- Effective date: 8 August 2026
- Last updated: 10 August 2026
- Version: 2.1
This Privacy Policy explains how "Reelty Shorts" collects, uses, shares, stores and protects personal data when you use the Reelty Shorts mobile application, our website, and related services.
Reelty Shorts is a short-video real-estate discovery platform. Sellers, builders, brokers and agents publish short videos ("reels") of properties; buyers and tenants discover, save, enquire about and book visits to those properties. Because the Platform connects two sides of a real-estate transaction, some of your information is deliberately shared with other users. Section 8 explains exactly what, and when.
Please read this Policy together with our Terms of Service. If you do not agree with this Policy, please do not use the Platform.
1. Who We Are and How to Reach Us
- Data Fiduciary / Data Controller:Veblix Innovation LLP, a company incorporated under the Companies Act, 2013, CIN [CIN], registered office at A/306, New Girnar CHSL, S.V.Road, Malad West, Mumbai 400064, Maharashtra, India.
- Grievance Officer (India — IT Rules, 2021 and DPDP Act, 2023): see Section 17.
- EU / UK representative (if appointed):"Not currently appointed".
For the purposes of India's Digital Personal Data Protection Act, 2023 ("DPDP Act"), we are the Data Fiduciary for personal data processed through the Platform, and you are a Data Principal. For the EU/UK GDPR we are the Controller, except where stated otherwise in Section 8.6.
2. Scope of This Policy
This Policy applies to:
- The Reelty Shorts mobile application for Android and iOS;
- Our public website and any web pages we operate;
- Communications we send you (SMS, push notifications, in-app messages, email);
- Our administrative and support operations relating to the above.
This Policy does not apply to third-party websites, apps or services that we link to, or to a seller's, broker's or builder's own processing of information you give them outside the Platform. Their own privacy notices govern that processing.
3. Key Definitions
- Personal data — any data about an individual who is identifiable by or in relation to such data.
- Processing — any operation on personal data, including collection, storage, use, sharing, disclosure and erasure.
- Data Principal / Data Subject / Consumer — the individual to whom personal data relates (you).
- Data Fiduciary / Controller — the entity that determines the purpose and means of processing (us).
- Data Processor — an entity that processes personal data on our behalf under contract.
- Reel — a short video listing published on the Platform.
- Lead — a record we create for a seller summarising a buyer's interest in that seller's listings.
- Contact unlock — a paid action by which a seller obtains a buyer's contact details (Section 8.2).
4. Personal Data We Collect
4.1 Information you give us
Account and profile
- Mobile phone number (this is your primary account identifier and login credential)
- One-time passcodes (OTPs) generated and validated for login
- Username, full name, profile photo / avatar
- Account type (buyer, seller, agent, builder) and seller status
- Profile biography and other free-text profile fields
We do not require an email address to create an account. If you provide one for support or billing, we process it for that purpose.
Identity and professional verification (sensitive) If you apply for a verified badge or seller verification, we collect:
- Aadhaar number and an image of your Aadhaar card
- RERA registration number (for regulated agents and promoters)
- Other supporting documents you upload, and any notes you add
This is sensitive personal data. See Section 5 for the additional protections that apply, and Section 20 for the specific limits imposed by the Aadhaar Act, 2016.
Content you publish
- Videos, poster images and thumbnails
- Captions, listing titles, calls to action, and advertiser URLs
- Structured listing attributes: price, property type and sub-type, listing type (sale/rent), bedrooms (BHK), bathrooms, carpet/built-up area, amenities, project name, developer name, project status, possession date and configuration details
- Property location, including the address text, the Google Place ID and the precise latitude and longitude of the property
- Comments you post on reels, and reports you file about other users' content
Enquiries, visits and live tours
- Visit requests, including preferred slot, visit mode (site visit or live video tour), number of visitors, preferred language, whether family are joining, and free-text notes
- Financing status and purchase timeline (financial information)
- Accessibility requirements and parking requirements — accessibility information may reveal information about a disability, and we treat it as sensitive (Section 5)
- Commute start location, where you provide it
- Post-visit feedback and outcome notes
- Audio and video streams during a live video tour, and metadata about the session
Payments and subscriptions
- Subscription plan, purchase history, lead-pack balances, contact unlocks purchased, and renewal or cancellation status
- Payment identifiers and status returned by our payment gateway (order ID, payment ID, signature, amount, currency, method type)
- Billing name and GST details, where you provide them
We do not collect or store your full card number, CVV, UPI PIN, net-banking credentials or bank account number. Card and UPI data are collected and processed directly by our PCI-DSS-compliant payment gateway (Section 8.5).
