Privacy Policy
Effective 27 June 2026. Compliant with the Digital Personal Data Protection Act, 2023. View Terms & Conditions →
Effective Date: 27 June 2026 | Last Updated: 27 September 2026 | Version: 2.3
This Privacy Policy explains how Vilkanundo (operated by Domoimate), the operator of vilkanundo.com and the Vilkanundo mobile app (together, the "Platform"), collects, uses, stores, shares, and protects your personal data, in accordance with the Digital Personal Data Protection Act, 2023 ("DPDP Act"), the Information Technology Act, 2000, and applicable rules thereunder.
Our Vision
Privacy is a commitment, not a checkbox.
We collect the minimum data required to run a safe, working marketplace — nothing more. We do not sell your data. We do not build shadow profiles. We do not track you across the web for advertisers. Your Aadhaar number is never stored in our systems. Every third party we share data with is named in this document, together with why. You can see, correct, export, or delete your data at any time. If we ever get this wrong, we will tell you plainly, and we will fix it.
BY CREATING AN ACCOUNT, YOU CONSENT TO THE COLLECTION AND PROCESSING OF YOUR PERSONAL DATA AS DESCRIBED IN THIS PRIVACY POLICY. ACCOUNT CREATION IS ONLY PERMITTED AFTER YOU ACCEPT THIS POLICY VIA THE MANDATORY CONSENT CHECKBOX AT SIGN-UP (OR THE EQUIVALENT "BY CONTINUING" NOTICE IN THE MOBILE APP'S OAUTH SIGN-IN).
1. Information We Collect
1.1 Information you provide directly
- Name, mobile number, email address, and password at registration (you may sign in with a Google account, Apple ID, a verified mobile number via OTP, an email/password, or a combination of these linked to one account);
- Profile details (display name, location, profile photo, preferred language);
- Listing details — item description, price, category, photos, video, location, condition. Uploaded photos and videos are processed on our servers to compress them, add a watermark, and reorder video data so it plays without waiting for a full download; no additional personal information is derived from them;
- Business details, where you register or apply for business verification (business name, address, GSTIN, licence numbers, supporting documents);
- Messages and media you send to other Users through the Platform's chat feature, including images, videos and voice messages;
- Reviews, ratings, and reports you submit about other Users or Listings;
- Communications with us (support requests, bug reports and any attached screenshots, grievance complaints, replies to our support chat);
- Saved searches and saved (favourited) Listings;
- Payment records for paid features (the Listing, amount, date, and the payment provider's reference) — never your card number, CVV, UPI PIN or bank credentials.
1.2 Information collected automatically
- Device information (make, model, OS version, app version, screen size, language, timezone);
- IP address and approximate location derived from it (city-level);
- Browser type and referrer (web);
- Usage data (pages viewed, searches, listings viewed / clicked / saved / reported, chat threads opened, login times, feature interactions);
- Contact actions — when you tap Call or WhatsApp on a Listing we record that the tap happened, against your account and that Listing, so we can measure genuine buyer interest and detect misuse. We record only that you tapped; we do not record, route, listen to, or otherwise access the call or the WhatsApp conversation itself, which take place entirely outside the Platform;
- Chat status — whether messages have been read, and when you were last active;
- Aggregate statistics about Listings (such as views of a Featured Ad), which are counts, not information about individual viewers;
- Approximate or precise device location, only when you grant location permission for a location-based feature (e.g. "Near me", distance sorting);
- A device push-notification token (via Google Firebase Cloud Messaging), only if you enable notifications, used solely to deliver alerts to your device;
- Diagnostic and crash reports (via Sentry-style tools when enabled) to help us fix bugs;
- Cookies and similar tracking technologies on the website (see §5).
1.3 Information from third parties
If you sign up or sign in via a third-party login (e.g., Google, Apple), we receive basic profile information as permitted by that service (email, name, profile picture, provider user id). We do not receive your contact list, calendar, or drive contents from those providers. If you sign in with a mobile number, we receive delivery confirmation from our SMS/OTP gateway provider but not the content of the SMS itself.
1.4 Identity verification (Aadhaar KYC)
Aadhaar verification is required to post a Listing, and unlocks the display of other Users' phone numbers. It is not required to browse, search, read, or send messages. You may choose either of two methods, and both are optional to you:
- DigiLocker.You are taken to the Government of India's DigiLocker service, where you sign in and consent to share your Aadhaar details. This is facilitated by SurePass Technologies Pvt. Ltd. Under this method your full Aadhaar number is never disclosed to us or to SurePass — DigiLocker returns only your name, date of birth, gender, address and a masked Aadhaar number (e.g., XXXXXXXX1234), together with a non-reversible identifier used solely to prevent one Aadhaar being used on multiple accounts.
