CoShot — operated by Axero Private Limited
Version: 4.0
Effective Date: 20 May 2026
This Privacy Policy is issued by Axero Private Limited ("Axero", "we", "us"), a company incorporated in India under the Companies Act, 2013, CIN U59201RJ2025PTC109427, with its registered office at Plot No. 46, Parihar Nagar, Bhadasiya, Jodhpur Mahamandir, Jodhpur 342006, Rajasthan, India.
It explains how we collect, use, share, store and delete personal data when you use:
Together these are the "Platform". Capitalised terms not defined here have the meaning given in the CoShot Terms & Conditions (the "Terms"). The two documents are meant to be read together and use the same definitions.
2.1 Law that governs this Policy now. We publish this Policy under Section 43A of the Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (the "SPDI Rules"), together with the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, the Consumer Protection (E-Commerce) Rules, 2020, the Aadhaar Act, 2016 and the regulations under it for offline verification, and the Reserve Bank of India's directions on the storage of payment-system data.
2.2 Transition to the DPDP regime. The Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 are being brought into force in phases. The obligations on notice, consent, data-principal rights, breach reporting and children's data are scheduled to commence on 13 May 2027. We have written this Policy to that standard now. Where this Policy describes a right or a mechanism that rests on a DPDP provision, that right is available to you from the date the provision commences; until then you can make the same request to our Grievance Officer, and we will act on it under this Policy as a matter of contract.
2.3 Other regimes. If you use the Platform from the European Economic Area, the United Kingdom or California, Sections 14.3 and 14.4 set out the additional rights you have. We do not target those markets and do not process EEA or UK data at a scale that requires a local representative.
Name, email address, mobile number verified by OTP, date of birth (to confirm you are 18 or over), an optional profile photograph, optional gender, language preference, and your password, which we store only as a bcrypt hash. Purpose: to create and secure your account and to communicate with you. Basis: your consent at registration and the performance of our contract with you.
For Studio Owners: studio name, address, photographs, equipment list, pricing, availability, cancellation terms and house rules. For Influencers: portfolio links, niches, languages, rate card and portfolio photographs. For Brands: brand name, campaign briefs, deliverable specifications and reference imagery. Purpose: to publish listings and campaigns and match them to Users and Influencers. Basis: performance of contract.
Booking and campaign identifiers, amounts, taxes, invoices, refund and payout records, and — for Campaigns — the payment status and reference the Brand and Influencer record in the campaign panel. We never collect, store or see card numbers, CVVs, UPI PINs or net-banking credentials. Payments made to us are processed by the Payment Aggregator named in Section 4.4; we receive a tokenised reference and a signature that lets us verify the payment happened. Purpose: to run bookings and campaigns, issue invoices and comply with tax law. Basis: performance of contract and legal obligation (GST and income-tax law).
Studio bookings. The Booking amount is paid through Razorpay Software Private Limited, a payment aggregator authorised by the Reserve Bank of India (the "Payment Aggregator"). Axero receives the Booking amount, keeps it in a designated bank account separate from its operating funds, and pays the Studio Owner's share on the settlement schedule in the Terms. The Platform Fee is Axero's; the Studio Owner's share is held for the Studio Owner until it is paid.
Campaigns. The Brand pays the Influencer directly, to the Influencer's Verified bank account, on the dates set in the campaign agreement. Axero does not collect, hold or route that payment; the Brand pays Axero only the Platform Fee (and, where Section 194-O of the Income-tax Act, 1961 applies, the tax to be deducted at source, which Axero deposits and certifies) through the Payment Aggregator. We record in the campaign panel the payment status and reference that the Brand and Influencer report, so that disputes can be resolved.
All payment-system data handled by the Payment Aggregator stays in India, as the Reserve Bank of India requires.
In-app chat messages, Voice Messages, call metadata (participants, start and end time, duration, quality indicators — never call content), support tickets, dispute records, reviews and ratings, and OTPs and transactional notifications sent through WhatsApp and email. Purpose: to let you communicate with the other side of a booking or campaign, to support you, and to resolve disputes. Basis: performance of contract; consent for optional marketing messages.
Described fully in Section 9.
IP address, device model, operating-system and app version, crash logs, language and time zone, push-notification tokens, and an approximate city-level location derived from your IP address (this is separate from the Location Data in Section 8). Purpose: to operate, secure and improve the Platform. Basis: performance of contract; consent for non-essential analytics.
