Legal

Privacy Policy

This Privacy Policy explains what personal data Moven collects, why we collect it, who we share it with, and the rights you have over it. It is written to comply with the Digital Personal Data Protection Act, 2023 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.

Last updated: 30 July 2026

01Who we are and what this covers

Moven is a service operated by Krishna Jitendra Jha, a sole proprietor trading as Codemyx. We are the Data Fiduciary for the personal data described in this policy, except where stated otherwise in the section on our two roles below.

This policy covers our marketing website at moven.in, the content management system we provide to clients, and the support and onboarding we deliver. It does not cover the independent privacy practices of a client whose website we host — each client is responsible for its own visitor-facing privacy notice.

02Our two roles: fiduciary and processor

The distinction matters for your rights, so we set it out plainly.

  • We are the Data Fiduciary for data about our own clients and prospects — the people who enquire about Moven, book a demo, subscribe, and log in to the CMS. We decide why and how that data is processed, and this policy governs it.
  • We act as a Data Processor for personal data belonging to the End Guests of our clients. Where a website we host captures an enquiry from a prospective guest, our client is the Data Fiduciary for that data and we process it only on our client's instructions. Requests about such data should go to the client operating the website; if you reach us instead, we will forward the request and tell you we have done so.

Guest enquiry capture is a planned feature rather than a current one. Until it ships, the only personal data flowing through Moven is our clients' own account, billing, and content data. This section is stated now so the policy stays accurate when the feature launches.

03What we collect

Information you give us

  • Contact and account data — your name, business name, email address, phone number, and the role you hold at your business.
  • Demo and enquiry data — what you tell us when you book a demo, message us on WhatsApp, or send us an email, including the content of that correspondence.
  • Billing data — billing name, billing address, GSTIN where you provide one, invoice history, and the payment method type and last four digits as reported back to us by our payment gateway.
  • Client Content — the property listings, photographs, pricing, descriptions, and brand assets you upload to the CMS. This is ordinarily business information rather than personal data, but it may include personal data where you choose to include it.
  • Support correspondence — the messages, screenshots, and files you send us when asking for help.

Information collected automatically

  • Usage and analytics data — pages viewed, referring page, approximate location derived from IP address, session duration, and the interactions we measure as events (for example, clicking a call-to-action).
  • Device and technical data — browser type and version, operating system, screen size, language, and IP address.
  • Server and security logs — request timestamps, requested URLs, response codes, and IP addresses, retained to diagnose faults and detect abuse.
  • Cookies and similar technologies — as described in the cookies section below.

What we do not collect

We do not collect your full card number, CVV, PIN, UPI PIN, or net-banking credentials. Those go directly to our payment gateway and never reach our servers. We do not knowingly collect biometric data, health data, caste or religious information, or sexual orientation, and we ask that you do not send such information to us.

04How we use your data

PurposeData used
Provide, host, and maintain your website and CMSAccount data, Client Content, technical data
Respond to your enquiry and run your demoContact data, demo and enquiry data
Onboard you and give you supportAccount data, support correspondence
Invoice you and collect paymentBilling data, account data
Diagnose faults, monitor performance, and secure our systemsServer and security logs, technical data
Understand which parts of our site work and improve themUsage and analytics data
Send you service notices — billing, downtime, policy changesContact data
Send occasional product updates, where you have not opted outContact data
Meet our legal, tax, and accounting obligationsBilling data, account data

We do not sell your personal data. We do not share it with advertising networks or data brokers, and we do not use it to build profiles for third-party advertising.

We do not use your personal data or your Client Content to train machine learning models.

06Cookies and analytics

We keep our use of cookies deliberately narrow. We do not run advertising or retargeting pixels on this website.

Google Analytics

We use Google Analytics 4 to understand how visitors find and use our site — which pages hold attention, where people drop off, and which calls to action get clicked. It sets first-party cookies (typically named _ga and _ga_*) that assign your browser a random identifier. We have not enabled Google Signals, advertising personalisation, or cross-device tracking, and we do not upload customer lists to Google.

You can prevent Google Analytics from running by installing the Google Analytics opt-out browser add-on, blocking third-party scripts, or using your browser's tracking-protection settings. Our site works fully with analytics blocked.

