Privacy Policy

This policy explains exactly what Flipn collects, why we collect it, who processes it on our behalf, and the rights you have over it under India's Digital Personal Data Protection Act, 2023. It describes the product as it is actually built — not a generic template.

Last updated

1. Who we are

Flipn is a peer-to-peer classifieds marketplace operated by Pending confirmation: REGISTERED_ENTITY_NAME(“Flipn”, “we”, “us”), a company registered in India under CIN Pending confirmation: CIN, with its registered office at Pending confirmation: REGISTERED_ADDRESS.

For the purposes of the Digital Personal Data Protection Act, 2023 (the “DPDP Act”), Flipn is the Data Fiduciary for the personal data described here, and you are the Data Principal. Questions about this policy go to Pending confirmation: PRIVACY_EMAIL.

2. What this policy covers

This policy applies to the Flipn website at flipn.in, the Flipn iOS app, the Flipn Android app, and every backend service behind them. It does not cover what a buyer or seller does with information you choose to share with them directly, and it does not cover third-party sites or apps you reach from a link on Flipn.

3. Personal data we collect

3.1 Account and identity

  • Phone number. Signing in with a phone number is the primary route into Flipn. We store the number in international (E.164) form and a flag recording whether it has been verified by one-time password.
  • Email address and its verification status, when you sign up or sign in by email.
  • Apple account identifier, if you use Sign in with Apple. We receive the identifier and, where you allow it, your name and relay email address.
  • Password, if you set one. It is stored only as a salted hash by our authentication layer; nobody at Flipn can read it.
  • Profile details you choose to add — display name, @handle, profile photo, bio and city.
  • Referral data— your own shareable invite code (created only when you first open the invite screen) and, if you joined through someone’s link, a single record of who invited you.

3.2 Identity verification (optional)

If you request a verified badge, you upload evidence — a government ID, an address proof or a selfie. These files go into a private storage bucket that is never served from a public URL: our reviewers open them through short-lived signed links that expire in fifteen minutes. We record the outcome of the review and, if it is rejected, the reason. You are never required to verify in order to use Flipn.

3.3 Listings and the content you publish

  • Title, description, price, condition, category and attributes of each listing.
  • Photos and videos you upload, stored in Cloudflare R2 and served over our CDN. Anything attached to a published listing is public.
  • Comments, likes, saves, ratings and reviews you leave, and the badges you earn.

3.4 Location

A listing needs a location so buyers nearby can find it. If you set a precise point, we never publish it. Before a listing becomes visible we snap the coordinates onto a fixed grid roughly half a kilometre across and publish only that coarsened point, plus a coarse region tag. The grid is deterministic, so the pin does not jitter between page loads and cannot be triangulated by refreshing. Your profile itself stores only a city name and a coarse coordinate pair, and you can hide the city entirely in Settings.

If you grant browser or device location permission, we use it to centre the map and sort results by distance. Denying it only means you have to pick a city yourself.

3.5 Messages

  • The text of buyer↔seller conversations, the offers made and their status, images sent in chat (stored privately, delivered through expiring signed links), and read receipts.
  • Timing data used to compute a seller’s typical response time.
  • If you enable WhatsApp or SMS forwarding, the message body is sent to the relevant provider so it can be delivered to your number, and your replies are ingested back into the Flipn thread.

3.6 Devices and notifications

We store push tokens (APNs on iOS, FCM on Android, Web Push in the browser) along with the platform, app locale and whether the token is a sandbox or production token, so that we can deliver notifications you have asked for. We also record a last-active timestamp, which you can hide from other users in Settings.

3.7 Payments

The only thing Flipn sells is credits. For each purchase we store the amount, the credits delivered, the pack, the status, and the provider’s order and payment identifiers — plus, for iOS, Apple’s transaction identifiers and an opaque account token.

3.8 Safety, support and audit

  • Support tickets you open, including the category, subject, messages and app version.
  • Abuse reports you file or that are filed against you, the reason selected, and any moderation action taken.
  • An append-only privacy log recording when you changed privacy settings, blocked or unblocked someone, exported your data, or deleted your account.
  • A redacted administrative audit trail of privileged staff actions, kept so that moderation decisions remain accountable.

