Vingo Policies
Privacy Policy
How Vingo collects, uses, shares, and protects your personal data when you use our mobile app and website.
#1Who we are
Vingo (“Vingo”, “we”, “us”, “our”) is a trust-based consumer-to-consumer (C2C) recommerce marketplace where members list pre-owned items and discover, bid on, and transact for them.
Vingo is owned and operated by Buseit Internet Private Limited, a company incorporated in India, with its registered office at Innov8, Lower Ground Floor, Saket Salcon Rasvilas,Saket District Centre, Sector 6, Pushp Vihar, Saket, New Delhi, Delhi 110017
(CIN: U47740DL2026PTC463917). For the purposes of the Digital Personal Data Protection Act, 2023 (“DPDP Act”) and other applicable Indian law, Buseit Internet Private Limited is the Data Fiduciary that decides how and why your personal data is processed.
This policy applies to the Vingo mobile application (application identifier com.justvingo.app, on both Android and iOS) and our website at justvingo.com (together, the “Platform”). Please read it together with our Terms of Service.
#2Scope & acceptance
This policy applies to everyone who uses the Platform buyers, sellers, and browsers. It does not cover third-party apps or sites we link to or integrate with; those have their own privacy policies.
By creating an account or using the Platform, you confirm that you have read and understood this policy. Where the law requires your consent, we ask for it before processing your data for that purpose.
#3Information we collect
We collect only what we need to run the marketplace, complete transactions, keep the Platform safe, and meet our legal obligations. The categories below reflect how the Vingo app actually works.
#3.1Information you give us
- Account & authentication: your mobile phone number, used to sign you in via a one-time password (OTP). We do not use passwords. To make sign-in easier, the app may read the OTP from an incoming SMS using Android’s SMS Retriever, which does not give us access to your other messages.
- Profile information: display name, profile photo (avatar), bio, date of birth, gender, and any optional social handles you choose to add (for example Instagram, LinkedIn, or Facebook).
- Addresses: delivery and pickup addresses you save, including a snapshot of the pickup address captured when you create a listing.
- Listing content: product details, condition, attributes, prices, the photos and videos you select to upload, and any personal “story” or description you add. Listings are visible to other users, so avoid including sensitive personal information in them.
- Transaction activity: bids, accepted/rejected offers, orders, wishlist items, and related statuses and communications.
- Identity verification (KYC): identity and verification details where required to transact — see Section 10.
- Support & communications: information you provide when you contact us (including via WhatsApp support), report a problem, or take part in a verification call.
#3.2Information collected automatically
- Device & connection data: device model and identifiers, operating-system version, app version, language/region, network connection state, IP address, and basic phone/telephony state.
- Diagnostics & crash data: when the app encounters an error or crash, we collect diagnostic information — error messages, stack traces, app state, and device context — through our error-monitoring provider (Sentry) to keep the app stable.
- Location data: with your permission, we access your device’s approximate or precise location to power address autocomplete, maps, and delivery features. Location is used only while you are using the app; we do not track your location in the background.
- Usage & log data: actions you take in the app, request timestamps, and server-side diagnostic logs (including per-request trace identifiers) used for security, debugging, and rate-limiting.
- Push token: a notification token issued by Firebase Cloud Messaging and a Firebase installation identifier, used to deliver notifications to your device.
- Advertising identifier: your device’s advertising identifier — the Google Advertising ID on Android, or the IDFA on iOS. On iOS this is collected only if you allow tracking when your device asks you. It is used for advertising measurement and is shared with Meta as described in Sections 7 and 8. You can switch this off at any time at Profile → Preferences → Personalised ads.
- Search terms: the words you type when you search in the app. We use them to return results, and — while advertising measurement is on — the search text is included in the search event shared with Meta (see Sections 7 and 8).
#3.3Information from third parties
- Payment status from our payment processor (for example, whether a payment succeeded or failed). We do not receive your full card or bank details — see Section 9.
- Social profile basics if you choose to link a social account, limited to what that provider shares and you authorise.
What we do not do: Vingo shows no advertising inside the app — there are no ads or ad placements anywhere in the product. We do not sell your personal data, and we do not use your data to make decisions about you within the app.
The app does include one advertising-measurement SDK, from Meta, which tells us which of our own advertising campaigns bring people to Vingo. It is measurement only. What it shares, and how to switch it off, is set out in Sections 7 and 8.
#4App permissions
The app requests the following Android permissions. Many are optional and requested only when you use the related feature; you can manage them in your device settings.
| Permission | Why we use it |
|---|---|
| Location (precise & approximate) | Address autocomplete, maps, and setting pickup/delivery locations. Used only while using the app. |
| Photos & videos | You select images and videos from your device to add to listings, using Android’s and IOS’s system photo picker. The app does not scan your full media library. |
| Notifications | Send you push and in-app alerts about bids, offers, and orders. |
| Network & internet state | Connect to our servers and detect whether you are online. |
| NFC | Supports certain contactless payment methods at checkout. |
| Vibrate, wake lock, ignore battery optimisations | Deliver notifications reliably and complete time-sensitive tasks. |
| Basic phone state | Read basic device/telephony status needed by some components; this does not give us your call logs or contacts. |
The app does not request access to your contacts, microphone, SMS inbox, or files outside the items you choose to share.
