Privacy Policy
Effective date: 23 July 2026 · Last updated: 23 July 2026
This Privacy Policy explains how personal data is collected, used, disclosed and protected when you use the Drishti website at drishtisignals.in (and its subdomains) and the Drishti Android application distributed through the Google Play Store and by direct download (together, the "Service"). It applies to the website and the Android application equally, except where a section states otherwise.
- Who is responsible for your data
- Definitions
- Summary of data handling
- Data we collect
- Data we do not collect
- How we use data
- Legal basis for processing
- Cookies, SDKs and similar technologies
- Disclosure and third-party processors
- International data transfers
- Data retention
- Security
- Your rights and how to exercise them
- Children
- Third-party sites and services
- Changes to this Policy
- Contact and grievance redressal
1. Who is responsible for your data
The Service is operated by Charandeep Kapoor, an individual (the "Operator", "we", "us" or "our"), who is the data fiduciary responsible for the personal data processed through the Service.
| Operator | Charandeep Kapoor (sole operator) |
|---|---|
| Postal address | [REGISTERED / CONTACT ADDRESS: to be completed], India |
| Contact for privacy matters | charandeep.kapoor@delta.exchange |
Drishti is an independent research and information project. It is not operated by, and this Policy does not cover the practices of, Delta Exchange or any exchange, broker or third-party platform to which the Service may link. See section 15.
2. Definitions
- "Personal Data" means any data about an individual who is identifiable by or in relation to such data, as defined under the Digital Personal Data Protection Act, 2023 (the "DPDP Act").
- "Processing" means any operation performed on Personal Data, including collection, storage, use, disclosure and erasure.
- "Data Fiduciary" means the person who determines the purpose and means of Processing (here, the Operator).
- "Data Principal" means the individual to whom the Personal Data relates (here, you).
- "Processor" means a third party that Processes Personal Data on the Operator's behalf.
- "Application" means the Drishti Android application, delivered as a Trusted Web Activity (package identifier
app.drishtisignals.twa) that presents the Drishti website inside an Android wrapper.
3. Summary of data handling
The following table summarises the categories of data the Service handles. It is provided for transparency and to align with the Google Play Data Safety disclosure. Full detail follows in sections 4 to 6.
| Data category | Collected | Purpose | Shared with | Linked to your identity |
|---|---|---|---|---|
| App activity and usage (screens viewed, in-app events, session data) | Yes | Analytics, product improvement | Google Analytics, PostHog | No (pseudonymous identifiers only) |
| Device and technical data (device model, operating system, browser, language, coarse IP-derived location) | Yes | Analytics, security, compatibility | Google Analytics, PostHog, Cloudflare, Vercel | No |
| Marketing attribution data (referrer, campaign and UTM parameters, advertising identifiers, IP address) | Yes, on tap of a download or open link | Measuring which campaign led to an app install or click-through | AppsFlyer | No |
| Push notification identifier (browser or device push endpoint) | Only if you opt in to alerts | Delivering signal alerts you requested | Cloudflare (storage); Google/Apple/browser push services (delivery) | No (stored as a SHA-256 hash) |
| Name, email, phone, address, payment or financial information, trading credentials | No | Not applicable | Not applicable | Not applicable |
4. Data we collect
We do not require registration, sign-in or any manual entry of Personal Data to use the Service. We collect the following automatically or with your consent.
4.1 Usage and analytics data
We use Google Analytics 4 (measurement identifier G-HDBCTR3R3R), Google Tag Manager and PostHog to understand how the Service is used. These tools collect pseudonymous usage and device data, which may include: pages and screens viewed, links and buttons interacted with, session start and duration, referring source, approximate location derived from your IP address (typically at city or region level), device type and model, operating system, browser type and version, screen size, and language settings. This data is associated with random, tool-assigned identifiers rather than your name.
4.2 App and click attribution data
When you tap a link in the Service to download or open a third-party application, we use AppsFlyer to attribute that action to a marketing source. AppsFlyer may process your IP address, device identifiers, referrer and campaign parameters (including UTM values) for this purpose. Attribution data measures the performance of campaigns and is not used to build a personal profile of you.
4.3 Push notification data
If, and only if, you opt in to receive alerts, your browser or device generates a push subscription that includes a push endpoint (a URL provided by the browser or platform push service). We store this subscription so that we can deliver the signal alerts you requested. The endpoint is stored under a key that is the SHA-256 hash of the endpoint, in Cloudflare R2 object storage. We do not collect your name, email or phone number as part of this process. You can withdraw consent at any time by disabling notifications in the Service or your browser or device settings, or by uninstalling the Application.
4.4 Server and log data
Our hosting and content-delivery providers (Vercel and Cloudflare) automatically log standard request information, such as IP address, timestamp, requested resource, user-agent string and response status, for the purposes of delivering content, security and abuse prevention.
5. Data we do not collect
The Service does not collect, request or store: your name; email address; postal address; telephone number; date of birth; government identifiers; payment card or bank details; exchange or wallet credentials; API keys; or any content of your trading accounts. The Service does not connect to, read from, or place orders on any exchange or brokerage account. It is an information display only.
6. How we use data
- To operate, maintain and display the Service and its signal content.
- To measure and analyse usage so that we can improve reliability, performance and content.
- To measure the effectiveness of marketing and referral links.
