Privacy Policy.

This Privacy Policy("Policy") was updated at 1st November, 2025 ("Effective Date").

This Privacy Policy ("Policy") is issued by METACIRCLES PRIVATE LIMITED, a company incorporated under the laws of India and having its registered office at [Insert Address], which owns and operates the website https://culture-circle.com and its relevant mobile application("Culture Circle" or "Company").

Culture Circle is an e-commerce platform that curates and showcases exclusive, community-driven, and culturally relevant products in the domains of fashion, sneakers, lifestyle collectibles, and designer-led collaborations. It enables users to explore, purchase, and engage with curated collections, while also inviting resellers and creators to contribute, showcase, and collaborate with the brand.

This Policy governs the collection, use, storage, processing, and disclosure of personal data of all individuals interacting with the Platform, including but not limited to customers, users, collaborators, and resellers. The Policy reflects Culture Circle's commitment to upholding the rights of individuals and its obligation to adopt responsible, transparent, and secure data practices.

This Policy is formulated in accordance with the provisions of the Digital Personal Data Protection Act, 2023 ("DPDPA"), the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and such other rules, regulations, and guidelines as may be applicable. It is also guided by internationally recognised privacy principles, including purpose limitation, data minimisation and data security.

The Policy reflects the Company's enduring commitment to ensure that all personal data is processed fairly, lawfully, and in a manner that respects the privacy rights of individuals and upholds the principles of integrity, confidentiality, and accountability.

WHEREAS

A. METACIRCLES PRIVATE LIMITED ("Culture Circle" or the "Company") operates an e-commerce platform and is committed to protecting the personal data and privacy rights of its users, resellers, customers, vendors, employees, and other stakeholders, in accordance with the highest standards of transparency, accountability, and ethical data governance;

B. Culture Circle is committed to ensuring that its data governance practices remain fully compliant with the applicable laws in force within India, including the Digital Personal Data Protection Act, 2023, the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, as well as any relevant rules, directions, advisories, or notifications issued by the Indian Computer Emergency Response Team (CERT-In) and the Ministry of Electronics and Information Technology (MeitY);

C. The Company acknowledges that personal data, including sensitive personal data such as payment-related information, must be processed on the basis of lawful grounds including consent or legitimate use, and managed through appropriate safeguards to prevent misuse, loss, or unauthorised access;

D. The protection of personal data, the implementation of industry-standard security safeguards, and the adoption of lawful, transparent, and accountable data handling procedures constitute core principles of Culture Circle's operational framework and commercial ethos.

NOW THEREFORE, Culture Circle hereby adopts this Privacy Policy to provide a clear, lawful, and user-centric framework for the collection, processing, storage, use, disclosure, and protection of personal data, thereby reinforcing its commitment to data privacy and regulatory compliance. By accessing, browsing, using the Platform, via website or its application, submitting any personal data voluntarily, or otherwise engaging with the services of Culture Circle, each user is deemed to have read, understood, and agreed to be bound by this Privacy Policy, and to adhere to the rights and obligations set out herein.

1. DEFINITIONS AND INTERPRETATION

1.1. Definitions:

In this Policy (including the recitals above hereto), except where the context otherwise requires, the following words and expressions shall bear the meaning assigned to them below:

1.2. Interpretation

2. APPLICATION

a) The purpose of this Privacy Policy is to establish a clear, lawful, and comprehensive framework for the collection, processing, usage, storage, disclosure, and protection of personal data submitted to, or collected by, the Culture Circle platform. The Policy reflects the Company's commitment to ensuring the privacy and dignity of individuals whose data is processed in connection with the use of the Platform.

b) This Policy applies to all data principals who interact with the Platform in any capacity, including but not limited to:

c) This Policy shall apply regardless of the device, platform, or medium used to access the Company's services, including desktops, mobile phones, tablets, smart devices, and other digital channels.

d) This Policy does not apply to:

e) By accessing or using the Platform or otherwise providing Personal Data to the Company, the User expressly acknowledges and agrees to the terms of this Policy, and consents to the processing of their Personal Data in accordance with the terms stated herein.

f) In case of any conflict between this Policy and any contractual terms agreed between the Company and any Data Principal (such as employees, vendors, or consultants), the provisions offering higher privacy protection shall prevail, unless otherwise required by applicable law.

3. CATEGORIES OF PERSONAL DATA COLLECTED

a) Culture Circle collects and processes specific categories of personal data to facilitate the delivery of its e-commerce services, enhance user experience, ensure legal compliance, and enable commercial collaboration. The nature and extent of data collected may vary depending on the user's role and interaction with the Platform, including but not limited to that of a customer, reseller, creator, visitor, or guest user;

b) Personal data may be acquired through one or more of the following sources:

ModeDescriptionExamplesTypical Use Cases
Voluntarily ProvidedInformation directly submitted by the user through forms, registrations, submissions, or communication.Account creation, checkout, newsletter sign-up, reseller onboarding, contact forms, event RSVPs.Creating user accounts, submitting business details, subscribing to communication.
Automatically CollectedData captured by systems, browsers, or devices during user interaction with the Platform.Cookies, device identifiers, IP address, session analytics, clickstream, cart abandonment patterns.Website interaction tracking, improving performance, fraud detection, analytics.
Collected from Third PartiesInformation obtained through external service providers, tools, or integrations.Social login data (e.g., Google, Meta), payment gateway status, influencer links, courier tracking data.Login via third-party providers, processing payments, affiliate and referral tracking.
Derived or Inferred DataData analytically generated based on existing data and behaviour patterns.Wishlist trends, repeat purchase analysis, likelihood of churn or engagement, profile preference tags.Behavioural targeting, personalisation, product recommendations, feature improvements.

