01Who we are & what this covers
This Policy explains how B4Bharat handles personal data across the b4bharat.com website, the B4Bharat app, our WhatsApp channels and related services (the "Platform"). Under the Digital Personal Data Protection Act, 2023 ("DPDP Act"), we are the Data Fiduciary and you are the Data Principal.
It applies to Dukaandaars, Brand Partner personnel, Sarthis, site visitors and anyone contacting support. It reads with our Terms of Service and doesn't cover third-party sites we link to.
02What we collect
Identity and business details to verify you, transaction data to fulfil orders, device and location data to run the app, and support conversations to help you.
| Category | Examples |
|---|---|
| Identity & contact | Name, mobile, email, shop name, business address, preferred language. |
| Verification / KYC | GSTIN, PAN, trade licence, government ID, shopfront photo, verification status. |
| Financial | Bank account, IFSC, UPI handle, transaction history, credit application status. We never store full card numbers or CVV that stays with PCI-DSS compliant payment partners. |
| Transactional | Orders, cart and browsing activity, invoices, returns, disputes, payout records. |
| Device & technical | Device model, OS, app version, IP address, device identifiers, crash logs. |
| Location | Where you grant permission for serviceability, delivery accuracy and Sarthi beat mapping. Revocable in device settings. |
| Communications | Support tickets, call recordings where notified, WhatsApp and SMS logs, feedback. |
We collect this directly from you, automatically through the app and website, from partners (KYC, payments, logistics, lending), and from a Sarthi onboarding your shop with your consent. We don't seek sensitive data beyond statutory KYC — please don't send documents we haven't asked for.
03Why we use it
Only for lawful purposes, based on your consent or the legitimate uses permitted by the DPDP Act.
| Purpose | What this involves |
|---|---|
| Account & verification | Registering your business, verifying GSTIN and identity, preventing duplicates. |
| Orders & payments | Processing orders, delivery, invoicing, refunds, Seller settlement, Sarthi commissions, tax reporting. |
| Support | Answering queries, investigating disputes, improving service quality. |
| Safety & fraud | Detecting fake accounts, circular trading, incentive abuse, unauthorised access. |
| Product improvement | Understanding usage, fixing bugs, testing features, aggregated analytics. |
| Communications | Transactional alerts by SMS, WhatsApp, email and push. Marketing only where permitted, always opt-out-able. |
| Legal compliance | Tax, company, e-commerce, anti-money-laundering and intermediary obligations. |
We don't use personal data for automated decisions with legal effect without human review, beyond routine fraud and risk scoring.
04Consent & who we share with
You can withdraw consent any time. We share only with partners who help run the service never with data brokers.
Where we rely on consent we ask clearly and separately, naming the data and purpose. You can withdraw it as easily as you gave it, in the app's privacy settings or via our Grievance Officer. Withdrawal doesn't undo lawful processing already done and may limit parts of the Platform; processing needed for a legal obligation or an order you've placed may continue. This notice is available in English and, on request, in any language in the Eighth Schedule to the Constitution of India.
We share personal data with:
- Sellers and logistics partners — order, name, address and phone needed to fulfil and deliver.
- Payment, KYC and lending partners — what's needed to process payments and payouts, verify you, or assess a credit application you make.
- Technology providers — hosting, analytics, crash reporting, communications and support tooling.
- Advisers and authorities — auditors, lawyers and insurers where necessary; government or courts where legally required.
- Corporate transactions — in a merger, acquisition or restructuring, with equivalent protections.
Every processor is bound by written contract to act only on our instructions and keep appropriate safeguards. We do not sell personal data.
05Cookies, retention & security
Cookies. We use strictly necessary cookies (authentication, security, core functionality not switchable), analytics cookies, and preference cookies, plus equivalent SDK identifiers in the app. Manage them in your browser and reset advertising identifiers in device settings; blocking necessary cookies will break parts of the Platform.
Retention. We keep data only as long as needed for its purpose, or as long as the law requires whichever is longer. Transactions, invoices and KYC documents are held for their statutory periods; support conversations for a limited dispute-resolution window; device and analytics logs briefly, then aggregated or anonymised. Account data is erased or anonymised once the account closes and any statutory period ends.
Security. We maintain safeguards appropriate to the data we hold: encryption in transit and at rest, least-privilege role-based access, multi-factor authentication internally, network segregation, logging and monitoring, periodic reviews and staff training, and contractual security obligations on processors. No system is completely secure keep your password and OTPs private and tell us immediately if you suspect misuse.
06Your rights
Ask what we hold, get it corrected or erased, nominate someone to act for you, and complain if you're unhappy.
- Access — a summary of the data we hold, how we process it, and who we've shared it with.
- Correction & completion — fix inaccurate data, complete what's incomplete, update what's outdated.
- Erasure — delete data no longer needed, where no law requires us to keep it.
- Withdraw consent — at any time, as described in Section 4.
- Grievance redressal — complain to us before approaching the Data Protection Board of India.
- Nomination — name someone to exercise these rights for you in the event of death or incapacity.
Use the privacy controls in the app or write to our Grievance Officer. We verify identity before acting and respond within the timelines set by law. Under the DPDP Act you also have a duty not to submit false particulars or raise frivolous complaints.
07Deleting your account
Request deletion any time in the app under Profile → Settings → Account → Delete account, online at b4bharat.com/account-deletion, or by writing from your registered email.
We'll first ask you to settle outstanding dues and complete orders in progress. Records we must keep by law invoices, transactions, KYC are retained for the statutory period and then erased. Everything else is deleted or irreversibly anonymised.
08Children, transfers, breaches & grievances
Children. The Platform is for business users aged 18 and above. We don't knowingly collect children's data, and we don't track, behaviourally monitor or target advertising at children. If we learn we've collected a child's data without verifiable guardian consent, we delete it promptly.
Transfers. Data is primarily stored and processed in India. Where a technology provider processes limited data abroad, we transfer only to countries not restricted by the Central Government under the DPDP Act, with contractual safeguards equivalent to this Policy.
Breaches. We maintain an incident response process to identify, contain and investigate security incidents. In a personal data breach we notify the Data Protection Board of India and each affected Data Principal in the form and timelines prescribed under the DPDP Act.
Changes. We may update this Policy as our services or the law change. The version and effective date at the top always show the current one, and we give reasonable prior notice of material changes.
Grievances. For any question, to exercise a right, or to complain, contact our Grievance Officer, appointed under the DPDP Act, 2023 and the IT (Intermediary Guidelines) Rules, 2021. Their name and contact details are at b4bharat.com/help. Complaints are acknowledged within 48 hours and ordinarily resolved within 30 days. If you remain unsatisfied, escalate to the Data Protection Board of India.
Prepared for review by qualified legal counsel; not itself legal advice.
↑ Back to top