Privacy Policy
Last Updated: September 16, 2026
1. This notice
This Privacy Policy explains how Findlen and/or Vaaryan Interfaces ("Findlen", "we", "us") process personal data when you use the Findlen website, mobile applications, and related services (the "Service").
It is written to be readable on its own. It describes the personal data we process, why we process it, how long we keep it in general terms, who we share it with, and how you can exercise rights under the Digital Personal Data Protection Act, 2023 ("DPDP Act") and the Digital Personal Data Protection Rules, 2025 ("DPDP Rules"), as those laws apply.
Findlen is a creator-led product. Creators use accounts to run their photography or videography business. Their customers usually receive quotations and photo/video deliveries through share links, without creating a Findlen account.
This notice is not a claim that we have been notified as a Significant Data Fiduciary, that we have a named Data Protection Officer, or that we hold a particular security certification. We have not made those claims because we cannot verify them here.
2. Who this applies to
This Policy applies to personal data relating to:
- Creators and brand users who register for a Findlen account
- Customers of creators whose names, contact details, or event information a creator stores in Findlen, or who open a quotation or delivery link
- People who appear in photos or videos that a creator uploads (including guests at an event)
- Website and app visitors, including people who only open a share link
Opening a quotation at /q/{token} or a delivery at /d/{token} does not create a Findlen user account.
3. Who decides how data is used
For Findlen accounts, billing of Findlen plans, security of the Service, and operation of our infrastructure, Findlen determines the purposes and means of processing and acts as a Data Fiduciary under the DPDP Act.
For customer contact lists, quotations, bookings, and event photos or videos, the creator decides what to collect, upload, and share (including whether a delivery is passcode-protected or public). Findlen provides the technical service. If you are a customer or a person in a photograph, the creator who collected or captured that information is usually the first person you should contact; you may also contact us using the details in Section 16.
4. Personal data we process
We process only the categories below as needed for the purposes in Section 5. We do not require a customer to create an account in order to receive a quotation or delivery.
A. Creator and brand account data
- Name, email address, phone number
- Login identifiers from email/password, Google, or Apple sign-in
- Profile photo, bio, social links, equipment or service descriptions
- Business details the creator chooses to store for branding (business name, logo, business phone, studio address)
- Plan or subscription status (not full card numbers)
- Account settings and support messages you send us
B. Customer records held for a creator
- Customer name, email, phone number, and notes the creator enters
- Event names, dates, locations, and other booking or quotation details
- Addresses or other fields the creator adds to a quotation or booking
These records exist so the creator can do business with their customer. The customer need not have a Findlen login.
C. Photos, videos, and delivery content
- Image and video files uploaded by the creator (including people who appear in them, file names, and technical metadata the file contains)
- Portfolio items and brand logos
- Organisation data such as booking, event, and folder labels used to present a delivery
Face-search or "Find Me" matching is not provided on delivery links (/d).
D. Quotations and bookings
- Quotation content, line items, amounts, and status
- Booking and event records, schedules, and related notes
- Share-link identifiers and passcode hashes (not the passcode in plain text after it is set)
E. Delivery-link and device data
- The fact that a particular share link was opened, passcode attempts needed to operate the Service securely, and similar technical logs
- Browser or device information, IP address, and approximate location derived from it
- Cookies used to remember a successful passcode for that link for a limited time (see Section 9)
F. Usage, security, and communications
- Pages or screens used in the creator app, diagnostics, and crash-type logs where collected
- Push-notification tokens if you enable notifications
- Emails we send (for example a quotation the creator asked us to send)
G. Payments for Findlen plans
If a creator buys a Findlen plan, payment is processed by Razorpay (web) and/or Apple (App Store). We receive subscription status and limited billing identifiers. We do not store full payment card or banking numbers.
5. Why we process personal data (purposes)
We process personal data for these specified purposes:
- Providing creator accounts — create, authenticate, and maintain creator/brand accounts and business details
- Quotations and bookings — let creators draft, send, and manage quotations and bookings
- Storing and delivering media — host creator-uploaded photos and videos and present them on delivery pages the creator shares
- Share links — operate quotation links (
/q) and delivery links (/d), including passcode checks and optional public access the creator enables - Downloads — where the creator allows it, issue time-limited signed links so a recipient can view or download files
- Email and notifications — send messages the creator requests (such as a quotation) and service notices to account holders
- Security and abuse prevention — protect accounts, links, and infrastructure (including App Check / reCAPTCHA where used)
- Plans and billing — provide paid creator features and record plan status
- Support — respond to questions and grievances
- Legal compliance — keep records we must keep under applicable law
We do not sell personal data. We do not use delivery-link browsing to build an advertising profile of a customer. Directory or discovery features, if enabled, are separate from quotation and delivery links and are not required to receive a share link.
