1. Who we are
Apnse ("we", "our", "us") is an online marketplace platform connecting clients with verified Chartered Accountants (CA) and Company Secretaries (CS) across India. Our website is accessible at www.apnse.com.
This Privacy Policy explains how we collect, use, disclose and protect your personal information when you use our platform, in accordance with India's Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, as well as applicable international standards including GDPR.
By using Apnse you agree to this Privacy Policy. If you do not agree, please do not use our platform.
2. Data we collect
2.1 Data you give us directly
- CA/CS professionals: Name, email, mobile number, city, state, ICAI/ICSI membership number, years of experience, practice type, firm name, bio, profile photo, membership certificate (document), government ID (document), service list and pricing.
- Clients sending enquiries: Name and mobile number (shared only with the specific professional you contact).
- All users: Email and password when creating an account.
2.2 Data we collect automatically
- IP address — used to determine approximate city/state for personalisation
- Device type — mobile, tablet or desktop
- Browser and operating system
- Screen size
- Referrer URL — which website you came from
- Pages visited and time of visit
- Internet Service Provider (ISP)
- Browser language preference
2.3 Sensitive personal data
We collect government-issued identity documents (Aadhaar/PAN) and professional membership certificates from CA/CS registrants for verification purposes only. These are stored securely with access limited to the Apnse verification team. They are never displayed publicly.
3. Cookies
Cookies are small text files stored on your device when you visit our website. We use the following categories of cookies:
| Category | Name | Purpose | Duration | Consent needed? |
|---|---|---|---|---|
| Essential | apnse_sid | Session identifier — keeps you logged in and tracks your visit session. Required for the platform to function. | Session / persistent | ❌ No (essential) |
| Essential | apnse_visited | Remembers if you have visited before (new vs returning visitor). No personal data stored. | Persistent | ❌ No (essential) |
| Preferences | apnse_consent | Stores your cookie consent preference (accepted / rejected). | 1 year | ❌ No (consent record) |
| Analytics | Visitor log | Records city, device type, referrer and time of visit for platform analytics. Stored server-side, not in a cookie. | 90 days | ✅ Yes |
| Personalisation | Visitor profile | Uses your IP-derived city and time of day to show relevant professionals and contextual banners. | Session | ✅ Yes |
Managing your cookie preferences
When you first visit Apnse, a cookie consent banner appears. You can choose "Accept all" (enables analytics + personalisation) or "Only essential" (essential cookies only).
You can change your preference at any time by clearing your browser's localStorage or by emailing us at hello@apnse.com to request a preference reset.
You can also control cookies through your browser settings. Note that disabling all cookies may affect the functionality of the platform.
4. How we use your data
- To verify CA/CS professional credentials against official ICAI/ICSI records
- To display verified professional profiles to clients searching on Apnse
- To forward client enquiries to the relevant professional (name + mobile number only)
- To personalise the homepage with city-relevant content and professionals
- To send transactional emails (enquiry notifications, registration approvals)
- To analyse platform usage and improve our services
- To show contextual banners relevant to your location, time and referrer
- To prevent fraud, abuse and unauthorised access
- To comply with applicable laws and legal obligations
We do not use your data for automated decision-making that produces legal effects about you.
5. Sharing your data
We do not sell, rent or trade your personal data to any third party. We share data only in these limited circumstances:
- Between users: When a client submits an enquiry, their name and mobile number are shared with the specific professional they contacted. The professional's public profile information is visible to all site visitors.
- Service providers: We may share data with trusted service providers who help us operate Apnse (e.g. email delivery, IP geolocation API). These providers are contractually bound to protect your data.
- Verification bodies: Membership numbers may be verified against ICAI/ICSI records via authorised verification APIs.
- Legal requirements: We may disclose data if required by law, court order or government authority in India.
6. Data retention
- Professional profiles: Retained while the profile is active. Deleted within 30 days of a deletion request.
- Enquiry records: Retained for 12 months, then anonymised.
- Visitor logs: Retained for 90 days, then permanently deleted.
- Uploaded documents: Retained for 12 months after profile deletion for legal compliance, then permanently deleted.
- Password reset tokens: Deleted immediately after use or expiry (1 hour).
7. Your rights
Under applicable Indian and international privacy law, you have the right to:
- Access: Request a copy of personal data we hold about you
- Correction: Request correction of inaccurate data (professionals can update most data via their dashboard)
- Deletion: Request deletion of your account and associated data
- Withdraw consent: Withdraw cookie consent at any time
- Grievance redressal: Under the IT Act, you may raise a grievance with our Grievance Officer
To exercise any of these rights, email us at hello@apnse.com with the subject line "Privacy Request". We will respond within 30 days.
Grievance Officer (IT Act 2000)
Name: Apnse Privacy Team
Email: hello@apnse.com
Response time: Within 30 days of receipt
8. Security
We implement reasonable security measures to protect your data including:
- HTTPS encryption on all pages (SSL/TLS)
- Passwords stored as one-way bcrypt hashes — never in plain text
- Uploaded documents stored with randomised filenames in a protected server directory
- Database access restricted with role-based credentials
- Brute-force protection on login and password reset
- Admin panel protected behind separate authentication
No system is 100% secure. In the event of a data breach affecting your rights, we will notify you within 72 hours of becoming aware.
9. Children's privacy
Apnse is not intended for use by anyone under the age of 18. We do not knowingly collect personal data from minors. If you believe a minor has provided us with personal data, please contact us immediately at hello@apnse.com.
10. Changes to this policy
We may update this Privacy Policy from time to time. When we make significant changes, we will update the "Last updated" date at the top of this page and may notify registered professionals by email. Continued use of Apnse after changes constitutes acceptance of the updated policy.
11. Contact us
For any privacy-related questions, requests or concerns:
Email: hello@apnse.com
Website: www.apnse.com
Response time: Within 30 working days