Billexa is committed to protecting your privacy across Billing, Marketplace, KYC, Telegram Bot, Admin Bot, Support Tickets, Analytics, Expense Tracking, Profile, Order Tracking, Two-Factor Authentication (2FA), Rate Limiting, and Account Deletion. By using Billexa, you consent to this policy.
📑 Privacy Policy Contents
- 1. Introduction
- 2. Data We Collect
- 3. How We Use Data
- 4. Data Sharing
- 5. Security Measures
- 6. 🛡️ KYC
- 7. 📊 Analytics
- 8. 🛒 Marketplace
- 9. 🤖 Telegram Bot
- 10. 👑 Admin & Support
- 11. 💰 Expense
- 12. 👤 Profile
- 13. Data Retention
- 14. Your Rights
- 15. Third-Party
- 16. Comparison
- 17. Contact
- 18. 🔨 Ban & Lock
- 19. ⭐ Trust Score
- 20. 🤖 AI Assistant
- 21. 📝 Login History
- 22. 🔐 2FA Privacy
- 23. 🔑 Password Recovery
- 24. ⏱️ Rate Limiting
- 25. 🎁 Referral
- 26. 🔒 Single Session
- 27. 🔥 Community Posts
- 28. 🛒 Buyer Trust Score
1 Introduction
2 Data We Collect
- Account: Name, email, mobile, DOB
- Billing: Products, invoices, sales, barcodes
- Marketplace: Listings, images, videos, payment proofs
- Orders: Name, mobile, address, status history
- KYC: Aadhar (F/B), PAN, Shop Photo, Selfie, Signature, Business info
- Telegram: Bot Token (encrypted), Chat ID, Username, command logs (30d)
- Analytics: Views (IP), clicks, conversions, revenue, demographics (anonymized)
- Support: Ticket content, category, status
- Expense Data: Expense records and bill/receipt images for your business.
- Profile Data: Full name, DOB, gender, optional business details, profile photo, business logo.
✍️ Invoice & Signature Data
When you use the optional signature feature on invoices (photo upload or digital draw), the signature image is stored securely in your invoice records. You are solely responsible for the authenticity and lawful use of all signatures and invoices generated from your account. Billexa does not use your signature data for any purpose other than displaying it on your invoices. Signature data is deleted when you delete your account.
🛡️ KYC Seller Signature
As part of KYC verification, you may submit a signature. This KYC signature is used specifically for seller verification and marketplace trust purposes. It is distinct from the optional invoice signature and is subject to the rules described in Section 6.
📸 Uploaded Content
Expense Bill Images: Stored securely, only you can view them through your account.
Profile Photos & Business Logo: Stored securely, only you can manage them. Removal permanently deletes from servers.
3 How We Use Data
- Provide Platform services, process orders, facilitate delivery
- Verify seller identity (KYC), assign Verified badge, display KYC signature for trust
- Generate invoices, reports, analytics
- Send Telegram Bot alerts
- Manage support tickets
- Improve Platform, prevent fraud, comply with law
- Financial Reports: Combine expense and invoice data for profit/loss summaries and PDF reports.
- Profile Personalization: Personalize experience, display identity in chats/marketplace, pre-fill business details on invoices.
4 Data Sharing
Billexa does not sell personal data or share it with third parties for advertising or marketing purposes. We may process or store data through trusted service providers where necessary to operate, secure, host, back up, or provide Billexa services.
Shared only: with consent (bot, delivery), legal orders, trusted providers (MongoDB, Cloudinary, Telegram API, PDFKit, OpenRouter for AI). Seller sees buyer name/mobile/address for delivery. KYC docs: admin only. Expense records and bill images are never shared with anyone. Profile photos and business details are never shared with third parties.
