Privacy Policy
How Flipns uses account, listing, location and payment information, your optional analytics choices, and the privacy rights that apply in your country.
Last updated
1. Who we are
Flipns is a peer-to-peer classifieds marketplace operated by Yuktiv Private Limited (“Flipns”, “we”, “us”). Its registered address is Jind, Haryana India 126114.
For the purposes of the Digital Personal Data Protection Act, 2023 (the “DPDP Act”), Flipns is the Data Fiduciary for the personal data described here, and you are the Data Principal. Where EU or UK GDPR applies, the operator is the controller for this processing. Questions about this policy may be sent to contact@flipns.com or the dedicated privacy contact, once confirmed: contact@flipns.com.
2. What this policy covers
This policy applies to the Flipns website at flipns.com, the Flipns iOS app, the Flipns Android app, and every backend service behind them. It does not cover what a buyer or seller does with information you choose to share with them directly, and it does not cover third-party sites or apps you reach from a link on Flipns.
3. Personal data we collect
3.1 Account and identity
- Phone number. Phone sign-in is one route into Flipns; SMS OTP is currently supported only in India. We store the number in international (E.164) form and a flag recording whether it has been verified by one-time password.
- Email address and its verification status, when you sign up or sign in by email.
- Apple account identifier, if you use Sign in with Apple. We receive the identifier and, where you allow it, your name and relay email address.
- Password, if you set one. It is stored only as a salted hash by our authentication layer; nobody at Flipns can read it.
- Profile details you choose to add — display name, @username, profile photo, bio and city.
- Referral data — your own shareable invite code (created only when you first open the invite screen) and, if you joined through someone’s link, a single record of who invited you.
Passkeys use a public-key credential associated with your account; the private key stays with your authenticator. Existing email, phone/password and username/password or passkey sign-in options remain subject to their availability. Social sign-in processes provider identifiers only when that option is enabled and you choose it.
3.2 Identity verification (optional)
If you request a verified badge, you upload evidence — a government ID, an address proof or a selfie. These files go into a private storage bucket that is never served from a public URL: our reviewers open them through short-lived signed links that expire in fifteen minutes. We record the outcome of the review and, if it is rejected, the reason. You are never required to verify in order to use Flipns.
3.3 Listings and the content you publish
- Title, description, price, condition, category and attributes of each listing.
- Photos and videos you upload, stored in Cloudflare R2 and served over our CDN. Anything attached to a published listing is public.
- Comments, likes, saves, ratings and reviews you leave, and the badges you earn.
3.4 Country and location
We use network-derived country information, including IP geolocation at our edge provider, and account information to select your marketplace, currency and available features. IP location can be inaccurate, especially with VPNs or mobile networks. Contact support if your country is wrong. Country detection does not require precise device location permission and does not give us your GPS position.
When you choose “Use my current location”, we ask your browser or operating system for location permission to find a nearby city or area within your account country. The website sends that one-time coordinate to our place resolver and saves the resulting city choice, not that browsing coordinate. You may decline and search for a city instead. You can revoke device permission in browser or operating-system settings. We do not request continuous background location for this feature.
A listing location is different: when you pick a pin or use location while creating a listing, we store the selected coordinates and location information for that listing. Public pins are approximate by default, using a stable secret-derived offset; a place-only listing receives an estimated point within its area. An approximate pin is not the seller’s doorstep and is not a guarantee of anonymity. Exact location may be shown only when the seller enables the relevant sharing option. Addresses or identifying details you put into public content may reveal your location independently of the pin.
Map and geocoding providers receive the information needed to display a map or resolve a place when you use those features. Your device permission is separate from the analytics preference. Changing either choice does not change your sign-in method.
3.5 Messages
- The text of buyer↔seller conversations, the offers made and their status, images sent in chat (stored privately, delivered through expiring signed links), and read receipts.
- Timing data used to compute a seller’s typical response time.
- If you enable WhatsApp or SMS forwarding, the message body is sent to the relevant provider so it can be delivered to your number, and your replies are ingested back into the Flipns thread.
3.6 Devices and notifications
We store push tokens (APNs on iOS, FCM on Android, Web Push in the browser) along with the platform, app locale and whether the token is a sandbox or production token, so that we can deliver notifications you have asked for. We also record a last-active timestamp, which you can hide from other users in Settings.
