This Privacy Policy describes how ISocial Sports Private Limited ("BeBetta", "we", "our", "us"), a company incorporated under the laws of India with its registered office at BVR Ek, Opposite Inder Residency, Ellisbridge, Ahmedabad, Gujarat – 380006, India, collects, uses, stores, shares, transfers, and erases your personal data when you use the BeBetta mobile application, the website www.bebetta.in, and associated services (collectively, the "Platform").
BeBetta acts as a Data Fiduciary under the Digital Personal Data Protection Act, 2023 ("DPDP Act") and the Digital Personal Data Protection Rules, 2025 ("DPDP Rules"), and, where applicable to users in the European Union / European Economic Area or the United Kingdom, as a Data Controller under Regulation (EU) 2016/679 ("GDPR") and the UK GDPR.
This Policy also serves as the notice required under Section 5 of the DPDP Act. It is designed to be understandable independently of any other document. You may access this notice, and every request for consent we make, in English or in any language specified in the Eighth Schedule to the Constitution of India. To request a copy in another language, use the in-app language selector or write to our Data Protection Officer at the contact details in Section 16.
1. Scope and Applicability
This Privacy Policy applies to:
- All users of the BeBetta mobile application (Android and iOS) and visitors to www.bebetta.in;
- Users who enable Commerce features, including receipt scanning, QR/barcode scanning, and SMS transaction parsing (Android only);
- Users who connect third-party accounts, including Google/Gmail (when this optional feature becomes available); and
- Users located in India (governed primarily by the DPDP Act and DPDP Rules) and users located in the EU/EEA or the UK (who have additional rights under the GDPR / UK GDPR as set out in Section 12).
This Policy is governed by and drafted to comply with the DPDP Act, 2023 and the DPDP Rules, 2025, the GDPR (for EU/EEA/UK users), the Information Technology Act, 2000 (to the extent applicable to matters not covered by the DPDP Act), and Google's API Services User Data Policy (for the optional Gmail integration).
2. Key Terms
- Personal Data: any data about an individual who is identifiable by or in relation to such data (Section 2(t), DPDP Act).
- Processing: any automated operation performed on digital personal data, including collection, recording, storage, use, sharing, disclosure, erasure, or destruction (Section 2(x), DPDP Act).
- Data Principal / Data Subject: you, the individual to whom the personal data relates. For a child, this includes the parent or lawful guardian.
- Data Fiduciary / Controller: BeBetta, which determines the purpose and means of processing your personal data.
- Data Processor: any person or entity that processes personal data on our behalf under a valid written contract.
- Consent Manager: a person registered with the Data Protection Board of India through whom you may give, manage, review, and withdraw consent.
- Child: an individual who has not completed eighteen years of age.
3. Personal Data We Collect, Purposes, and Legal Bases
In accordance with Section 5(1) of the DPDP Act and Rule 3 of the DPDP Rules, the table below provides an itemised description of each category of personal data we collect, the specific purpose for which it is processed, and the legal basis for that processing under both the DPDP Act and the GDPR. We collect and process only such personal data as is necessary for each specified purpose.