5 Security Measures
- bcrypt password hashing (10 rounds)
- HTTPS/SSL encryption for all connections
- MongoDB Atlas encryption at rest
- Cloudinary enterprise security (KYC docs, expense bills, profile photos)
- Bot Token encryption for Telegram bots
- Helmet.js security headers (CSP, XSS protection)
- Rate limiting on all routes (prevents brute force & DDoS)
- 24-hour session timeout with MongoDB session store
- IP logging for suspicious activity
- CORS protection
- Two-Factor Authentication (2FA) with encrypted secrets
- Account deletion requires password + 2FA verification
- Login lockout after 5 failed attempts (15 minutes)
Your expense records and bill images are encrypted and stored securely. No third party has access to your financial data. We never share your expense information with anyone. Your personal information including profile photos, business details, and GST number are encrypted and stored securely. We never share your personal or business information with third parties.
6 🛡️ KYC & Seller Verification Privacy
What We Collect SENSITIVE
- Aadhar Card (Front & Back), PAN Card, Shop Photo, Selfie, Signature, Business name & type, City & State
How We Use It
- Verify seller identity, assign 🟢 Verified badge, fraud prevention, and marketplace trust display.
Public Signature Display Consent
By completing KYC and participating as a Verified Seller, you expressly acknowledge and consent to the public display of the signature submitted during KYC for seller verification and marketplace trust purposes. This signature may appear on applicable product detail pages, order invoices, and QR code pages.
What is NEVER Publicly Displayed
- Aadhaar image, Aadhaar number, PAN, KYC photograph/selfie, private KYC information, or other confidential verification documents.
Storage & Access
- Cloudinary enterprise security. Only admin can view KYC documents. Never shared with buyers/sellers. Encrypted in transit & at rest.
Retention & Control
- Until account deletion. Deleted within 30 days. Withdraw anytime. Re-submit up to 3 times.
7 📊 Seller Dashboard & Analytics Privacy
What We Track
- Product views (IP-based, anonymous), clicks, conversions, revenue, customer locations (city/state only), peak times
What We DON'T Track
- Individual buyer identities, other sellers' data, personal browsing history
Data Isolation
- Each seller sees ONLY own analytics. No cross-seller sharing. Buyers anonymous.
Retention
- Views/Clicks: 12 months. Revenue: 7 years (legal). Aggregated: Indefinitely (anonymized).
Your Control
- View: Dashboard → Analytics. Export CSV/PDF. Opt-out via support. Deleted on account closure.
Analytics Disclosure: Billexa may use analytics tools to understand website usage, performance, and traffic. This may include Google Analytics. No ad trackers are used.
8 🛒 Marketplace Data Privacy
📋 Buyer Data (Visible to Seller)
- Name, Mobile, Address shared for delivery purposes only.
- Optional fields: Alternate Mobile, Landmark, Pincode also visible to seller for delivery.
- NOT shared after order completion or cancellation.
- Quantity ordered and total amount visible to seller.
- Buyer identity protected — seller cannot contact after order completion.
- Buyer email never shared with seller.
🏪 Seller Data (Visible to Buyer)
- Shop/Seller name, Verified/Unverified badge, Product listings, Ratings & Reviews.
- KYC Signature (if verified) may be displayed on product detail pages, order invoices, and QR code pages.
- Trust Score visible to help buyers make informed decisions.
- NOT visible: Email, Phone, Address, Aadhar, PAN, Bank details.
- Phone Number (Seller Controlled): Hidden by default; buyer clicks to reveal. Only for KYC verified sellers.
- Pincode (Optional): Visible on product detail and QR page.
- Seller location (if provided) visible on product cards.
⭐ Reviews & Ratings Data
- Reviews are public — visible to all marketplace users.
- Review includes: Buyer name, Rating (1-5), Review text, Images (max 2).
- Review images stored on Cloudinary secure servers.
- Buyer can delete their own review anytime.
📦 Order & Transaction Data
- Order history stored for both buyer and seller reference.
- Cancellation records maintained for fraud prevention (Terms 17.8).
- Delivery status tracked and visible to both parties.
