Official Policy
Privacy Policy
Last Updated: September 12, 2026
1. Introduction
- 1.1 Scope and Ownership:
This Privacy Policy outlines the practices, protocols, and standards governing the collection, storage, processing, transfer, and protection of personal data and sensitive personal information by Gamer Ghotu (the "Platform"), which is owned, controlled, and operated exclusively by Nikhil Punia (the "Operator"). This policy applies universally to all visitors, content consumers, community members, and users (collectively referred to as "Users" or "Customers") who access or interact with the Platform. - 1.2 Statutory and Regulatory Compliance:
This Privacy Policy is formulated, published, and maintained in strict compliance with the prevailing legal frameworks of the Republic of India, including but not limited to:- The Information Technology Act, 2000 (as amended) and the rules framed thereunder, specifically the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.
- The Digital Personal Data Protection (DPDP) Act, 2023, governing the processing of digital personal data.
- The applicable merchant compliance mandates under the Reserve Bank of India (RBI) Payment Aggregator Guidelines, via our authorized third-party payment processor, Razorpay Payment Gateway.
- 1.3 Explicit and Binding Consent:
By accessing the Platform, browsing its contents, or completing a digital service purchase, you explicitly acknowledge that you have read, understood, and unconditionally consent to the data practices, tracking, collection, and usage protocols detailed within this Privacy Policy. - 1.4 Integration of Policies:
This document operates in tandem with, and is explicitly incorporated into, the Gamer Ghotu Terms of Service and the Cancellation & Refund Policy. If you do not agree with any provision contained within this Privacy Policy, your sole and exclusive remedy is to immediately terminate your access to the Platform.
2. Data Categories & Collection Framework
- 2.1 Personally Identifiable Information (PII) Collected:
To facilitate transparent transaction tracking and maintain platform security, the Operator collects specific personal data voluntarily provided by you during the checkout process. This data is limited to:- Customer Identity Data: The legal or chosen name manually inputted by you at the time of transaction execution.
- Electronic Contact Data: Your valid email address, utilized strictly for transaction receipts, payment status confirmations, and direct customer assistance communications.
- User-Generated Content: Any optional, customized text messages or commentary voluntarily drafted and submitted by you during the service purchase process.
- Financial Transaction Metadata: The exact monetary value of the digital service fee selected by you, alongside platform-generated transaction tracking numbers.
- 2.2 Automatic Technical Logging:
When you interact with the Platform, our servers automatically capture standard network metadata to prevent fraudulent transactions and cyber threats. This includes your Internet Protocol (IP) address, browser configuration, device identifiers, and transactional timestamps. - 2.3 Absolute Exclusion of Financial Credentials:
For your maximum security and in accordance with the RBI Tokenisation and Payment Aggregator Guidelines, Gamer Ghotu does NOT collect, intercept, process, or store sensitive financial instruments on its servers. This exclusion strictly applies to:- Credit or debit card numbers, expiration dates, and Card Verification Values (CVV).
- Netbanking login credentials, corporate passwords, or transaction passwords.
- Unified Payments Interface (UPI) PINs, MPINs, or biometric authentication vectors.
- 2.4 Third-Party Processing Isolation:
All sensitive financial infrastructure, secure data entry forms, and encryption protocols are hosted and handled exclusively by our authorized payment gateway aggregator (Razorpay Payment Gateway). Your banking data passes directly through Razorpay's certified, encrypted channels and never touches or resides on our local infrastructure.
3. Data Storage Architecture & Retention Mechanisms
- 3.1 Server-Side Data Retention & Purpose:
The Operator stores your transaction records on secure, firewall-protected servers. This data consists strictly of your name, email address, service fee amount, user-generated message, and transaction status. This information is retained exclusively for:- Statutory accounting, tax compliance, and business record-keeping.
- Platform features, including live stream text integration and public community leaderboards.
- Resolving billing disputes, tracking duplicate debits, and facilitating customer assistance inquiries.
- 3.2 Client-Side (Local Browser) Storage for Convenience:
To enhance user experience on repeat visits, the Platform may utilize your browser’s local storage (such as cookies or local web storage tokens) to cache your name and email address. This mechanism operates under strict privacy boundaries:- Device Isolation: This data resides entirely within your local device partition and is never transmitted independently to our servers for marketing or profiling.
- Absolute User Control: You maintain absolute autonomy over this cached data. You can completely wipe it from your device at any time by utilizing the “Forget Me” button on our platform dashboard, or by manually clearing your web browser’s cache and site data.
- 3.3 Separation of Storage Environments:
You explicitly acknowledge that these two storage mechanisms are fundamentally independent. Client-side local storage is a non-mandatory, localized convenience feature for text autofill. Conversely, server-side storage is a secure, mandatory repository required to maintain the structural integrity and legal record of financial transactions.
