Legal
Privacy Policy
This policy explains what personal data IraOra Solutions Private Limited collects through wheelops.in and the WheelOps application, how we use it, who we share it with, and the rights and choices you have. It also describes how we handle information processed through the WhatsApp Business Platform.
Effective date 30 July 2026 · Last updated 30 July 2026
1. Who we are
WheelOps is a tyre shop and workshop management platform operated by IraOra Solutions Private Limited, a company incorporated in India with its registered office at 1st Floor, Enkay Tower, Vanijya Nikunj, Udyog Vihar Phase V, Gurgaon, Haryana 122016, India. In this policy, "we", "us" and "WheelOps" refer to IraOra Solutions Private Limited.
This policy covers the website wheelops.in, the WheelOps application at app.wheelops.in, and our use of the WhatsApp Business Platform. For any privacy question, contact privacy@wheelops.in.
2. Who this policy covers
This policy applies to:
- Visitors to wheelops.in, including people who request a demo or contact us.
- Businesses that hold a WheelOps account, and the owners and staff who sign in to it.
- Authorised representatives of a business who arrange for a WhatsApp Business Account to be used with WheelOps.
- Customers of those businesses whose details are stored in WheelOps, including people who receive WhatsApp messages sent through the platform. These people may never deal with us directly, but their names, phone numbers and vehicle details are processed on our systems on behalf of the business they deal with.
3. Our role: Data Fiduciary and Data Processor
For information we collect to run our own business, IraOra Solutions Private Limited decides the purpose and means of processing and acts as the Data Fiduciary. This applies to website enquiries, account registration and administration, billing, support, security and legal compliance.
For the business data a customer stores in WheelOps, including customer records, vehicles, invoices, job cards and WhatsApp messages sent on the customer's instructions, the customer business is the Data Fiduciary and we act as its Data Processor. We process that data only to provide the service and on the customer's instructions, except for limited processing we carry out in our own right for security, fraud prevention and legal compliance.
In this policy, "you" means the Data Principal: the individual the personal data relates to.
4. The basis on which we process personal data
- Your consent. Demo and contact enquiries, and any marketing messages we send you about WheelOps. You can withdraw this consent at any time (see section 11).
- Performance of our agreement with a business. Creating and running the account a business has signed up for, including storing its records and sending the messages it configures.
- Legal obligation. Invoices, GST and other tax records, and responding to lawful requests from authorities.
- Our legitimate interest in a service that works and is not abused. Security, fraud prevention, audit logging and diagnosing faults.
5. Information we collect
When you request a demo or contact us.Your name, business name, mobile number, city, business type, number of branches and anything you type into the message field. Our systems also record your IP address, browser user agent, the page you submitted from, the referring site, and any search terms or campaign parameters in that page's address.
When a business creates an account. The names, email addresses, phone numbers and roles of the people the business adds as users, along with hashed passwords, sign-in history and security logs.
When a business uses the application. The business data entered into WheelOps: customer names, mobile numbers, email addresses, addresses, birthdays and notes; vehicle registration numbers and details; service records, job cards, invoices and GST details; stock and supplier records; and photos uploaded to service records. This data belongs to the business. We do not sell it and we do not use it to build advertising profiles.
Where a business uses our Tally integration.A small agent installed on the business's own computer reads its Tally data and sends invoice information to WheelOps. No third party receives that data.
Technical and diagnostic information. Server logs, and first-party diagnostic events from the application that record which page was affected, an error type and code, a browser-family label, a random device and page identifier, and, where you were signed in, which WheelOps account the event belongs to. These events are deliberately restricted to a fixed set of technical fields: no free text, no error message or stack trace, no query values, no form values and no customer or message content can enter them. They stay on our own servers and are deleted after 90 days.
6. Sensitive personal data
The only category of sensitive personal data we collect by design is the password used to sign in, which is stored as a one-way hash. We do not ask for financial account details, payment card numbers, health information or biometric information. Subscription payments are made by bank transfer or UPI directly to us; no card details are collected or stored by WheelOps.
Free-text fields such as notes or messages may incidentally contain information a business or its customer chooses to include. We treat that content as part of the business's data, process it only to provide the service, and protect it with the security measures described below.