Support and correspondence
- Messages you send to support, grievance complaints, and the contents of any dispute you raise
4.2 Information collected automatically
Device and connection data
- Device model, operating system and version, app version and build number, device language and locale
- IP address, approximate location derived from IP, network type and carrier information
- Crash logs, error reports, performance traces and diagnostic data
- Server access logs, including timestamps, endpoints called and response codes
Location data
- With your permission, precise device location (Android
ACCESS_FINE_LOCATION, iOS "when in use"), used to show properties near you and to centre the map - Approximate location (
ACCESS_COARSE_LOCATION) as a lower-precision alternative - Location you enter manually, and locations you select from search suggestions
You can decline or later revoke location permission in your device settings. Location-based search and "near me" features will not work without it; the rest of the Platform will continue to function.
Usage and interaction data
- Reels viewed, watch counts, likes, saves, shares and follows
- Search queries in raw and normalised form, the structured criteria we extract from them, which search strategy was used, result counts and latency
- Which search results you clicked and at what position
- Advertisement impressions and clicks
- Feedback you give on recommendations, and upsell prompts shown to you
- Notification delivery and open events
Device permissions we request
| Permission | Why | Optional? |
|---|---|---|
| Camera | Record reels; join live video tours | Yes |
| Microphone | Record audio for reels; speak in live tours | Yes |
| Photo library / media | Upload an existing video or profile photo | Yes |
| Location (fine / coarse) | Nearby search, map centring, tagging a listing | Yes |
| Notifications | Push alerts for leads, visits, matches | Yes |
| Bluetooth / audio settings | Route call audio to headsets during live tours | Yes |
| Network state | Adapt video quality to connection | Required |
We ask for each permission in context and only when the relevant feature is used. Denying a permission disables only that feature.
4.3 Information from third parties
- Payment gateway — payment success/failure, method type and refund status
- Mapping and geocoding providers — place details, coordinates and address components for locations you select
- SMS provider — delivery receipts for OTP and transactional messages
- App stores and push services — device push tokens and delivery status
- Publicly available regulatory registers, where we verify a RERA registration number you supply
4.4 Data we derive or infer
- Lead scores and labels — we score each buyer's interest in a seller's properties and label it HOT, WARM or COLD, and we assign a pipeline stage
- Content moderation and classification outcomes — an automated decision on whether a reel is a genuine property listing and whether it complies with our content rules, with a confidence value and reason codes
- Search intent — structured criteria (location, budget, configuration, property type) extracted from your natural-language query
- Recommendations — a personalised feed ranking based on what you watch, save, like and search for
Section 7 explains your rights in relation to these automated processes.
5. Sensitive Personal Data
The following categories receive heightened protection. Under the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, these are "sensitive personal data or information"; under the GDPR some are "special category data" (Article 9).
- Aadhaar number and Aadhaar card image
- Financial information (financing status, payment records, subscription history)
- Precise geolocation
- Accessibility requirements, where these reveal or imply a disability
- Audio and video content in which you are identifiable
We process these categories only:
- with your explicit, separate and informed consent, given at the point of collection;
- for the specific purpose disclosed to you at that time;
- with access restricted to the minimum number of authorised personnel;
- with encryption in transit and at rest;
- for no longer than the retention periods in Section 12.
We do not use sensitive personal data for advertising, profiling or recommendations.
You may refuse to provide sensitive personal data. Verification is optional; declining it means you will not receive a verified badge and may have reduced visibility or reach on the Platform, but your account will otherwise continue to work.
