01Who we are and what this covers
Moven is a service operated by Krishna Jitendra Jha, a sole proprietor trading as Codemyx. We are the Data Fiduciary for the personal data described in this policy, except where stated otherwise in the section on our two roles below.
This policy covers our marketing website at moven.in, the content management system we provide to clients, and the support and onboarding we deliver. It does not cover the independent privacy practices of a client whose website we host — each client is responsible for its own visitor-facing privacy notice.
02Our two roles: fiduciary and processor
The distinction matters for your rights, so we set it out plainly.
- We are the Data Fiduciary for data about our own clients and prospects — the people who enquire about Moven, book a demo, subscribe, and log in to the CMS. We decide why and how that data is processed, and this policy governs it.
- We act as a Data Processor for personal data belonging to the End Guests of our clients. Where a website we host captures an enquiry from a prospective guest, our client is the Data Fiduciary for that data and we process it only on our client's instructions. Requests about such data should go to the client operating the website; if you reach us instead, we will forward the request and tell you we have done so.
Guest enquiry capture is a planned feature rather than a current one. Until it ships, the only personal data flowing through Moven is our clients' own account, billing, and content data. This section is stated now so the policy stays accurate when the feature launches.
03What we collect
Information you give us
- Contact and account data — your name, business name, email address, phone number, and the role you hold at your business.
- Demo and enquiry data — what you tell us when you book a demo, message us on WhatsApp, or send us an email, including the content of that correspondence.
- Billing data — billing name, billing address, GSTIN where you provide one, invoice history, and the payment method type and last four digits as reported back to us by our payment gateway.
- Client Content — the property listings, photographs, pricing, descriptions, and brand assets you upload to the CMS. This is ordinarily business information rather than personal data, but it may include personal data where you choose to include it.
- Support correspondence — the messages, screenshots, and files you send us when asking for help.
Information collected automatically
- Usage and analytics data — pages viewed, referring page, approximate location derived from IP address, session duration, and the interactions we measure as events (for example, clicking a call-to-action).
- Device and technical data — browser type and version, operating system, screen size, language, and IP address.
- Server and security logs — request timestamps, requested URLs, response codes, and IP addresses, retained to diagnose faults and detect abuse.
- Cookies and similar technologies — as described in the cookies section below.
What we do not collect
We do not collect your full card number, CVV, PIN, UPI PIN, or net-banking credentials. Those go directly to our payment gateway and never reach our servers. We do not knowingly collect biometric data, health data, caste or religious information, or sexual orientation, and we ask that you do not send such information to us.
04How we use your data
| Purpose | Data used |
|---|---|
| Provide, host, and maintain your website and CMS | Account data, Client Content, technical data |
| Respond to your enquiry and run your demo | Contact data, demo and enquiry data |
| Onboard you and give you support | Account data, support correspondence |
| Invoice you and collect payment | Billing data, account data |
| Diagnose faults, monitor performance, and secure our systems | Server and security logs, technical data |
| Understand which parts of our site work and improve them | Usage and analytics data |
| Send you service notices — billing, downtime, policy changes | Contact data |
| Send occasional product updates, where you have not opted out | Contact data |
| Meet our legal, tax, and accounting obligations | Billing data, account data |
We do not sell your personal data. We do not share it with advertising networks or data brokers, and we do not use it to build profiles for third-party advertising.
We do not use your personal data or your Client Content to train machine learning models.
05Our legal basis for processing
Under the Digital Personal Data Protection Act, 2023 we process personal data on one of the following bases:
- Your consent — given when you submit an enquiry, book a demo, create an account, or opt in to product updates. You can withdraw consent at any time, as described under your rights below.
- Performance of our contract with you — processing necessary to deliver the Service you have subscribed to, to bill you, and to support you.
- Compliance with law — retaining invoices and tax records for the statutory period, and responding to lawful requests from authorities.
- Legitimate uses permitted by the Act — securing our systems, preventing fraud and abuse, and pursuing or defending legal claims.
07Third-party service providers
We rely on the following providers to run the Service. Each processes only what it needs for its function, under contractual confidentiality and security obligations. This list is specific to what our systems actually use, and we keep it current.
| Provider | Function | Data it may process |
|---|---|---|
| Vercel Inc. | Application hosting, content delivery network, and file storage for uploaded media | Technical data, IP addresses, server logs, Client Content and media |
| Neon / managed PostgreSQL | Primary database for account records and site content | Account data, Client Content, CMS records |
| Google LLC (Google Analytics 4) | Website analytics and traffic measurement | Usage and analytics data, device data, truncated IP address |
| Google LLC (Fonts) | Typeface delivery. Fonts are self-hosted at build time, so no request is made from your browser to Google | None at page-load time |
| Zoho Corporation (Zoho Bookings) | Demo and meeting scheduling through our booking modal | Name, email, phone, and meeting preferences you enter |
| NimbusPop | Booking widget embed used to render the scheduling interface | Technical data, and the scheduling details you submit |
| Payment gateway provider | Processing subscription and setup fee payments | Billing name, email, phone, amount, and payment credentials entered directly with the gateway |
| Email and communication providers | Sending transactional email, and WhatsApp or telephone support | Contact data and the content of your correspondence |
We review this list when we change our infrastructure. If you would like to know the current provider for a particular function before engaging us, write to contact@moven.in and we will tell you.
08Payment information
Payments are handled by a third-party payment gateway that is certified to the Payment Card Industry Data Security Standard. Your card, UPI, or net-banking credentials are entered directly with that gateway.