7. Information we process through Meta and WhatsApp
WheelOps sends WhatsApp messages through Meta's WhatsApp Business Platform (Cloud API). Today, messages are sent either from a shared WheelOps business number that we operate, or from a business's own WhatsApp Business Account where that business has asked us to set it up and its authorised representative has supplied the necessary permissions to our team.
We are building support for Meta's Embedded Signup so that a business will be able to connect its own WhatsApp Business Account itself, without our team in the middle. This policy describes how we will handle the information that flow provides. Until Embedded Signup is available in WheelOps, we do not receive any information through it.
Where a business's own WhatsApp Business Account is connected, we hold:
- The WhatsApp Business Account ID and the phone number ID.
- The access token needed to send messages on the business's behalf. Tokens are stored encrypted and are never shown to another business.
- The name, language and variable structure of the message templates configured for that account.
When an administrator configures templates, we also read the list of approved templates on the connected account, including each template's name, language, category and approval status. That list is used to populate a selection screen and is not stored; only the name, language and variable structure of the template actually selected is saved.
For every message sent through the platform, we record:
- The recipient's phone number and name, taken from the business's own customer records in WheelOps, not from Meta.
- The text of the outbound message as it was sent.
- The message ID assigned by Meta, timestamps, and sent, delivered, read or failed statuses received from Meta, including any error codes.
About replies.A number used with the Cloud API is served by a webhook rather than by the WhatsApp Business app, so replies from a business's customers are delivered to our webhook endpoint. Our webhook reads delivery-status events only. Inbound message content is discarded without being read, stored, logged or displayed to anyone. WheelOps does not provide an inbox, so a business that needs to hold conversations with its customers should use a separate number or Meta's own tools.
8. Meta permissions our application uses
Our Meta app requests the following permissions. They apply only to WhatsApp Business Accounts that a business has authorised us to use:
whatsapp_business_management
This permission allows WheelOps to read the business profile and the message templates of the connected WhatsApp Business Account, so that the correct approved template can be selected for each type of message and its variables filled in correctly. Once Embedded Signup is available, it is also what allows a business to complete the connection and have its number registered for sending.
whatsapp_business_messaging
This permission allows WheelOps to send WhatsApp messages from the connected phone number and to receive message delivery information. We use it to send the service reminders, confirmations and broadcasts the business has configured, and to record delivery statuses against the message log the business sees in WheelOps.
Information available through these permissions is used only to provide the messaging features described in this policy. It is not used for advertising, is not sold, and is never shared with another business on the platform.
9. How we use information
- To respond to demo requests and enquiries, and to contact you about them.
- To create and administer accounts and authenticate users.
- To connect and operate the WhatsApp Business Accounts a business authorises.
- To send the WhatsApp messages a business has configured: service reminders, service completion confirmations, birthday wishes and broadcasts composed by the business.
- To record message delivery statuses and show the business its send log.
- To prevent duplicate or runaway messaging, through idempotency records and daily and monthly sending limits.
- To provide support, investigate faults and keep audit logs.
- To understand which pages and search terms bring us enquiries, using what you submit with the form together with anonymous, cookieless usage statistics described in section 23.
- To invoice for the service and keep the records tax law requires.
- To secure the platform and investigate fraud or abuse.
- To comply with applicable law and enforce our terms.
We do not sell personal data and we do not share it with advertisers.
10. Consent and WhatsApp opt-in
Two different authorisations are involved in WhatsApp messaging, and they are not the same thing.
The business's authorisation to us.An authorised representative of the business asks us to send messages from the shared WheelOps number, or authorises the use of the business's own WhatsApp Business Account. This authorises WheelOps to send messages on the business's behalf.
The recipient's opt-in to the business.That authorisation does not by itself permit the business to message every phone number. The business remains responsible for having a lawful basis and an appropriate WhatsApp opt-in before messaging a customer, for complying with WhatsApp's Business Messaging Policy and applicable law, and for honouring a customer who asks it to stop. A business can pause its automated reminders at any time in its messaging settings and controls which customers are included in any broadcast.
