Privacy Policy
How we collect, use, store, share and protect your personal information.
Effective Date: 20 July 2026
Effective Date: 20 July 2026
Last Updated: 20 July 2026
This Privacy Policy explains how [LEGAL ENTITY NAME], operating under the brand âNavi Mumbai Property Deals,â collects, uses, stores, shares, protects and otherwise processes personal information.
This Policy applies to:
- navimumbaipropertydeals.com;
- related mobile or web applications;
- User and Broker dashboards;
- Developer dashboards;
- course and learning modules;
- enquiry and contact forms;
- notification services;
- administrative and CRM interfaces; and
- related services operated by Navi Mumbai Property Deals.
In this Policy, âNMPD,â âwe,â âusâ and âourâ refer to [LEGAL ENTITY NAME].
1. Our Role
For personal data for which NMPD determines the purpose and manner of processing, NMPD acts as the relevant data fiduciary, controller or equivalent entity under applicable law.
In some circumstances:
- an Owner, Broker or Developer receiving an Enquiry may independently process the Userâs information;
- a lender or loan provider may independently determine how to process an applicantâs data;
- a third-party authentication or hosting provider may process information under its own terms; and
- a commercial customer may instruct NMPD to process certain information on its behalf.
This Policy should be read together with our Terms and Conditions, Cookie Policy and any service-specific privacy notice.
2. Personal Information We Collect
The information collected depends on how a person uses the Platform.
2.1 Account and profile information
We may collect:
- full name;
- email address;
- mobile number;
- password in hashed form;
- profile photograph;
- city or business location;
- account role;
- company or brokerage name;
- designation;
- professional biography;
- RERA registration details;
- business registration details;
- website and social profile information;
- language preference; and
- account-verification status.
We do not store passwords in readable plain-text form.
2.2 Authentication information
Where authentication services are enabled, we may process:
- OTP verification status;
- authentication tokens;
- login timestamps;
- device or browser information;
- Google account identifier;
- name, email address and profile image supplied by Google;
- security and fraud-prevention signals; and
- information required to maintain an authenticated session.
NMPD does not receive a Userâs Google password.
Firebase, Google or another authentication provider may independently process information according to its own terms.
2.3 Listing information
When a User posts or manages a property, we may collect:
- property type;
- transaction type;
- address and locality;
- approximate or precise map location;
- price, rent and deposit;
- area and configuration;
- ownership or authority details;
- possession and availability;
- furnishing and amenities;
- project and Developer details;
- RERA registration information;
- property photographs and videos;
- floor plans and brochures;
- uploaded supporting documents;
- contact preferences; and
- Listing history.
Listing information intended for publication may be visible to other Users and search engines.
2.4 Verification information
Depending on the service, we may request information to verify:
- identity;
- ownership;
- authority to list;
- professional registration;
- project registration;
- business status; or
- Listing authenticity.
Users should submit only documents specifically requested through an authorised process.
Users must not upload unredacted Aadhaar numbers, PAN details, banking credentials, signatures or sensitive identity documents into public fields.
Where sensitive verification documents are required, a separate notice may explain the purpose, access controls and retention period.
2.5 Broker2Broker information
We may collect:
- inventory details;
- property requirements;
- preferred locations and budgets;
- connection requests;
- introduction records;
- messages;
- brokerage-sharing proposals;
- direct or indirect mandate status;
- professional contact information;
- activity history; and
- reported disputes or misconduct.
2.6 Enquiry and lead information
When a person submits an Enquiry, we may collect:
- name;
- email address;
- mobile number;
- property or project of interest;
- budget;
- preferred location;
- transaction type;
- message or requirement;
- preferred callback time;
- source or campaign information;
- consent and communication preferences;
- assigned Broker, Agent or team member;
- lead status;
- call or follow-up notes; and
- site-visit or transaction progress.
2.7 Reviews and ratings
We may collect:
- rating;
- review text;
- identity associated with the review;
- relevant Listing, Agent or transaction;
- date and time;
- evidence submitted to support a review;
- response from the reviewed party; and
- moderation history.
Reviews may be displayed publicly together with the reviewerâs name or profile information, subject to the display settings shown when the review is submitted.