Strictly necessary cookies (session, security, load balancing) are always on. Functional and analytics cookies are off until you switch them on in the banner shown on your first visit. We do not use advertising or cross-site tracking cookies. You can change your choices at any time in the cookie preferences panel linked in the website footer. Non-essential cookies expire within 13 months.
We do not collect biometric data of any kind, health data, genetic data, sexual-orientation data, religious or political opinions, contacts, SMS, call logs, calendar data, or video files. The apps do not request or accept video uploads. We do not listen through your microphone or read your location except in the specific, user-initiated situations described in Sections 7 and 8, and we never do either in the background except for the single booking-reminder feature in Section 8.2.
Before a Studio Owner can be paid, before a Brand can publish a Campaign, and before an Influencer can be paid under one, we need to know that the person or business is who they say they are, that the bank account belongs to them, and — where they charge GST — that their GST registration is genuine. For Campaigns, a Verified bank account in the Influencer's own name is what lets a Brand pay the Influencer directly with confidence, and the Verified PAN is what lets us apply tax deduction at source correctly. Verification is therefore a condition of acting as a Partner; it is not required to browse or book as a User.
We use the Secure ID verification services of Cashfree Payments India Private Limited ("Cashfree"), a company incorporated in India and itself authorised by the Reserve Bank of India as a payment aggregator, as our Data Processor. Cashfree processes Verification Data in India, on our written instructions, and queries the authoritative government or banking source for each check. Cashfree does not use Verification Data for any purpose of its own.
| Check | What you provide | What the check returns | What Axero stores |
|---|---|---|---|
| PAN verification | Your PAN | Registered name from Income Tax records, PAN type (individual/business), status | PAN, registered name, status, date verified |
| Aadhaar via DigiLocker (required — see 5.4) | Nothing typed into CoShot; the Partner App opens Cashfree's DigiLocker service, you sign in to DigiLocker and share your Aadhaar record there | Name, date of birth, gender, address, photograph, and a masked Aadhaar number showing the last four digits only, returned to us by Cashfree | Name, date of birth, address, the last four digits, the Cashfree/DigiLocker reference identifier, and the result. We do not store the photograph and we never receive, store or see a full Aadhaar number. |
| Bank account verification | Account number and IFSC | Account-holder name as held by the bank and account status, obtained by a small test credit or a UPI-based check | Account number, IFSC, account-holder name, status, date verified |
| Name match | Nothing further | A similarity result comparing the name on your PAN, your bank account and, if used, your DigiLocker record | The match result only |
| GSTIN verification (Partners who charge GST) | Your GSTIN | Legal name, trade name, registration status, registration date and principal place of business from GST records | The returned details, date verified |
In the current version of the Partner App, identity verification is completed by sharing your Aadhaar record from DigiLocker through Cashfree's DigiLocker verification service, and a Partner cannot receive or make Campaign payments, or receive Booking settlements, until it is complete. The flow works like this: the Partner App opens a DigiLocker session provided by Cashfree; you sign in to DigiLocker with your own credentials; DigiLocker shows you a consent screen naming the document to be shared, and you may decline there; if you consent, DigiLocker releases the Aadhaar record to Cashfree, which returns to us the details listed in the table in 5.3 with the Aadhaar number masked to its last four digits. We act only as an offline-verification-seeking entity under the Aadhaar Act, 2016 and the Aadhaar (Authentication and Offline Verification) Regulations, 2021; Cashfree processes the record as our Data Processor and does not retain it for any purpose of its own; no full Aadhaar number is transmitted to or stored by us; and no biometric or OTP authentication against the UIDAI database is performed by us or on our behalf. You may revoke the consent you gave, and ask us to delete the resulting Verification Data, at any time under 5.5.
If you do not hold an Aadhaar number, or cannot use DigiLocker, write to the Grievance Officer under Section 20 and we will verify your identity instead from another government-issued photo identity document, checked by name match against your PAN and bank account. Declining Aadhaar does not affect your use of the Platform as a User; it affects only whether we can pay you as a Partner until an alternative verification is completed.
Each check is started by you, in the Partner App, after a screen that names the check, the data involved, and Cashfree as the processor. Your tap on "Verify" is your consent to that specific check. You may withdraw consent and ask us to delete Verification Data at any time by writing to the Grievance Officer. Withdrawal means you cannot act as a Partner until you re-verify; it does not affect payments already made or the retention of transaction records we must keep under tax law.
