Privacy Policy

We respect your privacy and are committed to protecting your personal data.

Last updated: June 15, 2026

This Privacy Policy describes how Bizoforce Technologies Pvt. Ltd. ("Bizoforce", "we", "our", or "us") collects, uses, shares, and protects information about you when you use our website at https://bizoforce.com and related services (collectively, the "Platform"). By using the Platform, you agree to the practices described below.

1. Information We Collect

a) Information you provide directly

  • Account registration details: name, email address, password.
  • Business / company profile data: company name, description, logo, website URL, location, social links.
  • Product listings: product names, descriptions, pricing, images.
  • Communications: messages sent via our contact form, support tickets, or review submissions.
  • Payment information: billing name, address; card details are processed directly by our payment provider (PayPal) and are never stored on our servers.

b) Information collected automatically

  • Log data: IP address (resolved to city/country only — raw IPs are not stored), browser type, pages visited, referring URL, time-stamps.
  • Device data: operating system, screen resolution, language settings.
  • Usage data: search queries, clicked listings, features accessed.
  • Cookies and similar tracking technologies (see Section 4).

c) Information from third parties

  • If you sign in via Google OAuth, we receive your name, email, and profile picture from Google.
  • We may enrich company profiles with publicly available business information (e.g., Google Places API).

2. How We Use Your Information

We use the information we collect to:

  • Create and manage your account and provide the services you request.
  • Display company and product listings in the marketplace.
  • Process subscription payments and send receipts.
  • Send transactional emails (e.g., lead notifications, password resets, listing updates).
  • Improve, personalise, and expand the Platform based on usage analytics.
  • Detect and prevent fraud, abuse, and security incidents.
  • Comply with legal obligations.
  • Send promotional communications — only with your explicit consent and only if you have opted in.

We rely on the following legal bases under GDPR (where applicable): contract performance, legitimate interests, legal obligation, and consent.

3. Sharing of Information

We do not sell your personal data. We may share it with:

  • Service providers who process data on our behalf under strict data-processing agreements (e.g., hosting, email delivery via Brevo/Sendinblue, analytics).
  • Payment processors (PayPal) solely to complete transactions.
  • Other users — public profile information (company name, description, logo, products) is visible to all visitors by design.
  • Legal authorities when required by law, court order, or to protect our rights or the safety of others.
  • Business transfers — in the event of a merger, acquisition, or asset sale, your data may be transferred; we will provide notice beforehand.

4. Cookies & Tracking

We use the following types of cookies:

TypePurposeDuration
Strictly NecessaryAuthentication token, session stateSession / 30 days
FunctionalUser preferences, language1 year
AnalyticsGoogle Analytics — page views, traffic sourcesUp to 2 years

You can manage or disable cookies through your browser settings. Disabling strictly necessary cookies may impair Platform functionality. We honour Do Not Track signals where feasible.

5. Data Retention

We retain your personal data for as long as your account is active or as needed to provide services. Specifically:

  • Account data — retained until you delete your account, then purged within 30 days.
  • Payment records — kept for 7 years to satisfy tax and accounting obligations.
  • Server logs — retained for 90 days, then automatically deleted.
  • Marketing consent records — retained indefinitely as proof of consent until withdrawn.

After the applicable retention period, data is securely deleted or anonymised.

6. Security

We implement industry-standard safeguards to protect your data:

  • All data in transit is encrypted via TLS 1.2+.
  • Passwords are hashed with bcrypt; we never store plain-text passwords.
  • JWT access tokens are short-lived; refresh tokens are stored in httpOnly cookies.
  • API keys are stored as hashed values with a visible prefix only.
  • Database access is restricted to server-side processes only; no direct public access.
  • Regular security reviews and dependency audits.

Despite these measures, no system is 100% secure. In the event of a data breach, we will notify affected users and relevant authorities as required by law.

7. GDPR — Your Rights (EEA & UK)

If you are located in the European Economic Area (EEA) or the United Kingdom, you have additional rights under the General Data Protection Regulation (GDPR) and the UK GDPR.

Your rights include:

  • Right of Access (Art. 15) — You may request a copy of all personal data we hold about you.
  • Right to Rectification (Art. 16) — You may ask us to correct inaccurate or incomplete data.
  • Right to Erasure / "Right to be Forgotten" (Art. 17) — You may request deletion of your personal data where there is no compelling reason for us to continue processing it.
  • Right to Restriction of Processing (Art. 18) — You may ask us to restrict how we process your data in certain circumstances.
  • Right to Data Portability (Art. 20) — You may receive your personal data in a structured, machine-readable format and transfer it to another controller.
  • Right to Object (Art. 21) — You may object to processing based on legitimate interests or for direct marketing purposes at any time.
  • Rights related to automated decision-making (Art. 22) — You have the right not to be subject to decisions based solely on automated processing that significantly affect you.
  • Right to Withdraw Consent — Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.

How to exercise your rights: Email us at clientservices@bizoforce.com with the subject line "GDPR Request". We will respond within 30 calendar days. We may need to verify your identity before processing the request.

Data Controller:

Bizoforce Technologies Pvt. Ltd.
Email: clientservices@bizoforce.com
Website: https://bizoforce.com

Supervisory Authority: You have the right to lodge a complaint with your local data protection authority. In the EU, you can find your authority at edpb.europa.eu. In the UK, the relevant authority is the ICO (ico.org.uk).

International Transfers: Where we transfer personal data outside the EEA/UK, we ensure appropriate safeguards are in place (e.g., Standard Contractual Clauses or an adequacy decision).

8. Third-Party Services

The Platform integrates with the following third-party services, each governed by their own privacy policy:

Our Platform may contain links to third-party websites. We are not responsible for the privacy practices of those sites and encourage you to review their policies.

9. Children's Privacy

The Platform is not directed at children under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal information, please contact us at clientservices@bizoforce.com and we will promptly delete it.

10. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date at the top of this page. For material changes, we will provide a more prominent notice (e.g., an in-app notification or email). Your continued use of the Platform after the effective date constitutes acceptance of the updated policy.

11. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Bizoforce Technologies Pvt. Ltd.

Email: clientservices@bizoforce.com

Website: https://bizoforce.com/contact-us