Welcome to Brickker, a product of Concetto Builders & Promoters Pvt Ltd ("Company", "we", "us", or "our"). This Privacy Policy explains how we collect, use, share, and protect personal information when you use the Brickker mobile applications (iOS & Android), website (brickker.com), and related services (collectively, the "Platform"). By accessing or using the Platform, you agree to the practices described in this policy.
1. Information We Collect
1.1 Information You Provide Directly
- Account Registration: Name, email address, phone number (primary authentication method), and profile photo/avatar.
- Professional Details (Brokers): Company name, office address, website URL, and additional contact phone numbers.
- Property Listings: Property details including title, description, category, pricing, area measurements, location (address, city, state, pincode, GPS coordinates), amenities, and media files (images, brochures, videos).
- Property Inquiries: Name, phone number, email address, and inquiry message when you contact a broker about a property.
- Waitlist & Lead Forms: Name, mobile number, email, city, and brokerage size when you join our waitlist.
- Support Tickets: Name, email, phone number, message content, and any attachments you submit when contacting support.
1.2 Information Collected Automatically
- Device Information: Device ID, device model, operating system version, and platform (iOS, Android, or Web).
- Device Logs: App launch events and session activity linked to your device and user account.
- Authentication Data: Login method used (phone OTP, email OTP, Google OAuth, or password), session tokens, and verification status.
1.3 Information from Third Parties
- Google Sign-In: If you choose to authenticate via Google, we receive your Google account ID, email address, name, and profile picture from Google's OAuth service.
2. How We Use Your Information
We use the information we collect to:
- Provide & operate the Platform: Create and manage your account, authenticate your identity, and enable you to list properties and connect with other brokers.
- Facilitate co-broking: Match brokers with complementary property needs and enable property inquiry communications between users.
- Verify accounts: Confirm broker identities and professional credentials to maintain a trusted network.
- Improve the Platform: Analyse usage patterns and device data to enhance features, fix bugs, and optimise performance.
- Communicate with you: Send OTP codes for authentication, respond to support tickets, and provide service-related notifications.
- Ensure safety & security: Detect and prevent fraud, abuse, or unauthorised access, and resolve disputes between co-brokers.
- Comply with legal obligations: Fulfil regulatory requirements and respond to lawful requests from authorities.
3. How We Share Your Information
We do not sell your personal information. We may share information in the following circumstances:
- With Other Users: Your public profile details and property listings are visible to other authenticated users of the Platform. When you submit a property inquiry, your contact details are shared with the listing broker.
- Service Providers: We use trusted third-party services to operate the Platform:
- MSG91 — for delivering SMS-based OTP verification codes (receives your phone number).
- Resend — for delivering email-based OTP codes and transactional emails (receives your email address).
- Google — for OAuth authentication (receives and provides authentication tokens).
- Formspree — for processing waitlist form submissions on our website.
- Legal & Compliance: We may disclose information if required by law, regulation, legal process, or governmental request, or to protect the rights, property, or safety of Brickker, our users, or the public.
- Business Transfers: In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction.
4. Data Storage & Security
- Your data is stored in MongoDB databases hosted on secure servers.
- Passwords are hashed using bcrypt with salt rounds and are never stored in plaintext.
- Authentication tokens (JWT) have limited lifespans — access tokens expire in 15 minutes and refresh tokens in 7 days.
- Uploaded files (images, documents, videos) are stored with randomised filenames to prevent enumeration.
- We implement industry-standard security measures including encrypted connections, access controls, and regular security reviews.
While we take reasonable precautions, no method of electronic storage or transmission is 100% secure. We cannot guarantee absolute security of your data.
5. Data Retention
- Account Data: Retained for as long as your account is active. Upon account deletion, your data is soft-deleted (flagged with a deletion timestamp) and permanently removed within 90 days.
- Property Listings: Active listings are retained until removed by you or deactivated. Deleted listings follow the same soft-delete and purge cycle.
- Support Tickets: Retained for up to 2 years after resolution for quality assurance and dispute reference.
- Device Logs: Retained for up to 12 months for security and diagnostic purposes.
- OTP Codes: Phone OTPs expire after 5 minutes; email OTPs expire after 10 minutes. Expired codes are discarded.
6. Your Rights & Choices
Depending on your jurisdiction, you may have the following rights:
- Access & Portability: Request a copy of the personal data we hold about you.
- Correction: Update or correct inaccurate information in your profile at any time through the app.
- Deletion: Request deletion of your account and associated data. You can submit a request through our Delete Account Request page.
- Withdraw Consent: Where processing is based on consent, you may withdraw it at any time, though this may affect your ability to use certain features.
- Opt-Out of Communications: You may opt out of non-essential communications by contacting us.
7. Cookies & Tracking
Our Platform uses JWT-based authentication (not cookies) for session management. We do not use third-party tracking cookies, advertising pixels, or behavioural analytics tools. We do not track your browsing activity across other websites or apps.
8. Children's Privacy
The Platform is intended for users aged 18 and above. We do not knowingly collect personal information from children under 18. If we become aware that we have collected data from a minor, we will take steps to delete it promptly.
9. Third-Party Links
The Platform may contain links to third-party websites or services. We are not responsible for the privacy practices of those third parties. We encourage you to read their privacy policies before providing any personal information.
10. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you through the Platform or via email. The "Last Updated" date at the top of this page reflects the most recent revision. Continued use of the Platform after changes constitutes acceptance of the updated policy.
11. Governing Law
This Privacy Policy is governed by the laws of India. Any disputes arising under this policy shall be subject to the exclusive jurisdiction of the courts in New Delhi, India.
12. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us:
For account deletion requests, please visit our Delete Account Request page.