Brand Ambassador Network (BAN)
Website: banindia.com
Operated by: Gajputri Technologies Private Limited
Last Updated: 18 September 2026
1. Introduction
Brand Ambassador Network (“BAN”, “we”, “us”, or “our”) is an online platform operated by Gajputri Technologies Private Limited through banindia.com.
BAN enables registered users to participate in promotional campaigns as Brand Ambassadors, refer other users, submit participation evidence, receive eligible remuneration, maintain a platform wallet, request withdrawals, create and fund advertising campaigns, book advertisements, and use other services made available through the Platform.
This Privacy Policy explains what personal data we collect, why we collect it, how it is used, stored, protected and shared, and the choices and rights available to users.
By using BAN, you acknowledge the practices described in this Privacy Policy. Where consent is the applicable basis for processing, we will seek consent in the manner required by applicable law.
2. Information We Collect
Depending on how you use BAN, we may collect the following information.
Account and Identity Information
This may include your:
- name;
- username;
- email address;
- verified mobile number;
- account identifiers;
- login and authentication information; and
- information necessary to create, maintain and secure your account.
Passwords are handled through the WordPress authentication system and should not be stored by BAN in readable plain-text form.
Profile and Location Information
To determine campaign eligibility and provide location-based services, we may collect information such as:
- address;
- State;
- City;
- Area;
- PIN code; and
- other profile information voluntarily or necessarily provided by you.
BAN may use this information to determine whether a campaign or advertisement is relevant or available for your selected geographic area.
We do not intend to collect precise real-time GPS location merely for ordinary campaign targeting unless a specific feature clearly requests it and an appropriate lawful basis exists.
Mobile Number and OTP Verification
BAN may use your mobile number for:
- registration verification;
- OTP authentication;
- verification of changes to your registered mobile number;
- account security;
- important transactional communications; and
- other services for which the number is reasonably required.
OTP delivery or verification may be performed using third-party SMS/OTP service providers.
Referral Information
If you participate in BAN’s referral programme, we may process:
- your referral code;
- referral relationships;
- referred-user identifiers;
- referral activity;
- qualifying or active referral counts; and
- remuneration-related referral records.
This information is used to operate and verify the referral and remuneration system.
3. Campaign Participation and Trace Information
When you participate in a campaign, BAN may create and process records including:
- Campaign ID;
- Participation ID;
- user/account ID;
- participation date and time;
- applicable remuneration information;
- generated campaign media;
- unique Trace ID;
- campaign and participation status; and
- related technical records.
Generated campaign media may contain a visible BAN Trace ID. This identifier is used to associate submitted promotional material with the relevant campaign, participation and account and to help prevent misuse, duplication or fraudulent claims.
4. Evidence Uploaded by Users
When campaign evidence is required, you may upload screenshots, images or other permitted evidence.
We may process:
- the uploaded evidence;
- Trace ID contained in the evidence;
- file characteristics and technical metadata;
- file hash or similar duplicate-detection information;
- evidence submission time;
- campaign and participation identifiers;
- required view or performance information; and
- approval, rejection and review records.
Evidence may be automatically checked and may also be reviewed by the relevant advertiser and/or authorised BAN administrators in accordance with the Platform’s campaign verification process.
Users should avoid uploading unrelated personal information or information belonging to another person unless necessary and lawfully permitted.
5. Wallet and Transaction Information
BAN maintains records necessary to operate its internal wallet and financial ledger, which may include:
- available and frozen wallet balances;
- credits and debits;
- campaign funding transactions;
- remuneration;
- refunds;
- wallet refill records;
- withdrawal requests;
- transaction IDs;
- payment status; and
- reconciliation and accounting records.
Wallet records may be retained where necessary for accounting, dispute resolution, fraud prevention, taxation, audit and other legal obligations.
6. Payments
Payments may be processed using WooCommerce and payment gateways enabled by us from time to time.
BAN is designed so that supported payment gateways can be added or changed without this Privacy Policy being limited to one particular payment provider.
Depending upon the gateway selected, the payment provider may process information necessary to complete the transaction, including payment identifiers and transaction details.