2.8 Course information
For course or learning services, we may collect:
- course enrolments;
- access history;
- video progress;
- quiz or assessment results;
- completion status;
- certificates;
- submitted assignments;
- questions and comments;
- payment and invoice records; and
- course-creator information.
2.9 Payment information
Where paid services are enabled, we may collect:
- transaction identifier;
- amount;
- currency;
- payment status;
- invoice details;
- billing name and address;
- tax information;
- refund status; and
- limited payment-method information supplied by the payment provider.
Full card, UPI or banking credentials are generally processed by the payment provider rather than stored by NMPD.
2.10 Device and technical information
We may automatically collect:
- IP address;
- device type;
- operating system;
- browser type and version;
- language;
- screen or interface information;
- date and time of access;
- pages visited;
- referring page;
- session information;
- crash logs;
- security events;
- login activity; and
- approximate geographic region derived from technical information.
2.11 Usage and analytics information
We may collect or generate information such as:
- searches and filters used;
- properties viewed;
- saved properties;
- contact-button activity;
- Listing views;
- response rates;
- regional activity;
- source of traffic;
- campaign performance;
- popular localities;
- top-performing Listings;
- User engagement;
- Agent performance indicators;
- lead and conversion dashboards; and
- aggregated market trends.
Analytics may be associated with an account where needed to provide personalised features or prevent misuse.
2.12 Push-notification information
Where web or application notifications are enabled, we may process:
- push-subscription endpoint;
- device or browser notification token;
- notification permissions;
- delivery status; and
- notification preferences.
2.13 Communications
We may retain communications sent through:
- contact forms;
- email;
- WhatsApp;
- SMS;
- in-platform messaging;
- customer support;
- complaint channels; and
- telephone follow-up notes.
Calls will not be recorded unless the User is informed and recording is legally permitted.
2.14 Information we do not ordinarily require
Unless specifically requested through a secure and lawful process, Users should not provide:
- passwords;
- OTPs;
- full bank-account credentials;
- card PINs;
- unredacted Aadhaar copies;
- private keys;
- health information;
- information about minors; or
- highly sensitive personal information unrelated to a property transaction.
3. How We Collect Information
We collect information:
3.1 Directly from Users
For example, through:
- registration;
- profile creation;
- Listing forms;
- Enquiry forms;
- contact forms;
- course enrolment;
- reviews;
- messages;
- document uploads;
- support requests; and
- communication preferences.
3.2 Automatically
Information may be collected through:
- cookies;
- local storage;
- authentication tokens;
- server logs;
- analytics technologies;
- security systems;
- pixels or similar technologies; and
- push-notification services.
3.3 From third parties
We may receive information from:
- Google sign-in;
- Firebase;
- property Owners;
- Brokers or Agents;
- Developers;
- authorised marketing partners;
- payment providers;
- lenders;
- publicly available RERA or government records;
- fraud-prevention services; and
- persons making a referral or introduction.
A person supplying another individualâs information must have lawful authority to do so and must ensure that the individual receives any legally required notice.
4. How We Use Personal Information
We may use personal information to:
4.1 Create and maintain accounts
This includes:
- registration;
- authentication;
- OTP verification;
- password reset;
- account recovery;
- role management;
- profile display; and
- account security.
4.2 Operate property Listings
We use information to:
- publish Listings;
- categorise properties;
- display location and property details;
- process media;
- moderate content;
- detect duplicates;
- validate information;
- provide search and filtering; and
- communicate Listing status.
4.3 Connect Users
We use information to:
- forward Enquiries;
- connect Buyers, Owners, Brokers and Developers;
- arrange callbacks;
- coordinate site visits;
- manage requirements;
- facilitate Broker2Broker introductions; and
- support requested services.
4.4 Provide personalised services
We may use searches, saved properties, preferences and activity to:
- suggest relevant properties;
- provide alerts;
- show local content;
- recommend Agents;
- remember preferences; and
- improve search results.
4.5 Send transactional communications
We may send:
- OTP messages;
- account-verification messages;
- password-reset emails;
- Listing approval or rejection notices;
- Enquiry confirmations;
- responses to support requests;
- security alerts;
- payment receipts;
- course-access information; and
- important service updates.
