OkGate← Back to home

Legal

Privacy Policy

OkGate is a free, ad-supported society and gated-community management platform owned and operated by Honco Pvt. Ltd. ("Honco", "we", "us", "our"). This Privacy Policy explains what information OkGate collects, how and why we use it, who we share it with, how long we keep it, and the rights you have over your data. It is written to comply with India's Digital Personal Data Protection Act, 2023 (the "DPDP Act"), the Information Technology Act, 2000, and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (the "SPDI Rules"). We have tried to keep it in plain English while still being complete. If anything is unclear, or to exercise your rights or raise a grievance, please write to us at privacy@okgate.co. By creating an account or using OkGate (the okgate.co website, our mobile apps, and related services, together the "Platform"), you acknowledge that you have read and understood this Policy and, where we ask for it, provide your consent as described in Section 5.

Last updated: 23 July 2026 · Version 1.0Operated by Honco Pvt. Ltd.
01

Who We Are, and Our Dual Role (Fiduciary vs. Processor)

OkGate is operated by Honco Pvt. Ltd. We provide software that residents' welfare associations, apartment societies, and gated communities (each an "RWA" or "Society") use to manage day-to-day community operations — visitor and gate management, resident and staff records, maintenance billing, complaints, notices, amenities, and safety alerts. The Platform currently operates in and is intended for India. Support for the UAE is planned but not yet enabled; if and when we launch there, we will update this Policy to add the additional legal provisions (including UAE Federal Decree-Law No. 45 of 2021 on Personal Data Protection) that a UAE service requires.

It is important to understand that OkGate plays two different roles depending on the type of data, and this affects who is accountable for it:

This distinction matters for your rights. For account/platform data, you can exercise your rights directly with us. For Society-operational data, your Society is the primary decision-maker; we will help you reach them and will act on their instructions and on lawful requests, but the Society controls what happens to that data. Where a Society is the Data Fiduciary, we handle that data only on its documented instructions and under a written data-processing agreement ("DPA") that binds OkGate as its Data Processor. This Policy describes how OkGate handles data; it does not replace, and is not a substitute for, your Society's own legal obligations as Data Fiduciary or any privacy notice your Society gives its residents.

  • Data Fiduciary (we decide the purpose and means): For your OkGate account and platform-level data — for example, your login identity (name, phone, optional email, hashed password), device push tokens, sales/marketing leads captured on our landing page, advertising measurement data, and our own security and audit logs — Honco is the Data Fiduciary and is directly responsible to you under the DPDP Act.
  • Data Processor (we act on the Society's instructions): For the operational data a Society manages inside OkGate about its residents and community — for example, membership and tenancy records, family members, vehicles, visitor logs, complaints, billing, and staff/domestic-help records — the Society (RWA) is the Data Fiduciary and OkGate acts as its Data Processor under a written DPA. In these cases the Society decides why and how the data is used; we process it on their behalf.
02

The Information We Collect

We collect only the information needed to run a community-management platform. What we hold depends on your role — resident/owner/tenant, family member, guard, committee member, Society or platform admin, visitor/guest, domestic help or Society staff, vendor, or sales lead. We do not collect Aadhaar or other government-ID numbers, date of birth, or gender through the Platform, and we do not build behavioural interest profiles of you.

Account and identity data. Your full name, mobile phone number (your unique login identity), an optional email address, a securely hashed password (accounts that log in only by OTP have no stored password at all), and an optional profile photo. Committee/admin and platform-staff accounts also hold name, email, phone, and a hashed password.

Residence and household data. Your Society's name and address (including city, state, pincode, region and timezone), your block/tower, unit/flat number, floor, unit type (e.g. 1BHK/2BHK), area, owner-vs-tenant status, move-in date, and KYC verification status. Household details include family members (name, relationship, optional phone), pets (name, species, breed, vaccination status and document), emergency contacts (name, phone, relationship), and vehicles (registration/number plate, type, parking slot/sticker).

Community, safety and operational data. Visitor logs and visitor photos, guest invites and QR passes, gate passes and collection OTPs, kid-exit authorizations (including the child's name and who is escorting them), move in/out requests and documents, domestic-help and staff records (including entry passcodes, attendance, guard patrol logs, and resident reviews/ratings), helpdesk/complaint tickets and comments, in-app messages and conversations, polls/votes, meetings and minutes, notice read-receipts, groups, and SOS/panic alerts.

Financial data. Per-unit invoices, line items, arrears, late fees, GST, payments (amount, mode such as UPI/card/netbanking/cash/cheque, transaction and gateway references), advance and prepaid-meter balances, security deposits, and credit notes. For counterparties, we may hold vendor and non-member contact and bank details and Society bank account numbers/IFSC.