- Order invoices (PDF) generated and stored securely.
💬 Chat & Communication
- Chat messages stored for 90 days for dispute resolution.
- Chat includes: Text messages, Images, Payment proofs.
- Chat automatically deleted after 90 days.
- Voice/Video calls are peer-to-peer (WebRTC) — not recorded or stored.
💳 Payment Data
- Cash on Delivery (COD) only — no financial data (bank/card/UPI) stored for marketplace orders.
- Payment proof images uploaded by buyer stored on Cloudinary.
- No online payment processing — all payments handled directly.
- Transaction amounts visible to both parties for order verification.
🔄 Return & Refund Data UPDATED
- 📸 Return Proof Images: Buyer can upload up to 3 images. Stored on Cloudinary temporarily, visible to seller only for verification.
- Images auto-deleted permanently from Cloudinary when: ✅ Refund completed or ❌ Return rejected.
- Images are never shared publicly or with third parties.
- 📦 Pickup Address: Provided by buyer, visible to seller only for item pickup.
- Bank Details Collected: Account Holder Name, Account Number, IFSC, Bank Name for refund processing.
- Bank details visible to seller only for the purpose of processing refund via UTR/Transaction ID.
- Last used bank details auto-saved for buyer convenience. Stored securely, not shared with third parties.
- UTR/Transaction ID: Recorded for refund tracking, visible to both parties.
- Return data retained as long as order data is retained (active account). Bank details deleted on account closure.
🖼️ Product Images
- All product images stored on Cloudinary secure cloud servers.
- Only images allowed (no videos) for product listings.
- Max 10 images per product, 10MB each. Deleted when product is deleted.
- Review images: Max 2 per review, 5MB each.
- KYC document images stored separately with enterprise security.
🛡️ Fraud Prevention Data
- Cancellation count tracked for penalty enforcement.
- 3+ cancellations in 30 days = KYC review/revocation.
- Delivery performance monitored for Trust Score calculation.
- Fraud reports stored for investigation.
- Banned users' Aadhar/PAN permanently blocked from reuse.
🔍 Search & Analytics
- Product search covers: Title, Description, Product ID, Seller name, Location, Category.
- Product views tracked for analytics (seller dashboard).
- Aggregated data used for marketplace trends (anonymized).
❤️ Wishlist Data
- Wishlist is private — only the logged-in user can view their own wishlist.
- Wishlist stores: Product ID and date added. No personal data shared.
- Wishlist data is not visible to sellers or other users.
🏪 Seller Store Data
- Seller store page (/marketplace/seller-products) shows public product listings only.
- Seller avatar, name, KYC verification status, and Trust Score are publicly visible.
- Seller's email, phone, and address are never exposed.
🔗 QR Code & Sharing
- Each product has a unique QR code. QR page is public — anyone with the link can view.
- Ordering requires login for buyer protection.
📤 Data Export & Portability
- Sellers can export: Products, Orders, Analytics reports (CSV/PDF).
- Buyers can export: Order history, Invoices (PDF).
- Complete account data export available via admin request.
⏱️ Data Retention
- Active account data: Retained indefinitely while account is active.
- Chat messages: 90 days, then auto-deleted.
- Deleted products: Images removed from Cloudinary immediately.
- Deleted account: All data permanently deleted within 30 days, except where legally required or for fraud prevention.
- Banned users: Aadhar/PAN permanently retained to prevent re-registration.
🔐 Third-Party Services
- Cloudinary: Image storage (Products, Reviews, KYC). Enterprise-grade security.
- MongoDB Atlas: Database hosting with encryption at rest.
- Socket.io: Real-time chat (messages not stored by third party).
- WebRTC: Peer-to-peer calls (no server storage).
- No data sold or shared with advertisers or analytics companies for marketing.
