PRIVACY POLICY

BIMAKART CONNECT

DEVELOPED BY 21 SPHERES | OPERATED BY INCIO FINTECH PRIVATE LIMITED

EFFECTIVE DATE: JANUARY 1, 2026

1. Introduction

  1. This Privacy Policy (“Policy”) describes how Incio Fintech Private Limited (“Company”, “we”, “our”) collects, uses, stores, discloses, and protects personal data when you use the Bimakart Connect mobile application (“App”).
  2. The App is developed and maintained by 21 Spheres, which acts only as a technology provider. 21 Spheres does not access, store, transfer, or process any user data.
  3. By using the App, you agree to this Privacy Policy.

2. Definitions

  1. “Personal Data” – Information that identifies an individual.
  2. “Sensitive Personal Data” – Aadhaar, PAN, KYC documents, identity proofs, insurance documents.
  3. “Processing” – Any operation performed on data (collection, storage, use, sharing).
  4. “Data Controller” – Incio Fintech Private Limited.
  5. “Developer” – 21 Spheres (no access to data).
  6. “DPDP Act” – Digital Personal Data Protection Act, 2023.

3. Roles and Responsibilities

  1. Data Controller:
    Incio Fintech Private Limited
    S.NO. 1-11-1022, Kabra Nagar, Shivajinagar (Nanded),
    Nanded, Maharashtra – 431602, India.
  2. Developer:
    21 Spheres acts only as a development and maintenance contractor and has no access to user data.

4. Information We Collect

  1. Personal Information
    1. Name
    2. Email
    3. Phone number
    4. Address
    5. Date of birth
    6. And more.
  2. Sensitive Personal Data
    1. Aadhaar
    2. PAN
    3. KYC documents
    4. Insurance policy documents
    5. Uploaded identity photos.
  3. Device & Technical Data
    1. Device model
    2. OS version
    3. IP address
    4. Usage logs
    5. Crash logs
    6. Precise GPS location
    7. And More
  4. Media & File Access
    1. Photos
    2. Camera access
    3. Uploaded files
    4. Storage
  5. Financial Information
    1. Policy-related financial details (no card/UPI/bank data).
  6. AI/LLM Processing
    1. Only policy text (never identity documents).

5. Purpose of Data Processing

We use your data to:

  1. Managing insurance policies
  2. identity verification
  3. customer support
  4. OTP and notifications
  5. Analytics
  6. fraud prevention
  7. AI-driven insights.
  8. Improve app performance and fix issues

6. Third-Party Processors

  1. Firebase (Google)
    1. Authentication
    2. Firestore Database
    3. Analytics
    4. Crashlytics
    5. Temporary cloud storage
    6. Push notifications
  2. Salesforce
    1. User profiles
    2. Identity documents
    3. KYC information
    4. Insurance data
  3. AWS – Backend/infrastructure hosting (India/US).
  4. AI/LLM Providers (OpenAI, Gemini, Claude)
    Receive only non-personal policy text, not identity data.
  5. Insurance Partners
    1. Insurance companies
    2. Policy service partners
  6. No data is shared with aggregators or advertisers.

7. Legal Basis

  1. Consent
  2. Contractual necessity
  3. Legitimate interests
  4. Regulatory compliance.

8. Storage & Retention

  1. Stored on Salesforce, Firebase, AWS.
  2. Retained permanently unless
    1. User requests deletion
    2. No longer needed
    3. Law requires otherwise.

9. Data Sharing

  1. Shared with:
    1. insurance companies
    2. Service partners
    3. Analytics providers
    4. Cloud providers
    5. Analytics platforms
    6. LLM processors (policy content only)
  2. We do not sell user data.

10. International Transfers

  1. Data may be transferred outside India (primarily the US) in compliance with applicable laws and cloud provider safeguards.

11. Security Measures

  1. We use:
    1. Encryption
    2. Access control
    3. Secured servers
    4. Firewalls
    5. Continuous monitoring
  2. Despite our efforts, no system is completely secure.

12. User Responsibility

  1. You are responsible for:
    1. Keeping login credentials confidential
    2. Not sharing OTPs
    3. Using the App on secure devices
    4. Ensuring that uploaded documents are accurate and genuine
    5. Avoiding rooted/jailbroken devices
  2. The Company is not liable for damages resulting from user negligence.

13. Document Authenticity

  1. You must upload only accurate and genuine documents.
  2. Misrepresentation, forged documents, or fraudulent submissions may result in:
    1. Account suspension
    2. Legal action
    3. Denial of services
  3. The Company is not responsible for incorrect or fraudulent user submissions.

14. Data Accuracy

  1. You are responsible for verifying your policy details and uploaded data.
  2. The Company is not liable for:
    1. Errors caused by user-supplied documents
    2. Mistakes in manually entered information
    3. Misinterpretation of policy content

15. AI Limitations

  1. AI-generated responses are:
    1. For support and informational purposes
    2. Not legally binding
    3. Not a replacement for official policy documents
  2. The Company does not guarantee the accuracy of AI-generated summaries.

16. Breach Notification

  1. If a data breach is likely to harm users, we will notify:
    1. Affected users
    2. Relevant authorities (as applicable)
  2. Notification may occur via:
    1. Email
    2. In-app alerts
    3. Website notices

17. User Rights

  1. You may request:
    1. Access to your data
    2. Correction
    3. Deletion
    4. Withdrawal of consent
    5. Explanation of data processing
  2. Requests must be sent to: support@bimakart.in

18. Account Deletion & Archival

  1. Upon requesting deletion:
    1. Personal data will be removed
    2. Certain data may remain archived if required by insurance regulations
    3. Audit logs may be retained to comply with legal obligations
  2. Deleted accounts cannot be recovered.

19. Children’s Privacy

  1. The App is strictly for users aged 18 and above. We do not knowingly collect data from minors.

20. Cookies & Tracking

  1. The App uses:
    1. Firebase Analytics
    2. Crashlytics
    3. Device identifiers
  2. No advertising trackers are used.

21. Changes

  1. We may update this Policy periodically.
  2. Latest version will always be available through the App or website.

22. Grievance Redressal

  1. Incio Fintech Private Limited
    S.NO. 1-11-1022, Kabra Nagar, Shivajinagar (Nanded),
    Nanded, Maharashtra – 431602, India
    Email: support@bimakart.in

23. Liability

  1. Incio Fintech is the sole entity responsible for data handling.
  2. 21 Spheres has no access to any user data and holds no liability.
  3. The Company is not liable for:
    1. User negligence
    2. Device compromise
    3. Incorrect uploaded documents

24. Governing Law

  1. This Policy is governed by the laws of India. Any disputes will be handled under Indian jurisdiction.