Introduction
This Privacy Policy explains what personal data Gayatri Financial Synergy, trading as BuyUnlistedShares (“GFS”, “we”, “us”), collects when you use this website or contact the desk, why we collect it, who we share it with, how long we keep it, and the rights you have under the Digital Personal Data Protection Act, 2023 (“DPDP Act”) and the Information Technology Act, 2000. It is the notice required by Section 5 of the DPDP Act. GFS is the data fiduciary for the personal data described here. We process personal data only on the bases set out under Legal basis: your consent, given by a clear affirmative act such as submitting a form or ticking a box, for the purpose stated at that point; the legitimate uses in Section 7 of the DPDP Act; and, for cookies and browser storage, only what is strictly necessary to run the website and the features you use.
Information we collect
1. Identity and contact data
- Name, phone number, email address, city or address, and any details you include in a message
2. Enquiry data
- Company or security of interest, indicative quantity, amount or investment range; for sell enquiries, holding type and expected indicative price; your preferences and the history of your communications with the desk
3. IPO pre-application data (only if you use the Pre-apply form)
- Applicant name as per PAN, PAN, depository, DP ID and client ID, UPI ID, bid category and lots, and your consent record. Bank account and payment details are never collected on this website; the UPI mandate is approved in your own bank or UPI app.
4. KYC, compliance and verification data
- When you deal with the desk, or choose to add them in your site account: PAN (stored encrypted and shown masked), demat details (depository, DP ID and client ID), and copies of your PAN card and client master list (CML) that you upload to your account; and, where the desk or the law requires them, proof of identity and address, bank details for payments to you, source-of-funds declarations and signatures. Uploaded documents are stored outside the public website and are shown only to you and to authorised desk staff.
5. Site account data (only if you log in)
- Your mobile number (verified by a one-time code), name and email; profile details you choose to add (username, investing-since year, a short “about” line, city, state, pincode and GSTIN); your watchlist, pinned companies, saved IPO applicants (stored encrypted) and pre-application references; the price and GMP alerts you set and the web-push subscription of each browser you switch them on in; holdings you enter; deals, invoices and holdings the desk records for you; enquiries linked to your number; and your consent choices, including the optional marketing choice
6. Partner programme data (only if you apply to be, or are, a partner)
- Name, phone number, email, city, partner type, ARN or broker/authorised-person details you give, photo, agreement acceptance and support tickets; your PAN and payout bank account, stored encrypted and shown masked, with the account-holder name match; fee, tax-deduction (TDS) and payout records; for referral links, the category and host of the website that sent the visit (for example search, social or direct), not the visitor’s identity; the mobile number of a client you introduce, so the right partner is credited; anti-abuse risk signals; a hashed network address when a partner downloads a price list; and, for an enquiry a partner submits about a client, the client’s contact details, the partner’s private notes and the enquiry’s status
7. WhatsApp taps
- When you tap a WhatsApp button on the website we count the tap (the page, the button’s place and the company, if any) under a visitor code made from a hash with a salt that changes every day. No name, phone number or IP address is stored with it, and the code cannot be linked to you on a later day
8. Device, technical and usage data
- IP address, approximate location derived from it, browser type and version, device type and identifiers, operating system, time zone, referrer, pages visited, time spent, clicks, searches, watchlist and tool inputs, form interactions, and error and performance logs
9. Cookies and browser storage
- The cookies and browser-storage keys listed under Cookies and browser storage below. The website carries no third-party analytics or advertising tags today; if that changes, this policy will say so first
10. Community and user content
- Anything you post on the Community pages, your display name and the metadata of your posts
11. Recordings
- Calls, WhatsApp threads and emails with the desk may be recorded and stored
How we collect information
- Directly from you when you fill in a form, tick a box, post on the Community pages, or contact us by phone, WhatsApp, email or in person
- Automatically through our own cookies, server logs and browser storage
- From third parties including depository participants and depositories, the SEBI-registered intermediary and registrar for an IPO bid, KYC registration agencies, service providers, public registers and databases, social-media platforms you contact us through, and BuyUnlistedShares partners who introduce you
Purposes
We use personal data to:
- run the website, the desk and every tool on it, and respond to your enquiries, callback requests and pre-applications;
- follow up on an enquiry by phone, WhatsApp, SMS or email, and carry out a deal you confirm with the desk, including payment, the demat-to-demat transfer through depository participants, invoices and the records the deal needs;
- for an IPO pre-application, pass your bid details to the SEBI-registered intermediary that places the bid;
- run the partner programme: credit introductions, verify partners, deduct tax, pay fees and prevent abuse;
- keep the compliance, KYC, anti-money-laundering and transaction records that the law, a depository or, for an IPO bid, an intermediary or registrar requires;
- detect, investigate and prevent fraud, misuse, automated access, false enquiries, security incidents and breaches of the Terms;
- measure and improve the website through analytics, testing and error logging;
- send you research, market updates, IPO alerts and offers, only if you have given the separate, optional marketing consent (for example by ticking “Send me research, IPO alerts and offers (optional)”), and until you withdraw it;
- send the price and GMP alerts you switch on in your account or browser;
- personalise content and communications;
- establish, exercise and defend legal claims, and respond to regulators, courts, exchanges and law-enforcement agencies; and
- any other purpose described to you at the point of collection or that is reasonably related to the above.
