PRIVACY POLICY
BIMAKART CONNECT
DEVELOPED BY 21 SPHERES | OPERATED BY INCIO FINTECH PRIVATE LIMITED
EFFECTIVE DATE: JANUARY 1, 2026
1. Introduction
- This Privacy Policy (“Policy”) describes how Incio Fintech Private Limited (“Company”, “we”, “our”) collects, uses, stores, discloses, and protects personal data when you use the Bimakart Connect mobile application (“App”).
- The App is developed and maintained by 21 Spheres, which acts only as a technology provider. 21 Spheres does not access, store, transfer, or process any user data.
- By using the App, you agree to this Privacy Policy.
2. Definitions
- “Personal Data” – Information that identifies an individual.
- “Sensitive Personal Data” – Aadhaar, PAN, KYC documents, identity proofs, insurance documents.
- “Processing” – Any operation performed on data (collection, storage, use, sharing).
- “Data Controller” – Incio Fintech Private Limited.
- “Developer” – 21 Spheres (no access to data).
- “DPDP Act” – Digital Personal Data Protection Act, 2023.
3. Roles and Responsibilities
-
Data Controller:
Incio Fintech Private Limited
S.NO. 1-11-1022, Kabra Nagar, Shivajinagar (Nanded),
Nanded, Maharashtra – 431602, India.
-
Developer:
21 Spheres acts only as a development and maintenance contractor and has no access to user data.
4. Information We Collect
-
Personal Information
- Name
- Email
- Phone number
- Address
- Date of birth
- And more.
-
Sensitive Personal Data
- Aadhaar
- PAN
- KYC documents
- Insurance policy documents
- Uploaded identity photos.
-
Device & Technical Data
- Device model
- OS version
- IP address
- Usage logs
- Crash logs
- Precise GPS location
- And More
-
Media & File Access
- Photos
- Camera access
- Uploaded files
- Storage
-
Financial Information
- Policy-related financial details (no card/UPI/bank data).
-
AI/LLM Processing
- Only policy text (never identity documents).
5. Purpose of Data Processing
We use your data to:
- Managing insurance policies
- identity verification
- customer support
- OTP and notifications
- Analytics
- fraud prevention
- AI-driven insights.
- Improve app performance and fix issues
6. Third-Party Processors
-
Firebase (Google)
- Authentication
- Firestore Database
- Analytics
- Crashlytics
- Temporary cloud storage
- Push notifications
-
Salesforce
- User profiles
- Identity documents
- KYC information
- Insurance data
- AWS – Backend/infrastructure hosting (India/US).
-
AI/LLM Providers (OpenAI, Gemini, Claude)
Receive only non-personal policy text, not identity data.
-
Insurance Partners
- Insurance companies
- Policy service partners
- No data is shared with aggregators or advertisers.
7. Legal Basis
- Consent
- Contractual necessity
- Legitimate interests
- Regulatory compliance.
8. Storage & Retention
- Stored on Salesforce, Firebase, AWS.
-
Retained permanently unless
- User requests deletion
- No longer needed
- Law requires otherwise.
9. Data Sharing
-
Shared with:
- insurance companies
- Service partners
- Analytics providers
- Cloud providers
- Analytics platforms
- LLM processors (policy content only)
- We do not sell user data.
10. International Transfers
- Data may be transferred outside India (primarily the US) in compliance with applicable laws and cloud provider safeguards.
11. Security Measures
-
We use:
- Encryption
- Access control
- Secured servers
- Firewalls
- Continuous monitoring
- Despite our efforts, no system is completely secure.
12. User Responsibility
-
You are responsible for:
- Keeping login credentials confidential
- Not sharing OTPs
- Using the App on secure devices
- Ensuring that uploaded documents are accurate and genuine
- Avoiding rooted/jailbroken devices
- The Company is not liable for damages resulting from user negligence.
13. Document Authenticity
- You must upload only accurate and genuine documents.
-
Misrepresentation, forged documents, or fraudulent submissions may result in:
- Account suspension
- Legal action
- Denial of services
- The Company is not responsible for incorrect or fraudulent user submissions.
14. Data Accuracy
- You are responsible for verifying your policy details and uploaded data.
-
The Company is not liable for:
- Errors caused by user-supplied documents
- Mistakes in manually entered information
- Misinterpretation of policy content
15. AI Limitations
-
AI-generated responses are:
- For support and informational purposes
- Not legally binding
- Not a replacement for official policy documents
- The Company does not guarantee the accuracy of AI-generated summaries.
16. Breach Notification
-
If a data breach is likely to harm users, we will notify:
- Affected users
- Relevant authorities (as applicable)
-
Notification may occur via:
- Email
- In-app alerts
- Website notices
17. User Rights
-
You may request:
- Access to your data
- Correction
- Deletion
- Withdrawal of consent
- Explanation of data processing
- Requests must be sent to: support@bimakart.in
18. Account Deletion & Archival
-
Upon requesting deletion:
- Personal data will be removed
- Certain data may remain archived if required by insurance regulations
- Audit logs may be retained to comply with legal obligations
- Deleted accounts cannot be recovered.
19. Children’s Privacy
- The App is strictly for users aged 18 and above. We do not knowingly collect data from minors.
20. Cookies & Tracking
-
The App uses:
- Firebase Analytics
- Crashlytics
- Device identifiers
- No advertising trackers are used.
21. Changes
- We may update this Policy periodically.
- Latest version will always be available through the App or website.
22. Grievance Redressal
-
Incio Fintech Private Limited
S.NO. 1-11-1022, Kabra Nagar, Shivajinagar (Nanded),
Nanded, Maharashtra – 431602, India
Email: support@bimakart.in
23. Liability
- Incio Fintech is the sole entity responsible for data handling.
- 21 Spheres has no access to any user data and holds no liability.
-
The Company is not liable for:
- User negligence
- Device compromise
- Incorrect uploaded documents
24. Governing Law
- This Policy is governed by the laws of India. Any disputes will be handled under Indian jurisdiction.