BicoincePrivacy Policy

Privacy Policy

Last updated: 26 July 2026

1. Who we are

Bicoince (“we”, “us”, “the Platform”) is a virtual-digital-asset (VDA) exchange operating in India, offering spot and derivatives trading, a peer-to-peer (P2P) marketplace, fiat on-ramp, and a non-custodial wallet. This Policy explains what personal data we process, why, who we share it with, and your rights. It is issued under the Digital Personal Data Protection Act, 2023 (DPDP Act) and the Information Technology Act, 2000, and reflects our obligations under the Prevention of Money-Laundering Act, 2002 (PMLA) and FIU-IND registration requirements for VDA service providers. Our registered legal-entity name, CIN and address are shown on our About page and in your account documents.

2. Data we collect

We collect only what the service and the law require. We do not embed advertising, analytics, or third-party tracking SDKs.

CategoryExamples
Account & contactEmail, mobile number, username (BCX handle), password (stored only as a salted hash)
Identity / KYCFull name, date of birth, address, selfie/liveness, and government IDs you provide — PAN, Aadhaar (or masked Aadhaar via DigiLocker), passport, GST, bank details
Financial & transactionOrders, positions, deposits/withdrawals, wallet addresses, balances, fees, and s.194S TDS records
LocationPrecise location (GPS latitude/longitude and its accuracy), captured once at identity verification and recorded with your address of record; and approximate/precise location when you use the P2P marketplace, for our anti-fraud geo-fence
Device & technicalDevice model/OS, app version, IP address, session tokens, and (if you enable push) a notification token
Why identity verification needs your location. Bicoince is a reporting entity under India's Prevention of Money Laundering Act, 2002 and the rules made under it, and is supervised by the Financial Intelligence Unit – India (FIU-IND). Those obligations require us to establish and record where a customer is when their identity is verified, so we capture a single GPS reading at that moment and store it alongside the address you declare. It is used to corroborate that address and to detect impersonation and account-farming — never for advertising, profiling, or tracking you afterwards.

The reading is taken once, only while you are completing verification. We do not collect location in the background, and the app does not request background-location permission. If you decline the permission we cannot complete identity verification, and your account stays limited to viewing — you can still browse the app, and you can delete your account at any time (section 10).
Biometrics stay on your device. Face/fingerprint unlock is performed by your device's operating system; we never receive, store or transmit your biometric data.
Your wallet keys stay with you. The DEX wallet is non-custodial — private keys remain under your control, you sign every transaction, and we cannot access or move those funds.

3. How we use your data

We do not sell your personal data.

4. Legal basis

We process data on the basis of your consent (which you may withdraw), the necessity of performing our contract with you, and compliance with legal obligations. Where processing is legally required, withdrawing consent may mean we can no longer provide the service.

5. Who we share it with

We do not sell your data. We share it only with:

6. International transfers

Some providers named above may process data outside India. Where they do, we rely on the transfer mechanisms permitted under the DPDP Act and contractual safeguards.

7. How long we keep it

KYC and transaction records are retained for at least five (5) years after the end of the business relationship or the transaction, as required by the PMLA. The verification-time location reading forms part of that KYC record and is retained on the same basis and for the same period — it is not kept separately or for longer. Other account data is kept for the life of your account and as needed thereafter for legal, tax and dispute purposes, then deleted or irreversibly anonymised.

8. How we protect it

No system is perfectly secure; keep your password, device and wallet recovery information safe.

9. Your rights

Subject to the DPDP Act, you may access, correct or erase your data (where no legal retention applies), withdraw consent, and nominate another individual to exercise your rights in the event of death or incapacity. To exercise a right, contact privacy@bicoince.com. You may also escalate to our Grievance Officer (below) and, if unresolved, to the Data Protection Board of India.

10. Deleting your account & data

You can request permanent deletion of your account and the personal data we are not legally required to keep, from the dedicated page:

Request account deletion →

KYC and transaction records subject to the five-year PMLA retention period are retained for that period and then deleted, even after account closure.

11. Children

The Platform is not intended for anyone under 18; we do not knowingly collect data from minors.

12. Grievance Officer & contact

In accordance with the Information Technology Act, 2000 and the DPDP Act, complaints may be raised with our Grievance Officer, contactable at grievance@bicoince.com. We aim to acknowledge complaints within 24 hours and resolve them within the timelines prescribed by law. General privacy queries: privacy@bicoince.com.

13. Changes to this Policy

We may update this Policy from time to time. Material changes are notified in-app or by email. The “Last updated” date above shows the current version.