Value Garage Private Limited ("Company", "we", "us", "our") operates the StopTap mobile application (the "App"). This Privacy Policy ("Policy") explains how we collect, use, disclose, and safeguard your information when you use our App.
This Policy does not cover the privacy practices of any third-party application, website, or service that you may access through links, integrations or deep-links from our Platform (for example, your UPI app, your bank's app, or your email provider). We encourage you to read those parties' privacy policies separately.
1. Plain-language summary
- The App reads your bank and financial-entity SMS messages on your phone and parses them on your device. We also upload those financial SMS (only messages from banks and financial senders) to our servers in encrypted form, so we can keep improving how accurately they are read. Personal SMS from individuals are filtered out and are never read or uploaded.
- We use this information so we can show you every recurring auto-debit running on your bank account in one place and help you cancel ones you no longer want, and to maintain and improve detection accuracy over time.
- Our servers are located in India (Mumbai).
- From version 1.1.33 onwards, the App includes the Meta (Facebook) SDK so we can measure which advertising campaigns drive new installs and optimise our marketing spend. This means your Android Advertising ID and a small set of standard funnel events (such as "OTP requested" or "cancel mandate clicked") are shared with Meta. We do not share your phone number, name, SMS content, mandate details, or any other personal data with Meta. You can reset or delete the Advertising ID at any time from your device's Settings → Privacy → Ads.
- You can withdraw consent or delete your account at any time from the Settings screen.
2. Information we collect
We collect only the data necessary to provide the App's core functions. We classify the data we process into the following categories:
2.1. Identification data
At Signup, we collect:
| Data point | Source | Purpose |
|---|---|---|
| Mobile phone number | Entered by you, verified via a one-time SMS OTP | For Authentication |
2.2. Device and technical data
We automatically collect:
| Data point | Purpose | |
|---|---|---|
| Device model, operating system version | Compatibility, debugging | |
| Firebase Cloud Messaging (FCM) token | Push notifications | |
| App version | Support and crash diagnosis | |
| Crash logs and diagnostic data | Stability of the App | |
2.3. SMS Data
This is the central data category for the App. The App parses your bank and financial-entity SMS messages on your device to power its features. We transmit and store two things on our servers: (a) the structured metadata listed below, and (b) the financial SMS messages themselves, stored in encrypted form, so we can refine and re-run our parsing over time and detect more of your auto-debits accurately. Only messages from banks and financial entities are stored; personal SMS from individuals are filtered out and are never read, transmitted, or stored. Stored financial SMS are retained for up to 18 months and then automatically deleted. The structured metadata includes:
- Merchant's name (as appearing in the SMS)
- Debit amount, Debit date and frequency (monthly, quarterly, annual, variable)
- Mandate identifier (UMN, UMRN, or Standing Instruction reference)
- UPI handle of the merchant
- VPA handle of the user
- The UPI app via which the mandate was registered (e.g. PhonePe, Google Pay, Paytm etc.)
- Mandate status (active, trial, possibly inactive, cancelled)
- Lender, Loan account number, EMI amount and Status
- Salary or other income credit details
- Bank name, last four digits of the relevant account number and balance amount
- Credit card provider, last 4 digits and outstanding amount
Purpose: To automatically detect autopay transactions, EMIs, credit card and other recurring payments and receipts mentioned in the banks or other financial entities SMS messages. Without SMS permission we cannot detect autopay transactions or help users cancel them.
2.4. Advertising ID and marketing analytics
From version 1.1.33 of the App onwards, we use the Meta (Facebook) SDK for measuring the performance of our app-install advertising campaigns. This SDK collects, on first launch and during specific in-app actions, the following:
- Your Android Advertising ID (a resettable identifier provided by the Android operating system specifically for advertising attribution).
- Standard install attribution signals — the timestamp of your first app launch and subsequent app opens.
- A small fixed set of in-app funnel events: OTP requested, OTP verified / signup completed, SMS permission granted, and cancel-mandate button clicked. Each event is just the event name and timestamp; no associated personal data, mandate metadata, or message content is sent.
- The fact that you have uninstalled the App, detected by Meta sending a silent push notification to your device's Firebase Cloud Messaging token. (No notification is shown to you.)
This data is sent to Meta Platforms, Inc. (Facebook) under their Privacy Policy and is used to (a) attribute new installs of the App to specific Meta advertising campaigns, (b) optimise the targeting of those campaigns to people more likely to install and use the App, and (c) measure post-install retention by detecting uninstalls.