Scheduling and embedded widgets

Our demo booking modal is provided by Zoho Bookings and loads through an embed script. When you open it, that provider may set its own cookies and receive the details you enter to schedule the meeting. Opening the modal is entirely your choice, and nothing loads into it until you do.

Essential cookies

The CMS uses strictly necessary cookies to keep you signed in and to protect against cross-site request forgery. These cannot be disabled without breaking authentication.

You can clear or block cookies through your browser settings at any time. Blocking essential cookies will prevent you from logging in to the CMS.

07Third-party service providers

We rely on the following providers to run the Service. Each processes only what it needs for its function, under contractual confidentiality and security obligations. This list is specific to what our systems actually use, and we keep it current.

ProviderFunctionData it may process
Vercel Inc.Application hosting, content delivery network, and file storage for uploaded mediaTechnical data, IP addresses, server logs, Client Content and media
Neon / managed PostgreSQLPrimary database for account records and site contentAccount data, Client Content, CMS records
Google LLC (Google Analytics 4)Website analytics and traffic measurementUsage and analytics data, device data, truncated IP address
Google LLC (Fonts)Typeface delivery. Fonts are self-hosted at build time, so no request is made from your browser to GoogleNone at page-load time
Zoho Corporation (Zoho Bookings)Demo and meeting scheduling through our booking modalName, email, phone, and meeting preferences you enter
NimbusPopBooking widget embed used to render the scheduling interfaceTechnical data, and the scheduling details you submit
Payment gateway providerProcessing subscription and setup fee paymentsBilling name, email, phone, amount, and payment credentials entered directly with the gateway
Email and communication providersSending transactional email, and WhatsApp or telephone supportContact data and the content of your correspondence

We review this list when we change our infrastructure. If you would like to know the current provider for a particular function before engaging us, write to contact@moven.in and we will tell you.

08Payment information

Payments are handled by a third-party payment gateway that is certified to the Payment Card Industry Data Security Standard. Your card, UPI, or net-banking credentials are entered directly with that gateway.

We receive only what we need to reconcile your account: whether the payment succeeded, the amount, the transaction reference, the method type, and the last four digits of a card. We never receive or store your full card number, CVV, or PIN. The gateway's own privacy policy governs its handling of your data.

09When we share data

We share personal data only in these circumstances:

  • With the providers listed above, to the extent each needs it to perform its function.
  • With professional advisers — our accountant, auditor, or lawyers — where they need it and are bound by professional confidentiality.
  • Where the law requires it — in response to a valid order from a court, tax authority, or law enforcement agency. We assess each request, comply only to the extent required, and notify you unless legally prohibited from doing so.
  • To protect rights and safety — where disclosure is necessary to investigate fraud or abuse, enforce our Terms, or protect our systems, our clients, or the public.
  • On a business transfer — if the business is incorporated, restructured, merged, or sold, data may transfer to the successor entity. We will notify you, and this policy or a materially equivalent one will continue to apply.

We do not sell, rent, or trade personal data.

10Where your data is stored and transferred

We prefer Indian or Asia-Pacific hosting regions where our providers offer them. Some of our providers are established outside India and may process data on servers in other countries, including the United States and the European Union.

Where personal data is transferred outside India, we do so as permitted by the Digital Personal Data Protection Act, 2023, and we require the receiving provider to apply security and confidentiality protections at least equivalent to those described in this policy — ordinarily through the provider's data processing agreement and standard contractual clauses.

11How long we keep data

DataRetention period
Enquiries and demo requests that do not convertUp to 24 months from last contact, then deleted
Client account data and Client ContentFor the life of the subscription, then 30 days after termination to allow export
Invoices, payment records, and tax documentsEight years, as required by Indian tax and accounting law
Support correspondenceUp to 36 months, to maintain continuity of support
Server and security logsUp to 90 days, unless retained longer for an active investigation
Analytics dataUp to 14 months, per our Google Analytics configuration
Routine backupsUp to 35 days on a rolling cycle, after which they expire automatically

When a retention period ends we delete the data or irreversibly anonymise it. Deletion from live systems is immediate on request; residual copies in backups expire on the cycle above and are not restored to live systems except in a disaster-recovery event.