c) The above Personal Data may be collected at the time of account creation, while placing an order, subscribing to newsletters, interacting with the Platform or customer care, participating in surveys or contests, or otherwise voluntarily provided by the User.

d) In addition to the above, the Company may collect certain Non-Personal Data (data that does not identify an individual directly or indirectly), which may include aggregated statistics, anonymised usage metrics, and analytics data, solely for internal research, service improvement, or marketing performance purposes.

e) The Company does not intentionally collect or process biometric data, health data, or official government identifiers (such as Aadhaar or PAN), unless specifically required by law or consented to by the User for a legitimate purpose.

f) The categories of personal data collected by the Company are presented in detail in the table provided below. Each entry defines the nature of the data, its origin, how it is collected, and the contextual interaction in which such collection typically occurs:

CategoryDescriptionSourceCollection MethodCollection Scenario
Identity DataName, username, date of birth, profile photo (if submitted)UserProvided voluntarilyDuring account registration, reseller onboarding, or checkout
Contact DataEmail, phone number, shipping and billing addressesUserProvided voluntarilyWhile placing an order, creating an account, or submitting forms
Payment & Financial DataMasked card details, UPI ID, payment ID, Card details, CVV payment timestampPayment gateway, userProvided via secure channelAt the time of making a purchase or processing a transaction
Order & Transaction DataPurchase history, cart contents, order IDs, shipping tracking infoPlatform backend, logisticsAutomatically collectedAfter placing orders or interacting with the cart
Device & Technical DataIP address, browser type, device model, OS, screen resolution, time zoneUser device/browserAutomatically collectedWhen browsing the site or interacting via any device
Usage & Log DataPage visits, session duration, clicks, crash reports, error logsInternal systemAutomatically collectedDuring any on-site or in-app activity
Location DataApproximate or precise geolocation via IP or browser (if permitted)User browser or deviceAutomatically collectedWhile accessing the Platform with location permissions
Behavioural DataItems viewed, wishlist activity, cart interactions, session flowPlatform analyticsAutomatically collectedAs part of browsing and shopping behaviour
Marketing & Communication DataNewsletter preferences, survey responses, promotional opt-ins/outUser, CRM systemsVoluntarily providedWhen subscribing, responding to campaigns, or updating preferences
Account CredentialsHashed passwords, OTP logs, login attemptsUserProvided voluntarilyAt registration or login
Game DataGame Token balance, Match Selections, Leaderboard rank, Redemption historyPlatform backend, UserAutomatically collectedWhile participating in the Predictions Game
Social Media DataPublic profile info (name, email, metadata) from linked accountsThird-party login APIsAPI-based retrievalWhen logging in via Google, Facebook, or other integrations
Customer Support DataEmails, chat transcripts, complaint recordsUser, support systemsProvided voluntarilyDuring customer support requests or helpdesk interactions
Referral or Affiliate DataReferral codes used, affiliate clicks, influencer coupon applicationAffiliate and marketing platformsAutomatically collectedWhen using referral links or participating in campaigns
User-Generated ContentReviews, testimonials, public comments, uploaded photos or videosUserProvided voluntarilyWhen submitting content via product pages or campaigns
Reseller/Business DataBusiness name, contact person, social handles, business summaryResellerProvided voluntarilyDuring reseller application or partnership proposal
Creator/Collaborator DataPortfolio links, bios, creative samples, brand associationsCreator/CollaboratorProvided voluntarilyDuring onboarding or collaboration discussions

4. PURPOSE OF DATA COLLECTION & USE

a) Culture Circle collects personal data through lawful, fair, and transparent means, using both direct and indirect collection mechanisms. All data is collected only to the extent necessary for defined, legitimate, and proportionate purposes in connection with the services provided on the Platform.

b) The Company may, from time to time, use AI-enabled tools or automated software systems to support internal processing, organisation, segmentation, or analysis of personal data, such as trend recognition, recommendation models, fraud detection, or customer preference mapping. All such tools are subject to ethical safeguards, accuracy checks, and restricted deployment. Automated processing shall not override user rights or be used as the sole basis for decision-making that materially affects the user.

c) All personal data collected and processed by Culture Circle is accessed internally on a strictly need-to-know basis, governed by the principles of role-based access control (RBAC) and least privilege. Access is granted only to authorised personnel depending on function, such as customer support, finance, marketing, compliance, fulfilment, or technology teams. Access logs are maintained and periodically reviewed, and no unauthorised or cross-functional access is permitted.

d) The following table outlines the specific purposes for which each category of Personal Data may be collected and used:

Purpose of ProcessingCategory of Personal Data InvolvedLegal Basis under DPDPAProcessing & Internal Access Control
To process, fulfil, and deliver ordersIdentity Data, Contact Data, Payment & Financial Data, Order & Transaction Data, Location DataPerformance of Contract; ConsentOrder and delivery managed by Logistics team; access restricted to logistics and transaction nodes
To provide account registration and login functionalityIdentity Data, Account Credentials, Contact DataConsent; Legitimate UseData encrypted and stored securely; access permitted to platform engineering and account services team
To communicate order updates and service-related informationContact Data, Order & Transaction DataLegitimate Use; Performance of ContractEnabled through CRM and order systems; limited to support and logistics personnel
To personalise user experience and recommend productsBehavioural Data, Usage Data, Wishlist, Purchase HistoryConsent (cookies); Legitimate UseAnalytics dashboards used; no direct identifiers accessed; limited to marketing analytics team
To conduct marketing campaigns and send promotional contentContact Data, Marketing Preferences, Purchase HistoryExplicit ConsentExecuted through marketing automation tools; accessed by authorised brand and campaign teams
To conduct customer satisfaction surveys, reviews, and feedbackContact Data, Usage Data, User-Generated ContentConsentSurvey data anonymised for analysis; review content published upon moderation; limited access to community team
To provide customer service and resolve complaintsContact Data, Order & Transaction Data, Customer Support DataLegitimate Use; Performance of ContractCase-specific access by grievance redressal team; records logged in helpdesk with limited audit rights
To detect and prevent fraud, abuse, or policy violationsIdentity Data, Device Data, Transaction Data, Account CredentialsLegitimate Use; Legal ObligationMonitored by fraud engine; escalated alerts reviewed by compliance and backend admin teams only.
To comply with applicable legal, regulatory, and tax requirementsIdentity Data, Transaction Data, Payment & Financial DataLegal ObligationReviewed by finance, legal, or compliance officers; maintained in audit-compliant formats.
To maintain records for audit, dispute resolution, and risk managementIdentity Data, Contact Data, Payment & Transaction DataLegal Obligation; Legitimate InterestRecords encrypted and archived in controlled-access databases; reviewed during audit cycles.
To improve website performance, analytics, and internal reportingUsage Data, Device Data, Aggregated Behavioural DataConsent (cookies); Legitimate UseData is pseudonymised and aggregated; accessible to analytics teams for platform enhancement only.
To process influencer codes and affiliate marketing programsReferral Data, Identity Data, Transaction DataConsent; Performance of ContractAffiliate activity tracked by partner platforms; access limited to campaign managers
To engage authorised third-party service providers for business operationsAll relevant data categoriesPerformance of Contract; Legitimate UseData shared over secured channels; processors bound by confidentiality and lawful processing obligations
To send transactional SMS and voice communications via authorised providersContact Data, Communication PreferencesConsentRouted through messaging APIs; governed by marketing or order communication SOPs
To onboard and evaluate resellers and commercial partnersReseller/Business Data, Contact Data, Identity DataConsent; Performance of ContractVerified by business onboarding team; stored securely and accessible only to B2B managers
To showcase creator submissions, portfolios, or collaborative contentCreator/Collaborator Data, Contact Data, Attribution MetadataConsentUsed only with explicit opt-in; access by creative and content publishing teams
To publish and moderate user-generated content such as reviews or testimonialsUser-Generated Content, Identity Data (where public), Feedback DataConsentModerated manually prior to publishing; limited to UGC moderation and community management teams
To operate, settle, and secure the Predictions Game, and to administer RedemptionsGame Data, Identity Data, Contact DataConsent; Legitimate UseManaged by the gaming/product team; access restricted to product, fraud, and customer support personnel

e) The Company does not use Personal Data for any purpose other than those stated above without providing appropriate notice and, where applicable, obtaining specific and informed consent from the Data Principal.

f) Where consent is the legal basis for processing, the User may withdraw such consent at any time by contacting the Grievance Officer or using the mechanisms provided on the Platform. However, withdrawal of consent may affect the ability to deliver certain products or services.

g) The Company ensures that all processing of Personal Data is proportionate, limited to the extent necessary for the stated purposes, and in accordance with the principles of fairness, transparency, and accountability under applicable law.

5. LEGAL BASIS FOR PROCESSING

a) The Company processes Personal Data only when there is a lawful basis for such processing under the Digital Personal Data Protection Act, 2023, or other applicable laws. The legal bases may include one or more of the following:

b) Consent of the Data Principal: Where the Company collects Personal Data directly from a User or Data Principal, it shall do so after obtaining the individual's free, specific, informed, unconditional, and unambiguous consent through clear affirmative action.

c) Examples:

d) The User may withdraw consent at any time through the settings panel, opt-out links, or by contacting the Grievance Officer. Such withdrawal shall not affect any prior lawful processing.

e) Performance of a Contract: The Company may process Personal Data where such processing is necessary to fulfil its obligations under a contract with the Data Principal or to take steps at their request before entering into a contract.

f) Compliance with Legal Obligations: The Company may process Personal Data where it is legally required to do so under applicable laws, court orders, or regulations, including requirements imposed by government or law enforcement agencies.

g) Examples:

h) Legitimate Use (as permitted under Section 7 of the DPDPA, 2023): The Company may process Personal Data without consent for certain "legitimate uses" as explicitly provided under the DPDPA, including but not limited to:

LEGITIMATE USE CATEGORYEXAMPLE
Voluntary Data Provided by UserUser submits details for placing an order or contacting customer support
Provision of Benefit or ServiceDelivering a purchased product or issuing an invoice
Legal Proceedings or Dispute ResolutionDefending legal claims, enforcing contractual rights
Public Interest or Public OrderCo-operating with investigations, law enforcement or public safety officials
Employment or Internal AdministrationProcessing employee/vendor data for internal compliance or record-keeping

i) The Company ensures that any reliance on legitimate use does not override the fundamental rights and expectations of the Data Principal and is consistent with the purpose limitation and necessity principles.

j) Public Interest or Public Health (If Applicable): In exceptional circumstances such as pandemics or emergencies, the Company may process Personal Data in the interest of public health, subject to applicable statutory permissions or directions from government authorities.

k) Where Personal Data is collected indirectly or through third-party service providers, the Company ensures that such third parties have obtained appropriate legal basis (including consent) for sharing such data with the Company. A list of categories of third parties (including their names, where applicable) with whom Personal Data may be shared is set out below. These third parties are contractually obligated to maintain the confidentiality and security of the data and to process such data strictly in accordance with applicable law and instructions issued by the Company.

l) The Company maintains detailed internal records of the legal basis applicable to each processing activity, and such records are reviewed periodically to ensure compliance.

m) In cases where the legal basis for processing changes (e.g., from contract to consent), the Company shall notify the Data Principal and, where required, obtain fresh consent before proceeding.