#5How we use your information
| Purpose | Examples |
|---|---|
| Provide the service | Create and manage your account, publish listings, run bidding, process orders and deliveries, maintain your wishlist and notifications. |
| Authentication & security | Send and verify OTPs, keep you signed in, detect fraud and abuse, enforce rate limits, and protect the Platform. |
| Payments & payouts | Process buyer payments, calculate fees and applicable taxes (including TDS), and pay sellers. |
| Trust & safety | Verify identities, moderate content, validate listings, and build reputation/karma signals. |
| Stability & performance | Diagnose crashes and errors and fix problems using diagnostic data. |
| Communications | Send transactional messages and notifications about bids, offers, and orders, and respond to your requests. |
| Legal & compliance | Meet legal, tax, accounting, and regulatory obligations and respond to lawful requests. |
| Advertising measurement | Understand which of our own advertising campaigns bring people to Vingo, and help Meta show Vingo’s advertising to relevant audiences. We do not use this data to make decisions affecting you inside the app. Optional — switch it off at Profile → Preferences → Personalised ads. |
#6Legal basis & consent
Under the DPDP Act, we process your personal data on the basis of the consent you provide and for the “legitimate uses” recognised by law, including providing a service you have requested and complying with legal obligations.
You may withdraw your consent at any time (see Your rights). Withdrawal does not affect processing already carried out, and some features may stop working if the data is essential — for example, we cannot complete an order without delivery details.
Advertising measurement. Sharing data with Meta for advertising measurement is disclosed in this policy and is on by default. You may withdraw at any time at Profile → Preferences → Personalised ads. Withdrawal takes effect immediately, not at your next sign-in, and no other part of the app changes. You do not need an account to reach this setting. On iOS, your device’s tracking permission applies in addition to this control, so declining it also limits what can be shared.
#7How we share information
- With other users, to complete transactions: when you buy or sell, we share the information needed to fulfil the transaction — for example, a buyer’s delivery address and a seller’s pickup details with our logistics partner, and limited contact details between the parties. Your public seller profile (name, photo, listings, reputation) is visible to other members.
- With service providers (Data Processors) who process data on our behalf under contract — see Section 8.
- For advertising measurement: we share a limited set of data with Meta Platforms, Inc. so we can tell which of our own advertising campaigns on Facebook and Instagram bring people to Vingo. What is shared: your device’s advertising identifier, an anonymous install identifier generated by Meta, your Vingo account identifier (an internal, opaque value — not your name, phone number, or email) when you are signed in, your IP address, a curated set of in-app actions such as opening a listing, searching, saving an item, publishing a listing, placing an offer and completing a purchase, the text you typed when searching, the value and currency of a purchase, and basic device and app information. We do not share your name, phone number, email address, postal address, or precise location with Meta. Reporting a listing or a user, blocking a user, and deleting your account are never shared with Meta. This sharing is on by default and you can switch it off at any time at Profile → Preferences → Personalised ads; switching it off stops the sharing immediately and changes nothing else about how the app works. On iOS, your device’s own tracking permission applies as well. See Sections 8 and 16.
- For legal reasons: to comply with applicable law, court orders, or lawful government requests, and to protect the rights, safety, and property of Vingo, our users, or the public.
- In a business transfer: if Vingo is involved in a merger, acquisition, financing, or sale of assets, your data may be transferred as part of that transaction, subject to this policy.
#8Third-party services
We rely on trusted providers to operate the Platform. Each processes only the data needed for its function. The main providers are:
| Provider | Purpose | Data involved |
|---|---|---|
| Razorpay | Payment processing & payouts | Payment and transaction details (card/UPI/bank data handled directly by Razorpay) |
| Google Firebase Cloud Messaging | Push notifications | Device push token, Firebase installation ID |
| Google Maps / Places | Maps, address autocomplete, geocoding | Location and address queries |
| Sentry (Functional Software, Inc.) | Crash & error monitoring | Diagnostic data: error/stack traces, device and app context, IP address |
| PostHog | Product analytics — understanding how the app is used so we can improve it | In-app actions and screens viewed, your Vingo account identifier, device and app context |
| Meta Platforms, Inc. | Advertising measurement — which of our campaigns bring people to Vingo | Advertising identifier, Meta anonymous install identifier, Vingo account identifier when signed in, IP address, a curated set of in-app actions, search text, purchase value and currency, device and app information. See Section 7. Optional — switch off at Profile → Preferences → Personalised ads |
| SMS OTP provider | SMS delivery of OTPs | Phone number, OTP |
| Google Cloud (hosting, database, media storage) | Run the backend and store data and media | All Platform data, including uploaded photos/videos |
| Replicate (optional) | Automated background removal for listing images | Listing images, where enabled |
Some providers process or store data outside India — see Section 16. We encourage you to review their privacy policies.
