop Customer Requests
Where an individual requests deletion of information that was originally collected and entered by a workshop, the person may be asked to contact the relevant workshop. Where appropriate, Fender may assist the workshop in processing a valid deletion or correction request.
22. User Account Deactivation vs Deletion
Workshop employee or staff user accounts may be deactivated rather than physically deleted where the user has created records such as Job Cards, estimates, inventory transactions, invoices, payment entries, Gate Passes or audit events. The historical record may continue to show the user's name or identifier so the workshop can maintain an accurate audit trail. The deactivated user will no longer be able to access Fender.
23. Deleted Job Cards, Estimates and Invoices
Fender may restrict permanent deletion of operational records. Instead, records may be cancelled, voided, archived or marked inactive. This helps preserve audit history, commercial records, document numbering, customer service history and legal compliance. Invoices or other statutory records should not be permanently deleted where retention is legally required.
24. Deletion from Backups
Where eligible information has been deleted from active systems, residual copies may remain in secure backups for a limited period. Those copies will generally be removed as backups rotate or expire. Restored backups may require deletion processes to be reapplied before the relevant data becomes operationally available again.
25. Anonymisation
Instead of deletion, we may anonymise information where individual identification is no longer required, aggregated analytics are still useful, demand analysis is required or product performance analysis is needed. Once information has been irreversibly anonymised so that an individual cannot reasonably be identified, it may no longer constitute personal data under applicable law.
Part E — Record Accuracy and User Control
26. Correction of Information
Authorised users may be able to update customer contact details, vehicle details, workshop information, user profiles and other operational records. Where a record has become legally or operationally final, Fender may preserve the original record and record a correction or amendment instead of overwriting history.
27. Export of Data
Fender may allow authorised workshop users to export certain information, including Job Cards, estimates, invoices, customer records, inventory information and other reports. Export availability may depend on user role, data type, platform functionality and security restrictions.
28. Account Closure Responsibilities
Before closing an account, workshops should export any information they require for tax compliance, customer history, insurance, accounting, legal disputes, warranty records or business continuity. Iradium Automobiles Private Limited does not guarantee indefinite access to records after account closure.
Part F — Data Security
29. Security Measures
We use reasonable organisational and technical safeguards intended to protect information against unauthorised access, loss, misuse, modification, disclosure and destruction. Measures may include authentication, role-based access, session controls, encryption where appropriate, logging, backups, security monitoring and access restrictions.
30. User Responsibilities
Users should keep login credentials confidential, protect OTPs, use device screen locks, prevent unauthorised staff access, deactivate departed employees promptly, avoid using shared credentials, keep devices updated and report suspicious activity.
31. Data Breaches and Incidents
Where we become aware of a security incident involving personal data, we may investigate, contain the incident, secure affected systems, restore services, notify affected persons where legally required and notify competent authorities where required.
Part G — Third-Party Service Providers
32. Service Providers
Fender may rely on third parties to provide services including cloud hosting, storage, authentication, email, SMS, WhatsApp communications, push notifications, analytics, error monitoring, maps and support infrastructure. Service providers may process data only to the extent reasonably required for their role, subject to applicable contractual and legal obligations.
33. Third-Party Platforms
If users choose to communicate or share documents through services such as WhatsApp, email, mapping services or other third-party applications, the independent privacy practices of those services may apply once information is transmitted to them.
Part H — Policy Changes
34. Changes to this Policy
We may update this Legal & Data Policy from time to time because of changes to Fender, changes in business practices, new features, changes in technology, changes in law, new service providers or security requirements. The updated version will contain a revised effective date. Material changes may also be communicated through Fender or another appropriate channel.
35. Relationship with Other Fender Policies
This Policy should be read together with the Privacy Policy and Terms of Use. If there is a conflict concerning personal-data processing, the Privacy Policy and applicable law will prevail. If there is a conflict concerning contractual use of Fender, the Terms of Use will prevail.
36. Governing Law and Jurisdiction
This Policy is governed by the laws of India. The Information Technology Act, 2000 provides the statutory framework for electronic records and transactions in India. Subject to any mandatory statutory forum or remedy, courts of competent jurisdiction at Pune, Maharashtra, India shall have jurisdiction over matters relating to this Policy.
37. Contact and Grievance Details
For requests concerning data collection, cookies, data retention, data deletion, account closure, privacy, correction of information or this Policy, please use the contact details below.
Pune, Maharashtra, India
