Fixed-price packages — the number you see is the number you pay Kickoff within 48 hours of purchase GST included · itemised at checkout Scope, deliverables and timeline agreed before we start
Data protection

Privacy Policy

What we collect, why we collect it, how long we keep it and what you can make us do about it — written in plain language, and aligned with the Digital Personal Data Protection Act, 2023 and the IT Rules.

Last updated 4 October 2026 Governing law: India BUYGORITHM PRIVATE LIMITED
We collect what an order needs

Name, email, phone, billing address and — if you give it — a project brief. Nothing speculative, nothing sold on.

No card data, ever

Payment details go straight to our gateway. They never reach our servers and we cannot see them.

We do not sell your data

Not to advertisers, not to data brokers, not to anyone. It is used to deliver what you bought.

You can make us delete it

Request access, correction or erasure at any time. We respond within 30 days.

Section 01

Who this applies to

This policy explains how BUYGORITHM PRIVATE LIMITED handles personal data collected through this website, during the delivery of our services, and in correspondence with us. In the language of the Digital Personal Data Protection Act, 2023 we are the Data Fiduciary and you are the Data Principal.

It applies whether you buy as a guest, create an account, submit an enquiry, or simply browse.

Section 02

What we collect

We collect the minimum needed to sell you a service, deliver it, invoice it correctly and answer your questions.

CategoryWhat it includesWhy we need it
Identity & contactName, email address, mobile number, company nameTo confirm your order, contact you for kickoff and provide support
BillingBilling address, city, state, PIN code, GSTIN if suppliedTo issue a GST-compliant tax invoice as required by Indian tax law
Order dataPackages purchased, amounts, order reference, payment statusTo fulfil the contract and maintain statutory financial records
Project briefAnything you voluntarily enter in the optional brief fieldTo arrive at kickoff already understanding your context
Account dataEmail address and a hashed password, if you create an accountTo let you sign in and see your order history
Service delivery dataAccess credentials or platform permissions you grant usTo perform the work you purchased
Technical dataIP address, browser type, pages viewed, referring sourceSecurity, fraud prevention and understanding how the site is used
What we never collect. We do not collect or store full card numbers, CVVs, UPI PINs or bank credentials. Those are handled entirely by our payment gateway, in line with RBI tokenisation guidelines. We also do not knowingly collect data from anyone under 18.
Section 03

Why we are allowed to process it

  • Performance of a contract — everything necessary to deliver and invoice the package you bought.
  • Legal obligation — retaining invoices and transaction records under Indian tax and company law.
  • Consent — optional things such as marketing email, which you opt into and can withdraw at any time without affecting your purchase.
  • Legitimate interest — securing the website, preventing fraud and improving the service, balanced against your rights.

Where processing relies on consent, you may withdraw it at any time by writing to care@buygoriithm.com. Withdrawal does not affect processing already carried out lawfully.

Section 04

What we do with it

  • Process your order, take payment and issue your tax invoice.
  • Contact you to schedule kickoff and to deliver the work.
  • Provide support and answer questions about your engagement.
  • Send transactional email — order confirmation, payment status, delivery updates. These are not marketing and cannot be opted out of while an order is live.
  • Detect and prevent fraudulent or abusive use of the site.
  • Comply with legal, tax and regulatory obligations.
  • Where you have opted in, send occasional email about services. One click unsubscribes, permanently.

We do not use your data for automated decision-making that produces legal or similarly significant effects on you, and we do not profile you for advertising purposes.

Section 05

Who else sees it

We share personal data only where it is necessary, and only with parties bound to protect it.

RecipientWhat they receiveWhy
Payment gatewayName, email, phone, amount, order referenceTo process the payment and handle refunds
Email service providerName, email address, order detailsTo send transactional email such as confirmations and invoices
Hosting providerData stored on our serversTo host the website and database
Professional advisersRecords as requiredAccounting, audit and legal advice, under confidentiality
AuthoritiesOnly what is legally compelledWhere required by law, court order or a valid regulatory request

We do not sell, rent or trade your personal data. We do not share it with advertisers or data brokers. If our business is ever transferred, personal data would move with it and you would be notified before any change in how it is handled.

Section 06

Cookies and tracking

We use a small number of cookies and similar technologies:

  • Essential — your session, your cart contents and CSRF protection. The site cannot function without these.
  • Analytics — if configured, an analytics tool tells us which pages are used and where people drop off, in aggregate.
  • Preferences — small local settings such as whether you prefer the catalogue in grid or list view.

Your cart is stored in your own browser rather than on our servers. Clearing your browser data clears it. You can block or delete cookies in your browser settings; essential cookies being blocked will break checkout.

Section 07

How long we keep it

DataRetention period
Order and invoice recordsEight years, as required by Indian tax and company law
Account dataUntil you ask us to close the account
Project briefs and work filesTwo years after delivery, then deleted unless you ask us to keep them
Access credentials you granted usRevoked and deleted at handover
Enquiry correspondenceTwo years from last contact
Marketing consent recordsUntil withdrawn, plus a record of the withdrawal itself
Section 08

How we protect it

  • The site is served over HTTPS/TLS; data in transit is encrypted.
  • Passwords are stored only as salted one-way hashes. Nobody here can read your password.
  • Database access is restricted to the accounts that require it, and administrative access is limited to named personnel.
  • Client credentials supplied for delivery are stored in a password manager, used only for the engagement, and revoked at handover.
  • We keep backups and test that they restore.
If a breach occurs. No system is perfectly secure. In the event of a personal data breach we will notify the Data Protection Board and affected individuals as required under the DPDP Act, describing what happened, what data was involved and what you should do.
Section 09

Your rights

Under the Digital Personal Data Protection Act, 2023 you have the right to:

  • Access — obtain a summary of the personal data we hold about you and how it is processed.
  • Correction — have inaccurate or incomplete data corrected or completed.
  • Erasure — have your data deleted where we no longer need it and no law requires us to keep it.
  • Withdraw consent — for anything processed on the basis of consent, as easily as it was given.
  • Grievance redressal — raise a complaint with our Grievance Officer, and escalate to the Data Protection Board if unsatisfied.
  • Nominate — nominate another individual to exercise these rights on your behalf in the event of death or incapacity.

To exercise any of these, write to care@buygoriithm.com from the email address associated with your orders, or use the request links in your account settings. We respond within 30 days and will tell you if we need longer and why.

Section 10

Grievance officer

In accordance with the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 and the DPDP Act, we have appointed a Grievance Officer to handle complaints about the handling of your personal data.

Contact details, response timelines and the escalation path are published on our Grievance Redressal page. Complaints are acknowledged within 24 hours and resolved within 15 days.

Data-specific complaints may also be sent directly to grievance@buygoriithm.com.
Section 11

Changes to this policy

We update this policy when our practices or the law change. The revision date at the top of this page always reflects the current version. Where a change materially affects how we use data you have already given us, we will notify you by email before it takes effect.

Exercise your rights

Ask us for your data — or to delete it

No forms to hunt for and no retention team trying to talk you out of it. Send the request and we will action it within 30 days.

Start something

Pick a package.
We start Monday.

No discovery retainer, no open-ended statement of work. Choose the outcome you want, pay online, and a specialist contacts you within 48 business hours to begin.

48hKickoff after payment confirmation
0Hourly overruns — the price is the price
100%Refundable before work begins