This Privacy Policy describes how Byonus (“we”, “us”, or “our”) collects, uses, stores, shares, and protects personal information when you use our mobile applications, websites, and related services (collectively, the “Services”).
The Services include the Byonus customer app
(package typically com.byonus.customer) and the
Byonus Merchant app (package typically
com.byonus.merchant), plus APIs that power coupons,
rewards, store visits, chat, notifications, and merchant
subscriptions.
1. Who we are (data controller)
For personal data processed through the Services, the controller is the operator of the Byonus platform (referred to in this policy as Byonus). We provide a local commerce platform that connects shoppers with merchants for coupons, lucky draws, happy hours, stamps/rewards, in-store QR collect/redeem flows, chat, and related features.
Merchants who use Byonus Merchant may also process limited customer information (for example, when approving a coupon request or chatting). In those cases, the merchant may act as an independent controller for how they handle customer interactions at their store. This policy covers Byonus’s own processing as the platform provider.
2. Scope and consent
This policy applies to personal information we process when you:
- Download, install, or use Byonus or Byonus Merchant
- Create or manage an account (including phone OTP login)
- Visit a store page, collect/redeem offers, or join draws
- Use maps, camera/QR scanning, chat, or notifications
- Subscribe to a merchant plan or complete a payment
- Contact support or browse our marketing website
By using the Services, you acknowledge this Privacy Policy. Where required by law, we will ask for additional consent (for example, device permissions for location or camera, or marketing messages).
3. Information we collect
We collect information in three ways: (a) you provide it directly; (b) it is generated through your use of the Apps; and (c) it comes from device permissions or third-party SDKs you enable.
3.1 Account and profile information
- Full name and display name
- Mobile phone number (used for OTP authentication)
- Email address (if provided)
- Profile photo or images you upload
- Address / city / pin code / state (if you add them)
- Account type (customer / merchant) and verification status
- Referral or invite codes, where used
3.2 Customer app activity
- Stores you view, search, or favourite
- Coupons you claim, collect, or redeem and their statuses
- Hot offers, happy hours, and marketing campaigns you open
- Lucky draw entries, winners, and claim actions
- Visit / stamp / reward history linked to outlets
- Chat messages you send to merchants (and related metadata)
- Support requests you start from the app (e.g. WhatsApp)
3.3 Merchant app and business information
- Business / outlet name, address, hours, categories, images
- Banking or GST details if you enter them for payouts/compliance
- Staff or related accounts you configure
- Offers you create (coupons, happy hours, lucky draws, hot offers, minimum buy, stamps)
- Customer lists and approval actions (collect/redeem decisions)
- Subscription plan, payment status, and billing-related identifiers
- Reports and operational metrics shown in the merchant dashboard
3.4 Location information
With your permission, we may collect approximate or precise location to show nearby outlets and offers, sort results by distance, and support maps/directions. Location may be collected in the foreground while you use relevant features. You can revoke location permission in system settings; nearby discovery may then be limited or use a last-known / manual location if available.
3.5 Camera and QR / images
With your permission, the customer app may use the camera to scan QR codes for in-store flows. We process scan results needed to identify the outlet or offer action. We do not use the camera to continuously record video for advertising. Profile or store images you upload are stored to display in the Apps.
3.6 Device, network, and diagnostics
- Device model, OS version, app version, language
- IP address and general network information
- Push notification tokens (FCM / device token)
- Crash logs, performance, and analytics events
- Approximate identifiers used to secure sessions and prevent abuse
3.7 Communications
- OTP SMS (sent via our messaging providers)
- In-app and push notifications about offers, approvals, chat, or account events
- Support conversations when you contact us
3.8 Information we do not sell
We do not sell your personal information to data brokers. We do not rent personal contact lists for unrelated third-party marketing.
4. App permissions (Android / iOS)
Depending on the app and OS version, we may request the following permissions. You can deny or later revoke them; some features will not work without them.
| Permission | Typical use |
|---|---|
| Internet / network | Load stores, offers, chat, auth, and sync with our servers |
| Location (fine / coarse) | Nearby stores, distance sorting, maps and directions |
| Camera | QR scanning for collect/redeem and related in-store flows |
| Notifications | Approvals, chat, offer updates, and transactional alerts |
| Photos / media (if prompted) | Uploading profile or store images where the OS requires it |
5. How we use information
We use personal information to:
- Provide the core product — accounts, OTP login, store discovery, coupons, rewards, lucky draws, happy hours, hot offers, visits, QR collect/redeem, merchant approvals, and chat
- Personalise relevance — show nearby or useful outlets and offers based on location and activity
- Operate merchant tools — outlet setup, campaign creation, customer management, reports, and subscriptions
- Communicate — OTPs, transactional pushes, service messages, and (where allowed) product updates
- Secure the platform — detect fraud, abuse, duplicate claims, and unauthorised access; enforce session expiry
- Improve quality — analytics, crash diagnosis, and feature performance
- Comply with law — respond to lawful requests and keep necessary records
6. Legal bases (where applicable)
Depending on your region, we process data under one or more of these bases:
- Contract — to provide the Services you request (account, offers, redemptions, merchant plans)
- Consent — for optional permissions (location, camera, marketing notifications) and certain SDK uses
- Legitimate interests — security, fraud prevention, product improvement, and basic service communications, balanced against your rights
- Legal obligation — when we must retain or disclose information under applicable law
7. Sharing and disclosure
We may share information only as described below:
- With the other side of a transaction you start — e.g. a merchant sees your collect/redeem request; a customer sees outlet and offer details a merchant published
- Service providers (processors) — hosting, databases, SMS/OTP, push notifications, maps, analytics, crash reporting, and payment gateways, under contracts that limit use to providing services to us
- Business transfers — if we merge, sell, or reorganise, data may transfer under continued protection commitments
- Legal & safety — to courts, regulators, or law enforcement when required, or to protect users, merchants, or Byonus from harm or fraud
We do not sell personal information. We do not share personal information for cross-context behavioural advertising as a business model of the Apps.