| Personal Data (Itemised) | Specified Purpose | Legal Basis — DPDP Act | Legal Basis — GDPR |
|---|---|---|---|
| Full name; mobile number; email address; date of birth; account credentials (hashed); profile photograph (optional) | Account creation and management; age verification; login authentication; service communications | Consent (S.6); certain legitimate uses — voluntary provision (S.7(a)) | Contract performance (Art. 6(1)(b)); consent (Art. 6(1)(a)) |
| Device model, OS and version; device identifier; IP address; approximate (city-level) location; app version; session and crash logs | Platform operation, security, fraud detection, abuse prevention, debugging | Consent (S.6) | Legitimate interests — security and fraud prevention (Art. 6(1)(f)) |
| Games played; time spent; scores; tournament participation; offers viewed, claimed and redeemed; in-app purchases; engagement metrics | Operating the gaming and rewards platform; internal product improvement | Consent (S.6) | Contract performance (Art. 6(1)(b)); legitimate interests (Art. 6(1)(f)) |
| Receipt / transaction data: merchant name; transaction date and time; purchase amount; items purchased (where printed); payment method type (never full card details); transaction reference | Purpose 1 — Rewards: detecting, extracting and validating purchase transactions to award Gems, points, or rewards; fraud prevention | Consent (S.6) — separate, specific consent per Section 5 of this Policy | Consent (Art. 6(1)(a)); contract performance (Art. 6(1)(b)) |
| Receipt / transaction data (as above) | Purpose 2 — Commercial Analytics: generating aggregated market intelligence, category-level consumer spend reports, and brand preference analytics that BeBetta licenses or sells to CPG companies, FMCG brands, retailers, and advertisers | Separate, specific, opt-in consent (S.6). This purpose is OPTIONAL — declining does not affect rewards or core features | Consent (Art. 6(1)(a)) — separate opt-in |
| Receipt / transaction data (as above) | Purpose 3 — Brand Partner Sharing: sharing receipt-derived insights with the categories of partners listed in Section 7 | Separate, specific, opt-in consent (S.6). OPTIONAL — declining does not affect rewards or core features | Consent (Art. 6(1)(a)) — separate opt-in |
| Profile, usage, and transaction data | Purpose 4 — Personalised Marketing: personalising offers, deals, and brand-partner recommendations shown to you within the Platform | Separate, specific, opt-in consent (S.6). OPTIONAL | Consent (Art. 6(1)(a)) |
| SMS transaction data (Android only): bank transaction alert content matching RBI-mandated formats — merchant, amount, timestamp, reference | Automated detection of eligible purchases for rewards (Purpose 1 only). Personal SMS, OTPs and non-transactional messages are never read or stored | Separate, specific consent (S.6) via a dedicated in-app disclosure and the Android READ_SMS permission | Consent (Art. 6(1)(a)) |
| Google user data (optional future Gmail integration): transactional emails relating to receipts, invoices and purchase confirmations only | Automated receipt detection and validation (Purpose 1 only). Never used for advertising, profiling, resale, or any secondary purpose | Separate, specific consent (S.6) via Google OAuth consent screen | Consent (Art. 6(1)(a)) |
| Grievance and support communications | Responding to requests, complaints, and rights exercises; maintaining records of grievance redressal | Certain legitimate uses (S.7(a)); legal obligation | Legal obligation (Art. 6(1)(c)); legitimate interests (Art. 6(1)(f)) |
What we do not do: We do not sell personal data in identifiable form. We do not use Google user data for advertising or profiling. We do not process children's personal data for commercial analytics, brand-partner sharing, behavioural monitoring, tracking, or targeted advertising under any circumstances (Section 13).
4. How We Obtain Your Consent
Where consent is our basis for processing, it is obtained in accordance with Section 6(1) of the DPDP Act and Articles 4(11) and 7 of the GDPR: it is free, specific, informed, unconditional, and unambiguous, and given through a clear affirmative action — such as ticking an unticked box or activating a clearly labelled toggle. We never rely on pre-ticked boxes, silence, inactivity, or your mere use of the Platform as consent.
Our consent architecture is granular. At onboarding and within the in-app Privacy Centre, you are presented with separate, individually controllable consents for:
- (a) Rewards Processing — processing your receipt and transaction data to award Gems and rewards (required only if you choose to use Commerce features);
- (b) Commercial Analytics — inclusion of your transaction data in aggregated market-intelligence products (optional; off by default);
- (c) Brand Partner Sharing — sharing of receipt-derived insights with the partner categories in Section 7 (optional; off by default);
- (d) Personalised Marketing — personalisation of offers and recommendations (optional; off by default);
- (e) SMS Transaction Parsing (Android only) and
- (f) Gmail Integration (when available) — each behind its own dedicated disclosure and permission flow.
Declining any optional consent will not affect your access to BeBetta's core gaming and rewards features. Each consent request is presented in clear and plain language, is available in English or any Eighth Schedule language, and includes the contact details of our Data Protection Officer.
4.1 Consent Records
We maintain auditable records of every consent given, including what you consented to, when, the version of the notice presented to you, and any subsequent modification or withdrawal. Under Section 6(10) of the DPDP Act, the burden of proving that notice was given and consent obtained rests with us, and our records are maintained accordingly.
4.2 Consent Manager
You may also give, manage, review, or withdraw your consent through a Consent Manager registered with the Data Protection Board of India, once such Consent Managers are operational. We will interoperate with registered Consent Managers as required by the DPDP Rules.