3.7 Payments
The only thing Flipns sells is credits. For each purchase we store the amount, the credits delivered, the pack, the status, and the provider’s order and payment identifiers — plus, for iOS, Apple’s transaction identifiers and an opaque account token.
3.8 Safety, support and audit
- Support tickets you open, including the category, subject, messages and app version.
- Abuse reports you file or that are filed against you, the reason selected, and any moderation action taken.
- An append-only privacy log recording when you changed privacy settings, blocked or unblocked someone, exported your data, or deleted your account.
- A redacted administrative audit trail of privileged staff actions, kept so that moderation decisions remain accountable.
Public API, MCP and backend activity
Our public APIs, MCP server and backend record service activity independently of browser and app analytics preferences. API request logs include the route template, HTTP method, response status, processing time, detected country and release version. MCP telemetry records protocol/client information, tool discovery and tool-call outcomes. Network-derived client keys support abuse controls and rate limiting. These signals help measure traffic sources, diagnose failures and investigate suspicious activity; client-provided source information is not proof of a person's identity.
Security, fraud-prevention, payment reconciliation and audit records continue when optional device analytics are switched off. We use information necessary for those purposes, restrict staff access and assess its legal basis separately. Browser/app activity, referral attribution and masked session recordings are product analytics; their legal basis and any consent requirements are assessed separately from necessary security processing.
3.9 Diagnostics and analytics
Flipns uses PostHog, a product-analytics platform we run in the European Union, to understand how the product is used and to find and fix faults. Device activity analytics are enabled by default. You can turn optional device analytics off using the control in section 13 without signing in, or in Settings. You can change your choice at any time — on this website in Settings → Data & analytics → Share usage analytics, and in the iOS and Android apps in Settings → Privacy → Share usage analytics.
Our servers record a product event whenever something actually happens in the database: an account is created or deleted; a listing is published, sold, expired, archived, taken down or restored; a conversation is started and its first message sent; an offer is made, accepted, declined or withdrawn; a rating is left or hidden; identity verification is submitted, approved or rejected; a report is filed or resolved; an account is banned or unbanned; an invite code is redeemed; a search runs; each stage of a credit purchase; and each use of the AI listing assistant. These carry your account identifier and the shape of the action — category, price, quantity, status, counts. They never carry the text of your messages, the words in your listing, your search terms, or a moderator’s written reason: where we would otherwise need free text we record its shape instead — that a reason was given and how long it was, rather than what it said. When you arrive from an external link we also record a referral-landing event: the referring site or AI assistant (for example ChatGPT or Perplexity), the campaign tag on the link and the page you landed on — never the full address of the page you came from.
Unless you turn off device analytics, the apps and this website additionally record:
- Interactions — the screens and pages you open, and the taps, clicks, scrolls and form submissions you make. We record that a field was filled in, never what you typed into it.
- Session recordings — a reconstruction of what the screen looked like while you used it, so we can see where the product confuses people. Everything you type is replaced with a blank placeholder on your device, before anything is uploaded — every field, on every screen, with no exceptions. So are all images and media, your chat messages, the description you write on a listing, your verification documents, your camera and your microphone. What remains readable is the product’s own text: the buttons, the labels and the error messages we wrote, so that a recording can show us which screen confused someone. It can show what the product said to you; it cannot show what you said to it. Recording never starts before you sign in, and on this website it is switched off entirely on the password-reset page and the staff console.
- Heatmaps — aggregate maps of where people tap and click on a page of this website.
- Error and performance diagnostics — crashes, unhandled errors, and how long screens take to load.
- Feature-flag and experiment assignment — which variant of a changed feature you were shown, so we can tell whether the change helped.
- Surveys — a short in-app question, and your answer only if you choose to give one.
For the AI listing assistant we record technical metadata about each model call: which model answered, which provider served it, how long it took, how many tokens it used, what it cost, and whether it failed.
Temporary analytics logging of AI listing-assistant prompts and answers ended on 5 September 2026. Technical model-call metadata continues to be recorded. Previously collected transcripts remain subject to the retention and deletion process below. The assistant still sends the content needed to answer your request to its model provider; that service processing is separate from analytics. The earlier device analytics setting did not control server-side transcript logging.
All of this is processed in the European Union and is linked to your Flipns account identifier, not to any advertising identifier. We do not read your device’s advertising ID, we do not run advertising trackers, we do not build advertising profiles, and we never sell or share this data with an advertising network or a data broker.
