LAPTOPFIRST MASTER PRIVACY POLICY

Privacy Framework for Platform Users, Laptop Rental Vendors & Managed Device Telemetry

Effective Date: 1st April 2026
Last Updated: 24th September 2026
Official Portal: https://laptopfirst.in | https://laptopfirst.in/privacy
Governing Regulation: Digital Personal Data Protection Act, 2023 (India) (“DPDPA”) & Information Technology Act, 2000
Operated By: Lapswap Tech Private Limited (CIN: U62099DL2024PTC426597), a company incorporated under the Companies Act, 2013, with its registered office at 161-L, Plot No. 9, Sector-7, Evergreen Apartment, Dwarka Sec-6, South West Delhi, Delhi – 110075, India.


SUMMARY & PRIVACY COMMITMENT: LaptopFirst provides cloud software and mobile device management (MDM) tools designed specifically for laptop rental businesses to manage, track, and protect their physical rental fleet.

We operate under strict data minimization principles:

  1. We never sell personal data or monetize data for third-party advertising.
  2. We do not spy on renters. Our agent collects technical hardware health data, device vitals, and physical location coordinates to protect rented inventory. It does not and cannot access personal photos, documents, browsing history, webcam, microphone, or private communications.
  3. Credit pulls are strictly soft pulls. We do not trigger hard credit inquiries that impact a renter’s credit score.
  4. Programmatic data pruning is active. Device location is permanently deleted after 90 days, heartbeats after 30 days, and logs after 7 days.

STRUCTURE OF THIS PRIVACY POLICY

  • PART I: Information LaptopFirst Collects and Controls as a Data Fiduciary (Vendor Account Data & Website Visitors)
  • PART II: Information LaptopFirst Processes on Behalf of Rental Vendors as a Data Processor (Managed Device Telemetry, Renter KYC & Soft Credit Relay)
  • PART III: Security Measures, Sub-Processors, Data Retention Schedules, and Statutory Rights

PART I: INFORMATION LAPTOPFIRST COLLECTS AS A DATA FIDUCIARY

This Part applies to rental business owners, vendor administrative staff, and website visitors accessing laptopfirst.in and app.laptopfirst.in.

1. Information Provided Directly by Vendors

  • Account Registration: Full name, corporate email address, mobile number, registered business name, physical corporate address, state, and country.
  • Statutory Business Details: Goods and Services Tax Identification Number (GSTIN), Permanent Account Number (PAN), and business bank payout details used solely for invoice generation and contract administration.
  • Administrative Credentials: Passwords (securely hashed via Supabase Auth) and assigned role-based permissions (Admin, Staff, Viewer).
  • Communications & Support: Enquiries, emails, ticket communications, and feedback submitted to our support team.

2. Information Collected Automatically on Platform Dashboards

  • Technical Log Data: IP address, browser type and version, language settings, operating system, timestamp of access, and referring URL.
  • Product Interaction Analytics: Navigation flows, feature utilization, and error diagnostics within the administrative dashboard.
  • Cookies & Local Identifiers: Essential session cookies managed via Supabase Auth to maintain secure authenticated sessions, and UI/UX heatmaps via Hotjar (governed by our Cookie Policy).

3. Purpose and Legal Basis for Processing

We process Vendor Account Data on the following legal bases:

  1. Contractual Necessity (DPDPA / Contract Law): To configure accounts, provision multi-tenant databases, deliver software services, and authenticate authorized users;
  2. Statutory Obligations: To issue tax-compliant invoices and preserve audit logs;
  3. Legitimate Business Interests: To protect the Platform against denial-of-service attacks, detect fraudulent accounts, and improve platform performance.

PART II: INFORMATION LAPTOPFIRST PROCESSES ON BEHALF OF VENDORS (SERVICE DATA)

This Part governs scenarios where LaptopFirst acts as a Data Processor on behalf of the Laptop Rental Vendor (who acts as the Data Fiduciary). This includes computing devices enrolled by the Vendor and prospective Renters evaluated by the Vendor.

