Jarlo
PrivacyTerms

Effective 15 September 2026

Privacy policy

What information Jarlo holds, why it is held, who else can see it, and how to ask for a copy, a correction or a deletion.

1. Who operates Jarlo

Operator
Kode Pundit
Business type
Sole proprietorship
Correspondence address
Siliguri, West Bengal, India
Privacy or grievance contact
contact@kodepundit.com

Jarlo is offered to businesses in India. This policy is written with the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 in mind.

2. What Jarlo is

Jarlo is a software tool for water-delivery businesses. A business owner uses it to keep track of their customers, record the deliveries they make, produce a monthly bill for each customer, send that bill over WhatsApp, and see who still owes money.

Jarlo is used by the business owner. The customers of that business do not have accounts and do not sign in. A customer may receive a link to a read-only copy of their own bill.

3. Information Jarlo collects

Account information, given by the business owner

  • The business name.
  • The owner’s name, which is optional at sign-up.
  • The owner’s mobile number. This is the sign-in identifier, so an account cannot be created without one. No email address is asked for or stored.
  • A password. The password itself is never stored. Jarlo stores only a one-way scrambled form of it, which cannot be turned back into the password.
  • A session record, created when the owner signs in. Jarlo stores only a one-way scrambled form of the session value, not the value held by the browser.
  • Business settings the owner chooses: the postal address shown on bills, the bill due day, a UPI ID and preferred UPI app, and the lines of text printed above and below a bill.

Customer information, entered by the business

This is information about the business’s own customers, which the business owner types in or imports. Jarlo holds it so the business can run its round and bill for it.

  • Customer name and nickname, and a short label such as a shop or floor.
  • Customer mobile number.
  • Customer address, where the owner records one.
  • A marker for a customer who is not reachable on WhatsApp.
  • Delivery records: the date, the product, the quantity, the price charged, and which trip of the day it was.
  • Products and prices, including a price set for one particular customer.
  • Bills: the month covered, the totals, the due date, the bill number once one is issued, and when the bill was sent.
  • Payments: the amount, the date received, the method, and a free-text reference the owner may use as a private note.
  • A record of each attempt to send a bill, including whether it succeeded and any error the messaging provider returned.

Contact import files are read inside the owner’s own browser and are never uploaded to Jarlo. Only the rows the owner reviews and keeps are sent, and only the name and phone number from those rows.

Technical information

  • The network address a request came from, used only to limit repeated sign-in attempts, repeated sign-up attempts, and repeated opening of public bill links. It is stored as part of a counter record.
  • One cookie, which identifies the signed-in session. See section 12.
  • Error logs. When something fails unexpectedly, Jarlo writes one line to the server log. Those lines carry record identifiers and a technical error message. They deliberately do not carry names, phone numbers, request headers or search terms.
  • A random link token, created when a bill is shared with a customer. Anyone holding the link can see that one bill until the link expires or the owner revokes it.

What Jarlo does not collect

  • No analytics, advertising or tracking service is used, and none is installed.
  • No location or GPS data.
  • No email addresses.
  • No payment card or bank account details are ever handled by Jarlo itself.

4. Why the information is used

  • To run the service. Customers, deliveries, products and prices are stored so the business can see its own records.
  • To sign the owner in and keep them signed in. The mobile number and password prove who is asking; the session record keeps them signed in afterwards.
  • To produce bills. Deliveries are added up into a monthly bill for each customer, and payments are recorded against it.
  • To send bills and reminders. A customer’s name, mobile number, bill amount and due date are used to compose the message the owner sends.
  • To prevent abuse. Network addresses are counted so that repeated password guessing and repeated automated requests can be slowed down.
  • To fix faults. Error logs are used to find and repair problems.
  • To manage a paid plan, where the owner has chosen one and online payment is switched on.

Information is not used for advertising, is not sold, and is not used to build a profile of anybody.

5. Who else can see the information

Jarlo does not sell information and does not share it for anybody else’s marketing. It does rely on a small number of service providers, and information necessarily passes through them.

Always involved

  • A hosting provider, which runs the application and receives every request made to it, including server error logs.
  • A database provider, which stores all of the records described above.

These two are unavoidable: a web application cannot run without somewhere to run and somewhere to keep its data. They act on instructions and do not use the information for anything of their own. Write to contact@kodepundit.com if you want to know which providers are in use at the moment.

Involved only if the feature is switched on

  • Automatic WhatsApp sending, through Meta’s WhatsApp Business Platform. If a business is on a plan that includes it and the operator has configured it, Jarlo sends the customer’s mobile number and the bill details to Meta so the message can be delivered. If this is not switched on, the owner sends bills from their own WhatsApp account and Jarlo sends nothing to Meta.
  • Online subscription payments, through Razorpay. If the operator has switched on online upgrades, Jarlo asks Razorpay to create a subscription and sends Razorpay the plan being bought and an internal reference for the business. Payment details are entered on Razorpay’s own checkout page and are handled by Razorpay, not by Jarlo. Jarlo also stores the notifications Razorpay sends back about the subscription.

