Privacy Policy
How ICEMAN Yotta Private Limited collects, uses, stores and protects personal data, and how to exercise your rights under India’s Digital Personal Data Protection Act, 2023.
Who we are
ICEMAN Yotta Private Limited (“ICEMAN”, “we”, “us”) is a company incorporated in India under the Companies Act, 2013, CIN U62013KA2025PTC205693, with its registered office at #139/5, 1st Floor, 4th A Cross, Asheervad Colony, Horamavu, Bangalore 560043, Karnataka, India.
We operate the website theiceman.ai and the rental inventory and operations platform at app.theiceman.ai, together with the ICEMAN Crew mobile application (the “Service”).
This policy explains what personal data we handle, why, and what you can do about it. It is written to align with the Digital Personal Data Protection Act, 2023 (“DPDP Act”) and the Information Technology Act, 2000 and rules made under it.
Two different roles we play
This distinction matters, because it determines who you should contact about a given record.
For data about our own customers — the rental company that subscribes, its account holders, people who fill in a demo form or write to support. We decide why and how that data is processed, and this policy governs it.
For data you enter into the platform — your clients, your crew, your drivers, your freelancers. You decide what goes in and why; we only process it on your instructions to run the Service for you. Requests about that data should go to the rental company that holds the account, not to us.
What we collect
Data you give us directly
- Account and contact data — name, company name, work email, phone number, city, role, and the team-size band you select.
- Enquiry data — anything you type into the demo form, send by email, or send us on WhatsApp or by phone.
- Billing data — company name, billing address, GSTIN and PAN for invoicing. Card, UPI and netbanking details are captured by Razorpay on their own systems and are never stored on ours; if you pay by bank transfer we see only what appears on the remittance.
Data generated by using the Service
- Operational records you create — equipment, serials, quotations, orders, dispatches, scans, crew rosters, vehicle documents, ledger entries.
- Scan and device data — RFID and barcode reads with timestamps, gate and warehouse identifiers, reader identifiers and session pins.
- Technical logs — IP address, browser and device type, operating system, pages and actions, timestamps, and error traces. We keep these to run, secure and debug the Service.
- Location — the Crew app may use device location for venue directions and shift check-in, only with your permission, and it can be switched off in the operating system at any time.
What we do not collect
We do not collect biometric data, we do not buy personal data from brokers, and we do not run advertising or cross-site tracking on our website.
Why we use it
We use personal data only for these purposes:
- To provide, operate and maintain the Service, including syncing scans and generating documents.
- To authenticate users and apply role-based permissions.
- To raise invoices, collect fees and meet tax obligations.
- To respond to enquiries, provide support and send service notices about outages, maintenance and material changes.
- To monitor for abuse, investigate incidents and keep the Service secure.
- To produce aggregated, de-identified statistics that cannot be traced back to a person, for capacity planning and product decisions.
- To comply with law and to establish, exercise or defend legal claims.
We do not sell personal data. We do not share it with advertisers. We do not use your operational data to train machine-learning models for other customers.
The basis on which we process
Under the DPDP Act we process personal data either on the basis of your consent, given at the point you provide the data, or as a legitimate use permitted by the Act — for example where you have voluntarily provided data for a specified purpose, or where processing is necessary to comply with a legal obligation or a court order.
Where processing rests on consent, you may withdraw it at any time using the contact details in the Grievance and contact section. Withdrawing consent does not affect processing already carried out, and may mean we can no longer provide part or all of the Service.
Who we share it with
We share personal data only in these circumstances:
- Service providers (sub-processors) who help us run the Service, bound by contract to process data only on our instructions and to protect it. The current list is published on our Security page.
- Within your own organisation, according to the role-based permissions your administrator configures.
- Where the law requires it — a valid order from a court, or a lawful request from a government agency. We assess each request, and where we are permitted to do so we tell the affected customer before responding.
- In a business transfer — if the company is acquired or merges, data may transfer to the successor, who remains bound by this policy until it is lawfully replaced. We will give notice before this happens.
Where your data is stored
Personal data processed through the Service is stored on cloud infrastructure located in India (Amazon Web Services, Asia Pacific – Mumbai, ap-south-1). Backups are held in the same region.
One exception: mobile push notifications for the ICEMAN Crew app are delivered through Google Firebase Cloud Messaging, which operates globally. Only the device token and the notification payload — a call time, a venue, a shift change — pass through it. No inventory, financial or client records leave India.
Any such transfer is limited to what the tool needs, is covered by contractual protections, and is only made to countries not restricted by the Central Government under the DPDP Act.
How long we keep it
| Category | Retention |
|---|---|
| Account and operational data | For as long as the subscription is active |
| After termination or non-renewal | Kept for 90 days so you can export, then permanently deleted |
| Invoices and tax records | 8 years, as required by Indian tax law |
| Technical and security logs | Up to 12 months |
| Demo enquiries that do not convert | 24 months |
| Backups | Rolling window, overwritten within 35 days |
You can ask us to delete your data sooner. We will do so unless we are required by law to keep a record, in which case we will tell you which record and why.
Your rights
Subject to the DPDP Act, you have the right to:
- Access a summary of the personal data we process about you and the processing activities involved.
- Correction and completion of data that is inaccurate or incomplete, and erasure of data no longer needed for the purpose it was collected for.
- Grievance redressal — to complain to us first, and to escalate to the Data Protection Board of India if we do not resolve it.
- Nominate another person to exercise these rights on your behalf in the event of death or incapacity.
- Withdraw consent at any time, as described above.
Account holders can exercise most of these directly in the product: profile data is editable in settings, and a full export of inventory, customers, orders, invoices and scan history is available from inside the platform without raising a ticket. For anything else, write to us.
If you are a crew member, freelancer or client of a rental company that uses ICEMAN, your data was entered by that company. Please contact them first — we will assist them, but we cannot amend or delete their records on your instruction alone.
How we protect it
We use encryption in transit and at rest, role-based access control, audit logging of deletions, and encrypted daily backups. The full description is on our Security page.
No system is perfectly secure. If a personal data breach occurs we will notify the Data Protection Board of India and every affected person, in the manner and within the timelines the DPDP Act and its rules require.
Cookies
Our marketing website uses no advertising cookies, no analytics cookies and no third-party trackers. It loads fonts from Google Fonts, which receives the request as an ordinary web request.
The platform at app.theiceman.ai sets strictly necessary cookies to keep you signed in and to protect against cross-site request forgery. These cannot be turned off without breaking sign-in, and they are not used to profile you.
Children
The Service is a business tool and is not directed at children. We do not knowingly process the personal data of anyone under 18. If you believe a child’s data has been entered into the Service, tell us and we will remove it.
Changes to this policy
We may update this policy as the Service or the law changes. The revision date at the top always reflects the current version. If a change materially affects how we handle your personal data, we will give you notice by email or in the product before it takes effect.
Grievance and contact
- Name
- Prabhakar M S
- info@theiceman.in
- Phone
- +91 99457 44882
- Post
- ICEMAN Yotta Private Limited, #139/5, 1st Floor, 4th A Cross, Asheervad Colony, Horamavu, Bangalore 560043, Karnataka, India
We acknowledge every grievance within 72 hours and aim to resolve it within 30 days. If you are not satisfied with our response, you may complain to the Data Protection Board of India.
Something unclear?
If any part of this page is ambiguous or you need it in a different form for a procurement review, ask us. A plain answer is faster than a legal argument.