4. Telemetry Collected from Managed Laptops & Desktops

When a Vendor installs the LaptopFirst Agent (“Mite”) on a rental device, the Agent communicates over encrypted HTTPS/WebSockets with our servers (mdm.laptopfirst.in). The following data points are collected:

Category Specific Data Collected Purpose
Hardware Identifiers Hardware Serial Number, MAC Address (primary non-loopback), Device Model, Motherboard Manufacturer, System UUID. Unambiguous hardware inventory matching; prevents hardware part swapping or spoofing.
System Specifications CPU processor model, Installed RAM capacity (GB), Root Disk partition size and free space (GB). Verifying return condition and monitoring hardware degradation.
Operating System OS Type (Windows / macOS), Kernel/Build version, Hostname, ComputerName. Determining update requirements, patch levels, and MDM compatibility.
Device Vitals Battery percentage, charging status (AC plugged/unplugged), system uptime in seconds, outbound IP address. Fleet battery health assessment, connectivity monitoring, and activity status.
Geographic Location Latitude, Longitude, City, Region, Accuracy method ("gps" via macOS CoreLocation or "ip" network geolocation). Asset recovery in the event of reported theft, rental default, or unreturned equipment.
Native MDM Attributes Installed application names (work inventory), MDM profile status, FileVault/BitLocker encryption status, APNs/OMA-DM push tokens. Ensuring disk encryption is active and corporate software policies are functional.

5. EXPLICIT DISCLAIMER: WHAT WE NEVER COLLECT OR MONITOR

To maintain complete integrity and respect renter privacy, the Agent is engineered with strict technical boundaries. LaptopFirst DOES NOT collect, record, stream, or inspect:

  • ❌ Personal files, folders, documents, photos, or video libraries;
  • ❌ Web browser history, cache, bookmarks, or incognito browsing sessions;
  • ❌ Passwords entered by the user or saved in browsers;
  • ❌ Text messages, chat conversations, emails, or personal messaging clients;
  • ❌ Keystrokes (no keylogger capabilities exist in the software);
  • ❌ Audio recordings from the microphone or visual captures from the webcam;
  • ❌ Personal financial documents stored on the hard drive.

6. Renter Verification & Soft Credit Pull Relay

The Platform allows Vendors to initiate pre-rental identity and credit evaluations for prospective Renters:

  1. Identity & KYC Relay: The Vendor uploads or instructs the Renter to upload government identity documents (PAN, Aadhaar/ID, Proof of Address). LaptopFirst securely relays these credentials to accredited identity verification service providers to validate authenticity.
  2. Soft Credit Evaluation: The Vendor may trigger an automated credit assessment via registered credit assessment partners. This inquiry is strictly a "Soft Pull". It retrieves risk scoring and repayment metrics solely to evaluate rental eligibility. It does not register as a formal inquiry on the Renter's credit bureau file and does not impact their credit score.
  3. Data Ownership: LaptopFirst does not own or monetize this verification data; we transmit it exclusively to display verification outcomes to the authorized Vendor.

PART III: GENERAL PROVISIONS, SECURITY, RETENTION & RIGHTS

7. Programmatic Data Retention & Pruning Schedules

We believe in programmatic data hygiene. Our databases enforce automated pruning scripts to ensure data is not retained beyond its active utility:

Data Type Retention Period Action Upon Expiration
Diagnostic Device Logs 7 Days Hard-deleted automatically from active database (device-log-service.js).
Device Heartbeats & Vitals 30 Days Hard-deleted automatically (heartbeat-service.js).
Geographic Location Coordinates 90 Days Hard-deleted automatically (heartbeat-service.js).
System & Security Audit Logs 400 Days Preserved for compliance with statutory auditing rules under Indian law (audit-retention.js), then purged.
Vendor Business Records / Invoices Duration of Subscription + 180 Days Archived during active subscription; purged 180 days following account closure.
BitLocker Recovery Keys Until Device Retirement / Unenrollment Encrypted with master secret; permanently destroyed upon clean unenrollment.

