Relationship Infrastructure — Aarnoaa (OPC) Private Limited

Privacy Policy

Effective date: 1 April 2026  ·  Aarnoaa (OPC) Private Limited

1. Who we are

BHASM is a product of Aarnoaa (OPC) Private Limited, a One Person Company incorporated under the Companies Act 2013, registered in India. Registered office: Gurgaon, Haryana 122001, India. CIN: U73100HR2025OPC137642. For all privacy matters, write to hello@bhasm.ai.

2. What data we collect and why

Account data: Name, email address, password (hashed, never stored in plain text), business name, city, industry, and market. This is used to create and manage the account and to calibrate the intelligence correctly from day one.

Customer relationship data: Transaction records, purchase history, contact identifiers (name, phone, email), and behavioural signals uploaded by the business. This data is used exclusively to generate retention intelligence — briefs, urgency scores, and suggested messages — for that specific business. It is never shared, sold, or used for any other purpose.

Usage data: Terminal activity, feature usage, and brief generation events. Used to improve the product and to ensure system stability. Not used for advertising.

3. How data is stored and secured

Account and customer data is stored on Supabase-managed PostgreSQL databases hosted in the United States (US East, Northern Virginia), and the application servers that process it run in the same region. Personal data provided by a business in India, the European Union or elsewhere is therefore transferred to and processed in the United States. Storage is encrypted at rest with AES-256 — that is applied by the managed database platform to the underlying volumes and backups, and it covers every field. On top of that, contact identifiers are protected at the application layer: email addresses and phone numbers are tokenised the moment they arrive, and where a raw value is retained at all it is encrypted field by field with AES-256-GCM under a key derived separately for each business, so one business's key cannot decrypt another's. Remaining customer fields, such as a customer's name, sit in ordinary database columns — covered by the storage-layer encryption and by per-business row access rules, not by field-level encryption. Traffic is encrypted in transit with TLS. Passwords are stored as a strong one-way hash — never in plain text, and never transmitted in logs. Access is restricted to service processes only. No human at Aarnoaa accesses individual customer records except in the event of a support request from the registered business.

3a. Indian data law — DPDP Act 2023

BHASM's data processing is designed for compliance with India's Digital Personal Data Protection Act 2023. In this framework, the registered business is the Data Fiduciary — the entity that collected consent from its own customers and determines the purpose of processing. Aarnoaa (OPC) Private Limited is the Data Processor — processing data strictly on the Fiduciary's instructions to generate retention intelligence.

BHASM does not independently collect data from end customers. It processes only data the business provides through connected sources (Shopify, GA4, Razorpay, etc.) or manual upload. The business remains responsible for having obtained valid consent from its own customers under applicable law before connecting those data sources to BHASM.

This notice in another language. Section 5(3) of the DPDP Act gives a Data Principal the right to receive this notice in English or in any of the 22 languages listed in the Eighth Schedule to the Constitution of India. This page is published in English. Write to hello@bhasm.ai naming the language you want and we will send you the notice in it. We do not machine-translate this page: a legal notice that is wrong in translation is worse than one you have to ask for, so each language is prepared and checked before it is sent.

3b. Data Processing Agreement

By creating an account and connecting data sources, the registered business enters into a Data Processing Agreement with Aarnoaa (OPC) Private Limited. The terms of this agreement are as follows: Aarnoaa will process personal data only for the purpose of generating retention intelligence for that business; will not share, sell, or use that data for any other purpose; will maintain appropriate technical and organisational security measures; and will delete or return all personal data on termination of the account. Businesses requiring a formal signed DPA document may request one by writing to hello@bhasm.ai. Access to production databases is restricted to essential personnel and is logged.

4. Data ownership

The business that uploads customer data retains full ownership of that data at all times. Aarnoaa (OPC) Private Limited acts as a data processor, not a data controller, in relation to customer relationship records. The business is responsible for ensuring it has appropriate authority to submit this data and that affected individuals have been informed in accordance with applicable law.

5. Data retention and deletion

Account data is retained for the duration of the account and for 90 days after closure to facilitate potential reactivation. Customer relationship data is retained for the duration of the account. All data is permanently deleted within 30 days of a verified deletion request. To request deletion, write to hello@bhasm.ai with the subject line "Data Deletion Request".

6. Third-party services

BHASM uses the following third-party processors: Supabase (database infrastructure), Railway (backend hosting), and Resend (transactional email delivery). Each processes data solely to provide the service to BHASM and is bound by their respective data processing agreements. No customer relationship data is shared with these parties beyond what is necessary for infrastructure operation.

7. No advertising. No data sales.

BHASM products carry no advertising. Aarnoaa (OPC) Private Limited does not sell, license, or otherwise commercialise account or customer data to any third party, under any circumstances.

