top of page

Privacy Policy & Data Rights

Elixiir Growth Services LLP | Last updated: May 2026

This policy applies to all Elixiir products: GrowOS, Wizard, wa.elixiir, and pay.elixiir

 

Protecting Your Data Is Not an Afterthought
 

At Elixiir Growth Services LLP, we build tools that help local businesses grow. In doing so, we handle personal data — of the businesses who use our products, and of the customers those businesses serve. We take that responsibility seriously.

This policy explains what data we collect, why we collect it, how we protect it, how long we keep it, and what rights you have over it — whether you are a business owner using our platform or a customer who has interacted with a business that uses Elixiir.

This policy is written in plain English. If you have any questions, email us at support@elixiir.in and a human will respond.

 

Who We Are
 

Elixiir Growth Services LLP is a technology company registered in India. We build a multi-product platform for Indian local businesses — salons, clinics, restaurants, jewellers, and other neighbourhood businesses — to manage their customer lifecycle across Google, WhatsApp, loyalty, and operations.

Our products are:

GrowOS — Customer loyalty, NFC-based touchpoints, POS, appointments, and staff management for local businesses.

Wizard — Google Business Profile intelligence, local SEO, AI content engine, and Growth Studio for social and Google posting.

wa.elixiir — WhatsApp Business governance platform for campaigns, commerce, inbox management, and compliance.

pay.elixiir — Subscription billing, wallet management, and payment processing for Elixiir platform subscriptions.

Registered address: Crossing Republic, Ghaziabad, Uttar Pradesh LLPIN: ACQ-6800 Contact: privacy@elixiir.in

 

Who This Policy Applies To

This policy covers two types of people:

Business users — owners, managers, and staff of local businesses who have signed up for any Elixiir product and use our platform to manage their business operations and customer communications.

End customers — individuals who are customers of a business that uses Elixiir products. You may have interacted with an Elixiir-powered touchpoint if you received a WhatsApp message from a local business, tapped an NFC card at a salon or clinic, received a loyalty reward, or were sent a Google review request.

If you are an end customer and want to know what data a specific business holds about you, you should contact that business directly. Elixiir acts as a data processor on behalf of that business for customer data — the business is the data fiduciary for their own customers under the DPDP Act, 2023.

 

What Data We Collect

From business users:

When you sign up for any Elixiir product, we collect your name, email address, mobile number, business name, business address, and GST number if applicable. We collect this to create and manage your account, process your subscription, and provide support.

When you use our products, we collect activity data — campaigns you create, templates you build, messages you send, loyalty programmes you run, Google posts you publish, and actions you take inside the platform. We collect this to deliver the service, generate reports, and improve our products.

When you connect payment methods or top up your wa.elixiir wallet, we collect transaction data. We do not store card numbers — payment processing is handled by Cashfree, our payment partner.

When you connect your WhatsApp Business Account via Meta Embedded Signup, Meta shares your WABA ID, phone number ID, and access token with us. We store the access token in encrypted form using AES-256-GCM encryption. We never log or expose this token in plain text.

When you connect your Google Business Profile via Wizard, Google shares profile access credentials with us. These are stored encrypted and used only to manage your Google presence on your behalf.

From end customers of businesses using Elixiir:

When a business uses GrowOS to manage customer loyalty, they may capture your name, mobile number, email address, date of birth, and visit history. This data is stored on your behalf by that business, with Elixiir acting as the technology platform.

When a business uses wa.elixiir to send you WhatsApp messages, we store your WhatsApp phone number, the delivery status of messages sent to you (sent, delivered, read, failed), your opt-out status if you have opted out, and any consent records if you provided consent through the platform.

When you tap an NFC card at a business using GrowOS, we record the tap event, the associated business location, and the time of the tap. This is used to trigger actions such as review requests or loyalty points.

We do not store the content of WhatsApp conversations beyond what is required for delivery reporting. We do not store payment card details for end customers. We do not build advertising profiles on end customers.

 

Why We Use Your Data

For business users, we use your data to provide the Elixiir platform services you have subscribed to, process your payments and manage your subscription, send you product updates and service communications, generate the reports and analytics shown in your dashboard, provide customer support, and comply with our legal obligations including GST filing and financial record keeping.

For end customers, data is used only on the instruction of the business you are a customer of. Common uses include sending you WhatsApp messages the business has authorised (campaigns, reminders, offers, booking confirmations), tracking whether those messages were delivered and read, managing your loyalty points and rewards, and recording your consent and opt-out preferences.

We do not use your data to serve you advertisements. We do not sell your data to any third party. We do not use your data for any purpose beyond what is described in this policy.

 

WhatsApp-Specific Data Practices

wa.elixiir is a Meta Business Partner application. When businesses use wa.elixiir to send WhatsApp messages, the following applies:

All WhatsApp messages are sent through Meta's official WhatsApp Cloud API. We are not a third-party bulk SMS provider — we use Meta's direct API, which means all messages comply with WhatsApp's Business Messaging Policy.

Every number that receives a WhatsApp message through wa.elixiir must have either opted in to receive messages from that business, or have an existing business relationship with them. We enforce opt-out requests immediately — any customer who replies STOP to a message is added to the DND registry and will not receive further messages from that business through our platform.

We enforce TRAI regulations automatically — no marketing messages are sent between 10 PM and 8 AM IST, regardless of when a business schedules them.

We maintain a consent audit trail for every number in the system. This audit trail is available to businesses for compliance purposes and to regulators upon lawful request.

