Table of Contents
- Preamble: Privacy Commitment, Constitutional Grounding & Scope (Clause PP-PRE)
- Section 3.1: Information We Collect & Device Permissions (Clause PP-3.1)
- Section 3.2: How We Use & Process Platform Data (Clause PP-3.2)
- Section 3.3: Customer PII Protection & Merchant Non-Disclosure (Clause PP-3.3)
- Section 3.4: Anti-Doxxing & Confidentiality Safeguards (Clause PP-3.4)
- Section 3.5: Cookies, Local Storage & Session State (Clause PP-3.5)
- Section 3.6: Account Lifecycle, Access & Deletion Rights (Clause PP-3.6)
- Section 3.7: System Security, Anti-Scraping & API Protection (Clause PP-3.7)
- Section 3.8: Law Enforcement Warrants & Regulatory Audits (Clause PP-3.8)
- Policy Governance, Version History & Data Protection Contact
Preamble: Privacy Commitment, Constitutional Grounding & Scope (Clause PP-PRE)
P.1 Hyperlocal Commerce Mission & Privacy Custodianship
The Near Buy provides the digital and operational infrastructure connecting neighborhood consumers with verified local brick-and-mortar merchants. Hyperlocal commerce is built upon direct proximity and personal trust: neighbors buying from neighborhood shops, receiving doorstep deliveries from local couriers, and engaging in open, real-time price negotiations.
Because physical retail proximity requires sharing sensitive physical location coordinates, real-time dispatch routes, contact numbers, and payment details, privacy is not merely a legal compliance checkbox—it is the indispensable foundation of neighborhood trade. The Near Buy operates as a fiduciary custodian of user data, holding personal information under strict safeguards, minimizing data collection exclusively to what is strictly necessary to consummate transactions, and fiercely protecting every participant from unwanted surveillance, spam, doxxing, and exploitation.
P.2 Constitutional & Statutory Foundations
This Privacy, Data Protection & System Security Policy operationalizes the fundamental rights and statutory protections established under the legal framework of the People’s Republic of Bangladesh:
- Constitutional Right to Privacy (Article 43(b)): The platform upholds the sacred fundamental constitutional right of every citizen to personal privacy, family dignity, and the inviolability of their correspondence, home, and telecommunications against unauthorized surveillance, interception, or intrusion.
- Ministry of Commerce Digital Commerce Operation Guidelines (2021): Specifically Clause 3.1.11, which strictly prohibits e-commerce operators and participating sellers from leasing, selling, disseminating, or unlawfully utilizing customer personal data, telephone numbers, and buying behavior without explicit statutory authorization.
- Cyber Security Act, 2023 & ICT Act, 2006: Protecting computer systems, databases, mobile networks, and digital communications from unauthorized access, hacking, data theft, identity impersonation, and fraudulent tampering, while establishing formal legal evidentiary standards for electronic audit logs.
- Consumer Rights Protection Act, 2009: Prohibiting deceptive data collection, undisclosed commercial tracking, misleading price representations, and unauthorized manipulation of consumer choices.
- Bangladesh Telecommunication Regulation Act, 2001: Enforcing the confidentiality of telecommunication and digital packet routing across terrestrial networks.
- National Board of Revenue (NBR) Fiscal Regulations: Governing the lawful preservation and cryptographic immutability of value-added tax invoices, sales receipts, and commercial payment ledgers for mandatory statutory audit periods.
P.3 Foundational Data Protection & Fiduciary Principles
Every data processing activity executed across The Near Buy is guided by six globally benchmarked data protection tenets:
- Lawfulness, Fairness & Transparency: Personal data is collected only with valid legal justification, under clear statutory grounds, and with complete upfront disclosure to the individual.
- Purpose Limitation: Information collected for marketplace discovery, price bargaining, order fulfillment, and dispute settlement is never repurposed for secondary objectives without explicit consumer consent.
- Data Minimization: The platform restricts collection strictly to data points indispensably required to operate the service. If a feature can operate with generalized district or neighborhood data, precise geographic coordinates are neither requested nor retained.
- Accuracy & Correction: Both buyers and merchants retain continuous rights to inspect, update, and rectify inaccuracies in their personal and commercial profile records.
- Storage Limitation: Information is retained only for the duration necessary to satisfy commercial fulfillment, ongoing customer warranties, dispute resolution windows, or statutory tax audit rules, following which it is permanently purged or cryptographically anonymized.
- Integrity & Confidentiality (Security): All digital assets, communication streams, and databases are protected by multi-layered technical controls, row-level authorization boundaries, cryptographic encryption in transit and at rest, and continuous intrusion monitoring.
P.4 Universal Scope of Applicability
This Policy governs all individuals, commercial entities, and automated services interacting with The Near Buy, including:
- Consumers & Buyers: Registered members and authenticated users browsing storefronts, initiating bargain offers, placing orders, communicating with sellers, and publishing customer feedback.
- Verified Merchants & Shop Personnel: Sole proprietors, corporate retail entities, shopkeepers, stall managers, and staff accessing merchant dashboard consoles, managing product catalogs, receiving customer orders, and fulfilling sales.
- Independent & Store Couriers: Delivery personnel and transport agents receiving localized route and customer dispatch information to execute doorstep deliveries.
- Marketplace Visitors: Unauthenticated individuals accessing public web storefronts, product catalogs, and informational pages.