9 🤖 Telegram Bot Data Privacy
What We Store MINIMAL
- Bot Token (encrypted), Chat ID, Username (optional), Alert preferences, Command logs (30 days)
What We DON'T Access
- Your Telegram messages, contacts, groups, or other bots
Security
- Token encrypted. Chat ID verified. Commands access only your data. No cross-user access.
Control
- Connect/disconnect anytime. /disconnect instant. All bot data deleted on disconnect. Alert settings customizable.
10 👑 Admin Bot & Support Privacy
Admin Access RESTRICTED
- Admin views platform-level stats only. Can view KYC docs for verification.
- Cannot view your invoices, product details, expense records, profile photos, or personal messages.
- All admin actions logged and auditable.
Support Tickets DATA
- Ticket content, category, status stored securely.
- Used for issue resolution only. Retained for 1 year.
- Admin replies visible to ticket creator only.
11 💰 Expense Tracking Privacy
Information We Collect
Expense Data: Amount, category, description, date, payment mode, and bill/receipt images for your business.
Uploaded Content
Expense Bill Images: Stored on secure cloud servers (Cloudinary). Only you can view them. Deleting an expense record permanently removes the associated image.
How We Use Your Data
Financial Reports: Combined with invoice data to provide profit/loss calculations and PDF reports.
Data Security
Encrypted and stored securely. Never shared with third parties.
Your Control
View, edit, or delete any expense record anytime. Export data as PDF.
12 👤 Profile & Account Privacy
Information We Collect
Profile Data: Full name, DOB, gender, optional business details (GST, address). Email/mobile collected at registration and cannot be changed.
Uploaded Content
Profile Photos & Business Logo: Stored on Cloudinary. Only you can view/manage. Removed photos/logos are permanently deleted. JPG, PNG, WebP, max 5MB.
How We Use Your Data
Personalize experience, display identity, pre-fill invoices, generate tax-compliant documents. Business logo appears on invoice PDFs, marketplace store, and seller dashboard.
Data Security
Encrypted and stored securely. Never shared with third parties.
Two-Factor Authentication (2FA)
Encrypted secret key and hashed backup codes stored. 2FA codes never stored. Deleted on account deletion.
Account Deletion
Permanently delete from /delete-account. Password required (+2FA if enabled). All data including profile, products, invoices, KYC, chats, orders, expenses are removed. Cannot be undone.
Your Control
Edit profile anytime. Email/mobile locked. Upload or remove photo/logo anytime. Delete account in Danger Zone.
13 📄 Data Retention
| Data Type | Retention | Deletion |
|---|---|---|
| Account Info | Until deletion | On request |
| Products | Until deletion | On request |
| Invoices | 7 years (legal) | After 7 years |
| KYC Documents | Until deletion | On request / 30d |
| Ban Records / Document Lock | Permanent (fraud prevention) | Not deletable, but kept confidential |
| Trust Score | Until KYC withdrawal | On KYC withdrawal/deletion |
| Analytics | 12 months | Rolling deletion |
| Chat Messages | 90 days | Rolling deletion |
| Bot Tokens | Until disconnect | On disconnect |
| Bot Logs | 30 days | Rolling deletion |
| Support Tickets | 1 year | Rolling deletion |
| IP Logs | 90 days | Rolling deletion |
| Expense Records | Until deletion | On request |
| Expense Bill Images | Until expense deleted | On expense deletion |
| Profile Photos | Until removal | On removal |
| Profile Data | Until account deletion | On account deletion |
| UPI/Payment Info (Referral/Refund) | Until account deletion / 7 years for payout records | On account deletion / legal retention |
Deleting an account removes personal/account data according to the stated deletion process, except information that must be retained where required for legal compliance, fraud prevention, security, dispute resolution, or other legitimate/legal requirements.
14 🔒 Your Rights under DPDP Act 2023
Under the Digital Personal Data Protection Act (DPDP Act) 2023, you have the following rights:
- Right to Access: Request a copy of your personal data. Contact admin@covexa.in.
