Privacy Policy
Last updated: 30 July 2026 · Version 1.0
1. Who we are
I'd Buy That ("the Platform") is operated by BTG Production Pvt. Ltd., a company registered in India with its registered office at 47/G Tellia Vaddo, Bastora, Bardez, Goa, India ("we", "us"). We are the data fiduciary under India's Digital Personal Data Protection Act, 2023 ("DPDP Act") and the data controller under the EU General Data Protection Regulation ("GDPR") for the personal data described here. Contact: TODO-your-contact@example.com.
2. What we collect
Account data: email address, password (stored as a hash by our authentication provider — we never see it), handle, display name, and optional bio and expertise tags. Content you create: projects, artwork images, reviews, verdicts, price anchors, ratings, and reports. Activity data: coin ledger entries, stakes, streaks, league points, and timestamps of your actions. Technical data: IP address and device information processed by our infrastructure providers for security and delivery.
We do not collect payment information, government identifiers, or precise location. We do not use advertising trackers.
3. Why we process it (purposes and legal bases)
To provide the service — accounts, publishing projects, reviews, the coin/league system (GDPR: performance of contract, Art. 6(1)(b); DPDP: consent given at sign-up). To keep the Platform safe — fraud prevention, rate limiting, moderation of reported content (GDPR: legitimate interests, Art. 6(1)(f)). To comply with legal obligations where applicable (Art. 6(1)(c)). We do not use your data for automated decisions with legal effect, and we do not sell personal data.
4. What is public
Your handle, display name, bio, published projects and artwork images, accepted reviews (with your handle), verdicts, aggregate demand scores, and league standings are publicly visible — that is the purpose of the Platform. Your email, coin ledger, individual stakes, and streaks are private to you.
5. Who processes it for us
We use Supabase (database, authentication, file storage) and Netlify (hosting/CDN) as processors. Data is hosted in the Supabase region we have selected: TODO — your Supabase region. Where personal data of EU users is transferred outside the EEA, transfers rely on the processors' Standard Contractual Clauses and equivalent safeguards. Where data of Indian users is transferred outside India, we do so in accordance with the DPDP Act.
6. How long we keep it
Account and content data are kept while your account exists. When you delete your account, your profile, projects, images, reviews, coins, stakes, and league records are permanently erased. Reports you filed are retained in de-identified form. Residual copies in encrypted backups are purged on the backup rotation cycle of our processors (typically ≤ 30 days).
7. Your rights
Everyone: you can access and correct your data in-app, and permanently delete your account (and all associated data) from your dashboard at any time. EU users (GDPR): you additionally have the rights of access, rectification, erasure, restriction, portability, and objection (Articles 15–21), and the right to lodge a complaint with your supervisory authority. India users (DPDP Act): you have the rights to access information about processing, correction and erasure, grievance redressal, and to nominate another individual to exercise your rights. To exercise any right not available in-app, email TODO-your-contact@example.com; we respond within the timelines required by law.
8. Grievance Officer (India)
As required under Indian law, our Grievance Officer is: TODO — Grievance Officer full name, TODO-your-contact@example.com, 47/G Tellia Vaddo, Bastora, Bardez, Goa, India. Grievances are acknowledged and addressed within the statutory period.
9. Children
The Platform is for users 18 years or older. We do not knowingly process children's data. If you believe a minor has created an account, contact us and we will delete it.
10. Cookies
We use only strictly necessary cookies: authentication session cookies set by our identity provider. We do not use analytics or advertising cookies. If that changes, we will update this policy and request consent where required.
11. Security
Data is encrypted in transit (TLS) and at rest by our processors. Access to personal data is protected by row-level security in our database, and coin/score records cannot be modified by users. In the event of a personal data breach we will notify the relevant authorities and affected users as required by the GDPR and the DPDP Act.
12. Changes
We will post updates to this policy here and update the date above. Material changes will be announced in-app.
This document is a draft prepared for review by qualified counsel and is not legal advice.