- Aadhaar OTP. You enter your Aadhaar number, which is transmitted securely to Cashfree Payments India Pvt. Ltd. through its government-authorised Verification Suite (KYC) API solely to trigger a one-time UIDAI OTP.
Under either method we never store your full Aadhaar number on our servers. Upon successful verification we retain only: (a) your name as returned by the verification provider, (b) the Aadhaar number in masked form showing only the last four digits, (c) your address as returned by the provider, and (d) a one-way, non-reversible identifier used exclusively to prevent the same Aadhaar from being used on multiple accounts. That identifier cannot be reversed to recover the Aadhaar number. We do not collect, process, or store any biometric information.
1.5 Wallet and referral activity
If you participate in the Refer & Earn program, we record your referral code, the accounts it is used by, the timestamps of those events, and the resulting Wallet credit history on your account, in order to administer the program and prevent abuse.
1.6 Consent records
We record the timestamp at which you accepted these terms (terms_accepted_at), and the method by which you accepted (checkbox at signup, OAuth notice, OTP name step). This record serves as evidence of your consent under the DPDP Act.
2. Purpose of Collection and Use
We collect and use your personal data to:
- Create and manage your account, including resolving sign-in across Google, Apple, mobile-OTP, and email/password so that the same verified identity always reaches the same account;
- Enable you to post Listings, message other Users, and connect with them;
- Confirm, via your Aadhaar verification status, that you are eligible to post a Listing and to see other Users' phone numbers — a control that exists to keep spam, impersonation and fraud away from other Users;
- Operate the mandatory sign-up consent and verification process;
- Send you OTPs for sign-in or verification, and (where enabled) push notifications about relevant account activity;
- Provide location-based features such as "Near me" and distance sorting, when you grant location permission;
- Administer the Wallet and Refer & Earn program, including detecting and reversing abuse;
- Provide paid features such as Featured Ads, including confirming payments, receipts, performance summaries and refunds;
- Support sellers and review business-verification applications (§4.6);
- Provide optional AI-assisted features — AI Camera Draft (from your uploaded photo), listing translation (Malayalam↔English), moderation pre-screening, personalised push copy;
- Rank search results and personalise the home page based on your saved searches and recent browsing;
- Communicate with you (account notices, support, bug reports, grievance responses);
- Maintain administrative and evidentiary records of deleted Listings for a minimum of three (3) years, for fraud-prevention, dispute-resolution, and legal-compliance purposes;
- Detect, prevent, and investigate fraud, misuse, or violations of our Terms;
- Improve and secure the Platform (bug fixes, performance monitoring, security auditing);
- Comply with legal obligations, including responding to lawful requests from law enforcement or regulators.
3. Legal Basis for Processing
We process your personal data on the basis of:
- Your explicit consent, given at the time of account sign-up via the mandatory consent checkbox / OAuth notice, and again for optional device permissions (location, camera, microphone, notifications);
- Performance of contract — where processing is necessary to deliver the services you signed up for (e.g., displaying your Listings, delivering messages you send);
- Legal obligation — where we must process data to comply with Indian law (e.g., retention for IT Rules, responding to lawful requests);
- Legitimate uses recognised under the DPDP Act, 2023 — fraud prevention, safety of Users, record-keeping for legal claims, and the operation of the Platform.
Location, camera, microphone, and notification permissions are separately requested by your device or browser and are entirely optional. You may withdraw consent at any time by contacting us (§13) or, for device permissions, from your device settings — though withdrawing core consent may result in suspension of your account.
4. How We Share Your Information
4.1 With other Users
Listing details (title, description, photos, price, city-level location, seller display name, seller Aadhaar-verified badge if applicable, seller join date) and any information you choose to share in chat are visible to Users you interact with. Your exact phone number is not shared publicly — Buyers contact you via in-app chat by default.
People you chat with can see when you have read their messages and when you were last active. Your Listings (including sold ones, until you delete them) and seller profile are public and may be shown by search engines; your phone number, email and Aadhaar details are never part of those public pages.