- Right to Correction: Update inaccurate data anytime from Profile.
- Right to Erasure: Delete your account or email us. Data removed within 30 days, except legal/security retention.
- Right to Withdraw Consent: Withdraw consent anytime. Deletion follows retention policy.
- Right to Grievance Redressal: Contact Grievance Officer at admin@covexa.in.
- Right to Nominate: Nominate another person in case of death or incapacity.
15 🔗 Third-Party Services & Backup
Billexa uses the following trusted service providers to store and process data:
- MongoDB Atlas – Primary database storage (India region). Encrypted at rest and in transit.
- Cloudinary – Storage for KYC docs, product images, expense bills, profile photos/logos. Enterprise encryption.
- GitHub – Automated encrypted backups of database dumps (private repositories).
- MEGA (mega.nz) – Encrypted cloud backup storage. End-to-end encryption. Backups auto-deleted after 90 days. MEGA Privacy Policy.
- Render – Web application hosting platform.
- OpenRouter / AI Providers – For AI Assistant queries (see Section 20).
Billexa does not sell personal data or share it with third parties for advertising or marketing purposes. Data may be processed through these providers as necessary to operate, secure, and provide the services.
16 📊 Privacy Comparison
| Feature | Billing | Marketplace | Orders | Telegram | KYC | Analytics | Expenses | Profile | Ban/Lock | Trust Score |
|---|---|---|---|---|---|---|---|---|---|---|
| Data Stored | ✅ | ✅ | ✅ | ✅ Token | ✅ Docs | ✅ Stats | ✅ Records | ✅ Info | ✅ Locked | ✅ Score |
| Encrypted | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ |
| Exportable | ✅ CSV | ✅ CSV | ✅ CSV/PDF | ❌ | ✅ CSV/PDF | ❌ | ❌ | ❌ | ||
| Deletable | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ❌ Permanent | ✅ |
| Shared? | ❌ | Listing public | Seller sees address | ❌ | Admin only | ❌ | ❌ | ❌ | ❌ | Buyer visible |
| Self-Manage | N/A | N/A | N/A | ✅ Disconnect | ✅ Withdraw | N/A | N/A | ✅ Delete | ❌ Appeal only | ✅ Auto |
17 📞 Contact for Privacy Concerns
Grievance Officer (IT Act 2000 & GDPR)
- Name: Shiv Kumar
- Email: admin@covexa.in
- Phone: +91 9351256357
- Address: Arwar, Ajmer, Rajasthan
⏱️ Response: 24-48 hours. Urgent: "URGENT: Privacy Concern" in subject or /support on Telegram.
18 🔨 Ban & Document Lock Privacy
18.1 What Happens When Banned
- 🚫 Immediate account suspension - cannot login
- 🔒 All KYC documents (Aadhar, PAN, photos) permanently locked
- 🚫 Aadhar & PAN numbers blocked from future use
- 📦 Marketplace products removed
- 💬 All active chats & orders terminated
18.2 Document Locking PERMANENT
When banned for valid reasons, your Aadhar and PAN numbers are permanently locked in our system for fraud prevention and to prevent banned users from creating duplicate accounts. This means:
- No other account can register with the same Aadhar number
- No other account can use the same PAN number
- Document images are flagged and cannot be re-uploaded
Locked KYC information remains confidential and is NOT publicly visible. It is only used to enforce platform security and prevent fraud.
18.3 Data After Ban
- KYC documents retained for legal/compliance and fraud prevention purposes
- Document numbers stored in locked state
- Personal data handled as per Data Retention policy (Section 13)
18.4 Unban & Data Recovery
If unbanned after appeal, documents are unlocked and account restored. Contact admin@covexa.in for ban appeals.
19 ⭐ Seller Trust Score Privacy
19.1 What We Calculate
Trust Score is calculated automatically based on marketplace activity: KYC status, products listed, sales, and delivery performance.
