Privacy Policy
How we collect, use, disclose, retain, secure, and delete information across the complete ShareKeyX product.
ShareKeyX Privacy Policy
Last updated: 9 August 2026
This Policy explains how Rusaka Technologies Private Limited processes personal data across ShareKeyX. We collect data by feature, minimise access by role, and do not treat public Community data, private account data, KYC, payment, portfolio, or credentials as the same data class.
Some features are controlled or not yet enabled. Their data is processed only when you use the feature, submit the relevant information, or the applicable provider sends an event.
1. Who is responsible and what this policy covers
Rusaka Technologies Private Limited is responsible for ShareKeyX processing described here and acts as the data fiduciary or controller where applicable. This Policy covers the public website, signed-in web application, Android and iOS applications, Community, AI research, subscriptions and wallet, referrals and affiliates, support, privacy requests, and connected-account features.
A provider may independently control data it collects in its own interface—for example, Razorpay, Apple, Google, an identity provider, broker, exchange, or verification provider. Review that provider’s notice at the point of use.
Rusaka Technologies Private LimitedT-133, Moongipa Arcade, D.N. Nagar, Andheri West, Mumbai, Maharashtra 400063, India
Email: info@sharekeyx.com
2. Information we collect
Account, identity, and profile
We may process account ID, name, email, verified phone, authentication provider references, password hash or delegated-authentication evidence, consent and policy versions, profile fields, avatar, safe location code, interests, notification choices, account state, and security settings. We do not need your authentication password from a third-party provider.
Product and support activity
We may process watchlists, selected instruments, saved preferences, research requests, support tickets and attachments, help interactions, privacy or deletion requests, exports, notification delivery, feature events, errors, and the actions required to investigate a complaint or reconcile an account.
Website forms
Contact forms collect name, email, phone where supplied, subject, message, consent, and anti-spam fields. Newsletter forms collect email, consent, and anti-spam fields. Account deletion collects identity and scope, reason where optional, acknowledgement, verification, status, timestamps, delivery evidence, user agent, and available request IP.
3. Public Community information
If you create or use Community features, we may process your handle and handle history, display name, avatar, biography, safe location code, interests, follows, blocks, hides, posts, revisions, comments, reactions, shares, canonical person and instrument mentions, BUY/NEUTRAL/ SELL votes, notification preferences, reports, appeals, moderation labels, enforcement actions, and activity events.
Public profile and publication fields can be visible to signed-in or public audiences according to the current product setting and may appear in an instrument’s Community area. Email, phone, authentication identity, KYC, risk answers, wallet, subscription, watchlist, portfolio, broker credentials, and private security data are excluded from Community public DTOs.
Public information may be copied, linked, quoted, indexed, or captured by other people. A later edit, block, or deletion cannot force independent recipients to erase a copy. We retain revision, report, and moderation evidence where needed for safety, appeals, disputes, or law.
4. AI, research, and personalization data
AI reports and chat may process prompts, selected company or instrument, conversation and report identifiers, retrieved sources, output, token and credit metering, citations, model and policy version, safety flags, failure state, and user feedback. If a feature expressly uses portfolio, watchlist, profile, or risk context, the interface and access control determine the permitted context. Community content is not silently treated as private advice.
We use these records to provide the requested output, maintain conversation or report history, meter credits, investigate failure, enforce safety, and improve reliability. Do not enter passwords, payment details, broker secrets, OTPs, PAN, Aadhaar, private health information, or another person’s confidential data in a prompt.
5. Payments, subscriptions, and wallet records
For Razorpay website billing, we may process ShareKeyX checkout ID, user and product binding, amount and currency, idempotency key, Payment Link, Plan, Subscription, Payment and Refund IDs, status, expiry, recurring lifecycle, webhook event ID, fulfilment, refund amount, provider response, and reconciliation evidence. Razorpay collects the payment method in its hosted interface; ShareKeyX does not receive the full card number or CVV.
For Apple or Google purchases, we may process product and order identifiers, purchase token or signed transaction evidence, store account correlation token, currency and price evidence, purchase, expiry, renewal, refund, revocation, voided-purchase and restoration states. Wallet and entitlement ledgers record grants, usage, subscription allowances, corrections, and compensating reversals. Provider redirects do not grant value without server verification.
