Privacy Policy & Data Security

Welcome to Pluto. We are profoundly committed to safeguarding your personal data, protecting your digital privacy, and maintaining absolute transparency regarding our administrative records. This Privacy Policy details how we collect, process, compile, and protect the information that you share when using our mobile application, local databases, transaction routing channels, and allied web services.

1. Introduction & Corporate Commitment

Pluto functions as a collaborative digital catalog and wallet ecosystem. By utilizing our App and accessing our subscription tiers, you unequivocally consent to the procedures described herein. We process your data in strict compliance with applicable global regulations, including the General Data Protection Regulation (GDPR) for European Union citizens, the California Consumer Privacy Act (CCPA) for California residents, and the Digital Personal Data Protection Act, 2023 (DPDP Act) of India.

2. Comprehensive Breakdown of Data We Collect

We collect multiple categories of information to verify accounts, process subscriptions, list catalog details, and secure wallet balances. The categories of personal data collected include:

  • Account Identifiers: Full legal name, verified email address, phone number, encrypted password hashes, and profile imagery.
  • Business & Partner Catalog Data: For independent businesses (Ateliers), we compile business registration names, geographical locations, operational addresses, service classifications, FSSAI regulatory license numbers, taxation codes, catalog listings, inventory specifications, and operational schedules.
  • Financial & Ledger Transactions: Records of all wallet transfers, manual checkouts, digital credits, deposit receipts, withdrawal bank details, transaction references, and StoreKit receipt verification hashes.
  • Mobile Device Telemetry: IP addresses, network carriers, hardware model specifications, operating system versions, localization data (GPS coordinates, with explicit permission), platform crash dumps, and application state variables.

3. Systemic Methods of Data Collection

Pluto collects user and partner data through three primary mechanisms:

  • Direct Input: Information manually entered during account creation, catalog updates, or wallet transactions.
  • Automated Platform Logging: As you navigate the app, our backend servers automatically log telemetry variables, API latencies, and device indicators to prevent fraud and optimize system performance.
  • Third-Party Integrations: We receive transaction states and receipt validation responses directly from payment gateways (such as Razorpay) and Apple StoreKit to verify subscription tiers.

We do not sell or lease your personal information. We process data strictly based on the following legal foundations:

  • Contractual Performance: Necessary to verify vendor credentials, maintain real-time wallet balances, route customer orders, and validate subscription packages.
  • Legitimate Business Interest: To detect fraudulent actions, monitor for objectionable content or illegal product listings, evaluate application crashes, and enforce our platform standards.
  • Legal Compliance: For taxation recording, keeping FSSAI license compliance logs, and cooperating with statutory law enforcement requests under the Information Technology Act, 2000.
  • Explicit Consent: For publishing geographical coordinates, accessing device photos for product catalog uploads, and tracking user-level analytics.

5. StoreKit receipt Validation & Subscription Data

All auto-renewable subscriptions inside the Pluto iOS app (Silver, Gold, Platinum Tiers) are governed by Apple StoreKit. When you purchase or restore a tier, the transaction is processed directly on Apple's secure infrastructure. StoreKit transmits a secure receipt token to our servers. Our backend acts as a verification proxy, sending this token to Apple's validation servers to determine subscription state, renewal dates, and billing periods. Pluto never accesses or stores credit card numbers, billing addresses, or iTunes credentials. The validated state is written to our backend database and synced to the local Hive database on your device.

6. Granular Data Retention Schedules

We retain personal and business data only as long as necessary for operational, legal, and compliance reasons:

  • Active Accounts: All account data, catalogs, and wallet records are stored continuously for the duration of the account's life.
  • Terminated Accounts: Upon account deletion requests, personal identifiers are permanently scrubbed or anonymized within 30 days, except where law requires otherwise.
  • Financial & Wallet Ledgers: Under financial regulations and anti-money laundering guidelines, all ledger records, payout references, and subscription transaction details are retained for a minimum of 7 years from the date of the transaction.
  • System Performance Logs: General crash logs and telemetry data are automatically deleted or rotated every 90 days.

7. Authorized Third-Party Disclosures

We share data only with trusted partners who operate under strict non-disclosure terms:

  • Payment Infrastructure: Apple App Store/StoreKit for iOS subscriptions, and Razorpay for wallet credits.
  • Hosting & Cloud Processing: AWS and Google Cloud servers where database engines are located.
  • System Communications: Email relay service providers (such as Brevo) used to dispatch transactional receipt notifications.
  • Legal Authorities: We disclose information if required under court order or statutory command to comply with anti-money laundering or safety standards.

8. Statutory Privacy Rights (GDPR / CCPA / DPDP 2023)

Under applicable global and local laws, you possess the following rights regarding your data:

  • Right to Access: You can request details of the personal data we hold about you at any time.
  • Right to Rectification: You can update incorrect or incomplete profiles directly in your settings.
  • Right to Erasure ('Right to be Forgotten'): You can request complete deletion of your account and personal history, subject to statutory retention limits.
  • Right to Restrict Processing: You can object to specific processing operations, such as marketing communication or device telemetry tracking.
  • Right to Data Portability: You can request a machine-readable copy of your personal details and catalog listings.
  • Right to Nominate (DPDP Act, 2023): You have the right to nominate any individual to exercise your privacy rights in the event of death or incapacity.

9. Cookies, Local Caching, & On-Device Storage

Pluto uses local data caching mechanisms (Hive boxes and SQLite) on your mobile device. These local repositories store session tokens, active partner catalog configurations, and localized wallet logs. Local cache minimizes network overhead and allows offline functionality. These files are stored within the sandbox of the Pluto app and cannot be read by other applications. You can clear local data by logging out or selecting 'Clear App Cache' in the Profile settings.

10. Child Privacy & COPPA Safeguards

Pluto does not knowingly collect, compile, or process personal data from children under the age of 13. If we discover that an account has been created by a minor under 13, the account, catalog listings, and wallet details will be deleted permanently from our production databases within 24 hours. Parents or guardians who believe their child has shared personal information can contact us immediately at admin@breakingstocks.in.

11. Grievance Officer & Official Contact Details

If you have queries, grievances, or seek to exercise your statutory data rights, you may contact our designated Grievance Officer under India's Information Technology rules. The Officer will address your concerns within 15 days of receiving the grievance email:

  • Email: admin@breakingstocks.in
  • Subject: Data Privacy Inquiry / Grievance Redressal
  • Address: Pluto Legal Team, New Delhi, India.