19.2 Data Used
Only your own marketplace data is used. We do NOT access other sellers' data or external financial data.
19.3 Score Visibility
- ✅ Visible to buyers on product detail pages.
- ✅ Visible to you on your KYC page.
- ❌ NOT shared with third parties.
- ❌ Does NOT expose private KYC information, Aadhaar, or PAN.
19.4 Auto-Update Schedule
Trust scores update automatically every midnight.
19.5 Score Deletion
Deleted when you delete your account or withdraw KYC verification.
20 🤖 AI Assistant Privacy
20.1 What We Collect
- Query Content: Your questions/messages sent to the AI assistant.
- Usage Data: Daily query count for rate limiting (10 guest, 30 registered, unlimited admin).
- Response Data: AI-generated replies (not stored long-term).
20.2 What We DON'T Collect
- ❌ Your personal identity is NOT sent to AI providers.
- ❌ Your business data (invoices, products, expenses) is NOT shared.
- ❌ Your account password or sensitive details.
- ❌ Chat history is NOT stored permanently.
20.3 Third-Party AI Providers
Queries are processed through OpenRouter API, which may route to models like Google Gemini, Meta Llama, or Mistral AI. These providers do NOT use your queries for training. Data is transmitted securely via HTTPS.
20.4 Data Storage & Security
- Query count stored in MongoDB for rate limiting.
- Query content NOT stored after response is generated.
- All AI API calls encrypted via HTTPS.
- Rate limit resets daily at midnight IST.
20.5 Your Control
- AI assistant is optional - use it only when needed.
- No personal data tied to AI queries.
- Query logs purged daily.
20.6 Data Retention
- Query Count: 24 hours (resets midnight).
- Query Content: Not stored.
- AI Responses: Not stored.
21 📝 Login History Privacy
21.1 What We Track
Billexa maintains a login history for account security. Each login attempt records: IP Address, Browser & OS, Device Type, Timestamp, Success/Failure, New Device Flag.
21.2 What We DON'T Track
- ❌ Your exact physical location (GPS)
- ❌ Your browsing activity outside Billexa
- ❌ Your device's unique ID or serial number
21.3 Purpose
- 🔍 Help you monitor account activity
- 🚨 Detect suspicious or unauthorized access
- 🛡️ Protect against hacking attempts
21.4 Your Control
- ✅ View at /login-history
- ✅ Clear history with one click
- ✅ Last 50 records retained (max)
21.5 Data Retention
- Maximum 50 login records stored
- Older records automatically removed
- Cleared history is permanently deleted
21.6 Admin Alerts
For admin accounts only, Telegram alerts are sent for new device logins, lockouts, and successful logins. Normal users do NOT receive these.
22 🔐 Two-Factor Authentication Privacy
22.1 What is 2FA?
Two-Factor Authentication adds extra security. After password, a 6-digit code from an authenticator app is required based on your configured threshold.
22.2 What We Store
- 🔑 Encrypted Secret Key — Used to verify 6-digit codes
- 🎫 Backup Codes — 8 one-time use codes (securely stored)
- 📅 Setup Date — When 2FA was enabled
- 📊 Daily Login Count — For Smart 2FA threshold tracking
- ⚙️ Threshold Setting — Your configured login limit (default: 3)
22.3 What We DON'T Store
- ❌ Your authenticator app data — stored only on your device
- ❌ Your 6-digit codes — one-time, never stored
- ❌ Login timestamps linked to 2FA — only daily count
22.4 Available for ALL Users
- ✅ 2FA is available for ALL users — Admin + Normal Users
- 👤 Enable from /setup-2fa
- 🔒 No 2FA data collected for users who haven't enabled it
22.5 Smart 2FA System
- 📊 Daily login counter tracks logins per day
- 🔄 Counter resets automatically at midnight IST
- 🔢 Default threshold: 3 free logins (4th needs 2FA)
- ⚙️ Users can change threshold: 1-20 logins
22.6 Data Security
- 🔐 Secret key stored securely in database
- 🔐 Backup codes stored with one-way protection
- 🔐 All 2FA data permanently deleted when you disable 2FA
- 🔐 All 2FA data deleted on account deletion
22.7 Backup Codes
- 🎫 8 backup codes generated during setup
- 🔢 Format: XXXX-XXXX
- ✅ Each code works only once
- ⚠️ Lost backup codes cannot be recovered
22.8 Your Control
- ✅ Enable/disable anytime at /setup-2fa
- ✅ Change threshold (1-20)
- ✅ All 2FA data deleted on account deletion
22.9 Lockout Protection
- 🔒 After 5 failed attempts → 15-minute lock
- ⏰ Auto-unlock after 15 minutes
- ✅ Successful 2FA resets counter
23 🔑 Password Recovery Privacy
23.1 Forgot Password Process
To reset your password, you must verify identity through: Username/Email, Registered Mobile Number, Date of Birth. All three must match.