11. Withdrawing consent
Where we rely on your consent, you can withdraw it by writing to privacy@wheelops.in. We will stop the processing that depended on it, and delete the enquiry record if you ask us to. Withdrawing consent does not affect processing that already happened, and some features cannot work without the data they depend on. Where the law requires us to keep a record, such as a tax invoice, we keep that record.
12. Who we share information with
We share personal data only with the service providers needed to run WheelOps, and only for the purposes described here:
- Meta Platforms(WhatsApp Business Platform), to deliver WhatsApp messages. Meta receives the recipient's phone number and the message content for each send.
- MSG91, where a business uses SMS delivery instead of WhatsApp.
- Resend, to deliver transactional emails such as account and billing emails.
- Cloudflare, which sits in front of our servers for network security, DNS and content delivery.
These providers process data on our instructions under their own contractual and security commitments. We may also disclose information to professional advisers under confidentiality, to authorities where the law requires it (see section 24), and to a buyer or successor if our business is transferred, in which case this policy continues to apply to the transferred data.
13. International data transfers
WheelOps is operated from India, and personal data may be stored and processed both in India and in other countries. The providers listed above operate globally: Meta and Cloudflare may process data outside India when delivering messages and network services, and Resend processes email in the United States.
Where personal data is processed outside India, we do so only where the recipient is bound by contract to protect it to at least the standard set out in this policy, and only to the extent the service needs. If you want to know where your data is hosted at a given time, write to privacy@wheelops.in and we will tell you.
14. How long we keep information
- Demo and contact enquiries: we aim to delete enquiry records within 24 months of your last contact with us, and will delete an individual enquiry sooner on request.
- Account and business data:for as long as the account is open. When an account is closed we delete the business's data on request, subject to records we must keep by law.
- WhatsApp message logs (outbound message text, recipient and delivery status): for as long as the account is open, unless the business asks us to delete them earlier.
- Access tokens and WhatsApp account identifiers: until the integration is disconnected, at which point we delete the stored token.
- Diagnostic events: 90 days, after which they are deleted automatically.
- Invoices, billing and tax records: for the period required by applicable Indian law.
- Security and audit logs: we do not currently delete audit logs; they are kept for the life of the account so that we can answer who changed what and when.
- Backups: where a backup copy exists, deleted data may persist in it until that copy is replaced or destroyed. Backups are not restored to live systems except to recover from a failure.
15. Security
We maintain a security programme proportionate to the data we hold. It includes encryption in transit (TLS) for the website, the application and our connections to Meta; passwords stored as one-way Argon2 hashes; WhatsApp access tokens and messaging credentials encrypted at rest with AES-256-GCM; row-level tenant isolation in the database so one business cannot read another's data; role-based access for staff accounts; restricted administrative access; and audit logging. How tenant data is isolated is described further on our security page.
Messages are transmitted to Meta over TLS and handled thereafter under Meta's own security terms. Because they are sent through the Cloud API rather than from a phone, they are not end-to-end encrypted in the way consumer WhatsApp chats are. Copies of outbound messages stored in WheelOps sit in our database and are protected by the controls above.
16. Personal data breaches
If a personal data breach affects you, we will tell you what happened, what data was involved, what we are doing about it, and how to reach us for help. We report incidents to CERT-In within the timelines its directions require, and will notify the Data Protection Board of India and affected individuals as the Digital Personal Data Protection Act, 2023 requires once those provisions are in force.
17. Your rights
Under Indian law, including the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 and the Digital Personal Data Protection Act, 2023 as its provisions come into force, you can ask us to:
- Tell you what personal data we hold about you and give you a copy.
- Correct data that is inaccurate, and complete or update data that is not.
- Delete your data (see section 18).
- Withdraw a consent you gave us (see section 11).
- Nominate another person to exercise these rights on your behalf if you die or become incapacitated.
Write to privacy@wheelops.in. We will verify the request against the email address or phone number on record and respond within 30 days. If you are unhappy with our response, you may raise it with our Grievance Officer (see section 21) or, once the Data Protection Board of India has been established and the relevant provisions of the Digital Personal Data Protection Act, 2023 are in force, with that Board.