4.2 With service providers (Sub-processors)
We share the minimum necessary data with third parties who help us operate the Platform, strictly for that purpose, under contractual confidentiality obligations:
| Sub-processor | Purpose | Data shared |
|---|---|---|
| Cloud hosting (server infrastructure) | Runs the app / database | All data, encrypted at rest |
| Cloudflare R2 (object storage) | Stores and serves images, videos and voice messages | Uploaded media |
| SMS/OTP gateway | Delivers login OTPs | Mobile number |
| Email provider (SMTP) | Sends transactional email | Email address, message body |
| Google Firebase Cloud Messaging | Push notifications | Device token, notification body |
| Cashfree Payments (KYC) | Aadhaar OTP verification | Aadhaar number (not stored by us) |
| SurePass Technologies (DigiLocker) | DigiLocker-based Aadhaar verification | Name, DOB, gender, address, masked Aadhaar — full Aadhaar number never disclosed |
| Payment gateway (Omniware) | Processes website payments for paid features | Order details, amount, and the billing details the gateway requires (name, mobile number, email, town) |
| Google Play / Apple App Store | In-app purchases in the mobile apps | Purchase verification only — payment details stay with Google / Apple |
| Google Gemini (AI) | Listing translation, camera drafts, moderation, notification copy | Only the relevant Listing / photo, no account identifiers |
| Meta / Facebook (Conversions API) | Attribution of ad-driven signups / installs | Hashed email, IP, user-agent — event only |
| Cloudflare | CDN, DDoS protection, caching of public pages for signed-out visitors | IP, request metadata |
4.3 For legal reasons
We may disclose your data, including retained records of deleted Listings, to law enforcement, courts, or regulators where required by law, in response to a valid subpoena / court order, or where we reasonably believe disclosure is necessary to prevent imminent harm.
4.4 In a business transfer
If Vilkanundo is acquired, merged, or its assets sold, your data may be transferred to the successor entity subject to the same or stronger privacy commitments; we will notify you of any such transfer.
4.5 We do not sell your personal data
We do not sell your personal data to third parties for unrelated marketing purposes. We do not build cross-site advertising profiles.
4.6 Internal support systems
We use an internal customer-support system, run on our own infrastructure, to assist sellers and review business-verification applications. It holds contact and account details you have already given us, is accessible only to authorised Vilkanundo staff, and is not shared with third parties.
5. Cookies and Tracking Technologies
The website uses cookies and similar technologies in three categories:
- Strictly necessary — sign-in session, CSRF protection, load-balancer stickiness. Cannot be disabled.
- Functional — remember your language, city, dark-mode preference, dismissed banners.
- Analytics & measurement — first-party page-view counts, Meta Pixel for ad measurement (see §4.2). You can disable these in your browser or by using standard blockers; disabling them does not affect Platform functionality.
The mobile app does not use browser cookies but uses secure device storage (Keychain on iOS, EncryptedSharedPreferences on Android) to hold your session token and settings.
6. Data Retention
| Data Type | Retention Period |
|---|---|
| Active account & profile data | While account is active, plus 90 days after closure for legal/audit purposes, then anonymised |
| Listings (deleted / expired) | Minimum 3 years from date of deletion |
| Chat messages (including voice messages) | While your account and the related Listing conversation remain active, plus a reasonable period thereafter for dispute / fraud investigation |
| Transaction / dispute-related communications | Up to 3 years for evidentiary purposes |
| Wallet / referral ledger | While account is active, plus 6 years after closure for audit purposes (financial-record norm) |
| Payment records for paid features | At least 6 years, for tax, accounting and dispute purposes — even if the Listing or account is deleted |
| Bug reports and support communications | Up to 2 years, for quality and follow-up purposes |
| Device push-notification tokens | Until notifications are disabled or the app is uninstalled / token expires |
| Location data (per-request) | Not stored beyond the session used to serve the location-based result, unless you save a location as a default |
| Login / security logs (IP, UA, timestamp) | 12 months |
| Consent records (terms_accepted_at) | Life of account + 3 years |
| Aadhaar KYC record (name + masked last-4 + fingerprint) | While account is Aadhaar-verified + 3 years after removal |
After the applicable retention period, data is securely deleted or anonymised (aggregated into non-identifying counts), unless a longer period is required by law or an ongoing legal / dispute matter.
7. Data Security
We implement reasonable technical and organisational security measures to protect your data against unauthorised access, alteration, disclosure, or loss:
- Encryption in transit — all traffic between your device and our servers is over HTTPS (TLS 1.2+);
- Encryption at rest — the database and object storage are encrypted at rest by the underlying cloud provider;
- Password hashing — passwords are stored using a modern one-way hashing algorithm; we never store plaintext passwords;
- Session tokens — held in HTTP-only cookies (web) or device secure storage (app), with device-bound revocation;
- Two-factor authentication — available for accounts that opt in, via TOTP authenticator apps;
- Rate limiting — on sign-in, OTP, and sensitive endpoints to deter brute force;
- Access controls — internal access to production data is restricted to named staff on a least-privilege basis, and audit-logged;
- Automated moderation — flags obvious phishing, scam, and prohibited content before it reaches other Users.
However, no system is completely secure, and we cannot guarantee absolute security. You are responsible for the security of your device, your passwords, and any OTP delivered to you.
8. AI Processing Disclosure
Where you use an optional AI-assisted feature (§7 of the Terms), a limited slice of your data is sent to the relevant AI provider (currently Google Gemini) strictly to perform that task:
- AI Camera Draft — the single photo you point the camera at, plus the category if pre-selected. No account identifier is sent.
