Privacy Policy

Version 1.2.0 · Effective 2026-05-27 · Last updated 2026-05-28

Privacy contact: privacy@tyren.com

On this page
  1. Introduction
  2. Personal Data We Collect
  3. How We Collect Personal Data
  4. How We Use Personal Data
  5. Processing Under the DPDP Act, 2023
  6. AI Features and Automated Processing
  7. Cookies and Similar Technologies
  8. Disclosure of Personal Data
  9. Storage and Processing Location
  10. Retention and Deletion
  11. Security Safeguards
  12. Rights of Data Principals
  13. Children
  14. Your Responsibilities
  15. Contact, Grievance Officer, and Redressal
  16. Updates to This Policy
1. Introduction

This Privacy Policy describes how Renaissa AI Labs Pvt Ltd, a company incorporated in India and operating the Tyren platform ("Tyren", "we", "our", or "us"), collects, uses, discloses, stores, and protects personal data when you use Tyren in India.

Tyren is an AI-powered cloud software platform for tyre and auto-care businesses in India. This Policy applies to our website, web application, application programming interfaces (APIs), kiosk mode, dealer locator, warranty-related flows, and related services made available in India (collectively, the "Service").

This Policy applies to: (a) registered users such as business owners, administrators, accountants, regional managers, managers, and staff; (b) authorised platform operators with elevated access for administration and support; (c) visitors to our public marketing pages in India; and (d) personal data of end-customers or other individuals that you upload or process through Tyren on behalf of your business (for example CRM records, warranty claimants, or lead form respondents).

By creating an account, logging in, accepting this Policy in the application, or continuing to use the Service after we publish an update, you acknowledge that you have read this Privacy Policy. Where required under applicable law, we record acceptance with policy version, date and time, and related audit metadata.

This Policy is intended to align with the Digital Personal Data Protection Act, 2023 (India) ("DPDP Act") and rules notified thereunder, as applicable to our processing. It is provided for transparency and does not constitute legal advice. You should obtain advice from qualified legal counsel in India regarding your own obligations.

2. Personal Data We Collect

We collect personal data depending on how you interact with Tyren. Categories include:

Account and authentication data: full name, email address, mobile number, username, business role (such as owner, admin, accountant, regional manager, manager, or staff), postal address, password hashes (we do not store plaintext passwords), sign-in identifiers (for example Google OAuth or enterprise SAML where enabled), multi-factor authentication configuration, session metadata, and optional AI preference settings in your account.

Business and tenant data: business or trading name, business type, GSTIN or other tax identifiers, business and billing contact details, subscription plan, billing cycle, currency and timezone settings, outlet names and addresses (including optional latitude and longitude from signup or map integrations), inventory records, invoices, job cards, appointments, point-of-sale transactions, financial reports, and other operational data you enter.

CRM and customer data (processed on your behalf): names, email, phone, address, vehicle information, lifecycle stage, communication preferences, consent flags for marketing channels, messages, and custom fields relating to your end-customers. You, as the Data Fiduciary for that data, are responsible for lawful collection, notice, and consent.

Payment and billing data: subscription status, plan identifiers, credit balances, usage metering, billing events, and payment metadata from Razorpay or Stripe (as configured for your plan). Card numbers and sensitive payment credentials are processed by the payment provider, not stored by Tyren.

Uploaded files and user-generated content: product catalogue images, warranty claim photographs, inventory import files (CSV/XLS), invoice PDFs and attachments, and text or markdown documents uploaded to AI knowledge bases.

AI interaction data: prompts, chat messages, conversation history, agent run metadata, page context used for assistance, tyre image inputs for diagnostic features, voice interaction metadata where enabled, AI usage logs for billing and security, feedback on outputs, and vector embeddings derived from documents you submit for semantic search within your tenant.

Communications data: email content and delivery metadata, WhatsApp Business messages and templates where you enable the integration, SMS metadata where the feature is enabled, and voice call metadata where telephony integrations (such as Twilio or ElevenLabs) are configured.