- Authorized Third-Party Service Providers: Integrated cloud infrastructure hosts, payment gateways, SMS notification dispatchers, and verification partners contracted to perform operational services on behalf of the platform.
The Near Buy makes an absolute, irrevocable legal covenant: We do not sell, rent, monetize, trade, or lease user personal information, phone numbers, location traces, or shopping histories to data brokers, third-party marketing networks, or behavioral advertising platforms under any circumstances.
Platform revenue is generated exclusively through legitimate marketplace services, verified merchant subscriptions, transparent transaction processing commissions, and platform-native commercial tools. We view customer and merchant data as a sacred trust, not an inventory asset to be exploited.
To deliver a secure, responsive, and legally compliant neighborhood commerce experience, The Near Buy collects specific categories of personal, commercial, and technical information. In adherence to our Data Minimization commitment, information is collected solely when relevant to marketplace transactions.
When individuals register, browse, interact, and purchase on The Near Buy, we collect:
- Account Identity Credentials: Full legal or display name, verified primary mobile phone number, valid email address, account password (stored exclusively via irreversible one-way cryptographic hashing with unique salt salts), and optional profile photography.
- Delivery & Physical Location Coordinates: Neighborhood name, thana, district, postal code, street address, building number, floor/apartment details, and identifiable local landmarks provided to facilitate physical courier delivery or in-store collection.
- Order & Transaction Data: Basket and cart selections, historical order records, order quantities, negotiated final prices, selected payment methods (Cash-on-Delivery or digital gateway channels), delivery dispatch preference, invoices, and payment confirmation receipts.
- Customer Communications & Feedback: Content shared during buyer-merchant in-app messaging, interactive price bargaining counter-offers, product ratings, written reviews, uploaded review photographs or videos, customer support inquiries, and dispute claim documentation.
- Cryptographic Handshake Verification: The generation and presentation of 8-digit Cash Confirmation QR codes and cryptographically signed Return/Exchange tokens utilized during in-person physical handovers.
3.1.2 Commercial, Regulatory & Identity Credentials Collected from Merchants
To maintain consumer protection and satisfy the Ministry of Commerce Digital Commerce Operation Guidelines 2021, commercial sellers must undergo rigorous onboarding verification. From merchants, we collect:
- Proprietor & Director Identity: Government-issued National Identity Card (NID) details, legal name, date of birth, residential address, biometric identity verification status, and contact phone numbers of the business owner or authorized legal representative.
- Statutory Business Documentation: Scanned copies and registration numbers of valid Municipal Trade Licenses, 13-digit Business Identification Numbers (BIN / VAT registration) issued by the National Board of Revenue, and registered Unique Business Identification (UBID) records.
- Storefront & Physical Premises Data: Official registered business name, commercial trade name, physical retail shop address, market or shopping complex name, stall or shop room number, GPS geographical coordinates of the physical establishment, shop banner imagery, and operating hours.
- Financial Settlement & Payout Details: Designated commercial bank account credentials (bank name, branch routing number, account title, and account number) or registered institutional Mobile Financial Services (MFS) merchant account numbers (such as bKash, Nagad, or Rocket) necessary to disburse digital wallet escrow balances.
- Product Catalog Data: Product titles, non-food category classifications, pricing structures, minimum floor bargaining thresholds, inventory quantities, manufacturer serial identifiers, BSTI certification seals, and packaging specifications.
When users navigate the platform’s digital applications and web interfaces, our systems automatically log technical and operational records:
- Network & Connectivity Identifiers: Internet Protocol (IP) address, approximate geographic location deduced from IP routing, Internet Service Provider (ISP), and telecommunication carrier network indicators.
- Device & Hardware Information: Device manufacturer, hardware model, operating system version, browser family, screen resolution, preferred language settings, and unique mobile application instance identifiers.
- Session & Behavioral Telemetry: Access timestamps, page interaction durations, navigation pathways, search queries entered, filter parameters applied, storefront views, and application error crash logs.
- Security & Audit Logs: Authentication attempts, multi-factor verification events, password resets, suspicious rate-limiting breaches, administrative actions, and anti-fraud risk indicators.
3.1.4 Mobile Device Hardware & Operating System Permissions
The Near Buy mobile application requests access to hardware components strictly on an as-needed basis. Each permission is requested dynamically at the point of feature activation, accompanied by an explicit on-screen explanation. Users retain the right to grant, restrict, or revoke these permissions at any time via device operating system settings:
| Device Permission |
Operational Justification & Usage Scope |
User Choice & Fallback Mechanism |
| Precise Geolocation (GPS / Network) |
Used exclusively to identify neighborhood shops within active delivery distance, calculate accurate courier delivery transit fees, and display nearby stores. The platform does not track user location in the background when the application is closed. |
Optional: Users may deny GPS access and manually select their neighborhood, thana, or city from an administrative geographic dropdown. |
| Camera Access |
Activated only when the user voluntarily captures a photo or video to upload a profile avatar, document a physical product defect for a return claim, scan a merchant’s pickup QR code, or photograph physical inventory for listing. |
Optional: Users may choose not to use real-time camera capture and instead select existing pre-captured images from their stored photo gallery. |
| Photo Library & Storage Access |
Required solely to attach images or documents when submitting product reviews, attaching damage evidence in the dispute resolution center, or uploading merchant business licenses during onboarding. |
Optional: If denied, media upload features will remain unavailable, but standard text browsing and ordering remain fully functional. |
| Push Notifications |
Deployed to deliver critical, time-sensitive transactional alerts: merchant order confirmations, courier dispatch milestones, incoming bargaining counter-offers, dispute status updates, and critical account security warnings. |
Configurable: Users can toggle operational notifications and promotional updates on or off within application notification settings. |
3.1.5 Integration Data from Third-Party Service Providers
The Near Buy collaborates with specialized, highly regulated third-party infrastructure providers to execute specialized operations:
- Payment Gateways & Mobile Financial Services (MFS): When paying online via debit/credit cards, internet banking, or digital wallets (such as bKash, Nagad, or Stripe-powered rails), payment card credentials and PINs are processed directly by Bangladesh Bank-licensed payment gateways adhering to PCI-DSS Level 1 compliance. The Near Buy never receives, logs, or stores full credit card numbers, CVV security codes, or MFS secret PINs. We receive only an anonymized transaction authorization token, transaction reference identifier, and payment status confirmation.