4. Processing Purposes & Legal Grounds for Data Usage
The Operator processes your personal data strictly for specified, lawful purposes. By interacting with the Platform, you acknowledge that your information will be utilized under the following frameworks:
- 4.1 Transaction Processing & Gateway Reconciliation:
To authenticate, log, and structurally record your digital service fees. This includes sharing necessary data vectors with our integrated payment processors (Razorpay) to complete secure transaction handshakes and verify successful funding. - 4.2 Live-Stream Integration & Public Media Licensing:
To dynamically execute the core digital features of the Platform. This includes generating real-time on-screen stream alerts, rendering visual text overlays, updating community leaderboards, and maintaining a public "Recent Customers" index. By purchasing a digital service, you grant the Operator a non-exclusive license to display your chosen name, transaction amount, and accompanying text message in these public digital formats. - 4.3 Dispute Resolution & Customer Assistance:
To investigate, address, and formally resolve user-submitted technical tickets, unreflected debits, billing issues, or duplicate charges. This data is also used to compile objective evidence to defend against fraudulent bank chargebacks or payment gateway disputes. - 4.4 Statutory Accounting & Fiscal Record-Keeping:
To preserve structured financial logs for institutional auditing, accounting, and tax compliance under applicable Indian fiscal laws. - 4.5 Regulatory and Law Enforcement Compliance:
To fulfill mandatory verification requests, satisfy payment aggregator security guidelines, or comply with any lawful orders issued by Indian courts, statutory bodies, or law enforcement agencies under the Information Technology Act, 2000.
5. Consent for Public Display & Media Licensing
- 5.1 Explicit Consent to Broadcast:
By completing a digital service purchase on Gamer Ghotu, you provide your explicit, unambiguous, and unconditional consent for the Operator to publicly display, broadcast, and transmit specific transaction-related data vectors across the Platform. This public disclosure encompasses:- Your inputted customer or user profile name.
- Your associated YouTube profile picture, channel graphics, or avatar metadata fetched via authorized digital handshakes or APIs.
- Your voluntarily submitted custom text messages or commentary.
- The exact financial value of your processed digital service fee.
- 5.2 Distribution Channels:
You acknowledge that this information will be rendered publicly in real time across various digital mediums, including but not limited to live-stream video broadcasts, live video-on-demand (VOD) archives, automated on-screen graphic overlays, community leaderboards, and "Recent Customers" web indices hosted on third-party platforms (e.g., YouTube, Twitch). - 5.3 Anonymity and Pseudonymity Options:
The Platform respects user privacy preferences. If you do not wish for your legal identity to be broadcast publicly, your sole and complete remedy at checkout is to enter a pseudonym or anonymous moniker in the identity field prior to processing the payment. The Operator bears no liability for public disclosure if you voluntarily choose to input your real name or sensitive information. - 5.4 Irrevocable Media License:
You hereby grant Gamer Ghotu and Nikhil Punia a worldwide, royalty-free, perpetual, and irrevocable license to display, replicate, stream, and archive the aforementioned data vectors (including public YouTube assets linked during the transaction) as part of the broadcast media content without any requirement for compensation, attribution, or separate prior approval.
6. Data Retention Policy & Secure Disposal
- 6.1 Standard Retention Lifecycle:
The Operator retains your personal data—specifically your customer name, electronic contact data, user-generated messages, and associated transaction metadata—for a base period of two (2) years from the date of your last recorded interaction or transaction execution on the Platform. - 6.2 Statutory and Regulatory Extensions:
Notwithstanding the provision in Section 6.1, you explicitly acknowledge and agree that specific transactional data blocks will be retained for an extended duration if strictly required to satisfy:- Indian Fiscal and Tax Mandates: Statutory ledger maintenance under the Income Tax Act, 1961, which may require financial and accounting records to be preserved for up to seven (7) years.
- Banking and Anti-Fraud Audits: Merchant compliance and dispute resolution lookback windows enforced by our authorized payment gateway aggregators (Razorpay) and the Reserve Bank of India (RBI).
- Legal Defense Frameworks: The preservation of objective evidence to protect the Operator against ongoing or anticipated legal claims, chargeback disputes, or law enforcement inquiries.
- 6.3 Secure Data Deprecation & Anonymisation:
Upon the expiration of the applicable retention timeline, or upon the verified resolution of all statutory obligations, the Operator will securely delete your personal identifiers from all primary databases. Alternatively, the Operator reserves the right to apply irreversible data anonymisation protocols, stripping away all personally identifiable data vectors so that the remaining transactional numbers can no longer be linked to your identity. Anonymised data may be retained indefinitely for structural platform analytics.
