Data Safety
Last updated: 30 July 2026 · Bobo Marketplace
This Data Safety statement describes how Bobo Marketplace protects the confidentiality, integrity, and availability of personal data and marketplace content. It complements our Privacy Policy and Terms of Service. We take a layered approach: secure transport, access control, payment isolation, monitoring, and clear processes when something goes wrong.
1. Security principles
We apply least privilege (people and systems get only the access required for their role), defense in depth (multiple controls rather than a single gate), and privacy by design (collect only what the product needs). Production secrets such as database URIs, payment keys, and webhook secrets are stored in environment configuration, not in public source code. Administrative surfaces (dashboard and admin) are restricted to authenticated, authorized users.
2. Encryption and transport
Public traffic to the Service is served over HTTPS so browsers negotiate TLS with modern cipher suites. Cookies and session tokens used for authentication are transmitted securely. Media files are stored with cloud object storage providers and delivered through HTTPS URLs. We encourage you to keep your own devices updated and to avoid public Wi‑Fi without a VPN when managing payments or uploads.
3. Account and authentication safety
Authentication is handled through our auth stack (including optional Google sign-in). Passwords, where used, are processed by the auth provider using industry-standard hashing—never stored as plaintext on Bobo application servers. You should enable available account protections, use unique passwords, and treat email inbox access as sensitive because password-reset flows depend on it. We may rate-limit login and checkout endpoints to reduce credential stuffing and brute-force attempts.
4. Payments and financial data
Card, UPI, and netbanking data are collected and processed by certified payment partners (such as Razorpay). Bobo receives order identifiers, payment status, and limited metadata needed to unlock Premium or Exclusive assets. We do not store full PAN, CVV, or UPI PINs. Webhook endpoints verify signatures before fulfilling orders, reducing the risk of forged payment events. Review your bank or wallet statements and contact both your provider and support@bobomarketplace.com if you see unrecognized charges.
5. Files, downloads, and entitlements
Asset downloads are gated by entitlement checks (Free with login, Premium subscription, or completed Exclusive purchase). Download events may be logged with hashed IP and user agent for abuse detection. Creators should avoid embedding secrets inside uploaded archives. We may remove malware, phishing kits, or clearly illegal content when detected. Exclusive and Premium gates exist to protect creator livelihoods; circumventing them violates our Terms and may result in account termination.
6. Application and infrastructure controls
- Input validation on forms and APIs to reduce injection risks.
- Security headers (including CSP-oriented controls) to limit cross-site scripting and clickjacking impact.
- Rate limiting on auth, search, and checkout routes.
- Crawler controls on expensive search endpoints to protect availability.
- Dependency and platform updates through our hosting provider’s managed environment.
7. Employee and vendor access
Operational access to production systems is limited to personnel who need it for support, engineering, or compliance. Processors (hosting, database, email, analytics, payments) are selected for their ability to provide commercially reasonable security. We review processor documentation as part of onboarding major services. Vendors may process data outside India; see the Privacy Policy for transfer and sharing details.
8. Monitoring, incidents, and breach notice
We monitor errors and suspicious traffic patterns to keep the Service available. If we become aware of a personal data breach that creates significant risk, we will take steps required by applicable law, which may include notifying affected users and regulators within mandated timelines, and documenting remediation. Report suspected vulnerabilities or incidents to support@bobomarketplace.com with enough detail for us to investigate (no public exploit dumps against production systems).
9. Your responsibilities
Data safety is shared. Keep credentials private, log out on shared devices, verify you are on the genuine Bobo domain before entering passwords, and be cautious of phishing emails that impersonate support. When downloading assets, scan files with up-to-date antivirus if your organization requires it. Parents and guardians should supervise minors; the Service is intended for adults.
10. Backups and continuity
Database and media storage rely on provider durability features and operational backups where configured. While we aim for high availability, outages can occur. Critical purchase records are designed so entitlements can be restored after recovery. Export or retain license receipts for your own records.
11. Updates to this statement
As architecture and processors evolve, we will update this page and the “Last updated” date. Material security practice changes may also be reflected in the Privacy Policy. Continued use of the Service after updates means you acknowledge the revised Data Safety practices.
12. Contact
Security and data safety: support@bobomarketplace.com. Website: https://assets.itsindianguy.in.
Related: Privacy Policy · Terms of Service · Data Safety · Refund Policy · Cookie Policy