Privacy Policy
Last updated: 16 March 2026 · Compliant with DPDP Act 2023 & IT Act 2000
1. Who We Are
Baniya Network of India ("we", "BNI", "the Platform") is operated by Baniya Network of India (baniyanetworkindia@gmail.com). We are a unified community platform for the Hindu Vaishya business community across India, accessible at baniyanetwork.com.
2. Data We Collect
We collect only what is necessary to operate the platform:
- Identity data: Name, phone number, email address
- Business data: Business name, type, city, state, community
- KYC data: PAN details (Level 1), DigiLocker documents (Level 2) — only with explicit consent
- Usage data: Referrals made, barter activity, pitches submitted
- Communication data: OTP verification records (deleted after 1 hour)
3. How We Use Your Data
- To create and manage your member account
- To verify your identity (phone OTP, KYC)
- To show your profile in the business directory (name, business, city — with your consent)
- To facilitate referrals, barter matches, and Shark Tank connections
- To send you community briefings and important platform updates
- To comply with legal obligations under Indian law
We do not sell your data. We do not use it for advertising profiles.
4. Legal Basis (DPDP Act 2023)
Under India's Digital Personal Data Protection Act 2023, we process your data based on:
- Consent: You provide explicit consent at enrollment and for each KYC level
- Legitimate use: Operating the platform and providing community services
- Legal obligation: Grievance redressal (IT Rules 2021), KYC compliance
5. Data Sharing
We share data only with:
- Supabase (Postgres): Secure cloud database (SOC 2 certified)
- Twilio: OTP delivery via SMS (data processed per their privacy policy)
- Vercel: Platform hosting (data processed in their secure infrastructure)
- Anthropic / Google: AI content generation — we do not send personal member data to AI models
6. Your Rights (DPDP Act 2023)
As a data principal, you have the right to:
- Access: Request a copy of your personal data
- Correction: Correct inaccurate or incomplete data
- Erasure: Request deletion of your account and data
- Nomination: Nominate a representative for data rights
- Grievance redressal: File a complaint with our Grievance Officer
To exercise any right, email us at baniyanetworkindia@gmail.com. We respond within 72 hours.
7. Data Retention
- OTP records: deleted within 1 hour of creation
- Active member data: retained while your account is active
- Post-deletion: data purged within 30 days, except records required by law
8. Security
We use industry-standard security: HTTPS-only connections, password-hashed OTPs, HTTP-only session cookies, server-side admin access only (service role keys never exposed to browsers), and role-based database access policies.
9. Cookies
We use one session cookie (bni_session) to keep you signed in. It is HTTP-only, secure, and expires in 30 days. We do not use tracking or advertising cookies.
10. Grievance Officer
In accordance with IT Rules 2021 and DPDP Act 2023:
Grievance Officer: Baniya Network Admin
Email: baniyanetworkindia@gmail.com
Response time: Acknowledgement within 24 hours · Resolution within 15 days
11. Changes to This Policy
We may update this policy. Material changes will be notified via SMS or email to registered members at least 7 days before taking effect.