- Telecommunication SMS Gateways: Mobile phone verification, One-Time Passwords (OTPs), and security notices are transmitted through licensed telecommunication aggregators. These aggregators receive only the recipient’s phone number and the automated template text required for immediate transmission.
- Cloud Infrastructure & Database Hosts: Encrypted database hosting, secure object storage, and real-time state synchronization are maintained through enterprise-tier cloud infrastructure providers adhering to ISO/IEC 27001, SOC 2 Type II, and global data confidentiality standards.
3.1.6 Children’s Privacy & Age-Restricted Marketplace Eligibility
The Near Buy is a commercial trading platform that facilitates legally binding contracts of sale, financial escrow settlements, and physical neighborhood handoffs.
In accordance with the Contract Act, 1872, the platform is exclusively designed for, and directed to, individuals who are at least eighteen (18) years of age and possess full legal capacity to enter into binding agreements.
- Strict Prohibition for Minors: Individuals under eighteen (18) years of age are strictly prohibited from creating merchant accounts, listing goods, or initiating commercial transactions independently. Minor dependents may make purchases only under the direct supervision, consent, and registered account of a parent or legal guardian.
- Zero Collection of Children’s Data: We do not knowingly solicit, process, or retain personal information from children under the age of thirteen (13).
- Expedited Deletion Protocol: If platform administrators discover, or are notified by a parent or guardian, that personal information belonging to an underage child has been inadvertently collected, the platform will immediately deactivate the account, quarantine all associated communications, and permanently expunge the underlying records from active production databases within seventy-two (72) hours.
The Near Buy processes collected information solely for legitimate operational, commercial, regulatory, and security purposes directly connected to facilitating neighborhood trade. In accordance with our Core Fiduciary Principles, we never process personal data in ways incompatible with the purposes disclosed below.
3.2.1 Core Marketplace Operations & Commercial Fulfillment
We process personal and transactional data to execute essential marketplace functions:
- Neighborhood Discovery, Search & Storefront Matching: Processing user-selected neighborhood districts, thanas, or approximate geographic coordinates to present nearby verified merchant storefronts, locally stocked non-food retail inventory, accurate physical distances, and real-time shop operating hours.
- Order Lifecycle & Fulfillment Coordination: Transmitting itemized order baskets to selected merchants, confirming item availability against current shelf stock, enforcing the mandatory merchant 60-minute order acceptance SLA, and scheduling delivery or customer pickup appointments.
- Interactive Price Negotiation Engine: Transmitting real-time bargaining proposals and counter-offers between buyers and merchants, validating submitted offers against merchant-established floor price rules, and legally cementing the agreed transaction price upon mutual bilateral confirmation.
- Digital Escrow Custodianship & Merchant Settlement: Maintaining double-entry escrow balances, calculating transparent platform service commissions, reconciling Cash-on-Delivery (COD) collections, and disbursing net sales proceeds to verified merchant bank or Mobile Financial Services (MFS) accounts.
- Physical Handshake Authentication: Generating, transmitting, and validating cryptographically secured 8-digit Cash Confirmation QR codes and return authorization tokens during in-person doorstep deliveries and store pickups.
Under the statutory framework of Bangladesh and internationally recognized data governance standards, every processing activity conducted by The Near Buy is anchored in a recognized lawful basis:
- Contractual Necessity: Processing essential to enter into or perform our commercial agreement with users, including account registration, order processing, delivery routing, payment reconciliation, and dispute management.
- Statutory & Regulatory Compliance: Processing and retaining records required to satisfy the Ministry of Commerce Digital Commerce Operation Guidelines 2021, tax invoice preservation mandates of the National Board of Revenue (NBR), consumer complaint records under the Consumer Rights Protection Act 2009, and electronic evidentiary rules under the Cyber Security Act 2023.
- Legitimate Operational Interests: Processing required to safeguard platform infrastructure, verify commercial authenticity, prevent spam and abuse, evaluate aggregated performance metrics, and resolve technical anomalies.
- Affirmative User Consent: Processing that relies on voluntary user choices, including optional promotional notifications, voluntary participation in platform surveys, or profile customization.