Switching the setting off stops optional analytics collected by the app or browser on that device. It does not stop the server-recorded product events described above: those are records of what happened in your account, and they follow the account rather than the device. You may contact support to object to account-level analytics or request deletion; we will assess the request under the law that applies to you. Necessary payment, security and legal records may still need to be retained. See section 9.
4. Why we process it
- To run the marketplace — create your account, publish listings, show results near you, deliver messages and offers, and let buyers and sellers rate each other.
- To keep it safe — verify phone numbers, detect fraud and spam, action reports, enforce the Community Guidelines, and stop banned users returning.
- To take payment for credits and maintain an accurate, auditable ledger of what was bought and spent.
- To send you notifications you have opted into, and service messages you cannot opt out of (security alerts, payment receipts, policy changes).
- To improve the product and fix faults — the analytics and diagnostics set out in section 3.9. Some of that is linked to your account rather than aggregated, which is why section 3.9 describes it in full and why it has its own switch.
- To meet legal obligations — tax and accounting records, and valid requests from competent authorities under applicable law.
We process information needed to provide the services you request, protect accounts and prevent fraud, and meet applicable legal obligations. The legal basis depends on the purpose and jurisdiction. Under EU/UK GDPR, this may include performing our contract with you, legal obligations, or legitimate interests for proportionate security and account-level service analysis, subject to your right to object. Where applicable law requires prior consent for analytics cookies, device access or session recording, that requirement takes priority. A default-on setting, accepting Terms or creating an account is not evidence of that consent. Security and fraud-prevention purposes do not automatically exempt general product analytics from consent requirements.
Where India’s DPDP framework applies and the relevant provisions have commenced, we rely on consent or an applicable permitted use. Optional device location uses the permission you give for that purpose. Change the device analytics preference in Settings and device location permission in your browser or operating system. Withdrawal does not undo processing already lawfully carried out. A consent or interests assessment for one purpose does not automatically authorise another purpose.
5. AI features and what they see
Three parts of Flipns send content to a third-party model provider:
- Listing assist — when you ask Flipns to draft a listing, the photos and any text you supplied are sent to the model so it can propose a title, description, category and price.
- Pre-publish contact scan — before a listing goes live, its title, description and images are inspected for phone numbers, WhatsApp links, email addresses, social handles and QR codes. This is why direct contact details are rejected at publish time.
- Semantic search — published listing text is turned into a numeric embedding so that searches match meaning rather than exact words.
The pre-publish contact scan and the semantic-search embeddings go to OpenAI. Listing assistance is different: to stay available and affordable it is routed across a rotating pool of model providers — OpenAI, DeepSeek, Groq, Google and OpenRouter (which itself forwards to a further model host such as NVIDIA, Tencent, Google or Poolside) — and which one answers a given request depends on availability at that moment, so we cannot tell you in advance. All of them are listed in section 6. Private chat messages are not sent to a model for any of these features. Do not include anything in a listing that you would not want processed by a third-party provider.
6. Who we share it with
We do not sell your personal data, and we do not share it for third-party advertising. The services below are used for the stated purposes. Some providers, including payment providers, may also process data for their own fraud-prevention, regulatory or account purposes under their own notices:
| Processor | What it handles | Where |
|---|---|---|
| Convex | Application database and backend functions — accounts, listings, chat, offers, reports, ledgers. | United States |
| Cloudflare | Object storage (R2) for listing photos, avatars, chat images and verification documents; CDN delivery; hosting for flipns.com. | Global edge network |
| Razorpay | Card, UPI, net-banking and wallet payments for credit purchases on the website where available. Razorpay collects your payment instrument directly; Flipns never sees it. | India |
| Apple | In-app purchases of credits on iOS, Sign in with Apple, and push delivery through APNs. | United States |
| Map rendering and place/geocoding services (Google Maps), Google Play credit purchases and push delivery to Android devices (FCM). | United States | |
| OpenAI | The pre-publish contact-details scan over your listing text and images, the embeddings that power semantic search, and one of the models in the listing-assistant rotation below. | United States |
| DeepSeek | Listing assistance — one of the models the request may be routed to (see section 5). | China |
| Groq | Listing assistance — one of the models the request may be routed to (see section 5). | United States |
| Google (AI Studio / Gemini API) | Listing assistance — one of the models the request may be routed to (see section 5). | United States |
