Legal
Privacy Policy
Last updated: 26 July 2026
modenX operates under two separate Privacy Policies — one for customers and visitors in the United States and one for customers and visitors in India. Read the version that applies to you.
United States
This section applies if your business, or the location you visited, is in the United States. ModenX Inc. is the responsible entity.
1. Who we are
ModenX Inc., a Delaware corporation with its principal place of business at 66 Ridgeview Drive, Basking Ridge, New Jersey 07920, is responsible for personal information covered by this policy for customers and visitors in the United States. In this policy, "modenX", "we" and "us" mean ModenX Inc.
modenX Inc. uses ModenX India Private Limited (India), an affiliate, as a service provider to host and operate the platform on its behalf. That affiliate processes personal information only on modenX Inc.'s instructions and under written contract. Personal information covered by this policy is currently stored and processed in India — see §11.
If your business is located in India, a separate India-market policy applies and ModenX India Private Limited is the entity responsible.
Contact us at [email protected] or at the postal address above.
2. Two roles — please read, it changes your rights
modenX handles personal information in two different capacities, and which one applies determines who you go to.
Our own customers. For the businesses that subscribe to modenX and the people who administer those accounts, we decide how that information is used. Under the CCPA and comparable state laws we are the business (controller) for this information.
Our customers' visitors — two roles, please read both.
Role one: as the venue's service provider. For the analytics, recognition, reporting and recommendations we produce for a venue, the venue decides and modenX acts only on that venue's documented instructions under a Data Processing Addendum. In that role we do not use the information for our own purposes, we do not sell it, we do not disclose it to any other venue, and we do not use one venue's data to serve another except as aggregated, de-identified benchmarks.
Role two: for Presora, in our own capacity. Where an individual holds a Presora account and has consented in the Presora app, their visits to participating venues also contribute to their Presora score. Presora is our own product, so for that use we act for ourselves and not as the venue's service provider, and the lawful basis is the individual's own consent given to us in the app. §7.5 explains this in full.
These are two different uses of the same underlying event, and we disclose both rather than describing only the first.
If you are a visitor and you want your information accessed, corrected or deleted, contact the business whose location you visited — they decide how it is used. Contact us at [email protected] and we will help identify the right business where we can, and we will assist that business in responding.
Consumer app users. For people who use the Presora consumer app, modenX is the business. See §7 and §8.
3. What we collect
From Client businesses and their administrators: Business name, contact name, work email address, work phone number, billing address, tax identifiers (EIN), plan selected, payment-method references and tokens from our payment provider, and a record of the consent given at signup.
Authentication: Login identifiers and tokens, via Auth0 (web) and Firebase Authentication (mobile).
Usage and device: Log data, IP address, device and browser identifiers, pages viewed, referring URLs, actions taken in the platform, and approximate location derived from IP address.
Communications: Contact forms, support tickets, and correspondence with us.
Visit and presence signals — processed for Clients: Arrival and departure events; dwell and movement signals derived from Bluetooth Low Energy (BLE), Wi-Fi and other sensors deployed at a Client's location; check-in and checkout events; transaction values; and loyalty identifiers. These signals can indicate an individual's location to a precision that state privacy laws treat as sensitive — see §5. A visitor is recognised only by an identifier they chose to provide — see §6.
Consumer app: See §8 for what the Presora consumer app collects.
We do not collect Social Security numbers, driver's licence numbers, financial account numbers, full payment card numbers, CVV, health or insurance information, precise racial or ethnic origin, religious beliefs, union membership, sexual orientation, immigration status, the contents of private communications, or any biometric identifier (see §6).
4. Why we use it
To provide, operate and secure the platform; to authenticate users; to process payments, renewals, refunds, taxes and fraud checks; to generate the analytics, benchmarks and recommendations Clients subscribe to; to send service, security, billing and legally required renewal notices; to answer support requests; to detect and prevent abuse, fraud and security incidents; to improve the platform; and to meet legal, tax, accounting and regulatory obligations.
We do not sell personal information. We do not use personal information for cross-context behavioural advertising. We do not use one Client's data to serve another Client except as aggregated, de-identified benchmarks that cannot reasonably be linked back to a Client or an individual.
We do not use automated decision-making technology to make decisions that produce legal or similarly significant effects about individuals — for example decisions about credit, housing, employment, insurance, education or healthcare. Our Terms prohibit Clients from using the platform for those purposes.
5. Location and presence information — please read
modenX's core function is detecting that a device or a recognised guest is present at a Client's location. That means:
- We process precise location information. Presence signals from BLE, Wi-Fi and in-venue sensors, and location collected by the consumer app, can place a person within a radius that state privacy laws treat as precise geolocation — generally 1,750 to 1,850 feet or less.
- Under the CCPA, precise geolocation is "sensitive personal information." Under most other state privacy laws it is "sensitive data" requiring opt-in consent before it is processed.