Marketplace and amenities. Resident marketplace listings (title, price, photos, location text, seller identity), amenity bookings and booking passcodes, and personal home-planner tasks/reminders.

Device and technical data. Per-device push notification tokens with the device platform (iOS/Android/web) and last-seen time; delivered notification content; hashed refresh tokens for your session; and audit logs recording who did what and the before/after of changes. Note that your push token is both collected by us (as Data Fiduciary) and shared with our push providers to deliver alerts (see Sections 4 and 7).

Landing-page leads. If you fill in a form on okgate.co, we collect the contact name, phone, email, Society name, city, flat count, and any message you send.

  • Sensitive-by-context data (handled with extra care under the SPDI Rules): financial information such as bank account numbers, IFSC codes and payment references; passwords (always stored hashed); and information about minors (see Section 9).
  • What we do NOT collect: no GPS/precise location; no device contacts/address book; no microphone/audio; no Aadhaar or government-ID numbers; no date of birth or gender; and no biometric templates (see the note on Face ID and "face" attendance in Section 4).
03

Information About Other People That You Provide

OkGate is a community tool, so residents, guards, and committee members regularly enter information about other people — for example, a guard logs a visitor's name, phone, vehicle number and photo; a resident invites a guest or authorizes a child's exit; a committee member onboards domestic help or staff; a resident lists an emergency contact or a family member.

When you enter information about a visitor, guest, family member, domestic worker, staff member, vendor, or emergency contact, you agree that you are entitled to share it and that, where you are personally required to, you have informed that person. This is a practical assurance we ask of you; it does not by itself make you a Data Fiduciary or transfer legal responsibility to you. Under the DPDP Act, the obligation to give notice to, and where required obtain the consent of, these individuals sits with the Society as Data Fiduciary (with OkGate as its Processor), not with the individual resident who entered the record. We make this operational data available to the relevant Society/committee, guards and residents, as appropriate to each role, so the community can function.

Visitors and guests: your name, phone, vehicle number, purpose of visit and (at the gate) your photo may be recorded by the Society to manage entry and for security. If you are a visitor and have a question about your data, please contact the Society you visited; we will help you reach them.

04

Automatically-Collected and Device Data (Mobile Permissions)

Our mobile apps ask for certain device permissions, and only for the specific features that need them. We ask at the moment the feature is used, and you can decline or later change these in your device settings (some features may then not work).

We want to be precise about two things. Face ID / Touch ID / fingerprint unlock is handled entirely on your device by your operating system to lock the app — no biometric data ever leaves your device or reaches our servers. Similarly, although staff attendance can be marked using a "face" method, we store only a flag that this method was used; we do not store any facial template, image embedding, or biometric identifier.

Forward-looking note: in-app voice/video calling is not currently active in the app (it is a placeholder that performs no call). If we enable real calling in the future, we will request microphone (and, for video, camera) permission at that time and update this Policy before doing so.

  • Camera: to capture visitor/vehicle/entry photos at the gate and set your profile picture, and to scan gate-pass and attendance QR codes.
  • Photos/Gallery: to let you pick an existing image as your avatar or as an attachment.
  • Push notifications: to deliver visitor approvals, gate-entry alerts, SOS notifications, and Society announcements (including actionable allow/deny and SOS-acknowledge actions).
  • Biometric unlock (Face ID/Touch ID/fingerprint): only to lock/unlock the app on-device; no biometric data is transmitted or stored by us.
  • Background app refresh and battery-optimization exemption: to keep notifications and offline sync working reliably when the app is in the background.
  • Device/platform info: platform (iOS/Android) and app/build version, used to route push notifications correctly and for support and diagnostics.
  • We do NOT access your location/GPS, your device contacts/address book, or your microphone.
06

Our Ad-Supported Model and Advertising

OkGate is free because it is ad-supported. Ads help us keep the Platform free for Societies and residents. We have designed advertising to be privacy-protective, and we want to be explicit about what we do and do not do.

We do NOT sell your personal data to advertisers. Advertisers never receive your name, phone number, email, unit/flat number, device identifiers, or any record of your individual activity. Advertisers only receive aggregated, non-identifying performance and reach numbers — for example, total or per-state/per-city impression and click counts, click-through rate, estimated reach, and pricing.

Ad targeting is contextual only — presently applied at the Society level (and by broader region where enabled), not on any behavioural or interest profile of you. We record ad impressions and clicks as our own first-party measurement data (campaign/creative/placement IDs, Society/city, and a timestamp). Where an internal pseudonymous user reference is used, it is used solely by us to cap how often you see the same ad each day and for aggregate, distinct-user (e.g. monthly-active-user) analytics — it is never handed to advertisers.

