TakeApp ↗

ORRO GROUP · ONLINE ACCOUNTS

Your account.
Your choice.

Privacy information for the TakeApp web CRM, optional device-local WhatsApp and optional Google or Facebook sign-in in the Android app.

Effective date: 4 October 2026 · Contact: support@takeapp.in

Who operates this service

Orro Group operates TakeApp online accounts and the CRM at app.takeapp.in. This page covers those services. The Android app publisher and its features are described separately in the app’s privacy policy and Google Play listing. Android 1.0.15 adds server synchronization for authenticated accounts. Earlier device-only profiles remain local until deliberately migrated to an online account.

Email and social sign-in

Online email accounts store your email address, a random account ID, and a salted password hash on our server. We do not store your plain-text password. When you choose Google or Facebook, that provider sends us an account identifier and email address to verify your identity and create or connect your TakeApp account. We do not request your contacts, messages, Facebook posts or friends. Google verifies the email it returns; a Facebook email is not treated as independently verified.

We temporarily exchange and validate provider credentials on our server, without saving provider access, refresh or ID tokens. Short-lived, one-use sign-in proofs expire within ten minutes. Android return codes expire after sixty seconds and require the device’s matching security verifier. We do not include your TakeApp session credential in a browser redirect.

Google sign-in does not ask for a TakeApp password. A verified Gmail or Google Workspace identity can connect to your existing TakeApp account directly. Other Google email addresses confirm ownership with a one-use email code before connecting. Facebook linking to an existing account still requires that account’s TakeApp password. Your account ID and business records remain attached to the same account.

Sessions and service security

Online sessions use secure, HttpOnly cookies. The server stores a hash of the session proof. Sessions expire after seven days or twelve hours of inactivity; logout revokes the current session. Android stores its session and temporary sign-in verifier using Android Keystore encryption. IP addresses, request timing and routine operational logs may be processed for security, rate limiting and service operation. OAuth callback codes and Android launch tickets are excluded from application access logs.

Business records

The web CRM stores the account-owned workspace you enter, which may include store details, products, customer or supplier details, sales, invoices, ledger balances, expenses, tasks, staff records and reservations. We process these records to provide the CRM and its backup and recovery functions. Android 1.0.15 saves authenticated native workspaces to our server and retains encrypted pending records on the device. Existing divergent device copies require a recovery choice before replacement. Website and Android formats use separate account documents and are not automatically merged.

PDF sharing and WhatsApp sharing happen when you choose a destination. The chosen service receives the document under its own privacy terms. Optional device-local WhatsApp reminders send only when you explicitly enable them, as described below.

Optional WhatsApp connection

When you choose to pair WhatsApp in the TakeApp browser workspace, scan the QR from WhatsApp's Linked devices screen. TakeApp stores the linked session credentials and signal keys encrypted on its servers. The QR is shown only to your signed-in account and expires. Messages, recipient numbers and optional receipt PDFs that you explicitly choose to send pass through TakeApp's server to WhatsApp. The app does not request a full chat-history sync.

Android's built-in connection keeps its WhatsApp session on that installation and sends directly from the device. Device ownership metadata is stored on TakeApp servers. Choosing Disconnect Android and connect here revokes Android sending, waits for a send already in progress to finish, and lets you scan a new QR in the browser. Android's saved reminders stay on Android and pause; they are not automatically copied. Remove the old session in WhatsApp's Linked devices if you want to unlink it from WhatsApp itself.

Browser reminder schedules stay encrypted in that browser and require the tab to stay active. A browser send uses a durable request reference, content hash, result and limited error information to prevent duplicate delivery. Disconnecting the browser removes its server session credentials. If a result is uncertain, check WhatsApp before retrying. WhatsApp processes delivered content under its own policies; copies already delivered or exported are not removed by disconnecting TakeApp.

Service providers and choices

Hosting infrastructure processes online account and CRM data for service delivery. Google and Meta process sign-in information under their own policies. You can use email and password instead of social sign-in, cancel a sign-in attempt, or disconnect TakeApp from your provider’s account settings. Provider disconnection does not automatically delete your TakeApp account or business records.