6. CONSENT MANAGEMENT

a) Obtaining Consent: The Company shall obtain the free, specific, informed, unconditional, and unambiguous consent of the Data Principal before collecting or processing any Personal Data, unless the processing is permitted under legitimate use or legal obligation in accordance with Section 5 of this Policy.

b) Consent is obtained in a clear and granular manner at the point of data collection, such as during:

c) Layered Notices: All consent requests are accompanied by a layered privacy notice that includes:

d) These notices are drafted in clear, plain, and concise language to ensure that Users understand what they are agreeing to.

e) Proof and Record of Consent: The Company maintains verifiable records of the consent obtained from each Data Principal, including the time, method, and purpose for which consent was granted. These records are stored securely and may be made available to the Data Protection Board or other authorities in the event of a lawful request or audit.

f) Refusal or Conditional Consent:

g) Withdrawal of Consent:

h) Consent for Minors:

i) Cookies and Tracking Consent:

j) The Company honours the User's tracking preferences and provides information on how to modify or withdraw cookie preferences in its Cookie Policy [insert].

k) Updates to Consent Preferences:

7. CHILDREN'S DATA

a) The Company is committed to protecting the privacy of children and complying with the provisions of Section 9 of the Digital Personal Data Protection Act, 2023, which restricts the processing of personal data of children without verifiable parental or guardian consent.

b) For the purposes of this Policy, a child is defined as an individual who has not completed the age of 18 years, unless a different age threshold is prescribed by applicable law.

c) The Company does not knowingly collect, process, or store Personal Data from children unless:

d) If it comes to the Company's attention that Personal Data of a child has been collected without lawful consent, the Company shall:

e) The Company does not engage in behavioural tracking, profiling, or targeted advertising towards children, directly or indirectly, in compliance with the prohibitions under Section 9 of the DPDPA.

8. COOKIE AND TRACKING TECHNOLOGIES

a) The Company uses cookies and similar tracking technologies (such as pixels, beacons, and local storage) on its website and mobile application to enhance user experience, deliver personalized content, enable core functionalities, analyze usage trends, and facilitate marketing campaigns.

b) Users are provided with a cookie policy, which can be accessed through the Platform, in accordance with the notice and consent requirements under the Digital Personal Data Protection Act, 2023, and the IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.

c) The types of cookies used, their purposes, and the list of third-party tools involved are described in the Company's Cookie Policy, which forms an integral part of this Privacy Policy.

d) Users may review or update their cookie preferences at any time by visiting the Cookie Preferences in their browser settings.

e) For more detailed information on our cookie practices, including how to manage or disable cookies at the browser level, please refer to our full Cookie Policy.

9. DATA SHARING AND THIRD-PARTY TRANSFERS

a) Internal Access and Sharing: Personal Data collected by the Company may be accessed by authorised internal teams, including but not limited to operations, customer support, marketing, logistics coordination, product development, finance, and compliance, strictly on a need-to-know basis. All such access is governed by internal access controls, confidentiality obligations, and data minimisation principles.

b) Third-Party Disclosures: The Company may share Personal Data with trusted third-party service providers, vendors, and business partners (collectively, "Third Parties") solely for the purpose of enabling the Company to provide its products and services efficiently. These Third Parties process Personal Data on behalf of the Company and are contractually bound to comply with applicable data protection laws, maintain data confidentiality, and use the data only for the specified purposes. A summary of categories of Third Parties with whom data may be shared, and the purpose of sharing, is set out in Section 5(a)(viii) above.

c) Categories of Third Parties May Include:

CATEGORYPURPOSE OF PROCESSINGTHIRD PARTY NAME(S)TYPE OF DATA SHARED
Payment ProcessorsTo facilitate secure paymentsRazorpay, Paytm, Cashfree, PhonePe, StripeName, contact, transaction ID, masked card/bank info
Shipping & Logistics PartnersTo deliver orders and provide trackingNimbuspost, Delhivery, Shiprocket, Bluedart, EkartName, contact, address, order details
Email & SMS CommunicationTo send order updates, alerts, and promotional messagesMailchimp, Sendinblue, Gupshup, TwilioEmail, phone number, communication logs
Web Hosting & InfrastructureWebsite operation, backups, and performanceHostinger, AWS, Cloudflare, DigitalOceanDevice metadata, IP address, access logs
Marketing and Retargeting ToolsOnline advertising, analytics, and promotional campaignsMeta (Facebook), Google Ads, Instagram, Hotjar, CleverTapIP address, browsing behavior, cookies
Customer Support ToolsCustomer query management and ticketingFreshdesk, Zoho Desk, IntercomName, contact, chat logs, order info
Analytics & Tracking ProvidersMonitor website usage and improve servicesGoogle Analytics, Facebook Pixel, Microsoft ClarityIP, session data, page visits, clicks
Affiliate/Influencer PlatformsTrack referral codes, commissionsImpact.com, Refersion, custom influencer codesReferral ID, coupon usage, transaction data
Internal Consultants & AuditorsLegal, tax, or compliance purposesCA firms, Legal counsel, Compliance auditors (on retainer)Financial, order, and sometimes user data
Government or Legal AuthoritiesLegal compliance, law enforcementIncome Tax Dept., Police, Consumer ForumsAny legally mandated personal data, upon request
Authentication & Access ServicesTo manage account logins, identity, and session securityFirebase Auth, AWS Cognito, custom OTP APIsUser ID, email, mobile, OTP verification logs
Sports Data ProvidersTo power match-analysis tools (statistics, form, rankings) within the Predictions Game[To be specified on appointment]Fixture and match-level data only; no User-identifying Personal Data

d) Cross-Border Transfers:

10. USER OBLIGATIONS

a) Users who access or interacting with the Culture Circle Platform are required to act in good faith, observe lawful conduct, and take reasonable responsibility for the personal data and activities associated with their accounts. By engaging with the Platform, each user accepts the obligation to comply with this Policy, the Platform's Terms of Use, and all applicable Indian laws.

b) Users are expected to ensure the accuracy, completeness, and legality of the information they provide. Personal data submitted must not be false, misleading, stolen, impersonated, or unlawfully obtained. Culture Circle shall not be liable for any consequences arising from reliance on erroneous or unauthorised data submitted by users.

c) Users shall be personally responsible for the integrity and confidentiality of their account credentials, devices, and access points used to engage with the Platform:

d) Users shall refrain from engaging in, authorising, or facilitating any activity that:

e) Users shall not attempt to:

f) Users must promptly notify Culture Circle in the event of:

g) Users may have the ability to submit, post, or upload content on the Culture Circle Platform, including but not limited to product reviews, testimonials, feedback, comments, ratings, creative media, and other publicly visible content ("User-Generated Content" or "UGC")

h) All UGC submitted must be original, lawful, respectful, and relevant to the purpose for which it is submitted. Users shall be solely responsible for the content they contribute, and represent that they have full rights and authority to submit such material.

i) By submitting UGC to the Platform, the user grants Culture Circle a worldwide, royalty-free, non-exclusive, and irrevocable license to use, display, reproduce, publish, modify, and distribute such content for the purposes of:

j) Culture Circle reserves the right to:

k) Users may request the removal of UGC that they have previously submitted by writing to the Company, subject to verification and lawful review.

l) Culture Circle reserves the right to suspend, restrict, or terminate a user's account or access if a violation of these obligations is suspected, reported, or confirmed. Further, the Company may initiate legal proceedings or report such violations to competent authorities under applicable law.

11. MARKETING, COMMUNICATIONS, NEWSLETTERS AND VISIBILITY PREFERENCES

a) Culture Circle may, from time to time, send users promotional communications, newsletters, event announcements, limited-edition releases, and product or brand-related updates, based on prior consent. Users are provided the option to manage their communication preferences at the time of subscription, registration, or through account settings.

b) Marketing and promotional content is shared only:

c) Users, collaborators, or business partners may withdraw their consent to receive marketing communications or newsletters at any time by:

d) Certain platform communications may be transactional in nature and not subject to consent withdrawal. These include order confirmations, delivery updates, security alerts, and account-related notices.

e) Resellers and creators onboarded on the Platform may be invited to participate in promotional campaigns, featured listings, or editorial content. Such visibility is optional and subject to:

f) All marketing and visibility preferences shall be recorded, timestamped, and retained as part of the Platform's consent management framework, in accordance with the Digital Personal Data Protection Act, 2023 and related regulations.

11A. CULTURE CIRCLE PREDICTIONS GAME

11A.1 Nature and Scope of the Feature

a) The Predictions Game is an optional, in-app feature made available to eligible Users during the football season, including major tournaments such as the FIFA World Cup, through which Users may predict the outcome of football matches using Game Tokens.

b) Game Tokens are issued to Users free of charge and cannot, under any circumstance, be purchased, deposited, withdrawn, transferred to another User, or converted to cash. Game Tokens have no monetary value and do not constitute a deposit, stake, wager, or bet of any kind. A User's participation in the Predictions Game does not involve the payment, deposit, or staking of any money or money's worth by the User at any stage.

c) The Predictions Game is offered solely for the entertainment, recreation, and engagement of Users, and is not, and is not intended to operate as, an "online money game", "betting", "gambling", or "wagering" activity under the Promotion and Regulation of Online Gaming Act, 2025, or any applicable state legislation. The Company keeps this Policy and the design of the Predictions Game under periodic review to ensure continued alignment with applicable law.

d) Nothing in this Section 11A shall be construed as creating any right to winnings, prize money, or monetary compensation of any kind. The User acknowledges that Game Tokens and Rewards exist solely within the closed ecosystem of the Platform.

11A.2 Eligibility and Age Restrictions

a) Participation in the Predictions Game is open only to Users who are at least 18 (eighteen) years of age. This eligibility criterion is in addition to, and not in substitution of, the general provisions on Children's Data set out in Section 7 of this Policy.

b) The Company reserves the right to request age verification prior to permitting participation in the Predictions Game, and to suspend or restrict access to the feature where it has reason to believe a User does not meet the eligibility criteria in this Section 11A.2.