4.6 Administer CRM and lead management
Information may be used in administrative dashboards to:
- assign Enquiries;
- track responses;
- avoid duplicate contact;
- record follow-ups;
- identify pending requests;
- measure service performance; and
- resolve complaints.
4.7 Provide courses
We use information to:
- provide course access;
- remember progress;
- assess completion;
- issue certificates;
- answer questions;
- prevent unauthorised sharing; and
- administer payments and refunds.
4.8 Operate calculators and related tools
Information entered into calculators or property-finder tools may be used to:
- produce requested results;
- remember selections;
- suggest properties;
- improve assumptions; and
- connect the User to a requested professional service.
4.9 Communicate about marketing and offers
Subject to applicable law and communication preferences, we may send:
- newsletters;
- market reports;
- new property alerts;
- price updates;
- event invitations;
- course information;
- service announcements; and
- promotional offers.
Users may withdraw marketing consent at any time.
4.10 Improve the Platform
We may analyse usage to:
- understand User needs;
- improve navigation;
- develop new features;
- measure campaigns;
- test performance;
- correct errors;
- optimise Listings; and
- generate aggregated insights.
4.11 Protect Users and the Platform
We process information to:
- prevent fraud;
- detect fake Listings;
- enforce limits;
- investigate complaints;
- identify account compromise;
- prevent spam;
- secure systems;
- preserve evidence;
- enforce our Terms; and
- protect legal rights.
4.12 Comply with legal obligations
Information may be processed to:
- respond to lawful government or court requests;
- maintain required records;
- comply with tax, consumer, cybersecurity, real-estate and telecom laws;
- investigate unlawful activity; and
- establish, exercise or defend legal claims.
5. Legal Grounds for Processing
Depending on the applicable law and context, we process information based on one or more of the following:
5.1 Consent
For example:
- marketing communications;
- push notifications;
- optional analytics where consent is required;
- sharing information with a requested lender;
- collection of optional profile data; and
- other processing for which consent is requested.
Consent may be withdrawn, although withdrawal will not invalidate lawful processing already undertaken.
5.2 Providing a requested service or performing a contract
For example:
- creating an account;
- publishing a Listing;
- forwarding an Enquiry;
- providing a paid service;
- supplying course access; and
- providing customer support.
5.3 Permitted legitimate uses under Indian law
We may process information for uses permitted without consent under applicable Indian data-protection law, where the legal requirements are satisfied.
5.4 Legal obligation
We may process information where required by law, regulation, court order or a competent authority.
5.5 Legitimate interests where recognised
Where another applicable law recognises legitimate interests as a lawful ground, we may rely on interests such as:
- securing the Platform;
- preventing fraud;
- improving services;
- maintaining business records; and
- responding to User requests,
provided those interests are not overridden by applicable individual rights.
6. Public Information
Information submitted for public display may be accessible to:
- Platform visitors;
- registered Users;
- search engines;
- social platforms where a Listing is promoted; and
- other third-party services indexing public webpages.
Public information may include:
- Listing descriptions;
- property photographs;
- approximate location;
- price;
- Broker or Developer profile;
- professional contact information;
- review content; and
- public responses.
Users should not place confidential or sensitive information in public fields.
Removal from NMPD may not immediately remove copies already indexed, cached, shared or independently retained by third parties.
7. How We Share Information
We may share personal information as described below.
7.1 With Owners, Brokers and Developers
When a User submits an Enquiry, we may share relevant information with the party responsible for the Listing or with a professional reasonably assigned to answer the request.
This may include:
- name;
- phone number;
- email address;
- budget;
- preferred location;
- property requirement;
- message; and
- requested callback details.
The receiving party must use the information only for the relevant Enquiry and related lawful follow-up.
7.2 Within Broker2Broker services
Professional contact and inventory information may be shared with another professional User when:
- a connection is requested;
- a requirement matches;
- information is posted for professional circulation; or
- the User authorises an introduction.
7.3 With service providers
We may use service providers for:
- cloud hosting;
- database infrastructure;
- authentication;
- OTP delivery;
- media storage;
- email delivery;
- analytics;
- push notifications;
- customer support;
- cybersecurity;
- payment processing;
- document verification; and
- data backup.