- What we use it for. To detect arrival and departure; to recognise a returning guest who has identified themselves; to generate the analytics and recommendations a venue subscribes to; to deliver offers a consumer app user has opted into; and — for individuals who hold a Presora account and have consented — to calculate their Presora score (see §7). We do not use it for advertising to people who have not asked for it.
- We do derive one inference from it, and only one. A Presora score is a measure of presence across participating venues, calculated from location and visit activity. That is an inference drawn from sensitive personal information, so we say so plainly, we do it only for people who have a Presora account and have consented, and you can direct us to stop — see US-4. We draw no other inferences: not about your health, finances, beliefs, or anything in the list at §3.
- We do not sell it or share it for advertising.
- We do not use it to detect visits to sensitive locations. modenX does not operate geofences within 2,000 feet of an in-person healthcare facility for the purpose of identifying, tracking, collecting data from, or advertising to individuals, and our Terms prohibit Clients from asking us to. See §9.
- For visitor data, the Client is responsible for the legal basis. Where the law of a Client's state requires notice, signage or opt-in consent before presence sensing, the Client — not modenX — is responsible for providing it. Our Terms require this of them.
6. Cameras, sensors and biometric information
modenX does not use facial recognition, and does not create, collect, store or use facial geometry, face templates, voiceprints, fingerprints, iris or retina scans, or any other biometric identifier or biometric information. We have verified this against the platform's source code.
We recognise a returning guest only by an identifier they have chosen to provide — a phone number, an email address, a loyalty identifier, a scan of a venue QR code, a check-in in the app, or a lookup performed by a store associate at the guest's request.
Where a Client operates cameras at its own locations, those cameras and any footage are the Client's, governed by the Client's own policies and signage. modenX does not receive, process or store images or video from them.
A profile photo a consumer app user chooses to upload is stored as an image supplied by that user. It is not converted into a face template and is not used to identify anyone.
7. Presora
Presora is a consumer product operated by modenX or a modenX affiliate. It is a separate product with its own account, its own terms and its own privacy notice, and using it is entirely voluntary.
7.3 The score is calculated by Presora from that individual's own Presora activity. The methodology is proprietary and patent-pending and is not disclosed in this or any other modenX document.
7.5 What your Presora score is built from
This is the part people most want a straight answer on, so here it is.
Your score is built from showing up. When you visit a participating venue and are recognised — because you check in, scan a QR code, or a store associate looks you up at your request — that visit contributes to your Presora score. Visits across different brands and venues all contribute. That is the point of the score: it reflects your presence across the participating network, not your activity at any single shop.
We do this only if you have a Presora account and have consented. If you do not use Presora, no score is calculated for you, and your visit data is handled only for the venue you visited, on that venue's instructions.
8. The Presora consumer app
This section applies to individuals who install and use the Presora consumer mobile app. For app users, modenX is the business and decides how the information below is used.
What the app collects
- Account and profile: name, email address, phone number, and any profile photo you add.
- Location, including precise and background location: used to detect when you enter a participating mall and to personalise your in-store experience. See §5.
- Bluetooth and proximity: signals from in-mall beacons, for location context.
- Camera and photos: images you capture or upload to scan QR codes, submit receipts, or set a profile photo.
- Activity and loyalty: visit history, offers viewed or redeemed, loyalty identifiers, and transaction data.
- Device and push: device identifiers, app version, and push notification tokens.
Permissions
Each permission is requested in context, is optional, and can be granted or revoked in your device settings at any time. Revoking a permission may limit features but does not close your account.
| Permission | Why |
|---|---|
| Location, including background | Detect nearby and participating malls; deliver location-relevant offers |
| Bluetooth | Detect in-mall beacons for location context |
| Camera | Scan QR codes; capture receipts |
| Photos | Upload receipts and a profile photo |
| Notifications | Send offers, alerts and account updates |
Consent for precise and background location
We ask for your express opt-in consent before collecting precise or background location, we tell you what it is used for at the point we ask, and you can withdraw it at any time in your device settings or in the app. We do not collect background location unless you have granted it.
We use your location and visit activity to calculate your Presora score — that is the purpose of the app — and we tell you so when we ask. We draw no other inferences about you from it.
Age
The Presora app is not directed to children under 13 and we do not knowingly collect personal information from them. If we learn we have collected information from a child under 13 we delete it promptly; contact [email protected] and we will act.
If you are between 13 and 17, we do not process your personal information for targeted advertising, for sale, or for profiling in furtherance of decisions producing legal or similarly significant effects, without the consent required by the law of your state.
Deleting your account
You can delete your account at any time in the app: Profile (YOU) → Delete Account. If you cannot reach the app, email [email protected] (US) with your details.