Usage, security, and technical data: feature usage, audit logs, API usage metering, login sessions (IP address, user agent, device type, browser, operating system), structured application logs, error and monitoring events, and in-product telemetry events stored in our systems.

Visitor and marketing data: pseudonymous visitor identifiers, cookie consent choices on our public site, referrer and UTM parameters, device and browser information, optional device fingerprinting for lead attribution where enabled, and information submitted through contact, demo, warranty, or dealer-locator forms.

We do not intentionally collect personal data of children. We do not ask you to upload health or other sensitive personal data unless you choose to enter it in free-text fields for your business needs; avoid uploading unnecessary sensitive personal data.

3. How We Collect Personal Data

Directly from you when you register (including multi-step signup), update profile or business settings, use dashboards, upload files, subscribe to plans, or contact support.

Automatically through cookies, HttpOnly session tokens, CSRF tokens, server logs, security controls, API metering, and application telemetry when you use the Service.

From integrations you or we enable that are part of the Service: payment gateway webhooks (Razorpay, Stripe), email delivery (SMTP, Amazon SES, SendGrid, or Mailgun as configured), WhatsApp Business API, voice telephony providers, Google sign-in or Google Business Profile, GST validation services, maps or location services (such as Geoapify), and AI model providers (including AWS Bedrock, OpenAI, Google Gemini, and other providers configured in the platform).

From your authorised staff or administrators who create, import, or update customer, inventory, and operational records.

From end-customers or visitors interacting with flows you operate, such as public warranty claims, appointments, kiosk interactions, and lead-capture or chat widgets.

Through AI-assisted processing of inputs you provide to generate summaries, recommendations, classifications, or drafts. Outputs are advisory; you must review them before operational or customer-facing use.

4. How We Use Personal Data

We use personal data to: create and manage accounts and business workspaces; authenticate users and enforce role-based and page-level access; provide features including POS, inventory, CRM, finance, appointments, warranty management, reporting, kiosk mode, and AI assistants; process subscriptions, payments, credits, and usage entitlements; send service, billing, and security communications; provide support; improve reliability and security; detect fraud and abuse; meet legal and regulatory obligations in India (including tax and GST-related record-keeping features); and respond to lawful requests from Indian authorities.

AI features may process your business data and prompts to provide analysis, automation, recommendations, summarisation, and conversational support. AI outputs are for decision support only.

Where you process personal data of your customers, employees, or other individuals in Tyren, you act as the Data Fiduciary for that data. Renaissa AI Labs Pvt Ltd acts as a Data Processor processing such data on your documented instructions through the Service, unless otherwise agreed in writing.

5. Processing Under the DPDP Act, 2023

The DPDP Act regulates how personal data is processed in India. Key terms used in this Policy: "personal data" means data about an individual who is identifiable from such data; "Data Principal" means the individual to whom the personal data relates; "Data Fiduciary" means the entity that determines the purpose and means of processing; and "Data Processor" means the entity that processes personal data on behalf of a Data Fiduciary.

For personal data relating to your Tyren account and our direct relationship with you, Renaissa AI Labs Pvt Ltd is the Data Fiduciary. For personal data of your end-customers or staff that you upload or manage in Tyren, you are the Data Fiduciary and we are your Data Processor.

We process personal data on one or more grounds recognised under the DPDP Act and applicable rules, including: your consent (for example when you accept this Policy in the application, accept marketing cookies on our public website, or configure consent flags in CRM); performance of a contract with you to provide the Service; compliance with any law in force in India; and certain legitimate uses as defined under the DPDP Act where applicable.

Where processing is based on consent, you may withdraw consent through available controls or by contacting us. Withdrawal does not affect the lawfulness of processing before withdrawal. Some features may not be available if you withdraw consent necessary for those features.

As a Data Principal, you may have rights under the DPDP Act, including the right to obtain information about personal data we process about you, request correction or erasure where applicable, withdraw consent where processing is consent-based, nominate another individual in permitted circumstances, and seek grievance redressal as described in Section 15 of this Policy.

If you are a Data Fiduciary using Tyren, you are responsible for providing notice to Data Principals, obtaining valid consent where required, responding to their requests, implementing grievance mechanisms for your organisation, and notifying personal data breaches as required by law. Use of Tyren does not by itself fulfil all obligations that may apply to your business under the DPDP Act.