Meta's own privacy policy governs how Meta handles data transmitted through the WhatsApp Business API. You can read Meta's policy at facebook.com/privacy/policy.

 

Data Deletion — Facebook and Meta Login

wa.elixiir uses Facebook Login and Meta Embedded Signup to allow businesses to connect their WhatsApp Business Accounts. In compliance with Meta's Platform Terms, we provide a data deletion mechanism for any data associated with this login.

To request deletion of data associated with your Facebook or Meta login on our platform, you can submit a request at:

https://elixiir.in/data-deletion

Or email support@elixiir.in with the subject line: META DATA DELETION REQUEST

Upon receiving a valid request, we will permanently delete your WhatsApp Business Account credentials from our servers, revoke and discard your access token, disconnect your account from the wa.elixiir platform, and schedule your campaign history and message logs for deletion within 30 days, except where retention is required by law.

You will receive a confirmation code to track the status of your deletion request.

 

Your Rights Under the DPDP Act, 2023

The Digital Personal Data Protection Act, 2023 gives you the following rights as a Data Principal. These rights apply to all personal data we hold about you across all Elixiir products.

Right to access information — You can request a summary of what personal data we hold about you, the purposes for which we are processing it, and who we have shared it with.

Right to correction and erasure — You can request that we correct inaccurate data or erase data that is no longer necessary for the purpose it was collected, subject to our legal retention obligations.

Right to grievance redressal — You can raise a complaint with our Data Protection Officer and receive a substantive response within 30 days.

Right to nominate — You can nominate another person to exercise your data rights on your behalf in the event of death or incapacity.

Right to withdraw consent — Where processing is based on your consent, you can withdraw it at any time. Withdrawal does not affect the legality of processing that occurred before withdrawal.

For end customers of businesses using Elixiir, please note that for data held by a business on your behalf — such as your loyalty history or contact details — you should raise your request directly with that business. We will assist the business in responding to your request where technically required.

 

How to Exercise Your Rights

To opt out of WhatsApp messages — Reply STOP to any WhatsApp message you receive from a business using wa.elixiir. Your number will be added to that business's DND list immediately and no further messages will be sent.

To request access, correction, or deletion of your data — Email support@elixiir.in with your full name, your registered email address or mobile number, the Elixiir product your request relates to, and a description of the action you are requesting. We will acknowledge within 48 hours and complete the action within 30 days.

To raise a grievance — Email support@elixiir.in with the subject line PRIVACY GRIEVANCE. If you are not satisfied with our response, you have the right to escalate to the Data Protection Board of India once constituted under the DPDP Act, 2023.

 

How We Protect Your Data

All data is transmitted over HTTPS using TLS 1.2 or higher. WhatsApp Business Account access tokens are stored encrypted using AES-256-GCM. Google Business Profile credentials are stored encrypted. Passwords are hashed using bcrypt and never stored in plain text. Access to personal data within our team is restricted on a need-to-know basis. We do not grant any third party access to your data except as described in the section below.

We conduct regular internal security reviews. If we become aware of a data breach that affects your personal data, we will notify you within 72 hours of becoming aware of it, as required under the DPDP Act.

 

Who We Share Data With

We share data only with the following categories of third parties, and only to the extent necessary to deliver our services:

Meta Platforms — when you use wa.elixiir, message data is transmitted through Meta's WhatsApp Cloud API. Meta's own privacy policy applies to data on their infrastructure.

Google — when you use Wizard, your Google Business Profile data is accessed via Google's APIs. Google's privacy policy applies to data on their infrastructure.

Cashfree — our payment processing partner for subscription billing and wallet top-ups. Cashfree is PCI-DSS compliant.

DigitalOcean — our cloud infrastructure provider. All data is stored on servers in the Mumbai or Bangalore region.

MSG91 — our OTP and SMS delivery partner for account verification.

We do not share data with data brokers, advertisers, or analytics companies. We do not share data across our business customers — each business's data is fully isolated from other businesses on the platform.

 

How Long We Keep Your Data

Business account data is retained for as long as your account is active. If you close your account, we will delete your personal data within 30 days, except where we are required to retain it by law.

Message delivery logs are retained for 12 months. Campaign records are retained for 24 months. Billing and wallet transaction records are retained for 7 years as required by Indian financial regulations. Consent and opt-out records are retained for 5 years for DPDP compliance. Admin and audit logs are retained for 3 years. Google Business Profile access credentials are deleted when you disconnect your account.

 

Cookies and Tracking

Our web applications use essential cookies only — for session management and authentication. We do not use advertising cookies, tracking pixels, or third-party analytics that share data with advertisers. Our dashboard uses first-party analytics only to help us understand how our products are being used.

 

Changes to This Policy

We may update this policy when our data practices change or when law requires it. When we make material changes, we will notify all registered business users by email at least 14 days before the change takes effect. The date at the top of this page will always reflect when it was last updated. Continued use of any Elixiir product after notification constitutes acceptance of the updated policy.

 

Contact

For any privacy question, data request, or grievance:

Data Protection Officer Elixiir Growth Services LLP Email: support@elixiir.in Response time: 48 hours for acknowledgement, 30 days for resolution

Registered address: C-5, iNURTURE Incubation Foundation, ABES Engineering College, Ghaziabad, Uttar Pradesh, 201009, LLPIN: ACQ-6800


This policy satisfies the data deletion callback requirement under Meta Platform Terms Section 3.2, the data principal rights provisions of the Digital Personal Data Protection Act, 2023, and Google API Services User Data Policy requirements.

 

bottom of page