1. INTRODUCTION
This Privacy Policy (“Policy”) sets forth the comprehensive framework governing the collection, processing, storage, usage, disclosure, and protection of personal and non-personal data by Bourmeg (“Platform”, “we”, “our”, “us”) in connection with its digital marketplace, applications, and related services (collectively, the “Services”). This Policy is designed to ensure transparency, accountability, and compliance with applicable data protection and privacy laws, including but not limited to the Digital Personal Data Protection Act, 2023 and the Information Technology Act, 2000, along with any rules, regulations, or amendments made thereunder. By accessing, registering on, or using the Platform in any capacity, you (“User”, “you”, “your”) expressly acknowledge, agree, and consent to the collection, processing, storage, and use of your data in accordance with this Policy. Such consent is deemed to be informed, specific, and unconditional, except where explicitly restricted by applicable law. This Policy applies to all categories of Users, including but not limited to:
- - Clients seeking services
- - Service Providers offering services
- - Visitors browsing the Platform
- - Any individual interacting with Bourmeg systems, interfaces, or support channels
The Platform operates as a technology-enabled intermediary facilitating service transactions between Users. In the course of providing such Services, Bourmeg may collect and process a wide range of data, including identity information, financial details, behavioral patterns, communication records, and device-level intelligence, strictly for purposes including but not limited to service delivery, security, fraud prevention, compliance, dispute resolution, and platform optimization. Users are advised that certain features of the Platform may require mandatory data collection, including but not limited to identity verification (KYC), location access, and communication monitoring, which are essential for the integrity, safety, and lawful operation of the Platform. Refusal to provide such data may result in restricted access, suspension, or termination of Services. This Policy must be read in conjunction with the Platform’s Terms of Service, Payment Policy, and other applicable legal documents. In the event of any conflict, the interpretation most favorable to the Platform’s operational integrity and legal compliance shall prevail, to the extent permitted by law. Bourmeg reserves the right, at its sole discretion, to modify, update, or replace this Policy at any time to reflect changes in legal requirements, technological advancements, or business practices. Continued use of the Platform after such updates shall constitute deemed acceptance of the revised Policy. If you do not agree with any part of this Policy, you are advised to discontinue use of the Platform immediately.
2. DEFINITIONS
For the purposes of this Privacy Policy, the following terms shall have the meanings ascribed to them below. These definitions are intended to provide clarity, legal certainty, and broad interpretative coverage. Any term not explicitly defined herein shall be interpreted in a manner most consistent with applicable laws and the Platform’s operational framework.
2.1 “Personal Data”
Means any information that relates to an identified or identifiable natural person, including but not limited to name, contact details, identification numbers, location data, online identifiers, financial information, and any other data that can directly or indirectly identify a User.
2.2 “Sensitive Personal Data”
Includes, without limitation, financial information (such as bank account details, UPI IDs), KYC documents (including Aadhaar, PAN), biometric data (such as facial recognition data, video verification data), and any other data classified as sensitive under applicable laws.
2.3 “User”
Means any individual or entity accessing, registering on, or interacting with the Platform in any manner, including Clients, Service Providers, and Visitors.
2.4 “Processing”
Means any operation or set of operations performed on data, whether automated or manual, including collection, recording, organization, structuring, storage, adaptation, retrieval, use, analysis, sharing, disclosure, restriction, or deletion.
2.5 “KYC Data”
Refers to identity verification information collected for compliance and security purposes, including but not limited to government-issued identification documents, photographs, live video verification data, and background verification records.
2.6 “Device Data”
Includes information related to the User’s device such as device ID, IP address, operating system, browser type, network information, device fingerprinting data, and other technical identifiers used for security, analytics, and fraud detection.
2.7 “Behavioral Data”
Means data derived from User interactions with the Platform, including browsing patterns, click behavior, service preferences, communication activity, transaction patterns, and usage analytics.
2.8 “Communication Data”
Includes all forms of interaction between Users conducted through or facilitated by the Platform, including chat messages, call records (where applicable), support communications, and any other exchange of information.
2.9 “Financial Data”
Refers to payment-related information including transaction records, wallet balances, earnings data, payout history, tax-related data, chargebacks, disputes, and payment instrument details processed via integrated third-party payment gateways.
2.10 “Location Data”
Includes real-time, approximate, or static geographical location information collected from Users for the purpose of service delivery, verification, and operational efficiency.
2.11 “Third-Party Services”
Means external service providers integrated with the Platform, including but not limited to payment gateways, KYC verification providers, analytics services, communication tools, and fraud detection systems.
2.12 “AI Systems”
Refers to automated technologies, algorithms, and machine learning models used by the Platform for data analysis, fraud detection, behavioral profiling, recommendation systems, and operational decision support.
2.13 “Fraud Detection System”
Means the combination of automated tools, AI systems, manual review processes, and analytical mechanisms used to identify, prevent, and investigate suspicious or fraudulent activities on the Platform.
2.14 “Services”
Refers to all functionalities, features, applications, and offerings provided by Bourmeg through its Platform, including service listings, bookings, payments, communication tools, and support systems.
2.15 “Platform”
Means the Bourmeg website, mobile applications, software systems, and any associated digital infrastructure operated by or on behalf of Bourmeg.
2.16 “Consent”
Means any freely given, specific, informed, and unambiguous indication of the User’s agreement to the processing of their data, including through acceptance of this Policy or continued use of the Platform.
2.17 “Applicable Law”
Refers to all laws, regulations, guidelines, and legal requirements in force within India, including but not limited to the Digital Personal Data Protection Act, 2023, Information Technology Act, 2000, and any amendments thereto.
2.18 “Account Compromise”
Means any unauthorized access, misuse, or breach of a User’s account resulting from factors including but not limited to credential sharing, phishing, device compromise, or negligence.
2.19 “Force Majeure Event”
Means any event beyond the reasonable control of the Platform, including but not limited to natural disasters, cyber-attacks, system failures, government actions, or network disruptions, affecting data security or service availability.