When you delete your account we permanently remove your profile and account data, location history, uploaded photos and receipts, and loyalty and activity data associated with your account. Some information may be retained for a limited period where required for legal, tax, accounting, security or fraud-prevention purposes, after which it is securely deleted. Deletion requests are actioned within 30 days.
9. Consumer health data
modenX does not intentionally collect, use, share or sell consumer health data, and does not seek to identify or infer any person's past, present or future physical or mental health status.
Because presence and location signals could in principle be interpreted to reveal a visit to a health service, we take specific measures: we do not operate geofences within 2,000 feet of an in-person healthcare facility for the purpose of identifying, tracking, collecting data from, or advertising to individuals; our Terms prohibit Clients from using the platform for that purpose or to infer health status; and we do not sell or share presence data.
This addresses the Washington My Health My Data Act, the Nevada Consumer Health Data Privacy Law and comparable state provisions. If you believe modenX holds consumer health data about you, contact [email protected] and we will investigate and, where it exists, delete it.
10. Sharing
We disclose personal information to the following categories of recipients, for the purposes stated, under written contract, and never in exchange for money:
| Category of recipient | Examples | Purpose |
|---|---|---|
| Affiliates | ModenX India Private Limited (India) | Hosting and operating the platform on our behalf |
| Cloud infrastructure | Microsoft Azure | Hosting, storage, compute |
| Payment processing | Stripe | Payments, subscriptions, refunds, fraud checks, tax calculation |
| Identity and authentication | Auth0, Firebase Authentication | Login and account security |
| Communications | email and push notification providers | Service, billing and legally required notices |
| Analytics and product telemetry | see the Cookie Policy | Understanding and improving use of the platform |
| Professional advisers | accountants, auditors, lawyers | Advice, audit, legal compliance |
| The relevant Client | — | Visitor information we process on that Client's behalf |
| Acquirers | — | In a merger, acquisition or sale of assets, with notice |
| Authorities | — | Where legally required, or to protect rights and safety |
A current list of sub-processors is available on request from [email protected].
We do not disclose personal information to data brokers and we are not a data broker.
11. Where your information is stored
As of the "Last updated" date above, personal information covered by this policy — including information about US Clients and their visitors — is stored and processed on Microsoft Azure infrastructure in the Central India region, and is accessed by ModenX India Private Limited (India) as modenX Inc.'s service provider, under written contract, for the purposes described in this policy. It is protected by the safeguards described in §12 regardless of where it is stored, and modenX Inc. remains accountable for it.
modenX intends to move US customer data to a Microsoft Azure region located in the United States. We will update this section, and the "Last updated" date, when that is complete.
12. Security
We maintain administrative, technical and physical safeguards designed to protect personal information: encryption in transit (TLS) and at rest; least-privilege role-based access control; network segregation; logging, monitoring and alerting; vulnerability management; background-checked personnel bound by confidentiality; and periodic review of controls and of our sub-processors.
No system is perfectly secure. If a breach affecting your personal information occurs we will notify you, and the relevant authorities, as required by applicable state breach-notification law.
Report a suspected vulnerability or incident to [email protected].
13. Retention
We keep personal information only as long as we need it for the purposes in §4, then delete or de-identify it.
| Information | Retention |
|---|---|
| Client account and profile data | Life of the account, then 90 days, then deleted |
| Visitor and presence data processed for a Client | As instructed by that Client under the DPA; deleted or returned on termination |
| Consumer app account data | Until you delete your account; then deleted within 30 days, subject to legal holds |
| Billing, invoice and tax records | As tax and accounting law requires, generally 7 years |
| Consent, subscription and cancellation records | At least 3 years, or 1 year after the subscription ends, whichever is longer |
| Website and product analytics | Up to 26 months |
| Access and security logs | At least 12 months |
| Support correspondence | 3 years from closure |
Where a legal hold, investigation or dispute requires it, we retain the affected information until it is resolved.
14. Cookies and tracking on modenx.com
See our Cookie Policy for the cookies, pixels, SDKs and similar technologies used on modenx.com, what each does, and how to control them.
We honour opt-out preference signals, including the Global Privacy Control (GPC), as a valid request to opt out of the sale or sharing of personal information for the browser or device that sends it. Where you are signed in, we apply it to your account.
We do not sell personal information for money.
Sharing your Presora score with a venue. Your score reaches a venue because you permitted it, in the Presora app, for the venues you chose. California law excludes from "sale" a disclosure the consumer directs the business to make, and you can withdraw that permission at any time. See §7.5.
The venue-to-modenX side is a different question, and we treat it conservatively. Because visit data collected by a venue also contributes to Presora — our own product — that disclosure may constitute a "sale" or a "share" under California law, which turns on any exchange of value and not only on money. We therefore offer the opt-out rather than argue about whether one is required. Use the "Do Not Sell or Share My Personal Information" link in the footer of every page, send a Global Privacy Control signal, or write to [email protected]. Venues are separately required by our contract to disclose this and offer you an opt-out at the point they collect your data. Some advertising and analytics technologies on modenx.com may also involve a "sale" or "share" as those terms are defined by California law — see our Cookie Policy.
