1. Who We Are
Anymo ("we", "us", "our") is a mobile-first rental management platform that helps rental businesses manage inventory, process orders, and connect with customers. This Privacy Policy explains how we collect, use, store, and protect your personal information when you use the Anymo mobile application and website (collectively, the "Service").
If you have questions about this policy, you can reach us at admin@anymo.app.
2. Information We Collect
2.1 Information You Provide
When you create an account and use Anymo, we collect the following:
- Account information — username, email address, mobile phone number (used for OTP-based authentication via SMS), and your country (automatically detected from your phone number during registration).
- Profile details — profile photo and brand logo (optional), which are uploaded and stored on our cloud servers.
- Address and location — street address, city, state, pincode, and GPS coordinates (latitude/longitude) when you grant location permission. Location is collected on-demand (not continuously in the background) and is used to show nearby rental products to customers and to set your business address.
- Product listings — product names, descriptions, photos, pricing, and availability information you add to your inventory.
- Messages — conversations between rental owners and customers within the app.
- Ratings and reviews — ratings and review text that users submit about rental owners.
2.2 Information Collected Automatically
When you use the Service, we automatically collect:
- Device tokens — Firebase Cloud Messaging (FCM) tokens for delivering push notifications about orders, payments, and messages.
- Crash and error data — technical error reports via Sentry and Firebase Crashlytics to help us identify and fix bugs. We have disabled the collection of personally identifiable information (PII) in these services.
- Order and transaction records — order details, rental dates, amounts, and status changes, including audit logs of modifications.
- Analytics and product-usage data — page views, screen views, session data, HTTP referrer, device model, operating-system version, and approximate location (derived from IP address) via Google Analytics 4 (website) and Firebase Analytics (mobile app). This data is pseudonymous — we do not link it to your name, email, or phone number.
- Advertising and conversion data — event data (e.g. page view, "Get the App" click, sign-up, listing created, booking started) sent to Meta Pixel (website) and Facebook App Events (mobile app), and to Google Ads conversion tags, so we can measure which ad campaigns drive real usage. On mobile devices this includes your advertising identifier (Apple IDFA on iOS if you allow tracking; Google Advertising ID on Android unless you opt out in your device settings).
- Attribution data — UTM parameters (
utm_source,utm_medium,utm_campaign,utm_content,utm_term), Google click identifier (gclid), Meta click identifier (fbclid), the landing page URL, and a first-touch timestamp — captured from your first visit and stored against your user record so we can compute cost-per-signup by campaign.
3. How We Use Your Information
We use the information we collect to:
- Create and manage your account, and authenticate you via OTP.
- Display nearby rental products to customers based on location.
- Facilitate messaging between rental owners and customers.
- Send push notifications about order updates, payment reminders, and new messages.
- Process and track rental orders, returns, and related transactions.
- Monitor and improve the stability of the app through crash and error reporting.
- Understand how the Service is used, measure feature adoption, and improve the product through pseudonymous analytics.
- Measure the effectiveness of our advertising campaigns, attribute installs and sign-ups to specific ads, and show relevant ads to prospective and existing users.
- Build custom and lookalike audiences on advertising platforms (Meta, Google) to reach people similar to our existing users.
- Enforce our Terms of Service and protect against misuse.
4. How We Share Your Information
We do not sell your personal data. We share information only in these limited circumstances:
- With other users — your username, profile photo, brand logo, general location, product listings, and ratings are visible to other users of the platform as part of the rental marketplace.
- Service providers — we use the following third-party services to operate Anymo:
- Amazon Web Services (AWS S3) — cloud storage for product images, profile photos, and brand logos.
- Twilio — SMS delivery for OTP authentication.
- Firebase (Google) — push notifications (FCM), crash reporting (Crashlytics), and mobile app analytics (Firebase Analytics).
- Google (Google Analytics 4, Google Ads) — website and app analytics, ad conversion measurement, and advertising.
- Meta Platforms (Meta Pixel, Facebook App Events) — ad conversion measurement, audience creation, and advertising for Facebook and Instagram campaigns.
- Sentry — error tracking and application monitoring (PII collection disabled).
- OpenStreetMap / Nominatim — reverse geocoding to convert GPS coordinates into readable addresses.
- Legal requirements — we may disclose information if required by law, regulation, legal process, or governmental request.
5. Cookies and Similar Technologies
Our website uses cookies and similar technologies for the purposes below. On the mobile app, equivalent identifiers (device advertising IDs, Firebase installation IDs) are used instead of cookies.
- First-party attribution cookie — we set a cookie on your first visit to remember which ad or link brought you to us (UTM parameters,
gclid,fbclid). Kept for 30 days; used solely so a sign-up you complete later is credited to the correct campaign. - Third-party analytics cookies — set by Google Analytics 4 to distinguish visitors and sessions. Do not identify you personally.
- Third-party advertising cookies — set by Meta Pixel and Google Ads to measure ad performance and show you relevant ads on Meta and Google properties. May be used for retargeting (showing you ads on Facebook, Instagram, or across the Google Display Network after you have visited us).
You can control cookies through your browser settings. Blocking third-party cookies will prevent our advertising partners from measuring conversions and showing you tailored ads, but will not affect your ability to use the Service.
6. Advertising and Marketing
We advertise Anymo on Google (search and display ads) and Meta (Facebook and Instagram ads). To measure whether these ads work, and to reach people who resemble our existing users, we share event data (as described in section 2.2) with these platforms. This includes:
- Aggregate conversion events (a sign-up happened, a listing was created, a booking started) tied to your device or browser via pseudonymous identifiers.