- To deliver push alerts that you have explicitly requested.
- To protect the Service against fraud, abuse, security incidents and technical faults.
- To comply with applicable law and to enforce our Terms and Conditions.
We do not sell your Personal Data. We do not use your data for automated decision-making that produces legal or similarly significant effects on you.
7. Legal basis for processing
Where the DPDP Act applies, we Process Personal Data on the following bases:
- Consent: for push notifications and for analytics or advertising cookies where consent is required. You may withdraw consent at any time; withdrawal does not affect Processing carried out before withdrawal.
- Legitimate uses and performance of the Service: for the technical operation, security and delivery of content you request.
8. Cookies, SDKs and similar technologies
The Service uses cookies, local storage and software development kits (SDKs) to function and to gather the analytics and attribution data described above. The main technologies are:
| Technology | Provider | Purpose |
|---|---|---|
| Google Analytics 4 | Google LLC | Usage analytics |
| Google Tag Manager | Google LLC | Tag and script management |
| PostHog | PostHog, Inc. | Product analytics |
| AppsFlyer OneLink | AppsFlyer Ltd. | Install and click attribution |
| Service Worker and Web Push | Browser / platform push service | Offline caching and alert delivery (only if you opt in) |
| Theme and preference storage | Operator (first-party) | Remembering your light or dark theme choice |
You can control or delete cookies through your browser or device settings. Disabling cookies may affect some features. Where a consent banner or control is presented, your choices there govern non-essential cookies.
9. Disclosure and third-party processors
We do not sell or rent Personal Data. We share data only with the Processors that provide the infrastructure and measurement described in this Policy, and only for those purposes:
| Recipient | Role | Data handled |
|---|---|---|
| Google LLC (Analytics, Tag Manager, Play) | Analytics and app distribution | Usage and device data; app-install data via the Play Store |
| PostHog, Inc. | Product analytics | Usage and device data |
| AppsFlyer Ltd. | Attribution | Attribution and device data |
| Cloudflare, Inc. | Content delivery and object storage | Log data; hashed push endpoints |
| Vercel Inc. | Website and application hosting | Log data |
Each Processor handles data under its own privacy terms and under our instructions. We may also disclose data where required by law, court order or a lawful request from a public authority, or to protect the rights, safety or property of the Operator or others.
10. International data transfers
Several of our Processors are established outside India and may Process data on servers located outside India, including in the United States and the European Union. Where data is transferred outside India, we rely on the Processor's contractual and technical safeguards and on the transfer being permitted under applicable law. The Government of India may restrict transfers to certain countries; we will comply with any such restriction.
11. Data retention
- Analytics data is retained for the period set by each analytics provider (for Google Analytics 4, the account's configured retention window), after which it is aggregated or deleted.
- Attribution data is retained by AppsFlyer for its standard attribution windows.
- Push subscriptions are retained until you unsubscribe, until the endpoint expires or is rejected by the push service, or until you uninstall the Application, after which the stored record is removed.
- Server logs are retained for a short period for security and diagnostics.
We retain Personal Data only for as long as necessary for the purposes set out in this Policy or as required by law.
12. Security
We apply reasonable technical and organisational measures appropriate to the limited data we handle. These include serving the Service over HTTPS, storing push endpoints only in hashed form, minimising the data we collect, and relying on established Processors that maintain their own security programmes. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If we become aware of a personal data breach that is likely to result in harm, we will notify the Data Protection Board of India and affected Data Principals as required by the DPDP Act.
13. Your rights and how to exercise them
Subject to applicable law, you have the right to:
- obtain confirmation of, and access to, the Personal Data we Process about you;
- request correction, completion, updating or erasure of your Personal Data;
- withdraw a consent you previously gave;
- nominate another individual to exercise your rights in the event of death or incapacity; and
- make a grievance to us and, if unsatisfied, to the Data Protection Board of India.
To exercise any of these rights, email charandeep.kapoor@delta.exchange with your request. Because we do not hold account or contact details for you, we may be unable to identify data relating to a specific individual; in that case we will explain what is technically possible. To stop push alerts immediately, disable notifications in the Service or your device settings, or uninstall the Application. To request deletion of app-related data, email the address above and identify the Application by name (Drishti).
14. Children
The Service is intended for adults (18 years or older) and is not directed to children. Trading in crypto derivatives is not suitable for minors. We do not knowingly collect Personal Data from children. If you believe a child has provided data through the Service, contact us and we will take reasonable steps to delete it.
15. Third-party sites and services
The Service contains links to third-party websites and applications, including Delta Exchange. When you follow such a link, you leave the Service and enter a property we do not control. This Policy does not apply to those properties. We are not responsible for the content, practices or privacy policies of any third party. Review the privacy policy and terms of each third party before using it.
16. Changes to this Policy
We may update this Policy from time to time. When we do, we will revise the "Last updated" date above and, for material changes, provide a more prominent notice within the Service. Your continued use of the Service after a change takes effect constitutes acceptance of the updated Policy.
17. Contact and grievance redressal
For any question, request or grievance regarding this Policy or your Personal Data, contact:
| Name | Charandeep Kapoor |
|---|---|
| charandeep.kapoor@delta.exchange | |
| Postal address | [REGISTERED / CONTACT ADDRESS: to be completed], India |
We will acknowledge and respond to grievances within the timelines required by applicable Indian law.