6. Connected accounts and orders
If you enable an Advanced connection, we may process provider and platform, delegated tokens or encrypted user-supplied credentials, masked account identity, permissions, portfolios, balances, positions, instruments, quotes, orders, preflight decisions, confirmations, executions, cancellations, reconciliation state, provider errors, rate pressure, and audit events. Access is limited to the requested account and supported operation.
Platform market-data credentials are separated from user account credentials. User secrets must remain server-side and encrypted or tokenized as appropriate. Disconnecting initiates revocation or deletion where the provider supports it, subject to records needed for completed instructions, disputes, fraud, audit, or law.
7. Referral, affiliate, KYC/KYB, and payout data
Referral processing may include invite contact and consent, signed link or code, click and install attribution, account binding, first qualifying purchase, refund hold, promotional credit entries, and fraud evidence. Referrers do not receive the invitee’s payment amount, KYC, portfolio, bank, tax, IP, or private account information.
Affiliate processing may include application identity and contact, entity type, promotion channels, agreement acceptance, beneficial owners and authorised signatory where applicable, PAN and tax profile, GSTIN, CIN or LLPIN, consent-bound DigiLocker or other identity result, provider reference, bank account and IFSC, penny-drop and beneficiary-name result, discounts, attribution, eligible billing, commission, reserves, withholding, statements, payout, cases, fraud signals, and appeals.
Full PAN, GSTIN, CIN/LLPIN, bank and payout trace values are restricted and encrypted or tokenized where implemented; dashboards use masked values. ShareKeyX does not retain the full Aadhaar number, Aadhaar OTP, biometric data, or raw DigiLocker documents in its affiliate verification records. Public leaderboards exclude KYC, bank, tax, customer payment, IP, and fraud data.
8. Cookies, sessions, IP, and device information
The website uses essential cookies to maintain signed-in state, refresh a session, bind a server-side session, and protect mutations against cross-site request forgery. Theme, layout, and guest preferences may use browser storage. We do not place provider secrets or privileged credentials in browser-readable storage.
| Category | Purpose | Typical lifetime |
|---|---|---|
| Access session | Authenticate a signed-in request through an HttpOnly, Secure cookie | Up to 15 minutes |
| Refresh/session binding | Renew and bind the server-side session; HttpOnly and Secure | Up to 7 days, or 30 days when “remember me” is chosen |
| CSRF protection | Confirm that a state-changing browser request came from the expected session | Up to 30 days |
| Interface preferences | Remember theme, layout, and eligible guest preferences | Until cleared or replaced by the browser or user |
Cookie expiry does not define the retention of the corresponding server record. We also may process IP address, accepted proxy chain, user agent, device/session identifier, app version, operating system, push token, language, time zone or coarse region, timestamps, request path, rate-limit state, integrity signal, crash, performance, and security event. We use IP and device evidence for security, regional operation, rate limiting, attribution support, and fraud investigation; IP alone does not determine affiliate attribution or adverse action.
Optional analytics or advertising storage, if introduced, must be separately disclosed and consent-controlled where required. Browser settings can block cookies, but essential account functions may then fail.
9. Purposes and legal grounds
Depending on the feature and applicable law, we process information to:
- create and secure an account and provide a service you request;
- publish and moderate Community content according to your action and audience choice;
- generate, store, meter, and reconcile AI reports, chat, subscriptions, and credits;
- operate a connected account or submit a user-confirmed provider instruction;
- verify purchases, refunds, attribution, KYC/KYB, tax, bank, commission, and payout;
- communicate service, security, support, privacy, purchase, and moderation information;
- detect spam, account takeover, manipulation, fraud, prohibited content, and abuse;
- measure reliability, debug failures, improve accessibility, and develop the product;
- comply with law, enforce agreements, establish or defend claims, and respond to lawful requests; and
- send optional marketing or publish an optional affiliate leaderboard with the required choice or consent.
We rely, as applicable, on your consent; processing needed to provide a requested service or perform an agreement; compliance with law; protection of users and systems; establishment or defence of claims; and other grounds or legitimate uses recognised by applicable law. You may withdraw consent prospectively, but withdrawal does not invalidate prior lawful processing or remove records that must be retained.