8. Authorized Third-Party Sub-Processors

We share data only with infrastructure and service partners who maintain robust physical, technical, and contractual safeguards:

Sub-Processor Role / Function Data Transmitted Location
Supabase (Firebase Inc.) Admin Authentication & JWT tokenization Vendor Admin Email, session token India
Railway Corp. MDM Server Infrastructure & API Control Plane Device telemetry, real-time agent payloads Singapore
Cloudflare, Inc. Dashboard Hosting (Workers), CDN, R2 Backup Web traffic, static assets, encrypted backups Global Edge
Amazon Web Services (AWS S3) Cold Storage Database Backups AES-256 encrypted database archives India
Apple Inc. Push Notification Service (APNs) & ABM/DEP Device UDID, APNs tokens, serials US
Accredited Identity Verification Service Provider Identity & Document Verification (KYC) Renter Government IDs, PAN, Address India
Registered Credit Assessment Partner Soft Credit Assessment & Risk Scoring Renter PAN, Full Name, Score Output India
Hotjar Ltd. Dashboard UI/UX Heatmaps & Analytics Vendor admin interaction paths, clicks EU (Malta)

9. Technical & Organizational Security Measures

LaptopFirst implements enterprise-grade technical safeguards:

  1. Data in Transit: All communications between Managed Devices, browsers, and the MDM server are encrypted using TLS 1.3 with modern cipher suites.
  2. Data at Rest: All databases, backups, and BitLocker keys are encrypted using AES-256 encryption.
  3. Multi-Tenant Isolation: Database architecture uses PostgreSQL Row-Level Security (RLS) guaranteeing that queries are strictly isolated by tenant_id.
  4. Agent Integrity & Code Signing: The Agent binary is code-signed. Watchdog daemons verify signature authenticity before execution to prevent binary injection or malware tampering.
  5. Anti-Tamper Protections: The Agent runs as an OS system service with auto-healing capabilities. Local uninstallation is cryptographically blocked unless authorized by the Vendor via a 6-digit Time-Based One-Time Password (TOTP).

10. Statutory Rights Under the Digital Personal Data Protection Act, 2023

Individuals whose data is processed by LaptopFirst are entitled to statutory rights under the DPDPA:

  • Right to Access Information: You have the right to request a summary of personal data processed and the identities of data fiduciaries/processors with whom it has been shared.
  • Right to Correction & Erasure: You have the right to request correction of inaccurate data or erasure of data that is no longer necessary for the purpose for which it was collected.
  • Right to Grievance Redressal: You have the right to access readily available grievance redressal mechanisms regarding our privacy practices.
  • Nomination: You have the right to nominate an individual who, in the event of death or incapacity, shall exercise your privacy rights.

Note for Renters: Because LaptopFirst is a Data Processor acting on behalf of the Laptop Rental Vendor, Renters seeking to exercise their rights regarding rental files, KYC records, or device tracking should primarily address their request to the Rental Vendor (the Data Fiduciary). We will assist the Vendor in fulfilling valid requests.

11. Grievance Redressal Officer

In compliance with the Digital Personal Data Protection Act, 2023, and Information Technology Act, 2000, the contact details of the Grievance Officer for LaptopFirst are:

  • Attn: Data Protection & Grievance Officer
  • Company: Lapswap Tech Private Limited (operating as “LaptopFirst”)
  • Registered Office: 161-L, Plot No. 9, Sector-7, Evergreen Apartment, Dwarka Sec-6, South West Delhi, Delhi – 110075, India
  • CIN: U62099DL2024PTC426597
  • Email: privacy@laptopfirst.in / grievance@laptopfirst.in
  • Response Window: All grievances will be acknowledged within 48 hours and addressed within statutory timelines.

12. Updates to this Policy

LaptopFirst reserves the right to update this Master Privacy Policy to reflect technical enhancements, architectural changes, or evolving regulatory mandates. Material modifications will be notified via email to registered Vendor admins and highlighted through a prominent notification on the Platform dashboard at least thirty (30) days prior to taking effect.