BAN generally receives information such as:
- WooCommerce Order ID;
- payment gateway/provider;
- transaction/payment reference;
- payment status;
- amount;
- date/time; and
- other information necessary to verify and reconcile the transaction.
Sensitive card, banking, UPI or authentication credentials entered directly into a payment gateway are subject to that payment provider’s own privacy and security practices. BAN does not need to store complete card credentials merely to credit a successfully verified wallet refill.
7. Withdrawal Information
Where withdrawals are supported, BAN may collect and process your UPI ID and related withdrawal information.
This may include:
- UPI ID;
- withdrawal amount;
- Withdrawal Request ID;
- payment status;
- payment reference/UTR; and
- transaction history.
A snapshot of the relevant payment information may be retained with the withdrawal record for reconciliation, audit and dispute handling.
8. Advertisers and Advertising Information
Users who advertise through BAN may provide information including:
- campaign details;
- advertisement content;
- uploaded media;
- campaign budget;
- campaign dates;
- geographic targeting;
- advertisement placements;
- payment information;
- campaign limits and remuneration settings; and
- campaign performance and review information.
Advertisements and promotional content intended for public display will, by their nature, be visible to relevant users or visitors.
9. How We Use Personal Data
We may process personal data as reasonably necessary to:
- create and maintain user accounts;
- verify mobile numbers;
- authenticate and secure accounts;
- maintain user profiles;
- determine campaign and advertisement eligibility;
- generate traceable campaign media;
- manage campaign participation;
- verify submitted evidence;
- detect duplicate, fraudulent or unauthorised claims;
- calculate remuneration and referral benefits;
- operate wallets and withdrawals;
- process and reconcile payments;
- manage advertising campaigns;
- issue transactional communications and notifications;
- provide customer support;
- maintain accounting, audit and transaction records;
- investigate abuse or security incidents;
- improve reliability and functionality of BAN;
- enforce applicable Platform terms; and
- comply with applicable legal obligations.
We seek to limit collection and processing to data reasonably required for the specified purposes.
10. Consent and Lawful Processing
Where processing is based on consent, BAN will seek consent for a specified purpose and users may withdraw that consent through the available mechanism, subject to processing that remains necessary or permitted under applicable law.
The DPDP Act provides, among other things, that consent should be free, specific, informed, unconditional and unambiguous and given through clear affirmative action; it also provides for withdrawal of consent. MeitY
Certain information may nevertheless need to be retained or processed after account closure or withdrawal of consent where required or authorised for purposes such as legal compliance, completed transactions, accounting, fraud prevention, dispute resolution or establishment/exercise of legal claims.
11. Sharing of Personal Data
We do not sell users’ personal data as a business model.
We may disclose or make data available only as reasonably necessary to categories such as:
Service providers: hosting providers, SMS/OTP providers, email providers, cloud or infrastructure providers, security providers and other processors supporting operation of BAN.
Payment providers: WooCommerce payment gateways and related payment service providers selected for a transaction.
Advertisers: information necessary to administer or review participation in their campaigns. Advertisers should not receive unrelated personal data merely because a user participated in a campaign.
Professional advisers: auditors, accountants, legal advisers and other professionals where reasonably necessary.
Government or regulatory authorities: where disclosure is required under applicable law, lawful order or legal process.
Corporate transactions: data may be transferred as part of a lawful merger, acquisition, restructuring, financing or transfer of the business, subject to applicable legal requirements.
12. Cookies and Similar Technologies
BAN, WordPress, WooCommerce and integrated service providers may use cookies or similar technologies for purposes such as:
- login sessions;
- authentication;
- security;
- OTP/payment flow continuity;
- user preferences;
- shopping/payment sessions;
- fraud prevention;
- analytics where enabled; and
- essential website functionality.
Essential cookies may be required for certain Platform features to function correctly.
Where consent is legally required for non-essential cookies or tracking technologies, appropriate choices should be provided.
13. Security
We use reasonable administrative, technical and organisational measures intended to protect personal data against unauthorised access, disclosure, alteration, loss or misuse.
These may include, where appropriate:
- access controls;
- authentication;
- OTP verification;
- encryption or protected storage of sensitive profile information;
- transaction verification;
- audit records;
- duplicate-transaction safeguards;
- controlled administrative access; and
- security monitoring.