15. Changes to this policy
We may update this policy. Material changes will be notified by updating the "Last updated" date and, where appropriate, by email or by notice in the app or on the website before the change takes effect. We will not apply a materially different use of previously collected information without the consent the law requires.
16. Contact
ModenX Inc., 66 Ridgeview Drive, Basking Ridge, NJ 07920, United States
Privacy and rights requests: [email protected] · Web form: modenx.com/privacy-request
Security: [email protected] · Support: [email protected]
US-1 The laws that apply
The California Consumer Privacy Act as amended by the CPRA, and the comprehensive consumer privacy laws of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky, Rhode Island and Florida, as and where they apply; the Washington My Health My Data Act and the Nevada Consumer Health Data Privacy Law; COPPA; and applicable state biometric-privacy and breach-notification laws.
Some of these laws apply only above certain thresholds, and most of them exclude information about individuals acting in a commercial or employment capacity. We provide the rights described below to all US individuals regardless of whether a given law requires it in their state. The CCPA has no business-to-business exemption, so a California resident's work contact details are covered by it.
US-2 Notice at collection
The categories in §3 correspond to these CCPA categories of personal information: identifiers; commercial information; internet or other electronic network activity information; geolocation data; professional or employment-related information; audio or visual information (photos a user uploads); and inferences drawn to create a profile about preferences and behaviour.
We collect one category of sensitive personal information: precise geolocation (see §5), and we use it to derive an inference — your Presora score — which is why the right to limit at US-4 genuinely applies. We do not collect biometric information, government identifiers, financial account information, racial or ethnic origin, religious beliefs, union membership, health information, sexual orientation, or the contents of private communications.
Sources, purposes, recipients and retention are as stated in §3, §4, §10 and §13. This notice is also provided at or before the point of collection.
US-3 Sale and sharing
See §14.
US-4 Sensitive personal information — your right to limit
We collect one category of sensitive personal information — precise geolocation — and we do use it to infer something about you: your Presora score. A score is a measure of your presence across participating venues, derived from where and how often you show up. We say so plainly because that inference is exactly what the right to limit exists for.
You may direct us to limit the use and disclosure of your sensitive personal information to the purposes the CCPA permits without a right to limit — providing the services you asked for, security, and fraud prevention. Three ways:
- the "Limit the Use of My Sensitive Personal Information" link in the footer of every page;
- [email protected] or modenx.com/privacy-request;
- in the Presora app, by turning off score sharing, deleting your account, or revoking the location permission in your device settings.
Exercising this right stops us using your location to calculate or update a score. We will not discriminate against you for it, though a Presora score is the app's core function, so limiting it means the app can no longer provide that feature.
US-5 Your rights
Depending on where you live, you have the right to:
- Know and access — the categories and specific pieces of personal information we hold about you, the sources, the purposes, and the categories of recipients;
- Delete — subject to the exceptions the law allows;
- Correct — inaccurate personal information;
- Portability — receive a copy in a portable, readily usable format;
- Opt out of sale or sharing for cross-context behavioural advertising;
- Opt out of targeted advertising and of profiling in furtherance of decisions producing legal or similarly significant effects;
- Limit the use and disclosure of sensitive personal information (see US-4);
- Withdraw consent where we relied on consent, as easily as it was given;
- Non-discrimination — we will not deny you service, charge a different price, or provide a different quality of service because you exercised a right.
US-6 How to exercise your rights
Two methods, as required: email [email protected], or use the web form at modenx.com/privacy-request. Consumer app users can also use the in-app controls.
We acknowledge a request within 10 business days and respond within 45 days, extendable once by a further 45 days where reasonably necessary, with notice to you.
We verify your identity before acting on a request, proportionately to its sensitivity — usually by confirming control of the account email or phone number, and for requests for specific pieces of information, by requiring you to be signed in. If we cannot verify you we will tell you why.
Authorised agents may submit a request on your behalf with your written permission; we may ask the agent for proof of authorisation and ask you to confirm it directly.
Exercising your rights is free. We may charge or decline where a request is manifestly unfounded or excessive, and we will explain why.
US-7 If we deny your request — appeals
If we decline your request in whole or in part, we will tell you why in writing and explain how to appeal.
To appeal, reply to our decision or write to [email protected] with "Appeal" in the subject line. A person who was not involved in the original decision will review it. We will respond within 45 days of receiving the appeal, with a written explanation of the reasons. If we deny the appeal, we will provide you with a method to contact your state attorney general to submit a complaint.
US-8 Visitors, not customers
If you visited a store or mall and want your information accessed, corrected or deleted, contact that business — they decide how it is used and modenX acts only on their instructions. Contact us and we will identify the right business where we can, and we will help them respond.
