BuyerCircle does not claim an unrestricted right to use identifiable buyer information. We use it for the service and safety purposes listed below, obtain a fresh choice before a materially different consent-based purpose, and may use only genuinely de-identified or aggregated information for broader lawful analysis.
1. Scope, responsibility and operator
This Privacy and Consent Notice applies to BuyerCircle websites, project pages, anonymous missing-project suggestions, buyer applications, administrator requests and accounts, private application-status pages, transactional email, privacy requests, security logs and the super-admin workspace. It should be read with the Terms of Use and the short consent statements shown at the point of collection.
BuyerCircle is currently an owner-operated service using the trading name “BuyerCircle.” For personal information processed through this service, BuyerCircle determines the purposes and means described in this Notice and acts as the responsible service operator or data fiduciary where that term applies. The BuyerCircle Privacy & Grievance Desk is the designated contact and is reachable through the online privacy-request form.
This Notice does not govern an external messaging group after you voluntarily join it, a builder’s systems, an email provider’s independent use, or another website reached through a link. Those parties have their own terms and privacy practices.
2. Notice at the time information is collected
Immediately before a buyer or administrator submits personal information, BuyerCircle displays separate, unticked controls for the Terms, this Notice and the relevant document-redaction or confidentiality confirmation. The form identifies the current policy versions and the server rejects an outdated, missing or incomplete acceptance.
A buyer’s required service consent covers only buyer verification, duplicate and fraud checks, authorised review, transactional communication, private invitation delivery, community administration, security and audit, grievance handling, and legal compliance or disputes. An administrator applicant’s consent separately covers request review, account provisioning and, when the project has no saved community invitation, the encrypted handling of a candidate invitation supplied with the request. An administrator’s access consent covers account access, assigned review operations and activity records. Consent to the core service is not consent to unrelated advertising or sale of personal information.
BuyerCircle keeps a durable, versioned receipt containing the subject record, server time, Terms version, Notice version, consent-statement version, accepted purposes and a cryptographic digest of the exact canonical wording. A verified withdrawal adds a withdrawal marker without rewriting the recorded acceptance. Network and browser evidence is protected with a keyed digest and is not displayed to buyers or administrators.
3. Personal data and other records we collect
The precise fields depend on the action you choose. BuyerCircle seeks to collect the minimum reasonably necessary for that action.
| Category | Typical data | Why it is needed |
|---|---|---|
| Project and unit | Selected project, builder reference, tower or block, and unit number | Route the request, distinguish communities and detect matching unit claims |
| Buyer identity and contact | Name, email address and phone number | Review the claim, communicate a decision and privately deliver an approved invitation |
| Buyer proof | One uploaded redacted PDF, JPEG or PNG file; generated storage name, type and size | Allow a limited human review connecting the buyer, project and unit |
| Application records | Application identifier, private status token, status, duplicate flag, reviewer, decision note, timestamps and email-delivery result | Operate the queue, show a private status and preserve decision integrity |
| Administrator records | Name, email, project relationship, request reason, assigned projects, password hash, invitation state, acceptance record and, only when no project invitation is saved, an encrypted candidate invitation | Assess requests, provision least-privilege access, configure a private invitation after approval and secure the admin workspace |
| Privacy requests | Name, email, request type, details, optional private status link match, outcome and timestamps | Verify and respond to access, correction, erasure, withdrawal or grievance requests |
| Technical and security records | Session identifiers, request timing, rate-limit counters, truncated or keyed network/browser signals, audit events and security errors | Authenticate users, prevent abuse, investigate incidents and demonstrate accountability |
| Project directory and suggestions | Project names, locations, builder names, types, dates, status descriptions, source-snapshot metadata and missing-project suggestions containing project metadata only | Let users find a project and let the super admin review a missing-project suggestion; the suggestion form does not request the guest’s name, email or phone number |
Do not put sensitive or unrelated information in free-text fields. Do not send passwords, one-time codes, complete identity numbers, bank information, payment-card information, health data, biometrics, full signatures or information about another person unless BuyerCircle specifically requests it through a suitable secure process and explains why.