Maintaining a secure and trustworthy marketplace requires proactive automated heuristics and human administrative oversight:
- Financial Fraud & Payment Protection: Monitoring transaction velocity, suspicious payment patterns, unauthorized payment reversals, and high-risk orders to intercept financial fraud, stolen payment card usage, and money-laundering attempts under the Money Laundering Prevention Act, 2012.
- Merchant Integrity & SLA Monitoring: Evaluating merchant operational metrics—including order acceptance latency, unprovoked order cancellation rates, counterfeit allegations, customer dispute frequency, and delivery SLA compliance—to protect consumers from deceptive trade practices.
- Abuse Prevention & Account Security: Detecting and preventing bot scraping, unauthorized credential stuffing, multi-account manipulation, review astroturfing, fake damage claims, and off-platform payment diversion attempts.
We utilize transaction records, communication transcripts, and user-submitted documentation to ensure equitable customer support and fair dispute outcomes:
- Multi-Step Return & Refund Resolution: Processing and evaluating customer-uploaded photographic or video evidence of alleged product damage or specification mismatches, reviewing merchant inspection reports, and executing automated escrow refund releases or replacement dispatches.
- Neutral Administrative Mediation: Enabling authorized platform support personnel and dispute mediators to examine chronological transaction audit logs, in-app messaging transcripts, and physical delivery timestamps when buyers and merchants fail to resolve a dispute amicably.
- Audit-Trail Preservation: Maintaining immutable, tamper-evident audit logs of customer support interactions, ticket statuses, and administrative decisions to satisfy due process standards.
The platform maintains a strict operational distinction between essential service notices and optional marketing communications:
- Mandatory Transactional Communications (Non-Opt-Out): To ensure transaction safety and commercial integrity, users receive automated transactional notifications via SMS, mobile push alerts, or email. These include mobile phone verification OTPs, order confirmation receipts, courier dispatch updates, interactive bargaining counter-offers, return claim milestones, and critical account security notices. Because these communications are indispensable to the execution of orders and account security, users cannot opt out of transactional messages.
- Optional Promotional Communications (Strictly Opt-In): The Near Buy may occasionally distribute promotional neighborhood store spotlights, seasonal discounts, or platform news. Promotional communications are delivered exclusively to users who affirmatively elect to receive them. Users retain the unrestricted right to opt out of marketing communications at any time via account notification preferences or the direct unsubscribe link provided in any promotional message.
3.2.6 Aggregation, Statistical Analysis & De-Identification
To improve platform performance, optimize neighborhood delivery efficiency, and understand macro-level retail trends:
- Statistical Insights: The platform aggregates operational and interaction telemetry into anonymized statistical summaries, such as neighborhood product category demand indices, peak shopping hours, and average delivery transit times across various thanas.
- Strict Irreversibility Standard: All aggregated statistical datasets are stripped of personal identity records, verified phone numbers, device tokens, and precise geographic coordinates. Aggregated statistical data is rendered permanently anonymous such that no insight can be reverse-engineered or linked back to any identifiable natural person or commercial entity.
Section 3.3: Customer PII Protection & Merchant Non-Disclosure (Clause PP-3.3)
In a hyperlocal marketplace where physical storefronts and neighborhood residents interact directly, protecting consumer Personally Identifiable Information (PII) from commercial misuse, off-platform harvesting, and unauthorized solicitation is paramount. This Section establishes legally binding confidentiality covenants applicable to all verified merchants, stall operators, commercial vendors, and logistics couriers operating on The Near Buy.
3.3.1 Need-to-Know Principle & Limited Data Exposure
Merchant access to consumer personal information is strictly governed by the operational principle of least privilege:
- Pre-Acceptance Stage: When an order is initially routed to a merchant, the merchant dashboard displays only the itemized product list, requested quantities, delivery preference (doorstep courier or in-store collection), and general destination neighborhood or thana. Customer full names, building addresses, and phone numbers remain masked.
- Active Fulfillment Window: Upon affirmative order acceptance within the mandatory 60-minute Service Level Agreement (SLA), the merchant is granted temporary visibility of the recipient’s delivery name, delivery street address, and active communication channel strictly to package the merchandise, generate physical delivery slips, and coordinate courier dispatch.
- Post-Fulfillment Masking: Once an order is successfully completed, confirmed via the 8-digit Cash Confirmation QR code, or concluded following a return inspection, active access to customer contact details automatically expires. Historical merchant sales records display only itemized transaction values, order timestamps, and anonymized order reference codes.
3.3.2 Absolute Prohibition on Secondary Databases & Data Harvesting
Consumer contact information is provided exclusively as a temporary transactional utility, not a transferable commercial asset. Merchants and their personnel are strictly prohibited from:
- Compiling Secondary Directories: Copying, transcribing, downloading, screen-capturing, or manually harvesting customer phone numbers, residential addresses, or order histories into local notebooks, digital spreadsheets, private contact lists, third-party software, or external Customer Relationship Management (CRM) databases.
- Data Resale & Commercial Sharing: Selling, renting, licensing, bartering, or distributing customer contact lists, purchasing behavior, or delivery coordinates to any external merchant, advertising agency, marketing network, or third party under any circumstances.
- Handling of Physical Delivery Labels: Any physical invoices, dispatch waybills, or packaging labels containing customer names, phone numbers, or delivery addresses must be handed directly to the authorized delivery courier or consumer. Discarded packaging slips, misprinted labels, or scrap receipts must be cross-cut shredded immediately. Maintaining physical binder archives of customer phone numbers or delivery addresses on shop premises is strictly prohibited.