6. Consent, notices, and other lawful processing
Under the DPDP Act, we process personal data for a lawful purpose with consent, or for certain legitimate uses recognised by the Act (for example where you voluntarily provide data for a specified purpose, or where processing is required by law).
Creators. Creating an account, adding business details, uploading files, and using sharing tools are requests for processing as described in this Policy. You may withdraw consent by deleting content, disabling a share link, closing your account, or emailing us. Withdrawal does not undo processing already completed (for example a file already downloaded by someone the creator shared with).
Customers and people in photographs. The creator typically collects your contact details and captures or receives photos and videos. When you open a share link and enter a passcode the creator gave you, you are using that link for the purpose of viewing the quotation or delivery. If you want a creator to stop using your details or to take down photos, contact that creator; you may also contact us and we will look into what we can do on the Service.
Consent for processing that is not necessary for a stated purpose is not required as a condition of that purpose. We do not ask you to waive the right to complain to the Data Protection Board of India.
7. Delivery links, passcodes, and public sharing
A delivery link (/d/{token}) shows client-visible files for one booking. It is not a Findlen client account.
Passcode-protected deliveries. By default a delivery is not public. The creator shares a link and a passcode. We store a hash of the passcode. After a correct passcode, we may set a short-lived cookie so the same browser can return to that link without typing the passcode again immediately. That cookie is not a Findlen login.
Public deliveries. A creator may choose to make a delivery public. Public access is off by default, requires confirmation in the product, and can be turned off by the creator. Findlen provides the sharing mechanism; we do not decide that a particular delivery should be public.
Anyone who obtains a public delivery link may be able to view and, if downloads are enabled, download the content made available through it. The creator is responsible for having the rights and permissions to make that content publicly accessible, including permissions from people who appear in the files.
If a creator disables or replaces a link, recipients will no longer be able to use the old link. Copies already downloaded cannot be pulled back by Findlen.
8. Downloads and cloud storage
Photos and videos are stored using Google Firebase / Google Cloud Storage. Viewing and downloading use time-limited signed URLs. Those URLs are not permanent public storage addresses and they expire.
Account, quotation, booking, and related records are stored using Google Firebase services and Google Cloud SQL (PostgreSQL) via Firebase Data Connect.
We use Google Cloud and Firebase as infrastructure providers (Data Processors for this purpose), together with Mailtrap for transactional email, Google and Apple for sign-in, Google reCAPTCHA / App Check for abuse resistance, Firebase Cloud Messaging for optional push notifications, and Razorpay and/or Apple for plan payments.
Some Google Cloud processing may occur outside India. The DPDP Act allows transfer of personal data outside India except to the extent the Central Government restricts a country or imposes conditions. We will follow any such restriction that applies to us. We do not claim that every copy of every file is stored only in India.
9. Cookies and similar technologies
We use cookies and similar technologies that are needed to run the Service, including:
- Creator session cookies — to keep a signed-in creator signed in
- Delivery passcode cookies (names beginning with
fl_d_) — after a correct delivery passcode, a short-lived, http-only cookie remembers access for that delivery link in that browser. It does not create a Findlen user - Quotation passcode cookies (names beginning with
fl_q_) — the same idea for a quotation link
You can delete cookies in your browser. If you delete a passcode cookie, you may need to enter the passcode again (unless the creator has made that delivery public).
Google reCAPTCHA and Firebase App Check may set their own cookies or collect device signals as described in Google's policies, to distinguish people from automated abuse.
10. How we share information
At the creator's direction
When a creator sends a quotation or delivery link, the people who receive that link can see the content the creator made available. If the creator makes a delivery public, anyone with the link may see it.
Business name, logo, and similar branding the creator configures may appear on client-facing quotation and delivery pages.
Service providers (Data Processors)
We use the infrastructure listed in Section 8 under contracts or provider terms, so they process data on our behalf to host, send email, authenticate, and bill plans.
Legal requirements
We may disclose information if required by law or to:
- Protect our legal rights
- Prevent fraud or abuse
- Enforce our Terms
- Protect people's safety
No sale of personal data
We do not sell personal data to third parties.
11. Retention and deletion
We keep personal data while it is needed for the purposes in Section 5, or for as long as applicable law requires.