We will endeavour to respond to Data Principal requests and grievances within timelines prescribed under the DPDP Act and applicable rules, subject to verification of identity and applicable exceptions.

6. AI Features and Automated Processing

Tyren includes AI assistants, agents, and automation that may process business records, conversation text, uploaded documents, images, and contextual metadata (such as current page or tenant) to generate suggestions, drafts, analytics, diagnostics, or operational insights.

AI outputs may be inaccurate, incomplete, or outdated. They are decision-support only. You must independently verify AI-generated content before relying on it for pricing, safety, warranty, tax, or customer-facing decisions.

Prompts, responses, and related context may be stored in conversation history, AI audit logs, and usage metering for quality, security, billing, and support.

We may send prompts to third-party AI providers configured for the Service (such as AWS Bedrock, OpenAI, Google Gemini, or other configured endpoints). We limit data shared to what is necessary for the requested feature.

Knowledge-base features may convert document text into vector embeddings stored in our database (for example using pgvector) for semantic search within your tenant. Embeddings are derived from content you upload.

By default, Tyren does not make solely automated decisions that produce significant legal or similar effects about individuals without meaningful human involvement. If you implement binding automated decisions outside our defaults, you remain responsible for compliance with the DPDP Act.

Do not submit unnecessary sensitive personal data in AI prompts or uploads unless required for your legitimate business purpose.

7. Cookies and Similar Technologies

Necessary cookies and tokens: HttpOnly authentication cookies (access and refresh tokens), CSRF protection tokens, and session identifiers required to operate the Service securely. These are essential for logged-in use.

Preference storage: theme selection (light/dark) and similar UI preferences may be stored in your browser local storage.

Analytics on our public marketing site: after you accept our cookie consent banner, we may use analytics tools such as PostHog, and optionally Google Analytics or Hotjar if configured by us, to understand how visitors use our site. This is separate from in-app acceptance of this Privacy Policy.

Visitor tracking: where enabled, our public site may record visitor sessions, UTM parameters, and events through our visitor tracking API to support lead attribution and product improvement.

In-app telemetry: authenticated use may generate product telemetry events stored in our systems, distinct from third-party marketing analytics.

You can manage non-essential cookies through our cookie banner where shown. Browser settings may also limit cookies; some features may not work without necessary cookies.

8. Disclosure of Personal Data

We may disclose personal data to the following categories of recipients, only as needed to operate the Service or comply with law:

Infrastructure and technology service providers (for example Amazon Web Services for hosting, storage, and AI services); payment processors (Razorpay, Stripe); AI and embedding model providers; email, SMS, WhatsApp, and voice telephony providers; maps and geolocation services; analytics and monitoring tools; professional advisers bound by confidentiality; and government, regulatory, or judicial authorities in India when required by applicable law.

Within your organisation, personal data is accessible to users according to role (owner, admin, accountant, regional manager, manager, staff), outlet assignments, and page-level permissions you configure. Platform operators with super-admin access may access data only as necessary for platform administration, support, and security.

We do not sell personal data. We may share aggregated or de-identified information that cannot reasonably identify an individual.

If we undergo a merger, acquisition, reorganisation, or sale of assets, personal data may be transferred subject to this Policy or notice to you, in compliance with applicable law in India.

9. Storage and Processing Location

Tyren is operated from India. We primarily store and process personal data using infrastructure located in India or regions selected for our Indian operations.

Some service providers we use (for example cloud hosting, email, payment, or AI providers) may process personal data using systems located outside India as part of delivering the Service. Where personal data is processed outside India, we take steps consistent with the DPDP Act and applicable rules regarding cross-border processing, including contractual arrangements with processors where appropriate.

By using the Service, you acknowledge that limited processing outside India may occur through such providers when necessary to provide features you use. For questions about processing locations, contact us using Section 15.

10. Retention and Deletion

We retain account and business workspace data while your subscription is active and for a reasonable period afterward to support reactivation, billing reconciliation, disputes, and legal obligations in India.