#9Payments & financial data
Payments on Vingo are processed in-app by our payment partner, Razorpay. When you pay, your card, UPI, netbanking, or other payment credentials are collected and processed directly by Razorpay under its own security standards and privacy policy. Vingo does not collect or store your full card numbers or bank credentials.
We receive and retain transaction-level information — order amounts, payment status, payout amounts, fees, and tax deductions (including TDS under applicable income-tax provisions) — which we need to run the marketplace, pay sellers, and meet legal and accounting obligations.
#10Identity verification (KYC)
To maintain trust and meet legal requirements, we may ask you to verify your identity before you can sell or complete certain transactions. This may involve collecting government-issued identification details and verifying them through a verification call or video step.
Note on government IDs: Identity documents such as Aadhaar and PAN are sensitive and subject to specific Indian legal requirements. We collect them only where necessary, handle them through secure verification flows, restrict access to authorised personnel, and retain them only as long as required.
#11Data stored on your device
To make the app work offline-friendly and keep you signed in, we store some data locally on your device: authentication tokens in your device’s secure storage (Android Keystore), app settings and preferences, a local database for faster browsing, and cached images. This data stays on your device and is cleared when you log out or uninstall the app (cached files may be removed by the system as needed).
#12Data retention
We keep your personal data only as long as needed for the purposes in this policy, or as required by law:
- Account and profile data are kept while your account is active and for a reasonable period afterwards.
- Transaction, payment, and tax records are retained for the periods required under applicable financial, accounting, and tax laws.
- Authentication sessions (refresh tokens) expire by default after 30 days and are revoked when you log out.
- Inactive device push tokens are automatically removed after about 30 days of inactivity.
- Unconfirmed media uploads are automatically deleted from temporary storage within about one day.
- Diagnostic/crash data is retained for a limited period in line with our error-monitoring provider’s defaults.
When data is no longer needed, we delete or anonymise it, except where retention is legally required. For exactly what is deleted and what is retained when you close your account, see Delete Your Account.
#13Data security
We use reasonable technical and organisational measures to protect your data, including: hashed storage of OTPs and authentication tokens, secure on-device storage backed by the Android Keystore, token-based sessions, role- and permission-based access controls, security headers and request rate-limiting, audit logging of sensitive actions, and access-controlled storage of media and database records. Traffic between the app and our servers is encrypted in transit.
No system can be guaranteed completely secure. If we become aware of a personal data breach affecting you, we will notify you and the relevant authorities as required by law. Please help keep your account safe by protecting access to your phone and device.
#14Your rights
Subject to applicable law, including the DPDP Act, you have the right to:
- Access a summary of the personal data we hold about you and how we process it.
- Correct, complete, or update inaccurate or incomplete data — you can edit much of your profile directly in the app.
- Erase your personal data where it is no longer needed and retention is not legally required — you can delete your account directly in the app (Profile → Edit Profile → Delete account) or by email, as described at Delete Your Account.
- Withdraw consent for processing based on consent. You do not have to contact us to stop advertising measurement — switch it off yourself, at any time, at Profile → Preferences → Personalised ads. It stops immediately.
- Nominate another individual to exercise your rights in case of death or incapacity.
- Grievance redressal — raise concerns with our Grievance Officer (see Section 18\) and, if unresolved, with the Data Protection Board of India.
To exercise any of these rights, contact us using the details below. We may need to verify your identity first.
#15Children
The Platform is intended for users aged 18 and over. We do not knowingly create accounts for, or collect personal data from, anyone under 18. If we learn we have collected a minor’s data without the consent required by law, we will delete it. If you believe a minor is using the Platform, please contact us.
#16Storage & cross-border transfer
Your data is stored and processed primarily on cloud infrastructure in India. Some service providers process data on servers outside India — for example, our crash-monitoring provider (Sentry) processes diagnostic data on servers in the European Union, and certain Google services may process data in other regions. Where data is transferred internationally, we take steps to ensure it is handled in line with this policy and applicable law.
Advertising measurement. Where advertising measurement is switched on, the data listed in Section 7 is transferred to Meta Platforms, Inc. and processed by Meta outside India. Once transferred, how long Meta keeps that data is governed by Meta’s own retention practices, set out in Meta’s Privacy Policy. You can stop this transfer at any time at Profile → Preferences → Personalised ads.
#17Changes to this policy
We may update this policy to reflect changes in our practices or the law. For material changes, we will update the “Last updated” date above and, where appropriate, notify you in the app. Continued use after an update means you accept the revised policy.
#18Grievance Officer & contact
For questions, to exercise your rights, or to raise a complaint, contact our Grievance Officer (appointed in accordance with applicable Indian law):
| Grievance Officer | Krish vashistha |
|---|---|
| grievance@justvingo.com | |
| Operated by | Buseit Internet Private Limited |
| Operating Address | Nukleus 3rd Floor, Tower B3, Prestige Blue Chip, Dairy Colony, Adugodi, Bengaluru, Karnataka 560029 |
| General support | support@justvingo.com |
We aim to acknowledge and respond to grievances within the timelines required by applicable law.