No Internet-based system can guarantee absolute security. Users are also responsible for protecting their passwords, OTPs and account access.
14. Data Retention
We retain personal data only for as long as reasonably necessary for the purpose for which it was collected or for a period required or permitted under applicable law.
Different categories may have different retention periods. Transaction, wallet, payment, withdrawal, campaign, tax, accounting, fraud-prevention and dispute records may need to be retained after an account becomes inactive or is closed.
When personal data is no longer required and no lawful reason for continued retention applies, we will take appropriate steps to delete, anonymise or otherwise dispose of it in accordance with applicable requirements.
The DPDP Rules, 2025 also prescribe requirements concerning notices and other aspects of personal-data processing, with phased commencement dates.
15. Children’s Data
BAN is not intended to knowingly permit children to independently enter into activities, financial arrangements or other services for which they are not legally eligible.
Where processing of a child’s personal data is undertaken and applicable law requires verifiable consent of a parent or lawful guardian, BAN will follow the applicable legal requirements.
Users should not provide false age or identity information to circumvent eligibility requirements.
16. Your Privacy Rights
Subject to applicable law and the commencement/application of relevant statutory provisions, you may have rights concerning your personal data, including rights relating to:
- obtaining information about processing;
- accessing information associated with your account;
- correction of inaccurate or incomplete personal data;
- updating personal data;
- erasure where legally applicable;
- withdrawing consent where processing is based on consent;
- grievance redressal; and
- nomination or other rights provided under applicable data-protection law.
Some requests may be subject to identity verification and lawful retention requirements.
The DPDP framework expressly provides a statutory scheme concerning Data Principal rights, although its substantive provisions are subject to the Government’s phased commencement notification.
17. Account Closure and Deletion Requests
A user may request account closure or deletion of eligible personal data through the contact mechanism provided below or through an account facility where available.
Closing an account does not necessarily require immediate deletion of every record. We may retain information that must reasonably or legally be maintained for completed transactions, wallet accounting, withdrawals, campaign settlements, taxation, fraud prevention, disputes, enforcement or legal obligations.
18. Data Breach and Security Incidents
If a personal-data breach occurs, BAN will investigate and take reasonable containment and remedial measures.
Where applicable law requires notification to affected individuals, the Data Protection Board of India or another competent authority, such notification will be undertaken in accordance with the applicable requirements in force at that time.
The DPDP Rules, 2025 contain specific breach-notification and security-related requirements, subject to their prescribed commencement schedule. MeitY
19. Third-Party Websites and Services
BAN may contain links to third-party websites, social-media services, payment providers or other external services.
When you leave BAN or independently interact with a third-party service, that third party’s privacy policy and terms may apply. BAN is not responsible for independent processing carried out by third parties outside our control.
20. International Processing
Some service providers may process or store information using infrastructure located outside India.
Where personal data is transferred or processed outside India, we will endeavour to do so subject to applicable Indian law and any restrictions, requirements or directions issued by the Government of India.
21. Changes to this Privacy Policy
We may update this Privacy Policy when our services, technology, business practices or applicable legal requirements change.
The updated policy will be published on banindia.com with a revised “Last Updated” date. Where a change requires additional notice or consent under applicable law, we will take appropriate steps.
22. Grievance and Privacy Contact
For any questions, requests for correction or erasure, privacy concerns, complaints, or grievances regarding the processing of personal data, please contact:
Gajputri Technologies Private Limited
Brand Ambassador Network (BAN)
Website: banindia.com
Registered Office:
Naya Bas, Pali Bazar, Mahamandir,
Jodhpur – 342001, Rajasthan, India
Grievance Email: CC@banindia.com
Grievance Officer / Authorised Contact: Virender Jain
We will endeavour to acknowledge and address legitimate privacy grievances in accordance with applicable Indian law.
23. Governing Law
This Privacy Policy and processing of personal data by BAN are governed by applicable laws of India, including the Digital Personal Data Protection Act, 2023, provisions brought into force thereunder, the Digital Personal Data Protection Rules, 2025 as and when applicable according to their commencement schedule, the Information Technology Act, 2000, and other applicable laws and regulations.