3. DATA WE COLLECT
Bourmeg collects, receives, generates, and processes various categories of data to enable secure, efficient, and reliable operation of its Services. The nature and extent of data collected may vary depending on the User’s interaction with the Platform, the features used, and applicable legal requirements. The categories of data collected include, but are not limited to, the following:
3.1 Personal Identification Data
We collect basic identity-related information required for account creation and service usage, including:
- - Full name
- - Phone number
- - Email address
- - Profile details (such as profile photo, gender, preferences, etc.)
3.2 KYC & Identity Verification Data
To ensure trust, safety, and regulatory compliance, we may collect and process identity verification data, including:
- - Aadhaar details (masked or tokenized where applicable)
- - PAN details
- - Government-issued identification documents
- - Selfie photographs and facial recognition data
- - Live video verification data
- - Background verification data (where applicable)
Such data may be collected directly or through authorized third-party verification providers.
3.3 Financial & Transactional Data
We collect and process financial and transaction-related information necessary for payments, settlements, and compliance, including:
- - Payment transaction records
- - Wallet balances and transaction history
- - Earnings data (for Service Providers)
- - Payout and withdrawal records
- - Tax-related information
- - Failed transactions, chargebacks, and dispute records
All payment processing is facilitated through integrated third-party payment gateways, and Users are advised to review the respective privacy policies of such providers.
3.4 Device & Technical Data
We automatically collect technical information related to the devices used to access the Platform, including:
- - IP address
- - Device type and model
- - Operating system and browser type
- - Network and connection data
- - Device identifiers and device fingerprinting data
Such data is used for security, analytics, fraud detection, and performance optimization.
3.5 Behavioral & Usage Data
We collect and analyze information related to how Users interact with the Platform, including:
- - Browsing behavior and navigation patterns
- - Clickstream data and feature usage
- - Service preferences and interaction history
- - Transaction patterns and activity logs
This data is used for personalization, recommendation systems, and fraud detection.
3.6 Communication Data
We may collect, store, and analyze communications exchanged through or facilitated by the Platform, including:
- - Chat messages between Users
- - Customer support interactions
- - Complaint and dispute communications
Such data may be used for dispute resolution, fraud investigation, service improvement, and legal compliance.
3.7 Location Data
We collect location-related information to enable service delivery and verification, including:
- - Static location data (such as registered address)
- - Real-time or event-based location data (such as arrival confirmation at service location)
Continuous tracking is not performed unless explicitly required for operational or security purposes.
3.8 Fraud Detection & Risk Signals
We may collect and generate additional data points to identify and prevent fraudulent or suspicious activities, including:
- - Multiple account indicators
- - Suspicious login patterns
- - Device mismatch signals
- - Behavioral anomalies
Such data may be generated through automated systems and AI-based analysis.
3.9 AI-Generated & Derived Data
The Platform may generate inferred or derived data using AI systems and analytical models, including:
- - Risk scores
- - Behavioral profiles
- - Recommendation signals
- - Fraud probability indicators
Such data is used strictly for internal decision support, security enhancement, and platform optimization.
3.10 Optional & Consent-Based Data
Certain types of data may be collected only with explicit User consent, including:
- - Additional profile information
- - Location access beyond basic requirements
- - Enhanced verification data
Users may choose to provide or withhold such data; however, refusal may limit access to certain features or Services. Bourmeg ensures that all data collection practices are conducted in a lawful, fair, and transparent manner, and only to the extent necessary for the purposes outlined in this Policy. Users acknowledge that certain data collection is essential for the functioning, security, and integrity of the Platform, and refusal to provide such data may result in restricted or denied access to Services..
4. HOW WE USE DATA
Bourmeg processes User data for multiple operational, security, analytical, and legal purposes. All data usage is aligned with the necessity of providing reliable Services, ensuring platform integrity, preventing fraud, and complying with applicable laws. The purposes for which data may be used include, but are not limited to, the following:
4.1 Service Delivery & Platform Operations
- - To create and manage User accounts
- - To facilitate service listings, bookings, and transactions
- - To enable communication between Clients and Service Providers
- - To manage wallet operations, payments, settlements, and withdrawals
4.2 Identity Verification & Trust Management
- - To verify User identity through KYC processes
- - To conduct enhanced verification such as facial recognition, video verification, and background
checks
- - To maintain trust and safety within the Platform ecosystem
4.3 Fraud Prevention & Risk Management
- - To detect, prevent, and investigate fraudulent, suspicious, or abusive activities
- - To analyze behavioral patterns, device data, and transaction anomalies
- - To generate risk scores and fraud indicators using automated systems and AI technologies
- - To restrict, suspend, or terminate accounts based on identified risks
4.4 Financial Processing & Enforcement
- - To process payments through third-party gateways
- - To maintain transaction records and financial history
- - To enforce penalties, recover dues, and process auto-debits (where applicable)
- - To manage disputes, chargebacks, and financial investigations
4.5 Communication Monitoring & Dispute Resolution
- - To facilitate and store User communications conducted through the Platform
- - To review chats, messages, and support interactions for dispute resolution
- - To use communication data as evidence in case of conflicts, fraud investigations, or legal
proceedings
4.6 AI-Based Analysis & Decision Support
- - To utilize AI systems for detecting fraud, analyzing behavior, and generating recommendations
- - To assist administrative teams in identifying risks, violations, and operational improvements
- - To generate insights such as risk scores, usage patterns, and recommendation signals
All final decisions impacting Users (such as suspension or penalties) are subject to human review, unless otherwise required for immediate security action.
4.7 Personalization & User Experience Enhancement
- - To customize content, recommendations, and service visibility
- - To personalize advertisements and promotional content (where applicable)
- - To optimize platform performance and usability
4.8 Security & System Integrity
- - To monitor system activity and detect unauthorized access
- - To enforce security measures including authentication, OTP verification, and suspicious activity
alerts
- - To investigate account compromise, unauthorized usage, and security incidents
4.9 Legal Compliance & Regulatory Obligations
- - To comply with applicable laws, legal processes, and regulatory requirements
- - To respond to lawful requests from government authorities and law enforcement agencies
- - To maintain records as required under applicable regulations
4.10 Internal Analytics & Business Intelligence
- - To analyze usage trends, operational efficiency, and platform growth
- - To improve Services, develop new features, and enhance overall business strategy
4.11 Enforcement of Platform Policies
- - To enforce Terms of Service, Payment Policies, and other legal agreements
- - To investigate violations, misuse, or abuse of the Platform
- - To take appropriate actions including warnings, restrictions, suspensions, or legal escalation
Bourmeg ensures that all data processing activities are conducted on a need-to-know basis and are proportionate to the purpose for which such data is collected. Users acknowledge that certain data processing activities, including monitoring, analysis, and automated flagging, are essential for maintaining a secure, trustworthy, and legally compliant Platform environment.