When a creator deletes content, disables a share, or requests account deletion, we typically soft-delete: the record is marked deleted and is excluded from the live product, rather than every copy being destroyed at that instant. Backups, security logs, and legal records may remain for a limited further period.
The DPDP Act requires erasure when consent is withdrawn or when the specified purpose is no longer served, unless retention is required by law. We honour deletion requests through the product and through the contact details below. We do not claim a published, item-by-item retention schedule for every table, and we do not claim that we fall into a DPDP Rules Third Schedule class (those classes apply to certain large intermediaries by user count).
Creators should not treat Findlen as the only copy of their originals. Recipients who download files control those copies.
12. Security
We use reasonable technical and organisational measures, including encrypted transport (HTTPS), access controls on creator accounts, hashed passcodes for share links, short-lived signed download URLs, and provider-side controls on Google Cloud / Firebase. Passcode cookies are set as http-only so ordinary page scripts cannot read them.
No method of internet transmission or storage is completely secure. A creator who shares a link, a passcode, or a public URL is choosing to make that content available to the people who receive it.
If we become aware of a personal data breach, we will notify affected individuals and the Data Protection Board of India in the manner required by the DPDP Act and DPDP Rules when those obligations apply to us.
13. Children
Findlen accounts are for individuals 18 years or older. We do not knowingly create accounts for children, and we do not use the Service to track children for advertising.
Creators may upload event photographs or videos that include children (for example a family wedding). That is the creator's processing. The creator must have the rights and, where the DPDP Act requires it, verifiable parental consent before uploading or publicly sharing a child's personal data. Findlen does not obtain that consent for the creator.
If you believe we have an account for a child, or that a child's data was uploaded or made public without appropriate authorisation, contact us. We will take steps we can reasonably take, which may include asking the creator to restrict the content or disabling a share.
14. Your rights (Data Principals)
Subject to the DPDP Act and DPDP Rules, you may request:
- Access — a summary of personal data we process about you and the processing activities, and (where applicable) the identities of other fiduciaries or processors with whom it has been shared
- Correction, completion, and updating of inaccurate or incomplete data
- Erasure of personal data, unless we must retain it for a specified purpose that is still being served or for compliance with law
- Withdrawal of consent where consent is the basis for processing, with ease comparable to giving it
- Nomination of another individual to exercise your rights in the event of your death or incapacity, by emailing us with the particulars we need to identify you
- Grievance redressal as described in Section 16
How to make a request. Creators can update much of their account information in settings and can request account deletion there. Anyone may email support@findlen.app (or support@vaaryan.com) from a reachable address, stating the right you wish to exercise and enough information for us to identify you (for example the email or phone used, or the quotation/delivery link if the request relates to a share). We may ask for additional information to prevent impersonation.
If your data was uploaded only by a creator (for example your guest photos), we may need to involve that creator to locate or take down the files.
15. Duties when you provide data
The DPDP Act also asks Data Principals not to impersonate others, not to suppress material information where identity documents are involved, not to file false or frivolous grievances, and to provide authentic information when asking for correction or erasure. Please do not request access to someone else's account or files without authority.
16. Grievance redressal and contact
If you have questions about this Policy or about processing of your personal data, or if you wish to raise a grievance, contact:
Email: support@findlen.app
Alternative Email: support@vaaryan.com
These addresses are the business contact we publish for questions about processing. We have not appointed a separately named Data Protection Officer on this page because we are not stating that we have been notified as a Significant Data Fiduciary.
We aim to respond to grievances within a reasonable period not exceeding ninety (90) days from receipt, as provided under the DPDP Rules for grievance redressal systems.
You should exhaust this grievance process before approaching the Data Protection Board of India. After that, you may make a complaint to the Board in the manner prescribed under the DPDP Act and DPDP Rules.
17. Third-party sites and messages
Creators often send Findlen links through WhatsApp, SMS, email, or other tools we do not control. Those services have their own practices. We are not responsible for third-party websites or apps that you open from the Service.
18. Changes to this Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated "Last Updated" date.
Continued use of the Service after changes become effective constitutes acceptance of the updated policy where consent is not otherwise required. Where the law requires a new notice or fresh consent, we will provide it.
19. Terms of Use (EULA)
For Apple App Store users, Findlen uses the standard Apple Terms of Use (EULA):
https://www.apple.com/legal/internet-services/itunes/dev/stdeula/
Our Terms & Conditions are at https://findlen.app/terms-and-conditions.