1. Scope and responsible organisation
MoolSocial is a product of SuperMandi Tech Pvt Ltd. This policy applies to MoolSocial websites, mobile applications and features that connect with other services and link to this policy. References to “MoolSocial”, “we”, “us” or “our” mean the MoolSocial product and its operator.
Questions about this policy or our privacy practices can be sent to hello@moolsocial.com.
2. Information we may collect
Account and profile information
- Name, contact details, language, location or service area, and account identifiers.
- Creator, worker, business or workspace details that you choose to provide.
- Authentication and session records needed to protect your account.
Activity, content and transaction information
- Actions you take in MoolSocial, saved preferences, support requests and consent records.
- Content, media or information you choose to create, upload or distribute.
- Commerce, booking, work, payment reference or payout records when those services are used.
Device and service information
- Device, app version, security, crash, performance, approximate network and fraud-prevention signals.
- Service responses, error codes and security logs that do not intentionally contain passwords or one-time passwords.
3. How we use information
We use information to:
- provide, secure and improve MoolSocial services;
- deliver the social, commerce, work and business features you choose;
- connect optional external accounts and perform only the actions you authorize;
- personalise content and service discovery within MoolSocial;
- prevent fraud, abuse, duplication and unauthorized access;
- provide support, notices and account controls;
- meet legal, accounting, compliance and dispute obligations; and
- develop and evaluate AI-assisted features with appropriate access controls and human accountability.
4. Connected services and API integrations
Payments
Payment gateways, aggregators, banks or payment networks may receive the amount, order or payout reference, transaction contact details and other information needed to authorize, settle, refund, reconcile or investigate a payment. MoolSocial may retain the provider reference, status, amount and reconciliation record, but does not store full card details, CVV, UPI PIN, banking password or one-time password.
Social, commerce and other services
Social or content services, commerce partners, maps, mobility, logistics, communications, identity and business APIs may receive only the account, content, order, location, delivery or service information needed to complete your request. Provider-specific terms or notices apply to information that a provider independently receives and processes.
Google and YouTube API Services
MoolSocial uses YouTube API Services only when you choose a YouTube feature. It may use public content metadata and, after Google authorization, the selected channel identity and data or actions included in the consent screen. We request only the permissions needed for the chosen feature, do not ask for your Google password, do not sell Google user data, and do not download or store YouTube audiovisual content for playback. Use is subject to the YouTube Terms of Service and Google Privacy Policy. Use and transfer of information received from Google APIs will follow the Google API Services User Data Policy, including applicable Limited Use requirements.
When the official YouTube player is shown, it sends basic device and usage information to YouTube to display and protect the player. Additional information may be sent when playback begins.
6. Retention, refresh and deletion
We retain information only for the period needed for the disclosed purpose, security, support, transactions or legal obligations. Provider data is refreshed or deleted within the periods required by the applicable service and purpose.
- YouTube API Data is generally refreshed or deleted within 30 calendar days unless policy permits longer retention, in which case continuing authorization and availability are rechecked at least every 30 days.
- When YouTube access is disconnected or revoked, the relevant token is revoked and associated Authorized Data is deleted as soon as possible and within 7 calendar days.
- Payment, order, refund, payout, tax, fraud and dispute records may be retained for the period needed for the transaction or required by law.
- A verified request to delete MoolSocial-stored user data is completed as soon as possible and within 7 calendar days, except limited records we are legally required to retain.
7. Your choices and controls
- Disconnect YouTube using our disconnect instructions.
- Revoke Google access directly from Google Security settings.
- Raise a payment, refund or transaction-data question through MoolSocial support.
- Request deletion through our account and data deletion page.
- Ask for access, correction or further information by emailing hello@moolsocial.com.
Deleting information stored by MoolSocial does not delete information independently held by a connected provider. Use that provider’s controls where required.
8. Security and children
We use technical and organisational safeguards designed to protect accounts, tokens, private data and sensitive operations. No system can guarantee absolute security, so we also use monitoring, restricted access and recovery controls.
MoolSocial services may apply age, consent and feature restrictions. Users must meet the age requirements in our Terms and any connected provider’s terms.
9. Updates and contact
We may update this policy as MoolSocial services or legal requirements change. The effective date above identifies the current version. Material changes will be communicated as required.
Privacy and connected-service data questions: hello@moolsocial.com.