11A.3 Categories of Game Data Collected

a) In addition to the categories of Personal Data described in Section 3 of this Policy, the Company collects the following categories of Game Data in connection with a User's participation in the Predictions Game:

CategoryDescriptionCollection MethodCollection Scenario
Game Token BalanceRunning total of free Game Tokens credited to and debited from a User's accountAutomatically recordedOn grant of free tokens and after each Match Selection is settled
Match Selection DataMatch chosen, predicted outcome, Game Tokens committed, and settlement result (won/lost)Automatically recordedEach time a User submits or settles a Match Selection
Match Analysis Interaction DataStatistical summaries, form data, or rankings viewed by the User prior to a Match SelectionAutomatically collectedWhile browsing the match-analysis tools within the Predictions Game
Leaderboard DataUser's relative rank and Game Token total as displayed to other UsersAutomatically generatedContinuously, while the Leaderboard feature is active
Redemption DataReward Threshold reached, Reward issued, Reward redemption status, and qualifying purchase used to apply a RewardAutomatically recordedAt the time of Redemption and subsequent qualifying purchase

11A.4 Purpose and Legal Basis for Processing Game Data

a) Game Data is processed for the following purposes: (i) operating, settling, and securing the Predictions Game; (ii) administering Game Token balances and Redemptions; (iii) generating and displaying the Leaderboard; (iv) detecting and preventing fraud, multiple-accounting, or manipulation of match outcomes; and (v) improving the design and fairness of the Predictions Game.

b) The legal basis for processing Game Data is the User's consent, given by opting into the Predictions Game, and the Company's legitimate use in operating the feature and preventing misuse, consistent with Section 5 of this Policy. Game Data is not used for any purpose beyond those listed in this Section 11A.4 without further notice to, and where required, fresh consent from, the User.

11A.5 Leaderboard

Where a User opts into the Predictions Game, the User's in-app username and Game Token total may be displayed to other Users of the Predictions Game through the Leaderboard. The Company does not display a User's real name, contact details, or any other category of Personal Data on the Leaderboard.

11A.6 Token Mechanics and Settlement

a) Game Tokens are credited to a User's account on joining the Predictions Game, and additional Game Tokens may only be earned by correctly predicting the outcome of a football match only.

b) Where a Match Selection is settled as correct, the User's committed Game Tokens are returned together with any additional Game Tokens awarded. Where a Match Selection is settled as incorrect, the committed Game Tokens are deducted from the User's balance. A User bears no financial loss in either outcome, as no money or item of monetary value belonging to the User is at risk at any stage.

c) The Company reserves the right to correct any Game Token balance, Match Selection, or Leaderboard entry that is shown to be the result of a technical error, fraud, or manipulation, and to take such corrective action as it considers necessary, including reversing affected Game Tokens or Rewards.

11A.7 Redemption and Rewards

On reaching the applicable Reward Threshold, a User may redeem accumulated Game Tokens for a Reward, in the form and value notified within the Predictions Game interface from time to time. A Reward is usable solely on the Platform, is conditional on the User making a qualifying purchase with their own funds, and is non-transferable and not redeemable for cash. The Company may, at its discretion, prescribe expiry periods, minimum purchase values, or category restrictions applicable to a Reward, which shall be notified to the User at or before the time of Redemption.

11A.8 Fraud, Abuse and Manipulation

a) A User shall not create or operate multiple accounts to obtain additional Game Tokens, manipulate or attempt to manipulate the outcome of any Match Selection or the Leaderboard, or use any automated means to participate in the Predictions Game, in addition to the general User Obligations set out in Section 10 of this Policy.

b) The Company monitors Game Data for indicators of fraud or abuse consistent with Section 4(c) of this Policy (fraud detection and prevention), and reserves the right to suspend or terminate a User's access to the Predictions Game, void affected Game Tokens or Rewards, and where appropriate, take the further actions described in Section 10(l) of this Policy.

11A.9 Grievances Relating to the Predictions Game

Any grievance relating to the settlement of a Match Selection, a Game Token balance, a Leaderboard entry, or a Redemption shall be raised with the Grievance Officer at the contact details set out in Section 16 of this Policy, and shall be handled in accordance with the timelines prescribed in that Section.

11A.10 Disclaimer Regarding Match Data and Outcomes

Statistical summaries, form data, player information, and rankings displayed within the Predictions Game are sourced from Sports Data Providers and are provided for informational purposes only. The Company does not guarantee the accuracy, completeness, or timeliness of such data and shall not be liable for any Match Selection made in reliance on it. The Company shall not be liable for postponed, abandoned, or rescheduled matches, save that it will act reasonably in settling or voiding affected Match Selections.

11A.11 Modification, Suspension and Discontinuation

The Company may, at its sole discretion, modify the mechanics, Reward Thresholds, Rewards, or availability of the Predictions Game, or suspend or discontinue the Predictions Game in whole or in part, at any time, with notice to Users provided through the channels described in Section 20 of this Policy. Discontinuation of the Predictions Game shall not entitle a User to any compensation, given that Game Tokens carry no monetary value.