5. DATA SHARING & DISCLOSURE
Bourmeg may share, transfer, disclose, or provide access to User data to third parties under specific circumstances, strictly on a need-to-know basis and in accordance with applicable laws, operational requirements, and security considerations. Such sharing shall be limited, proportionate, and subject to appropriate safeguards. The categories of data sharing include, but are not limited to, the following:
5.1 Service Providers & Infrastructure Partners
We may share data with trusted third-party service providers who support the operation of the Platform, including:
- - Payment gateways and financial processors
- - KYC and identity verification providers
- - Cloud storage and hosting services
- - Analytics and performance monitoring tools
- - Communication and notification systems
Such providers are contractually obligated to process data only for specified purposes and maintain reasonable data protection standards.
5.2 User-to-User Data Sharing (Service Execution)
To enable service delivery, certain data may be shared between Users, including:
- - Client contact details shared with Service Providers
- - Service Provider profile and verification details shared with Clients
- - Location-related data necessary for service fulfillment
Users acknowledge that such data sharing is essential for the functioning of the Platform and consent to such exchanges. Bourmeg shall not be responsible for misuse of data exchanged directly between Users outside the controlled environment of the Platform.
5.3 Legal Authorities & Law Enforcement
We may disclose User data to:
- - Government authorities
- - Law enforcement agencies
- - Regulatory bodies
Such disclosure may occur:
- - In response to lawful requests, legal notices, or court orders
- - For the purpose of investigation, prevention, or prosecution of illegal activities
- - To protect the rights, safety, and integrity of the Platform and its Users
5.4 Fraud Detection & Risk Intelligence Partners
We may share data with fraud detection agencies, security partners, and risk assessment systems to:
- - Identify suspicious activities
- - Prevent financial fraud and abuse
- - Enhance platform security
Such sharing may include behavioral data, device information, and transaction patterns.
5.5 Business Transfers & Corporate Restructuring
In the event of a merger, acquisition, investment, restructuring, or sale of assets, User data may be transferred as part of the business transaction. Users acknowledge that such transfers may occur as a standard business practice, subject to continued data protection obligations.
5.6 Cross-Border Data Transfers
User data may be stored, processed, or transferred to servers located outside India, including to jurisdictions with different data protection laws. By using the Platform, Users consent to such transfers, provided that reasonable safeguards are implemented to protect their data.
5.7 Communication Monitoring & Evidence Use
Data related to User communications (including chats and support interactions) may be:
- - Accessed internally for dispute resolution
- - Shared with legal authorities when required
- - Used as evidence in investigations or legal proceedings
5.8 No Sale of Personal Data
Bourmeg does not sell Personal Data to third parties for monetary consideration. However, data may be used for internal analytics, personalization, and business intelligence purposes in accordance with this Policy.
5.9 Limited Liability for Third-Party Practices
While Bourmeg ensures reasonable due diligence in selecting third-party partners, it shall not be held liable for:
- - Data breaches or failures occurring within third-party systems
- - Unauthorized use of data by third-party services beyond Bourmeg’s control
Users are encouraged to review the privacy policies of such third parties before engaging with their services. Bourmeg ensures that all data sharing practices are aligned with the principles of necessity, proportionality, and legal compliance. By using the Platform, Users expressly acknowledge and consent to such data sharing arrangements as described in this Policy.
6. COOKIES & TRACKING TECHNOLOGIES
Bourmeg uses cookies, tracking technologies, and similar tools to enhance user experience, ensure platform functionality, analyze usage patterns, and support personalization and security mechanisms. By accessing or using the Platform, Users consent to the use of such technologies in accordance with this Policy, unless disabled through available browser or device settings.
6.1 What Are Cookies
Cookies are small data files stored on a User’s device that help the Platform recognize the User, remember preferences, and improve functionality. In addition to cookies, Bourmeg may use technologies such as web beacons, pixels, local storage, and device fingerprinting to collect and process information.
6.2 Types of Cookies & Tracking Technologies Used
(a) Essential Cookies These are necessary for the basic functioning of the Platform, including:
- - User authentication and login sessions
- - Security and fraud prevention
- - Account management
Disabling these may result in limited or non-functional services. (b) Performance & Analytics Cookies Used to collect information about how Users interact with the Platform, including:
- - Pages visited
- - Time spent on features
- - Error logs and performance data
This helps improve platform performance and user experience. (c) Functional Cookies These enable enhanced functionality and personalization, including:
- - Remembering user preferences
- - Customizing interface settings
- - Enhancing usability
(d) Advertising & Personalization Technologies We may use tracking technologies to:
- - Deliver personalized advertisements
- - Measure effectiveness of promotional campaigns
- - Analyze user behavior for targeted marketing
Such tracking may involve behavioral profiling and usage analytics.
6.3 Device Fingerprinting & Advanced Tracking
In addition to cookies, Bourmeg may use device fingerprinting and similar technologies to:
- - Identify devices uniquely
- - Detect suspicious or fraudulent activity
- - Prevent multiple account abuse
Such tracking may operate even where traditional cookies are disabled.
6.4 Third-Party Tracking Technologies
Third-party service providers integrated with the Platform (such as analytics tools or payment services) may use their own cookies and tracking mechanisms. Bourmeg does not control such third-party technologies and Users are advised to review their respective privacy policies.
6.5 User Control & Opt-Out Options
Users may manage or disable cookies through their browser or device settings. However:
- - Disabling cookies may impact platform functionality
- - Certain features may become unavailable
- - Security and fraud detection capabilities may be limited
For advertising-related tracking, Users may opt out where such options are provided, subject to applicable laws and technical limitations.
6.6 Consent & Continued Usage
By continuing to use the Platform, Users acknowledge and agree to the use of cookies and tracking technologies as described in this section. Withdrawal of consent may require discontinuation of certain Platform features or Services. Bourmeg ensures that all tracking technologies are used responsibly, proportionately, and in alignment with legitimate business purposes including security, analytics, and personalization.
