Bazaar
Privacy Policy
Last updated: 9 September 2026 · Version 1.0
Scope. This policy applies to Bazaar, the customer shopping app for iOS and Android, and to nothing else. It does not cover the point-of-sale software the shops themselves use to run their counters — that is a separate product with a separate relationship, and folding the two together would make this policy wrong in both directions. It is a product policy, not a company-wide one; other Arivaatral products publish their own at their own product pages.
The short version. Bazaar is a service, not an offline app. You can browse shops and products without an account or any personal detail at all. To place an order you sign in with your phone number, and from that point we store your name, phone number, delivery addresses and order history on servers we operate. The shop you order from sees the name, phone number and delivery address on that order — it has to, in order to deliver it. Nobody else does. We do not sell your data, we run no advertising, and the app ships no analytics, advertising or social-login SDKs. You can delete your account at arivaatral.com/bazaar/delete-account.
1. Who we are
Bazaar is developed and operated by Arivaatral, an independent software studio based in Tamil Nadu, India. Arivaatral is the data controller for the account and service data described in this policy. You can reach us at sheikalthafdev@gmail.com.
A note on roles that matters in a marketplace: the shops listed in Bazaar are independent businesses, not our employees or branches. When you place an order, you are buying from that shop. It receives your order and your delivery details as a merchant in its own right, keeps its own customer and sales records under its own obligations, and decides its own prices, stock and delivery. We provide and operate the software the order travels through.
2. Using Bazaar without an account
Browsing is anonymous. You can open the app, look through shops, read product pages and fill a basket without signing in and without giving us a name, a phone number or an email address.
To keep a basket attached to your device between launches, the app generates a random session identifier and stores it on the device. It is a random string. It is not derived from your phone, it carries no advertising identifier, and it is not linked to you as a person unless and until you sign in and place an order.
3. What the service stores once you sign in
Account
- Your phone number — this is how you sign in, and it is the identifier your orders are keyed to
- Your name, as you enter it
- A session token, so you stay signed in between launches
- The time-limited one-time codes sent to you while signing in
Delivery
- Every delivery address you save — the address text, any landmark or instruction you add, and the contact name and phone number for that address if they differ from your own
Orders
- What you ordered, from which shop, in what quantity and at what price
- The delivery address on the order and the delivery window or slot chosen
- Order status and its history — placed, accepted, packed, out for delivery, delivered, cancelled
- Any note you attach to an order
- Recurring delivery subscriptions you set up — the plan, the schedule, the pauses and the deliveries made against it
- Order-related messages shown in the app's notifications list
Payment
Orders are cash on delivery. Bazaar takes no payment inside the app. We do not ask for, receive, process or store a card number, a UPI ID, a bank account or any other payment instrument. What we record is what the order was worth and whether the shop marked it settled.
4. Location
With your permission, the app uses your device's approximate location to show you shops near you. The app requests coarse location only — it does not ask for, and cannot obtain, a precise GPS fix. The fix is used to pick the nearest town that has shops, and it is used at that moment.
We do not track you. There is no location history, no background location collection and no movement profile. The app has no permission to read your location while it is closed.
You can decline. If you refuse the permission, the app asks you to pick your town from a list instead, and everything else works normally.
5. Who can see what
Access is scoped by relationship and enforced on the server, not merely hidden in the interface:
- You see your own profile, addresses, orders, subscriptions and notifications.
- The shop you ordered from sees that order and the details needed to fulfil it: your name, your phone number, the delivery address on the order, and what you bought. It also sees your order history with that shop, because that is how a shop knows a returning customer. This is the disclosure worth reading twice — placing an order with an independent business necessarily hands that business your delivery details.
- A shop cannot see another shop's orders, or its customers, or a customer who has never ordered from it. Companies are isolated from one another on the server.
- Nobody else — there is no public profile, no customer directory, no search that returns other people, and no way for one customer to reach another through the app.
6. What we do not do
- We do not sell, rent or trade your data, and we never will.
- There is no advertising in the app, and no data goes to advertisers or data brokers.
- The app ships no third-party analytics SDK, advertising SDK, attribution SDK, crash-reporting SDK or social login. It requests no advertising identifier and declares no
AD_IDpermission. - We do not build behavioural profiles, and we do not use your order history to target you anywhere outside the app.
- Staff access to production data is limited to what is necessary to operate the service or investigate a fault you have reported.
7. Processors — the third parties involved
A short list, because there is a short list. Each of these processes data on our instructions, for the purpose stated, and for nothing else of its own.
| Who | What they receive | Why |
|---|---|---|
| Ping4SMS | Your phone number and the one-time code | To deliver the sign-in SMS. Nothing else is sent, and they do not receive your orders, addresses or name. |
| Our hosting provider | The service data described above, at rest and in transit on the servers we rent | To run the servers. They are infrastructure; they do not use the data. |
The shops you order from are not in this table, deliberately. A shop is not processing on our behalf — it is an independent business receiving your order as the seller. That relationship is described in section 5 rather than here, because calling it processing would understate it.
8. Data stored on your device
- The anonymous session identifier described in section 2
- Your session token once you sign in
- Your current basket
- Your chosen town, and app preferences such as theme
- Cached product images, so the app is not re-downloading the same picture
Signing out clears the token. Deleting the app removes all of it. Note that deleting the app does not delete your account or your orders from our servers — for that, see section 10.
9. Retention
- Account details — kept while your account exists.
- One-time sign-in codes — valid for minutes, then discarded.
- Addresses — kept until you delete them, or until your account is deleted.
- Orders — kept as commercial records. An order is a completed sale between you and a shop, and both we and that shop have record-keeping and tax obligations attached to it. Orders therefore survive account deletion in anonymised form: the items, amounts and dates remain; the name, phone number and delivery address attached to them are removed. See section 10.
- Server logs — operational logs are short-lived and kept only for diagnosing faults and abuse.
10. Your rights, and deleting your account
You can see and correct your profile and addresses inside the app at any time, and your full order history is in the app under Orders.
You can delete your account. Doing so removes your name, phone number, saved addresses, notifications and the link between you and your past orders. Your orders themselves are retained in anonymised form for the record-keeping reasons in section 9, and the shops you ordered from keep their own copies of the sales they made, under their own obligations — we cannot delete a shop's records on your behalf, and we say so rather than implying otherwise.
To request it, follow the instructions at arivaatral.com/bazaar/delete-account. You do not need the app — the request goes by email and we verify it against the phone number you sign in with. A delete button inside the app, under Account, is coming in a future update.
For access to a copy of your data, or any other request, email sheikalthafdev@gmail.com and we will deal with it.
11. Security
All traffic between the app and our servers is over HTTPS. Sign-in is by one-time code to your phone number, so there is no password of yours for us to lose. Access to your data is scoped per account on the server, and shops are isolated from one another at the same layer. No system is perfect; if we ever discover a breach affecting your data, we will tell you rather than hope you do not notice.
12. Children
Bazaar is intended for adults placing orders with shops. It is not directed at children, we do not knowingly collect data from anyone under 18, and there is no user-generated content, messaging or way for users to contact one another.
13. Changes to this policy
If this policy changes, we will update the date at the top of this page. If a change is material — a new processor, a new category of data, a payment method that involves an actual payment processor — we will say so plainly in the app's release notes rather than quietly editing this page. Changes here apply to Bazaar only.
14. Contact
Questions about this policy, or about anything the app does, go to sheikalthafdev@gmail.com. We answer.