Privacy Policy

    Last updated: June 2, 2026

    Template notice: This document is a working draft aligned with India's Digital Personal Data Protection Act 2023 and the IT (Reasonable Security Practices) Rules 2011. It is not legal advice. Please have a qualified Indian technology lawyer review before final publication.

    1. Who we are

    TrustMyBiz ("we", "us", "our") is a business reviews and verified-listings platform operated by BRC Web (the "Operator"), based in Noida, Uttar Pradesh, India. This Privacy Policy describes how we handle personal data of visitors, registered users, and business owners who use trustmybiz.online, trustmybiz.in and related properties (the "Platform").

    For questions or to exercise your rights under the Digital Personal Data Protection Act, 2023 ("DPDP Act"), contact our Grievance Officer at contact@brcwebhelper.in.

    2. Data we collect

    • Account data: name, email, phone number, password (hashed), profile photo.
    • Business verification data: company name, registered address, GSTIN, CIN, Udyam/MSME number, PAN, business documents you upload.
    • Reviews and content: ratings, written reviews, photos, comments, replies.
    • Usage data: pages viewed, clicks, search queries, device and browser information, IP address, approximate location.
    • Communications: messages you send via contact forms, service-request forms, or support.
    • Cookies and similar technologies: session cookies, analytics cookies (Google Analytics). See Section 8.

    3. Purpose and legal basis

    We process personal data only for specified, lawful purposes. Under Section 6 of the DPDP Act, we rely on the following grounds:

    • Consent — for account creation, posting reviews, marketing emails, and uploading business documents.
    • Legitimate use — for fraud prevention, security, compliance with law, and responding to legal requests.
    • Contractual necessity — to deliver listing, verification and service-request features you sign up for.

    4. How we use your data

    • Create and maintain your account and public profile.
    • Verify business identity using documents you upload.
    • Display reviews, ratings and listings on the Platform.
    • Detect and remove fake reviews and policy-violating content (see our Review Integrity Policy).
    • Send transactional emails (verification, password reset, service-request notifications).
    • Provide customer support and respond to enquiries.
    • Improve Platform features, security and performance.
    • Comply with applicable laws, including responding to lawful requests from government authorities.

    5. Sharing and disclosure

    We do not sell your personal data. We share it only with:

    • Service providers who help us run the Platform — cloud hosting (Lovable Cloud / Supabase), email delivery, analytics (Google Analytics), and AI services (Google Gemini / OpenAI). These providers are contractually bound to process data only on our instructions.
    • Business owners when you submit a service request — your name, contact details and request message are shared with the business you contacted.
    • Other users — your public reviews, ratings and profile information are visible to anyone who visits the Platform.
    • Authorities — when required by law, court order, or to protect rights, safety and property.

    6. Cross-border transfers

    Some of our service providers process data outside India. We transfer personal data only to jurisdictions and providers that maintain protection comparable to the DPDP Act and only where permitted by Government of India notifications under Section 16 of the DPDP Act.

    7. Data retention

    • Account data: retained while your account is active and for 3 years after deletion for fraud-prevention and legal-compliance purposes.
    • Reviews and ratings: retained indefinitely as part of the public record unless removed under our Review Integrity Policy.
    • Verification documents: retained for the duration of verification status and 7 years thereafter, as required by Indian tax and corporate-records laws.
    • Server logs: 12 months.

    8. Cookies

    We use strictly necessary cookies (session, CSRF, authentication) and analytics cookies (Google Analytics) to understand usage. You can disable non-essential cookies via your browser settings; some features may not work correctly without them.

    9. Your rights under the DPDP Act

    As a Data Principal, you have the right to:

    • Access a summary of the personal data we hold about you.
    • Correct or update inaccurate or incomplete data.
    • Erase personal data that is no longer necessary for the purpose collected.
    • Withdraw consent at any time (this does not affect prior lawful processing).
    • Nominate another individual to exercise these rights in case of death or incapacity.
    • Grievance redressal — write to our Grievance Officer; if unresolved within 30 days, escalate to the Data Protection Board of India.

    To exercise any of these rights, email contact@brcwebhelper.in with the subject line "DPDP Request".

    10. Children

    The Platform is not intended for users under 18. We do not knowingly process personal data of children. If we learn we have collected data from a child without verifiable parental consent, we will delete it promptly.

    11. Security

    We implement reasonable security practices as required by the IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 — including encrypted transport (HTTPS), encryption at rest for documents, role-based access control, password hashing, and routine security reviews.

    12. Data breaches

    In the event of a personal-data breach likely to cause harm, we will notify affected Data Principals and the Data Protection Board of India in accordance with Section 8(6) of the DPDP Act.

    13. Changes to this policy

    We may update this Privacy Policy from time to time. Material changes will be notified via email or a prominent Platform notice at least 7 days before they take effect.

    14. Contact & Grievance Officer

    Grievance Officer: Raj Singh Senger
    Email: contact@brcwebhelper.in
    Phone: +91 96666 40889
    Address: BRC Web, Noida, Uttar Pradesh, India