4. Where information comes from
Most personal data comes directly from the buyer, administrator applicant, invited administrator or privacy requester. When an administrator applicant supplies a candidate private-group invitation because the project has no saved invitation, that value also comes directly from the applicant. A super admin may create an administrator account using the name and email supplied for that purpose. Assigned administrators create review decisions and notes, while the email service returns delivery or failure information.
Project-directory records may come from public source snapshots, manual super-admin entries or anonymous guest suggestions reviewed by the super admin. The suggestion content is limited to project metadata and does not ask for a guest name or contact detail; ordinary technical and anti-abuse records may still arise from the interaction. Duplicate alerts are derived from normalised project, tower and unit values already submitted to BuyerCircle. Security records arise automatically from interaction with the service. We do not silently import a buyer’s contacts, messaging history or mailbox contents.
5. The specified purposes for processing
BuyerCircle processes personal data only where reasonably necessary for one or more of these specified purposes:
- receive and validate a buyer application for the selected project;
- allow the super admin or an active administrator assigned to that project to review the proof and decide access;
- normalise tower and unit values, identify matching claims and support human fraud or duplicate review;
- send transactional status, invitation, account, password, security, policy or grievance messages;
- deliver a project’s private community invitation by email after approval and record whether the email provider accepted the send;
- review administrator requests; hold a candidate private-group invitation in encrypted form when no project invitation exists; and, only after super-admin approval and only if the project still lacks one, promote that candidate into protected project settings;
- receive and review anonymous missing-project suggestions containing project metadata without requesting the guest’s name or contact details;
- create, assign, authenticate, audit and deactivate administrator accounts;
- protect buyers, invitations and systems through rate limits, access controls, audit logs, incident investigation and misuse prevention;
- respond to privacy choices, correct records, process withdrawal, resolve grievances and document the result;
- establish, exercise or defend legal claims, preserve evidence under a legal hold, and comply with binding law or valid legal process; and
- create genuinely de-identified or aggregate measurements for service reliability, capacity, safety and improvement.
If a purpose is not listed or reasonably compatible with what was specifically explained, BuyerCircle will not treat the original checkbox as permission for that new identifiable-data use.
6. Ownership or booking proof documents
A proof is private evidence for a limited community-access decision. It is not posted publicly, included in invitation email, shown on the buyer’s public-facing project page or shared with other buyers. Within the admin workspace it is displayed directly alongside the application so an authorised reviewer can assess it without downloading or opening an uncontrolled copy.
Proofs may be seen only by the super admin, an active project admin assigned to the relevant project, and infrastructure processors that technically store or transmit content for BuyerCircle. New proof files are encrypted by BuyerCircle before object storage and decrypted only after an authorised request. Earlier files are protected by private storage, transport security and the same application access controls while they age out. Proof access is subject to authentication, project-level authorisation, no-cache responses, rate limits and audit controls.
Upload no more than the file-size limit displayed in the submission form and enforced by BuyerCircle’s backend, and redact everything not needed to connect your name, project and unit. You remain responsible for authority to supply the document. BuyerCircle may reject or quarantine an unreadable, excessive, malicious, mismatched or insufficiently redacted file.
7. Duplicate-unit and fraud alerts
BuyerCircle compares normalised project, tower or block and unit values. When two or more applications contain the same normalised values, each relevant application can be flagged for a reviewer. The reviewer sees only records within their authorised project.
A flag is not a legal finding, ownership determination or accusation. Joint purchasers, family submissions, resubmissions, formatting differences, re-numbering and clerical errors can produce a match. A human administrator decides whether to approve, reject, request clarification or investigate through an appropriate channel.
8. Administrator data, duties and access boundaries
A project-admin request contains the applicant’s name, email, relationship explanation and, where supplied, unit or private application reference. If the project has no saved community invitation at submission time, the applicant must also supply a candidate invitation. BuyerCircle encrypts that candidate while the request is pending; the normal super-admin review interface and API reveal only whether a candidate was supplied, not its URL. Only the super admin may approve the request, create or disable admins, replace or remove an existing protected community link, or view the complete operational database. On approval, the controlled workflow promotes the encrypted candidate into project settings only if the project still has no invitation; if one has since been saved, the candidate is discarded. On either approval or rejection, the request copy is cleared. An assigned project admin may otherwise enter the link once for a project that has no link yet; after that first save it is hidden and locked from that admin.