| OpenRouter | Listing assistance — a routing layer that forwards the request to a further model host (NVIDIA, Tencent, Google or Poolside) when one of the models above is unavailable. | United States, and the model host's own region |
| MSG91 | Delivery of login OTPs by SMS, and SMS message-forwarding if you turn it on. | India |
| Zoho ZeptoMail | Transactional email — email verification codes and password resets. | India |
| Meta (WhatsApp Business Cloud API) | Forwarding buyer messages to your WhatsApp and ingesting your replies — only if you enable WhatsApp forwarding. | Ireland / United States |
| PostHog | Product analytics and diagnostics, described in full in section 3.9: your display name and email address, so that an account is recognisable to us as a person rather than an identifier — never your phone number; server-recorded product events (account created, listing published or sold, offers, ratings, verification, reports, bans, credit purchases, invite redemptions, referral landings); the screens and pages you open and the taps, clicks and form submissions you make; session recordings in which everything you type is masked; heatmaps; crash, error and performance diagnostics; which variant of a changed feature you were shown; your answers to in-app surveys; and technical metadata about AI assistant calls. Assistant transcript analytics ended on 5 September 2026. Device analytics are enabled by default with a device opt-out; API/MCP and account-level server records are separate — see section 3.9. | European Union |
We also disclose data where we are legally required to — to a court, a law-enforcement agency or a regulator acting under valid authority — and where it is necessary to investigate fraud or protect someone’s safety. If Flipns is ever acquired or merged, your data may transfer to the acquiring entity under the same commitments; we will tell you before that happens.
7. What other people can see
Public listing and public seller pages can be read worldwide and indexed by search engines and AI retrieval services. Country restrictions on participation do not make public pages private. Copies held by third parties may remain after removal from Flipns; contact us for help with an applicable removal request.
Publicly visible by default:
- Your display name, @username, profile photo, bio, member-since date, verification badges, ratings and reviews.
- Your active listings, their photos, and their coarsened map pin.
Private by default, with disclosure only as described below:
- Your account phone number and email address, except information you expressly authorise a contact feature to disclose. Listing content is checked for prohibited contact details.
- Precise listing coordinates, unless the seller expressly enables their disclosure through the sharing options.
- Your verification documents, your chat messages, your payment records and your credit balance.
In Settings → Privacy you can set your profile to public, members-only or private, hide your city, and hide your last-active time. You can also block another user, which stops messaging in both directions.
8. Storage and international transfers
Hosting, messaging, AI, payment and analytics providers may process data outside your country. The provider table describes the service locations known to us; a provider may use further subprocessors. Cross-border transfers are subject to the law applicable to the data and service, including any required adequacy decision, contractual safeguards, supplementary measures or local restrictions. Contact support for information about the arrangements relevant to your data.
Opening a marketplace is subject to a separate review of provider contracts and transfer arrangements. Listing a country or provider in this policy does not claim that a local representative has been appointed or that every country is available.
9. Your privacy rights
Depending on the applicable law, you may request access, correction, deletion, a portable copy, restriction of processing, withdrawal of consent or objection to processing based on legitimate interests. You may complain to the competent data-protection authority. US state rights, verification and appeal procedures apply where the relevant law covers our service and your request. We do not penalise you for exercising applicable privacy rights.
Use Settings → Help & support or contact@flipns.com for a privacy request, including if a dedicated contact shown below is awaiting confirmation. The India-specific rights below apply subject to the relevant provisions being in force.
- Right to access. Get a summary of the personal data we hold and who we have shared it with. Available immediately in the app: Settings → Privacy → Export my data downloads a machine-readable file covering your profile, listings, comments, likes, verification requests, credit transactions, payments, blocks and privacy events.
- Right to correction and completion. Edit your profile in the app, or write to us for anything you cannot change yourself.
- Right to erasure. Delete your account from Settings → Privacy → Delete account, or use the no-login route on our account deletion page. That page sets out exactly what is erased and what we must keep.
- Right to withdraw consent. Turn off an optional feature — product analytics (section 3.9), message forwarding, push notifications, location — at any time, or delete your account to withdraw consent entirely. Withdrawal does not undo processing already carried out.
- Right to object (EEA/UK). Where processing relies on legitimate interests, contact support to submit an objection and we will assess it under the applicable law. The device analytics switch stops optional device analytics; it does not automatically suppress account-level server events.
- Right to nominate. Nominate someone to exercise these rights on your behalf if you die or become incapacitated — write to the Grievance Officer.