12. DATA RETENTION & STORAGE

a) Retention Principle: The Company retains Personal Data only for as long as is reasonably necessary to:

b) The retention period is determined by the nature of the data, the purpose of processing, and any applicable legal or contractual requirements.

c) Data Retention Timelines:

Category of DataTypical Retention PeriodLegal / Operational Basis
Identity and Contact Data3 years from last activity or transactionStatutory limitation for consumer claims, account recovery, and customer support
Order and Transaction Data8 years from date of transactionIncome Tax Act compliance, accounting, audit, GST and invoice retention requirements
Payment and Financial Data (masked)As per RBI Payment Aggregator Guidelines or 13 monthsRegulatory requirements, fraud monitoring, chargeback defence
Customer Support and Complaint Logs3 years from date of last correspondenceGrievance handling, dispute resolution, internal quality audit
Marketing Preferences and Opt-In DataUntil withdrawal of consent or 2 years of inactivityConsent-based retention for promotional communications
Analytics and Usage Data (pseudonymised)12–18 months from date of collectionPlatform optimisation, performance measurement, and internal benchmarking
Account Credentials (Hashed)Until account is deleted or voluntarily deactivatedEssential for user login, multi-factor authentication, and session recovery
Unused or Dormant Account Data2 years of inactivity, with 30-day advance notice before deletionData minimisation, privacy-by-default, and periodic account housekeeping
Reseller / Business Partner Data5 years from last engagement or active listingBusiness record maintenance, compliance, fraud traceability, onboarding due diligence
Creator / Collaborator Data5 years from end of engagement or publication dateBrand representation, portfolio attribution, legal traceability of submitted creative content
User-Generated Content (UGC)Until takedown request is verified and processedPublic content hosted until user requests removal or account is deleted
Anonymised or Aggregated DataRetained indefinitelyNo longer constitutes "personal data" under DPDPA; used for trends, reports, or insights

Note: The above periods are subject to change in case of any legal proceedings, enforcement actions, or statutory hold directives.

d) Deletion and De-identification: Upon expiration of the applicable retention period, Personal Data is either:

The Company ensures that deletion is performed in a secure manner using industry-standard sanitisation or erasure methods.

e) Right to Request Deletion:

f) Such requests will be honoured subject to legal and contractual retention obligations and shall be responded to within a reasonable period as prescribed under the DPDPA, 2023.

g) Storage Location and Backups: Personal Data is stored on secure servers operated by the Company or its authorised hosting providers, currently located in India. Periodic encrypted backups are maintained to ensure data recoverability in case of system failure, which are subject to the same retention and deletion practices outlined above.

h) Policy Review and Updates: The Company periodically reviews its data retention schedules and storage practices to ensure compliance with evolving legal standards and operational needs. Any changes to retention durations will be notified through an update to this Policy.

13. REASONABLE SECURITY PRACTICES

a) Culture Circle is committed to ensuring the security, integrity, and confidentiality of the Personal Data it collects and processes. In line with Rule 8 of the IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and Section 8(5) of the Digital Personal Data Protection Act, 2023, the Company implements appropriate technical, organizational, and administrative security measures to protect Personal Data against accidental loss, unauthorised access, destruction, misuse, alteration, or disclosure.

b) The Company adopts industry-standard safeguards including, but not limited to:

c) Personal Data is stored in secure servers hosted on reputable cloud platforms that are compliant with industry frameworks such as ISO/IEC 27001 and SOC 2, where applicable. All third-party service providers processing Personal Data on the Company's behalf are contractually bound to adhere to similar or higher levels of security and confidentiality.

14. NOTIFICATION OF PERSONAL DATA BREACH

a) Culture Circle, adopts a proactive and structured approach to identifying, mitigating, and responding to any personal data breach. A personal data breach refers to any unauthorised or accidental disclosure, alteration, loss, destruction, or access to Personal Data that compromises its confidentiality, integrity, or availability whether caused by technical failures, malicious attacks, human error, or organisational gaps.

b) Data Breach Response Procedure and Timelines: In the event of a suspected or confirmed data breach, the Company shall activate its internal Data Breach Response Procedure, which comprises the following steps and timeframes as detailed in Annexure A.

c) Information Included in Notifications: Any notification to the Data Protection Board of India, CERT-In, or affected individuals (Data Principals) shall include the following information:

d) Breach Severity Categorisation: The Company classifies data breaches into three severity levels:

Only Level 2 and Level 3 breaches require mandatory external notification.

e) User Cooperation: Users who become aware of any potential compromise of their account, such as unauthorised login attempts, phishing emails, or suspicious transactions, must report the same immediately by emailing customersupport@culture-circle.com. The Company will investigate such reports on priority and take appropriate action.

15. RIGHTS OF DATA PRINCIPALS

a) As a Data Principal under the Digital Personal Data Protection Act, 2023, you are entitled to exercise the following rights in relation to your Personal Data collected and processed by Culture Circle. These rights are subject to reasonable limitations and applicable legal requirements.

b) As per the Digital Personal Data Protection Act, 2023, Data Principals have the following rights in relation to their Personal Data:

RIGHTDESCRIPTIONTIMELINE FOR RESPONSEHOW TO EXERCISE THIS RIGHT
Right to AccessTo know whether the Company processes your Personal Data and request details such as categories, purpose, recipients, and retention period.Within 15 working daysEmail a request to customersupport@culture-circle.com or use your account dashboard (if available).
Right to CorrectionTo request correction, updating, or completion of inaccurate, outdated, or incomplete Personal Data.Within 10 working daysSubmit a correction request with valid supporting documents to customersupport@culture-circle.com
Right to ErasureTo request deletion of Personal Data that is no longer necessary, has been unlawfully processed, or after consent withdrawal.Within 15 working daysSend a deletion request via email to customersupport@culture-circle.com with identity verification.
Right to Withdraw ConsentTo withdraw previously given consent for specific data processing activities.Immediate upon confirmationUse opt-out links in emails or write to customersupport@culture-circle.com specifying the consent to withdraw.
Right to Grievance RedressalTo file a complaint regarding delay, denial, misuse, or mishandling of Personal Data or non-fulfilment of rights.Acknowledgement in 48 hrs, resolution in 7 working daysEmail your grievance to the Grievance Officer at customersupport@culture-circle.com
Right to NominateTo nominate another individual to exercise your rights under this Policy in the event of your death or incapacity.As per Company recordsSend a signed nomination form or declaration via email to customersupport@culture-circle.com
Right to Be InformedTo receive clear, accessible information on data collection, legal basis, purpose, rights, third-party disclosures, and policy changes.Continuous rightReview this Privacy Policy regularly and subscribe to update notifications via email or the Platform.

