Back to Home
    LegalLast updated: April 18, 2026Effective date: April 18, 2026

    BarterNow Privacy Policy

    This Privacy Policy explains how BarterNow collects, uses, stores, shares, and protects personal data when users access the BarterNow platform, website, dashboards, workflows, analytics tools, communication systems, and related services.

    BarterNow is a B2B sponsorship discovery, workflow, data-management, and analytics platform. In this policy, "BarterNow", "we", "our", or "us" means BarterNow.

    This policy is published in compliance with the Digital Personal Data Protection Act, 2023 ("DPDP Act") and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.

    1Introduction

    This Privacy Policy explains how BarterNow collects, uses, stores, shares, and protects personal data when users access the BarterNow platform, website, dashboards, workflows, analytics tools, communication systems, and related services.

    2Data We Collect

    We may collect the following categories of personal and business-related data:

    1. Account data:
      • full name;
      • email address;
      • phone number;
      • password hash and authentication metadata;
      • account verification status.
    2. Organization and profile data:
      • company, brand, agency, or event details;
      • business domain and public profile information;
      • uploaded logos, decks, documents, and media.
    3. Deal and workflow data:
      • sponsorship requests;
      • negotiation messages;
      • deliverables, approvals, proofs, and reports;
      • invoices, payment references, and payout-related metadata.
    4. Technical and usage data:
      • login history;
      • IP address;
      • browser and device information;
      • session, CSRF, and security-related cookies;
      • activity logs and audit records.
    5. Support and grievance data:
      • complaint details;
      • support emails;
      • dispute-related communications.

    3Why We Use Data

    We use personal data to:

    1. create and manage user accounts;
    2. verify users and secure platform access;
    3. enable matching, discovery, communication, and deal workflows;
    4. process subscription, platform fee, and payment-related operations;
    5. generate analytics, reports, product insights, benchmarking, comparative brand/event performance metrics, and cohort-level sponsorship intelligence;
    6. provide support, grievance handling, and dispute assistance;
    7. maintain logs, prevent fraud, detect abuse, and improve security;
    8. comply with legal, tax, accounting, and regulatory requirements.

    5Sharing of Data

    We may share personal data:

    1. with the relevant counterparty on the Platform where the workflow requires it;
    2. with payment gateways, hosting providers, communications providers, analytics vendors, storage providers, and other service providers acting on our instructions;
    3. with professional advisors, auditors, or legal representatives where necessary;
    4. with law-enforcement agencies, regulators, courts, or government authorities where required by law.

    We do not sell personal data to data brokers or third-party advertisers.

    6Data Retention

    We retain personal data only for as long as reasonably necessary for the purposes described in Section 3 and to meet legal obligations. Indicative retention periods per category:

    1. Account data (name, email, phone, password hash, verification status): retained for the lifetime of the account, plus 36 months after closure for fraud prevention and dispute recovery.
    2. Organization and profile data (company details, uploaded logos, decks, media): retained for the lifetime of the organization on the Platform, plus 12 months after deactivation.
    3. Deal and workflow data (sponsorship requests, negotiation messages, deliverables, approvals, proofs, reports): retained for 8 years after deal closure to satisfy GST, audit, and contractual recordkeeping obligations.
    4. Payment and invoicing data (Razorpay references, settled-deal invoices, payout metadata): retained for 8 years after the financial year in which the transaction occurred, per Indian tax recordkeeping requirements.
    5. Technical and usage data (login history, IP, device, audit logs): retained for 18 months for security monitoring and incident response.
    6. Support and grievance data (complaints, support emails, dispute communications): retained for 36 months after resolution to evidence outcomes.

    Incomplete accounts may be automatically removed after the applicable internal retention period. Records subject to active disputes, legal holds, or regulatory inquiry are retained until the triggering matter is fully resolved.

    7User Rights

    Subject to applicable law and operational feasibility, users ("Data Principals" under the DPDP Act) may request:

    1. access to a summary of personal data being processed and the processing activities;
    2. correction of inaccurate or misleading personal data, and updating incomplete records;
    3. erasure of personal data that is no longer necessary for the purposes for which it was collected, except where retention is required by law or for an ongoing dispute;
    4. nomination of another individual to exercise these rights on the user's behalf in the event of death or incapacity (per Section 14 of the DPDP Act);
    5. withdrawal of consent at any time, subject to the consequence that some Platform features may become unavailable. Withdrawal does not affect lawful processing already undertaken before withdrawal;
    6. grievance redressal through the contact in Section 11.

    To exercise any of these rights, email [email protected] from the address on file. We acknowledge requests within 48 hours and respond substantively within 30 days. Where a request cannot be completed due to legal retention duties, fraud-prevention needs, audit obligations, or active disputes, BarterNow retains the minimum necessary data for those purposes and explains the basis in writing.

    8Security Measures

    BarterNow uses reasonable technical and organizational measures, including:

    1. HTTPS/TLS in transit;
    2. bcrypt-hashed passwords with per-user salts;
    3. role-based access controls and per-organization scoping;
    4. secure cookie handling, Origin validation, and CSRF protection on state-changing requests;
    5. structured security event logging and anomaly monitoring;
    6. JWT issuance with rotation, blacklisting, and short-lived sessions;
    7. encryption at rest for managed database and object storage providers.

    Breach notification. If we become aware of a personal-data breach likely to result in risk to user rights, we notify the Data Protection Board of India and affected users within 72 hours of becoming aware, in accordance with Section 8(6) of the DPDP Act. Notifications include the nature of the breach, categories of data affected, likely consequences, and remedial action taken.

    No system can guarantee absolute security, and users should also protect their account credentials and devices.

    9Children

    The Platform is intended for business users aged 18 or above. BarterNow does not knowingly provide services to children.

    10Cross-Border Processing

    BarterNow primarily operates in India and prefers India-region infrastructure. The following third-party processors may handle limited categories of personal data on our instructions:

    1. Razorpay Software Private Limited — payment processing and Razorpay Route payouts. Servers located in India. Subject to Razorpay's privacy and data-protection terms.
    2. Cloudflare, Inc. — object storage (Cloudflare R2) for user-uploaded files (logos, decks, deal media, proof artefacts). Buckets configured for India-region locality where available; metadata and edge cache may be processed across Cloudflare's global network.
    3. Amazon Web Services (AWS) — production hosting and managed database (Mumbai ap-south-1 region for the primary deployment).
    4. Email delivery providers — transactional email for verification, notifications, and grievance correspondence; provider may operate outside India under standard contractual safeguards.

    Where processing involves transfer outside India, BarterNow relies on the safeguards set out in the DPDP Act and the receiving processor's contractual data-protection commitments. We do not transfer personal data to jurisdictions notified as restricted by the Central Government.

    11Grievance Contact

    For privacy questions, complaints, or data-related requests, contact:

    BarterNow — Grievance Officer & Data Protection Officer

    Utkarsh Mishra

    Email: [email protected]

    Acknowledgement within 48 hours. Resolution within 30 days. Per IT Rules 2021, Section 4 and the Digital Personal Data Protection Act, 2023.

    12Policy Changes

    We may update this Privacy Policy from time to time. Material updates may be notified through the Platform, email, or other reasonable means. Continued use after such update may require renewed acceptance where legally necessary.

    © 2026 BarterNow. All rights reserved.