Information may also be disclosed where the law requires it, or where it is necessary to investigate abuse of the service.

Information may be processed outside India. Whether it is depends on the providers in use and the regions they run in. Where automatic WhatsApp sending is switched on, messages are handled by Meta’s own international infrastructure. Write to contact@kodepundit.com if you need to know the current position for a particular provider.

6. How long information is kept

The general rule is that information is kept for as long as it is needed for the purpose it was collected for, and removed when that purpose has ended.

Business records are the exception, and deliberately so. Customers, deliveries, products, bills and payments are kept for as long as the account exists. A delivery ledger is the business’s own history, and deleting last year’s bills on a schedule would remove records the business may need. They are deleted when the account is deleted.

Everything else has a shorter life.

  • Sign-in sessions. A session expires 30 days after sign-in. The record is deleted when the owner signs out, and expired records are removed by a routine cleanup.
  • Rate-limiting counters, which hold a network address. The count resets once its time window passes. The record for a mobile number is deleted on a successful sign-in, and records are removed by the same routine cleanup once they are more than a day past their window. This is what removes a network address from the database.
  • Customers and products the owner removes are archived rather than deleted, because past bills refer to them. They go when the account goes.
  • Bill links expire on a date stored with the bill, and the owner can revoke one at any time.
  • Records of subscription payments made by the owner to Jarlo are kept for as long as accounting and tax rules require them to be kept.
  • Server error logs are kept for as long as the hosting provider keeps them. They carry record identifiers and no names or phone numbers.

Backups are the honest caveat on all of the above. A backup taken before something was deleted still contains it until that backup ages out of the rotation, so deletion is never instantaneous everywhere.

7. Security

Jarlo takes reasonable measures to protect the information it holds. Passwords are stored only in a one-way scrambled form using a standard, deliberately slow method. Session values are stored the same way, so the stored copy cannot be used to sign in. The session cookie is not readable by scripts in the browser and is sent only over an encrypted connection in production.

Each business can only reach its own records. That separation is enforced by the database itself as well as by the application, so one business cannot see another’s customers even if the application were at fault.

Repeated sign-in attempts are slowed down. Bill links use long random values and can be revoked.

No service can promise that information will never be exposed. If a breach affecting personal data does happen, the operator will act on it and notify the people and the authorities that the law requires to be notified.

8. Your rights and how to use them

A person whose personal data Jarlo holds can ask for a summary of that data, ask for a correction, ask for it to be erased, and raise a grievance about how it has been handled.

Some of this can be done in the product. A business owner can edit their own business details and their customers’ details at any time from within Jarlo, and can remove deliveries and payments they recorded.

There is no button that deletes an account. To ask for an account to be deleted, or to make any request above, write to contact@kodepundit.com. The operator will ask enough questions to confirm who is making the request before acting on it, and will respond within the time the law requires.

If a request concerns a customer of a water business rather than the business owner, the right place to start is usually that business, because the business decides what it records about its customers. Jarlo will help the business act on the request.

Privacy or grievance contact: contact@kodepundit.com. Grievances about how Kode Pundit has handled personal data go to the same address, and are answered by Kode Pundit. A grievance that is not resolved can be taken to the Data Protection Board of India under the Digital Personal Data Protection Act, 2023.

9. Customer information entered by a business

When a business enters its customers’ details into Jarlo, the business decides what to record and why. Jarlo stores and processes that information on the business’s instructions so that the business can run its deliveries and collect what it is owed.

A business using Jarlo is responsible for making sure it is entitled to hold the customer details it enters, that those details are accurate, and that it uses the mobile numbers it holds in a way its customers would expect. In practice, for a delivery business, that means the details of people it actually delivers to.

Jarlo does not contact a business’s customers on its own account, and does not use their details for anything except providing the service to that business.

10. Children

Jarlo is a tool for running a business. It is meant for business users aged 18 or over, and it is not designed for or directed at children. Accounts should not be created by anyone under 18.

Jarlo does not verify age at sign-up, so this is a condition of use rather than something the software checks. Jarlo does not knowingly collect personal data about children, and does not track, profile or advertise to anybody.

11. Changes to this policy

This policy may be updated, for example when a new service provider is introduced or a feature changes what information is collected. The effective date at the top of this page shows when the current version took effect. A change that materially affects how personal data is handled will be brought to the owner’s attention rather than only published here.

12. Cookies

Jarlo sets one cookie, and it is required for the service to work. There is no analytics cookie, no advertising cookie, and no third-party cookie.

  • jarlo_session. Keeps the owner signed in. It holds a random value and nothing else, is not readable by scripts in the browser, is sent only over an encrypted connection in production, and lasts 30 days or until sign-out.

Because this cookie is strictly necessary to provide a service the owner asked for, Jarlo does not show a cookie consent banner. If a non-essential cookie is ever added, that will change.

Privacy policyTerms of useBack to sign in

Jarlo is operated by Kode Pundit, Siliguri, West Bengal, India. Questions about either document go to contact@kodepundit.com.