7. COMMUNICATION POLICY
Bourmeg may communicate with Users through various channels for operational, transactional, promotional, security, and legal purposes. By registering on or using the Platform, Users expressly consent to receiving such communications as outlined below.
7.1 Types of Communications
(a) Transactional Communications These include essential messages required for the functioning of the Platform, such as:
- - OTPs and authentication messages
- - Booking confirmations and updates
- - Payment confirmations and transaction alerts
- - Service-related notifications
Such communications are mandatory and cannot be opted out of while using the Platform. (b) Security & System Alerts We may send communications related to:
- - Suspicious login attempts
- - Account activity alerts
- - Security warnings and risk notifications
- - Account compromise or unauthorized access alerts
These communications are critical for protecting User accounts and platform integrity. (c) Administrative & Legal Communications We may send important notices regarding:
- - Policy updates and changes
- - Terms of Service modifications
- - Legal notices and compliance requirements
- - Dispute-related communications
Users acknowledge that such communications are legally binding and form part of their agreement with the Platform. (d) Promotional & Marketing Communications We may send:
- - Offers, discounts, and promotional campaigns
- - Service recommendations and updates
- - Personalized advertisements (where applicable)
Users may opt out of promotional communications at any time through available settings or unsubscribe options.
7.2 Communication Channels
Communications may be sent through:
- - SMS
- - In-app notifications
- - Push notifications
- - Automated calls or messaging systems (where applicable)
Users are responsible for ensuring that their contact information is accurate and up to date.
7.3 Consent & Authorization
By providing contact details and using the Platform, Users:
- - Consent to receive communications from Bourmeg
- - Authorize the use of automated systems for message delivery
- - Acknowledge that certain communications are essential and cannot be disabled
7.4 Delivery & Responsibility
Bourmeg shall make reasonable efforts to ensure delivery of communications; however:
- - Delivery may be affected by network issues, device settings, or third-party service failures
- - Bourmeg shall not be liable for delayed, failed, or undelivered communications
Users are responsible for checking their registered communication channels regularly.
7.5 Misuse & Restrictions
Users agree not to misuse communication channels provided by the Platform, including:
- - Sending abusive, fraudulent, or illegal messages
- - Attempting to bypass Platform communication systems
Bourmeg reserves the right to monitor, restrict, or take action against misuse of communication systems. Bourmeg ensures that all communications are conducted in accordance with applicable laws and are limited to purposes necessary for platform operation, user engagement, and legal compliance.
8. DATA RETENTION POLICY
Bourmeg retains User data for as long as necessary to fulfill the purposes outlined in this Privacy Policy, including service delivery, legal compliance, dispute resolution, fraud prevention, and enforcement of platform policies. The duration of data retention may vary depending on the nature of the data, the purpose for which it was collected, and applicable legal or regulatory requirements.
8.1 General Retention Principles
- - Data is retained only for as long as it is necessary and relevant for operational, legal, and
security purposes
- - Retention periods may be extended in cases involving disputes, investigations, or regulatory
obligations
- - Certain data may be retained in anonymized or aggregated form for analytics and business
intelligence purposes
8.2 Account-Related Data
- - User account data is retained for the duration of the account’s existence
- - Upon account deletion request, data may be retained for a reasonable period to process the
request and ensure compliance Inactive accounts may be flagged and subject to restricted access, archival, or deletion after a defined period as determined by Bourmeg.
8.3 Financial & Transactional Data
- - Financial records, including transactions, payments, wallet history, and tax-related data, may
be retained for a minimum period as required under applicable laws (including up to 8 years or more where necessary)
- - Such data may not be deleted upon User request where retention is legally mandated
8.4 KYC & Verification Data
- - Identity verification data may be retained for compliance, fraud prevention, and audit purposes
- - Even after account deletion, certain KYC data may be retained to prevent identity misuse,
duplicate accounts, or fraudulent re-registration
8.5 Communication & Dispute Data
- - Chat records, support communications, and dispute-related data may be retained for
evidentiary, legal, and investigation purposes
- - Such data may be preserved beyond normal retention periods if required for ongoing or
potential disputes
8.6 Security Logs & Fraud Detection Data
- - Device logs, login history, risk signals, and fraud detection data may be retained for security
monitoring and future risk assessment
- - This data may be used to identify repeat offenders or suspicious patterns
8.7 Retention Despite Deletion Requests
Bourmeg reserves the right to retain certain data even after a User requests deletion, including but not limited to:
- - Legal compliance requirements
- - Fraud prevention and investigation
- - Enforcement of platform policies
- - Protection of rights, property, or safety of Users or the Platform
8.8 Data Deletion Requests
- - Users may request deletion of their data by contacting the Platform through designated
channels
- - Such requests shall be processed within a reasonable timeframe (which may extend up to 90
days or longer depending on complexity)
- - Identity verification may be required before processing deletion requests
8.9 Anonymization & Aggregation
- - Data may be anonymized or aggregated in a manner that no longer identifies the User
- - Such anonymized data may be retained indefinitely for analytics, research, and business
purposes Bourmeg ensures that data retention practices are aligned with legal obligations, operational requirements, and legitimate business interests. Users acknowledge that complete deletion of all data may not always be possible due to regulatory, technical, or security constraints.
9. DATA SECURITY
Bourmeg implements a range of technical, administrative, and organizational security measures designed to protect User data from unauthorized access, misuse, alteration, disclosure, or destruction. These measures are aligned with industry standards and are continuously reviewed and updated to address evolving security risks.
9.1 Security Measures Implemented
Bourmeg employs multiple layers of security, including but not limited to:
- - Encryption protocols for data transmission and storage (where applicable)
- - Secure servers and infrastructure protection mechanisms
- - Access control systems with restricted and role-based permissions
- - Continuous monitoring and anomaly detection systems
- - Firewall protection and intrusion detection mechanisms
9.2 Account Security & Authentication
- - OTP-based verification is implemented for account access and sensitive actions
- - Optional multi-factor authentication (2FA) may be provided for enhanced security
- - Users may receive alerts for suspicious login attempts or unusual activity
Users are responsible for maintaining the confidentiality of their account credentials, including passwords, OTPs, and device access.
