This page describes, in plain terms, how we protect the data described in our Privacy Policy. It's a summary of our practices rather than an exhaustive technical audit.
How your data is protected
Encrypted in transit
All traffic between the app and our servers, and to this website, is encrypted using HTTPS/TLS. We do not accept plain-text API traffic.
No passwords stored by us
Sign-in is handled by Google (and other supported providers). We never see or store your Google account password.
No card data stored by us
Payments are handled directly by PCI-DSS compliant payment processors (Razorpay, Cashfree, Paytm, Stripe). Card, UPI, and bank details never touch our servers.
Access-controlled infrastructure
Our database and file storage are not publicly browsable. Administrative access is restricted to authorized personnel and gated by credentials that are not shared with the client app.
Media in cloud object storage
Uploaded images and generated posters are stored in Cloudflare R2, a managed object-storage service, rather than on the same server that runs our public website.
Scoped API access
The mobile app authenticates its API calls with an app-level key; user-level actions are tied to the signed-in account.
Data minimization
We only ask for the information a feature actually needs — for example, we request location access only for features that use your location (like local content or banner promotion), and you can decline it. We don't request permissions we don't use.
Data deletion
When you request account deletion, we permanently remove your account record, business/marketplace profiles, and associated uploaded media from our production database and storage. See Account Deletion for how to request this and what's covered.
Third-party processors
Where we rely on a third party to help run the service — Google Firebase, Google Gemini API, Google Mobile Ads, OneSignal, our payment processors, Mappls, and Cloudflare — each of those providers maintains its own security program and data-processing terms, which apply to the data they process on our behalf. We choose established providers with published security and compliance practices.
Reporting a security issue
If you believe you've found a security vulnerability affecting PosterBanao or the Vande Bharatam project, please report it to privacy@vandebharatam.com so we can investigate. Please don't publicly disclose a vulnerability before we've had a reasonable chance to address it.
Questions
For anything not covered here, contact privacy@vandebharatam.com.