4.3 Fresh Consent for New Purposes
If we propose to process your personal data for a purpose not covered by your existing consents, we will present you with an updated notice and obtain fresh, affirmative consent before the new processing begins. Continued use of the Platform is never treated as consent to a new processing purpose.
5. Withdrawing Your Consent
You may withdraw any consent, in whole or in part, at any time, with the same ease with which you gave it (Section 6(4), DPDP Act; Article 7(3), GDPR). Each consent listed in Section 4 has its own toggle in the in-app Privacy Centre (Profile → Privacy Centre → My Consents). You may also withdraw consent by writing to our DPO, or through a registered Consent Manager.
Upon withdrawal:
- We will, within a reasonable time, cease processing your personal data for the withdrawn purpose, and cause every Data Processor engaged by us to cease such processing (Section 6(6), DPDP Act);
- We will erase the relevant personal data in accordance with Section 10 of this Policy, unless retention is required by law;
- Withdrawal does not affect the lawfulness of processing carried out before withdrawal; and
- The consequences of withdrawal (for example, inability to earn receipt-based rewards after withdrawing Rewards Processing consent) are borne by you, but withdrawal will never affect features that do not depend on the withdrawn consent.
6. Receipt Scanning and SMS Parsing — Detailed Disclosure
6.1 Receipt Scanning (Android and iOS)
When you submit a receipt via camera scan, image upload, or QR/barcode scan, our systems use optical character recognition to extract the transaction fields itemised in Section 3, validate the transaction against fraud-detection rules before awarding rewards, and store only the extracted data (the raw image is retained only where required for fraud adjudication, and is deleted once adjudication concludes).
6.2 SMS Transaction Parsing (Android Only)
- A dedicated in-app disclosure screen explains exactly what will be read and why, before the Android READ_SMS permission is requested;
- Only messages matching known RBI-mandated bank transaction alert patterns are processed; personal SMS, OTPs, and non-transactional messages are never read, stored, or transmitted;
- Parsing occurs locally on your device; only the extracted transaction fields are transmitted, over an encrypted connection. Raw SMS content is never stored on our servers; and
- You may revoke the permission at any time via your device settings or the in-app Privacy Centre; both routes are equally effective.
6.3 Fraud Prevention
We apply automated anomaly detection to flag duplicate, altered, or suspicious receipts; a 72-hour reward hold for new users pending verification; manual review of escalated cases by authorised staff in a logged environment; and configurable thresholds on spend amounts and submission frequency. This processing is necessary to protect the integrity of the rewards programme.
7. Commercial Analytics and Data Sharing — Full Disclosure
A part of BeBetta's business is the generation of aggregated market intelligence — such as category-level consumer spend reports, brand preference indices, and campaign measurement analytics — which BeBetta licenses or sells to third parties. Your transaction data is included in these products only if you have given the separate, opt-in Commercial Analytics consent described in Section 4(b).
7.1 Categories of Recipients
Where you have given the applicable consent, receipt-derived insights may be shared with the following categories of recipients:
- Consumer packaged goods (CPG) and fast-moving consumer goods (FMCG) manufacturers and brands;
- Retailers, e-commerce platforms, and quick-commerce platforms;
- Advertising, media, and market-research agencies acting for the above; and
- Brand partners whose offers are redeemable on the Platform, for campaign measurement.
Form of sharing: insights shared with these recipients are aggregated and anonymised in accordance with the standard in Section 10.3. We do not share your personal data with these recipients in identifiable form. If any future product were to involve sharing identifiable personal data, it would require a further separate consent naming the recipient category and purpose.
7.2 Other Disclosures
- Service Providers (Data Processors): cloud hosting, OCR processing, analytics infrastructure, fraud detection, customer support, and communications vendors process personal data on our behalf strictly under written contracts meeting the requirements of Section 8(2) of the DPDP Act and Article 28 GDPR — covering scope of processing, confidentiality, security measures, restrictions on onward disclosure, breach notification, audit rights, and erasure obligations (including certification of erasure) on termination or consent withdrawal.
- Legal Authorities: where required by law, court order, or direction of a competent authority in India or another applicable jurisdiction.