These may include, where enabled:
- Google;
- Firebase;
- Cloudinary;
- Brevo;
- email-delivery providers;
- hosting and database providers;
- analytics providers; and
- payment gateways.
Providers may process information only for the services they supply, subject to contractual and legal obligations.
7.4 With loan and financial-service providers
Information will be shared with a lender, NBFC, loan distributor or financial-service provider when:
- the User requests the service;
- the intended sharing is disclosed; and
- legally required consent has been obtained.
The provider independently determines eligibility and may issue its own privacy notice.
7.5 With professional advisers
We may share information with:
- lawyers;
- accountants;
- auditors;
- insurers;
- cybersecurity advisers; and
- compliance consultants
where reasonably necessary and subject to confidentiality obligations.
7.6 For legal and safety purposes
We may disclose information where reasonably necessary to:
- comply with law;
- respond to a court, regulatory or government order;
- investigate fraud;
- prevent harm;
- enforce our Terms;
- protect legal rights;
- respond to an emergency; or
- assist law-enforcement authorities through lawful process.
7.7 Corporate transactions
Information may be transferred in connection with:
- merger;
- acquisition;
- restructuring;
- investment;
- sale of assets;
- insolvency; or
- transfer of the Platform.
The recipient will be required to process information consistently with applicable law.
7.8 With User direction
We may share information with another party where the User specifically directs or authorises us to do so.
8. We Do Not Sell Personal Information
NMPD does not sell or rent personal information to unrelated third parties in exchange for money.
Sharing an Enquiry with the relevant Owner, Broker, Developer or requested service provider is part of providing the requested service and is not treated by NMPD as a sale of personal information.
Where a law applies a broader definition of âsaleâ or âsharing,â we will provide any legally required rights or choices.
9. Cookies, Local Storage and Similar Technologies
The Platform may use:
9.1 Essential technologies
These are used for:
- authentication;
- session continuity;
- security;
- load balancing;
- account functions;
- fraud prevention; and
- remembering privacy choices.
Disabling essential technologies may prevent parts of the Platform from functioning.
9.2 Preference technologies
These may remember:
- language;
- locality;
- filters;
- saved searches;
- display preferences; and
- notification choices.
9.3 Analytics technologies
These help us understand:
- visitor numbers;
- page usage;
- traffic sources;
- property views;
- errors; and
- service performance.
9.4 Marketing technologies
Where enabled and legally permitted, these may be used to:
- measure campaigns;
- limit repeated advertisements;
- understand conversions; and
- display relevant promotions.
9.5 Authentication tokens
Authentication information may be stored through secure cookies, browser local storage or another appropriate technical method.
Users should sign out when using shared devices and protect access to their browser profile.
9.6 Cookie choices
Where required, Users will be given a choice concerning non-essential cookies.
Browser settings may also be used to block or delete cookies, although this may affect functionality.
Further information should be provided in a separate Cookie Policy at [COOKIE POLICY LINK].
10. Communication Preferences
10.1 Service communications
We may send essential communications concerning:
- security;
- OTPs;
- account access;
- Enquiries;
- Listings;
- payments;
- complaints;
- policy changes; and
- requested services.
These communications cannot always be disabled while the relevant service remains active.
10.2 Marketing communications
Users may opt out through:
- an unsubscribe link;
- notification settings;
- a STOP instruction where supported;
- contacting the sender; or
- emailing [PRIVACY EMAIL].
10.3 Telephone, SMS and WhatsApp
Where a User asks to be contacted, NMPD or the relevant Listing party may communicate about the request.
Marketing calls and messages must be conducted in accordance with applicable telecom and DND requirements.
Withdrawing marketing consent does not prevent a party from responding to an active Enquiry or sending legally necessary communications.
10.4 Push notifications
Push notifications may be disabled through:
- Platform settings;
- browser settings; or
- device settings.
11. International Data Transfers
Some service providers may store or process information outside India.
Where information is transferred internationally, we will take measures reasonably required by applicable law, which may include:
- contractual protections;
- security reviews;
- access restrictions;
- transfer assessments; and
- compliance with any government restrictions on transfers to specified countries or territories.