6. Why We Process Your Data, and Our Legal Basis
Under the DPDP Act our processing is based on your consent, or on a "certain legitimate use" under Section 7 of that Act (such as processing for a purpose for which you voluntarily provided data, or to comply with law). Under the GDPR, where it applies, we rely on the bases named below.
| Purpose | Data used | DPDP basis | GDPR basis |
|---|---|---|---|
| Create and authenticate your account | Phone number, OTP, device data | Consent / voluntary provision | Contract (Art. 6(1)(b)) |
| Show, host and deliver reels and listings | Content, listing attributes, media | Consent / voluntary provision | Contract |
| Search, map and "near me" discovery | Location, search queries | Consent | Consent (Art. 6(1)(a)) |
| Personalised feed and recommendations | Usage and interaction data | Consent | Legitimate interests (Art. 6(1)(f)) |
| Generate leads and share them with sellers | Interaction signals, profile, contact details | Consent | Consent / Legitimate interests |
| Process a contact unlock | Buyer contact details, payment record | Consent | Contract / Consent |
| Book and coordinate visits and live tours | Visit request data, A/V streams | Consent / voluntary provision | Contract |
| Identity and RERA verification | Aadhaar, RERA, documents | Explicit consent | Explicit consent (Art. 9(2)(a)) / Legal obligation |
| Payments, invoicing, tax records | Payment and billing data | Legal obligation / voluntary provision | Contract / Legal obligation |
| Content moderation, safety and fraud prevention | Content, usage, device, reports | Legitimate use / legal obligation | Legal obligation / Legitimate interests |
| Transactional SMS and push notifications | Phone number, push token | Consent / voluntary provision | Contract / Consent |
| Marketing and promotional messages | Phone number, preferences | Consent | Consent |
| Analytics, debugging and service improvement | Usage, device, diagnostic data | Legitimate use | Legitimate interests |
| Responding to grievances and legal claims | All relevant data | Legal obligation | Legal obligation / Legitimate interests |
| Complying with court orders and lawful requests | All relevant data | Legal obligation | Legal obligation |
Where we rely on legitimate interests, we have carried out a balancing assessment and you may object at any time (Section 13).
We will not use your personal data for a materially different purpose without giving you fresh notice and, where required, obtaining fresh consent.
7. Automated Processing, AI and Profiling
We use automated systems, including third-party large language models, in the following ways.
7.1 AI-assisted caption and listing copy. When you ask the app to draft a caption or listing description, the listing attributes and any prompt text you supply are sent to our AI provider to generate the draft. You review and edit the output before publishing.
7.2 Natural-language search. Your search query may be sent to an AI provider to extract structured search criteria (location, budget, configuration). Queries are logged for quality measurement — see the retention schedule in Section 12.
7.3 Content moderation and classification. Uploaded reels are automatically analysed to decide whether they are genuine property listings and whether they comply with our content rules. Content may be held for manual review, restricted or removed on the basis of this analysis, and repeated violations may lead to account restriction.
7.4 Lead scoring. Buyer interactions with a seller's listings are aggregated into a score and a HOT/WARM/COLD label that is shown to that seller.
7.5 Feed ranking. Your feed is ordered using signals about what you view, save, like, follow and search for.
Your rights over automated processing. Automated moderation and account-restriction decisions can significantly affect you. Under GDPR Article 22, and as a matter of policy for all users regardless of location, you have the right to:
- be told that an automated decision was made and the main reasons for it;
- obtain human review of that decision by writing to our Grievance Officer;
- express your point of view and contest the outcome.
We do not use AI to make decisions about your creditworthiness, and we do not sell profiles or scores to third parties.
We do not permit our AI providers to use your data to train their models. We use enterprise/API endpoints that are contractually excluded from provider model training.
8. When and How We Share Your Data
8.1 Content you publish is public
Reels you publish as public, together with their captions, listing details, property location and coordinates, and your public profile (username, name, photo, bio, verification badge, follower counts), are visible to any Platform user and may be visible to anyone on the internet via our website, and may be indexed by search engines. Comments you post and your likes and follows may also be visible to others.
Do not include information in a reel, caption, comment or profile that you do not want to be public. Consider carefully before publishing a property's exact address or interior footage of an occupied home, and obtain the occupant's consent before filming them or their belongings.
Making a reel private, or deleting it, stops future distribution. It cannot recall copies already downloaded, screenshotted or cached by others or by search engines.
8.2 Sharing between buyers and sellers — please read carefully
The Platform is a lead-generation marketplace. This means:
- When you interact with a seller's listing — by viewing, liking, saving, following, searching, requesting a visit or joining a live tour — we create or update a lead record for that seller. The seller can see that a buyer showed interest, which listing, what type of interaction, when, how often, and the interest score and label we calculated.