12How we protect your data

We apply reasonable security practices proportionate to the sensitivity of the data we hold:

  • Encryption in transit using TLS across every connection to our sites, the CMS, and our APIs
  • Encryption at rest for our databases and file storage, as provided by our infrastructure providers
  • Role-based access control in the CMS, so you decide who on your team can view or edit what
  • Tenant isolation, so one client's content and account data are not reachable from another client's session
  • Access to production systems restricted to personnel who need it, protected by multi-factor authentication
  • Automated daily backups, with restoration tested periodically
  • Dependency and vulnerability monitoring, with security patches applied promptly

No system is perfectly secure, and we do not claim otherwise. If a personal data breach occurs that is likely to affect you, we will notify you and the Data Protection Board of India as the Digital Personal Data Protection Act, 2023 requires, and we will tell you what happened, what data was involved, and what we are doing about it.

If you believe you have found a security vulnerability in our platform, please report it privately to contact@moven.in rather than disclosing it publicly. We will acknowledge your report and keep you informed while we investigate.

13Your rights

As a Data Principal under the Digital Personal Data Protection Act, 2023, you have the right to:

  • Access — obtain confirmation of what personal data we hold about you, why we process it, and who we have shared it with.
  • Correction and completion — have inaccurate or misleading data corrected, incomplete data completed, and out-of-date data updated.
  • Erasure — have your personal data deleted where we no longer need it for the purpose it was collected and no law requires us to keep it.
  • Withdraw consent — withdraw consent you previously gave, at any time and as easily as you gave it. Withdrawal does not affect processing already carried out lawfully, and may mean we can no longer provide parts of the Service.
  • Nominate — nominate another individual to exercise these rights on your behalf if you die or become incapacitated.
  • Grievance redressal — complain to us first, and escalate to the Data Protection Board of India if we do not resolve your complaint satisfactorily.

How to exercise them

Write to contact@moven.in describing what you want. We will acknowledge your request within one business day and respond substantively within 30 days. We may ask you to verify your identity before we act, to make sure we are not disclosing your data to someone else. Exercising these rights is free; we may decline a request that is manifestly unfounded or repetitive, and we will explain why if we do.

To stop receiving product update emails, use the unsubscribe link in any such email or simply tell us. We will still send you service notices about billing, security, downtime, and policy changes while your subscription is active — those are part of the Service, not marketing.

14Grievance Officer

In accordance with the Digital Personal Data Protection Act, 2023 and the Information Technology (Intermediary Guidelines) Rules, 2011, the following person handles complaints about how we process personal data:

  • Name — Krishna Jitendra Jha
  • Designation — Grievance Officer
  • Email — contact@moven.in
  • Phone — +91 90286 03703
  • Address — A/402, Rashmi Heights, Thane, Maharashtra 401209, India

Please put "Privacy grievance" in your subject line so it reaches the right place quickly. We will acknowledge your complaint within 24 hours of receipt and resolve it within 15 days, as the Rules require.

If you are not satisfied with our response, you may escalate your complaint to the Data Protection Board of India.

15Children's data

The Service is intended for businesses and is not directed at children. We do not knowingly collect personal data of anyone under 18, and we do not carry out tracking, behavioural monitoring, or targeted advertising directed at children.

If you believe a child's personal data has reached us, write to contact@moven.in and we will delete it promptly.

16Changes to this policy

We update this policy when our practices, providers, or legal obligations change. The date at the top of the page always reflects the current revision.

For material changes — a new category of data, a new purpose, or a new provider handling your data — we will notify active clients by email at least 15 days before the change takes effect. Where the law requires fresh consent, we will ask for it rather than assume it.

17How to contact us

For any question about this policy or your data, reach us at:

  • Entity — Krishna Jitendra Jha, Sole Proprietorship, trading as Codemyx
  • Email — contact@moven.in
  • Phone / WhatsApp — +91 90286 03703
  • Address — A/402, Rashmi Heights, Thane, Maharashtra 401209, India
  • Hours — Monday to Saturday, 10:00 to 19:00 IST

Still have a question?

Reach us directly — no ticket queue, no chatbot.

contact@moven.in+91 90286 03703

A/402, Rashmi Heights
Thane, Maharashtra 401209
India