8. Rights of data subjects

Individuals whose data has been uploaded to BHASM by a business have the right to request access, correction, or deletion of their data. Such requests should be directed to the business that holds the account; businesses are required to action such requests within 30 days. Aarnoaa (OPC) Private Limited will support businesses in fulfilling these obligations upon request.

8a. California residents — CCPA/CPRA

For personal information of California residents, the business holding the account acts as the "business" under the California Consumer Privacy Act (as amended by the CPRA) and Aarnoaa (OPC) Private Limited acts as its "service provider". Aarnoaa does not sell or share personal information as those terms are defined by the CCPA, and processes it solely to provide retention intelligence to the account holder. California residents may exercise rights of access, deletion, and correction through the business that holds the account; deletion requests are actioned end-to-end — BHASM's own records and every connected platform BHASM has written to — within 30 days.

8b. AI-generated content

Message drafts produced by BHASM are generated with the assistance of AI and are reviewed, editable, and stoppable by the account operator before any send, subject to the account's autonomy settings. Demo and sample messages shown in the product or on this site are AI-generated illustrations, not records of real customers.

9. Cookies and product usage

First-party cookies, and only if you accept them. We set four cookies on this domain, all first-party, none before you choose. bhasm_vid counts returning visits and which pages and campaigns bring people to this site, kept 180 days. bhasm_aid is the identifier used by our behavioural tag — the same tag accounts install on their own sites, running here on ours — kept 13 months. bhasm_consent holds the grant or refusal itself, kept 13 months. bhasm_optout is set only if you opt out, kept 13 months. Each stores a random value that refers to a browser, not to you: no name, no email, nothing that identifies you as a person, and nothing that can be connected to a customer record.

Nothing is written to your device until you choose. When you first arrive we ask, and no cookie and no identifier exists on your device before you answer. If you decline, none is set and we record only the fact that you declined, so that we do not ask again — honouring a refusal is the one thing we do without asking. Expiries are the ones listed above. bhasm_consent and bhasm_optout are mirrored to local storage so your choice survives a browser that rejects cookies. Two further values last only until the tab is closed: a session identifier for this site, and one for the tag.

You can withdraw at any time, as easily as you gave it. Declining later removes these cookies and stops the collection, on both paths; you do not need to contact us to do it. We keep a record of consent decisions — the choice, the time, and the version of this policy it was given against — because we are required to be able to demonstrate that consent was given, and because consent to an earlier version of this text should never carry over to a later one silently.

Google Tag Manager. If you accept, we also load Google Tag Manager to help us measure how this site is used. It is a Google service, so accepting means Google receives your visit and may set its own cookies. It does not load unless you accept. Nothing from Google runs on this site before you choose, and declining keeps it off entirely — we removed the fallback that used to load it for visitors without JavaScript, because a tag that cannot be refused is not consented to.

We set no advertising cookies of our own, and we place no advertising tag in that container. Your data is not sold and is not sent to any advertising network. We do not store your IP address alongside your visit activity, and our own analytics are served from our own domain.

Your signed-in session is not a cookie: it is held in your browser's local storage on your own device, alongside the mirrored consent flags described above, and is sent only when your browser makes a request to us.

Within the signed-in terminal we also record how the product itself is used — which screens are opened and which actions are taken — against your account, so we can see where the product is working and where it is not. This record contains no customer data, no message content, and no personal details; it is not shared with any third party and is not used to build a profile of you outside your account. It is generated only while you are signed in.

The same tag on an account's own website. Accounts may place this tag on the website they operate. There BHASM is the processor and the account holder is the controller: the notice that governs that visit is theirs, not this one. On this site we are the controller, and what the tag sets here is listed at the top of this section rather than in this paragraph. This paragraph states what the tag stores on an account's site, so it can be read and repeated by anyone who has to describe it.

The tag writes nothing until the site operator records a consent grant for that visitor. On a grant it stores, first-party and on that site's own domain: bhasm_aid, a random identifier for the browser, kept 13 months; bhasm_consent, the grant or refusal itself, kept 13 months; and bhasm_optout, set only if the visitor opts out, kept 13 months. Each is a cookie, mirrored to local storage so the choice survives a browser that rejects cookies. Two further values last only until the tab is closed: a session identifier, and an account-supplied reference where the site has identified the visitor to itself. Withdrawing consent erases the identifier and the pending activity in the same action.

The tag honours Global Privacy Control and Do Not Track as a refusal, without waiting to be asked, and mints no identifier while either is set. It records pages viewed, actions taken and the campaign a visit arrived from. It reads no other cookie on the page, no form field, and no page content.

10. Changes to this policy

Material changes to this policy will be communicated by email to all registered accounts at least 14 days before they take effect. Continued use of the service after the effective date constitutes acceptance of the revised policy.

11. Contact

For any privacy-related questions or requests: hello@bhasm.ai
Aarnoaa (OPC) Private Limited, India.