8. Third-party services
The Apps integrate third-party technologies. Their processing is governed by their own policies in addition to ours. Categories include:
| Category | Examples of use |
|---|---|
| Cloud hosting / API | Store accounts, offers, and app traffic securely |
| Authentication / OTP SMS | Send one-time passwords to your phone number |
| Firebase / push (FCM) | Deliver notifications; optional analytics/crash tools |
| Maps | Show maps and open directions to outlets |
| Payment gateway (e.g. Razorpay) | Process merchant plan payments; we do not store full card numbers on Byonus servers |
Links or SDKs that open third-party sites (maps, WhatsApp, payment pages) are outside our direct control once you leave our Apps.
9. Payments and merchant subscriptions
Merchant subscriptions and plan upgrades may be processed by a payment partner (such as Razorpay). When you pay:
- Payment card or UPI details are typically entered on the payment partner’s secure checkout and handled under their PCI-compliant processes
- We receive limited confirmation data (for example payment success, order/payment IDs, plan status) so we can unlock merchant features
- We do not store full payment card PAN/CVV on our application servers
Refunds, chargebacks, and tax invoices (if any) follow the terms of the merchant subscription / payment partner and applicable law.
10. Data retention
We keep personal information only as long as needed for the purposes above, including:
- Account data — while your account remains active
- Offer / redemption records — as needed for dispute handling, merchant operations, and fraud prevention
- Billing / subscription records — as required for accounting and legal retention
- Logs & security data — for a limited period unless needed longer for investigations
When you delete your account (where the feature is available), we delete or anonymise personal data associated with the account, except information we must retain by law or for legitimate security / dispute reasons. Residual copies may remain in encrypted backups for a limited time until rotated.
11. Security
We use administrative, technical, and organisational measures designed to protect personal information, such as:
- Encrypted transport (HTTPS / TLS) for API traffic
- Token-based authentication and session controls
- Access controls on production systems
- Monitoring for abuse of collect/redeem and account flows
No method of electronic storage or transmission is completely secure. You are responsible for keeping OTP codes and devices secure. If you believe your account was compromised, contact us promptly.
12. Your rights and choices
Subject to applicable law (including Indian IT rules and, where relevant, other regional laws), you may have rights to:
- Access the personal data we hold about you
- Correct inaccurate or incomplete data
- Delete your account / request erasure
- Withdraw consent for optional permissions or marketing
- Object to or restrict certain processing
- Receive a copy of data you provided (portability), where required
In-app choices:
- Update profile details in account / edit profile screens
- Revoke location, camera, or notification permissions in device settings
- Log out to end the local session on that device
- Use in-app delete-account flows where available
To exercise rights that are not available in-app, contact us using the details in Section 16. We may need to verify your identity (typically via the registered phone number) before fulfilling a request.
13. Children’s privacy
The Services are intended for a general audience and are not directed to children under 13 (or under 18 where local law requires parental consent for similar services). We do not knowingly collect personal information from children. If you believe a child has provided us data, contact us and we will take appropriate steps to delete it.
14. International data transfers
We primarily operate Services for users in India. Servers, subprocessors, or SDKs may process data in India or other countries. Where data is transferred internationally, we take steps designed to ensure an appropriate level of protection consistent with this policy and applicable law.
15. Changes to this policy
We may update this Privacy Policy to reflect product, legal, or operational changes. We will revise the “Last updated” date at the top of this page and, when changes are material, provide additional notice in the Apps or by other reasonable means. Continued use of the Services after an update constitutes acceptance of the revised policy, except where consent is required by law.
16. Contact us
For privacy questions, data requests, or complaints about how we handle personal information, contact:
- Product / brand: Byonus
- Email: support@byonus.com
- WhatsApp support: +91 98337 29591
- In-app: Help / Support from the Byonus customer or merchant app
- Website: Byonus home
We aim to respond to verifiable privacy requests within a reasonable period, and within any timeline required by applicable law.