Privacy Policy
Last Updated: August 21, 2026 • How banalo.business protects and handles your data
1. Scope & Data Controller
This Privacy Policy describes how Banalo Business ("we", "us", or "our") collects, uses, processes, stores, and protects your personal and commercial data when you access or use banalo.business (the "Platform").
We adhere to the provisions of the Digital Personal Data Protection Act, 2023 ("DPDPA"), the Information Technology Act, 2000, and international data protection standards (including principles of GDPR and CCPA where applicable).
2. Categories of Information We Collect
- Account & Authentication Data: Email address, user identification tokens, profile display name, and password hashes collected via secure Firebase Authentication.
- Billing & Transaction Information: Customer name, billing address, country, transaction ID, payment status, and subscription tier processed via our certified PCI-DSS Level 1 payment processor (Dodo Payments). We never store raw credit/debit card numbers, CVVs, or UPI PINs on our servers.
- Proprietary Formulation & Chat History: User-inputted chemical notes, active ingredient percentages, dilution preferences, batch calculations, and real-time conversation sessions generated within our AI Co-founder studios.
- Supplier Feedback & Interactions: Reviews, ratings, notes, and inquiries submitted regarding third-party vendors listed in our Supplier Directory.
- Technical Telemetry & Log Data: Internet Protocol (IP) address, browser user-agent, operating system, timestamped session actions, and performance metrics to detect anomalous access and prevent malicious abuse.
3. Lawful Basis & Purposes for Processing
We process your personal and commercial data strictly for the following lawful business purposes:
- To provision and maintain your access to the multi-category formulation studios, landed cost calculators, and verified supplier networks.
- To authenticate your session, enforce subscription tier entitlements, and process recurring renewals.
- To transmit your formulation prompts to AI inference models and deliver contextual responses.
- To detect, investigate, and prevent fraudulent transactions, credential stuffing, scraping, and intellectual property theft.
- To comply with statutory accounting, taxation, and regulatory reporting obligations under Indian law.
4. Ironclad Non-Disclosure & Zero Data Sale Commitment
We Do Not Sell Your Data: Banalo Business maintains an absolute policy against monetizing user data. We will NEVER sell, lease, rent, trade, or distribute your email address, formulation recipes, chemical compositions, or proprietary business ideas to third-party data brokers, advertising exchanges, or external market researchers.
Your confidential formulation work belongs entirely to you and is treated as confidential commercial information.
5. AI Model Processing & Zero Public Training Guarantee
When you interact with our AI Co-founders, your queries are processed via secure enterprise APIs (including Google Cloud / Gemini Enterprise endpoints). Your proprietary formulas, chat messages, and ingredient calculations are NOT used to train public foundation models. They are processed ephemerally solely to return your immediate session output and saved into your private database space.
6. Authorized Third-Party Sub-processors
We partner with trusted, SOC-2 and ISO-27001 certified infrastructure providers to deliver our platform services:
- Google Cloud & Firebase: Encrypted database storage (Firestore), user authentication, and cloud infrastructure.
- Dodo Payments / Payment Gateways: PCI-DSS compliant payment processing, recurring billing, and merchant of record compliance.
- Google Gemini Enterprise: Secure, isolated AI inference computation.
7. Security Architecture & Encryption
We implement comprehensive organizational and technical security safeguards:
- Encryption in Transit: All HTTP traffic is secured using TLS 1.3 / SSL encryption.
- Encryption at Rest: Cloud databases utilize AES-256 bit encryption at rest.
- User-Level Access Isolation: Database access is governed by strict Firestore Security Rules ensuring users can only read and write their own data.
8. Cookies & Local Storage
We use strictly necessary cookies and browser local storage to maintain your active authentication session, cache user interface preferences, and track essential application state. We do not employ invasive cross-site advertising cookies.
9. Data Retention & User Rights (Right to Erasure)
Under applicable data protection legislation, you possess the following rights regarding your personal information:
- Instant Chat Deletion: You can purge individual conversation sessions or clear your entire formulation history directly inside the application.
- Right to Rectification: You may update or correct your account credentials at any time.
- Account & Data Erasure: You have the right to request permanent deletion of your account and all associated database records by emailing our team at contact@banalo.business. Requests are fulfilled within 30 days.
10. Security Incident & Breach Notification
In the unlikely event of a security incident that compromises the integrity or confidentiality of personal data, we will notify affected users and competent regulatory authorities in compliance with applicable statutory reporting timelines under the DPDPA and Indian law.
11. Grievance Officer & Privacy Contact
If you have questions, concerns, or grievances regarding our privacy practices or data processing, please contact our designated Grievance Officer at:
Entity: Banalo Business
📧 Email: contact@banalo.business
🌐 Platform: https://banalo.business