US-9 Children
The modenX platform is a business product and is not directed to children. The Presora consumer app is not directed to children under 13 — see §8.
US-10 California-specific
- Shine the Light (Civ. Code § 1798.83). California residents may request the categories of personal information disclosed to third parties for their direct-marketing purposes. modenX does not make such disclosures.
- Notice of financial incentive. Where a Client offers a loyalty benefit through modenX, that Client — not modenX — is responsible for any financial-incentive notice its programme requires.
- CCPA metrics. modenX does not handle the personal information of 10 million or more California residents in a calendar year and therefore does not publish request metrics.
- Data broker. modenX is not a data broker and is not required to register with the California Privacy Protection Agency.
US-11 Nevada, Washington and other health-data states
See §9.
US-12 Do Not Track
We respond to the Global Privacy Control (see §14). There is no consensus industry standard for "Do Not Track" browser headers, and we do not respond to them separately.
India
This section applies if your business, or the location you visited, is in India. ModenX India Private Limited is the responsible entity.
1. Who we are
ModenX India Private Limited (CIN U46512TN2024PTC167731), a company incorporated under the Companies Act, 2013, with its registered office at No. 182/129, 2nd Floor, Othavadai Street, Kodambakkam, Chennai – 600024, Tamil Nadu ("modenX", "we", "us"), is the entity responsible for the personal data described in this policy.
Under the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 (together, the "DPDP Act"), modenX is:
- the Data Fiduciary for the personal data of our own customers, their administrators, our website visitors and users of the Presora consumer app — including the calculation of Presora scores from visit activity across participating venues, which is our own product and our own purpose (see §6.5); and
- a Data Processor for personal data about visitors to our customers' locations to the extent we process it to provide analytics and recognition to those customers, on their instructions only.
The same visit event can fall under both roles, and we describe both rather than only the second.
Contact: [email protected] (Data Protection Officer) · [email protected] (Grievance Officer).
modenX Inc. (Delaware, USA) is an affiliate and is responsible for personal data of customers in the United States under a separate US policy.
2. Two roles — please read, it changes who you go to
If you are our customer, or administer a customer account. We decide how that data is used. We are the Data Fiduciary and this policy applies to you directly.
If you visited a store or mall that uses modenX — two roles, please read both.
As the venue's Data Processor. For the analytics, recognition and reporting we produce for that venue, the venue is the Data Fiduciary and modenX acts only on its documented instructions under a Data Processing Addendum. We do not use that data for our own purposes in this role. To access, correct or erase that data, or withdraw consent, contact that business. Contact us at [email protected] and we will help identify it and assist it in responding.
As a Data Fiduciary in our own right, for Presora. If you hold a Presora account and have consented in the app, your visits to participating venues also contribute to your Presora score. Presora is our own product, so for that use we determine the purpose and we are the Data Fiduciary, relying on the consent you give us in the app. For anything to do with your score, come to us directly — [email protected] or the in-app controls. §6.5 explains this in full.
If you use the Presora consumer app. We are the Data Fiduciary. See §6 and §9.
3. What personal data we collect — itemised
From customer businesses and their administrators: Business name; contact person's name; work email address; work phone number; billing address; GSTIN; PAN where required for tax; plan selected; payment-method references and tokens from our payment provider; e-mandate reference; and a record of the consent given at signup.
Authentication: Login identifiers and tokens, via Auth0 (web) and Firebase Authentication (mobile).
Usage and device: Log data; IP address; device and browser identifiers; pages viewed; referring URLs; actions taken in the platform; approximate location derived from IP address.
Communications: Contact forms, support tickets, grievance correspondence.
Visit and presence signals — processed for customers, not for us: Arrival and departure events; dwell and movement signals derived from Bluetooth Low Energy (BLE), Wi-Fi and other sensors deployed at a customer's location; check-in and checkout events; transaction values; loyalty identifiers. These become personal data when they are linked to an individual who has identified themselves — see §5 and §7.
Presora consumer app: See §9.
We do not collect Aadhaar numbers, PAN of individuals other than where tax law requires it, bank account numbers, full payment card numbers, CVV, UPI PINs, health data, caste, religion, or any biometric identifier (see §7).
