IP
IndiaPulse

Privacy Policy

Last updated and effective: 26 August 2026

1. Operator and scope

IndiaPulse is currently a personally operated Indian equity-research and analytics service. IndiaPulse is the data fiduciary for personal data handled through the website and associated applications. Questions and grievances can be sent to privacy@indiapulse.org.

2. Data we collect

  • Account details: name, email, password hash, role, profile picture, and Google OAuth identifier where used.
  • Consent evidence: accepted legal-document versions, method, and timestamp.
  • Workspace data: watchlists, portfolios, holdings, journal notes, paper-trade plans, saved screens, alerts, calendar preferences, and delivery history.
  • Security and operations data: IP address, user agent, request identifiers, timestamps, error events, and authentication-attempt counters.
  • Optional mobile data: an Apple push token only after push permission is granted.

We do not request broker, demat, bank passwords, trading PINs, or OTPs. Do not enter them anywhere on the Platform.

3. Why we use it

We process personal data only to:

  • create and secure accounts, authenticate sessions, and prevent abuse;
  • provide saved research, portfolios, paper trades, alerts, and requested communications;
  • operate, diagnose, measure, and improve reliability and accessibility;
  • respond to support, privacy, security, and legal requests; and
  • meet applicable legal, regulatory, tax, and security obligations.

IndiaPulse does not sell personal data and does not use third-party advertising or behavioural-tracking cookies.

4. Hosting and processors

Primary production services and the production database run on Google Cloud in Mumbai, India. A restricted Oracle Cloud environment in Mumbai may hold a shadow or disaster-recovery copy. Google and Oracle process infrastructure data under their service terms. Google also processes data when you choose Google OAuth; Apple processes push-token delivery when you enable mobile notifications.

We do not intentionally transfer account or portfolio data outside India. A provider may process limited support or security metadata according to its own global operations and contractual safeguards.

5. Cookies and local storage

Essential cookies include an HTTP-only signed session cookie that lasts up to 24 hours and short-lived OAuth state, return-path, and consent cookies that last up to 10 minutes. Secure cookies are sent only over HTTPS in production and use SameSite=Lax.

Browser local storage remembers display theme, the anonymous five-minute preview start, temporary scanner selections, locally saved screens, and paper-risk input defaults. These values stay in that browser unless you clear them. They are not advertising identifiers.

6. Retention

  • Account and workspace data remain while the account is active and are erased when account deletion completes, subject to required exceptions.
  • Consent evidence and records needed to establish legal compliance may be retained after deletion for the applicable limitation period.
  • Cybersecurity and access logs are retained for at least 180 days in India where CERT-In directions apply. Selected security evidence may be retained for up to one year or longer where law or an active investigation requires it.
  • Backups follow provider rotation schedules. Deleted records can remain in protected backups until those backups expire and are not restored except for disaster recovery.
  • OAuth flow cookies expire after 10 minutes; expired rate-limit records are periodically removed.

7. Your choices and rights

Signed-in users can export a machine-readable copy of their account and workspace data or permanently delete their account from Account settings. You may also ask us to provide access, correct inaccurate data, erase data, withdraw optional communications, or resolve a grievance by emailing the address below.

Withdrawal does not invalidate processing already performed and may prevent us from providing features that require the data. We may verify identity before fulfilling a request and may retain information where law requires it.

8. Security and incidents

Controls include encryption in transit and at rest, HTTP-only session cookies, bcrypt password hashing, least-privilege service identities, authentication throttling, restricted administrative access, backups, and security logging. No system is completely secure, and IndiaPulse has not claimed SOC 2 or ISO 27001 certification.

We will investigate suspected personal-data breaches and notify affected users and competent authorities when and as applicable law requires. Report security concerns under the Security Policy.

9. Children

IndiaPulse is for users aged 18 or older. We do not knowingly create accounts for children. Contact us if you believe a child supplied personal data so we can investigate and delete it where required.

10. Policy changes

We may update this policy when products, providers, or law change. Material changes will be presented in the Platform or by email where practicable. If renewed consent is required, the Platform will request it before issuing a new authenticated session.

11. Privacy and grievance contact

Role: IndiaPulse Privacy and Grievance Officer
Email: privacy@indiapulse.org
Privacy Policy | IndiaPulse