9.3 User Responsibility & Negligence
Users acknowledge and agree that:
- - Sharing passwords, OTPs, or account access with third parties may result in unauthorized use
- - Failure to secure devices or credentials may lead to account compromise
Bourmeg shall not be held liable for any loss, damage, or unauthorized activity arising from User negligence, including but not limited to credential sharing, phishing attacks, or device compromise.
9.4 Monitoring & Security Investigations
Bourmeg may monitor system activity, login patterns, device behavior, and transaction anomalies to:
- - Detect unauthorized access or suspicious behavior
- - Investigate potential security incidents
- - Take preventive or corrective action, including account restriction or suspension
9.5 Account Compromise Handling
In the event of a suspected or reported account compromise:
- - Bourmeg may temporarily restrict access to the account
- - Conduct an internal investigation based on logs, device data, and activity history
- - Require identity verification before restoring access
While Bourmeg may assist in investigating such incidents, it does not guarantee recovery of lost data, funds, or access.
9.6 Limitations of Security
While Bourmeg strives to implement robust security measures, Users acknowledge that:
- - No system can be completely secure or immune from breaches
- - Cyber-attacks, unauthorized access, or technical failures may occur despite reasonable
safeguards Accordingly, Bourmeg does not guarantee absolute security of User data.
9.7 Third-Party Security Risks
Certain services, including payment processing and verification systems, are operated by third-party providers. Bourmeg shall not be held responsible for:
- - Security breaches occurring within third-party systems
- - Failures or vulnerabilities beyond its direct control
Users are advised to review the security practices of such third-party services.
9.8 Force Majeure & Uncontrollable Events
Bourmeg shall not be liable for any data breach, loss, or unauthorized access resulting from events beyond its reasonable control, including but not limited to:
- - Natural disasters
- - Cyber warfare or large-scale attacks
- - Government actions or regulatory restrictions
- - Network or infrastructure failures
Bourmeg is committed to maintaining a secure environment for its Users; however, Users acknowledge that participation in digital platforms involves inherent risks, and they agree to use the Platform with due caution and responsibility.
10. USER RIGHTS (DPDP COMPLIANCE)
In accordance with the Digital Personal Data Protection Act, 2023 and other applicable laws, Users are granted certain rights regarding their personal data. Bourmeg is committed to facilitating these rights, subject to reasonable limitations, verification requirements, and legal obligations.
10.1 Right to Access
Users have the right to request access to the personal data held by Bourmeg, including information on how such data is processed and used. Such requests may be subject to:
- - Identity verification
- - Reasonable processing time
- - Limitations where disclosure may affect security, fraud prevention, or legal obligations
10.2 Right to Correction
Users may request correction of inaccurate, incomplete, or outdated personal data. Bourmeg reserves the right to:
- - Verify the authenticity of correction requests
- - Reject or delay requests that are inconsistent, fraudulent, or unverifiable
10.3 Right to Erasure (Deletion)
Users may request deletion of their personal data, subject to the Data Retention Policy outlined in this document. Deletion requests may be:
- - Partially fulfilled where complete deletion is not feasible
- - Denied or delayed where retention is required for legal compliance, fraud prevention, dispute
resolution, or enforcement purposes
10.4 Right to Withdraw Consent
Users may withdraw consent for specific data processing activities at any time. However, Users acknowledge that:
- - Withdrawal of consent may result in limited or complete loss of access to the Platform
- - Certain data processing activities are essential and cannot be discontinued without affecting
service availability
10.5 Right to Grievance Redressal
Users have the right to raise complaints or concerns regarding data processing. Bourmeg shall:
- - Acknowledge and review such complaints
- - Respond within a reasonable timeframe
- - Take appropriate corrective actions where required
10.6 Right to Restrict or Object (Where Applicable)
Users may request restriction or object to certain types of data processing, including:
- - Promotional communications
- - Personalization activities
Such requests may be honored subject to technical feasibility and operational requirements.
10.7 Limitations & Exceptions
The rights provided under this section are not absolute and may be restricted under circumstances including, but not limited to:
- - Legal or regulatory obligations
- - Ongoing or potential disputes
- - Fraud detection, prevention, or investigation
- - Protection of platform integrity, security, or other Users
Bourmeg reserves the right to deny, limit, or defer any request that is:
- - Excessive, repetitive, or abusive
- - Technically impractical
- - Likely to compromise security or operational integrity
10.8 Request Processing & Verification
- - All requests must be submitted through designated communication channels
- - Identity verification may be required before processing requests
- - Processing timelines may vary depending on the nature and complexity of the request
Bourmeg ensures that User rights are respected in accordance with applicable laws while maintaining necessary safeguards to prevent misuse, protect platform integrity, and comply with legal obligations.
11. CHILDREN’S PRIVACY
Bourmeg’s Services are intended solely for individuals who are legally capable of entering into binding contracts under applicable laws. Accordingly, the Platform is not designed for or directed at individuals below the age of 18 years.
11.1 No Intentional Data Collection from Minors
Bourmeg does not knowingly collect, process, or store Personal Data from individuals under the age of 18. If it comes to our knowledge that data has been collected from a minor without appropriate authorization, such data shall be subject to review and may be deleted in accordance with applicable laws and internal policies.
11.2 Responsibility of Users
Users represent and warrant that:
- - They are at least 18 years of age
- - They possess the legal capacity to use the Platform
If a User is found to have misrepresented their age:
- - Bourmeg reserves the right to suspend or terminate the account
- - Any associated data or activity may be restricted or removed
11.3 Parental or Guardian Concerns
If a parent or legal guardian becomes aware that a minor has provided personal data to the Platform, they may contact Bourmeg through designated channels to request review or removal of such data. Such requests may be subject to identity verification and legal requirements.
11.4 Limitation of Liability
Bourmeg shall not be held liable for any unauthorized use of the Platform by minors, including cases where:
- - Age is misrepresented
- - Accounts are accessed using another User’s credentials
- - Devices are shared without adequate supervision
Bourmeg encourages parents and guardians to monitor and guide the online activities of minors and ensure that they do not access or use the Platform without proper authorization.