A project administrator is limited to active projects explicitly assigned to that account. Before buyer-data access, the administrator must accept the current Terms, this Notice and a continuing confidentiality undertaking. Existing administrators are required to re-accept when the current legal version changes.
Administrator views and decisions may be logged. Administrators are prohibited from exporting, photographing, copying, marketing to, profiling, harassing, disclosing or otherwise using buyer data outside the assigned review purpose. BuyerCircle may suspend access immediately when a project is archived, an assignment is removed or a security concern arises.
9. Consent and other lawful grounds
Where BuyerCircle relies on consent, the consent is requested through a clear affirmative action for specified data and purposes. It must be freely given, informed, specific, unconditional and unambiguous to the standard required by applicable law. We keep evidence because the service operator may need to demonstrate what notice and choice were presented.
Certain limited processing may continue without consent where applicable law requires or authorises it—for example, responding to binding legal process, protecting a person in an emergency where a recognised ground applies, preventing or investigating unlawful access, or establishing and defending legal claims. BuyerCircle will not use such an exception merely for convenience.
The service cannot practically verify a buyer, send an invitation or secure an administrator account without the required fields. You may decline, but BuyerCircle may then be unable to provide that requested feature.
10. Uses BuyerCircle does not make
BuyerCircle does not sell or rent buyer proofs, phone numbers, email addresses, unit claims or administrator data. It does not publish an invitation on the website. It does not use a proof to offer loans, brokerage, debt collection, advertising or unrelated property sales. It does not grant administrators a right to build their own buyer database.
BuyerCircle does not treat acceptance of the core service as consent to unrelated marketing, targeted advertising, behavioural advertising, data brokerage, or research using identifiable records. Any future optional purpose of that kind would require a separate, unticked and specific choice naming the data, recipient and purpose where consent is the lawful ground.
12. Email delivery and external private groups
When a buyer is approved, BuyerCircle asks its email provider to send the project’s private community invitation to the email submitted by that buyer. The invitation is not returned by the approval API, placed in a status page or displayed in the browser. If the provider does not accept the message successfully, the application returns to the review queue for a controlled retry rather than being marked finally approved.
Joining the external group is voluntary. After joining, the group provider and other group members may be able to see a phone number, display name, profile image, messages and participation information, depending on settings and the provider’s design. BuyerCircle cannot control, recall or guarantee confidentiality for content shared after joining.
Never forward an invitation to an unverified person. Report a suspected leaked invitation through the privacy and grievance channel so the super admin can investigate and, where appropriate, replace the stored link.
13. Processing locations and cross-border services
BuyerCircle is directed to users in India. Cloudflare and Google/Gmail may process or support data from infrastructure or personnel located in India or other locations permitted under their service terms and applicable Indian restrictions. Internet routing can also cross national borders.
Where a cross-border restriction applies, BuyerCircle will follow the applicable restriction and use reasonable contractual, organisational and technical safeguards. A provider’s own independent processing remains governed by its published terms. Contact the Privacy & Grievance Desk if you need current recipient-category or location information for a particular request.
14. De-identified and aggregated information
BuyerCircle may create statistics from operational records—for example, application volumes, review times, failure rates, duplicate-alert counts, project activity and storage capacity. If the result has been genuinely anonymised or aggregated so that no individual is reasonably identifiable, it is no longer treated as an identifiable buyer record for ordinary analysis.
BuyerCircle may use such genuinely de-identified information for any lawful purpose, including service improvement, safety research, capacity planning, reporting and development. We do not include raw proofs, direct contact details, private tokens or invitation links in those outputs and do not attempt to re-identify a person.
