Skip to content

Legal

Privacy policy

What we hold, why, and how to get it back.

Last reviewed 22 August 2026

This document has not been through legal review

Abroad Allies has not incorporated, so there is no company named here to be contracted with, and no lawyer has approved this text. What follows is an honest description of how the software actually behaves, written from the code that runs it — useful to read, and not yet an agreement anybody can rely on in a dispute.

It is published rather than withheld because a signup form that asks you to accept terms you cannot open is worse than one that shows you an unfinished draft. When the entity exists, this notice goes and a reviewed version replaces the text.

Who is responsible for this data

Registered name
Not published yet — set NEXT_PUBLIC_COMPANY_LEGAL_NAME.
Registered office
Not published yet — set NEXT_PUBLIC_COMPANY_ADDRESS.
Privacy contact
Not published yet — set NEXT_PUBLIC_PRIVACY_EMAIL.

When the data is about somebody else

This is the situation this service is mostly in, so it comes first rather than in a footnote. If you upload your mother’s passport, list her medications, or share photographs of her home, she is the person that data is about — not you.

  • You are confirming you may share it. That you have their permission, or another proper basis such as acting under a power of attorney or as their guardian.
  • They keep their own rights over it, regardless of whose account it sits in. They can ask us for a copy, for a correction, or for deletion, and they do not need an account to do so — see below.
  • We will tell them if they ask. If somebody contacts us about data held about them, we will confirm what we hold and, where it is right to do so, who provided it. We will not conceal it from them to protect the account holder.

The same applies to a parcel recipient who never used this service at all: their name and address are held because somebody sent them something, and they can exercise their rights without an account.

What we collect and why

  • Account details — name, email, password (stored only as a hash we cannot reverse), language, timezone. To let you in and to reach you about your orders.
  • People you add — parents, beneficiaries, family circle members: their names, addresses, contact details, and where a care service needs it, allergies, medications and medical notes. To do the work you asked for.
  • Documents — whatever a service requires: passports, deeds, marksheets, medical records, powers of attorney. To submit, attest, or act on them.
  • Orders and evidence — what was requested, each step and who did it, photographs and reports from visits, location tags where a visit had to be proven to have happened. To do the work, and to show you it was done.
  • Payments — amounts, invoices, refunds and the ledger behind them. Card and bank details are handled by the payment provider; we do not store them.
  • Messages — what you and our staff say to each other about an order.
  • Technical records — the network address and browser used when privileged actions happen, and when documents are opened. To keep the audit trail meaningful.

What allows us to hold it

  • Performing the contract with you — nearly everything operational: your account, your orders, the documents needed to complete them.
  • Legal obligation — invoices, ledger entries, tax records and the audit trail. We are required to keep these and cannot delete them on request.
  • Explicit consent — health information about a person receiving care. This is a special category of data, it is only held where a service genuinely requires it, and it can be withdrawn.
  • Legitimate interests — keeping the service secure and preventing fraud, balanced against the effect on the people involved.

Who can see it

Staff see what their role requires and no more, and every privileged action is recorded against the individual who took it — with what changed and the reason given. The controls behind that, and their limits, are set out on the security page; please read it before deciding what to upload.

Outside our own staff, data goes to:

  • Government offices and registries — the documents a service exists to submit.
  • Professionals we engage for you — a lawyer, a chartered accountant, a notary, where the service requires one.
  • Payment providers — to take payment and issue refunds.
  • Carriers — a recipient’s name and address, to deliver a parcel.
  • Infrastructure providers — hosting, email delivery and similar, under contract and only to run the service.

We do not sell data, we do not share it for advertising, and there is no advertising network or third-party analytics script on this site.

One thing we do count. When you use a share button we record which channel you chose — WhatsApp, email, copy link and so on — and the path of the page you shared, so we can tell which of them are worth keeping. That is the whole record: no name, no account, no device or visitor identifier, nothing that could be traced back to you or joined to anything else, and no third party involved. The web address is stored without its query string, so a personalised or invitation link cannot end up in it.

Where it is held

The work happens in India and the data is held in India. If you are outside India — which most account holders are — then using this service necessarily involves your information being processed there, by the people doing the work.

How long we keep it

The intended schedule gives every class of data a period and a stated reason: financial records for the eight years India’s company law requires, the audit trail for the same, visit evidence for a period after the order closes, call recordings for far less. Records under a legal hold are kept until it lifts.

This schedule is not yet enforced automatically

The periods above are the design. The nightly job that acts on them has not been built, so nothing is currently being deleted on a schedule. Deletion happens when you ask for it, under the rights below.

Stating this rather than describing the schedule as though it ran is deliberate. The same rule is applied throughout the security page.

Your rights, and how to actually use them

Whether or not you have an account, you can ask us to:

  • tell you what we hold about you, and give you a copy;
  • correct something that is wrong;
  • delete it, where we are not legally required to keep it;
  • stop a particular use, or withdraw consent you gave for health information;
  • give you your data in a portable form.

A dedicated privacy address has not been published on this deploy — NEXT_PUBLIC_PRIVACY_EMAIL is unset. Until it is, use any route on the contact page and mark it as a data request; it will be treated as one from the day you send it.

If you are not satisfied with how we handle it, the Grievance Officer is the escalation, and you can complain to the data protection authority where you live.

Cookies

We set what the site needs to work: keeping you signed in, and remembering your theme, language and timezone. Those rely on legitimate interest rather than your consent, because the site cannot function without them, and they are the only things set before you have chosen anything. Nothing here follows you to other sites.

Everything else is off until you turn it on. A banner asks once, on your first visit, and refusing everything optional is a single click that sits beside accepting it. Your answer is kept in your browser; once you sign in it is recorded against your account, per purpose, against the version of this notice you were shown — so it follows you to another device and you can change it later. If we publish a new version of this notice, you are asked again only about the purposes whose scope actually changed.

As it stands, none of the optional purposes is running: there is no advertising network, no third-party analytics and no chat widget on this site today, and the share count described above sets nothing and stores no identifier. The banner records your answer ahead of any of them, rather than arriving after the fact.

Children

Accounts are for adults. Data about a child may legitimately appear inside a service — a school admission, a passport for a minor — and it is held under the same rules and shared only with the office it is being submitted to.

The rest of the set: Terms of service, Privacy policy, Refunds & cancellations, Grievance officer. How documents are handled is on Security & privacy.