Google privacy policy · Meta privacy policy

Optional Android notifications

Android builds that include account notifications ask you to enable them in Settings and allow Android’s notification permission. Notifications start off. If you opt in while signed in, we register a random installation ID, an encrypted Firebase Cloud Messaging delivery token, the app’s package name and your TakeApp account ID on our server. Your device stores a separate encrypted credential that permits only notification retrieval and acknowledgements; it expires after ninety days and cannot open your business records.

We use Google Firebase Cloud Messaging to send notification and delivery identifiers to your device. The app retrieves the administrator’s message from TakeApp after checking your account and plan access, then shows an Android notification. This integration does not send your business workspace, invoice files, passwords or customer contact details to Firebase. Google processes delivery tokens and connection information under its Firebase privacy information. We do not enable Firebase Analytics through this feature.

The administrator can address active accounts, a plan or selected accounts, and schedule a message. TakeApp records the message, its audience and timing, provider acceptance or failure, and acknowledgements when the app reports a display or an opening. Provider acceptance does not prove that a notification appeared or was read. Notifications may be visible to someone who can use your unlocked device; Android’s lock-screen settings control their visibility.

Turn off Notifications in Android Settings or TakeApp Settings to stop new displays. TakeApp clears its local notification credential and requests removal of that device’s registration when connected. Signing out also clears local notification access; server logout, account blocking and account-access revocation invalidate registrations. These changes do not retract messages already seen. Notification access is optional and separate from marketing measurement consent.

Optional Meta analytics

The CRM offers optional Meta Pixel measurement, switched off until you choose Allow analytics. After consent, a generic PageView event contains only our fixed public CRM address, event type and time. We never send your actual page address, query strings, sign-in callbacks, form values, account identifiers, emails, financial values or business records to Meta through this feature. No Meta JavaScript or automatic advanced matching is used.

Meta receives the request's IP address, browser and network details and may receive its own cookies under your browser settings. Choices are stored in this browser for up to 180 days, separately from the landing site and Android app. You can decline or withdraw at Privacy choices, also linked from login, Settings and Preferences. Withdrawal stops new requests; it does not retract information already received by Meta. Refusal does not prevent sign-in or CRM use. Read our optional measurement notice for recipients, purpose, retention and controls.

Retention and deletion

Online account and business records remain until removal is requested or required for service administration. To request online account or data deletion, email support@takeapp.in from your registered address. We verify account ownership before acting; identify which online account and records you want removed. Backups and records that must be retained for legal or security reasons may persist for their applicable retention period.

Clearing Android app storage or uninstalling removes its local data; it does not delete your server account or copies already exported or shared. Export records you need before deleting local data. Contact support for access, correction or deletion questions. Do not send passwords, provider tokens or unnecessary customer or employee information.

Server workspace storage

Signed-in website and Android accounts save business records to TakeApp servers over HTTPS. Android keeps an encrypted pending copy for interrupted saves and uploads resized product photos. Website and Android records use separate account documents; this release does not merge their different formats. Revision checks reject conflicting saves. Existing device copies are retained for recovery, and a conflict requires your choice before replacement. Android WhatsApp pairing and dispatch stay on the device. Optional browser pairing uses encrypted TakeApp server credentials and server-assisted delivery as described above. Server account and record deletion can be requested at support@takeapp.in.

Service visit and account alerts

TakeApp uses first-party service notifications to monitor website visits, new account registrations and verified subscription activations. Public and account-entry pages report the page category, referring website hostname and campaign source, medium and name when supplied. We do not include form values, passwords, verification codes, full referrer addresses, arbitrary URL queries, ad click identifiers or business/customer records in these reports. A signed, HttpOnly cookie keeps a random visitor reference across TakeApp subdomains for up to thirty days. Referrer data may be missing and campaign values are browser-reported, not independently verified.

TakeApp sends a limited alert to its configured operator through a Telegram bot. Visit alerts contain the short visitor reference and available source information; signup alerts use masked contact details and an account reference; billing alerts describe confirmed subscription or trial activation. Telegram processes these notifications under its privacy policy. Visit reporting respects browser Do Not Track and Global Privacy Control signals, ignores known bot user agents, and deduplicates and rate-limits alerts. These service alerts are separate from the optional Meta measurement controls.

Visit records and delivery event details are retained for up to thirty days. The initial source associated with an account and minimal subscription-alert dedupe keys remain until the account is deleted. Operators can disable new alerts. Messages already sent may remain in Telegram until removed there. Contact support@takeapp.in for questions or data requests.