Legal basis
We process personal data on the basis of your consent, given by the clear affirmative act of submitting a form, ticking a consent box, logging in, posting content or contacting the desk, for the purpose stated at that point (for example, handling your enquiry or running your account). Marketing is a separate purpose: it relies only on a separate, optional consent that you give by ticking an unticked box, and saying no does not affect anything else. A price or GMP alert, or a web-push subscription, that you switch on is your consent to those alerts; switching it off withdraws it. Cookies and browser storage are limited to what is strictly necessary to run the website and the features you use, and are not used for advertising. We also process personal data without separate consent for the “legitimate uses” permitted by Section 7 of the DPDP Act, including where you have voluntarily provided the data for a specified purpose, to comply with a law, judgment or order, to respond to a regulator, and for the purposes of employment and security. You may withdraw consent as described below; withdrawal does not affect processing already done, or processing that the law requires.
Sharing of information
We share personal data with:
- Market infrastructure and intermediaries: depositories and depository participants for the demat transfer of a deal you confirm with the desk, and our bank for payments; for an IPO pre-application, the SEBI-registered intermediary that places the bid, the registrar to the issue, the sponsor bank and the exchanges; and KYC registration agencies, as needed to act on what you asked for;
- Service providers who process data for us, such as hosting, cloud, CRM, email, messaging, WhatsApp Business, telephony, analytics, advertising, security, backup and IT-support providers, under contracts that limit their use of the data;
- Professional advisers including lawyers, accountants, auditors and insurers;
- Authorities: SEBI, exchanges, depositories, tax authorities, the police, courts, tribunals, the Data Protection Board and any other authority where we are required or permitted by law to disclose, or where we consider disclosure necessary to protect our rights, property or safety or those of others;
- A buyer or successor of all or part of the BuyUnlistedShares business or of GFS, in connection with any merger, acquisition, restructuring, financing or sale, at any stage of that process;
- A partner who introduced you: if an approved BuyUnlistedShares partner introduced you to the desk, that partner sees limited status details of the enquiry: your first name, the last four digits of your mobile number, the company, whether it is a buy or a sell, and its status;
- Affiliates of GFS for the purposes above.
The processors we use today and what each receives: Hostinger International Ltd (the servers and database, Mumbai, India — everything above); HanuOTP and Fast2SMS (one-time login codes — your mobile number and the code); Zoho Mail (desk email — whatever you write to us); Google Cloud (the desk’s lead CRM, Mumbai region, and the service accounts that read our own sheets — enquiry name, phone, email, message); Google Drive (encrypted off-site backups of our internal systems); Telegram (desk alerts that carry a masked phone number and a reference, never your details); Amazon SES (transactional email, if enabled); your browser’s push service (for example Google, Mozilla or Apple, for web-push alerts you switch on — the alert text and your browser’s subscription address, never your name or number). A full list with each provider’s data-processing terms is kept by the desk and available on request.
We do not sell personal data. Data shared with a registered intermediary, registrar, bank, depository or exchange is governed by that entity’s own privacy practices once it reaches them.
Data retention
We retain personal data for as long as the purposes it was collected for continue — providing dealing, research and enquiry services to you, sending the market updates, IPO alerts and research you signed up for, maintaining the transaction, KYC and compliance records of the desk, and establishing or defending legal claims — and thereafter for as long as a law, regulation, exchange rule, intermediary requirement or limitation period requires. In particular, KYC and transaction records are kept for at least five years from the last transaction under the Prevention of Money Laundering Act and SEBI norms, and accounting and tax records for eight years. Records of consent and of enquiries are kept as evidence of what was asked and agreed. Short-lived technical data is removed automatically: one-time login codes within 24 hours, expired login sessions within 7 days, and no IP address is stored for article read counts. Encrypted database backups are overwritten on a 14-day cycle. Data that is no longer needed for any of these purposes is deleted or anonymised.
Data security
We take reasonable security measures appropriate to the data we hold, as Section 8(5) of the DPDP Act requires, including access controls, HTTPS, server hardening and encryption at rest of PAN, demat and UPI details collected through the Pre-apply form, of the PAN in your account’s KYC record and your saved IPO applicants, and of partners’ PAN and bank account numbers. Your browser keeps only a tracking token for a pre-application. No system is completely secure, and we do not guarantee that data will not be accessed, altered or disclosed through a breach, a cyber-attack or a failure beyond our reasonable control; you accept that risk in using the website. If a personal-data breach occurs we will tell the Data Protection Board of India without delay and give it the full report within 72 hours, and we will tell every affected person what happened, what it may mean for them and what we are doing about it, as the DPDP Act and the Digital Personal Data Protection Rules, 2025 require. Our internal breach runbook assigns who does what from the first hour. Keep your own devices, email and UPI app secure; we are not responsible for a compromise on your side.