We keep Verification Data for the life of your Partner relationship plus three years, which is the limitation period for a claim relating to a payment, and then delete it. If verification fails or you abandon it, the data submitted for the failed or abandoned check is deleted within 30 days.
6.1 Scope. The apps request camera and photo-library access only when you start an action that needs a photograph — profile photo, studio listing photo, campaign deliverable, brand reference image, support or review attachment, or a photo sent in chat. Both the camera function and the gallery picker are limited to still images; video files cannot be selected or captured.
6.2 What we receive. Only the file you actively choose, with whatever metadata your device embedded in it. We do not scan, index or read any other photograph on your device.
6.3 Location metadata is stripped. GPS and other location fields are removed from every Uploaded Photograph at the point of upload, before the file is stored. The removed data is not logged or retained. The one exception is a studio listing photograph for which you have separately switched on the studio-map feature; there we store the coordinates you confirm, separately from the photograph, and the photograph itself is still stripped.
6.4 No facial or biometric processing. We do not run facial recognition, face matching, age estimation, emotion analysis or any other biometric processing on Uploaded Photographs, and we do not use them to train or evaluate any machine-learning model, our own or anyone else's.
6.5 Your responsibility for photographs of others. By uploading a photograph you confirm that every identifiable person in it has agreed to its use on the Platform, that you hold the rights to it, and that it does not depict a Child except your own child, uploaded by you as their parent or guardian for a lawful purpose.
6.6 Permissions. On iOS we request camera and read-only photo-library access and honour the "Selected Photos" choice. On Android 13 and above we request the images-only media permission and prefer the system photo picker; on Android 14 and above we honour partial access. Each system prompt is preceded by an in-app screen stating the purpose. Revoking the permission in your device settings stops future access; it does not delete photographs already uploaded, which you delete using the in-app control on the relevant screen or by writing to us.
6.7 Storage. Uploaded Photographs are stored in Amazon Web Services' Mumbai region, encrypted at rest, and retrieved only through short-lived, access-restricted links.
6.8 Camera during video calls. Your camera is also used, with a separate permission, during in-app video calls. That is Live Call Media: relayed in real time through our own infrastructure, never recorded or stored, and released the moment the call ends.
The apps use your microphone only to record a Voice Message you choose to send, or to carry your side of a voice or video call you choose to join. Voice Messages are stored as chat attachments for the period in Section 13. Live Call Media is never recorded, stored or transcribed; we log only call metadata. We do not extract voice-prints, and we do not use Voice Messages or call audio to train any model. The microphone permission is requested at first use of these features, never at launch, and can be revoked in your device settings; revocation stops the features going forward and does not delete Voice Messages already sent, which you can delete from the chat.
8.1 While you use the app. With your permission we use your location to show studios near you, sort results by distance, suggest a service area when you create a listing, give you directions to a booked studio, and confirm your check-in at a booked studio when you choose to.
8.2 In the background — one purpose only. With a separate "Always" permission, and only while you hold an active confirmed booking, we use your location to send a reminder and check-in instructions when your device is near the booked studio. We collect no background location at any other time. Before requesting this permission on Android we show a separate disclosure screen explaining exactly this use, that the data is not used for advertising or shared for it, and that it is deleted within seven days of the booking ending. You can decline it and keep every other feature.
8.3 Precision. You may grant approximate rather than precise location; the app then shows distances at city level rather than in metres and otherwise works normally. You can also downgrade precision at any time in Profile → Privacy → Location Precision.
8.4 What we never do with Location Data. We do not sell it, share it for advertising, supply it to data brokers or location-intelligence firms, build movement profiles, infer sensitive characteristics from where you go, or use it to train any model.
8.5 Storage and deletion. Location Data is stored in Amazon Web Services' Mumbai region, encrypted. Session location is cleared from the device within 24 hours and is not kept on our servers beyond the session unless you save a search area. Check-in coordinates form part of the booking record. Background location is deleted within seven days of the booking ending. You can delete historical Location Data at any time in Profile → Privacy → Delete My Location Data.
9.1 What we ask for. If you connect an Instagram Business or Creator account, we request only two Instagram Graph API permissions: instagram_basic and instagram_manage_insights. We never request permission to publish content, read or send direct messages, or manage comments.
9.2 Why. So that a Brand can see that you control the handle you claim and can rely on first-party audience metrics rather than screenshots. That is the entire purpose.
9.3 What we cache. Username, account ID, profile-picture link, account type and media count; up to your 50 most recent posts (identifier, caption, type, link, thumbnail, timestamp, like and comment counts); account-level insights over a rolling 30-day window; and insights for the cached posts. We refresh insights on demand or at most once every 24 hours.