  • No behavioural or interest-based profiling of residents drives ad targeting.
  • No resident-level records are ever sold or transmitted to advertisers.
  • Advertiser data we hold (advertiser name, contact, billing, budgets, creatives, and geographic targeting values) is business data, not resident data.
07

How We Share Information

We do not sell your personal data. We share it only in the limited ways described below, and only as needed to run the Platform, comply with the law, or act on your Society's instructions.

With your Society and its authorized people. Operational data is visible, as appropriate to each role, to your Society's committee/admins, guards, and (where relevant) other residents — for example, a committee member can see membership records; a guard can see and create visitor logs. The Society (Data Fiduciary) governs this access.

With our service providers (Data Processors). We use a small number of trusted providers who process data only on our instructions and are bound to protect it. Their credentials in our systems are stored encrypted (AES-GCM), and payment-gateway details are handled securely.

For legal and safety reasons. We may disclose data if required by law, court order, or a lawful request from a government or regulatory authority, or where necessary to protect the rights, safety, or security of users, the public, or Honco (for example, responding to a safety emergency or investigating fraud or abuse).

In a business transfer. If Honco is involved in a merger, acquisition, financing, or sale of assets, personal data may be transferred as part of that transaction, subject to this Policy and applicable law.

  • Razorpay — payment gateway. When you pay maintenance dues, we send the payment amount, currency, and internal references (invoice, unit and Society IDs) to create the order. We do NOT send your name, email or phone in that order payload. You enter your card/UPI/bank details directly with Razorpay in its own secure checkout; those payment-instrument details do not pass through OkGate's servers. Razorpay acts as an independent payment processor for that instrument data.
  • SmartPing — SMS/OTP delivery. We send your mobile number and the message text (including OTP codes and notices) so the message can be delivered.
  • Cloud object storage (AWS S3, or S3-compatible Cloudflare R2 / MinIO) — media and document hosting for uploaded images and files (e.g. avatars, visitor/gate-pass photos, listing photos, and documents), referenced by URL. Depending on deployment, S3-compatible storage (R2/MinIO) may be self-hosted infrastructure rather than a distinct third party.
  • Push providers — Firebase Cloud Messaging (Google) and the Expo Push Service (which relays to FCM/APNs). We send device push tokens, the platform, and notification title/body/data so alerts reach your device.
  • Infrastructure (Redis) — used to cache OTPs, enforce ad frequency caps, and fan out realtime events (e.g. an SOS or visitor approval scoped to a Society). Depending on deployment this may be self-hosted rather than a distinct third party.
  • Providers are configurable; some are enabled only when credentials are set. We do not share data with any provider beyond what a given feature requires.
08

Data Retention

We keep personal data only for as long as it is needed for the purposes described in this Policy, to provide the service to you and your Society, and to meet legal, accounting, tax, safety, and dispute-resolution requirements.

For Society-operational data, the Society (as Data Fiduciary) determines how long records are kept within its community, and we retain them on the Society's behalf while it uses OkGate. For account and platform data that we control, we retain it for the life of your account and for a reasonable period afterwards where required.

When personal data is no longer required and there is no legal reason to keep it, we delete or anonymise it. Some records are kept for defined periods, for example:

  • One-time passwords (OTPs): expire automatically after about 5 minutes.
  • Short-lived ad-tracking records used to reconcile impressions/clicks: expire automatically after 24 hours; per-user ad frequency-cap counters reset daily.
  • Session refresh tokens: valid for up to 7 days, after which they expire.
  • Financial and billing records (invoices, payments, GST): retained for as long as required to meet accounting, tax and statutory-limitation obligations (typically up to about 8 years).
  • Audit logs and security-related logs: retained as needed for security, compliance, and to establish, exercise or defend legal claims.
09

Children's and Minors' Data

OkGate is intended for use by adults — residents, committee members, guards, staff, and Society administrators. It is not designed for children to create their own accounts.

In the ordinary course of community management, limited information about minors may be entered by adults — for example, a child's name and the person picking them up in a kid-exit authorization, or a minor listed as a family member. Under the DPDP Act, processing a child's personal data requires verifiable consent from a parent or lawful guardian, and we do not knowingly use children's data for advertising, tracking, or behavioural monitoring.

If you are a parent or guardian and believe a child's data has been entered without appropriate consent, please contact us at privacy@okgate.co and we will work with the relevant Society to review and, where appropriate, correct or delete it.

10

Data Security

We take reasonable security safeguards to protect personal data against unauthorised access, disclosure, alteration, and loss, in line with the DPDP Act and the SPDI Rules. We maintain a documented information-security programme comprising managerial, technical, operational and physical controls commensurate with the nature of the data we handle, consistent with the 'reasonable security practices and procedures' standard under Rule 8 of the SPDI Rules (such as the IS/ISO/IEC 27001 framework or an equivalent documented and periodically reviewed programme).