In accordance with Clause 3.1.11 of the Digital Commerce Operation Guidelines 2021, customer information obtained through marketplace operations must never be repurposed for independent marketing or off-platform solicitation:
- Prohibited Marketing Channels: Merchants are explicitly forbidden from utilizing customer phone numbers acquired through the platform to initiate unsolicited WhatsApp messages, SMS broadcast campaigns, automated robocalls, direct telemarketing calls, Viber/Telegram messages, or social media friend/connection requests.
- Prohibition of Off-Platform Transaction Diversion: Merchants may never contact a consumer via phone or messaging to solicit off-platform transactions, propose private cash settlements to bypass platform escrow fees, offer unauthorized offline discounts, or demand payment transfers to personal mobile financial services (bKash/Nagad) wallets. Bypassing platform escrow rails forfeits all transaction protections, guarantees, and dispute resolution coverage, and constitutes criminal consumer deception under Section 44 of the Consumer Rights Protection Act, 2009.
- Channel Exclusivity: All pre-sale inquiries, interactive bargaining negotiations, order coordination, and post-delivery dispute communications must be conducted exclusively through the platform’s monitored in-app messaging and resolution center interfaces.
3.3.4 Physical & Logistics Courier Confidentiality Obligations
Delivery personnel—whether store-employed delivery staff, neighborhood transport riders, or independent couriers—serve as trusted physical conduits of neighborhood commerce. They are bound by strict non-disclosure rules:
- Permissible Contact Scope: Couriers may initiate contact with a customer via voice call or SMS strictly during active delivery transit, and solely for essential logistical coordination (e.g., verifying landmark directions, requesting gate entry clearance, or announcing physical arrival at the doorstep).
- Prohibited Courier Conduct: Couriers are strictly prohibited from:
- Saving customer telephone numbers, full names, or apartment details into their personal smartphone address books.
- Initiating social, personal, romantic, or non-commercial communications with customers before, during, or after delivery completion.
- Disclosing or discussing customer delivery addresses, building access details, or order contents with neighbors, building security personnel, or third parties.
- Returning to a customer’s private residence or doorstep for any non-official reason following order handoff.
- Field Verification Verification Handshake: Couriers must complete handovers strictly through the physical verification of the recipient’s 8-digit Cash Confirmation QR code and may never demand additional personal identification, phone verification, or paper signature slips once the cryptographic token is successfully scanned.
3.3.5 Merchant Vicarious Liability & Employee Safeguards
Under the legal doctrine of vicarious liability and the Contract Act, 1872, the registered business proprietor or verified trade license holder is directly and legally responsible for the conduct of all shop personnel:
- Scope of Liability: Merchants are fully answerable for any data breach, customer harassment, unauthorized marketing broadcast, or doxxing incident committed by store managers, sales clerks, family assistants, or employed couriers operating under their merchant account credentials.
- Premises & Terminal Security: Merchants must implement robust operational safeguards on shop premises:
- Store dashboard terminals, shared computers, and merchant mobile devices must be password-protected and never left unattended in publicly accessible areas of the store.
- Merchant dashboard login credentials must never be shared with temporary or unverified staff.
- Upon employee termination or reassignment, the merchant must immediately rotate account passwords and revoke physical access to merchant operational tools.
The Near Buy actively enforces merchant data confidentiality through automated anomaly detection, post-delivery customer satisfaction surveys, and administrative compliance audits:
- Four-Tier Enforcement Ladder for Data Breaches:
- Tier 1 (First Minor / Inadvertent Infraction): Immediate formal compliance reprimand, compulsory written certification of deletion of harvested contact lists, and a 14-day suspension of in-app messaging capabilities.
- Tier 2 (Repeat Unsolicited Contact / Unapproved Marketing): 30-day temporary suspension of the merchant storefront, freezing of promotional balance disbursements, and mandatory retraining on customer privacy standards.
- Tier 3 (Willful Data Harvesting / Off-Platform Payment Diversion): Indefinite storefront deactivation, forfeiture of platform escrow privileges, and revocation of verified merchant badges.
- Tier 4 (Severe Commercial Exploitation / Stalking / Data Resale): Permanent expulsion of the proprietor, partners, and corporate entity from The Near Buy platform, permanent blacklisting of associated National ID (NID) and Trade License credentials, and forfeiture of all pending promotional reserves.
- Statutory Referral to Law Enforcement: In cases involving persistent harassment, stalking, extortion, or the unauthorized sale of customer directories, The Near Buy will immediately refer the offending merchant and all supporting audit logs to the Directorate of National Consumer Rights Protection (DNCRP) under Section 50 of the Consumer Rights Protection Act, 2009, and lodge a formal cybercrime report with the Cyber Crime Investigation Division of the Bangladesh Police under the Cyber Security Act, 2023.
Section 3.4: Anti-Doxxing & Confidentiality Safeguards (Clause PP-3.4)
In neighborhood commerce, transactions occur within close physical proximity. While proximity creates convenience, it also heightens the risk of personal exposure if disputes arise. The Near Buy enforces an uncompromising zero-tolerance policy against doxxing, retaliatory public disclosure, online shaming, and the weaponization of personal data. Every platform participant is entitled to absolute confidentiality regarding their private life, residential coordinates, and commercial communications.