9.4 Tokens. The access token Meta issues is encrypted at rest with keys held in a hardware-backed key-management service, is never written to logs, never sent to a device in plaintext, and never shared with anyone.
9.5 Public Instagram information used for campaign Discovery. When a Brand has published a verified Campaign, we may identify potential Influencers using information that is publicly visible on Instagram — public username, follower count, public posts and bio — obtained only through means Meta permits. We do not scrape Instagram, send automated bulk messages, or access anything non-public without your connected-account consent. Personal data you have yourself made public is outside the DPDP Act; we still use it only for this purpose.
9.6 Disconnecting. Open the Partner App → Profile → Personal Details → Instagram → Delete Instagram Connection. This revokes our token with Meta and immediately removes the token, cached profile and posts, and cached insights from our live systems; backup copies are overwritten within 35 days. You can also remove CoShot from Instagram itself (Settings → Apps and Websites → Active → CoShot → Remove), which triggers a deauthorisation message to us that starts the same deletion; or email contact@coshot.com and we will complete it within seven days. Disconnecting does not delete your CoShot account or your campaign, billing or support history.
9.7 No other use. Instagram-derived data is used only for the campaign features described here. It is never sold, licensed, used for advertising or model training, or combined into any audience product.
| Activity | Basis now (SPDI Rules / Contract Act) | Basis from DPDP commencement |
|---|---|---|
| Account creation, login, security | Consent; contract | Consent (s. 6); performance of contract (s. 7(a)) |
| Listings, search, ranking, matching | Contract | s. 7(a) |
| Bookings, campaigns, payments, invoicing | Contract; legal obligation (GST, income tax) | s. 7(a); s. 7(b) |
| Partner verification via Cashfree (Section 5) | Consent to each check; contract; tax law (verified PAN for deduction at source) | Consent (s. 6); s. 7(a); s. 7(b) |
| Pre-publication review of Campaigns | Intermediary Rules due diligence; contract | s. 7(a); s. 7(b) |
| Instagram-connected analytics | Consent | s. 6 |
| Camera, microphone, location features | Consent at the system prompt; contract | s. 6; s. 7(a) |
| Support, disputes, grievance redress | Contract; legal obligation | s. 7(a); s. 7(b) |
| Fraud prevention, security, abuse investigation | Legitimate business need; legal obligation | s. 7(b); s. 7(g) |
| Marketing messages | Opt-in consent, revocable | s. 6 |
| Non-essential analytics | Opt-in consent | s. 6 |
| Breach notification, regulatory reporting, legal claims | Legal obligation | s. 7(b); s. 7(g) |
You may withdraw any consent as easily as you gave it — by the in-app toggle, by revoking the device permission, or by writing to contact@coshot.com — without affecting processing that happened before withdrawal.
11.1 Other users, to the extent the transaction needs it. A Studio Owner sees a User's name and contact details only after a booking is confirmed. A Brand sees an Influencer's profile, public handle and — only with the Influencer's consent — connected analytics. A User sees a Studio Owner's listing, business name, area and photographs. Photographs uploaded to a public listing, profile, review or campaign deliverable are visible to other users for that purpose.
11.2 Within a Campaign. Communication between a Brand and an Influencer for a verified Campaign runs through the Platform's campaign panel, in which Axero has visibility for dispute resolution, fraud prevention and audit. The Brand's identity is shown to the Influencer in every message Axero relays on the Brand's behalf.
11.3 Processors, each limited to its role.
| Processor | Role | Data | Where |
|---|---|---|---|
| Amazon Web Services (Mumbai) | Hosting, storage, databases, key management | All operational data, Uploaded Photographs, Voice Messages, Location Data, Verification Data | India |
| Razorpay Software Private Limited | Payment Aggregator: processing of Booking payments, Platform Fees and refunds | Payment-instrument data (we do not see it) | India |
| Cashfree Payments India Private Limited | Partner verification (Section 5) | Verification Data | India |
| Setu (WhatsApp Business API) | OTPs and transactional WhatsApp messages | Mobile number, message text | India |
| Zoho Corporation (ZeptoMail) | Transactional email | Email address, message | India |
| Meta Platforms (Instagram Graph API) | Source of Instagram data on your authorisation | Token, public profile, insights | Meta's infrastructure |
| Apple and Google | Push notifications | Device token, notification text (never photographs, Voice Messages, Location Data or Verification Data) | Global |
We do not share Uploaded Photographs, Voice Messages, Live Call Media, Location Data or Verification Data with any image-recognition, voice-recognition, advertising, analytics or machine-learning provider. If we ever propose to, we will update this Policy first and ask for your consent before anything is shared.
