Adzora
Legal
Privacy Policy
Last updated: 27 September 2026 (uploaded photos and videos added; how long files are kept after a plan ends)
Adzora (“we”, “us”) helps local businesses manage their Google Business Profile, their Instagram posts and related marketing. Adzora is a product of Codevel Technologies LLP, 3rd Floor, Jakotia Complex, Pochammaidan, Opp: Ratna Hotel, Warangal, Telangana 506002, India. This policy explains what data we collect, why, and the choices you have. We design for consent first, in line with India’s Digital Personal Data Protection (DPDP) Act.
What we collect
- Account details — your name, email address and password (stored hashed), or your Google sign-in identity.
- Business details — your business profile information (name, category, address, hours, photos, reviews and performance metrics) pulled from Google with your permission, plus the brand details you add (logo, colours, tone, services).
- Customer contacts you add — names and phone numbers you provide for review requests, together with their consent status. These are stored per business and never shared across customers or used for anything except the messages you send.
- Photos and videos you upload — kept in our file storage (Cloudflare R2) so they can be posted where you choose. Videos are converted on our servers to a standard format for Instagram; location and other hidden information stored inside a video file is removed, and the original file is deleted as soon as the converted copy exists. Only you (and the people you invite to your business) can see them in the app; they are published only when you approve a post.
- Usage and audit data — actions taken in the app (approvals, publishes, pauses) recorded in an audit log, and technical logs needed to run the service reliably.
How we use it
- To operate the product: create and publish posts you approve, draft review replies, send review requests to opted-in contacts, and show your results.
- To generate content with AI: your brand details and prompts are processed by our AI provider solely to produce your drafts.
- To notify you (in-app, email or WhatsApp, per your preferences) when something needs you.
- To bill you, via our payment provider (Razorpay). We do not store your card or UPI credentials.
We do not sell your data. We do not use your customer contact lists for our own marketing.
Google user data
Adzora connects to Google only when you choose to, using Google’s own sign-in and permission screen. This section explains exactly what we access from Google and what we do with it.
What we access
- Google Sign-In (scopes
openid, email, profile): your name, email address and profile picture, used only to create and sign in to your Adzora account.
- Google Business Profile (scope
https://www.googleapis.com/auth/business.manage, requested only when you tap “Connect Google Business”): the list of business profiles you own or manage, and for the profile you choose — its business information, posts, photos, customer reviews and performance insights (such as calls, direction requests, website clicks and views).
How we use it
- To publish the posts and photos you approve or schedule to your own Business Profile.
- To show you your customer reviews, draft replies for you, and publish the replies you approve.
- To show you your profile’s performance in the Adzora dashboard.
We only act on business profiles that you own or manage and have connected. We never create reviews, and we never change your business information without an action from you.
How we share it
- We do not sell Google user data, and we do not use it for advertising, for credit or lending decisions, or for any purpose unrelated to the features described above.
- We share Google user data only with service providers needed to run those features: our hosting and database provider, and our AI provider, which receives only the text needed to draft a post or review reply for you and is not permitted to use it for its own purposes.
- We do not use Google user data to develop, improve or train generalised AI or machine-learning models.
- Our staff do not read your Google user data unless you ask us to (for example, for support), it is needed for security or to comply with the law, or it has been aggregated and anonymised for internal operations.
How we protect and keep it
- Google access tokens are encrypted at rest and never shown in the app or sent to your browser. All traffic uses HTTPS.
- We keep Google user data only while your business profile is connected. When you disconnect it in Adzora or delete your account, we delete the stored Google tokens straight away and delete the related Google data within 30 days (except where the law requires us to keep records).
- You can also remove Adzora’s access at any time from your Google Account at myaccount.google.com/permissions.
Limited Use. Adzora’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Instagram user data
If your business uses Adzora's Instagram feature, you connect your Instagram professional (Business or Creator) account through Instagram's own login and permission screen. You can disconnect at any time.
- What we access (permissions
instagram_business_basic and instagram_business_content_publish): your Instagram account's id, username, account type and profile picture, and the ability to publish the posts you schedule in Adzora.
- How we use it: only to publish the photos and captions you approve or schedule to your own Instagram account, and to show you whether each post went live (with its link). We don't read your followers, messages or other people's content.
- Storage: the Instagram access token is encrypted at rest, never shown in the app, and renewed automatically while you stay connected. The photos you post are hosted by us at a public web address because Instagram downloads them from there.
- Sharing: we don't sell Instagram data or use it for advertising, and we don't use it to train AI models.
- Deletion: disconnecting in Adzora deletes the stored token immediately. You can also remove Adzora in Instagram (Settings → Website permissions / Apps and websites); when Meta tells us you did, we delete the token automatically. You can see the status of a deletion request at adzora.co.in/data-deletion, or write to hello@adzora.co.in.
Consent and messaging
Review requests are sent only to contacts you confirm have opted in, with frequency limits, and recipients can opt out at any time — opt-outs are honoured automatically.
Your rights
From Settings you can request an export of your data or the deletion of your account and data at any time, and you can disconnect Adzora from your Google account whenever you choose. You can also start account deletion from the web, without the app, at adzora.co.in/delete-account. For anything else, write to hello@adzora.co.in.
Security and retention
Access tokens and secrets are encrypted at rest, access is role-based and audited, and we keep data only as long as needed to provide the service or as required by law. When you delete a photo or video, its file is removed from our storage; uploads that are never finished are removed automatically within a day; and when you close your account all of your files are deleted. If a plan ends, your files are kept read-only for 90 days (we tell you 30 and 7 days before that date) so you can download them or choose a plan again; after that we may remove the files above the Free allowance.
Changes
If this policy changes materially, we will notify you in the app or by email before the change takes effect.
Contact
Codevel Technologies LLP (Adzora), 3rd Floor, Jakotia Complex, Pochammaidan, Opp: Ratna Hotel, Warangal, Telangana 506002, India · hello@adzora.co.in
← Back to adzora.co.in