Bicoince (“we”, “us”, “the Platform”) is a virtual-digital-asset (VDA) exchange operating in India, offering spot and derivatives trading, a peer-to-peer (P2P) marketplace, fiat on-ramp, and a non-custodial wallet. This Policy explains what personal data we process, why, who we share it with, and your rights. It is issued under the Digital Personal Data Protection Act, 2023 (DPDP Act) and the Information Technology Act, 2000, and reflects our obligations under the Prevention of Money-Laundering Act, 2002 (PMLA) and FIU-IND registration requirements for VDA service providers. Our registered legal-entity name, CIN and address are shown on our About page and in your account documents.
We collect only what the service and the law require. We do not embed advertising, analytics, or third-party tracking SDKs.
| Category | Examples |
|---|---|
| Account & contact | Email, mobile number, username (BCX handle), password (stored only as a salted hash) |
| Identity / KYC | Full name, date of birth, address, selfie/liveness, and government IDs you provide — PAN, Aadhaar (or masked Aadhaar via DigiLocker), passport, GST, bank details |
| Financial & transaction | Orders, positions, deposits/withdrawals, wallet addresses, balances, fees, and s.194S TDS records |
| Location | Precise location (GPS latitude/longitude and its accuracy), captured once at identity verification and recorded with your address of record; and approximate/precise location when you use the P2P marketplace, for our anti-fraud geo-fence |
| Device & technical | Device model/OS, app version, IP address, session tokens, and (if you enable push) a notification token |
We do not sell your personal data.
We process data on the basis of your consent (which you may withdraw), the necessity of performing our contract with you, and compliance with legal obligations. Where processing is legally required, withdrawing consent may mean we can no longer provide the service.
We do not sell your data. We share it only with:
Some providers named above may process data outside India. Where they do, we rely on the transfer mechanisms permitted under the DPDP Act and contractual safeguards.
KYC and transaction records are retained for at least five (5) years after the end of the business relationship or the transaction, as required by the PMLA. The verification-time location reading forms part of that KYC record and is retained on the same basis and for the same period — it is not kept separately or for longer. Other account data is kept for the life of your account and as needed thereafter for legal, tax and dispute purposes, then deleted or irreversibly anonymised.
No system is perfectly secure; keep your password, device and wallet recovery information safe.
Subject to the DPDP Act, you may access, correct or erase your data (where no legal retention applies), withdraw consent, and nominate another individual to exercise your rights in the event of death or incapacity. To exercise a right, contact privacy@bicoince.com. You may also escalate to our Grievance Officer (below) and, if unresolved, to the Data Protection Board of India.
You can request permanent deletion of your account and the personal data we are not legally required to keep, from the dedicated page:
KYC and transaction records subject to the five-year PMLA retention period are retained for that period and then deleted, even after account closure.
The Platform is not intended for anyone under 18; we do not knowingly collect data from minors.
In accordance with the Information Technology Act, 2000 and the DPDP Act, complaints may be raised with our Grievance Officer, contactable at grievance@bicoince.com. We aim to acknowledge complaints within 24 hours and resolve them within the timelines prescribed by law. General privacy queries: privacy@bicoince.com.
We may update this Policy from time to time. Material changes are notified in-app or by email. The “Last updated” date above shows the current version.