3.9 Diagnostics and analytics

We record a small set of server-authoritative product events — sign-up completed, listing created, listing sold, offer made, offer accepted, rating submitted, account banned — together with crash and error reports. When you arrive from an external link we also record a referral-landing event: the referring site or AI assistant (for example ChatGPT or Perplexity), the campaign tag on the link and the page you landed on — never the full address of the page you came from. Analytics are processed in the European Union. We do not run advertising trackers and we do not build advertising profiles.

4. Why we process it

  1. To run the marketplace — create your account, publish listings, show results near you, deliver messages and offers, and let buyers and sellers rate each other.
  2. To keep it safe — verify phone numbers, detect fraud and spam, action reports, enforce the Community Guidelines, and stop banned users returning.
  3. To take payment for credits and maintain an accurate, auditable ledger of what was bought and spent.
  4. To send you notifications you have opted into, and service messages you cannot opt out of (security alerts, payment receipts, policy changes).
  5. To improve the product using aggregate usage data.
  6. To meet legal obligations — tax and accounting records, and lawful requests from Indian authorities.

Our lawful basis is your consent, given when you create an account and when you enable an optional feature, together with the “legitimate uses” permitted by section 7 of the DPDP Act — principally responding to your own requests, and complying with law. You may withdraw consent at any time; see section 9.

5. AI features and what they see

Three parts of Flipn send content to a third-party model provider:

  • Listing assist — when you ask Flipn to draft a listing, the photos and any text you supplied are sent to the model so it can propose a title, description, category and price.
  • Pre-publish contact scan — before a listing goes live, its title, description and images are inspected for phone numbers, WhatsApp links, email addresses, social handles and QR codes. This is why direct contact details are rejected at publish time.
  • Semantic search — published listing text is turned into a numeric embedding so that searches match meaning rather than exact words.

These calls go to OpenAI. Private chat messages are not sent to a model for any of these features. Do not include anything in a listing that you would not want processed by a third-party provider.

6. Who we share it with

We do not sell your personal data, and we do not share it for third-party advertising. We use the following processors, each bound to handle data only on our instructions:

Third-party processors used by Flipn
ProcessorWhat it handlesWhere
ConvexApplication database and backend functions — accounts, listings, chat, offers, reports, ledgers.United States
CloudflareObject storage (R2) for listing photos, avatars, chat images and verification documents; CDN delivery; hosting for flipn.in.Global edge network
RazorpayCard, UPI, net-banking and wallet payments for credit purchases on web and Android. Razorpay collects your payment instrument directly; Flipn never sees it.India
AppleIn-app purchases of credits on iOS, Sign in with Apple, and push delivery through APNs.United States
GoogleMap rendering on the browse map (Google Maps) and push delivery to Android devices (FCM).United States
OpenAIListing assistance, the pre-publish contact-details scan over your listing text and images, and the embeddings that power semantic search.United States
MSG91Delivery of login OTPs by SMS, and SMS message-forwarding if you turn it on.India
Zoho ZeptoMailTransactional email — email verification codes and password resets.India
Meta (WhatsApp Business Cloud API)Forwarding buyer messages to your WhatsApp and ingesting your replies — only if you enable WhatsApp forwarding.Ireland / United States
PostHogProduct analytics events such as sign-up completed, listing created, offer accepted and referral landing (which site or AI assistant linked you to Flipn).European Union

We also disclose data where we are legally required to — to a court, a law-enforcement agency or a regulator acting under valid authority — and where it is necessary to investigate fraud or protect someone’s safety. If Flipn is ever acquired or merged, your data may transfer to the acquiring entity under the same commitments; we will tell you before that happens.

7. What other people can see

Publicly visible by default:

  • Your display name, @handle, profile photo, bio, member-since date, verification badges, ratings and reviews.
  • Your active listings, their photos, and their coarsened map pin.

Never publicly visible:

  • Your phone number and email address. Listings cannot contain them either — that rule is enforced automatically.
  • Your exact location, and the precise coordinates of any listing.
  • Your verification documents, your chat messages, your payment records and your credit balance.

In Settings → Privacy you can set your profile to public, members-only or private, hide your city, and hide your last-active time. You can also block another user, which stops messaging in both directions.

