Privacy Policy
How BytePlay collects, uses, shares, and protects your personal data across the website, app, waitlist, Byte Passport, matchmaking, Hubs and voice rooms, Game Connect, and ByteArcade — and the rights you have over it under India's Digital Personal Data Protection Act, 2023.
Who We Are & What This Covers
THEBYTEPLAY PRIVATE LIMITED ("BytePlay," "we," "us"), a company incorporated in India, is the Data Fiduciary under the Digital Personal Data Protection Act, 2023 (DPDP Act) for personal data processed through the BytePlay website, app, waitlist, Byte Passport, matchmaking, Hubs/voice rooms, Game Connect, ByteArcade, and related services (the "Services").
Registered office: 32/1, NR Pathareniwas, Tukaramnagar Chandannagar, Vadgaon Sheri, Pune, Pune City, Maharashtra, India, 411014.
Privacy & Grievance contact: privacy@thebyteplay.com
This policy does not cover third-party platforms you connect (Steam, Riot, Discord, Google, etc.) — their own privacy policies apply.
Age Eligibility
Services are for users 18 years and older only. We do not knowingly collect data from anyone under 18. If we learn a minor's data was collected, we suspend the account and delete the data. If you believe a minor has registered, contact privacy@thebyteplay.com.
Data We Collect
| Category | Examples |
|---|---|
| Account & auth | Email/phone, login provider, session & security logs |
| Profile (Byte Passport) | Username, avatar, bio, games/sports, rank, availability, playstyle, visibility settings |
| Connected gaming accounts | Provider ID, stats, ranks, achievements, activity — only what you authorize and the provider permits (no passwords stored) |
| Matchmaking & location | Game/mode preferences, match history, reports; approximate location always; precise location only with explicit permission, for nearby-player/IRL features, never shown publicly by default |
| Communications | Chat, Hub posts, voice-room metadata (audio not recorded by default), support tickets |
| Device & usage logs | IP, device/OS, crash reports, interaction events — for security and product improvement |
Data is labelled Verified / Official / Linked / User-Submitted based on how it was obtained; only verified data carries a verification badge.
How We Use It
To operate accounts, matchmaking, Byte Passport, ByteScore, chat/voice, and ByteArcade; provide support; detect fraud/abuse and enforce rules; improve and secure the Services; send service and (opt-in) marketing communications; and meet legal obligations. We don't use data for materially different purposes without fresh consent where required.
ByteScore & Automated Processing
ByteScore (reputation/trust signal) is derived from profile completeness, verified activity, and community reliability. It does not determine legal or similarly significant outcomes on its own. You can view score components, contest inaccurate inputs, and request human review. Private messages/voice are not used to train AI models without separate notice and consent.
Legal Basis for Processing (DPDP Act)
- Consent — waitlist signup, marketing, precise location, connecting accounts, non-essential cookies. Withdrawable anytime, without affecting prior lawful processing.
- Certified/legitimate uses — contract performance (running the Services), compliance with law, and other purposes DPDP treats as not requiring separate consent (e.g., fraud/security response, emergency, employer/court-mandated disclosure).
Consent requests are itemized, specific, and given in clear language — not bundled or pre-ticked.
Sharing & Disclosure
We share data with: (a) other users, per your visibility settings; (b) service providers/processors (hosting, auth, analytics, voice infra) under contract; (c) connected platforms, to sync authorized data; (d) event/Hub organizers, limited to what's needed; (e) authorities, where legally compelled; (f) an acquirer, in a merger/sale, with safeguards.
We do not sell personal data and do not currently use it for cross-context behavioural advertising.
Cookies
Essential (auth/security), analytics, and preference cookies. Non-essential cookies stay off until you consent. Manage via browser/device settings.
Data Retention
| Data | Retention |
|---|---|
| Waitlist | Up to 24 months after last interaction, or on request |
| Account/profile | Active account + limited post-closure window (recovery, legal, safety) |
| Connected-platform tokens | Until disconnected/revoked/expired |
| Security & diagnostic logs | ~30–180 days |
| Support & moderation records | As long as reasonably needed to resolve/enforce |
| Legal/transaction records | As required by law |
Data no longer needed is deleted, aggregated, or anonymized.
Security & Breach Notification
We use encryption in transit, access controls, row-level security, rate limiting, monitoring, and vendor security reviews. No system is 100% secure — protect your own credentials.
India-specific: Reportable cyber-security incidents are reported to CERT-In within 6 hours of detection, per IT Rules 2013/CERT-In directions. Affected users and the Data Protection Board of India are notified as required under the DPDP Act.
Your Rights (DPDP Act, 2023)
You may: access your data, correct/update/complete it, erase it (subject to legal retention needs), withdraw consent, nominate another person to exercise your rights if you die/are incapacitated, and file a grievance. We verify identity before acting and may decline requests where law permits (fraud prevention, legal retention, safety).
To exercise a right: Email privacy@thebyteplay.com — subject "BytePlay Privacy Request" — with your username, account email, and the right sought. Never send passwords or ID documents unless we request them via a secure channel.
Grievance Redressal
BytePlay is currently a small team, and privacy/grievance matters are handled directly by our founder as the designated point of contact under the DPDP Act, 2023 and the IT (Intermediary Guidelines) Rules, 2021 — rather than a separate compliance department. As we scale, this function will be formalized with a dedicated, resident Grievance Officer.
Contact: privacy@thebyteplay.com
We acknowledge grievances within 24 hours and aim to resolve within 15 days (up to 30 days for complex data-protection matters). Unresolved complaints may be escalated to the Data Protection Board of India.
International Transfers
Data may be processed in India and other countries via our service providers, subject to contractual and technical safeguards. Cross-border transfer restrictions (if any are notified by the Indian government under the DPDP Act) will be complied with.
Changes to This Policy
Material changes will be notified in-app/by email and, where required, fresh consent will be sought. The "Last Updated" date at the top of this page reflects the latest version.
Contact
Vadgaon Sheri, Pune, Pune City, Maharashtra, India, 411014