3.4.1 Legal Definition & Zero-Tolerance Doxxing Prohibition
Under this Policy, Doxxing is defined as the intentional, non-consensual, malicious, or retaliatory publishing, broadcasting, leaking, or disseminating of an individual’s Personally Identifiable Information (PII) to any public or third-party forum.
- Protected Data Attributes: Prohibited disclosures include real legal names, personal mobile telephone numbers, home or apartment addresses, building nameplates, landmark descriptions, workplace locations, family member identities, photographic likenesses captured without consent, private correspondence, and financial payment records.
- Statutory Grounding: Doxxing represents a severe violation of Article 43(b) of the Constitution of Bangladesh (guaranteeing the privacy of the home and correspondence), constitutes actionable cyber harassment and unauthorized disclosure under the Cyber Security Act, 2023, and violates Sections 499, 500, and 506 of the Penal Code, 1860 (governing criminal defamation and criminal intimidation).
Commercial disputes, delayed deliveries, or critical customer reviews must be addressed strictly through authorized platform resolution channels. The platform strictly prohibits:
- Merchant Retaliatory Shaming: A merchant may never publish, share, or threaten to expose a customer’s name, telephone number, residential address, or order history in response to a critical 1-star review, a disputed bargain negotiation, or an initiated product return claim.
- External Social Media Broadcasting: Users and merchants are strictly forbidden from posting transaction disputes, customer contact details, courier identities, or storefront private records onto third-party social media platforms, including Facebook community groups, neighborhood forums, WhatsApp group chats, TikTok, or YouTube.
- Consumer Retaliatory Attacks: Buyers may never publish the private residential address, personal mobile phone number, family details, or private financial records of a merchant proprietor or shop employee. Legitimate consumer grievances must be submitted through the platform’s dispute resolution center or the statutory Directorate of National Consumer Rights Protection.
- Incitement to Vigilantism: Calling for community boycotts, mob harassment, in-person intimidation at a merchant’s shop, or physical confrontations at a consumer’s home constitutes a severe criminal breach resulting in immediate platform debarment and police referral.
3.4.3 Confidentiality of In-App Messages, Bargaining Dialogs & Financial Records
All bilateral communications conducted across The Near Buy are private, confidential, and legally protected:
- In-App Messaging & Bargaining Transcripts: Chat logs, voice recordings, bargaining offers, price counter-proposals, and return claim discussions between buyers and merchants are confidential commercial records. Capturing screenshots or video recordings of private in-app conversations and publishing them on public websites, social media, or public review forums without the prior written consent of all involved parties is strictly banned.
- Financial & Banking Records: Payment authorization tokens, Mobile Financial Services (bKash/Nagad/Rocket) transaction identifiers, bank deposit slips, digital wallet escrow balances, and settlement ledger summaries are sensitive financial instruments. Publishing or leaking any party’s banking details, payment slips, or wallet balances to third parties or public forums is strictly prohibited.
3.4.4 Courier Privacy & Protection from Public Blacklisting
Field logistics couriers and delivery riders operate in public neighborhoods and face distinct personal safety and privacy risks:
- Prohibition on Courier Harassment & Unauthorized Filming: Consumers and merchants may not record, photograph, or film delivery couriers without their voluntary, affirmative consent. Filming couriers to publicly humiliate, mock, or blame them for transit delays, traffic congestion, or damaged manufacturer packaging on social media is strictly prohibited.
- Protection of Courier PII: Posting a courier’s personal mobile number, personal photograph, motorcycle/bicycle registration plate, or national ID details online is treated as an aggravated doxxing offense.
- Prohibition of Off-Platform Courier Blacklists: Merchants, courier agencies, and independent riders are strictly prohibited from compiling, maintaining, or participating in informal off-platform registries or blacklist groups (e.g. social media groups or messaging chats) that share customer phone numbers or delivery coordinates labeled as “difficult customers,” “bargainers,” or “return abusers.”
3.4.5 Public Review & Feedback Space Safeguards
The platform’s public review and feedback features (“On Your Mind”) are dedicated solely to evaluating product quality and commercial fulfillment. Public review submissions and merchant responses must remain free of private PII:
- Strictly Prohibited Review Elements: Public product reviews, star ratings, and merchant responses must never contain:
- Personal telephone numbers, email addresses, or external hyperlinks.
- Specific street addresses, building numbers, apartment door numbers, or photographs of private residential entryways.
- Screenshots of private in-app chat dialogues, SMS threads, or WhatsApp exchanges.
- Banking records, mobile financial service transaction IDs, or payment receipts.
- Personal allegations, defamatory insults, or commentary regarding a merchant’s or consumer’s family, religious faith, ethnicity, or private life.
- Automated Screening & Pre-Publication Suppression: The platform deploys automated text-filtering heuristics to scan all incoming reviews and merchant responses. Any submission containing telephone number sequences, email formats, street address keywords, or profanity is automatically blocked from publication and routed to administrative compliance moderators for review and sanitization.
3.4.6 Emergency Takedown Protocol & Criminal Legal Prosecution
The Near Buy maintains a proactive, rapid-response protocol to protect victims of doxxing and private data exposure:
- Two-Hour Emergency Takedown SLA: Platform compliance officers operate a 24/7 emergency incident queue. Upon receiving a verified report or detecting unauthorized personal data published anywhere within the platform’s digital ecosystem, the offending content will be permanently removed or redacted within two (2) hours of verification.