No system can be guaranteed to be perfectly secure, and you also play a part — please keep your OTP and password confidential and enable the app's biometric lock if your device supports it.

If we become aware of a personal data breach, we will notify the Data Protection Board of India and affected users in the manner and within the timelines prescribed under the DPDP Act, and, where applicable, report the incident to CERT-In in accordance with its directions (including the 6-hour reporting requirement for specified incidents).

  • Passwords are stored only in hashed form, and OTP-only accounts store no password at all.
  • Session refresh tokens are stored hashed, and third-party provider credentials are encrypted (AES-GCM).
  • Access is controlled by role (resident, guard, committee, admin, platform), so people see only what their role permits.
  • We keep audit logs of key actions, and payment-instrument details are handled by the payment gateway rather than stored by us.
  • Data is encrypted in transit, and access to systems is limited to authorised personnel.
11

Cookies and Similar Technologies

Our website and apps use cookies and similar technologies (such as local storage and device tokens) for essential purposes — to keep you logged in, remember your session, keep the service secure, and enable core features. We use push notification tokens to deliver alerts to your device.

We do not use third-party advertising cookies to build a behavioural profile of you across the web; as explained in Section 6, our advertising is contextual and applied at the Society level. You can control cookies through your browser settings and manage push notifications and app permissions through your device settings, though disabling essential cookies or tokens may affect how the Platform works.

12

International Data Transfers

OkGate currently operates in India. Some of our service providers (for example, cloud storage and push-notification providers) may process or store data on servers located outside India. Where personal data is transferred across borders, we do so in accordance with the DPDP Act and applicable law, and we require our providers to protect the data to standards consistent with this Policy.

We do not transfer personal data to any country or territory that has been restricted by the Government of India for such transfers under the DPDP Act. If we launch in additional jurisdictions such as the UAE, we will update this Policy to reflect the cross-border and local-law requirements that apply.

13

Your Rights Under the DPDP Act

The DPDP Act gives you rights over your personal data. You can exercise these rights by emailing privacy@okgate.co with your request and enough detail to locate your records. For account/platform data that we control, we will act on your request directly. For Society-operational data where the Society is the Data Fiduciary, we will forward your request to the relevant Society and assist, but the Society is the primary decision-maker.

How we handle requests. Before acting, we will verify your identity — typically by confirming control of the registered mobile number or email on your account (for example, via an OTP) — so that we do not disclose or change data for the wrong person. We will respond within the timelines required by law. Exercising your rights is free, and we will not discriminate against you for doing so.

Your rights include:

  • Right to access: obtain a summary of the personal data we process about you and how we process it.
  • Right to correction and updating: have inaccurate or incomplete data corrected or completed.
  • Right to erasure: request deletion of your personal data where it is no longer needed and no legal reason requires us to keep it.
  • Right to withdraw consent: withdraw consent at any time via the mechanisms in Section 5 (this will not affect processing already carried out, and some features may stop working).
  • Right to grievance redressal: raise a complaint about how your data is handled and receive a timely response (see Section 14).
  • Right of nomination: nominate another individual to exercise your rights on your behalf in the event of your death or incapacity.
  • Right to escalate: if you are not satisfied with our response, you may complain to the Data Protection Board of India.
14

Grievance Officer and How to Contact Us

If you have any questions, concerns, or complaints about how your personal data is handled, or if you wish to exercise your rights, please contact our Grievance Officer (who also serves as the person able to answer questions about our processing on behalf of Honco as Data Fiduciary). We take grievances seriously: we will acknowledge your grievance within 72 hours and endeavour to resolve it within the period prescribed under the DPDP Act, the IT Act and the SPDI Rules (and in any event within a reasonable time).

You can reach us as follows:

  • Grievance Officer: The Grievance Officer, Honco Pvt. Ltd. (contactable by email at the address below).
  • Grievance / privacy contact email: privacy@okgate.co
  • General enquiries: hello@okgate.co
  • Company: Honco Pvt. Ltd.
  • Website: okgate.co
  • If your query concerns operational data managed by your Society, please also contact your Society's committee/administrator; we will help you connect with them.
15

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our services, technology, or legal requirements. When we make material changes, we will update the "Last updated" date shown at the top of this Policy and, where appropriate, notify you through the Platform or by other reasonable means.

We encourage you to review this Policy periodically. Your continued use of OkGate after an update means you acknowledge the revised Policy. If a change requires your consent under applicable law, we will ask for it before the change applies to you.