12. THIRD-PARTY LINKS & SERVICES
The Platform may contain links to third-party websites, applications, or services, and may integrate or rely on external service providers to facilitate certain functionalities. Bourmeg does not own, operate, or control such third-party platforms and shall not be responsible for their practices, policies, or actions.
12.1 External Links
The Platform may include links to external websites or services for user convenience or operational purposes. Users acknowledge that:
- - Accessing such links is at their own discretion and risk
- - Bourmeg does not endorse or guarantee the accuracy, reliability, or safety of such third-party
content Users are advised to review the privacy policies and terms of such third-party platforms before interacting with them.
12.2 Integrated Third-Party Services
Bourmeg may integrate third-party services including, but not limited to:
- - Payment gateways
- - Identity verification (KYC) providers
- - Analytics and tracking tools
- - Communication systems
Such services may independently collect, process, or store User data in accordance with their own privacy policies.
12.3 No Control Over Third-Party Practices
Bourmeg does not control:
- - Data collection practices of third parties
- - Data storage or processing mechanisms used by them
- - Security measures implemented by such providers
Accordingly, Bourmeg shall not be held liable for:
- - Data breaches, leaks, or unauthorized access occurring within third-party systems
- - Misuse of data by third-party service providers
- - Service failures, interruptions, or inaccuracies caused by third-party systems
12.4 User Responsibility
Users are responsible for:
- - Reviewing and understanding the policies of third-party services
- - Exercising caution when sharing data with external platforms
12.5 Third-Party Communication & Transactions
Any interaction, communication, or transaction conducted directly between the User and a third-party service provider shall be governed solely by the terms and policies of that third party. Bourmeg shall not be responsible for:
- - Disputes arising between Users and third-party services
- - Losses, damages, or claims resulting from such interactions
12.6 Future Integrations
Bourmeg may introduce new third-party integrations from time to time to enhance functionality and user experience. Continued use of the Platform after such integrations shall be deemed acceptance of any associated data-sharing practices, subject to this Policy. Bourmeg ensures reasonable due diligence in selecting third-party partners; however, Users acknowledge that external services operate independently and are beyond the direct control of the Platform.
13. DATA TRANSFER
Bourmeg may store, process, and transfer User data to servers, systems, or service providers located within or outside India, depending on operational requirements, infrastructure needs, and third-party integrations.
13.1 Cross-Border Data Transfers
User data may be transferred to jurisdictions outside India, including to countries that may have different data protection laws than those applicable within India. Such transfers may occur for purposes including:
- - Cloud storage and infrastructure services
- - Payment processing and financial systems
- - Analytics and performance monitoring
- - Fraud detection and security operations
13.2 Consent to Transfer
By using the Platform, Users expressly consent to the transfer, storage, and processing of their data in locations outside India, where such transfer is necessary for providing Services or maintaining platform functionality.
13.3 Safeguards & Protections
Bourmeg shall take reasonable steps to ensure that:
- - Data transferred to external jurisdictions is handled securely
- - Appropriate contractual or technical safeguards are implemented where feasible
However, Users acknowledge that:
- - Data protection laws in other jurisdictions may differ from those in India
- - Absolute equivalence of legal protections cannot be guaranteed
13.4 Third-Party Transfers
Where data is processed by third-party service providers located outside India:
- - Such providers shall operate under their own data protection frameworks
- - Bourmeg shall not be held liable for differences in legal standards or regulatory requirements
in such jurisdictions
13.5 Operational Necessity
Users understand and agree that cross-border data transfer may be essential for:
- - Efficient platform performance
- - Global infrastructure reliability
- - Integration with industry-standard technology providers
Refusal to consent to such transfers may result in limited or restricted access to the Platform.
13.6 Transitional Data Storage Arrangement
At present, certain User data may be stored and processed on servers located in jurisdictions outside India, including but not limited to Europe, as part of Bourmeg’s existing infrastructure and third-party service integrations. Bourmeg intends to transition and localize data storage within India by or around November 2026, subject to operational, technical, and regulatory considerations. During this transition period:
- - Data may continue to be stored and processed across multiple jurisdictions
- - Appropriate safeguards and security measures shall be maintained
- - Cross-border data transfer provisions outlined in this Policy shall continue to apply
Users acknowledge and consent to such transitional arrangements and understand that data storage locations may change as part of infrastructure optimization and regulatory alignment. Bourmeg reserves the right to modify timelines, infrastructure strategies, or data storage locations based on business needs, legal requirements, or technological constraints. Bourmeg ensures that cross-border data transfers are conducted in a manner consistent with operational requirements, legal obligations, and reasonable data protection practices.
14. DATA BREACH POLICY
Bourmeg takes data security seriously and maintains procedures to identify, respond to, and mitigate potential data breaches or security incidents. A “Data Breach” refers to any unauthorized access, disclosure, alteration, or destruction of User data, whether accidental or intentional.
14.1 Detection & Investigation
In the event of a suspected or confirmed data breach:
- - Bourmeg shall initiate an internal investigation
- - System logs, device data, and access records may be analyzed
- - Necessary steps shall be taken to identify the scope, cause, and impact of the incident
14.2 Mitigation Measures
Bourmeg may take appropriate actions to contain and mitigate the impact of a data breach, including:
- - Restricting or suspending affected systems or accounts
- - Enhancing security controls
- - Coordinating with relevant service providers or authorities
14.3 User Notification
Where required by applicable laws or deemed necessary by Bourmeg:
- - Affected Users may be notified about the breach
- - Such notification may include general information about the nature of the incident and
recommended precautions Bourmeg reserves the right to determine the timing, method, and extent of such notifications based on the severity and nature of the breach.
14.4 Legal & Regulatory Reporting
Bourmeg may report data breaches to:
- - Relevant government authorities
- - Regulatory bodies
- - Law enforcement agencies
Where required under applicable laws or where deemed necessary for investigation and compliance.