Opt-out: at the operating system level, you can reset or delete your Android Advertising ID at any time via Settings → Privacy → Ads (the exact path varies by Android version and device manufacturer). Once deleted, the SDK receives a zeroed-out identifier and Meta cannot attribute your activity to a specific device.
We do not share with Meta: your phone number, your name, the contents of any SMS message, the merchant or amount or identifier of any mandate, your bank or account information, your authentication tokens, or any other content covered by sections 2.1 to 2.3.
2.5. SMS Permission Disclosure (Google Play Compliance)
In compliance with Google Play's Permissions and APIs that Access Sensitive Information policy, we make the following disclosures regarding our use of the READ_SMS permission:
- Core feature use only: SMS access is used solely to detect and track recurring auto-debits, EMIs, standing instructions, salary credits and credit-card transactions from messages sent by banks and other financial entities. It is not used for advertising, marketing, profile-building, or any purpose unrelated to the App's core functionality.
- Processing and storage: SMS parsing runs on your device to power the App's features. In addition, the financial SMS — only those from banks and financial senders — are uploaded to and stored on our servers in encrypted form, retained for up to 18 months, solely to maintain and improve detection accuracy. This is never used for advertising, profiling, or sale. Personal SMS from individuals are filtered out and are never uploaded or stored. See section 2.3.
- Sender filtering: The App only reads SMS messages from transactional senders (banks, NBFCs, UPI service providers, card networks, and other financial entities identified by their DLT-registered sender IDs). Personal SMS messages from individuals or non-financial senders are filtered out and never accessed by the App.
- Permission is required for core functionality: SMS access is necessary to provide the App's primary feature of automatic autopay detection. If you do not grant or later revoke this permission, the automatic detection feature will not function; however, you may continue to use other features of the App and may revoke the permission at any time through your Android device's Settings → Apps → StopTap → Permissions.
- No sharing of SMS content: We do not sell, rent, or share SMS data or any information derived from it with advertisers, data brokers, or any unaffiliated third party for marketing or commercial purposes.
3. Information we do not collect
For clarity:
- We do not read, upload, or store SMS messages from personal or non-financial senders. Only messages from banks and financial entities are processed and stored (in encrypted form), as described in section 2.3.
- We do not collect or process your Aadhaar number, PAN, passport, or any other government-issued identity number.
- We do not collect your bank account password, debit card PIN, credit card CVV, internet banking credentials, or UPI PIN. The App does not have any feature that asks for these, and you should never share them with us or anyone claiming to be us.
- We do not access your device contacts, photos, files, location, microphone, or camera.
- We do not read SMS messages from non-transactional senders. Personal SMS messages from individuals are filtered out at the source.
4. How do we collect information
We collect personal data in the following ways:
- Directly from you — when you enter your phone number, request an OTP, or submit a request through the App.
- Automatically from your device — when the App reads your transactional SMS after you grant SMS-read permission (parsing runs on your device, and the financial SMS are uploaded to our servers in encrypted form as described in section 2.3), and when the App generates technical/diagnostic data.
Lawful basis for processing: We process your personal data on the basis of your free, specific, informed, and unambiguous consent obtained at sign-up and at the time of granting in-app permissions, in accordance with the Digital Personal Data Protection Act, 2023. You may withdraw your consent at any time through the in-app Settings screen or by writing to us at hello@stoptap.in. Withdrawal of consent will not affect the lawfulness of processing carried out before withdrawal.
5. How do we use your information
5.1 Provide core services
- Authenticate your account using phone number verification
- Detect and track your autopay subscriptions
- Display your recurring payment information
5.2 Improve our services
- Analyze app usage patterns (anonymized)
- Fix bugs and improve performance
- Develop new features
5.3 Communication
- Send push notifications
- Provide customer support
- Send important service updates
5.4 Marketing measurement and ad optimisation
- Measure which Meta (Facebook) advertising campaigns are responsible for new App installs.
- Help Meta's ad-delivery system find users similar to those who install and actively use StopTap, so that our advertising spend reaches a more relevant audience.
- Track aggregate uninstall rates so we can identify and fix issues that make users leave.
The data used for this purpose is limited to the items disclosed in section 2.4 (Advertising ID + a small fixed set of standard event names). No data covered by sections 2.1 to 2.3 is used for marketing measurement.
6. Data storage and security
6.1. Storage location
All data is stored on cloud infrastructure located in Mumbai, India. Stored financial SMS are encrypted at rest. Backups may be replicated within other Indian regions for redundancy. No data is stored, replicated, or processed outside India.