23.2 Identity Verification Privacy
- 🔒 Failed verification does NOT reveal which field is wrong
- 🔒 Multiple failed attempts may trigger security review
- 🔒 We do NOT send passwords via email/SMS
- 🔒 No password reset links (prevents phishing)
23.3 Password Security
- 🔐 All passwords hashed with bcrypt (10 rounds)
- 🔐 Plain text passwords NEVER stored
- 🔐 Old password required for changes
23.4 Change Password (Logged In)
- 🔒 Current password required
- 🔒 New password must be 6+ characters
- 🔒 Session remains active after change
23.5 Account Recovery Limitations
- ⚠️ Email and mobile cannot be changed after registration
- ⚠️ Lost access to both = account may be unrecoverable
24 ⏱️ Rate Limiting & Privacy
24.1 What We Track
- 🌐 IP Address
- 🔢 Request Count
- 🕐 Timestamp
- 🛤️ Route Path
24.2 What We DON'T Track
- ❌ Personal identity
- ❌ Request content or payload data
- ❌ Browsing history
24.3 Data Storage
- Counters stored in memory only
- Data automatically expires after time window
- No permanent storage
24.4 Current Limits
| Route | Limit | Window |
|---|---|---|
| Login / Register | 5 | 15 min |
| KYC Upload | 3 | 1 hour |
| Support / Feedback | 5 | 30 min |
| Delete Account | 2 | 1 hour |
| General API | 100 | 15 min |
| All Routes | 50 | 15 min |
24.5 Your Privacy
- 🔒 Rate limit data never shared
- 🔒 No personal information stored
- 🔒 IP addresses not logged permanently
24.6 Data Retention
- Counters: Auto-deleted after window
- No permanent records
25 🎁 Referral Program Privacy
We collect only essential data to process your referral rewards. Your UPI ID is encrypted and never shared with other users.
25.1 Data We Collect
| Data Type | Purpose | Retention |
|---|---|---|
| 💳 UPI ID | For sending referral payouts only | Until account deletion |
| 🔗 Referral Code | Unique identifier | Until account deletion |
| 👥 Referral Records | Who referred whom | Until account deletion |
| 📊 Condition Progress | UPI, Email, KYC, Product, 7 Days status | Until account deletion |
| 💰 Payout History | UTR numbers, amounts, dates | 7 years (legal) |
| 📋 UPI History | Previous UPI IDs (admin only) | Max 20 records |
25.2 What We DON'T Collect
- ❌ Bank account numbers or IFSC codes (except for refunds)
- ❌ UPI PIN, passwords, or OTPs
- ❌ Payment gateway credentials
25.3 How Data is Used
- ✅ UPI ID used exclusively for referral rewards
- ✅ UTR number shared with referrer after payment
- ✅ UPI change history logged for security (admin only)
25.4 Eligibility Conditions (5)
- 💳 UPI ID Set
- 📧 Email Verified
- 🛡️ KYC Verified (Aadhar + PAN)
- 📦 At least 1 Product Added
- 📅 Account 7 Days Old
25.5 Data Visibility
Your UPI ID, referral status, and condition progress are visible only to you and admin. UTR number visible to you. UPI history visible only to admin.