- Your contact details are not shown to the seller by default. A seller must perform a paid contact unlock to obtain your phone number and profile contact details.
- When you request a visit or a live tour, the details necessary to arrange it are shared with that seller. This includes your name, the requested slot, visitor count, preferred language, accessibility and parking requirements, whether family are joining, your financing status and purchase timeline, and any notes you write.
- Sellers may add their own notes, tags and pipeline stages to their lead record about you.
- Sellers are independent businesses. Once a seller lawfully receives your contact details, that seller becomes a separate Data Fiduciary/Controller for their own use of them. We require sellers by contract to use your details only to respond to your property enquiry, to comply with applicable data protection and telemarketing law, and to honour opt-out requests — but we do not control their systems.
Your controls. You can withdraw consent to lead sharing, ask us to close a lead, ask a seller to stop contacting you, and register your objection with us (Section 13). Withdrawing consent will limit your ability to enquire about properties, because passing your enquiry to a seller is the essential purpose of that feature.
8.3 Live video tours
During a live tour, your audio and video are transmitted in real time to the other participants through our real-time communications provider. We use these streams to deliver the call. We do not record live tours unless recording is expressly offered in the interface and all participants are told that recording is on. Other participants may nonetheless capture the session using their own device; we cannot prevent this.
8.4 Service providers (processors)
We share personal data with vendors who process it on our behalf, under written contract, only on our instructions, and who are prohibited from using it for their own purposes.
| Provider | Function | Data shared | Location |
|---|---|---|---|
| Cloud hosting and object storage (AWS / [PROVIDER]) | Application hosting, media storage, CDN delivery | All Platform data, media files | [REGION] |
| Razorpay Software Pvt Ltd | Payment processing, subscriptions | Name, phone, amount, order and payment identifiers | India |
| OpenAI | AI captions, natural-language search, classification | Prompt text, listing attributes, search queries | USA |
| Google (Maps, Places, Geocoding) | Location search, map display, address lookup | Search text, coordinates, IP address | Global |
| Google Firebase Cloud Messaging | Push notification delivery | Device push token, message payload | Global |
| MSG91 | SMS OTP and transactional SMS | Phone number, message content | India |
| LiveKit | Real-time audio/video for live tours | A/V streams, session and participant metadata | [REGION] |
This list is accurate as at the "last updated" date and may change. We will update this Policy when it does.
8.5 Payments
Card, UPI and net-banking details are entered into, and processed by, our payment gateway. We receive only a transaction result and non-sensitive identifiers. The gateway is an independent controller for the payment instrument data it collects and applies its own privacy policy.
8.6 Legal, safety and regulatory disclosure
We may disclose personal data where we believe in good faith that it is necessary to:
- comply with a valid legal obligation, court order, subpoena or lawful government request;
- respond to a request from a government agency authorised under Rule 3(1)(j) of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, within the timelines those Rules require;
- comply with directions issued by CERT-In under Section 70B of the Information Technology Act, 2000;
- enforce our Terms, investigate suspected fraud, impersonation or platform abuse;
- protect the rights, property or safety of our users, our staff or the public, including in an emergency involving a risk of death or serious injury.
Where we are legally permitted to do so, we will notify you before disclosing your data in response to a legal request.
8.7 Business transfers
If we are involved in a merger, acquisition, financing, reorganisation or sale of assets, personal data may be transferred as part of that transaction. We will require the recipient to honour this Policy, and we will notify you before your data becomes subject to a materially different privacy policy.
8.8 What we never do
- We do not sell your personal data.
- We do not share your personal data for cross-context behavioural advertising.
- We do not disclose your identity documents or Aadhaar to other users, sellers or advertisers.
- We do not use sensitive personal data for advertising or recommendations.
- We do not knowingly process children's data for tracking or targeted advertising.
9. Advertising on the Platform
Some reels in your feed are advertisements and are labelled as such. We measure advertisement impressions and clicks so that we can report performance to advertisers.
- Advertising is currently contextual and platform-first: we may target based on the city or property category you are browsing and on your account type.
- We report aggregated, de-identified performance statistics to advertisers. We do not give advertisers your identity, phone number or profile unless you separately choose to contact that advertiser.
- We do not operate third-party ad-tech tracking pixels or cross-site advertising identifiers on the Platform. If this changes, we will update this Policy and, where required, obtain your consent first.