14.5 Third-Party Involvement
If a data breach originates from or involves third-party systems:
- - Bourmeg may coordinate with such third parties for investigation and resolution
- - Bourmeg shall not be held liable for breaches occurring solely due to failures within third-party
systems beyond its control
14.6 No Guarantee of Prevention
While Bourmeg implements reasonable security measures, Users acknowledge that:
- - Data breaches may occur due to evolving cyber threats
- - Absolute prevention of all security incidents cannot be guaranteed
14.7 Limitation of Liability
To the maximum extent permitted by law, Bourmeg shall not be held liable for:
- - Indirect, incidental, or consequential damages arising from a data breach
- - Loss of data, financial loss, or reputational harm resulting from unauthorized access
- - Breaches caused by User negligence, third-party failures, or force majeure events
Bourmeg remains committed to maintaining a secure platform environment and will take all reasonable steps to respond to and manage data breach incidents responsibly and in compliance with applicable laws.
15. CONSENT & WITHDRAWAL
Bourmeg processes User data based on consent, legal obligations, and legitimate business purposes as outlined in this Privacy Policy. By accessing, registering on, or using the Platform, Users provide their explicit and informed consent to the collection, processing, storage, and use of their data in accordance with this Policy.
15.1 Nature of Consent
User consent is deemed to be:
- - Free, informed, and specific
- - Provided through acceptance of this Policy and continued use of the Platform
- - Applicable to all data processing activities described herein, unless otherwise restricted by law
15.2 Implied Consent Through Usage
Continued use of the Platform, features, or Services shall constitute ongoing consent to data processing practices, including any updates made to this Policy.
15.3 Withdrawal of Consent
Users may withdraw consent for specific data processing activities by submitting a request through designated communication channels. However, Users acknowledge that:
- - Withdrawal of consent may result in restricted or complete loss of access to certain or all
Services
- - Certain essential data processing activities cannot be discontinued without affecting platform
functionality
15.4 Limitations on Withdrawal
Withdrawal of consent shall not:
- - Affect the lawfulness of processing carried out prior to such withdrawal
- - Require deletion of data where retention is necessary for legal compliance, fraud prevention,
dispute resolution, or enforcement purposes Bourmeg reserves the right to deny or limit withdrawal requests where:
- - Processing is necessary for security or operational integrity
- - There are ongoing disputes or investigations
- - Legal or regulatory obligations require continued processing
15.5 Consequences of Withdrawal
Upon withdrawal of consent:
- - User account access may be restricted, suspended, or terminated
- - Certain features or functionalities may become unavailable
- - Ongoing services or transactions may be affected or discontinued
15.6 Re-Consent & Re-Activation
If a User withdraws consent and later wishes to resume use of the Platform:
- - Fresh consent may be required
- - Additional verification or compliance steps may be enforced
Bourmeg ensures that consent is obtained and managed in a transparent manner, while maintaining necessary safeguards to prevent misuse, protect platform integrity, and comply with applicable laws.
16. GRIEVANCE REDRESSAL
Bourmeg is committed to addressing User concerns, complaints, and grievances related to data privacy and processing in a fair, transparent, and timely manner, in accordance with applicable laws.
16.1 Grievance Officer
In compliance with applicable legal requirements, Bourmeg has designated a Grievance Officer to handle privacy-related concerns. Details of the Grievance Officer:
- - Name: [Ravjee Khasiya]
- - Email: help@bourmeg.com
- - Address: [Pichhva, gir Gadhda, Gujarat 362530]
16.2 Scope of Grievances
Users may raise concerns relating to:
- - Data collection and processing practices
- - Data access, correction, or deletion requests
- - Unauthorized use or suspected misuse of data
- - Privacy violations or security concerns
16.3 Submission of Complaints
Grievances may be submitted through:
- - Email communication to the designated Grievance Officer
- - Any official support channel provided by the Platform
Users are required to provide sufficient details to enable proper investigation of the complaint.
16.4 Acknowledgment & Response Timeline
- - Bourmeg shall acknowledge receipt of a grievance within a reasonable timeframe
- - Efforts shall be made to resolve the complaint within a time period consistent with applicable
legal requirements Response timelines may vary depending on:
- - Nature and complexity of the issue
- - Requirement for verification or investigation
16.5 Investigation & Resolution
Bourmeg may:
- - Review relevant data, logs, and communications
- - Seek additional information or clarification from the User
- - Take appropriate corrective actions where required
16.6 Escalation Rights
If a User is not satisfied with the resolution provided, they may:
- - Escalate the matter to relevant regulatory authorities
- - Seek remedies available under applicable laws
16.7 Misuse & False Complaints
Bourmeg reserves the right to:
- - Reject or deprioritize complaints that are frivolous, abusive, or submitted with malicious intent
- - Take appropriate action against Users misusing grievance mechanisms
Bourmeg aims to maintain a responsive and accountable grievance redressal system while ensuring protection against misuse and maintaining operational efficiency.
17. LEGAL COMPLIANCE
Bourmeg is committed to complying with all applicable laws, regulations, and legal frameworks governing data protection, privacy, and digital services within India.
17.1 Applicable Laws
This Privacy Policy is designed to comply with, and shall be interpreted in accordance with, applicable Indian laws, including but not limited to:
- - The Digital Personal Data Protection Act, 2023
- - The Information Technology Act, 2000
- - Relevant rules, regulations, and guidelines issued by competent authorities
17.2 Regulatory Cooperation
Bourmeg shall cooperate with:
- - Government authorities
- - Regulatory bodies
- - Law enforcement agencies
Where required for:
- - Legal compliance
- - Investigation of unlawful activities
- - Enforcement of regulatory requirements
17.3 Dynamic Compliance Framework
Bourmeg acknowledges that data protection laws and regulatory standards may evolve over time. Accordingly, Bourmeg reserves the right to:
- - Update its data processing practices
- - Modify this Privacy Policy
- - Implement additional safeguards or controls
To ensure continued compliance with applicable legal and regulatory requirements.
17.4 International Standards (Future Readiness)
While currently focused on compliance within India, Bourmeg may align its practices with internationally recognized data protection standards where required for operational or expansion purposes. Such standards may include, but are not limited to:
- - General data protection principles recognized globally
- - Industry best practices for data security and privacy
17.5 Interpretation & Priority
In the event of any conflict between this Privacy Policy and applicable laws:
- - Applicable law shall prevail to the extent required
- - The remaining provisions of this Policy shall continue to remain in full force and effect
Bourmeg is committed to maintaining a legally compliant, transparent, and accountable data protection framework that adapts to evolving legal and technological landscapes.