Transaction, invoice, and tax-related records (including GST-related data) may be retained for longer periods as required under applicable Indian law (including record-keeping requirements under tax laws, commonly up to seven years for certain records, as advised by your tax professional).

Security logs, audit trails, and policy acceptance records are retained for periods aligned with security, fraud prevention, and compliance needs.

AI conversation logs, agent runs, and embeddings may be retained according to operational requirements until deleted where the product supports deletion.

When you delete records in the application, residual copies may remain in backups for a limited retention period before automatic purging.

Upon account closure, we will delete or anonymise personal data where feasible, subject to retention required by law. You may request access, correction, or erasure regarding your account data by contacting us under Section 15.

11. Security Safeguards

We implement reasonable technical and organisational measures to protect personal data, including: encryption in transit (TLS); password hashing (Argon2); HttpOnly authentication cookies; CSRF protection on state-changing requests; role-based and page-level access controls; multi-tenant and outlet-scoped isolation; rate limiting; structured logging with redaction of sensitive fields where configured; audit trails for key actions; and backup practices.

No method of transmission or storage is completely secure. You are responsible for safeguarding your credentials, configuring staff permissions appropriately, and reporting suspected unauthorised access promptly.

We do not claim security certifications unless explicitly published by us in writing.

12. Rights of Data Principals

If you are a Data Principal whose personal data we process as Data Fiduciary (for example your Tyren account data), you may exercise applicable rights under the DPDP Act, including:

The right to access information about personal data we process about you and the processing activities, subject to applicable exceptions.

The right to request correction of inaccurate or misleading personal data.

The right to request erasure of personal data where applicable under the DPDP Act.

The right to withdraw consent where processing is based on consent, as described in Section 5.

The right to nominate another individual to exercise your rights in the event of death or incapacity, in accordance with the DPDP Act.

The right to grievance redressal through our Grievance Officer or contact channels in Section 15. If your grievance is not resolved satisfactorily, you may have the right to approach the Data Protection Board of India under the DPDP Act and applicable rules.

If you are an end-customer of a business using Tyren, contact that business (the Data Fiduciary) for requests relating to data they control. We will assist our business customers as required by our agreements and applicable law.

We may verify your identity before responding to requests. To exercise rights regarding your Tyren account, contact us using Section 15.

13. Children

The Service is intended for business users and individuals who are at least 18 years of age. We do not knowingly collect personal data from children. If you believe we have collected personal data of a child without appropriate authority, contact us and we will take steps to delete it where required by law.

14. Your Responsibilities

You must provide accurate account information, keep credentials confidential, configure appropriate access for staff, and notify us of unauthorised access.

If you upload personal data about third parties (customers, employees, or others), you must comply with the DPDP Act and other applicable Indian laws, including providing notice, obtaining consent where required, and honouring commercial communication rules (including Telecom Regulatory Authority of India (TRAI) and Distributed Ledger Technology (DLT) requirements for SMS where applicable).

You must not use the Service to process unlawful content or personal data without proper authority.

15. Contact, Grievance Officer, and Redressal

For privacy questions, Data Principal requests, or grievances under the DPDP Act, contact:

Privacy enquiries: privacy@tyren.com

Grievance redressal: use the grievance contact email published in the Service (or the privacy contact if not separately listed).

Data Protection Officer (if appointed): dpo@tyren.com

General support: support@tyren.com

Registered office: as published in the Service for Renaissa AI Labs Pvt Ltd.

Grievance Officer: [Name and contact details to be appointed and published by legal counsel]

We will acknowledge and endeavour to resolve grievances in accordance with timelines under the DPDP Act and applicable rules.

16. Updates to This Policy

We may update this Privacy Policy from time to time. We will update the version number, effective date, and last updated date at the top of the policy.

Material changes may require you to accept the updated policy in the application before continuing to use protected features. Prior acceptance records (version, timestamp, IP address, and user agent where collected) are retained for audit purposes.

This document is provided for operational transparency. It does not constitute legal advice. Please review with qualified counsel for your jurisdiction.

Return to home · Terms and Conditions