The location of processing may depend on the infrastructure of authentication, cloud, email, media-hosting and analytics providers.
12. Data Retention
We retain information only for as long as reasonably necessary for the relevant purpose, legal obligations, security, disputes and business records.
Our intended default retention schedule is:
12.1 Account information
Account information is retained while the account is active.
After a valid deletion request:
- the account may remain soft-deleted for thirty days;
- permanent deletion or anonymisation will then be initiated; and
- protected backups may take up to ninety additional days to cycle out.
12.2 Listings
Active Listings are retained while published.
Removed or expired Listing records may be retained for up to three years where needed for:
- fraud prevention;
- complaint resolution;
- duplicate detection;
- regulatory enquiries;
- transaction disputes; or
- legal claims.
Public media may be removed sooner where no retention purpose applies.
12.3 Enquiries and CRM records
Enquiry and follow-up records may be retained for up to three years after the last meaningful interaction, unless:
- a transaction remains active;
- a longer period is required for legal or regulatory purposes;
- a dispute exists; or
- the User requests earlier deletion and no lawful retention ground applies.
12.4 Reviews and complaints
Reviews may remain while relevant to the Platform.
Complaint, moderation and evidence records may be retained for up to three years after closure or longer during litigation, investigation or regulatory proceedings.
12.5 Course records
Course progress may be retained for the duration of the account and for a reasonable period afterward.
Certificates and transaction records may be retained where required for verification, accounting, taxation or legal compliance.
12.6 Financial and tax records
Invoices, payment records and tax-related information may be retained for the period required by applicable law.
12.7 Security logs
Security, login and access logs may be retained for the period reasonably necessary for cybersecurity, incident investigation and compliance with applicable directions.
12.8 Marketing consent records
Consent and opt-out records may be retained as necessary to demonstrate compliance and ensure that withdrawn preferences continue to be honoured.
12.9 Legal holds
Deletion may be suspended where information is subject to:
- litigation;
- investigation;
- regulatory request;
- legal notice;
- fraud review; or
- another lawful preservation requirement.
13. Security Measures
We use reasonable administrative, technical and organisational safeguards appropriate to the nature of the information processed.
Measures may include:
- hashed password storage;
- encrypted data transmission;
- authentication and access controls;
- role-based administrative permissions;
- rate limiting;
- secure security headers;
- logging and monitoring;
- input validation;
- spam and abuse detection;
- controlled production access;
- backups;
- vulnerability remediation; and
- employee or contractor confidentiality obligations.
No internet system or storage method is completely secure.
Users are responsible for:
- selecting strong credentials;
- protecting their email and mobile accounts;
- not sharing OTPs;
- keeping devices secure;
- signing out from shared devices; and
- reporting suspected compromise promptly.
14. Personal Data Breaches
Where we become aware of a personal-data breach, we will:
- investigate and contain the incident;
- assess the nature and likely consequences;
- take reasonable remedial measures;
- preserve appropriate incident records;
- notify affected persons where required; and
- notify the competent authority or Data Protection Board where required by applicable law.
Notification timing and content will depend on the applicable legal requirements and the facts of the incident.
Users should report suspected security incidents to [SECURITY EMAIL].
15. User Rights
Subject to applicable law and lawful exceptions, a person may request:
15.1 Access
Information about the personal data being processed and, where applicable, a summary or copy.
15.2 Correction and updating
Correction of inaccurate or incomplete account and profile information.
15.3 Erasure
Deletion of personal information that is no longer required or is being processed without a lawful basis, subject to legal retention requirements.
15.4 Withdrawal of consent
Withdrawal of consent for processing based on consent.
Withdrawal will not affect processing already lawfully completed.
15.5 Marketing opt-out
Cessation of promotional email, SMS, telephone, WhatsApp or push communications.
15.6 Grievance redressal
Submission of a complaint concerning personal-data processing or handling of a rights request.
15.7 Nomination
Where provided by applicable Indian data-protection law, a person may nominate another individual to exercise relevant rights in the event of death or incapacity.