- On mobile devices, your advertising identifier (Apple IDFA / Google Advertising ID) unless you opt out.
- Attribution data (UTM parameters, click identifiers) so the platform can match the event back to the ad you clicked.
You can control what these platforms do with your data through their own settings:
- Google Ads — My Ad Center and Google Analytics Opt-out.
- Meta (Facebook / Instagram) — Meta Ad Preferences.
7. Your Choices
You can control what data we and our advertising partners collect:
- iOS App Tracking Transparency — when you first open the app, you will see Apple's "Allow tracking" prompt. Choosing "Ask App Not to Track" prevents the Meta SDK from accessing your Apple advertising identifier (IDFA); Meta then falls back to aggregated, non-user-level measurement.
- Android advertising ID — you can reset or opt out of ads personalisation in Settings → Google → Ads on your Android device.
- Web browser — you can block third-party cookies, install the Google Analytics Opt-out add-on, or use privacy-focused browser features (Do Not Track, tracking prevention).
- Location, camera, photos, notifications — grant or revoke these permissions in your device settings at any time.
8. Data Storage and Security
Your data is stored in a PostgreSQL database and AWS S3 cloud storage. Authentication tokens are stored securely on your device using encrypted storage. We use JWT-based authentication, rate limiting on sensitive endpoints, and log sanitization to protect your information.
While we take reasonable measures to protect your data, no method of electronic storage or transmission is 100% secure. We cannot guarantee absolute security.
9. Data Retention
We retain your account data for as long as your account is active. If you delete your account, we soft-delete your profile (marking it as deleted and disabling push notifications). Order and transaction records may be retained for legal and accounting purposes even after account deletion.
Analytics and advertising event data is retained by our third-party providers (Google, Meta) according to their standard retention policies — typically 14 to 26 months for user-level data, longer for aggregated reporting. Attribution data stored against your user record is retained for the life of the account.
10. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access the personal data we hold about you.
- Correct inaccurate data in your profile (you can do this directly in the app).
- Delete your account (available in the app under account settings).
- Withdraw consent for location access, notifications, or ad tracking through your device settings.
To exercise any of these rights, contact us at admin@anymo.app.
11. Permissions We Request
The Anymo mobile app requests the following device permissions:
- Location (GPS) — to show nearby rental products and set your business address. You can deny or revoke this at any time in your device settings.
- Camera — to capture product photos for your inventory listings.
- Photo library — to upload existing images as product photos, profile pictures, or brand logos.
- Notifications — to receive alerts about orders, payments, and messages.
- App Tracking Transparency (iOS only) — asks whether we may use your Apple advertising identifier to measure ad effectiveness. Declining does not affect app functionality.
All permissions are optional. Core functionality may be limited if certain permissions are denied.
12. Consent
By creating an account on Anymo, you explicitly consent to the collection and processing of your personal data as described in this policy. You must accept our terms during registration to use the Service. You may withdraw consent at any time by deleting your account or adjusting individual permissions (such as location, notifications, and ad tracking) through your device settings.
13. Compliance with India's Digital Personal Data Protection Act (DPDP Act, 2023)
Anymo processes personal data of individuals in India and is committed to complying with the Digital Personal Data Protection Act, 2023 ("DPDP Act"). The following outlines how we meet our obligations under this law:
13.1 Lawful Purpose and Consent
We collect and process your personal data only for the lawful purposes described in this policy. We obtain your explicit consent at the time of account registration before collecting any personal data. You may withdraw your consent at any time by deleting your account through the app or by contacting us — upon withdrawal, we will cease processing your data except where retention is required by law.
13.2 Data Principal Rights
Under the DPDP Act, you (as a "Data Principal") have the right to:
- Obtain a summary of your personal data and the processing activities carried out on it.
- Request correction and completion of inaccurate or incomplete personal data.
- Request erasure of your personal data (subject to legal retention requirements).
- Nominate another individual to exercise your rights in the event of your death or incapacity.
You can exercise most of these rights directly within the app. For requests that cannot be handled in-app, contact our Grievance Officer (details below).
13.3 Data Retention and Erasure
We retain your personal data only as long as it is needed for the purposes described in this policy. When you delete your account, we soft-delete your profile and cease all active processing. Order and transaction records may be retained for up to 3 years to meet accounting and legal obligations, after which they will be permanently erased.
13.4 Data Security and Breach Notification
We implement reasonable security safeguards including encrypted token storage, JWT-based authentication, rate limiting, and PII scrubbing in logs and error reporting. In the event of a personal data breach, we will notify the Data Protection Board of India and affected users as required under the DPDP Act.
13.5 Grievance Officer
In accordance with the DPDP Act, you may direct any questions, complaints, or requests regarding your personal data to our Grievance Officer:
Grievance Officer — Anymo
Name: Sandeep Jayakumar
Email: admin@anymo.app
Address: Kochi, Kerala, India
Acknowledgement: Within 24 hours of receiving your complaint
Resolution: Within 15 days, in line with the Information Technology
(Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021
and the Digital Personal Data Protection Act, 2023
14. Children's Privacy
Anymo is not intended for use by anyone under the age of 18. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact us and we will delete it.
15. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date at the top of this page and, for material changes, prompt you in the app to review and accept the updated policy. We encourage you to review this policy periodically. Continued use of the Service after changes constitutes acceptance of the updated policy.
16. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us at:
Anymo
Email: admin@anymo.app