Privacy Policy
Stepwhere Mobile App Privacy Policy
Effective date: 25 August 2026
Data controller: Seven96 Step Solution Pvt. Ltd.
1. Introduction and scope
Seven96 Step Solution Pvt. Ltd. ("Stepwhere", "we", "us", or "our") provides a mobile companion service for parents and legal guardians who use Stepwhere GPS-enabled children's shoes. This Privacy Policy explains what personal data we collect through the Stepwhere mobile app and its related backend services, why we use it, when it may be disclosed, how long we retain it, and the choices available to users. This policy applies to the Stepwhere mobile app and app-specific account, support, privacy, and deletion pages. It does not apply to the Stepwhere ecommerce storefront, which is governed by a separate storefront privacy policy.
The current Stepwhere mobile service is intended for users in India. We process personal data in accordance with privacy laws applicable to our operations and users. Additional rights may apply depending on a person's location.
2. Who may use Stepwhere
The Stepwhere parent application is intended for adults, parents, and legal guardians. Children do not create Stepwhere accounts or directly sign in to the parent application. An adult creates and manages each child profile and links it to a Stepwhere shoe.
By creating or managing a child profile, the adult represents that they are the child's parent or legal guardian, or that they otherwise have lawful authority to provide the child's information and use Stepwhere for that child. Stepwhere must not be used to monitor a spouse, employee, unrelated adult, or any person whom the account holder does not have lawful authority to monitor.
3. Information we collect
Depending on the features used, we may collect the following categories of personal data.
3.1 Parent or guardian information
Name, mobile number, email address, and date of birth.
Postal address and family-account details.
Profile photograph, when provided.
Google account identifier and verification status when Google verification is used.
Account preferences and communication settings.
3.2 Child-profile information
Name and date of birth.
Gender and school information, when provided.
Profile photograph.
Relationship to the parent, guardian, or other family members.
3.3 Shoe, activity, and service information
Shoe hardware identifier, device association, activation status, connectivity status, and battery information.
Step count, activity duration, activity history, goals, and estimated calorie information.
Safe-zone settings, alert preferences, and related service events.
Information used to create, expire, or revoke a guardian-initiated live-sharing link.
3.4 Technical, authentication, and security information
User, installation, session, and push-notification identifiers.
IP address, user-agent information, authentication records, verification records, and security events.
Operational logs, error information, and diagnostic information needed to operate, secure, and troubleshoot the service.
3.5 Communications
We collect information that a user provides in support requests, feedback, privacy requests, account-deletion requests, and other communications with us.
4. Location Data
We do not store a child's location data. It is used only in real time to provide live tracking, activity, route, and related service features.
Location is used only in real time to support app features (e.g. mapping a walk) and is never saved on our servers or shared. At all times, parents must grant permission for location access, and they can revoke it at any time in device settings. We explain the purpose of location use in the app’s permission prompt. By design, we treat location data as ephemeral (transient); after each use it is discarded.
5. How we use information
We use personal data only where we have consent or another lawful basis and for purposes such as:
Creating, authenticating, verifying, maintaining, and securing user accounts.
Creating and managing family and child profiles.
Linking and operating Stepwhere shoes.
Showing activity, history, safe-zone information, alerts, and device status.
Sending authentication messages, service notifications, safety alerts, and push notifications.
Creating and managing time-limited live-sharing links requested by a guardian.
Personalizing account settings and providing requested features.
Responding to support, privacy, and deletion requests.
Preventing fraud, misuse, unauthorized access, and security incidents.
Diagnosing failures and maintaining or improving the reliability of the service.
Complying with legal obligations, resolving disputes, and enforcing our agreements.
We do not sell personal data. We do not use child data or precise location for behavioural advertising, and we do not permit advertisers to profile children through Stepwhere.
6. Guardian responsibility and children's privacy
Parents and legal guardians create and manage child profiles. The adult providing a child's information is responsible for ensuring that they have the authority to do so and that the information is accurate.
A parent or guardian may ask to access, correct, or delete a child's personal data by using available in-app controls or contacting us. We may ask the requester to verify their identity, account ownership, or authority concerning the child before acting on the request.
If we learn that a child profile was created without appropriate adult authority, we may restrict the account and delete the affected information, subject to any information we must retain by law.
7. Service providers and disclosure
We use service providers to operate Stepwhere. Depending on the deployed configuration and features used, these may include:
Supabase and PostgreSQL-based services for authentication, accounts, and application data.
