Privacy Policy

Last updated: May 21, 2026

1. Who we are

Build Your Network (BYN, we, us) is an intent-based professional networking platform operated from India. Our registered contact for privacy matters is [email protected].

2. What data we collect

  • Account data: name, email address, hashed password, and the date you created your account.
  • Profile data: bio, headline, profession, location (city name), skills, interests, photos, LinkedIn/Instagram/website URLs, and what you are working on.
  • Location data: approximate GPS coordinates (rounded to ~1 km) if you enable location-based discovery. We never collect precise real-time location.
  • Usage data: connection requests you send, messages you exchange, profiles you view, and your last-active timestamp.
  • Acquisition data: how you heard about us (e.g. LinkedIn, referral) — collected once during onboarding.
  • Payment data: plan type, currency, and Razorpay order/payment IDs. We do not store card numbers — Razorpay handles card processing.
  • Device data: push notification tokens (if you enable notifications). We do not collect device fingerprints or advertising IDs.

3. Why we process your data

PurposeLegal basis (GDPR)
Provide the platform and match you with other usersContract (Art. 6.1.b)
Verify your email addressContract (Art. 6.1.b)
Send transactional emails (OTP, receipts, deletion warnings)Contract (Art. 6.1.b)
Process payments and prevent fraudContract + Legitimate interest (Art. 6.1.b, 6.1.f)
Analyse aggregate platform usage to improve the productLegitimate interest (Art. 6.1.f)
Analytics tracking (Google Analytics) — only with consentConsent (Art. 6.1.a)
Send marketing emails — only with consentConsent (Art. 6.1.a)
Comply with legal obligationsLegal obligation (Art. 6.1.c)

4. Cookies and tracking

We use a cookie (byn_consent) to store your cookie preference. If you accept analytics cookies, we load Google Analytics (G-5NQDBYG4CJ) which sets its own cookies and collects anonymised usage data. You can withdraw consent at any time using the cookie settings link in the app footer.

We do not use advertising cookies, tracking pixels, or third-party retargeting.

5. Who we share your data with

We share data only with the vendors listed below, each under a data processing agreement:

  • Supabase (database hosting, EU/US region) — stores all user data.
  • Cloudinary (media storage) — stores profile photos.
  • Resend (transactional email) — sends OTP, receipts, and system emails.
  • Razorpay (payments, India) — processes premium subscriptions.
  • Expo (push notifications) — delivers in-app notifications.
  • Google Analytics (analytics, consent-gated) — aggregated usage stats.
  • Railway (hosting) — runs the application server.

We do not sell your personal data to any third party.

6. Your rights

Depending on your location, you have the following rights:

  • Access: download all your data at Settings → Export my data or by emailing [email protected].
  • Erasure: delete your account and all associated data at Settings → Delete account. Deletion is immediate and irreversible.
  • Rectification: update your profile at any time from the Edit Profile screen.
  • Portability: your data export is provided as a structured JSON file.
  • Withdraw consent: toggle analytics cookies off at any time.
  • Do Not Sell (CCPA): California residents may opt out of any sale of personal information at Settings → Privacy → Do Not Sell My Data. We do not currently sell personal data, but this setting is available as required by law.
  • Complaint: you may lodge a complaint with your local data protection authority.

To exercise any right, email [email protected]. We respond within 30 days.

7. Data retention

We keep your data for as long as your account is active. Accounts inactive for more than 18 months will receive a 30-day deletion warning by email. If you do not log in within that period, your account and all associated data are permanently deleted.

After you request account deletion, all data is erased immediately. Payment records may be retained for up to 7 years to comply with financial regulations.

8. Security

Passwords are hashed with bcrypt (cost factor 12). Connections use HTTPS/TLS. API endpoints are rate-limited. We conduct security reviews before major releases. Despite these measures, no system is 100% secure — please use a strong, unique password.

9. Children

BYN is not directed at children under 18. We do not knowingly collect data from anyone under 18. If you believe we have collected data from a minor, contact us immediately at [email protected].

10. Changes to this policy

We will notify you of material changes by email or in-app notice at least 14 days before they take effect. Continued use after that date constitutes acceptance.

11. Contact

Privacy enquiries: [email protected]
General support: [email protected]