We receive only what we need to reconcile your account: whether the payment succeeded, the amount, the transaction reference, the method type, and the last four digits of a card. We never receive or store your full card number, CVV, or PIN. The gateway's own privacy policy governs its handling of your data.
10Where your data is stored and transferred
We prefer Indian or Asia-Pacific hosting regions where our providers offer them. Some of our providers are established outside India and may process data on servers in other countries, including the United States and the European Union.
Where personal data is transferred outside India, we do so as permitted by the Digital Personal Data Protection Act, 2023, and we require the receiving provider to apply security and confidentiality protections at least equivalent to those described in this policy — ordinarily through the provider's data processing agreement and standard contractual clauses.
11How long we keep data
| Data | Retention period |
|---|---|
| Enquiries and demo requests that do not convert | Up to 24 months from last contact, then deleted |
| Client account data and Client Content | For the life of the subscription, then 30 days after termination to allow export |
| Invoices, payment records, and tax documents | Eight years, as required by Indian tax and accounting law |
| Support correspondence | Up to 36 months, to maintain continuity of support |
| Server and security logs | Up to 90 days, unless retained longer for an active investigation |
| Analytics data | Up to 14 months, per our Google Analytics configuration |
| Routine backups | Up to 35 days on a rolling cycle, after which they expire automatically |
When a retention period ends we delete the data or irreversibly anonymise it. Deletion from live systems is immediate on request; residual copies in backups expire on the cycle above and are not restored to live systems except in a disaster-recovery event.
12How we protect your data
We apply reasonable security practices proportionate to the sensitivity of the data we hold:
- Encryption in transit using TLS across every connection to our sites, the CMS, and our APIs
- Encryption at rest for our databases and file storage, as provided by our infrastructure providers
- Role-based access control in the CMS, so you decide who on your team can view or edit what
- Tenant isolation, so one client's content and account data are not reachable from another client's session
- Access to production systems restricted to personnel who need it, protected by multi-factor authentication
- Automated daily backups, with restoration tested periodically
- Dependency and vulnerability monitoring, with security patches applied promptly
No system is perfectly secure, and we do not claim otherwise. If a personal data breach occurs that is likely to affect you, we will notify you and the Data Protection Board of India as the Digital Personal Data Protection Act, 2023 requires, and we will tell you what happened, what data was involved, and what we are doing about it.
If you believe you have found a security vulnerability in our platform, please report it privately to contact@moven.in rather than disclosing it publicly. We will acknowledge your report and keep you informed while we investigate.
13Your rights
As a Data Principal under the Digital Personal Data Protection Act, 2023, you have the right to:
- Access — obtain confirmation of what personal data we hold about you, why we process it, and who we have shared it with.
- Correction and completion — have inaccurate or misleading data corrected, incomplete data completed, and out-of-date data updated.
- Erasure — have your personal data deleted where we no longer need it for the purpose it was collected and no law requires us to keep it.
- Withdraw consent — withdraw consent you previously gave, at any time and as easily as you gave it. Withdrawal does not affect processing already carried out lawfully, and may mean we can no longer provide parts of the Service.
- Nominate — nominate another individual to exercise these rights on your behalf if you die or become incapacitated.
- Grievance redressal — complain to us first, and escalate to the Data Protection Board of India if we do not resolve your complaint satisfactorily.
How to exercise them
Write to contact@moven.in describing what you want. We will acknowledge your request within one business day and respond substantively within 30 days. We may ask you to verify your identity before we act, to make sure we are not disclosing your data to someone else. Exercising these rights is free; we may decline a request that is manifestly unfounded or repetitive, and we will explain why if we do.
To stop receiving product update emails, use the unsubscribe link in any such email or simply tell us. We will still send you service notices about billing, security, downtime, and policy changes while your subscription is active — those are part of the Service, not marketing.
14Grievance Officer
In accordance with the Digital Personal Data Protection Act, 2023 and the Information Technology (Intermediary Guidelines) Rules, 2011, the following person handles complaints about how we process personal data:
- Name — Krishna Jitendra Jha
- Designation — Grievance Officer
- Email — contact@moven.in
- Phone — +91 90286 03703
- Address — A/402, Rashmi Heights, Thane, Maharashtra 401209, India
Please put "Privacy grievance" in your subject line so it reaches the right place quickly. We will acknowledge your complaint within 24 hours of receipt and resolve it within 15 days, as the Rules require.
If you are not satisfied with our response, you may escalate your complaint to the Data Protection Board of India.
15Children's data
The Service is intended for businesses and is not directed at children. We do not knowingly collect personal data of anyone under 18, and we do not carry out tracking, behavioural monitoring, or targeted advertising directed at children.
If you believe a child's personal data has reached us, write to contact@moven.in and we will delete it promptly.
16Changes to this policy
We update this policy when our practices, providers, or legal obligations change. The date at the top of the page always reflects the current revision.
For material changes — a new category of data, a new purpose, or a new provider handling your data — we will notify active clients by email at least 15 days before the change takes effect. Where the law requires fresh consent, we will ask for it rather than assume it.
17How to contact us
For any question about this policy or your data, reach us at:
- Entity — Krishna Jitendra Jha, Sole Proprietorship, trading as Codemyx
- Email — contact@moven.in
- Phone / WhatsApp — +91 90286 03703
- Address — A/402, Rashmi Heights, Thane, Maharashtra 401209, India
- Hours — Monday to Saturday, 10:00 to 19:00 IST
Still have a question?
Reach us directly — no ticket queue, no chatbot.