Legal
Privacy Policy
Last updated: April 2026
This Privacy Policy explains what personal data Best Card Today collects, why, how it is stored, and your rights under Indian law, including the Digital Personal Data Protection Act, 2023 (DPDP Act).
By using the service, you consent to the practices described below.
1. Who is the data fiduciary
Best Card Today, operating from [New Delhi, India], is the Data Fiduciary for the personal data described in this policy.
For data protection queries, contact: [email protected]
2. What we collect
We collect only the data we need to operate the service.
Account data
- Email address
- Password (stored only as a bcrypt hash; we never see or store the plaintext)
- Telegram chat ID, if you choose to enable notifications
Card data
- A name you choose for each card (e.g., "HDFC Regalia")
- Statement date
- Due date
We do not collect: your bank login credentials, card number, CVV, PIN, transaction history, balances, account numbers, PAN, Aadhaar, phone number, or address.
Operational data
- IP address (for rate limiting and abuse prevention)
- Timestamps of account activity (login, card creation, password reset)
- Email delivery and bounce status (when password reset is used)
What we do not use
- We do not use cookies for tracking or advertising
- We do not run analytics scripts
- We do not embed third-party ad networks
3. Why we collect it
| Data | Purpose | Legal basis under DPDP |
|---|---|---|
| Email, password hash | Account login and security | Performance of contract |
| Card name, statement date, due date | Generating your recommendation | Performance of contract |
| Telegram chat ID | Sending your daily notification | Consent (you opt in) |
| IP address, activity timestamps | Security, abuse prevention | Legitimate use |
| Email for password reset | Account recovery | Performance of contract |
4. Who we share it with
We do not sell, rent, or share your personal data for marketing purposes.
We share data only with the following processors, strictly to operate the service:
- Render (hosting, USA): runs our application and PostgreSQL database
- Cloudflare (DNS, CDN, USA): handles domain routing and DDoS protection. Sees only IP addresses and request metadata, not card data
- Brevo (transactional email, EU): sends password reset emails. Receives your email address only when you request a password reset
- Telegram (messaging, global): receives the recommendation message and your Telegram chat ID, only if you have enabled notifications
Some of these processors are based outside India. By using the service, you consent to your data being processed outside India for the purposes described above. We use providers with industry-standard security practices.
We may also disclose data if required by law, court order, or to investigate fraud or abuse.
5. How long we keep it
| Data | Retention |
|---|---|
| Account and card data | For as long as your account is active |
| Account data after deletion | Deleted within 30 days of account deletion |
| Backups containing deleted data | Purged within 90 days of account deletion |
| Operational logs (IP, timestamps) | 90 days |
| Password reset tokens | 1 hour from issue, then deleted |
6. How we secure it
- Passwords are hashed with bcrypt; we cannot recover them, only reset them
- All traffic is encrypted in transit using HTTPS, with HTTPS enforcement at the edge
- Database access is restricted to the application server
- Authentication uses signed JWT tokens with a 7-day expiry
- Rate limiting is applied at the IP level to prevent brute-force attempts
- No employee has routine access to your card data; access for support requires a documented reason
No system is perfectly secure. If we discover a breach affecting your data, we will notify you and the Data Protection Board of India in accordance with the DPDP Act.
7. Your rights
Under the DPDP Act, you have the right to:
- Access the personal data we hold about you
- Correct inaccurate data (you can edit most data directly in your account)
- Erase your data by deleting your account
- Withdraw consent for any processing based on consent (e.g., disable Telegram notifications)
- Nominate a person to exercise these rights on your behalf in the event of death or incapacity
- Grievance redressal by contacting us first; if unresolved, you may approach the Data Protection Board of India
To exercise any of these rights, email [email protected]. We will respond within 30 days.
8. Children
The service is not intended for, and may not be used by, anyone under 18. We do not knowingly collect data from children. If we learn we have done so, we will delete it.
9. Marketing
We do not send marketing emails. The only emails you will receive from us are:
- Password reset emails (when you request one)
- Critical service notices (e.g., a security incident or a material change to these terms)
10. Changes to this policy
We may update this policy. The "Last updated" date at the top reflects the current version. Material changes will be notified by email to active accounts.
11. Contact and grievance officer
For privacy questions, data requests, or grievances:
[email protected]
[New Delhi, India]
We will acknowledge grievances within 7 days and resolve them within 30 days.