25.6 Data Retention
- Referral records: until account deletion
- UPI ID: deleted on account deletion
- UPI History: max 20 records
- Payout history: 7 years (legal compliance)
25.7 Your Rights
- ✏️ Edit UPI ID anytime
- 👁️ View condition progress
- 🗑️ Delete all data by deleting account
- 🔒 UPI ID never shared with other users
26 🔒 Single Session Protection
26.1 What is Single Session?
Single Session Protection ensures your account can only be actively used on one device or browser at a time. Logging in on a new device terminates the previous session.
26.2 How It Works
- 🔐 One Active Session
- 🔄 Auto-Detection every 30 seconds
- ⚠️ Instant Alert with popup
- 🔑 Redirected to login page
26.3 What We Track
- Session ID
- Session Timestamp
- Active Status
26.4 What We DON'T Track
- ❌ GPS or exact physical location
- ❌ Browsing history
- ❌ Device files or personal data
- ❌ Keystrokes or form inputs
26.5 When Session Terminated
- 📱 New Login
- 🕐 Auto-Check mismatch
- 🔒 Manual Logout
- ⏰ Session Expiry (24 hours inactivity)
26.6 Data Security
- 🔐 Session ID stored securely
- 🔐 Encrypted HTTPS checks
- 🔐 No personal data in API calls
- 🔐 Session data auto-cleared on logout
26.7 Your Control
- ✅ Automatic — works by default
- ✅ No opt-out (security first)
27 🔥 Community Posts Privacy
27.1 What We Collect
- 📝 Post Content (text, images, links)
- 💬 Comment Content (text, timestamps)
- 👤 User Identity (name visible)
- ❤️ Like Data
- 📅 Timestamps
27.2 What We DON'T Collect
- ❌ Email or mobile — NEVER shared
- ❌ Location or IP linked to posts
- ❌ Browsing history
27.3 Content Visibility
- 🌐 All posts and comments are public.
- 👤 Name appears on posts/comments.
- 🖼️ Post images publicly visible.
27.4 Image Storage & Security
- ☁️ Stored on Cloudinary.
- 🔒 Encrypted in transit and at rest.
- 🗑️ Deleted post images permanently removed.
27.5 Data Control
- ✏️ Edit posts/comments anytime.
- 🗑️ Delete posts/comments anytime.
- 🔒 Account deletion removes all posts/comments.
27.6 Data Retention
- Active: until deleted by user/admin.
- Deleted posts: permanently removed with images.
- Deleted comments: soft-deleted for moderation.
28 🛒 Buyer Trust Score Privacy
28.1 What is Buyer Trust Score?
Buyers get a Trust Score (0-100) based on marketplace order behavior to help sellers evaluate reliability.
28.2 Data Used
- Total Orders Placed
- Completed Orders
- Cancelled Orders
- Returned Orders
- Total Amount Spent
- Account Age
28.3 What We DON'T Use
- ❌ Product details viewed
- ❌ Chat content
- ❌ Payment method or UPI details
- ❌ Browsing history
28.4 Score Visibility
- 👤 You (Buyer): ✅ AI Assistant, Profile
- 🏪 Seller: ✅ Only on Order Detail page for their orders
- 👥 Other Buyers/Public: ❌ Never visible
28.5 Buyer Badges
- 🏆 Trusted Buyer (90-100)
- ⭐ Premium Buyer (75-89)
- 👍 Verified Buyer (60-74)
- 👤 Regular Buyer (40-59)
- 🆕 New Buyer (0-39)
28.6 Data Retention
- 📁 Stats retained while account active
- 🗑️ Deleted on account deletion
- 📊 Only current score stored