Legal

Privacy Policy

Last updated: August 20, 2026

VyrlOne, operated by VyrlOne Tech LLP, is the Data Fiduciary responsible for personal data processed through vyrlone.com and related applications under the Digital Personal Data Protection Act, 2023. This Privacy Policy explains what we collect, why we collect it, how we use and share it, and the rights available to you.

1. Scope and Data Fiduciary

This Privacy Policy applies to personal data collected through vyrlone.com, our web and mobile applications, and related services (together, the "Platform"), operated by VyrlOne Tech LLP ("VyrlOne", "we", "us"), having its registered office at C 475, Sec 2, Chitrakoot, Vaishali Nagar, Jaipur - 302021, Rajasthan.

VyrlOne is the Data Fiduciary for personal data processed through the Platform. This policy does not apply to third-party websites or services linked from the Platform.

2. Information We Collect

  • Identity and KYC data: Name, PAN, and identity documents you upload for verification (such as Aadhaar front/back images and PAN card). Documents are stored securely and reviewed by our team to verify identity before payouts. We collect only what is necessary for KYC and legal compliance.
  • Contact information: Email address, phone number, and profile photo.
  • Professional information: Social media handles, audience niche, and content samples you choose to share.
  • Connected social account data: Read-only profile and performance metrics from Instagram, Facebook, or YouTube when you voluntarily connect an account (see Section 6).
  • Payment information: Bank account or UPI details, processed by our RBI-authorised payment partner Cashfree; VyrlOne does not store full card numbers.
  • Usage data: Pages visited, features used, and Campaign interactions.
  • Device data: IP address, browser type, operating system, and device identifiers.
  • Communications: Messages exchanged between Brands and Creators through our Platform, and correspondence with our support team.

3. Purpose and Legal Basis for Processing

We process personal data on the basis of your consent (for example, when you connect a social account or subscribe to marketing communications), for performance of the contract between you and VyrlOne (account creation, Campaign facilitation, payments), and to comply with legal obligations (KYC, tax, and financial record-keeping). We use personal data to:

  • Provide, operate, and improve the Platform, including Campaign matching, Contracting, and Company Escrow.
  • Display connected social metrics on Creator profiles, refreshed periodically while the connection remains active.
  • Verify identity and prevent fraud, fake accounts, or manipulated engagement.
  • Process payments and manage Company Escrow and payouts.
  • Send Platform notifications, Campaign updates, and service communications.
  • Comply with legal, tax, and regulatory obligations, and enforce our Terms of Conditions.

4. Consent

Where we rely on your consent, we will ask for it in clear language at the point of collection (for example, before connecting a social account or before sending marketing communications), and you may withdraw consent at any time through account settings or by contacting us at support@vyrlone.com, without affecting the lawfulness of processing before withdrawal.

Withdrawing consent for certain processing (for example, KYC) may mean we are unable to continue providing parts of the Platform.

5. How We Share Information

We do not sell personal data. We share it only in the following circumstances:

  • With the Brand or Creator you are collaborating with, limited to what is needed for that Campaign, including social metrics you have chosen to display.
  • With Meta (Facebook/Instagram) and Google, solely to authenticate and retrieve the data you authorise when connecting a social account.
  • With Cashfree, solely to process wallet top-ups, Company Escrow, and creator payouts.
  • With law enforcement, courts, or government authorities where required by law, or to protect the rights, safety, or property of VyrlOne, our Users, or the public.
  • As part of a merger, acquisition, or sale of assets, subject to the acquiring entity honouring this Privacy Policy for previously collected data.
  • With your consent, for any other purpose not listed here.

5A. Sub-processors and Infrastructure

We use the following service providers to operate the Platform. Each processes data only on our instructions and under contractual confidentiality and security obligations:

  • Neon (PostgreSQL): Account, profile, campaign, wallet, and transaction data — hosted in AWS ap-southeast-1 (Singapore).
  • Amazon Web Services (EC2, S3): API hosting, Redis cache, and file storage (KYC documents, contracts, media, invoice PDFs) — primarily AWS ap-south-1 (Mumbai, India).
  • Amazon Web Services (Amplify Hosting / CloudFront): Website and application delivery — content may be cached at edge locations outside India.
  • Cashfree: Payment collection, escrow, and bank payouts — India.
  • Meta Platforms (Facebook / Instagram): OAuth authentication and read-only social metrics — international processing.
  • Google (YouTube Data API): OAuth authentication and read-only channel statistics — international processing.
  • Resend or SMTP email providers: Transactional emails (login OTP, notifications) — region depends on provider configuration.

6. Social Media Account Connections

Creators may optionally connect Instagram, YouTube, and/or Facebook accounts from onboarding or account settings. Connection is always voluntary, initiated by you, and removable at any time.