Where the data in question is business data we process on behalf of a WheelOps customer, we may need to refer the request to that business, since the data is theirs to control.
18. Data deletion
Full instructions for requesting deletion of your data, including deletion of WhatsApp integration data, are on our data deletion page. In short: email privacy@wheelops.in from the email address associated with your account, we verify the request, and we delete or anonymise the personal data we no longer need. We confirm to you once deletion is complete. We may retain limited records where the law requires it or where they are needed to resolve disputes, prevent fraud or protect our systems.
19. Requests from WhatsApp recipients
If you received a WhatsApp message sent through WheelOps, it was sent on behalf of a business you have dealt with, and that business controls your data. Please contact that business first: it can correct or delete your details and stop messaging you. You can also write to us at privacy@wheelops.inand we will help identify the business or forward your request. We do not disclose one business's account information to an unverified requester.
20. Disconnecting WhatsApp and revoking access
A business can end our access to its WhatsApp Business Account at any time by:
- Removing WheelOps from its WhatsApp Business Account in Meta Business Settings, or revoking the token there. This is the route the business controls itself, and it takes effect immediately.
- Asking our support team to disconnect the integration, which deletes our stored token.
- Asking us to close its WheelOps account.
Once disconnected, new outbound messages from the business's number stop and we stop processing webhook events for it. If a business revokes our access at Meta, the token stops working immediately; tell us as well so that we delete our stored copy. Message logs already recorded in WheelOps follow the retention rules in section 14 and can be deleted on request as described in section 18.
21. Grievance Officer
In accordance with the Information Technology Act, 2000 and the rules made under it, the contact details of our Grievance Officer are:
Name: Archit Mahato
Designation: Grievance Officer, IraOra Solutions Private Limited
Address: 1st Floor, Enkay Tower, Vanijya Nikunj, Udyog Vihar Phase V, Gurgaon, Haryana 122016, India
Email: privacy@wheelops.in
Contactable Mon–Sat, 10:00 – 18:00 IST
We acknowledge privacy grievances within 48 hours of receipt and aim to resolve them within one month, or any shorter period applicable law requires.
22. Children
WheelOps accounts are intended for people aged 18 or older acting on behalf of a business. We do not knowingly let children create accounts. We do no behavioural tracking, profiling or advertising of any kind, and none directed at children.
A business's customer records may include a date of birth, because WheelOps can send birthday messages. Where a business holds the details of someone under 18, that business is responsible for obtaining verifiable parental consent before messaging them. Tell us if you believe we hold a child's personal data and we will delete or restrict it.
23. Cookies and analytics
This marketing site sets no advertising or tracking cookies. We use Google Analytics to count page views, how far down a page people read and which buttons they press, configured so that it stores nothing on your device — no cookie and no browser storage — and so that your IP address is anonymised before it is recorded. It therefore cannot recognise you on a later visit, and because it stores nothing on your device it needs no cookie consent. We do not use the Meta Pixel, and no WhatsApp data is used for advertising.
The WheelOps application uses a cookie to keep you signed in, and a first-party diagnostic identifier, stored in a cookie and in browser storage, that lets us tell one browser's fault reports apart from another's. That identifier is a random value kept for up to a year. It is not linked to advertising, is never shared, and carries no name, number or message content.
The product tour video is embedded from youtube-nocookie.com and loads only if you press play; YouTube's own privacy policy applies to that interaction.
24. Government and legal requests
We may disclose personal data where Indian law requires it: to comply with a valid court order, to authorised government agencies for the prevention, detection or investigation of offences, or to protect our users, systems and legal rights. We disclose only what the request lawfully covers.
25. Changes to this policy
If we change this policy we will update the dates at the top. Material changes affecting how we use your data will be notified to account holders directly, and where a new purpose needs your consent we will ask for it rather than assume it.
26. Contact
IraOra Solutions Private Limited, 1st Floor, Enkay Tower, Vanijya Nikunj, Udyog Vihar Phase V, Gurgaon, Haryana 122016, India.
Email: privacy@wheelops.in · Phone: +91 91158 38675