4. Why we use it, and on what basis
| Purpose | Basis under the DPDP Act |
|---|---|
| Providing, operating and securing the platform for a customer | Performance of our contract with the customer; data voluntarily provided for that purpose |
| Authenticating users | Same |
| Processing payments, e-mandates, renewals, refunds, GST and invoicing | Consent given at signup; compliance with tax and RBI requirements |
| Generating the analytics and recommendations customers subscribe to | Instructions of the customer as Data Fiduciary |
| Service, security, billing and renewal notices | Performance of contract; legal obligation |
| Answering support requests and grievances | Data voluntarily provided for that purpose |
| Detecting and preventing fraud, abuse and security incidents | Legitimate use permitted under section 7 of the DPDP Act; compliance with the CERT-In Directions |
| Meeting legal, tax, accounting and regulatory obligations | Legal obligation |
| Presora consumer app features | Your consent, given in the app |
| Calculating your Presora score from your visits to participating venues | Your consent, given in the Presora app on a standalone itemised notice; withdrawable at any time |
| Disclosing your score and tier to a venue you have permitted | Your consent and your permission, given in the Presora app and withdrawable at any time |
We do not sell personal data. We do not use one customer's data to serve another, except as aggregated, de-identified benchmarks that cannot reasonably be linked back to a customer or an individual. We do not use personal data to make automated decisions that have a legal or similarly significant effect on an individual.
Note on the absence of "legitimate interests." The DPDP Act does not contain a general legitimate-interests basis. Where consent is required, we obtain it by clear affirmative action on a standalone notice, and you may withdraw it at any time as easily as you gave it.
5. Location and presence data
modenX's core function is detecting that a device, or a guest who has identified themselves, is present at a customer's location. Because that is easy to misunderstand, we state plainly what happens:
- Aggregate footfall counting — counting devices without linking them to an identified person — produces statistics, not personal data about you.
- Recognition happens only when a guest has provided an identifier themselves (see §7). At that point the visit data becomes personal data and the DPDP Act applies to it in full.
- The customer, not modenX, is the Data Fiduciary for that data. The customer is responsible for giving you the standalone itemised notice the DPDP Rules require and, where consent is the basis, for obtaining it by clear affirmative action. Our contract with every customer requires this of them, and requires that consent be free and unconditional — a venue must not make entry or service conditional on consent that is not necessary for it.
- How presence data is used. For the venue, to provide the analytics and recognition it subscribes to. Separately, if you hold a Presora account and have consented, your visits across participating venues are used to calculate your Presora score — see §6.5. We do not use presence data for advertising and we do not sell it.
- We do not use presence data to infer your health condition, caste, religion, sexual orientation, disability status or political affiliation, and our customer contract prohibits customers from asking us to.
- We do not target or profile children. See §9.
6. Presora
Presora is a consumer product operated by modenX or a modenX affiliate. It is a separate product with its own account, terms and privacy notice, and using it is entirely voluntary.
6.3 The score is calculated by Presora from that individual's own Presora activity. The methodology is proprietary and patent-pending and is not disclosed in this or any other modenX document.
6.5 What your Presora score is built from
Your score is built from showing up. When you visit a participating venue and are recognised — because you check in, scan a QR code, or a store associate looks you up at your request — that visit contributes to your Presora score. Visits across different brands and venues all contribute. That is the point of the score: it reflects your presence across the participating network, not your activity at any single shop.
Only if you have a Presora account and have consented. If you do not use Presora, no score is calculated for you, and your visit data is handled only for the venue you visited, on that venue's instructions. For the calculation of your score, modenX is the Data Fiduciary and the basis is the consent you give us in the app, on a standalone itemised notice that names this use.
7. Cameras, sensors and biometric data
modenX does not use facial recognition, and does not create, collect, store or use facial geometry, face templates, voiceprints, fingerprints, iris or retina scans, or any other biometric identifier. We have verified this against the platform's source code.
We recognise a returning guest only by an identifier they have chosen to provide — a phone number, an email address, a loyalty identifier, a scan of a venue QR code, a check-in in the app, or a lookup performed by a store associate at the guest's request.
Where a customer operates cameras at its own locations, those cameras and any footage are the customer's, governed by the customer's own policies and signage. modenX does not receive, process or store images or video from them.
A profile photo an app user chooses to upload is stored as an image supplied by that user. It is not converted into a face template and is not used to identify anyone.
8. Payments
Card, UPI and account details are collected and processed by Razorpay under PCI-DSS. modenX never receives full card numbers, CVV or UPI credentials. We store Razorpay's customer, subscription, mandate and transaction references, the amounts and dates of charges, and invoice records.
No subscription fee is taken during the 90-day free trial. Registering the e-mandate the Reserve Bank of India's rules require may involve a small verification debit that is reversed automatically. Your card issuer will notify you at least 24 hours before each recurring debit and again after it. The full mechanics are in §7 of the Subscription Terms.
9. The Presora consumer app
This section applies to individuals who install and use the Presora consumer mobile app. For app users, modenX is the Data Fiduciary.
What the app collects
- Account and profile: name, email address, phone number, and any profile photo you add.
- Location, including precise and background location: to detect when you enter a participating mall and personalise your in-store experience.
- Bluetooth and proximity: signals from in-mall beacons, for location context.
- Camera and photos: images you capture or upload to scan QR codes, submit receipts, or set a profile photo.
- Activity and loyalty: visit history, offers viewed or redeemed, loyalty identifiers, transaction data.