  • Instagram: Via Meta's Instagram Login, we request read-only access to your professional account (username, profile URL, follower count, media count, reach, impressions, and engagement metrics). We do not post, edit, delete, or message on your behalf.
  • Facebook: Via Meta's Facebook Login for Business, we connect a Page you administer (Page name, Page ID, and available Page metrics), and may use a Page-linked Instagram Business/Creator account where that flow is enabled.
  • YouTube: Via Google OAuth (youtube.readonly scope), we collect channel title, URL, subscriber count, total views, and video count via the YouTube Data API. We do not upload, modify, or delete YouTube content.
  • VyrlOne's use of data received through Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements, and by connecting YouTube you also agree to the YouTube Terms of Service.
  • Synced metrics refresh approximately every 24 hours while connected. Disconnecting stops future syncs and deletes stored OAuth tokens; you can also revoke access directly from your Google (myaccount.google.com/permissions) or Meta (Business Integrations) account settings.
  • OAuth tokens are encrypted at rest and used only to sync your connected metrics. Brands never receive your passwords or raw tokens — only the metrics you choose to display.

7. Cross-Border Data Transfer

VyrlOne is based in India, but not all personal data is stored exclusively in India. Our primary application database (account, campaign, wallet, and transaction records) is hosted on Neon PostgreSQL in AWS ap-southeast-1 (Singapore). KYC documents, uploaded media, and contract files are stored on Amazon S3 in AWS ap-south-1 (Mumbai, India). Our API backend runs on Amazon EC2 in ap-south-1 (Mumbai, India).

The vyrlone.com website and application frontend are served through AWS Amplify Hosting and Amazon CloudFront, which may route or cache content at edge locations outside India to improve performance.

When you connect Instagram, Facebook, or YouTube, Meta and Google may process authentication and metrics data on servers outside India, subject to their respective privacy policies.

Payments and payouts are processed by Cashfree in India.

Where personal data is transferred outside India, we do so in a manner consistent with Section 16 of the DPDP Act, 2023, and only to countries or territories not notified as restricted by the Central Government from time to time. As of the date of this policy, Singapore (where our database is hosted) is not on such a restricted list.

8. Data Retention

  • Account and profile data is retained while your account is active and for a reasonable period after deactivation to handle disputes or legal requirements, after which it is deleted or anonymised.
  • Connected social account tokens and synced metrics are retained only while the connection is active, and deleted on disconnection or account deletion.
  • Campaign records and payment data may be retained for up to 7 years to comply with tax, financial, and anti-money-laundering regulations, even after account deletion.
  • KYC documents and verification records are retained only for as long as necessary for identity verification, fraud prevention, and legal compliance (including tax and anti-money-laundering obligations).

9. Data Security

  • TLS encryption for data in transit and AES-256 encryption for sensitive data at rest.
  • Access controls limiting internal data access to authorised personnel on a need-to-know basis.
  • Regular security reviews and penetration testing.
  • A documented incident response process, including notification to the Data Protection Board of India and affected Data Principals without undue delay in the event of a personal data breach, as required under the DPDP Act.

10. Your Rights as a Data Principal

Under the DPDP Act, and subject to applicable exceptions, you have the right to:

AccessAccess a summary of the personal data we hold about you and the processing activities undertaken.
CorrectionCorrect inaccurate or incomplete personal data, and update outdated data.
ErasureErase personal data that is no longer necessary for the purpose it was collected, subject to our legal retention obligations.
Withdraw consentWithdraw consent at any time, as described in Section 4.
NominateNominate another individual to exercise your rights in the event of death or incapacity.
Grievance redressalRaise a complaint with our Grievance Officer (Section 13), and if unresolved, escalate to the Data Protection Board of India.

11. Children's Data

The Platform is intended for users aged 18 and above and is not directed at children.

We do not knowingly collect personal data from anyone under 18. If we learn that we have inadvertently collected such data, we will delete it promptly; please contact us at support@vyrlone.com if you believe this has occurred.

12. Cookies and Tracking Technologies

We use cookies and similar technologies to remember your preferences, keep you signed in, analyse traffic, and improve the Platform.

You can control cookies through your browser settings; disabling them may limit some Platform functionality.

We do not use cookies to track you across unrelated third-party sites for advertising purposes.

13. Grievance Officer and Contact

In accordance with the Information Technology Act, 2000, the SPDI Rules, 2011, and the DPDP Act, 2023, you may contact our Grievance Officer for any privacy-related complaint or query:

Name: Sandeep Kumar · Email: support@vyrlone.com · Address: C 475, Sec 2, Chitrakoot, Vaishali Nagar, Jaipur - 302021, Rajasthan.

We will acknowledge complaints within 24 hours and aim to resolve them within 30 days.

14. Changes to this Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements.

We will notify you of material changes by email or a prominent notice on the Platform before they take effect.

The "Last updated" date at the top of this page reflects the most recent revision.

Contact VyrlOne Support Team

For privacy-related inquiries, contact the VyrlOne Support Team or our Grievance Officer:

support@vyrlone.com