- Corporate Transactions: in a merger, acquisition, reconstruction, or asset transfer approved by a competent court, tribunal, or authority, personal data may be transferred to the successor entity subject to protections at least equivalent to this Policy, and you will be notified of any such transfer.
Where personal data we process is likely to be used to make a decision that affects you, or is disclosed to another Data Fiduciary, we ensure its completeness, accuracy, and consistency as required by Section 8(3) of the DPDP Act.
8. International Data Transfers
Your personal data is primarily stored and processed in India. If personal data is transferred outside India, such transfer will comply with Section 16 of the DPDP Act and any Central Government notification restricting transfers to specific countries or territories.
For users in the EU/EEA or UK, any transfer of personal data outside the EEA/UK is made only: (a) to jurisdictions covered by an adequacy decision of the European Commission (or UK equivalent); or (b) subject to appropriate safeguards under Article 46 GDPR, such as Standard Contractual Clauses, together with supplementary measures where necessary. You may obtain a copy of the relevant safeguards by contacting our DPO.
9. Security and Breach Notification
- All data is encrypted at rest (AES-256) and in transit (TLS 1.2+); access is restricted to authorised personnel on a need-to-know basis; OAuth tokens are stored securely and never exposed in logs;
- We implement appropriate technical and organisational measures under Section 8(4)–(5) of the DPDP Act and Article 32 GDPR, and conduct periodic security reviews; and
- In the event of a personal data breach, we will intimate the Data Protection Board of India and each affected Data Principal in the form and manner prescribed under the DPDP Rules and, for EU/EEA/UK users, notify the competent supervisory authority within 72 hours and affected data subjects where required by Articles 33–34 GDPR.
10. Data Retention and Erasure
10.1 Retention Schedule
| Data Category | Retention Period | Trigger for Erasure |
|---|---|---|
| Account data | Duration of active account + up to 90 days post-deletion (recovery window) | Account deletion request; consent withdrawal; prolonged non-use per Rule timelines |
| Receipt and transaction data | Up to 24 months from submission, unless a shorter period applies | Purpose fulfilment; consent withdrawal; account deletion |
| SMS-parsed transaction data | Same as receipt data | Same as receipt data; revocation of SMS permission stops new collection immediately |
| Google user data (when integration is live) | Only while the integration is active | Deleted within 30 days of disconnection or account deletion |
| Grievance and consent records | As required to demonstrate compliance and by applicable law | Expiry of statutory limitation periods |
| Irreversibly anonymised aggregate data | May be retained (no longer personal data — see 10.3) | Not applicable |
10.2 Erasure and the Deletion Cascade
Upon your withdrawal of consent, your erasure request, or when the specified purpose is no longer being served (whichever is earlier), we will, unless retention is required by law: (a) erase your personal data from our production systems, analytics platforms, model-training datasets, reporting pipelines, backups (on the next scheduled backup cycle), and archived cohort datasets; and (b) cause every Data Processor to erase the personal data we made available to it, obtaining certification of erasure (Section 8(7), DPDP Act; Article 17 GDPR). Where you do not approach us for the specified purpose or exercise any rights for the period prescribed under the DPDP Rules, the purpose is deemed no longer served and erasure follows automatically; we will notify you at least 48 hours before such erasure so you may retain your account if you wish.
10.3 Anonymisation Standard
Data is treated as anonymised — and therefore outside the scope of this Policy — only where it has been irreversibly transformed such that you can no longer be identified, directly or indirectly, by any means reasonably likely to be used. Pseudonymised data, and aggregated outputs from which individual-level data remains recoverable, remain personal data and are erased as part of the deletion cascade.
11. Your Rights (All Users — DPDP Act)
- Right to Access (S.11): obtain a summary of your personal data being processed, the processing activities undertaken, and the identities of all Data Fiduciaries and Data Processors with whom it has been shared, with a description of the data shared.
- Right to Correction, Completion, Updating and Erasure (S.12): have inaccurate or misleading data corrected, incomplete data completed, data updated, and personal data erased unless retention is necessary for the specified purpose or required by law.
- Right of Grievance Redressal (S.13): readily available means of grievance redressal, as set out in Section 15 below.
- Right to Nominate (S.14): nominate another individual to exercise your rights in the event of your death or incapacity, via Privacy Centre → Nominee or by writing to the DPO.