Your rights under the DPDP Act
Subject to the DPDP Act and Rules, you have the right to:
- Access: a summary of the personal data we process about you and the processing activities, and the identities of the data fiduciaries and processors we have shared it with (Section 11);
- Correction, completion, updating and erasure of your personal data, except where retention is needed for a specified purpose or required by law (Section 12);
- Withdraw consent at any time, with effect for the future (Section 6(4));
- Grievance redressal through the grievance officer named below (Section 13), and, if you are not satisfied with our response, a complaint to the Data Protection Board of India;
- Nominate a person to exercise these rights if you die or become incapacitated (Section 14).
How to exercise them. Write to the grievance officer at care@buyunlistedshares.com from the email address or mobile number you used with us, saying which right you are exercising. We verify that the request comes from the person the data belongs to (usually a one-time code to that mobile number) before acting, and answer verified requests within the period the DPDP Rules allow. We may decline a request that is unverified, manifestly unfounded, excessive or repetitive, or that would require disclosing another person’s data, and will give the reason. Where you ask for erasure or withdraw consent we keep what the law requires us to keep (see Data retention) and may be unable to continue an enquiry, KYC or pre-application. Consent can be withdrawn the same way at any time, with effect for the future. To nominate a person to exercise these rights for you, write to the grievance officer with their name and contact details. You must not give false information or impersonate anyone when exercising a right (Section 15).
Children
The website and the desk are for persons aged 18 and over; any transaction needs a PAN in your own name, which is not issued to a minor, and the desk verifies identity before acting. We do not knowingly collect personal data from anyone under 18, and we do not obtain parental consent because we do not offer services to children. If you believe a child has given us data, write to us and we will delete it.
Cookies and browser storage
We use a small number of our own cookies and browser-storage keys to run the website and the features you use, and to remember your preferences. You can block or delete cookies through your browser settings; some features may then not work. This website sets three cookies of its own: bus_session (your login, 30 days, HttpOnly), bus_ref (which partner link brought you here, so the desk can credit them) and, for staff only, the panel sign-in cookie. It carries no third-party analytics or advertising tags today; if that changes this section and the consent banner will say so first. The site also uses browser storage (localStorage) for conveniences that stay on your device: bus-auth and bus-acct (who is signed in, no secrets), bus-watch and bus-scr-pins (watchlist and pinned companies), bus.allot.v1 (saved applicants for the allotment checker — kept on your device, and synced to your account only encrypted), bus.preapply.v1 and bus.ipoapps.v1 (pre-application references), bus.apply.broker, bus-theme, bus-scr-cols, bus-scr-view, bus-dep-view, bus-nudge-shown, bus-login-toast, bus-sync-reloaded and the bus.gate.* keys (display preferences and whether you have already seen a prompt). Clear them from your browser at any time; a signed-in account keeps its watchlist and saved lists on our server so they follow you across devices. These cookies and keys are strictly necessary for the website and the features you choose to use, so they are set without a separate consent; blocking them may stop login, the watchlist or partner credit from working.
Where data is processed
The website, its database and its nightly encrypted backups run on servers in Mumbai, India (Hostinger). The desk’s lead CRM runs on Google Cloud in the Mumbai region. One-time codes are sent by Indian SMS providers. Some processors keep data outside India: Google (service accounts and the encrypted off-site backups of our internal systems on Google Drive), Telegram (desk alerts, which carry no personal data beyond a masked number) and Zoho Mail (desk email, on Zoho’s India data centres for Indian accounts). Section 16 of the DPDP Act allows transfer to any country the Central Government has not restricted; none of these is restricted today, and we will move a processor if that changes.
Third-party links
The website links to third-party websites and services, including broker sign-up pages on the Open Demat page, registrar pages from the allotment checker, exchange and SEBI pages, and social-media platforms. We are not responsible for their privacy practices, cookies or content. Where a broker link is a partner link, that is disclosed on the page.
Changes to this policy
We may change this policy at any time by posting the revised version with a new “Last updated” date. The revised policy takes effect from that date. Where a change affects a purpose you consented to, we will ask for fresh consent where the DPDP Act requires it.
Grievance officer and contact
Privacy requests, complaints and DPDP Act grievances go to the grievance officer of Gayatri Financial Synergy: care@buyunlistedshares.com · 2nd Floor, SCO-39, HUDA Market, Sector 7A, Faridabad, Haryana 121006 · +91 91691 65959 · Mon–Sat, 8:30am–6pm IST. If you are not satisfied with the response you may complain to the Data Protection Board of India.
The grievance officer is a designated role at Gayatri Financial Synergy, reachable at the address above; the same officer is our contact for the Data Protection Board. We aim to acknowledge a complaint within 2 working days and to answer it within 30 days.