18. POLICY UPDATES
Bourmeg reserves the right, at its sole discretion, to modify, update, amend, or replace this Privacy Policy at any time to reflect changes in legal requirements, technological advancements, business practices, or operational needs.
18.1 Right to Modify
Bourmeg may revise this Policy without prior individual notice to Users, subject to applicable legal requirements. Updates may include, but are not limited to:
- - Changes in data collection or processing practices
- - Introduction of new features or services
- - Updates required for legal or regulatory compliance
18.2 Notification of Changes
Where required or deemed appropriate, Bourmeg may notify Users of significant changes through:
- - Email notifications
- - In-app alerts or banners
- - Platform announcements
However, Bourmeg shall not be obligated to provide individual notice for every modification.
18.3 Effective Date of Updates
All changes to this Policy shall become effective:
- - Immediately upon publication on the Platform, or
- - On such date as specified in the updated Policy
18.4 User Responsibility
Users are responsible for periodically reviewing this Privacy Policy to stay informed of any updates or changes.
18.5 Continued Use as Acceptance
Continued access to or use of the Platform after any modifications to this Policy shall constitute:
- - Deemed acceptance of the updated terms
- - Ongoing consent to revised data processing practices
18.6 Disagreement with Updates
If a User does not agree with any updates to this Policy:
- - The User must discontinue use of the Platform immediately
- - Continued usage shall override such disagreement
Bourmeg ensures that all updates are made in good faith and in alignment with legal, operational, and technological developments while maintaining transparency and accountability.
19. CONTACT US
Bourmeg provides multiple channels for Users to reach out for queries, concerns, or support related to privacy, data protection, and Platform usage.
19.1 General Inquiries
For general questions, assistance, or support requests, Users may contact:
- - Email: help@bourmeg.com
19.2 Privacy & Data-Related Concerns
For matters specifically related to privacy, data processing, or personal data requests, Users are encouraged to contact:
- - Email: help@bourmeg.com
Users may mark their communication as “Privacy Urgent” where immediate attention is required.
19.3 Response Expectations
Bourmeg shall make reasonable efforts to:
- - Acknowledge communications within a reasonable timeframe
- - Provide responses or resolutions based on the nature and complexity of the request
19.4 Communication Guidelines
Users are advised to:
- - Provide accurate and complete information while contacting the Platform
- - Use official communication channels only
Bourmeg shall not be responsible for:
- - Communications sent to unofficial or incorrect channels
- - Delays caused due to incomplete or inaccurate information provided by Users
19.5 Record of Communication
Bourmeg may maintain records of communications for:
- - Support and service improvement
- - Dispute resolution
- - Legal and compliance purposes
Bourmeg is committed to maintaining accessible, transparent, and efficient communication channels to support its Users and address their concerns effectively.
20. DATA LIMITATION & LIABILITY
Bourmeg implements reasonable measures to protect User data and ensure secure operation of its Services. However, Users acknowledge and agree that the use of digital platforms involves inherent risks, and Bourmeg’s liability shall be limited as set forth in this section.
20.1 No Absolute Security Guarantee
While Bourmeg employs industry-standard security measures, it does not guarantee:
- - Absolute protection against unauthorized access
- - Complete prevention of data breaches or cyber-attacks
- - Continuous or error-free operation of the Platform
Users acknowledge that no system can be entirely secure.
20.2 User Responsibility & Negligence
Users are solely responsible for:
- - Maintaining confidentiality of account credentials (passwords, OTPs, device access)
- - Avoiding sharing sensitive information with third parties
- - Securing their devices and communication channels
Bourmeg shall not be liable for any loss, damage, or unauthorized activity resulting from:
- - User negligence or misconduct
- - Credential sharing or phishing attacks
- - Unauthorized access due to user-side vulnerabilities
20.3 Third-Party Risks
Bourmeg shall not be held responsible for:
- - Failures, breaches, or disruptions caused by third-party service providers
- - Unauthorized access or misuse of data occurring within third-party systems
- - Errors or delays in payment processing, verification, or communication services
20.4 User-to-User Interactions
Bourmeg acts solely as an intermediary platform and shall not be liable for:
- - Misuse of data exchanged between Users
- - Unauthorized use of contact information shared during service execution
- - Disputes arising from off-platform interactions
20.5 Indirect & Consequential Losses
To the maximum extent permitted by law, Bourmeg shall not be liable for:
- - Indirect, incidental, special, or consequential damages
- - Loss of profits, business opportunities, or reputation
- - Data loss or financial loss arising from unauthorized access or system failures
20.6 Force Majeure
Bourmeg shall not be liable for any failure or delay in performance, or for any data loss or breach, resulting from events beyond its reasonable control, including but not limited to:
- - Natural disasters
- - Cyber warfare or large-scale attacks
- - Government actions or regulatory restrictions
- - Network, server, or infrastructure failures
20.7 Platform Role Limitation
Bourmeg operates as a technology-enabled intermediary and does not:
- - Independently verify all User-provided data in real-time
- - Guarantee the accuracy, completeness, or reliability of User-generated content
20.8 Limitation to Maximum Extent Permitted by Law
All limitations of liability set forth in this Policy shall apply to the maximum extent permitted under applicable laws. By using the Platform, Users expressly acknowledge and agree to the limitations of liability described herein and accept the inherent risks associated with digital services.
21. FINAL ACKNOWLEDGEMENT
By accessing, registering on, or using the Bourmeg Platform, Users acknowledge that they have read, understood, and agreed to this Privacy Policy in its entirety. Users further confirm that:
- - They have been informed about the nature, scope, and purpose of data collection and
processing
- - They consent to the use, storage, and sharing of their data as described in this Policy
- - They understand the risks associated with digital platforms and agree to use the Services at
their own discretion If a User does not agree with any provision of this Privacy Policy, they must immediately discontinue use of the Platform. Continued access to or use of the Platform shall constitute:
- - Ongoing acceptance of this Policy
- - Binding agreement to its terms
- - Confirmation of informed consent
This Privacy Policy forms an integral part of the Platform’s legal framework and shall be read in conjunction with all other applicable policies and terms governing the use of Bourmeg Services.