15.8 Other applicable rights
Users located in another jurisdiction may have additional rights under its law.
16. Exercising Privacy Rights
Requests may be submitted to [PRIVACY EMAIL].
A request should include:
- the name associated with the account;
- registered email address or mobile number;
- the right being exercised;
- relevant details; and
- information reasonably required to verify identity.
We may decline or limit a request where:
- identity cannot be verified;
- the request concerns another person;
- retention is legally required;
- disclosure would affect another personâs rights;
- the request is fraudulent or abusive; or
- another lawful exception applies.
We will respond within the period required by applicable law.
We will not ordinarily charge for a reasonable request, but may address manifestly abusive or repetitive requests as permitted by law.
17. Childrenâs Privacy
The Platform is intended for adults who are legally capable of entering into real-estate and related contracts.
Users must be at least eighteen years old to create an account, post a Listing, submit a transaction-related Enquiry or purchase a service.
We do not knowingly collect personal information from children.
Where we learn that a childâs information was collected contrary to this Policy, we will take reasonable steps to delete or restrict it, subject to applicable law.
A parent or guardian may report such information to [PRIVACY EMAIL].
18. Third-Party Services
Third-party services integrated with or linked from the Platform may independently collect personal information.
These may include:
- Google;
- Firebase;
- Cloudinary;
- Brevo;
- mapping providers;
- social platforms;
- payment gateways;
- banks and lenders; and
- external property or regulatory websites.
Their processing is governed by their respective privacy notices.
NMPD is not responsible for a third partyâs independent privacy practices, although we will exercise reasonable care in selecting important service providers.
19. External Links
The Platform may link to external websites and services.
Once a User leaves NMPD, this Policy does not govern the external service.
Users should review the privacy terms of the destination service before providing information.
20. Automated Moderation and Decision Support
We may use automated tools to:
- identify spam;
- detect duplicate Listings;
- flag suspicious words or prices;
- assess Listing completeness;
- detect potential policy violations;
- rank search results; and
- assist moderators.
Automated flags do not necessarily establish wrongdoing.
Where appropriate, a User may request human review of a material account or Listing restriction by contacting [GRIEVANCE EMAIL].
21. Aggregated and De-Identified Information
We may create and use aggregated or de-identified information that does not reasonably identify an individual.
Such information may be used for:
- market analysis;
- regional trends;
- product development;
- reporting;
- research;
- service improvement; and
- business planning.
We will not intentionally attempt to re-identify properly de-identified information except for security testing or where permitted by law.
22. Changes to This Privacy Policy
We may update this Policy because of:
- legal or regulatory changes;
- new services;
- new service providers;
- changes to data practices;
- security requirements; or
- business restructuring.
Material changes will be communicated through an appropriate method, which may include:
- Platform notice;
- account notification;
- email; or
- a new consent request where legally required.
The âLast Updatedâ date will show when the Policy was most recently revised.
23. Grievance Officer and Privacy Contact
Legal Entity: [LEGAL ENTITY NAME]
Platform: Navi Mumbai Property Deals
Registered Office: [REGISTERED OFFICE ADDRESS]
Privacy Email: [PRIVACY EMAIL]
Support Email: [SUPPORT EMAIL]
Telephone: [OFFICIAL PHONE NUMBER]
Privacy and Grievance Officer
Name: [GRIEVANCE OFFICER NAME]
Designation: [DESIGNATION]
Address: [OFFICIAL ADDRESS]
Email: [GRIEVANCE EMAIL]
Telephone: [OFFICIAL PHONE NUMBER]
Working Hours: Monday to Friday, [TIME], excluding public holidays
A privacy complaint should include:
- name and contact details;
- account or Enquiry reference, where applicable;
- description of the concern;
- the relief requested; and
- supporting evidence.
Where applicable, we will acknowledge and resolve grievances within the periods prescribed by Indian law.
24. Contact Us
Questions concerning this Privacy Policy may be sent to:
Navi Mumbai Property Deals
Operated by: [LEGAL ENTITY NAME]
Address: [REGISTERED OFFICE ADDRESS]
Email: [PRIVACY EMAIL]
Telephone: [OFFICIAL PHONE NUMBER]