10. Cookies and Similar Technologies
On our website we use:
- Strictly necessary cookies — session, authentication, anti-forgery (CSRF) and load-balancing cookies. These are required for the site to work and are set on the basis of our legitimate interest in providing a secure service. They cannot be disabled.
- Preference cookies — remember choices such as language, theme and recent search filters.
- Analytics cookies and local storage — measure aggregate usage to help us improve the site. Where required by law, these are set only after you consent.
In the mobile app we use device storage and app-generated identifiers to keep you signed in, cache media for smooth playback, remember preferences and deliver push notifications. We do not use the Android Advertising ID or Apple's IDFA. On iOS we do not track you across other companies' apps and websites, and therefore do not present an App Tracking Transparency prompt.
You can clear cookies and block them through your browser settings, and clear app storage through your device settings; blocking strictly necessary cookies will prevent you from signing in.
We honour Global Privacy Control (GPC) and other recognised opt-out preference signals where our browser-based services receive them.
11. Communications and Marketing
Transactional messages. We send SMS and push notifications that are necessary to operate your account: login OTPs, visit confirmations and reminders, new-lead alerts, subscription and payment receipts, security notices, and saved-search matches you asked for. These are part of the service; you cannot opt out of security and transaction messages while your account is active, though you can turn off push notifications at the operating-system level.
Promotional messages. We send marketing messages only with your consent. You can withdraw that consent at any time from in-app notification settings, by replying STOP to a marketing SMS, or by writing to us.
Indian telecom rules. Our SMS traffic is sent through a registered sender in accordance with the Telecom Commercial Communications Customer Preference Regulations, 2018 (TCCCPR) and the applicable DLT registration framework. Registering on the national Do Not Disturb (DND) register does not stop transactional messages such as OTPs, which are necessary to log in.
Push notifications. You choose whether to allow push notifications when first prompted, and can change that at any time in your device settings. Turning them off does not disable other parts of the Platform.
12. How Long We Keep Your Data
We keep personal data only for as long as necessary for the purpose it was collected for, or for as long as the law requires. When a period ends we delete the data or irreversibly de-identify it.
| Data | Retention |
|---|---|
| Account profile | For the life of the account, then 30 days after deletion request, then erased |
| Soft-deleted account and content | 30 days (recovery window), then permanent erasure |
| Reels and media | Until you delete them, or account deletion + 30 days |
| OTP sessions | Until expiry (minutes); purged within 24 hours |
| Identity documents (Aadhaar, RERA) | 180 days after the verification decision, or the minimum period the law requires, whichever is longer — then erased. Only the verification outcome and badge status are retained |
| Payment and invoice records | 8 years, as required by the Companies Act, 2013 and the Income-tax Act, 1961 |
| Subscription and lead-unlock records | 8 years (financial record) |
| Lead records and lead activity | 24 months after the last activity on the lead, or until you withdraw consent |
| Visit requests and feedback | 24 months after the visit date |
| Search query and click logs | 90 days, then aggregated and de-identified |
| Server, security and access logs | 180 days (extended where CERT-In directions or an active investigation require it) |
| Push tokens | Until the app is uninstalled or the token becomes invalid |
| Content moderation and report records | 24 months, or longer if related to an ongoing investigation or legal claim |
| Grievance and support correspondence | 3 years from resolution |
| Live tour audio/video | Not retained; streams are transient |
Where deletion is not immediately possible for technical reasons (for example, encrypted backups), we isolate the data and delete it on the next backup rotation cycle, which does not exceed 90 days.
Legal holds. If data is relevant to an active legal claim, regulatory investigation, or a preservation order, we retain it until that matter is resolved, notwithstanding the periods above.
13. Your Rights and How to Exercise Them
13.1 Rights available to all users
Regardless of where you live, you may:
- Access — obtain a summary of the personal data we process about you, the processing activities, and the identities of the Data Fiduciaries and processors with whom it has been shared.
- Correct, complete and update — have inaccurate or incomplete data corrected. You can edit most profile and listing data directly in the app.
- Erase — have your personal data deleted where it is no longer needed for the purpose it was collected for and we are not required to retain it.
- Withdraw consent — withdraw consent at any time, as easily as you gave it. Withdrawal does not affect processing already carried out, and may mean we can no longer provide the relevant feature.