- Right to grievance redressal. See section 14. You may escalate to the competent authority, including the Data Protection Board of India where the applicable process is in force, if you are not satisfied with our response.
We acknowledge written requests within 2 working days and aim to resolve them within 30 days, subject to shorter statutory deadlines and any lawful extension communicated to you. We may ask you to verify the phone number or email on the account before we act, because acting on an unverified request is itself a privacy risk.
10. How long we keep data
| Data | How long we keep it |
|---|---|
| Account profile | Until you delete your account. On deletion, contact details, name, avatar, bio and location are erased immediately. |
| Listings | Until you delete them or your account. Deleted and archived listings leave the feed, search index and map immediately. |
| Chat messages and offers | For the life of the conversation. Messages you have already sent remain visible to the other participant, attributed to “Deleted user”, after you leave. |
| Verification documents (government ID, address proof, selfie) | Kept only while the request is under review and for the period we must retain proof of the check; stored in a private bucket that is never publicly addressable. |
| Payment records and the credit ledger | Retained for the period required by Indian tax, accounting and anti-fraud law, even after account deletion. |
| Abuse reports, moderation actions and the audit log | Retained after account deletion so that safety decisions and repeat-offender patterns remain reviewable. |
| Push tokens and notification preferences | Deleted the moment you delete your account, or when the device token is reported invalid. |
| Uploads that were never attached to a listing | Purged automatically by a scheduled job once the staging window passes. |
| Analytics events, session recordings and diagnostics (section 3.9) | Deleted when you delete your account — the analytics person, its events and its recordings are erased along with it. Until then they are kept for the retention period configured on our analytics project, and are deleted automatically when it expires. |
11. How we protect it
- All traffic is encrypted in transit over TLS.
- Private files — chat images and verification documents — are never publicly addressable and are only reachable through signed URLs that expire after fifteen minutes.
- One-time passwords are stored hashed, expire quickly, and are invalidated after a small number of failed attempts.
- Login, OTP delivery, AI calls and payments are rate-limited per user and globally, so a compromised account cannot be used to burn resources or spam numbers.
- Administrative access is role-based, and every privileged action writes an entry to an append-only audit ledger.
No system is perfectly secure. If a personal data breach occurs we will assess the incident and notify the competent authorities and affected people within the periods required by applicable law.
12. Children
Flipns is not intended for anyone under 18. We do not knowingly create accounts for children or process children’s personal data, and we do not use personal data for behavioural advertising or tracking directed at children. If you believe a child has created an account, tell us and we will remove it.
13. Cookies and local storage
Optional analytics on this browser: on.
Essential storage keeps you signed in and remembers requested settings such as theme, selected city and your analytics choice. Security and anti-abuse mechanisms protect the service. Declining optional analytics does not disable these functions.
PostHog analytics identifiers, events and masked session recording are optional and enabled by default. You can turn them off here without signing in, or using Settings → Data & analytics → Share usage analytics on the web or Settings → Privacy → Share usage analytics in the apps. This choice applies to that browser or device. Saved opt-outs are retained when upgrading; clearing site data or using a new browser returns to the default. Enabling analytics by default does not amount to legal consent.
When analytics are enabled, PostHog uses browser storage and first-party identifiers to recognise sessions; requests pass through t.flipns.com to our EU analytics service. First-party does not mean anonymous: signed-in events can be linked to your account. Session recording additionally requires sign-in and masks personal input as described in section 3.9. We do not use advertising cookies or third-party ad pixels.
Opting out stops future optional device collection; it does not automatically erase previously collected records. Use the privacy request process for deletion. Account-level server records are described separately in section 3.9 and are not controlled by a browser-cookie setting.
14. Grievance Officer
In line with the DPDP Act, 2023 and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, the Grievance Officer for Flipns is:
ArvindGrievance Officer, Yuktiv Private Limited
Jind, Haryana India 126114
Email: contact@flipns.com
Hours: 10:00 AM – 5:00 PM IST, Monday to Friday
Intermediary grievances are acknowledged within 24 hours and resolved within 15 days, or sooner where the applicable law requires. Privacy requests follow section 9. Full contact details are on our contact page.
15. Changes to this policy
We will update this page when the product changes. The “last updated” date at the top always reflects the current version, and we will give notice in the app before a material change takes effect. Where a new purpose requires consent, we will request it separately; continued use alone does not supply optional analytics or location consent.