16. GRIEVANCE REDRESSAL MECHANISM

a) Culture Circle India is committed to addressing all privacy-related concerns, complaints, and requests in a transparent, secure, and time-bound manner. In accordance with Section 13 of the Digital Personal Data Protection Act, 2023 and Rule 5(9) of the IT Rules, 2011, the Company has appointed a Grievance Officer to ensure proper handling of grievances related to Personal Data.

b) Lodging a Grievance: If you have any concerns or grievances regarding:

c) You may raise a grievance by sending an email to the designated Grievance Officer:

Grievance Officer

Email: customersupport@culture-circle.com

Address: Plot no. 9, 4 Bay, Institutional Area, Sector 32, Gurugram, Haryana - 122001

Working Hours: Monday to Friday, 10:30 AM to 7:00 PM IST

d) Grievance Handling Procedure and Timelines:

STAGEACTIONTIMELINE
AcknowledgementThe Grievance Officer will acknowledge receipt of your complaint.Within 48 hours
Initial ReviewAssess completeness and legitimacy of the grievance.Within 2 working days
Investigation and ResolutionConduct internal inquiry, coordinate with relevant departments, resolve issue.Within 7 working days
Notification of OutcomeCommunicate resolution decision or status update to the complainant.Within 10 working days total

e) If you are dissatisfied with the resolution provided by the Grievance Officer or if no response is received within the prescribed period, you have the right to escalate the matter to the Data Protection Board of India under Section 13(2) of the Digital Personal Data Protection Act, 2023.

17. FORCE MAJEURE

The Company shall not be held liable for any failure or delay in performing its obligations under this Privacy Policy, including the processing of rights requests or breach notifications, due to circumstances beyond its reasonable control. Such events may include natural disasters, war, civil unrest, pandemic, governmental actions, electricity or internet outages, cyberattacks, or other force majeure events. During such periods, the Company will take reasonable steps to mitigate the impact and restore normal operations as soon as practicable.

18. GOVERNING LAW AND JURISDICTION

This Privacy Policy shall be governed by and construed in accordance with the laws of India. Any disputes arising out of or in connection with this Policy shall be subject to the exclusive jurisdiction of the competent courts located in [New Delhi], India, without regard to conflict of law principles.

19. CHANGE IN OWNERSHIP OR CONTROL

In the event of a merger, acquisition, reorganisation, or sale of all or a portion of the Company's assets or business, Personal Data held by the Company may be transferred to the successor entity. Such transfer will continue to be governed by the terms of this Privacy Policy unless and until it is amended by the successor with due notice to Users.

20. POLICY UPDATES AND NOTIFICATION

The Company may update or modify this Privacy Policy from time to time to reflect changes in legal requirements, business practices, or technological advancements. Any material changes will be notified to Users through:

Users are encouraged to periodically review this Policy to stay informed of how their Personal Data is protected.

21. CONTACT US

If you have any questions, concerns, or require clarification regarding this Privacy Policy, the processing of your Personal Data, or your rights as a Data Principal, you may contact our designated

Grievance Officer

Email: customersupport@culture-circle.com

Address: Plot no. 9, 4 Bay, Institutional Area, Sector 32, Gurugram, Haryana - 122001

Working Hours: Monday to Friday, 10:30 AM to 7:00 PM IST.

By continuing to access or use the Platform, you acknowledge that you have read and understood this Privacy Policy and agree to its terms. Your continued use of the services constitutes your consent to the collection, processing, and disclosure of your Personal Data in accordance with this Policy.

This Privacy Policy shall remain in effect until it is updated, superseded, or revoked by the Company.

ANNEXURE A

DATA BREACH RESPONSE FRAMEWORK & TIMELINE

STAGEACTIONTIMELINE
1. Detection & ContainmentIdentify and verify the breach, isolate affected systemsWithin 6 hours of detection
2. Preliminary Risk AssessmentAssess scope, type of data affected, sensitivity, and potential impactWithin 12 hours of detection
3. Internal EscalationNotify Compliance Officer, Data Protection Officer, and senior managementWithin 12 hours
4. Reporting to AuthoritiesNotify CERT-In and/or the Data Protection Board of India, where applicableWithin 6 hours of confirming the breach (as per CERT-In guidelines)
5. Notification to IndividualsInform affected Data Principals of the nature of the breach, risk, and mitigation stepsWithin 48 hours, where risk of harm is high
6. Remedial ActionContain breach, patch systems, reset credentials, and prevent recurrenceImmediate, completed within 72 hours
7. Documentation & Audit TrailRecord breach details, investigation logs, and corrective measures takenWithin 7 days of incident
8. Final Report & Policy UpdateRoot cause analysis and review of internal policies/trainingWithin 15 days of breach
FOLLOW US ON
InstagramTwitterYouTube
DOWNLOAD THE CULTURE CIRCLE APP
Google Play
App Store
SUBSCRIBE TO OUR NEWSLETTER
© 2026 CultureCircle — All rights reserved
METACIRCLES TECHNOLOGIES PVT LTD