Privacy Policy

How BuyUnlistedShares collects, uses, shares and protects the information you give the desk: enquiry details, cookies, retention and your rights.

Last updated: 26 September 2026 · BuyUnlistedShares (formerly Unlisted Axis), a brand of Gayatri Financial Synergy (GFS), Faridabad, Haryana · This Privacy Policy forms part of the Terms & Conditions

Introduction

This Privacy Policy explains what personal data Gayatri Financial Synergy, trading as BuyUnlistedShares (“GFS”, “we”, “us”), collects when you use this website or contact the desk, why we collect it, who we share it with, how long we keep it, and the rights you have under the Digital Personal Data Protection Act, 2023 (“DPDP Act”) and the Information Technology Act, 2000. It is the notice required by Section 5 of the DPDP Act. GFS is the data fiduciary for the personal data described here. We process personal data only on the bases set out under Legal basis: your consent, given by a clear affirmative act such as submitting a form or ticking a box, for the purpose stated at that point; the legitimate uses in Section 7 of the DPDP Act; and, for cookies and browser storage, only what is strictly necessary to run the website and the features you use.

Information we collect

1. Identity and contact data

2. Enquiry data

3. IPO pre-application data (only if you use the Pre-apply form)

4. KYC, compliance and verification data

5. Site account data (only if you log in)

6. Partner programme data (only if you apply to be, or are, a partner)

7. WhatsApp taps

8. Device, technical and usage data

9. Cookies and browser storage

10. Community and user content

11. Recordings

How we collect information

Purposes

We use personal data to:

Legal basis

We process personal data on the basis of your consent, given by the clear affirmative act of submitting a form, ticking a consent box, logging in, posting content or contacting the desk, for the purpose stated at that point (for example, handling your enquiry or running your account). Marketing is a separate purpose: it relies only on a separate, optional consent that you give by ticking an unticked box, and saying no does not affect anything else. A price or GMP alert, or a web-push subscription, that you switch on is your consent to those alerts; switching it off withdraws it. Cookies and browser storage are limited to what is strictly necessary to run the website and the features you use, and are not used for advertising. We also process personal data without separate consent for the “legitimate uses” permitted by Section 7 of the DPDP Act, including where you have voluntarily provided the data for a specified purpose, to comply with a law, judgment or order, to respond to a regulator, and for the purposes of employment and security. You may withdraw consent as described below; withdrawal does not affect processing already done, or processing that the law requires.

Sharing of information

We share personal data with:

The processors we use today and what each receives: Hostinger International Ltd (the servers and database, Mumbai, India — everything above); HanuOTP and Fast2SMS (one-time login codes — your mobile number and the code); Zoho Mail (desk email — whatever you write to us); Google Cloud (the desk’s lead CRM, Mumbai region, and the service accounts that read our own sheets — enquiry name, phone, email, message); Google Drive (encrypted off-site backups of our internal systems); Telegram (desk alerts that carry a masked phone number and a reference, never your details); Amazon SES (transactional email, if enabled); your browser’s push service (for example Google, Mozilla or Apple, for web-push alerts you switch on — the alert text and your browser’s subscription address, never your name or number). A full list with each provider’s data-processing terms is kept by the desk and available on request.

We do not sell personal data. Data shared with a registered intermediary, registrar, bank, depository or exchange is governed by that entity’s own privacy practices once it reaches them.

Data retention

We retain personal data for as long as the purposes it was collected for continue — providing dealing, research and enquiry services to you, sending the market updates, IPO alerts and research you signed up for, maintaining the transaction, KYC and compliance records of the desk, and establishing or defending legal claims — and thereafter for as long as a law, regulation, exchange rule, intermediary requirement or limitation period requires. In particular, KYC and transaction records are kept for at least five years from the last transaction under the Prevention of Money Laundering Act and SEBI norms, and accounting and tax records for eight years. Records of consent and of enquiries are kept as evidence of what was asked and agreed. Short-lived technical data is removed automatically: one-time login codes within 24 hours, expired login sessions within 7 days, and no IP address is stored for article read counts. Encrypted database backups are overwritten on a 14-day cycle. Data that is no longer needed for any of these purposes is deleted or anonymised.

Data security

We take reasonable security measures appropriate to the data we hold, as Section 8(5) of the DPDP Act requires, including access controls, HTTPS, server hardening and encryption at rest of PAN, demat and UPI details collected through the Pre-apply form, of the PAN in your account’s KYC record and your saved IPO applicants, and of partners’ PAN and bank account numbers. Your browser keeps only a tracking token for a pre-application. No system is completely secure, and we do not guarantee that data will not be accessed, altered or disclosed through a breach, a cyber-attack or a failure beyond our reasonable control; you accept that risk in using the website. If a personal-data breach occurs we will tell the Data Protection Board of India without delay and give it the full report within 72 hours, and we will tell every affected person what happened, what it may mean for them and what we are doing about it, as the DPDP Act and the Digital Personal Data Protection Rules, 2025 require. Our internal breach runbook assigns who does what from the first hour. Keep your own devices, email and UPI app secure; we are not responsible for a compromise on your side.