8. Storage and international transfers

Flipn stores data with the processors named in section 6. Several of them operate outside India, so your personal data is transferred abroad for hosting and processing. Those transfers are made under contractual protections with each processor, and only to countries not restricted by the Central Government under section 16 of the DPDP Act. If a country is restricted, we will stop transferring to it.

9. Your rights under the DPDP Act, 2023

  • Right to access. Get a summary of the personal data we hold and who we have shared it with. Available immediately in the app: Settings → Privacy → Export my data downloads a machine-readable file covering your profile, listings, comments, likes, verification requests, credit transactions, payments, blocks and privacy events.
  • Right to correction and completion. Edit your profile in the app, or write to us for anything you cannot change yourself.
  • Right to erasure. Delete your account from Settings → Privacy → Delete account, or use the no-login route on our account deletion page. That page sets out exactly what is erased and what we must keep.
  • Right to withdraw consent. Turn off an optional feature (message forwarding, push notifications, location) at any time, or delete your account to withdraw consent entirely. Withdrawal does not undo processing already carried out.
  • Right to nominate. Nominate someone to exercise these rights on your behalf if you die or become incapacitated — write to the Grievance Officer.
  • Right to grievance redressal. See section 12. You may escalate to the Data Protection Board of India if you are not satisfied with our response.

We acknowledge written requests within 2 working days and resolve them within 30 days. We may ask you to verify the phone number or email on the account before we act, because acting on an unverified request is itself a privacy risk.

10. How long we keep data

Retention periods by data category
DataHow long we keep it
Account profileUntil you delete your account. On deletion, contact details, name, avatar, bio and location are erased immediately.
ListingsUntil you delete them or your account. Deleted and archived listings leave the feed, search index and map immediately.
Chat messages and offersFor the life of the conversation. Messages you have already sent remain visible to the other participant, attributed to “Deleted user”, after you leave.
Verification documents (government ID, address proof, selfie)Kept only while the request is under review and for the period we must retain proof of the check; stored in a private bucket that is never publicly addressable.
Payment records and the credit ledgerRetained for the period required by Indian tax, accounting and anti-fraud law, even after account deletion.
Abuse reports, moderation actions and the audit logRetained after account deletion so that safety decisions and repeat-offender patterns remain reviewable.
Push tokens and notification preferencesDeleted the moment you delete your account, or when the device token is reported invalid.
Uploads that were never attached to a listingPurged automatically by a scheduled job once the staging window passes.

11. How we protect it

  • All traffic is encrypted in transit over TLS.
  • Private files — chat images and verification documents — are never publicly addressable and are only reachable through signed URLs that expire after fifteen minutes.
  • One-time passwords are stored hashed, expire quickly, and are invalidated after a small number of failed attempts.
  • Login, OTP delivery, AI calls and payments are rate-limited per user and globally, so a compromised account cannot be used to burn resources or spam numbers.
  • Administrative access is role-based, and every privileged action writes an entry to an append-only audit ledger.

No system is perfectly secure. If a personal data breach occurs we will notify the Data Protection Board of India and each affected user as required by the DPDP Act.

12. Children

Flipn is not intended for anyone under 18. We do not knowingly create accounts for children or process children’s personal data, and we do not use personal data for behavioural advertising or tracking directed at children. If you believe a child has created an account, tell us and we will remove it.

13. Cookies and local storage

Flipn sets a session cookie so you stay signed in, and uses your browser’s local storage for your theme preference and to hold an invite code until you finish signing up. We do not use advertising cookies, cross-site trackers or third-party ad pixels. Clearing site data signs you out.

14. Grievance Officer

In line with the DPDP Act, 2023 and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, the Grievance Officer for Flipn is:

Pending confirmation: GRIEVANCE_OFFICER_NAME
Grievance Officer, Pending confirmation: REGISTERED_ENTITY_NAME
Pending confirmation: REGISTERED_ADDRESS
Email: Pending confirmation: GRIEVANCE_OFFICER_EMAIL
Phone: Pending confirmation: SUPPORT_PHONE (Pending confirmation: SUPPORT_HOURS)

Complaints are acknowledged within 2 working days and resolved within 30 days. Full contact details are on our contact page.

15. Changes to this policy

We will update this page when the product changes. The “last updated” date at the top always reflects the current version, and we will give notice in the app before a material change takes effect. Continuing to use Flipn after that means you accept the updated policy.