- Translation — the specific Listing text or chat message you asked to translate. No account identifier.
- Moderation pre-screening — a new Listing's text and thumbnail. No account identifier.
- Notification copy — aggregated keywords derived from your saved searches. No account identifier.
We have contractual assurances from our AI provider that data sent to their API is not used to train their models. If you do not want any AI processing, do not use the AI-marked features — the Platform is fully usable without them.
9. Cross-Border Data Transfer
Certain of our sub-processors (e.g., Google Firebase, Google Play, Apple, Cloudflare, Google Gemini, Meta) may process data on infrastructure located outside India. Where this occurs, we rely on the recipient's public commitments to comply with applicable data-protection standards and, where required, the mechanisms permitted under the DPDP Act, 2023. The Central Government of India may from time to time restrict transfer of personal data to certain countries; we will comply with any such restriction.
10. Your Rights (under the DPDP Act, 2023)
Subject to applicable law, you have the right to:
- Access — request a summary of the personal data we hold about you and how it is being processed;
- Correction — request correction or updating of inaccurate or incomplete data (most fields can be edited directly from your account settings);
- Erasure — request deletion of your personal data, subject to our legal retention obligations (§6);
- Data portability — request a machine-readable copy of the data you have provided to us (JSON export);
- Withdraw consent at any time, including revoking location, camera, or notification permissions from your device settings;
- Object to automated decisions — request human review of any automated action taken against you (§16 of the Terms);
- Nominate another individual to exercise your rights on your behalf in the event of death or incapacity;
- Lodge a complaint with our Grievance Officer, and thereafter with the Data Protection Board of India.
To exercise any right, email us at [email protected] from the address registered on your account (or verify your identity via OTP if you sign in by phone). We will respond within 30 days. If we need more time (complex request), we will tell you and explain why.
11. Marketing Communications
We send marketing communications (feature announcements, seasonal campaigns) only where you have not opted out. Every marketing email contains an unsubscribe link; every marketing SMS contains an opt-out keyword; you may disable marketing push in-app under Notifications. Opting out of marketing does not stop transactional messages (OTPs, receipts, replies to your grievances).
12. Children's Privacy
The Platform is not intended for individuals under 18 years of age. We do not knowingly collect personal data from minors. If we become aware that a minor has registered, we will take steps to delete the relevant account and data. If you believe a minor is using the Platform, please email [email protected].
13. Grievance Officer / Data Protection Contact
In accordance with the DPDP Act, 2023 and the IT Rules, 2021, you may contact our Grievance Officer for privacy-related complaints or data-rights requests:
- Email: [email protected]
- Address: Domoimate, Ekp Arcade, Ekkapramba, near Ozhukur Road, 673641, Kerala, India
We will acknowledge complaints within 24 hours and aim to resolve them within 15 days.
If you are dissatisfied with our response, you may escalate to the Data Protection Board of India once it is operational, in accordance with the DPDP Act, 2023.
14. Data Breach Notification
We maintain an incident-response process for personal-data breaches. In the event of a breach likely to cause harm, we will take prompt steps to (a) contain the breach, (b) assess the affected data and Users, (c) notify affected Users through the app / email / SMS with clear guidance on what has happened and what they should do, and (d) notify the Data Protection Board of India within the timelines required under the DPDP Act.
15. Third-Party Links
The Platform may link to third-party websites or services (e.g., a Seller's website mentioned in their bio, or the badge links to Google Play / the App Store). This Privacy Policy does not apply to those third parties, and we encourage you to review their privacy policies separately. We do not endorse and are not responsible for third-party content or practices.
16. Do-Not-Track Signals
The website does not currently respond to browser Do-Not-Track (DNT) signals, as there is no universally accepted standard for interpreting them. However, the categories of tracking we do use are limited to those described in §5 above, and cookies can be controlled through your browser.
17. Data Minimisation Commitment
We commit to collecting only the data required for the specific purpose stated in this policy. Where an existing field can serve a new purpose, we prefer that over adding a new field. Where data can be aggregated / anonymised without loss of function, we do so. If you notice a field on our forms whose purpose is not obvious, please ask — [email protected] — and we will explain or, if it's truly not needed, remove it.
18. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we do, we will (a) update the "Last Updated" date and version above, and (b) for material changes (new categories of data collected, new sub-processors, new purposes), notify you via email, in-app banner, or push notification at least 7 days before the change takes effect. Continued use after that period constitutes acceptance of the updated policy.
19. Contact Us
Support & privacy queries: [email protected] | Address: Domoimate, Ekp Arcade, Ekkapramba, near Ozhukur Road, 673641, Kerala, India