15. Retention, minimisation and deletion
BuyerCircle retains identifiable data only while reasonably necessary for the purpose collected, an active administrator account, duplicate and fraud controls, security and audit, an unresolved privacy request or dispute, consent evidence, legal defence, a legal hold or a binding retention requirement. Different records therefore have different periods.
A pending candidate community invitation is cleared from the administrator-request record when the request is approved or rejected. It is also cleared by request-expiry or retention minimisation, and it is never retained as an approved request detail; only a candidate promoted into protected project settings remains there. Rejected administrator-request details are designed to be minimised after thirty days, approved administrator-request details after ninety days, and unresolved requests older than ninety days are expired and minimised through the admin workflow. Completed privacy-request identity and narrative fields are designed to be minimised after one hundred eighty days. Anonymous missing-project suggestion content may be retained as project-directory metadata or as minimal review history because the form does not request guest identity or contact fields. Minimal references, decisions, timestamps, consent receipts and audit records may remain longer where needed for accountability, security or law.
A pending buyer application expires after ninety days without a decision. Its proof is removed and the request is closed. A decided buyer proof is removed ninety days after the decision, unless a pending privacy request or a documented legal hold requires a temporary pause. Rejected application identity and unit fields are minimised after one hundred eighty days; approved application identity and unit fields are minimised after one year. Minimal decisions, consent receipts and audit records may remain where needed for accountability, security or law.
If an encrypted proof reaches private storage but the related application and consent receipt cannot be saved, BuyerCircle records a restricted cleanup marker and retries deletion. Such an upload is not made available to reviewers and is removed independently of the ordinary application periods.
A verified erasure request can accelerate proof removal and record minimisation where no lawful exception applies. Deletion from the active application does not control a provider backup schedule; if a protected backup still contains the data, access remains restricted and the data is not returned to ordinary processing except for justified disaster recovery or law. A legal hold suspends ordinary deletion only for the affected material.
16. Technical and organisational safeguards
Safeguards include backend field validation; strict file-type and configured backend upload-size checks; same-origin checks; rate limiting; application-layer encryption for new proofs, contact fields, request narratives, saved invitation links and pending candidate invitations; boolean-only exposure of candidate-invitation presence in normal review responses; keyed digests for lookup and network evidence; strong password hashing; secure, HTTP-only session cookies; least-privilege project assignments; super-admin-only controls; database constraints; no-store responses for private material; and audit trails.
Authorised reviewers are required to keep credentials and buyer information confidential. Provider access is limited to technical operation. Security controls are reviewed as the service changes, but no system connected to the internet can promise absolute security or prevent every attack.
You can reduce risk by redacting the proof, using a private device and mailbox, choosing a unique administrator password, signing out on shared devices, keeping status and invitation links secret, and reporting a suspected compromise promptly.
17. Security incidents and notifications
BuyerCircle investigates suspected unauthorised access, loss, disclosure, alteration or destruction. Reasonable response can include containment, credential or link rotation, access suspension, evidence preservation, processor coordination and remediation.
If an incident triggers a legal notification duty, BuyerCircle will notify affected individuals and competent authorities in the manner and time required by applicable law. A notification may describe the nature and likely consequences, mitigation taken, recommended protective steps and the contact channel. Security-sensitive details may be limited where disclosure would increase risk.
18. Access, correction, erasure and grievance choices
Subject to applicable law and proportionate identity verification, you may ask BuyerCircle to:
- provide a summary of personal data held and the processing undertaken;
- identify relevant categories of processors or recipients;
- correct inaccurate or misleading information and complete an incomplete record;
- erase data that is no longer necessary and is not required or authorised to be retained;
- withdraw consent for future consent-based processing;
- review a decision, suspected misuse or privacy grievance; and
- use any nomination or additional right that applicable law makes available.
Use the Privacy & Grievance Desk. There is no charge for an ordinary genuine request, but BuyerCircle may ask for clarification where a request is ambiguous, repetitive, manifestly unfounded, affects another person or seeks data the requester is not authorised to receive.
19. Withdrawing consent and service consequences
Withdrawal is available through the same online privacy channel used for other requests. State the relevant project or include the private status link if available. Withdrawal applies prospectively and does not make processing already performed under valid consent unlawful.