- Jurisdiction Over Off-Platform Doxxing: If a merchant or buyer publishes doxxed information on external social networks (such as Facebook or YouTube) regarding a transaction that originated on The Near Buy, the platform exercises its full administrative authority to impose commercial sanctions—including immediate storefront deactivation and permanent account bans—regardless of where the external disclosure occurred.
- Account Sanctions & Asset Forfeiture: Any verified act of doxxing results in immediate Tier 4 platform termination, permanent revocation of merchant verification, freezing of promotional balances, and permanent blacklisting of associated National ID (NID), Trade License, and device identifiers.
- Preservation of Forensic Evidence & Statutory Referral: In all verified doxxing incidents, The Near Buy preserves cryptographically signed electronic audit logs, IP connection histories, and communications records in tamper-evident storage. We provide full evidentiary dossiers to the victim and immediately notify the Cyber Crime Investigation Division of the Bangladesh Police and the Criminal Investigation Department (CID) for formal criminal prosecution under Sections 17, 18, and 24 of the Cyber Security Act, 2023.
Section 3.5: Cookies, Local Storage & Session State (Clause PP-3.5)
To provide a secure, efficient, and personalized neighborhood marketplace experience, The Near Buy utilizes standard client-side storage technologies across its web portals and mobile applications. In accordance with our Core Fiduciary Principles, we maintain absolute transparency regarding the technical purpose, operational scope, and lifespan of all stored data.
3.5.1 Technological Scope & Architectural Overview
When users access The Near Buy, small data files and cached tokens may be placed on their device or browser:
- HTTP Cookies: Compact text strings transmitted between our web servers and the user’s browser, stored locally to maintain state across page navigations.
- Modern Web Storage (Local Storage & Session Storage): High-capacity, client-side web storage mechanisms allowing the application to persist interface preferences and transactional states without transmitting data with every server request.
- Mobile Application Sandbox Storage: Secure device-level keychains and sandboxed application cache partitions maintained within iOS and Android operating systems to enable offline resiliency, authentication persistence, and real-time push notification routing.
3.5.2 Strictly Necessary Operational & Security Storage
These technologies are indispensable to the core functionality of the marketplace and cannot be deactivated without rendering the service inoperable:
- Authenticated Session Management: Encrypted authentication tokens that verify user identity as they navigate between storefronts, view product catalogs, and access account dashboards, eliminating the need to re-enter credentials upon every page request.
- Cryptographic Anti-Tampering & CSRF Protection: Cryptographically signed security tokens embedded in web forms and transaction requests to prevent Cross-Site Request Forgery (CSRF), clickjacking, and unauthorized automated script submissions.
- Cart & Checkout State Persistence: Client-side storage preserving selected items, chosen quantities, delivery preferences, and coupon entries during active shopping sessions or intermittent network disconnections.
- Interactive Bargaining State: Real-time caching of active price counter-offers, merchant response countdown timers, and negotiation dialogs to prevent loss of state during browser navigation.
- Offline Handshake Resiliency: Secure local caching of generated 8-digit Cash Confirmation QR codes and Return authorization tokens, ensuring codes can be displayed and verified during doorstep deliveries even in areas with weak cellular network reception.
3.5.3 Interface Preferences & Localized State
These storage mechanisms enhance user convenience and eliminate redundant configuration across visits:
- Language & Localization: Storing user preferences between Bengali (Bangla) and English to ensure the interface renders in the chosen language.
- Display & Visual Theme: Retaining user display choices, such as dark mode, light mode, or system-matching contrast settings.
- Geographic Filtering & Neighborhood Memory: Remembering the user’s preferred district, thana, or neighborhood market area to automatically prioritize relevant nearby shops and local inventory upon subsequent visits.
To maintain high technical availability, detect software defects, and optimize loading speeds:
- Performance Diagnostics: Measuring real-world page load times, image rendering latencies, and server response times to identify technical bottlenecks across different Internet Service Providers and telecommunication carriers.
- Error Reporting & Crash Telemetry: Logging client-side script exceptions, failed network calls, or rendering failures to enable platform engineers to troubleshoot and deploy rapid software patches.
- Aggregated Traffic Trends: Evaluating aggregate visitor volumes, popular search terms, and general navigation flows across platform categories. All telemetry is aggregated anonymously and is never tied to identifiable natural persons.
3.5.5 Explicit Ban on Third-Party Ad Trackers & Retargeting Pixels
The Near Buy operates under an uncompromising Clean Web Architecture:
- Zero Third-Party Advertising Trackers: The platform does not host third-party advertising cookies, cross-site surveillance beacons, or commercial retargeting pixels (such as cross-web tracking scripts operated by external ad brokers).
- No Cross-Site Surveillance: We never track user activity, searches, or browsing behaviors across external websites or non-platform services.
- Zero Commercial Fingerprinting: We do not compile hardware device fingerprints, canvas hashes, or cross-device identifiers to sell or monetize user profiles with commercial marketing networks or data syndicates.
3.5.6 Retention Lifecycles & User Management Controls
The duration for which client-side storage remains on a user’s device is strictly bounded:
- Storage Lifespans:
- Session Storage: Automatically wiped immediately when the user closes their browser tab or logs out of their active session.
- Authentication Cookies: Maintained for the duration of the active login session or until explicit logout, expiring automatically after a prescribed period of inactivity.