7. Tracking Technologies, Cookies, and Analytics
- 7.1 Deployment of Cookies and Local Storage:
The Platform utilizes localized text identifiers, tracking scripts, and client-side web storage mechanisms (collectively referred to as "Cookies" and "Local Browser Storage"). These technologies are deployed strictly under two operational classifications:- 7.1.1 First-Party Essential Cookies: These are technically necessary storage tokens used to sustain vital platform architecture. This includes caching user checkout entries (such as autofill parameters for names and emails) to optimize functionality for recurring visits.
- 7.1.2 Third-Party Performance Analytics: The Platform integrates aggregate, non-personal performance monitoring instrumentation, specifically Google Analytics. These modules evaluate macro-level web usage statistics, compile traffic volumes, map standard navigational layouts, and assess system diagnostic feedback.
- 7.2 Scope of Data Collected via Analytics:
The technical vectors evaluated through our analytical services are inherently restricted to anonymized, non-personally identifiable metadata. This scope includes, but is not limited to, generalized device categories, active browser configurations, network latency metrics, unique clickstream counts, pages visited within our subdomain, and total active session durations. - 7.3 Strict Isolation and Cross-Site Tracking Prohibitions:
The Operator explicitly guarantees that no tracking tokens or script configurations deployed on Gamer Ghotu are utilized to isolate your direct legal identity, build personal commercial profiles, or trace your behavioral actions across external third-party applications or independent websites. The Platform does not process or implement behavioral tracking or targeted cross-site marketing networks. - 7.4 User Management and Opt-Out Mechanisms:
You possess absolute control over your local tracking preferences. You may, at your discretion, configure your web browser settings to block all tracking cookies, reject local storage requests, or completely clear your local device storage cache at any time. You acknowledge that restricting essential first-party cookies may disable the automated text saving and processing features built into the checkout terminal.
8. Third-Party Integrations & Data Transfers
- 8.1 Authorized Payment Gateway Aggregators:
To guarantee secure financial transactions, the Platform integrates certified, third-party payment gateway aggregators, specifically the Razorpay Payment Gateway. - 8.2 Independent Data Controller Standard:
When you initiate a digital service purchase on the Platform, you interact directly with the secure, encrypted checkout interfaces hosted by these authorized aggregators. The collection, encryption, transmission, and processing of your sensitive financial data (including card numbers, UPI vectors, and authentication codes) are controlled exclusively by Razorpay. These operations are governed strictly by their respective corporate privacy policies, merchant terms, and international PCI-DSS (Payment Card Industry Data Security Standard) frameworks. The Operator holds no data controller liability, structural oversight, or custodial responsibility for data managed within these independent banking environments. - 8.3 Non-Commercialisation of Data:
The Operator explicitly guarantees that your personal information, electronic contact details, and transaction records are never sold, leased, rented, or traded to third-party marketing firms, commercial brokers, or advertising networks under any circumstances. - 8.4 Lawful Disclosures and Legal Mandates:
We reserve the right to disclose personal data to external third parties strictly under the following legally mandated conditions:- To comply with a valid subpoena, court order, or warrant issued by a competent judicial authority or statutory law enforcement body under the Information Technology Act, 2000.
- To cooperate with regulatory investigations or banking compliance audits initiated by the Reserve Bank of India (RBI) or our gateway aggregators.
- To enforce our Terms of Service, defend against fraudulent bank chargebacks, or protect the personal safety, rights, and digital security of the Operator, the Platform, and its community members.
9. Data Principal Rights & Exercising Mechanisms
Under the Digital Personal Data Protection (DPDP) Act, 2023, you are recognized as a "Data Principal" and possess specific, legally enforceable statutory rights regarding the personal data processed by the Operator.
- 9.1 Codified Rights Portfolio:
You may exercise the following rights at any time:- 9.1.1 Right to Access & Summary: You have the right to request a digital summary of the personal data currently held about you by the Operator, along with a description of the processing activities performed.
- 9.1.2 Right to Correction and Updation: You have the right to request the immediate correction, rectification, or updating of any inaccurate, incomplete, or out-of-date personal data linked to your identity.
- 9.1.3 Right to Erasure (Deletion): You have the right to request the permanent erasure of your personal data from our primary servers. You explicitly acknowledge that this right is strictly subject to legal and regulatory overrides. The Operator is not obligated to erase data vectors that are required to satisfy statutory accounting logs, tax compliance under the Income Tax Act, 1961, or active anti-fraud lookup windows required by our payment gateway aggregators.
- 9.1.4 Right to Withdraw Consent: You maintain the right to unconditionally withdraw your consent for the processing or future public display of your customer name, YouTube graphics, or custom messages on stream alerts and leaderboards. Upon processing your withdrawal request, your future data will be entirely anonymised or hidden. Withdrawal of consent does not affect the lawfulness of processing or public broadcasts executed prior to your request.
