# Privacy Policy

How Dronaware handles information across the website, Testbench, purchases, device registration, and Optical Flow delivery.

*Last updated: 25 September 2026 · Effective date: 25 September 2026*

## 1. Who is responsible

**Dronaware** is the trading name of **Tushar Sharma**, sole proprietor, and an Udyam-registered MSME in India. Tushar Sharma trading as Dronaware is the data fiduciary, controller, or business responsible for personal information where applicable. Do not send Aadhaar numbers, full payment-card details, passwords, or unrelated sensitive information by ordinary email.

## 2. Information we collect

**Website and communications.** We may receive name, email address, messages, preferences, browser and device information, IP address, approximate country derived from IP, timestamps, referrer, cookie or security identifiers, and request, error, and abuse-prevention logs.

**Identity and purchases.** For checkout and licence workflows, we may process a verified email, name if supplied by an identity provider, provider type and provider user identifier, verification events, workflow and purchase identifiers, product, quantity, amount, currency, country, payment status, merchant references, invoice or tax information, refund or chargeback status, and support correspondence. The payment provider or merchant of record handles payment credentials; Dronaware does not intend to store full card or bank credentials.

**Device registration and flashing.** We may process an ESP32 chip model, a factory MAC read from the connected device, a derived device identifier, registration and licence identifiers, firmware version, erase permission, flashing-session identifier and status, progress or failure events, activation time and result, IP address, country, and security audit records. The browser communicates with the connected device; Dronaware's backend does not receive raw serial traffic merely because Web Serial is used.

## 3. Testbench local processing

Testbench is designed to read and analyze serial telemetry locally in your browser. Unless a feature clearly states otherwise before collection, raw serial telemetry, sensor output, test runs, and run summaries are not uploaded to Dronaware. Closing the tab or clearing browser storage may remove locally stored session information. Your browser, operating system, drivers, and connected hardware may maintain their own logs under their providers' policies.

## 4. Why we use information

- provide, secure, maintain, troubleshoot, and improve the services;
- verify identity, confirm purchases, provide receipts, register devices, administer device-bound licences, deliver firmware, and provide updates for registered devices;
- detect fraud, chargebacks, abuse, unauthorized distribution, credential misuse, and activation anomalies;
- respond to support, privacy, refund, legal, and safety requests;
- maintain tax, accounting, transaction, licence, and dispute records; and
- send essential service communications and, only where permitted, optional marketing that you may opt out of.

Depending on applicable law, processing is based on providing a requested service or contract, compliance with law, consent, and legitimate operational, security, fraud-prevention, and legal interests.

## 5. Providers and disclosures

We use infrastructure providers for website, application, database, storage, security, and delivery services; an email provider for transactional messages; identity providers selected by you for OAuth verification; and the payment provider or merchant of record named at checkout for payment processing, taxes where applicable, refunds, and fraud checks. Each provider is responsible for the service it supplies under its applicable terms and privacy notice. We share only information reasonably necessary for the relevant service.

We may disclose information to professional advisers, insurers, authorities, courts, or other persons when reasonably necessary to comply with law, investigate an incident or claim, enforce rights, or protect users and the service. We do not sell personal information. Providers may process information outside India; we use the contractual, organizational, or technical safeguards required by applicable law.

## 6. Retention

Temporary verification, workflow, rate-limit, and flashing-session records are configured to expire after their operational or security purpose, generally in minutes, hours, or a short security window. Ordinary infrastructure logs are retained according to configured infrastructure and service settings and may be retained longer for a security incident.

Identity, purchase, invoice, tax, payment-event, licence, device-registration, activation, refund, and chargeback records are retained for the life of the licence and for the additional period reasonably required for tax, accounting, fraud prevention, support, safety investigations, disputes, and legal obligations. Support and incident records are retained for as long as reasonably necessary to handle the request and defend or establish legal rights. We delete or anonymize information when it is no longer needed, subject to backups and legal holds.

## 7. Security

We use measures appropriate to the service, including encrypted transport, restricted administrative access, secrets management, time-limited workflow credentials, one-time or short-lived flashing-session artifacts, hashed or derived identifiers where suitable, and audit records. No system can guarantee absolute security. You are responsible for protecting access to your email, identity-provider account, device, browser, and flashing session.

## 8. Your choices and rights

Subject to applicable law, you may ask for information about processing; access, correction, completion, deletion, or restriction; withdrawal of consent where processing relies on consent; or an end to optional marketing. We may verify your identity and may retain information required for tax, licence administration, fraud prevention, incident investigation, disputes, or other legal obligations.

Indian requests and grievances will be handled under the Digital Personal Data Protection Act, 2023 and rules in force. Other laws may provide additional rights or a right to complain to a supervisory authority. Send requests to [hello@dronaware.com](mailto:hello@dronaware.com).

## 9. Children and third-party services

The services are intended for developers and organizations and are not directed to children. We do not knowingly request children's personal information. Links, OAuth pages, payment pages, browsers, operating systems, and connected hardware are governed by their providers' own policies.

## 10. Changes

We may update this policy as our services, providers, or legal obligations change. The date above identifies the current version. We will communicate material changes where required.

## 11. Contact and grievances

Data fiduciary/controller: **Tushar Sharma, sole proprietor trading as Dronaware**
Privacy requests: [hello@dronaware.com](mailto:hello@dronaware.com)
Grievance Officer: **Tushar Sharma, Proprietor** · [support@dronaware.com](mailto:support@dronaware.com)

We aim to acknowledge consumer grievances within 48 hours and resolve them within one month, subject to the nature of the matter and applicable law.

---
Dronaware · Udyam-registered MSME in India