10. Providers, disclosures, and international processing
We share the minimum relevant data with approved categories of provider: hosting, database and storage; authentication; Razorpay, Apple, and Google billing; email and push communications; AI and retrieval; market, company, fund, news and map data; security, support and observability; user-selected brokers and exchanges; and, when enabled, identity, DigiLocker, PAN, GST, MCA, bank-verification, tax, and payout providers. Website deletion records may use Supabase and transactional messages may use Resend.
We may disclose data to professional advisers, auditors, insurers, acquirers under appropriate safeguards, regulators, courts, law enforcement, or other parties when authorised by you, required by law, or reasonably necessary to protect rights, users, or the service. We do not sell your payment credentials, KYC, broker credentials, or portfolio data as a data product.
Providers may process data in India or other permitted locations. We use contractual, technical, organisational, and transfer safeguards appropriate to the provider and applicable law. A user-selected broker or exchange may be subject to its own jurisdiction.
11. Retention, deletion, and legal holds
We retain each data class only for the feature, security, dispute, audit, tax, financial, moderation, provider, or legal period that applies. Active account and content data generally remains while the account or feature is used. Unaccepted invitations, stale sessions, raw security signals, transient provider payloads, and error events use shorter schedules where practicable. The backend default for retained error events is 30 days unless an approved environment policy changes it.
A confirmed full-account deletion request enters a 60-day cooling-off period during which it can be cancelled before processing. Processing revokes active sessions and removes or de-identifies data that is not required. Purchase, refund, subscription, wallet, order, commission, tax, payout, security, fraud, moderation, grievance, legal-hold, and audit evidence may remain in a minimised or pseudonymised form for the applicable period. Backups expire on their protected rotation and are not restored to ordinary use solely to recover deleted data.
12. Security and breach response
Measures include server-side policy enforcement, HttpOnly session cookies, exact-origin and CSRF controls, authentication and step-up checks, role-based access, least-privilege database policies, secret management, encryption or tokenization for sensitive fields, provider signature verification, idempotent ledgers, validation, rate limiting, audit trails, backup, monitoring, and incident procedures. Public Community DTOs use explicit allowlists.
No system can guarantee absolute security, prevent every screenshot, or make browser-delivered code and public data secret. If a personal-data breach triggers a legal notice obligation, we will notify affected people and the appropriate authority in the form and time required by applicable law. Report suspected compromise immediately without sending the exposed secret.
13. Your rights and choices
Subject to applicable law and verified identity, you may request a summary or copy of personal data, correction or completion, withdrawal of optional consent, erasure, account deletion, grievance handling, and information about relevant recipients. Where applicable, you may nominate another individual to exercise rights in the event of death or incapacity. You can also manage notifications, clear browser preferences, disconnect supported providers, block or hide Community users, edit or delete eligible content, and appeal eligible moderation or affiliate decisions.
Use in-product privacy controls or email info@sharekeyx.com. We may request proportionate verification, clarify scope, protect another person’s rights, and preserve records required by law. Withdrawing consent or deleting necessary data may make a requested feature unavailable. You may escalate an unresolved grievance through the forum available under applicable law.
14. Children
ShareKeyX is intended for adults aged 18 or older. We do not knowingly offer accounts, Community publishing, paid research, affiliate onboarding, or connected financial-account features to children. If you believe a child’s data was submitted, contact us so we can investigate and take the action required by law.
15. Changes and grievance contact
We may update this Policy for product, provider, retention, security, or legal changes. The effective version and date will remain published; material changes receive notice or renewed consent where required. Policy versions accepted for Community, billing, privacy, or affiliate actions may be retained as audit evidence.
Address privacy questions, correction or erasure requests, and grievances to the ShareKeyX Grievance Officer using the contact below. Include your account email, request category, and enough non-sensitive detail to locate the issue. Do not include passwords, OTPs, full payment credentials, broker secrets, or Aadhaar documents.
Rusaka Technologies Private LimitedT-133, Moongipa Arcade, D.N. Nagar, Andheri West, Mumbai, Maharashtra 400063, India
Email: info@sharekeyx.com
