Legal

Privacy Policy

Effective date: 12 June 2026 · Last updated: 12 June 2026

1. Who we are

This Privacy Policy is issued by Spaces Neighborhood Commerce Technologies Pvt Ltd (“SPACES”, “Beyond Spaces”, “we”, “our”), the Tech Operating Company that owns and operates the SPACES platform, app and SPACES Ad Exchange. Each per-asset Spaces {Location} Hub LLP is a separate legal entity; where personal data relates to your status as a partner in such an LLP, the relevant LLP is a joint data fiduciary with us for that limited purpose.

We act as a Data Fiduciary under the Digital Personal Data Protection Act, 2023 (“DPDP Act”) of India.

2. Data we collect

  • Identity & KYC data — name, date of birth, PAN, Aadhaar reference (masked), photograph, address proof, video-KYC capture.
  • Financial & accreditation data — source-of-funds declaration, bank account details, UPI VPA, demat (where applicable), ITR snapshot or CA-certified net-worth statement.
  • Partnership records — LLP slot allocation, capital contribution, profit-share statements, RoC Form 4 filings, Deed of Assignment on P2P exit.
  • Landowner data — title deed, encumbrance certificate, parcel coordinates, JDA / master-lease terms.
  • Brand tenant data — GSTIN, FSSAI / trade licences, lease terms, in-store sensor and footfall metrics.
  • Usage data — device, IP address, app interactions, dashboard views, support tickets.

3. Purposes & legal basis

We process personal data only for the following specified purposes, on the basis of your consent or a legitimate use recognised under the DPDP Act:

  • To complete KYC, AML / CFT screening and accreditation gating before any private-placement slot under MCA Section 42 is surfaced to you.
  • To onboard you as a Designated Partner of the relevant LLP and file the statutory MCA forms (FiLLiP, Form 3, Form 4).
  • To compute and disburse the 60% partner profit share, 25% ground rent and 15% franchise fee through the escrow gateway.
  • To operate the in-app P2P marketplace, including DCF price quoting, buyer matching and Aadhaar e-Sign of the Deed of Assignment.
  • To maintain books, statutory registers, tax filings (incl. §10(2A) profit-share reporting) and audit trails.
  • To detect fraud, prevent platform abuse and meet our obligations to law-enforcement and regulators (MCA, IT Dept, FIU-IND, SEBI on SM REIT conversion).

4. Aadhaar handling

Aadhaar is used only as an offline e-KYC / e-Sign instrument through a licensed UIDAI-empanelled provider. We do not store your raw 12-digit Aadhaar number, biometric data or e-KYC XML; we retain only the masked reference and signed digital artefact required to evidence the transaction.

5. Sharing & disclosure

We share personal data only with:

  • The specific per-asset LLP in which you hold a partnership interest.
  • Statutory and regulatory authorities where required by law (MCA / RoC, Income Tax, FIU-IND, SEBI, RBI, courts and tribunals).
  • Vetted service providers under written Data Processing Agreements — escrow & payment gateway, e-Sign provider, video-KYC vendor, cloud hosting, accounting and audit firms.
  • Successors in interest in the event of a corporate reorganisation, SM REIT conversion or sale of business assets.

We do not sell personal data. We do not share KYC data with brand tenants or with other partners in your LLP beyond what statutory registers require.

6. Cross-border transfers

Personal data is primarily stored on servers located in India. Where a sub-processor operates outside India, transfers occur only to jurisdictions not restricted by the Central Government under §16 of the DPDP Act, and under contractual safeguards.

7. Retention

We retain partnership, KYC, AML and financial records for the longer of (a) the life of your partnership interest plus eight years, or (b) the minimum period mandated under the Companies Act, 2013, LLP Act, 2008, Income Tax Act, 1961 and PMLA, 2002. Usage and telemetry data is retained for up to 24 months.

8. Your rights as a Data Principal

  • Right to access and obtain a summary of your data and the processing activities.
  • Right to correction, completion, updating and erasure of inaccurate data (subject to statutory retention).
  • Right to grievance redressal — write to our Grievance Officer below.
  • Right to nominate another individual to exercise rights in the event of death or incapacity.
  • Right to withdraw consent at any time, without affecting the lawfulness of prior processing.

9. Security

We employ encryption in transit (TLS 1.2+) and at rest, role-based access controls, quarterly VAPT, segregated production environments and an audited incident-response playbook. In the unlikely event of a personal data breach, we will notify the Data Protection Board of India and affected Data Principals as required by the DPDP Act.

10. Cookies & analytics

We use strictly-necessary cookies for session, security and consent management. Optional product-analytics cookies are loaded only with your consent and can be revoked from the in-app privacy controls.

11. Children

The platform is restricted to adults (18+) and to accredited founding partners. We do not knowingly collect personal data of children. The processing of children’s data is not contemplated under our service.

12. Grievance Officer

Grievance Officer & Data Protection Officer
Spaces Neighborhood Commerce Technologies Pvt Ltd
Email: privacy@beyondspaces.in
We will acknowledge complaints within 72 hours and resolve within 30 days, as required by the DPDP Act and the Consumer Protection (E-Commerce) Rules, 2020.

13. Changes to this policy

Material changes will be notified through the app and via email at least 15 days before they take effect. Continued use of the platform after the effective date constitutes acknowledgement of the updated policy.