Privacy Policy — UPXME

Effective: 18 April 2026 • Version 2.0 • Jurisdiction: India
BINDING NOTICE
By using UPXME you give free, specific, informed and unambiguous consent under Section 6 of the Digital Personal Data Protection Act, 2023 ("DPDP Act") to the processing of your personal data strictly as described below. If you do not consent, do not use the app.

1. WHO WE ARE

UPXME is a Data Fiduciary under the DPDP Act. You are the Data Principal. Contact: privacy@upxme.in.

2. LEGAL FRAMEWORK

This Policy is issued under the DPDP Act 2023, the IT Act 2000, SPDI Rules 2011, PMLA 2002, and the Consumer Protection (E-Commerce) Rules 2020.

3. DATA WE COLLECT

4. DATA WE DO NOT COLLECT

Aadhaar, biometrics, precise GPS, contact lists, SMS, call logs, passwords, video uploads.

5. CHILDREN & MINOR PLAYERS

UPXME's investor (Contributor) role is strictly 18+. However the Player (talent) role is open to minors, since talent is age-independent.

Where a Player is below 18, the account is opened and operated by a parent or legal guardian who provides verifiable consent under Section 9 of the DPDP Act, 2023. The guardian is the contractual signatory and controls all data, content and payouts. In respect of such minors we (a) do not track the minor for advertising, (b) do not target ads at minors, (c) do not undertake behavioural profiling of minors, and (d) honour guardian requests to access, correct or delete the minor's data within the timelines in Section 10. Any user found to be accessing the Contributor role while under 18 will have the account terminated and funds returned to the source, less statutory deductions.

6. PURPOSES & LAWFUL BASIS

7. SHARING

We DO NOT sell, rent or barter your data. Limited sharing only with:

PAN, bank account and phone are never shown publicly in-app.

8. CROSS-BORDER TRANSFERS

Data is stored in Asia-Pacific. Any routing outside India is restricted to countries not notified under Section 16 DPDP Act and is subject to contractual safeguards.

9. RETENTION

After retention lapses, data is irreversibly erased or anonymised.

10. YOUR RIGHTS (Chapter III, DPDP Act)

Write to privacy@upxme.in. We respond within 30 days. Abusive or excessive requests may be refused with written reasons.

11. SECURITY

TLS 1.2+ in transit; storage encryption at rest; passwordless OTP; short-lived JWTs; role-based access; admin actions audit-logged; KYC fields never returned on public endpoints and redacted in logs; anti-abuse controls (2% holding cap, 7-day sell lock, 10% daily sell cap, circuit breaker at 30% price spike, atomic race-safe deductions). Practices substantially aligned with IS/ISO/IEC 27001. You are responsible for device security and must never share OTPs.

12. BREACH NOTIFICATION

On a personal data breach creating real risk to your rights, we will notify the Data Protection Board of India and each affected Data Principal within 72 hours of becoming aware, consistent with Section 8(6) DPDP Act and CERT-In directions.

13. GRIEVANCE OFFICER

Name: Grievance Officer, UPXME
Email: grievance@upxme.in
Acknowledgement within 24 hours; resolution within 15 days.
Escalation: Data Protection Board of India under Chapter V DPDP Act.

14. AUTOMATED DECISIONS

No fully automated decisions produce legal effects on you. Fraud flags are reviewed by humans before any restriction.

15. NO SALE • NO BEHAVIOURAL ADVERTISING

We do not sell data to brokers and do not run behavioural advertising. Any future change will require fresh explicit opt-in consent and will not apply retrospectively.

16. POLICY CHANGES

Material changes are notified at least 30 days in advance via app and registered email. Continued use after the effective date is acceptance.

17. CONTACT

Privacy: privacy@upxme.in
Grievance: grievance@upxme.in