Legal
Privacy Policy
Last updated: March 10, 2026
This Privacy Policy applies to Genie Bazaar Private Limited ("Genie Bazaar", "we", "our", or "us") and governs the collection, use, storage, disclosure, and protection of personal data obtained through our website (geniebazaar.com) and enterprise software-as-a-service platform (collectively, the "Services"). By using our Services you agree to the terms of this policy.
1. Who We Are
Genie Bazaar Private Limited is an enterprise technology company incorporated under the Companies Act, 2013 in India. We provide cloud-based operational management software covering asset tracking, procurement, maintenance, facilities and financial operations.
For data protection purposes, Genie Bazaar Private Limited is the Data Controller for personal data collected via the website and marketing activities, and acts as a Data Processoron behalf of our enterprise customers in relation to data stored within the platform.
Data Controller Contact
Genie Bazaar Private Limited
101, Siddhivinayak CHS, Plot No. 20, Sector 42A, Nerul, Navi Mumbai – 400706, Maharashtra, India
Email: support@geniebazaar.com
2. Data We Collect
2.1 Data you provide directly
- Account registration: Name, work email, company name, designation, phone number, country.
- Demo / webinar registrations: The above plus company size and current system in use.
- In-platform data: Asset records, vendor details, purchase orders, maintenance logs, and other operational data entered by your team.
- Support communications: Messages, attachments, and metadata from email or chat interactions with our team.
2.2 Data collected automatically
- Usage analytics: Pages visited, features used, session duration, click events — via our analytics infrastructure.
- Device & browser data: IP address, browser type and version, operating system, referrer URL.
- Cookies and similar technologies: Session cookies (required for authentication), preference cookies, and analytics cookies (subject to your consent). See Section 6.
- UTM / marketing attribution: Source, medium, and campaign parameters appended to URLs by marketing channels (e.g., Google Ads, LinkedIn).
2.3 Data from third parties
- Calendar integration data (Google Calendar) where you explicitly authorise the connection.
- Payment processor tokens (we do not store full card numbers).
3. How We Use Your Data
| Purpose | Legal basis (GDPR / DPDP) |
|---|---|
| Provide, operate and improve the Services | Contract performance / Legitimate interest |
| Process demo or webinar registrations | Consent / Legitimate interest |
| Send transactional emails (confirmations, calendar invites) | Contract performance |
| Send product updates, newsletters and marketing communications | Consent (opt-in) |
| Analyse usage to improve product features | Legitimate interest |
| Detect and prevent fraud, abuse and security threats | Legitimate interest / Legal obligation |
| Comply with applicable laws and regulations | Legal obligation |
| Respond to support requests and queries | Contract performance / Legitimate interest |
We do not sell personal data to third parties. We do not use personal data for automated individual decision-making that produces legal or similarly significant effects without human review.
4. Data Sharing & Disclosure
We share personal data only in the following circumstances:
- Service providers: Cloud hosting (AWS), email delivery, analytics, payment processors, calendar APIs — under data processing agreements that restrict use to our instructions.
- Enterprise customers: Where you are an end-user of a customer's Genie Bazaar instance, your data may be visible to that customer's administrators as permitted by their agreement with us.
- Corporate transactions: In the event of a merger, acquisition or asset sale, personal data may be transferred subject to equivalent privacy protections.
- Legal requirements: Where required by law, court order, or government authority, and only to the minimum extent necessary.
5. International Data Transfers
Our primary infrastructure is hosted on AWS in the Asia-Pacific region (Singapore / Mumbai). If you access our Services from the European Economic Area (EEA), United Kingdom, or other regions with data transfer restrictions, your data may be transferred to and processed in India and/or Singapore.
For EEA/UK users, such transfers are conducted on the basis of Standard Contractual Clauses (SCCs) approved by the European Commission, or other appropriate safeguards. You may request a copy of the applicable transfer mechanism by contacting support@geniebazaar.com.
6. Cookies
We use the following categories of cookies:
| Category | Examples | Consent required |
|---|---|---|
| Strictly necessary | Session authentication, CSRF tokens | No |
| Functional / Preferences | Language, UI state | No |
| Analytics | Page-view tracking, event tracking | Yes |
| Marketing / Advertising | Conversion tracking (Google Ads, LinkedIn) | Yes |
You can manage your cookie preferences at any time via our Cookie Consent banner or by clearing cookies in your browser settings. Withdrawing consent does not affect the lawfulness of processing carried out before withdrawal.
7. Data Retention
- Active accounts: Data is retained for the duration of the contract plus 7 years (to meet Indian statutory requirements under the Companies Act and Income Tax Act).
- Marketing leads: Retained for up to 3 years from last interaction or until withdrawal of consent.
- Server and access logs: Retained for 90 days.
- Deleted accounts: Purged within 30 days of termination request, except where a longer retention is required by law.
8. Your Rights
Depending on your jurisdiction, you have the following rights:
| Right | Description |
|---|---|
| Access | Request a copy of personal data we hold about you. |
| Correction | Request correction of inaccurate or incomplete data. |
| Erasure ("right to be forgotten") | Request deletion of your data subject to legal retention obligations. |
| Data portability | Receive your data in a structured, machine-readable format. |
| Objection | Object to processing based on legitimate interests or for direct marketing. |
| Restriction | Request that we restrict processing while a dispute is resolved. |
| Withdraw consent | Withdraw consent for processing at any time without affecting prior lawful processing. |
| Lodge a complaint | File a complaint with the relevant supervisory authority (e.g., CNIL, ICO, or the Data Protection Board of India). |
To exercise any of these rights, email support@geniebazaar.com. We will respond within 30 days (or as required by applicable law).
9. Security
We implement industry-standard technical and organisational measures to protect personal data, including AES-256 encryption at rest, TLS 1.2+ in transit, role-based access controls, and regular penetration testing. See our Security page for full details. To report a security concern, contact us at support@geniebazaar.com.
10. Children's Privacy
Our Services are designed for enterprise use and are not directed at individuals under 18 years of age. We do not knowingly collect personal data from minors. If you believe we have inadvertently collected such data, contact us immediately at support@geniebazaar.com.
11. Changes to This Policy
We may update this Privacy Policy periodically. Material changes will be communicated via email (for registered users) or a prominent notice on our website at least 14 days before they take effect. Continued use of the Services after the effective date constitutes acceptance of the revised policy. The latest version will always be available at geniebazaar.com/privacy.
12. Applicable Law & Jurisdiction
This Privacy Policy is governed by the laws of India, including the Digital Personal Data Protection Act 2023 (DPDP Act). For users in the EEA/UK, the GDPR or UK GDPR also applies. Disputes shall be subject to the exclusive jurisdiction of the courts at Mumbai, Maharashtra, India.
For GDPR inquiries, see our GDPR Compliance page.
Questions? Contact us at support@geniebazaar.com