Privacy Policy
Effective date: 2025 — We care about your data, how it powers Banao, and how we protect it.
1. Overview
Banao builds the Idea → App workspace that empowers founders, engineers, and communities to launch faster. This Privacy Policy explains what data we collect, why we collect it, and how we keep everything secure. It applies to everyone using banao.app, our APIs, and the Evolution WhatsApp community.
2. Data We Collect
- Account basics: name, email address, avatar, and social handles when you sign up via Google or GitHub.
- Workspace activity: project names, repository metadata, prompts, conversations, and deployment events you trigger within Banao.
- Billing details: payment confirmations, invoices, Razorpay references, and Funds hub transactions tied to your workspace.
- Telemetry & analytics: device info, session duration, feature usage, and diagnostics collected through Vercel Analytics and Google Tag Manager (gtag.js).
3. How We Use Your Data
We process data to run the workspace, ship better features, and keep your builds safe:
- Authenticate you seamlessly across the app and Evolution community touchpoints.
- Provide secure GitHub imports, project collaboration, and Funds hub listings.
- Send you transactional emails, WhatsApp updates, and release notes you opt into.
- Monitor for abuse, fraud, or suspicious activity to protect your projects and donors.
4. Sharing & Retention
We only share data with processors that help us deliver the product (Vercel, Prisma, Razorpay, PostHog-style analytics, WhatsApp). They operate under strict contractual and security commitments. We retain account information for as long as your workspace is active or as required by law. You can request deletion of your account and associated data at any time.
5. Your Controls
- Update profile information from your Account dashboard.
- Opt out of non-essential communication from email footers or by pinging us on Evolution.
- Request exports or deletion by emailing privacy@banao.app.
- Disable analytics cookies through your browser or local privacy controls.
6. Compliance
Banao aligns with GDPR, CPRA, and India DPDP Act guidelines for consent, data minimisation, and user rights. We encrypt sensitive fields in transit and at rest, enforce least-privilege access, and run regular security reviews with SecOps tooling.
7. WhatsApp & Mobile QR Sessions
When you scan the mobile QR code from the navigation dropdown, we generate a short-lived pairing token to connect you with our WhatsApp workspace. The underlying session uses Evolution API Lite and Baileys. QR payloads expire after a few seconds, are never stored at rest, and are only associated with the phone number you use to message us. Conversations that flow through WhatsApp are mirrored into your Banao workspace so you can resume work, trigger builds, or kick off new projects from your phone. You can disconnect at any time by sending “logout” or by removing the device from WhatsApp > Linked Devices.
8. Contact
Have questions? Reach out at privacy@banao.app or drop a note inside Evolution. We’ll respond within 3 business days.