6.2. Security measures
We employ industry-standard technical and organizational measures to protect data, including:
- Encryption in transit — all data exchanged between the App and our servers is protected using TLS 1.2 or higher.
- Encryption at rest — sensitive fields (authentication tokens, mandate identifiers) are stored encrypted in our database, and authentication tokens on your device are stored using Android Encrypted Shared Preferences.
- Network segmentation — production databases are not directly exposed to the public internet.
- Access control — only authorised personnel of Value Garage Private Limited may access user data, and access is logged and audited.
- Periodic review — we periodically review our security practices and update them in line with industry standards.
7. Sharing of personal data with third parties
We share personal data only with the following categories of third parties, only to the extent necessary for the purposes listed:
| Third party | What we share | Purpose |
|---|---|---|
| Fast2SMS (operated by Walkover Web Solutions Pvt. Ltd.) | Phone number, OTP code | Delivery of one-time passwords |
| Google LLC (Firebase Cloud Messaging, Crashlytics, Analytics for Firebase) | FCM token, device data, crash logs, in-app event data | Push notifications, crash reporting, product analytics |
| Meta Platforms, Inc. (Facebook SDK) | Android Advertising ID, install + app-open timestamps, the four event names listed in section 2.4, and (for uninstall detection) FCM token reachability | Attribution and optimisation of our app-install advertising campaigns; uninstall measurement |
| DigitalOcean LLC (Mumbai region) | All backend personal data | Cloud hosting, database, compute |
We do not "sell" your personal data to anyone for advertising or any other commercial purpose.
We may also disclose personal data:
- To law enforcement, regulators, or courts when required by Indian law, court order, or a lawful request from a government agency;
- To our professional advisors (lawyers, auditors, accountants) under confidentiality;
- In connection with a corporate transaction — such as a merger, acquisition, financing, or sale of assets — provided the recipient is bound by data protection terms at least as protective as this Policy.
8. Your rights
You have the right to:
- 8.1 Access your data — request a copy of the personal data we hold about you.
- 8.2 Correct your data — update or correct inaccurate information.
- 8.3 Delete your data — request deletion of your account and associated data.
- 8.4 Withdraw consent — revoke permission for SMS access at any time through device settings.
- 8.5 Data portability — request your data in a portable format.
To exercise these rights, contact us at hello@stoptap.in.
9. Data retention and deletion
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by Indian law.
- Identification data (phone, name) — retained until 30 days after your deletion request.
- Mandate and transaction metadata — retained until 30 days after your deletion request.
- Authentication tokens — automatically refreshed, deleted on logout.
- Anonymized, aggregated statistics — indefinitely (no longer identifies you).
You may request deletion at any time:
- In-app: Settings → Delete account.
- Web: Visit https://www.stoptap.in/delete-account and submit a deletion request using the registered mobile number associated with your account.
- Email: Send a deletion request from your registered email address (or the mobile number on file) to hello@stoptap.in.
We may retain some information for longer where required by law (for example, fraud-prevention records) or where it has been irreversibly anonymized so that it can no longer identify you.
10. Children and minors
The App is not intended for users under 18 years of age. We do not knowingly collect or process personal data of children. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at hello@stoptap.in.
11. Cookies and similar technologies
The App is a native Android application and does not use cookies. The Website uses minimal cookies for essential functions (such as remembering your theme preference) and basic analytics. We will not place non-essential cookies without your consent. A separate cookie banner appears when you first visit the Website.
12. Changes to this Policy
We may update this privacy policy from time to time. We will notify you of any changes by:
- Posting the new privacy policy in the app
- Updating the "last update date"
- Sending a notification for significant changes
Your continued use of the App after changes constitutes acceptance of the updated privacy policy.
13. Contact us
For any questions about this Policy or our data practices, please contact us:
Value Garage Private Limited
Email: hello@stoptap.in
Address: Flat no. 26, Vandana Apartments, Plot no. 42, IP Extension, Delhi 110092, India.
14. Grievance redressal
Under the Digital Personal Data Protection Act, 2023, the Information Technology Act, 2000, and rules made thereunder, the name and contact details of the Grievance Officer are:
Name: Suraj Agarwalla
Designation: Director and Co-founder
Email: suraj@stoptap.in
Alternate email: nevaid@stoptap.in
Phone: +91 98672 70000
Postal address: Grievance Officer, Value Garage Private Limited, Flat no. 26, Vandana Apartments, Plot no. 42, IP Extension, Delhi 110092, India.
This Privacy Policy is governed by the laws of India. Any disputes arising out of or in connection with it will be subject to the exclusive jurisdiction of the courts of Delhi, India.