- Device and push: device identifiers, app version, push notification tokens.
Permissions and consent
Each permission is requested in context, with a plain-language explanation of what it is used for, and each is optional. You may grant or revoke any of them in your device settings at any time. Revoking a permission may limit features but will not close your account.
| Permission | Why |
|---|---|
| Location, including background | Detect nearby and participating malls; deliver location-relevant offers |
| Bluetooth | Detect in-mall beacons for location context |
| Camera | Scan QR codes; capture receipts |
| Photos | Upload receipts and a profile photo |
| Notifications | Send offers, alerts and account updates |
We ask for your consent by clear affirmative action, on a standalone itemised notice, before collecting precise or background location. Nothing is pre-ticked. You can withdraw consent at any time in the app or in your device settings, as easily as you gave it, and we will stop the corresponding processing and erase the data unless we are required by law to keep it.
Children — India's rules are stricter than most
The Presora app is for individuals aged 18 and over. Under section 9 of the DPDP Act, a child is anyone under 18. For a child's personal data, modenX must obtain verifiable parental consent, and the Act prohibits tracking, behavioural monitoring of children, and targeted advertising directed at children — outright, and regardless of whether a parent consents.
Parents and guardians may contact [email protected] at any time.
Deleting your account
You can delete your account in the app: Profile (YOU) → Delete Account. If you cannot reach the app, email [email protected] with your details.
We permanently erase your profile and account data, location history, uploaded photos and receipts, and loyalty and activity data. Some data may be retained for a limited period where required for legal, tax, accounting or fraud-prevention purposes, or where the CERT-In Directions require logs to be kept, after which it is securely erased. Deletion requests are actioned within 30 days.
10. Who we share personal data with
| Category of recipient | Examples | Purpose |
|---|---|---|
| Cloud infrastructure | Microsoft Azure (India) | Hosting, storage, compute |
| Payment processing | Razorpay | Payments, e-mandates, refunds, fraud checks |
| Identity and authentication | Auth0, Firebase Authentication | Login and account security |
| Communications | email, SMS and push notification providers | Service, billing and statutory notices |
| Analytics and product telemetry | see the Cookie Policy | Understanding and improving use of the platform |
| Affiliates | modenX Inc. (USA) | Group functions, under written contract |
| Professional advisers | chartered accountants, auditors, lawyers | Advice, audit, statutory compliance |
| The relevant customer | — | Visitor data we process on that customer's behalf |
| Acquirers | — | In an amalgamation, acquisition or sale of assets, with notice |
| Government authorities | CERT-In, the Data Protection Board of India, tax and law-enforcement authorities | Where required by law |
Every processor and sub-processor is engaged under a written contract requiring compliance with the security safeguards Rule 6 of the DPDP Rules prescribes. A current list of sub-processors is available from [email protected].
We do not sell personal data and we do not disclose it to data brokers.
11. Where personal data is stored, and transfers outside India
Personal data covered by this policy is stored and processed on Microsoft Azure infrastructure in India.
Logs of our information and communication technology systems are maintained within Indian jurisdiction for at least 180 days, as the CERT-In Directions require.
Where personal data is transferred outside India — for example for group functions or support by our US affiliate — we do so under written contract and appropriate safeguards, and only to countries not restricted by the Central Government under section 16 of the DPDP Act. We will not transfer personal data to a restricted jurisdiction, and we monitor any notification the Central Government issues on this.
12. Security and personal data breaches
Safeguards
We maintain reasonable security safeguards consistent with Rule 6 of the DPDP Rules, 2025 and section 43A of the Information Technology Act, 2000: encryption in transit and at rest; masking or obfuscation where appropriate; least-privilege role-based access control; network segregation; logging, monitoring and alerting; retention of processing logs for at least one year; vulnerability management; personnel confidentiality obligations and training; written contracts imposing equivalent measures on our processors; and periodic review of controls. Our ICT system clocks are synchronised to the NIC or NPL network time protocol servers.
If a breach happens
There is no harm threshold under the DPDP Rules — every personal data breach is notifiable. On becoming aware of one we will:
- report to CERT-In within six hours of becoming aware, where the incident is reportable under the CERT-In Directions, 2022;
- intimate affected Data Principals without delay, in plain language, describing the breach, the nature and extent of the data involved, the likely consequences, the measures we are taking, what you can do to protect yourself, and how to contact us;
- report to the Data Protection Board of India without delay, and provide the detailed report within 72 hours — covering the events, circumstances and reasons leading to the breach, the mitigation measures taken, remedial measures to prevent recurrence, and the intimations given to affected Data Principals; and
- assist any affected customer in meeting its own obligations as Data Fiduciary.
Report a suspected vulnerability or incident to [email protected].