- Right to Withdraw Consent (S.6(4)): as set out in Section 5 above.
12. Additional Rights for EU/EEA and UK Users (GDPR)
If you are located in the EU/EEA or the UK, you additionally have the following rights, exercisable free of charge, to which we will respond within one month (extendable by two further months for complex requests, with notice):
- Access (Art. 15), Rectification (Art. 16), Erasure / "right to be forgotten" (Art. 17), Restriction of processing (Art. 18);
- Data Portability (Art. 20): receive the personal data you provided to us in a structured, commonly used, machine-readable format, and have it transmitted to another controller where technically feasible;
- Right to Object (Art. 21): object at any time to processing based on legitimate interests, and to direct marketing (in which case we will stop);
- Automated Decision-Making (Art. 22): we do not make decisions based solely on automated processing that produce legal or similarly significant effects concerning you. Fraud-detection flags are subject to human review before any adverse action is taken; and
- Complaint to a Supervisory Authority (Art. 77): lodge a complaint with the supervisory authority of your habitual residence, place of work, or the place of the alleged infringement.
13. Children's Data
BeBetta is intended only for individuals aged 18 and above.
- Age verification: our onboarding flow includes a reasonable and verifiable age-assurance mechanism proportionate to the risks of our processing, consistent with Section 9 of the DPDP Act and Rule 10 of the DPDP Rules — self-declaration alone is not relied upon. Processing does not commence until age assurance is completed.
- No child profiling — absolute: we do not, under any circumstances, undertake tracking or behavioural monitoring of children or targeted advertising directed at children (Section 9(3), DPDP Act), and children's data is never included in commercial analytics or brand-partner products.
- If a minor is identified post-registration: we immediately suspend all processing of that account's data and exclude it from every analytics pipeline; we then either obtain verifiable consent of the parent or lawful guardian in the manner prescribed under Rule 10 (verifying that the consenting individual is an identifiable adult), following which the account may continue with child-safe restrictions, or — where such consent is not obtained within a reasonable period — erase all associated personal data, including from Data Processor systems, and terminate the account.
- Reporting: if you believe a child has created an account, contact dpo@bebetta.in.
14. Cookies and Tracking Technologies
Our website uses cookies for session management and authentication (strictly necessary), and — only with your consent given through the cookie banner — analytics and preference cookies. Non-essential cookies are off by default. You may change your choices at any time via the cookie settings link in the website footer or your browser settings. Declining non-essential cookies does not affect core functionality.
15. Grievance Redressal and Complaints to the Board
Step 1 — Contact us: raise any grievance regarding our obligations or your rights through Privacy Centre → Raise a Grievance, or by writing to the Grievance Officer / DPO at the details in Section 16. We will acknowledge within 48 hours and respond within the period prescribed under the DPDP Rules, and in any event within 30 days.
Step 2 — Data Protection Board of India: if you are not satisfied with our response, or in the case of a personal data breach, you may complain to the Data Protection Board of India in the manner prescribed under the DPDP Act and DPDP Rules, through the Board's digital portal (details are published by the Board and linked in our Privacy Centre). Please note that under Section 13(3) of the DPDP Act, you must first exhaust the grievance redressal opportunity with us before approaching the Board.
EU/EEA/UK users may additionally complain to their supervisory authority as described in Section 12.
16. Data Protection Officer and Contact
We have designated a Data Protection Officer (DPO), based in India, who is the point of contact for all questions, rights requests, and grievances under this Policy:
Data Protection Officer: [Name of DPO — to be designated by the Board of Directors]
Email: dpo@bebetta.in (rights requests and grievances); grievance@bebetta.in (grievance redressal); legal@bebetta.in (legal notices)
Address: ISocial Sports Private Limited, BVR Ek, Opposite Inder Residency, Ellisbridge, Ahmedabad, Gujarat – 380006, India
The business contact information of the DPO is published on our website in accordance with Section 8(9) of the DPDP Act.
17. Changes to This Policy
We may update this Policy to reflect changes in our features, legal requirements, or practices. When we make material changes we will update the version number and "Last Updated" date, notify you by in-app notice and email, and — where a change involves a new or expanded processing purpose — obtain your fresh, affirmative consent before that processing begins. We will never treat your continued use of the Platform as consent to a new processing purpose.