Because identity, project, unit, proof and contact data are essential to buyer verification and invitation delivery, withdrawal may require BuyerCircle to stop a pending review, remove or restrict a membership, disable an administrator account, or become unable to provide a requested feature. BuyerCircle will explain material consequences before completing a verified withdrawal where practicable.
Some minimal data may continue to be processed without relying on the withdrawn consent where necessary for security, abuse prevention, consent evidence, a dispute, a legal hold or a binding legal requirement. Such retention does not authorise unrelated use.
20. Verifying a privacy requester
BuyerCircle must avoid disclosing or deleting a record for an impostor. It may therefore compare the request email with the encrypted application or admin record, validate an optional private status token, ask a proportionate account question, or send a confirmation to an address already on file.
Do not upload another unredacted identity document unless BuyerCircle specifically explains why a less intrusive method is insufficient. Verification information is used only to authenticate and process the request, secure the service and preserve the outcome record.
21. Adults-only service
The buyer and administrator features are intended only for people aged eighteen years or older. A child must not submit a buyer application, proof or administrator request. The service does not knowingly target, profile or advertise to children.
A parent, guardian or any person reporting suspected accidental child data may use the Privacy & Grievance Desk even though the buyer and administrator features are adults-only. If BuyerCircle learns that a child’s personal data was submitted without a lawful, verifiable process, it will restrict the record and seek deletion unless retention is required to protect the child, respond to a guardian or comply with law.
22. Automated processing and human decisions
BuyerCircle uses automated validation, normalisation, duplicate matching, rate limits, security checks and queue routing. These tools may reject a malformed request or produce a duplicate alert, but they do not adjudicate property ownership.
Buyer approval, rejection, administrator-request approval, missing-project suggestion approval and privacy-request resolution are made or confirmed by an authorised human. If an automated control appears to have blocked a valid submission, contact the Privacy & Grievance Desk for review.
24. Third-party services and links
BuyerCircle depends on Cloudflare hosting, D1 database and R2 object storage, and Google/Gmail transactional email. Approval email may contain a private link to WhatsApp. Those providers may process device, delivery or account information under their own terms and may experience outages or policy changes.
BuyerCircle is not affiliated with Google, Gmail, WhatsApp, builders, lenders, brokers or public authorities merely because a service, project or source is referenced. Review the external provider’s privacy controls before joining a group or using its features.
25. Notice changes, versioning and fresh consent
Every published Notice has an effective date and version. BuyerCircle may update it to reflect law, security, providers or features. Historical consent receipts remain tied to the exact versions and canonical wording presented when the user accepted.
A clarification that does not change the purpose may be communicated by posting or transactional notice. BuyerCircle will not rely on continued use or a hidden policy edit to authorise a materially different identifiable-data purpose. Where consent is required, a new specific notice and affirmative choice will be presented. Administrators are blocked from buyer access until they accept the current legal version.
26. Contact, complaints and response process
The BuyerCircle Privacy & Grievance Desk is the designated first point of contact. Submit an access, correction, erasure, withdrawal, security report or grievance through the online form. The form creates a reference in a super-admin-only queue and may be linked privately to an existing buyer record.
BuyerCircle will address a genuine privacy grievance within one month. Complex identity verification, another person’s rights, legal holds or compulsory process may affect the remedy available but do not remove the duty to respond. The outcome record states whether the request was resolved or rejected and why. Nothing in this process prevents a complaint to a competent authority or court where applicable law allows it.
27. Applicable privacy framework and interpretation
This Notice is designed for operation in India and should be interpreted consistently with applicable provisions of the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, the Digital Personal Data Protection Act, 2023 and rules or commencement notifications made under it, as each applies from time to time.
Some requirements commence in stages. BuyerCircle may voluntarily apply a stronger practice before it becomes mandatory. A contractual sentence cannot waive a privacy, consumer, complaint or other statutory right that applicable law makes non-waivable. If this Notice conflicts with a mandatory requirement, that requirement controls to the extent of the conflict.