- Nominate — under Section 14 of the DPDP Act, nominate another individual to exercise your rights in the event of your death or incapacity.
- Grievance redressal — raise a complaint with us and receive a response within the timelines in Section 17.
13.2 How to exercise them
- In the app: Settings → Privacy Policy, profile editing, notification preferences, and Settings → Delete Account for account deletion.
- By email: [privacy@reelty.app] with the subject line "Data Rights Request".
- In writing: to the Grievance Officer at the address in Section 17.
Verification. We will verify your identity before acting, normally by sending an OTP to the phone number registered on the account. We will not ask you for your password or for a copy of your Aadhaar in order to process a rights request.
Timelines. We acknowledge requests within 72 hours and respond substantively within 30 days. If a request is complex we may extend by a further 30 days and will tell you why. Requests are free; we may charge a reasonable fee only for manifestly unfounded or repetitive requests, and will tell you before doing so.
If we refuse, we will tell you why and how to escalate.
13.3 Account deletion — what happens
When you delete your account from Settings → Delete Account:
1. Your account is immediately deactivated and you are signed out on all devices. 2. Your profile, reels, comments, likes, saves, follows, reports, subscriptions and contact unlocks are marked deleted and stop being served to other users. 3. After a 30-day recovery window, the data is permanently erased from our production systems, and from backups within a further 90 days. 4. Exceptions we must retain: payment and invoice records (8 years, tax law); records needed for an ongoing legal claim, regulatory requirement, fraud investigation or safety enforcement; and aggregated or de-identified statistics that can no longer identify you. 5. Content you posted that another user has already downloaded or re-shared outside the Platform cannot be recalled by us.
You can also delete individual reels, comments, saves and follows at any time without deleting your account.
13.4 Your responsibilities as a seller or agent
If you use the CRM to receive buyer leads, you become an independent Data Fiduciary/Controller for that buyer data. You must:
- use buyer contact details only to respond to that buyer's property enquiry;
- comply with the DPDP Act, TCCCPR/DLT rules and any other law applicable to you;
- honour opt-out and deletion requests from buyers promptly;
- keep buyer data secure and not sell, rent or transfer it to anyone else;
- delete buyer data when it is no longer needed for the enquiry.
Misuse of buyer data is a breach of our Terms and may result in immediate account termination and reporting to the relevant authority.
14. Children and Young People
The Platform is intended for users aged 18 and over. Real-estate transactions require legal capacity to contract, and we do not knowingly permit accounts for anyone under 18.
- We ask you to confirm you are 18 or older at registration.
- Consistent with Section 9 of the DPDP Act, we do not undertake tracking, behavioural monitoring or targeted advertising directed at children, and we do not process a child's data in a way likely to cause any detrimental effect on their well-being.
- If we learn that we hold data of a person under 18 without verifiable parental or guardian consent, we will delete the account and its data promptly.
- If you believe a child has provided us with personal data, contact our Grievance Officer and we will act within 72 hours.
The same protections apply to persons with disability who have a lawful guardian, where we are made aware of the guardianship.
Consistent with the US Children's Online Privacy Protection Act (COPPA), we do not knowingly collect personal information from children under 13.
15. International Data Transfers
We are based in India and our primary infrastructure is located in [REGION]. Some of our service providers process data outside India — in particular our AI provider (USA) and global mapping and push-notification services.
- India (DPDP Act, Section 16): we may transfer personal data outside India except to countries the Central Government restricts by notification. We monitor that list and will stop transfers to any restricted territory.
- Sector rules: where sectoral regulations require data to be stored in India — including RBI's requirements for payment system data — that data is stored in India by the relevant provider.
- EEA and UK (GDPR Chapter V): where we transfer personal data from the EEA or UK to a country without an adequacy decision, we rely on the European Commission's Standard Contractual Clauses, and the UK International Data Transfer Addendum, together with a transfer impact assessment and supplementary technical measures (encryption in transit and at rest, access controls, and a policy of challenging unlawful government access requests).
You may request a copy of the safeguards we rely on by writing to us.
16. Security
We implement reasonable security safeguards appropriate to the risk, aligned with the ISO/IEC 27001 standard referenced in Rule 8 of the SPDI Rules, 2011, and with Section 8(5) of the DPDP Act.