- 9.2 Operational Procedure for Rights Enforcement:
To formally exercise any of your statutory rights, you must submit a written request via email to the Operator at ghotulabs@gmail.com. For security purposes and to prevent unauthorized identity theft, your email must include valid verification details proving that you are the true owner of the associated transaction or email address. - 9.3 Statutory Response Timelines:
The Operator will review, process, and formally respond to your verified data rights request within a maximum window of thirty (30) calendar days from the date of initial receipt, in accordance with applicable Indian digital privacy mandates.
10. Data Security Architecture & Limitation of Security Liability
- 10.1 Implementation of Reasonable Security Practices:
The Operator implements and maintains Reasonable Security Practices and Procedures (RSPP) as codified under Section 43A of the Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011. These safeguards comprise a mix of technical, administrative, and physical controls engineered to protect your personal data against unauthorized access, malicious alteration, unlawful disclosure, accidental loss, or destruction. - 10.2 Technical Safeguards Infrastructure:
Our primary data security protocols include, but are not limited to:- Transmission of all transactional metadata over securely encrypted SSL/TLS channels.
- Strict backend server firewall configurations and access-controlled database permissions.
- Complete operational separation from financial cardholder environments, ensuring zero local exposure to raw payment credentials.
- 10.3 Acknowledgement of Inherent Electronic Risks:
While the Operator employs industry-standard mechanisms to secure your data repositories, you explicitly acknowledge that no method of electronic transmission over the internet, and no system of digital storage, is completely infallible or one hundred percent (100%) secure. - 10.4 Exclusion of Liability for Third-Party Cyber Incidents:
Consequently, the Operator cannot and does not guarantee the absolute, bulletproof security of your personal data. To the maximum extent permitted by applicable law, the Operator shall not be held liable for any direct, indirect, incidental, or consequential damages resulting from an unauthorized data breach, systemic hacking event, data interception, malware injection, or third-party cyber-attack, provided the Operator has maintained the standard reasonable security practices outlined in Section 10.1.
11. Grievance Redressal Mechanism & Grievance Officer
- 11.1 Statutory Appointment:
In strict accordance with the provisions of the Information Technology Act, 2000, the rules framed thereunder, and the Digital Personal Data Protection (DPDP) Act, 2023, the Operator has designated a formal Grievance Officer to oversee data protection compliance, handle user discrepancies, and address privacy-related complaints. - 11.2 Contact Credentials:
You may direct any official grievances, complaints regarding data processing, violations of privacy, or non-compliance with these policies to the designated officer using the credentials set forth below:- Name of Officer: Nikhil Punia
- Official Email Address: ghotulabs@gmail.com
- Operational Heading: All communication must be clearly marked with the subject line: "Official Privacy Grievance – Gamer Ghotu Platform".
- 11.3 Statutory Redressal Timeline:
The Grievance Officer shall review, investigate, and systematically resolve any valid, verified grievances or data discrepancies submitted by you within a maximum statutory window of thirty (30) days from the absolute date of successful receipt of the grievance. - 11.4 Escalation Framework:
You acknowledge that you must first exhaust this internal grievance mechanism by providing the Grievance Officer with appropriate evidence and time to investigate before escalating any dispute to external regulatory bodies, consumer forums, or the Digital Personal Data Protection Board of India.
12. Amendments and Modifications to the Privacy Policy
- 12.1 Absolute Discretion to Amend:
The Operator reserves the right, at his sole, absolute, and unreviewable discretion, to update, modify, amend, alter, or replace this Privacy Policy at any time, either in whole or in part, to reflect operational modifications, structural platform changes, or evolving regulatory mandates under applicable Indian digital laws. - 12.2 Instant Publication & Revision Notice:
Any modifications executed under Section 12.1 shall become legally effective immediately upon their official publication on this specific webpage. The date of the most recent revision will be conspicuously cited at the top or bottom of this document under the "Last Updated" indicator field. - 12.3 Waiver of Individual Notification:
By utilizing the Platform, you explicitly waive any statutory or civil right to receive direct, individualized notification (such as direct emails or private system alerts) regarding minor or standard structural modifications made to this policy. - 12.4 Binding Acceptance through Continued Use:
Your continued access to, browsing of, or interaction with the Platform following the publication of any revised Privacy Policy constitutes your unconditional, explicit, and legally binding acceptance of the updated data processing practices. If you do not agree with the modified provisions, your sole, exclusive, and immediate remedy is to permanently cease all interaction with the Platform and terminate your access. - 12.5 Periodic Review Obligation:
It remains your exclusive responsibility to review this webpage periodically to preserve active awareness of how your data is collected, stored, and protected by the Operator.
13. Other Policies And Contact Info
- 13.1 Terms and ConditionsRead our Terms and Conditions
- 13.2 Shipping PolicyRead our Shipping Policy
- 13.3 Cancellation & Refund PolicyRead our Cancellation & Refund Policy
- 13.4 Contact UsContact Us at Email : ghotulabs@gmail.com