11.4 Others. The scheduled commercial bank that holds the designated account described in Section 4.4; our auditors, lawyers and accountants under confidentiality; law-enforcement agencies, regulators, courts and the Data Protection Board of India when a valid legal process requires it (we review every request for validity and scope and, where the law allows, tell you); and a buyer or successor in a merger or sale of the business, under confidentiality and with notice to you where practicable.
11.5 What we never do. We do not sell personal data, share it for cross-context behavioural advertising, or give it to data brokers.
12.1 India by default. The Platform, including its chat, Voice Message and call services, is hosted in Amazon Web Services' Mumbai region. Uploaded Photographs, chat text, Voice Messages, Location Data, Verification Data and payment-system data are stored only in India.
12.2 Limited transfers. Push notifications pass through Apple's and Google's global infrastructure, carrying only the notification text. Instagram data is retrieved from Meta's infrastructure when you connect. No other personal data leaves India. When the DPDP Act's cross-border provisions commence, we will not transfer personal data to any country the Central Government has restricted.
| Data | Kept until |
|---|---|
| Account data | Account deletion, then erased within 30 days from live systems and 35 days from backups |
| Accounts inactive for 3 years | Deleted after 48 hours' notice to the registered email |
| Verification Data (Section 5) | End of the Partner relationship + 3 years; failed/abandoned checks deleted within 30 days |
| Transaction records and invoices | 8 financial years (Companies Act, 2013, s. 128) and at least 72 months from the due date of the relevant annual return (CGST Act, 2017, s. 36), whichever is longer |
| Content we remove for breaching the rules | 180 days minimum (Intermediary Rules) |
| Grievance records | 3 years |
| Security and access logs | At least 1 year |
| Instagram token | Until you disconnect, or after 60 days without use |
| Cached Instagram data | Deleted on disconnect (live systems immediately; backups within 35 days) |
| Profile, listing, portfolio and campaign photographs | Until you delete them or your account; then 30/35 days — except photographs that form part of a completed booking, campaign, dispute or review, which follow the transaction-record period above |
| Chat photographs and Voice Messages | Duration of the chat thread + 90 days, or until you delete the message, then 30/35 days |
| Live Call Media | Never stored |
| Call metadata | 12 months |
| Session Location Data | Cleared from the device within 24 hours; not stored on our servers beyond the session |
| Check-in coordinates | With the booking record, per the transaction-record period |
| Background Location Data | Active booking + 7 days, then 30/35 days |
| Marketing-consent data | Until you withdraw consent + 30 days |
| Non-essential cookies | Up to 13 months |
After a period ends we erase the data or anonymise it so that it can no longer reasonably identify you.
14.1 Rights you can exercise now, under this Policy and the SPDI Rules. To review the personal data we hold about you and have it corrected; to withdraw any consent you have given; to have your account and personal data deleted subject to Section 13; to export your Uploaded Photographs and profile data in a machine-readable form; and to have a grievance heard by our Grievance Officer.
14.2 Rights from the DPDP commencement date. The rights of access, correction, completion, updating and erasure under Sections 11 and 12 of the DPDP Act; grievance redress under Section 13; the right to nominate another person to exercise your rights if you die or become incapacitated; and the right to withdraw consent under Section 6(4). We will honour requests framed under these sections from the date they commence, and treat them as requests under 14.1 until then.
14.3 EEA and UK users additionally have the rights of rectification, erasure, restriction, portability and objection, and the right not to be subject to a purely automated decision with legal or similarly significant effect, and may complain to their national supervisory authority.
14.4 California residents additionally have the rights to know, delete, correct, opt out of sale or sharing, limit the use of sensitive personal information (including precise location), and not be discriminated against for exercising them. We do not sell or share personal information and have not done so in the preceding 12 months.
14.5 Specific controls. Delete any Uploaded Photograph or Voice Message from the screen where it appears; delete all your photographs or all your Voice Messages by request; downgrade or revoke location precision; delete historical Location Data; switch booking reminders off without losing anything else; disconnect Instagram (Section 9.6); withdraw verification consent (Section 5.5).