Amazon Web Services for storing uploaded profile images and related infrastructure services.
Google identity services for account verification.
Google Maps, Places, geocoding, and route-related services for map and place functionality.
Twilio or another active messaging provider for authentication or service messages.
Expo Push Notification services and Firebase Cloud Messaging for push notifications.
Hosting, network, security, monitoring, and operational service providers.
These providers may process data only to provide their contracted services to us and are required to protect it appropriately.
When a guardian creates a live-sharing link, the information made available through that link is disclosed to people chosen by the guardian. Anyone who receives or is forwarded the link may be able to view the shared information until the link expires or is revoked. Guardians should share such links only with trusted recipients.
We may also disclose information when required by law, legal process, or a lawful government request, or when reasonably necessary to protect a person, investigate misuse, secure the service, or establish, exercise, or defend legal claims. If our business is reorganized, merged, financed, or transferred, information may be disclosed as part of that transaction subject to applicable law and appropriate safeguards.
We do not share personal data with advertisers or social networks for their independent advertising purposes.
8. Data retention and deletion
We retain personal data only for as long as reasonably necessary to maintain an account, provide the requested service, satisfy legal obligations, resolve disputes, prevent fraud or abuse, and enforce our agreements. Retention periods may differ by data category and operational or legal requirement. When data is no longer required, we delete or de-identify it unless continued retention is required or permitted by law.
8.1 Account deletion
An authenticated user may initiate account deletion from the app under Profile → Delete account. The user must confirm the request using a one-time verification code.
When deletion is scheduled:
Account access and applicable tracking are stopped.
The user has 72 hours to cancel the deletion by signing in again.
After that undo period, permanent deletion begins and can no longer be cancelled.
We aim to complete deletion within 30 days, subject to legal retention requirements and the time needed to remove information from active systems and service providers.
If the requester is the only family administrator, deleting the account may delete the family, associated child profiles, tracking information, uploaded images, sharing records, push information, and other family data. If other family members remain, the requester's account and personal information are deleted while shared family and child information may remain under the continuing family administration. Administrative responsibility may be transferred to a remaining eligible family member.
Limited non-identifying records of the deletion request may be retained for security, auditing, fraud prevention, dispute resolution, or legal compliance.
A user may also start an account-deletion request through Stepwhere's public account-deletion webpage.
8.2 Child profiles
Removing a child profile through the app may archive the profile and unlink its shoe rather than immediately erase every associated record. A parent or legal guardian who wants permanent erasure of a child's associated personal data should contact us using the details below. We will verify the request and delete applicable information unless retention is legally required.
9. Data security
We use reasonable administrative, technical, and organizational safeguards designed to protect personal data. Supported network transmissions are protected using SSL/TLS encryption, and access to data is restricted according to role and operational need. We also use authentication, access controls, and security monitoring appropriate to the service.
No storage or transmission method is completely secure, and we cannot guarantee absolute security. If you believe that an account or personal data has been accessed without authorization, contact us promptly.
10. User rights and choices
Subject to applicable law, a parent, guardian, or account holder may ask us to:
Confirm whether we process their personal data.
Provide access to or a copy of applicable personal data.
Correct inaccurate or incomplete information.
Withdraw consent where processing relies on consent.
Delete an account or applicable child information.
Address a privacy grievance or complaint.
Recognize an eligible nominee who may exercise applicable rights on the user's behalf.
Users may update certain information and communication choices inside the app. Device-level notification or permission settings may also be changed through the device settings.
We may need to verify the requester's identity, account ownership, or guardian authority. We may decline or limit a request where permitted or required by law and will explain the reason when applicable.
To exercise a privacy right, email ceo@stepwhere.in. We will respond within the period required by applicable law.
11. Changes to this policy
We may update this Privacy Policy to reflect changes to the service, our practices, providers, or legal obligations. We will update the effective date and make the revised policy available on our website. For material changes, we will provide notice through the app, email, or another appropriate channel and request fresh consent where required by law.
12. Contact and grievances
Questions, privacy requests, deletion requests, and grievances may be directed to:
Seven96 Step Solution Pvt. Ltd.
17, Jethiyo Ka Akhada
Outside Chandpole, Ambamata
Udaipur, Rajasthan 313001
India
Email: ceo@stepwhere.in
Telephone: +91 8560909555
We may request information needed to verify the identity and authority of a person submitting a request. We will acknowledge and respond to privacy inquiries and grievances in accordance with applicable law.