13. Retention and erasure
We keep personal data only as long as it is needed for the purpose it was collected for, and erase it when that purpose is no longer being served — including where you withdraw consent.
| Data | Retention |
|---|---|
| Customer account and profile data | Life of the account, then 90 days, then erased |
| Visitor and presence data processed for a customer | As that customer instructs under the Data Processing Addendum; erased or returned on termination |
| Presora app account data | Until you delete your account, then erased within 30 days, subject to legal holds |
| Billing, invoice, GST and TDS records | As tax and company law require |
| Consent, subscription and cancellation records | At least 3 years, or 1 year after the subscription ends, whichever is longer |
| Processing logs and records under the DPDP Rules | At least 1 year |
| ICT system logs under the CERT-In Directions | At least 180 days, within India |
| Website and product analytics | Up to 26 months |
| Grievance and support correspondence | 3 years from closure |
Advance notice before erasure. Where the DPDP Rules require us to erase personal data because a retention period has expired or you have not engaged with the service, we will give you at least 48 hours' notice before erasing it, so that you can log in or ask us to keep it if you still want the account.
Where a legal hold, investigation, grievance or proceeding requires it, we retain the affected data until it is resolved.
14. Your rights and how to exercise them
As a Data Principal under the DPDP Act, you have the right to:
- Access — a summary of the personal data we hold about you, the processing activities we have undertaken, and the identities of other Data Fiduciaries and Data Processors with whom we have shared it, and what was shared;
- Correction, completion and updating of inaccurate or incomplete personal data;
- Erasure of personal data, unless retention is required for a specified purpose or by law;
- Withdraw consent at any time, as easily as you gave it — after which we stop the processing that relied on it, and erase the data unless law requires otherwise;
- Nominate another individual to exercise your rights on your death or incapacity;
- Grievance redressal — see §15.
How to exercise them. Email [email protected], or use the form at modenx.com/privacy-request. App users can also use the in-app controls, including Delete Account. Please tell us which right you are exercising and give us enough information to identify you; we verify identity proportionately before acting, and will explain if we cannot.
We respond within 30 days. Exercising your rights is free.
If you visited a store or mall, direct your request to that business — it is the Data Fiduciary (see §2). Contact us and we will help identify it.
Your duties. The DPDP Act also places duties on Data Principals, including not impersonating another person, not suppressing material information, and not filing false or frivolous grievances.
15. Grievances
Grievance Officer email: [email protected]
Address: No. 182/129, 2nd Floor, Othavadai Street, Kodambakkam, Chennai – 600024, Tamil Nadu
Acknowledged within 48 hours, resolved within one month of receipt.
Data Protection Officer: [email protected] — for questions about the processing of personal data.
If your grievance is not resolved, you may complain to the Data Protection Board of India. You may also have remedies under the Consumer Protection Act, 2019 and the Information Technology Act, 2000.
16. Consent Managers
The DPDP Act provides for Consent Managers — registered intermediaries through which you can give, manage, review and withdraw consent across Data Fiduciaries. Registration of Consent Managers with the Data Protection Board opens on 13 November 2026. We will accept and honour consent given or withdrawn through a registered Consent Manager once that framework is operational, and we will update this section when we do.
17. This policy is not the consent notice
The DPDP Rules require that, where we rely on your consent, we give you a separate, standalone, itemised notice — independent of this policy and of our Terms — stating the specific personal data being collected, the specific purposes, and direct links to withdraw consent, exercise your rights and complain. That notice is presented at the point of collection, is available in English and, on request, in any language listed in the Eighth Schedule to the Constitution, and is what your consent attaches to. Accepting our Terms is not, by itself, your consent under the DPDP Act.
18. Cookies
See our Cookie Policy for the cookies, pixels, SDKs and similar technologies used on modenx.com, what each does, and how to control them. Non-essential cookies are set only with your consent.
19. Significant Data Fiduciary status
The Central Government may notify a Data Fiduciary as a Significant Data Fiduciary based on the volume and sensitivity of the personal data it processes and the risks involved. modenX has not been so notified. If we are, we will appoint a Data Protection Officer based in India who reports to our board, conduct annual data protection impact assessments and independent audits, and comply with the additional obligations that follow, and we will update this policy.
20. Changes to this policy
We may update this policy. Material changes will be notified by updating the "Last updated" date and, where appropriate, by email or by notice in the app or on the website before the change takes effect. Where a change means we need a different consent from you, we will ask for it rather than assume it.
21. Contact
ModenX India Private Limited (CIN U46512TN2024PTC167731)
No. 182/129, 2nd Floor, Othavadai Street, Kodambakkam, Chennai – 600024, Tamil Nadu
| Purpose | Contact |
|---|---|
| Privacy, rights requests, Data Protection Officer | [email protected] |
| Web form for rights requests | modenx.com/privacy-request |
| Grievance Officer | [email protected] |
| App support and account deletion | [email protected] |
| Security incidents | [email protected] |
| General support | [email protected] |