14.6 How to exercise a right. Write to contact@coshot.com with the subject "Privacy Request", or use Profile → Privacy → My Data Requests in either app. We verify identity by OTP to your registered mobile or email and respond within 30 days.
14.7 If you are not satisfied. You may approach the Adjudicating Officer appointed under Section 46 of the Information Technology Act, 2000; a Consumer Commission under the Consumer Protection Act, 2019; and, from the commencement of the relevant provisions, the Data Protection Board of India.
We use automated processes to rank studios and campaign matches, to flag suspicious payments and reviews, and to recommend content. None produces a decision with legal or similarly significant effect on you without a person reviewing it: verification rejection, account suspension, payout holds and content removal that affects your account are each confirmed by a human. We do not run biometric matching, voice-print extraction or location-based profiling. To ask for human review of any automated outcome, write to contact@coshot.com; we respond within seven business days.
We protect personal data with controls modelled on ISO/IEC 27001 practice: TLS 1.2 or higher for all data in transit; AES-256 encryption at rest for Verification Data, Instagram tokens, Uploaded Photographs, Voice Messages and Location Data, with keys in a managed key-management service; bcrypt password hashing at a work factor of 12 or more; cryptographic verification of every Payment Aggregator and Cashfree webhook; short-lived access tokens with rotating refresh tokens and revocation on suspicious activity; strict browser security headers; role-based, least-privilege access with quarterly access reviews; tamper-evident audit logging retained for at least one year; independent vulnerability assessment and penetration testing at least annually; and tested, encrypted backups. No system is perfectly secure; if you suspect a compromise, write to contact@coshot.com immediately.
We report cyber-security incidents to CERT-In within six hours of noticing them, as the CERT-In Directions of 28 April 2022 require, and inform the Payment Aggregator and any affected bank under our agreements with them. We tell affected users without delay, in plain language: what happened, which data is involved, the likely consequences, what we have done, what you can do, and whom to contact. From the commencement of Rule 7 of the DPDP Rules, we will additionally intimate the Data Protection Board of India without delay and file the detailed report within 72 hours of becoming aware of the breach.
The Platform is for adults. We do not knowingly collect personal data from a Child. If we learn that a Child has registered, or that a photograph on the Platform depicts a Child in breach of Section 6.5, we suspend the account, erase the Child's data including photographs unless the law requires us to keep it, do not track or profile the Child, and — where the material may indicate an offence under the Protection of Children from Sexual Offences Act, 2012 — report it to the National Cyber Crime Reporting Portal and preserve the records the law requires. From the commencement of Rule 10 of the DPDP Rules we will process a Child's data only with verifiable parental consent obtained as that Rule prescribes. Write to contact@coshot.com if you believe a Child's data is on the Platform.
From the date Consent Manager registration opens under Rule 4 of the DPDP Rules, we will integrate with at least one registered Consent Manager so that you can manage your consents to CoShot from a single interface.
Appointed under Rule 5(9) of the SPDI Rules, Rule 3(2) of the Intermediary Rules and Rule 4(4) of the E-Commerce Rules:
Name: A designated officer of Axero Private Limited
Address: Plot No. 46, Parihar Nagar, Bhadasiya, Jodhpur Mahamandir, Jodhpur 342006, Rajasthan, India
Email: contact@coshot.com
Hours: Monday–Friday, 10:00–18:00 IST (excluding public holidays in Rajasthan)
We acknowledge every complaint within 48 hours and resolve it within one month of receipt; content-related complaints follow the shorter timelines in the Terms. We may in future operate the separate addresses grievance@coshot.com and privacy@coshot.com; their activation will be reflected on this page without further amendment to this Policy.
Non-material changes — corrections, updated processor names, address changes — are made by updating the version and date at the top. Material changes — a new category of data, a new purpose, a new recipient, a new transfer, or a change to retention or your rights — take effect only after we show an in-app notice, email registered users at least 30 days in advance, and obtain your fresh click-to-accept on your next sign-in. You then have 60 days to review, accept, or close your account with a full export of your data.
This Policy is governed by the laws of India. Disputes follow the dispute-resolution provisions of the Terms — internal grievance, then mediation, then arbitration seated in Jodhpur — without prejudice to your right to approach a Consumer Commission under the Consumer Protection Act, 2019, which no provision of this Policy limits.
Axero Private Limited
Plot No. 46, Parihar Nagar, Bhadasiya, Jodhpur Mahamandir, Jodhpur 342006, Rajasthan, India
Email: contact@coshot.com
Website: https://www.coshot.com