Your rights under the DPDP Act

Subject to the DPDP Act and Rules, you have the right to:

How to exercise them. Write to the grievance officer at care@buyunlistedshares.com from the email address or mobile number you used with us, saying which right you are exercising. We verify that the request comes from the person the data belongs to (usually a one-time code to that mobile number) before acting, and answer verified requests within the period the DPDP Rules allow. We may decline a request that is unverified, manifestly unfounded, excessive or repetitive, or that would require disclosing another person’s data, and will give the reason. Where you ask for erasure or withdraw consent we keep what the law requires us to keep (see Data retention) and may be unable to continue an enquiry, KYC or pre-application. Consent can be withdrawn the same way at any time, with effect for the future. To nominate a person to exercise these rights for you, write to the grievance officer with their name and contact details. You must not give false information or impersonate anyone when exercising a right (Section 15).

Children

The website and the desk are for persons aged 18 and over; any transaction needs a PAN in your own name, which is not issued to a minor, and the desk verifies identity before acting. We do not knowingly collect personal data from anyone under 18, and we do not obtain parental consent because we do not offer services to children. If you believe a child has given us data, write to us and we will delete it.

Cookies and browser storage

We use a small number of our own cookies and browser-storage keys to run the website and the features you use, and to remember your preferences. You can block or delete cookies through your browser settings; some features may then not work. This website sets three cookies of its own: bus_session (your login, 30 days, HttpOnly), bus_ref (which partner link brought you here, so the desk can credit them) and, for staff only, the panel sign-in cookie. It carries no third-party analytics or advertising tags today; if that changes this section and the consent banner will say so first. The site also uses browser storage (localStorage) for conveniences that stay on your device: bus-auth and bus-acct (who is signed in, no secrets), bus-watch and bus-scr-pins (watchlist and pinned companies), bus.allot.v1 (saved applicants for the allotment checker — kept on your device, and synced to your account only encrypted), bus.preapply.v1 and bus.ipoapps.v1 (pre-application references), bus.apply.broker, bus-theme, bus-scr-cols, bus-scr-view, bus-dep-view, bus-nudge-shown, bus-login-toast, bus-sync-reloaded and the bus.gate.* keys (display preferences and whether you have already seen a prompt). Clear them from your browser at any time; a signed-in account keeps its watchlist and saved lists on our server so they follow you across devices. These cookies and keys are strictly necessary for the website and the features you choose to use, so they are set without a separate consent; blocking them may stop login, the watchlist or partner credit from working.

Where data is processed

The website, its database and its nightly encrypted backups run on servers in Mumbai, India (Hostinger). The desk’s lead CRM runs on Google Cloud in the Mumbai region. One-time codes are sent by Indian SMS providers. Some processors keep data outside India: Google (service accounts and the encrypted off-site backups of our internal systems on Google Drive), Telegram (desk alerts, which carry no personal data beyond a masked number) and Zoho Mail (desk email, on Zoho’s India data centres for Indian accounts). Section 16 of the DPDP Act allows transfer to any country the Central Government has not restricted; none of these is restricted today, and we will move a processor if that changes.

The website links to third-party websites and services, including broker sign-up pages on the Open Demat page, registrar pages from the allotment checker, exchange and SEBI pages, and social-media platforms. We are not responsible for their privacy practices, cookies or content. Where a broker link is a partner link, that is disclosed on the page.

Changes to this policy

We may change this policy at any time by posting the revised version with a new “Last updated” date. The revised policy takes effect from that date. Where a change affects a purpose you consented to, we will ask for fresh consent where the DPDP Act requires it.

Grievance officer and contact

Privacy requests, complaints and DPDP Act grievances go to the grievance officer of Gayatri Financial Synergy: care@buyunlistedshares.com · 2nd Floor, SCO-39, HUDA Market, Sector 7A, Faridabad, Haryana 121006 · +91 91691 65959 · Mon–Sat, 8:30am–6pm IST. If you are not satisfied with the response you may complain to the Data Protection Board of India.

The grievance officer is a designated role at Gayatri Financial Synergy, reachable at the address above; the same officer is our contact for the Data Protection Board. We aim to acknowledge a complaint within 2 working days and to answer it within 30 days.

Indicative reference price, dated. BuyUnlistedShares is India's premium unlisted shares desk: the unlisted and pre-IPO dealing desk of Gayatri Financial Synergy, Faridabad, in the market since 2002. Reviewed by the BuyUnlistedShares desk before publishing. Data as of 06 Oct 2026.

All unlisted shares · IPO calendar · Research & learning · Send an enquiry · Calculators · Ask · Community · Jobs · About · Contact · Privacy · Terms · Disclaimer · Grievance redressal

Part of the Gayatri Financial Synergy group (gayatrifin.com): AMFI-registered mutual fund distributor, Faridabad, since 2002.

Privacy Policy | BuyUnlistedShares