Privacy Policy
Contents
- We do not sell your personal data. Ever, to anyone, for any purpose.
- We do not share your identity with a developer or seller without your explicit, specific consent — and expressing interest in an opportunity does not by itself give it.
- We do not use your data to build profiles for advertising.
- We do not make automated decisions producing legal effects about you.
1. Who we are
Estate Circle is the Data Fiduciary for the personal data described here. We decide why and how it is processed.
2. What we collect, and why
| Data | Why we need it | Basis |
|---|---|---|
| Name, email, phone | Create and secure your account; contact you about your membership | Necessary to provide the service you asked for |
| Password (hashed) or Google sign-in identifier | Authenticate you | Necessary |
| Investment profile — capital range, horizon, objectives | Assess whether the service suits you; tailor which opportunities we surface | Consent |
| Payment records — amount, date, Razorpay reference | Provide and prove your membership; statutory record-keeping | Necessary and legal obligation |
| Activity — opportunities viewed, documents opened, EOIs, site visits | Deliver member services; understand what is useful | Necessary, and consent for analytics |
| Community contributions | Operate the member community | Necessary |
| Support correspondence | Answer you and keep a record | Necessary |
We do not collect card or bank details. Payment is processed by Razorpay and card data never reaches our systems.
3. What we do not do
- We do not sell your personal data. Ever, to anyone, for any purpose.
- We do not share your identity with a developer or seller without your explicit, specific consent — and expressing interest in an opportunity does not by itself give it.
- We do not use your data to build profiles for advertising.
- We do not make automated decisions producing legal effects about you.
4. Who we share it with
Only these, and only for the purpose stated:
| Recipient | Purpose |
|---|---|
| Supabase | Database and authentication hosting |
| Vercel | Application hosting |
| Razorpay | Payment processing |
| Resend | Transactional email |
| Analytics providers | Aggregate usage measurement |
| Professional advisers | Legal, accounting, audit — where necessary |
| Authorities | Where required by law |
Where you ask us to introduce you to a developer or seller, we share only what is necessary for that introduction, and only after you have consented to that specific introduction.
5. Where your data is held
Primarily in India (Supabase region: South Asia, Mumbai). Some processors operate outside India. We transfer only where permitted under the Digital Personal Data Protection Act 2023 and where the processor is contractually bound to equivalent protection.
6. How long we keep it
| Data | Retention |
|---|---|
| Account and profile | While your membership is active, plus 3 years |
| Payment and tax records | 8 years — statutory |
| Audit logs of trust-critical actions | 8 years — append-only, cannot be edited or deleted, by design |
| Activity data | 3 years |
| Community contributions | Until you delete them, or account closure |
| Support correspondence | 3 years |
Audit logs are a deliberate exception to deletion. They record who did what and when to scores, memberships and member records. Their integrity is what makes our trust claims checkable, so they are append-only and survive account deletion. Where you exercise a deletion right, we anonymise your identifiers in those logs rather than destroying the record of the event.
7. Your rights
Under the Digital Personal Data Protection Act 2023 you may:
- Access a summary of the personal data we hold and how it is processed
- Correct or complete inaccurate data
- Erase data where the purpose is served and no legal obligation requires us to keep it, subject to §6
- Withdraw consent where consent was the basis. Withdrawal is as easy as giving it, and does not affect prior lawful processing
- Nominate someone to exercise your rights if you die or become incapacitated
- Complain to us, and then to the Data Protection Board of India
Exercise these in your Profile → Privacy tab, which provides working request paths for export and deletion — not a link back to this page — or by emailing the Grievance Officer. A request is recorded and a person acts on it; there is no automatic export yet, and the tab says so.
We respond within thirty (30) days.
8. Consent
Where we rely on consent we ask for it specifically, in plain language, for a stated purpose, and we record when and how it was given. Consent is never bundled and never inferred from silence or a pre-ticked box.
Consent records are kept for as long as we rely on them, plus three years.
9. Security
- Encryption in transit and at rest
- Passwords hashed, never stored or logged in plain text
- Role-based access; staff see only what their role requires
- Documents in private storage, served only through short-lived signed links
- Every trust-critical action written to an append-only audit log
- Access reviewed periodically
No system is perfectly secure. If a breach is likely to affect you, we will tell you and the Data Protection Board as required, and we will tell you what happened rather than only that something happened.
10. Children
The service is for adults. We do not knowingly collect data from anyone under 18. If we learn we have, we delete it.
11. Cookies
We use cookies necessary for sign-in and session security. Analytics are not running yet — no analytics or session-recording script is loaded, and none will be until we ask you for that consent separately. You can review every consent we hold in your Profile → Privacy tab, and withdraw any of them at any time without losing access to anything — except the one that covers operating your account itself, which cannot be withdrawn while the account exists, because withdrawing it is the same thing as deleting the account. The tab explains this where it applies.
12. Changes
Material changes are notified by email at least thirty (30) days before they take effect. Where a change requires fresh consent, we ask for it rather than assuming it.
13. Grievance Officer
Raju Datla — grievance@estatecircle.club
We acknowledge within two working days and respond within thirty (30) days.
If unsatisfied, you may complain to the Data Protection Board of India.