Technical measures
- TLS encryption for all data in transit; encryption at rest for stored media and databases
- Passwordless OTP authentication with short-lived, single-use codes and expiry
- Signed, expiring access tokens; token invalidation on logout and account deletion
- Role-based access control and least privilege for administrative staff, with permission-scoped admin roles
- Server-side secrets management; API credentials are never exposed to client applications
- Rate limiting, request throttling and abuse detection
- Network segregation, hardened infrastructure and patch management
- Logging and monitoring of administrative access to personal data
Organisational measures
- Confidentiality obligations for all staff and contractors
- Access to identity documents restricted to trained verification personnel
- Written data-processing agreements with every processor
- Periodic review of access rights, vendor security posture and this Policy
- Incident response plan with defined roles and escalation
No system is perfectly secure. You are responsible for keeping your device and your phone number secure, and for not sharing OTPs with anyone. We will never ask you for an OTP.
Personal data breaches. If a breach occurs, we will:
- notify the Data Protection Board of India and each affected Data Principal without delay, in the form and manner prescribed under the DPDP Act;
- report to CERT-In within 6 hours of becoming aware, where the incident falls within the reportable categories of the CERT-In Directions of 28 April 2022;
- notify the competent supervisory authority within 72 hours and affected individuals without undue delay where the GDPR applies and the criteria in Articles 33–34 are met;
- notify affected residents of US states in accordance with applicable state breach-notification law.
Our notice will describe the nature of the breach, the likely consequences, the measures taken, and what you should do.
17. Grievance Redressal
Grievance Email: - support@reeltyshorts.com Hours: Monday to Friday, 10:00–18:00 IST, excluding public holidays
Our commitments
- Acknowledge every complaint within 24 hours
- Resolve ordinary complaints within 15 days
- Act on reports of non-consensual intimate imagery or impersonation within 24 hours
- Act on a valid court order or government takedown direction within 36 hours
- Respond to data-rights requests within 30 days (Section 13.2)
Escalation
- India: if you are not satisfied with our response, or we do not respond in time, you may complain to the Data Protection Board of India under Section 13(3) of the DPDP Act. You must ordinarily exhaust our internal grievance process first.
- EEA/UK: you may lodge a complaint with your local supervisory authority or, in the UK, the Information Commissioner's Office (ico.org.uk).
- California: you may contact the California Privacy Protection Agency or the Office of the Attorney General.
18. Region-Specific Disclosures
18.1 India — Digital Personal Data Protection Act, 2023
This Policy, together with the notices shown in the app at the point of collection, constitutes the itemised notice required by Section 5 of the DPDP Act. It tells you the personal data to be processed, the purpose, how to exercise your rights, how to complain to us, and how to complain to the Data Protection Board.
- Consent is free, specific, informed, unconditional and unambiguous, given by clear affirmative action, and is limited to the data necessary for the specified purpose.
- You may withdraw consent at any time; we will stop processing within a reasonable time unless another lawful ground applies.
- We do not currently use a registered Consent Manager. If we appoint one, we will name it here.
- You have the rights of access, correction, completion, updating, erasure, grievance redressal and nomination set out in Sections 11–14 of the Act.
- Your duties (Section 15): you must not impersonate anyone, suppress material information, register a false or frivolous grievance, or furnish false particulars. The Act provides for penalties for breach of these duties.
- We also comply with the Information Technology Act, 2000 and the SPDI Rules, 2011 to the extent they continue to apply.
Intermediary status. We are an intermediary under Section 2(1)(w) of the IT Act, 2000 and comply with the IT Rules, 2021, including publishing our rules, privacy policy and user agreement, appointing a Grievance Officer, and acting on prohibited content under Rule 3(1)(b).
Real estate. Listings for projects that require registration under the Real Estate (Regulation and Development) Act, 2016 (RERA) must display a valid registration number. We collect and verify RERA numbers from agents and promoters and may share them with the relevant State Real Estate Regulatory Authority on lawful request. We are a listing platform, not a broker, promoter or party to any transaction between users.
18.2 European Economic Area and United Kingdom — GDPR / UK GDPR
If you are in the EEA or UK, you additionally have the right to:
- restrict processing in the circumstances in Article 18;
- object to processing based on legitimate interests, and to object to direct marketing at any time (Article 21);
- data portability — receive the data you provided in a structured, commonly used, machine-readable format and have it transmitted to another controller (Article 20);
- not be subject to solely automated decisions with legal or similarly significant effects (Article 22 — see Section 7);
- lodge a complaint with a supervisory authority;
- withdraw consent at any time.
