BuySure is operated by A Unit of Knovedad PVT LTD, A private limited company incorporated under the Companies Act, 2013, with its registered office at K-22, Lower Ground Floor, Near Vijay Sales, Lajpat Nagar, New Delhi - 110024 (“we”, “us”, “our”). This policy explains what personal data the app handles, why, and what control you have over it. It is written to meet the Digital Personal Data Protection Act, 2023 and Google Play's User Data policy.
1. Two kinds of people use this app
BuySure is business software. A registered business — a store, a buyback partner, a repair chain — subscribes to it and its staff use it to record purchases of pre-owned goods (mobile phones, laptops, appliances, and similar electronics) from walk-in customers.
| Who | Our role |
|---|---|
| Business account holders and their staff | We are the Data Fiduciary. We decide how your account, billing and usage data is handled, and this policy governs it directly. |
| Customers whose details a business records in the app | The business is the Data Fiduciary. We are a Data Processor acting on its instructions. We store and process the record; we do not decide what is collected or why. |
If you sold an item at a store and were asked for your ID: the store, not BuySure, is answerable for that collection. Ask them first. If you cannot reach them, write to us at prince.kumar@cashforphone.in and we will route your request to the correct business and support them in answering it.
2. What we collect
From business account holders
- Business name, contact name, email address and phone number
- Registered address, city and state
- GSTIN and CIN, where you provide them for invoicing
- Identity documents of the authorised signatory (Aadhaar, PAN or Driving Licence number, date of birth) submitted during business verification
- Company logo, if uploaded
- Wallet balance, top-up records and per-transaction usage charges
- Login credentials — passwords are stored only as a one-way hash and are never readable by us
From end customers, entered by the business
- Identity: full name, mobile number, email address, residential address, city, state and PIN code
- Document: document type (Aadhaar, PAN or Driving Licence), document number, name on the document, date of birth, gender and the address printed on the document
- Photographs: a photograph of the customer, a photograph of the identity document, photographs of the item, its retail box and original bill, and a screenshot confirming payment
- Item: category (phone, laptop, appliance, accessory), brand, model, colour, IMEI numbers or serial number, condition grade and warranty status
- Transaction: quoted value, final value, payment mode and payment reference
- Verification trail: the one-time password sent to the customer's mobile number and whether it was confirmed, plus the timestamp and result of any electronic signature
Automatically
- Server logs — request path, timestamp and error traces, kept for security and debugging
- App version and platform, used to support the correct build
We do not collect contacts, call logs, SMS content, browsing history, installed-app lists, microphone audio or continuous background location. We do not use advertising identifiers. There are no advertising or analytics-broker SDKs in this app.
3. Why we use it
- To deliver the service: creating a purchase record, generating the invoice PDF, and producing the signed document a business is legally expected to keep.
- To verify identity: confirming a customer's mobile number by OTP and, where the business enables it, validating an identity document against the issuing authority through our verification partner.
- To take a signature: sending the customer a secure link to review and electronically sign the purchase document.
- To bill correctly: deducting verification and e-signature charges from a business's prepaid wallet and maintaining a ledger of those deductions.
- To keep the service secure: detecting misuse, fraudulent records and unauthorised access.
- To meet legal obligations: retaining transaction records where tax or trade law requires it, and responding to lawful requests from authorities.
We never sell personal data, rent it, or share it with data brokers. We do not use it to train machine-learning models and we do not use it for advertising.
4. Who we share it with
Only with processors who need it to make a specific feature work, and only to the extent that feature requires:
| Recipient | What they receive and why |
|---|---|
| Amazon Web Services | All documents and photographs are stored in Amazon S3 in the Mumbai (ap-south-1) region. Objects are private; they are served only through short-lived signed links. |
| Manch | Identity document details for verification, and the unsigned purchase document plus the customer's name, mobile number and email for electronic signature. |
| SMS gateway partner | The customer's mobile number, to deliver the one-time password on templates registered under the TRAI DLT framework. |
| Email delivery partner | The customer's email address and name, to deliver the signature link and a copy of the completed document. |
| Payment gateway | Business billing details for wallet top-ups. Card and bank credentials go directly to the gateway; we never see or store them. |
We may also disclose data where compelled by law, court order or a valid request from a law-enforcement or regulatory authority, and to professional advisers or an acquiring entity in a merger or acquisition — in which case this policy continues to apply until you are told otherwise.
5. Permissions the app asks for
| Permission | Why |
|---|---|
| Camera | To photograph the customer, their identity document and the item being purchased. Used only while a capture screen is open. |
| Photos | To attach an existing image — usually a payment screenshot — to a record. We read only the files you pick. |
You can refuse or later withdraw any of these from your device settings. Refusing camera or photo access will prevent the parts of the flow that require an image.
6. How long we keep it
- Purchase records, documents and photographs are kept for as long as the business's account is active, and then for the period that Indian tax and commercial law requires records of a transaction to be preserved.
- Business account data is kept while the account is open and for up to 90 days after closure, so the account can be restored if closure was a mistake.
- Server logs are kept for up to 90 days.
- One-time passwords expire within minutes and the verification result — not the password — is what is retained.
When a business closes its account it may request deletion of its records. We will delete or irreversibly anonymise them within 30 days, except where a law requires us to keep a copy.
7. How we protect it
- All traffic runs over HTTPS/TLS. The API is served only over an encrypted connection.
- Files in Amazon S3 are private by default and encrypted at rest. They are reachable only through signed links that expire.
- Passwords are stored as salted one-way hashes.
- Sessions use signed tokens that expire; every request is scoped to the requesting business so one account can never read another's records.
- Access to production systems is restricted to named personnel who need it.
No system is perfectly secure. If a breach occurs that is likely to affect you, we will notify affected users and the Data Protection Board of India as the Digital Personal Data Protection Act, 2023 requires.
8. Your rights
Under the Digital Personal Data Protection Act, 2023 you may:
- Ask what personal data of yours we hold and how it has been processed
- Ask for correction of data that is inaccurate, or completion of data that is incomplete
- Ask for erasure, where no legal obligation requires us to keep it
- Withdraw consent you previously gave, without affecting processing already carried out
- Nominate someone to exercise these rights on your behalf if you die or become incapacitated
- Escalate an unresolved complaint to the Data Protection Board of India
Write to prince.kumar@cashforphone.in. We respond within 30 days. If you are an end customer rather than an account holder, see the note in section 1 — we will pass your request to the business that holds the record and help them act on it.
9. Children
BuySure is not offered to anyone under 18 and is not designed for children. Businesses using the app must not record a purchase from a minor. If we learn that a child's data has been recorded, we will delete it.
10. Where data is stored
All data is stored and processed in India. Some processors named in section 4 may route limited data through infrastructure outside India; where they do, we require contractual safeguards consistent with Indian law.
11. Changes
If we change this policy we will update the date at the top, and for material changes we will notify account holders in the app or by email before the change takes effect. Continuing to use BuySure after that means you accept the revised policy.
12. Contact
A Unit of Knovedad PVT LTD
K-22, Lower Ground Floor, Near Vijay Sales, Lajpat Nagar, New Delhi - 110024
Grievance Officer: Prince kumar
Email: prince.kumar@cashforphone.in
Privacy queries: info@cashforphone.in
Support: info@cashforphone.in · 8800880101
BuySure