Legal & Privacy

Privacy Policy for
Soni Pannalal Bhojraj

App: Soni Pannalal Bhojraj Bullion Effective: 10 April 2026 Last Updated: 10 April 2026

This Privacy Policy explains how Soni Pannalal Bhojraj ("we", "our", "us") collects, uses, stores, and protects your information when you use our mobile app, backend services, and push notifications. By using the app, you agree to the practices described in this policy.

1

Information We Collect

Account & Profile
  • Full name, email address, mobile number, and password (stored in hashed form)
  • WhatsApp number and country code (optional — only if provided during registration)
  • User role (trader / admin) and account approval status
Business & Tax Information
  • Firm name, firm address, city, state, and pincode
  • PAN number (optional), GST number (optional), and Aadhaar number (optional) — collected only if provided during registration
  • Bank account details including account name, number, IFSC code, and branch (optional)
KYC & Document Uploads
  • PAN card, Aadhaar card, bank proof, profile photo, GST certificate, firm registration, and trade license
  • Document metadata: type, filename, storage key, upload timestamp, and verification status
App Activity Data
  • Rate view history, news reads, and account activity timestamps
  • Operational remarks and admin actions on accounts
Device & Technical Data
  • Push notification token (FCM token) and device registration details
  • Device ID, name, platform, model, OS version, app version, and build number
  • IP address, user agent, and last-seen timestamp
Local App Storage
  • Authentication token and current user profile stored locally on your device for session continuity
2

How We Use Your Data

  • Create and manage your account, and authenticate access to the app
  • Process onboarding, KYC review, and account approval workflows
  • Display live bullion rates, market news, and bank information
  • Deliver push notifications for market alerts and account updates
  • Maintain registered device tokens for notification delivery
  • Protect platform security, detect abuse, and enforce rate limits
  • Maintain, troubleshoot, and improve app performance and reliability
3

Legal Bases for Processing

Depending on your jurisdiction, we process personal data under one or more of the following legal bases:

  • Contract performance — processing required to provide the app and services you signed up for
  • Legal obligations — compliance with applicable Indian laws and regulations
  • Legitimate interests — platform security, fraud prevention, and service operations
  • Consent — optional permissions such as push notifications, which you can withdraw at any time
4

App Permissions & Device Access

  • Push Notifications — sends market updates and account alerts. You can disable this in your device settings at any time.
  • Camera — used to capture KYC and verification documents during onboarding.
  • Media Library / File Access — used to select and upload KYC and business documents.
  • Internet / Network Access — required to communicate with backend APIs, pricing, and notification services.
  • Vibration & Notification Support — used for notification behavior on supported Android devices.
We request only the permissions required for core app functionality. No access to contacts, microphone, or location is requested.
5

Third-Party Services

We do not sell your personal information. We share data only with service providers necessary to operate the app:

  • Cloud Infrastructure — secure database and API backend hosting (AWS)
  • Document Storage — cloud object storage for KYC and business document uploads
  • Push Notifications — Firebase Cloud Messaging (FCM) for delivery of alerts and updates

All third-party providers are bound by data processing agreements. We may also disclose information when required by law, legal process, or to protect the rights and security of our users and platform.

6

Data Retention

We retain your data for as long as necessary to provide services, meet legal compliance requirements, resolve disputes, and enforce our terms:

  • Account data — retained for the lifetime of the account and a reasonable period after deletion
  • KYC documents — retained as required under applicable regulatory obligations
  • Activity records — retained for audit and compliance purposes
  • Device & log data — retained for a limited period for security monitoring
7

Security Practices

We implement technical and organisational measures to protect your data against unauthorised access, loss, or disclosure:

🔒 TLS 1.2+ Encryption in Transit
🗝️ Password Hashing (bcrypt)
🛡️ JWT-Based Authentication
🚦 API Rate Limiting
☁️ Encrypted Cloud Storage
🔐 Security Middleware (Helmet)
No method of transmission or storage is completely secure. While we apply best-practice safeguards, we cannot guarantee absolute security. Report any suspected vulnerabilities to spb.jodhpur@gmail.com.
8

Your Rights

👁️
Access
Request a copy of the personal data we hold about you.
✏️
Correction
Update or correct inaccurate profile information via the app or by contacting support.
🗑️
Deletion
Request account deletion, subject to applicable legal and compliance obligations.
🔕
Opt-Out
Disable push notifications at any time through your device settings.
📋
Portability
Request a structured export of your personal data where applicable by law.
🚫
Object
Object to processing of your personal data for specific purposes where permitted.
To exercise any of these rights, contact us at spb.jodhpur@gmail.com. We will respond within 30 days.
9

Children's Privacy

This app is intended exclusively for adult business users engaged in bullion and jewellery operations. We do not knowingly collect personal information from individuals under the age of 18. If we become aware that a minor has provided personal data, we will delete it promptly.

10

International Data Transfers

Your data may be processed and stored in regions where our infrastructure and service providers (including AWS) operate. By using the app, you acknowledge that your data may be transferred outside your local jurisdiction, subject to appropriate safeguards consistent with applicable data protection laws.

11

Changes to This Policy

We may update this Privacy Policy from time to time. Updated versions will be posted with a revised "Last Updated" date. Material changes may be communicated through the app or by email. Continued use of the app after updates constitutes your acceptance of the revised policy.

12

Contact Us

For privacy questions, data requests, or concerns, reach us through any of the following:

📞
Phone
✉️
Email
📍
Registered Address
SONI PANNALAL BHOJRAJ · Bullion & Jewellery
Amli Ka Bas, Chowk Ka Chowk
Jodhpur – 342001, Rajasthan, India