Our legal bases are in the table at Section 6. Retention periods are in Section 12. Transfer safeguards are in Section 15.
18.3 California — CCPA / CPRA
Categories of personal information collected in the last 12 months (as classified by the CCPA): identifiers; customer records information; commercial information; internet or network activity; geolocation data; audio, visual and similar information; professional information; and inferences. Sensitive personal information collected: government identifiers (Aadhaar), precise geolocation, and financial information.
Sources, purposes and disclosures are described in Sections 4, 6 and 8.
We do not sell personal information, and we do not share it for cross-context behavioural advertising. We have not done so in the preceding 12 months, including with respect to minors under 16.
Your rights: to know, access, delete, correct, opt out of sale/sharing (not applicable), limit the use of sensitive personal information, and to be free from discrimination for exercising your rights. You may use an authorised agent. Exercise these rights via the contacts in Section 13.2. We honour Global Privacy Control signals.
Limiting sensitive personal information. We use sensitive personal information only for the purposes permitted by CCPA § 7027(m) — performing the service, security, and legal compliance — and not for inferring characteristics. No separate "limit" right is therefore triggered, but you may still ask us to delete it.
18.4 Other United States states
If you are a resident of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana or another state with a comprehensive privacy law, you have rights to access, correct, delete, obtain a portable copy, and opt out of targeted advertising, sale and certain profiling. We do not conduct targeted advertising or sales as those terms are defined. You may appeal a refusal of a request by replying to our decision; we will respond to appeals within 45 days.
18.5 Other jurisdictions
Where the law of your country grants you rights beyond those described here — including Brazil (LGPD), Canada (PIPEDA), Singapore (PDPA), UAE, Saudi Arabia (PDPL) and Australia (Privacy Act) — we will honour those rights on request. Contact us at [privacy@reelty.app].
19. Third-Party Links and Services
Reels may include advertiser URLs and sellers may link to their own websites. Our website and app may link to app stores, maps and payment pages. We do not control those destinations and are not responsible for their content or privacy practices. Review their privacy policies before providing personal data.
20. Specific Notice on Aadhaar
Where you choose to submit Aadhaar details for verification:
- Submission is voluntary. If you would rather not submit Aadhaar through the in-app verification form, contact our Grievance Officer and we will process your verification using your RERA registration number or another accepted document instead.
- We use Aadhaar details only to verify your identity for a verified badge or seller verification.
- We do not use Aadhaar as an account identifier, and we do not disclose your Aadhaar number to other users, sellers or advertisers.
- We do not publish or display your Aadhaar number anywhere on the Platform.
- Consistent with Section 29 of the Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act, 2016 and UIDAI guidance, we store the minimum necessary, mask the number in all interfaces and logs, encrypt it at rest, restrict access to authorised verification personnel, and erase it in accordance with Section 12.
- We do not perform Aadhaar authentication or e-KYC through UIDAI unless we become an authorised entity and tell you so.
If you would prefer not to submit Aadhaar at all, write to our Grievance Officer and we will process your verification through an alternative document.
21. Changes to This Policy
We may update this Policy to reflect changes in the Platform, our vendors or the law.
- We will post the updated Policy on our website and in the app with a new "last updated" date and version number.
- For material changes — such as a new purpose, a new category of sensitive data, a new category of recipient, or a change that reduces your rights — we will give you at least 14 days' prior notice by in-app notice, push notification or SMS, and where the law requires it, we will obtain your fresh consent before the change takes effect.
- Previous versions are available on request.
Continuing to use the Platform after a change takes effect means you accept the updated Policy, except where the change requires your consent, in which case we will ask for it separately.
22. Contact Us
- General support: - support@reeltyshorts.com
- Post: Veblix Innovation LLP, A/306, New Girnar CHSL, S.V.Road, Malad West, Mumbai 400064, Maharashtra, India.
We are committed to resolving your concerns directly. Please contact us before escalating to a regulator, so that we have the opportunity to put things right.
This Policy is published in English. If we provide a translation and there is a conflict, the English version governs, except where local law requires otherwise.