- Preference Storage: Retained for up to ninety (90) days to preserve interface selections, after which it is renewed upon subsequent user visits.
- User Disablement Rights & Browser Controls:
- Users retain full autonomy to inspect, block, or delete cookies and web storage at any time via web browser settings (such as Google Chrome, Apple Safari, Mozilla Firefox, or Microsoft Edge) or through mobile device operating system application settings.
- Important Operational Notice: Disabling or blocking strictly necessary functional cookies will impair core marketplace operations. Users will be unable to log in, maintain cart items across pages, submit bargaining offers, or execute secure checkout flows without functional session storage enabled.
Section 3.6: Account Lifecycle, Access & Deletion Rights (Clause PP-3.6)
The Near Buy is committed to providing users with total sovereignty over their personal data. We recognize that individuals must have clear, accessible, and legally enforceable mechanisms to inspect, rectify, export, and permanently erase their digital footprint. This Section defines the procedures governing data access, account deactivation, permanent deletion, and the statutory boundaries governing fiscal and regulatory record retention under Bangladesh law.
3.6.1 Statutory Data Subject Rights (Access, Rectification & Portability)
Every registered buyer, merchant, and courier on The Near Buy maintains fundamental rights regarding their personal data:
- Right of Inspection & Access: Users may at any time inspect their registered personal identity credentials, active delivery addresses, historical transaction records, order statuses, product reviews, and customer service ticket histories through their account dashboard.
- Right to Rectification: If personal data is inaccurate, obsolete, or incomplete, users may immediately update their profile details, phone numbers, or delivery locations. Verified merchants may update business details or submit updated municipal trade licenses and tax certificates through the merchant verification console.
- Right to Data Portability: Upon identity verification, registered users may request an electronic copy of their personal account information, purchase histories, and communication records in a structured, commonly used, and machine-readable format. Data portability requests are processed by the platform privacy team within thirty (30) calendar days of verified submission.
3.6.2 Account Deletion Procedures & Self-Service Request Workflows
To empower users and comply with global application store standards (including Google Play and Apple App Store user account management mandates), The Near Buy provides dual self-service deletion pathways:
- In-App Account Deletion: Authenticated users may initiate an account deletion request directly within mobile application account preferences under the “Privacy & Security” management menu.
- Public Web Deletion Portal: For users who have uninstalled the mobile application or cannot access their primary device, The Near Buy maintains a public, dedicated web-based Account Deletion Request portal. Any user can initiate account closure by providing their registered mobile phone number or email address.
- Mandatory Identity Authentication: To prevent malicious account deletions, account takeover sabotage, or unauthorized deletion requests by third parties, all deletion requests require affirmative cryptographic verification via a time-sensitive One-Time Password (OTP) dispatched to the registered mobile number or an authentication link sent to the verified email address.
3.6.3 The 14-Day Deactivation Grace Period
To protect users from irreversible data loss resulting from impulsive decisions, accidental clicks, or temporary device compromise:
- Immediate Public Quarantine: Upon successful submission and verification of a deletion request, the account immediately enters a fourteen (14) calendar day deactivation cooling-off period. During this period:
- The user’s profile is instantly hidden from public discovery and directory searches.
- If the user is a merchant, all listed products are unlisted, the digital storefront is taken offline, and active bargaining sessions are cancelled.
- All pending non-essential promotional communications and notification dispatches are permanently terminated.
- Voluntary Reactivation Option: If the account holder logs back into the platform using their verified credentials within the 14-day window, the deletion request is automatically cancelled, and account access is fully restored.
- Irreversible Execution: Following the conclusion of the fourteenth (14th) calendar day without a cancellation request, the account lifecycle transitions automatically into permanent technical data erasure.
3.6.4 Technical Data Erasure & Irreversible Anonymization Protocol
Once the 14-day cooling-off period concludes, automated platform data lifecycle processes execute permanent data destruction:
- Permanent PII Eradication: All Personally Identifiable Information—including full legal names, verified telephone numbers, email addresses, cryptographic password hashes, profile avatars, saved residential delivery addresses, and precise GPS coordinate histories—is permanently purged from active production databases and cloud storage buckets.
- Session & Push Token Revocation: All active authentication sessions, mobile device push notification tokens, and hardware authorization keys associated with the account are immediately invalidated and expunged.
- Disassociation of Public Feedback: Product reviews, star ratings, and seller feedback submitted prior to account deletion are retained to preserve catalog transparency and historical product evaluation integrity. However, all identifying author information is permanently stripped, and the review is permanently re-attributed to an anonymous “Former Marketplace Member.”
- Permanent Storefront Dissolution: For merchant accounts, the commercial storefront profile, custom shop banner media, and catalog descriptions are permanently deleted.
3.6.5 Mandatory Statutory Retention Exceptions & Legal Holds
The right to erasure is subject to mandatory legal exceptions established under the statutory laws of the People’s Republic of Bangladesh. The Near Buy cannot expunge records where statutory retention mandates supersede private deletion requests:
- Fiscal & Taxation Compliance (National Board of Revenue): Under the Value Added Tax and Supplementary Duty Act, 2012 and statutory tax auditing standards, all fiscal records—including electronic sales invoices, tax receipts, merchant commission deductions, and digital escrow payout vouchers—must be securely preserved for a minimum period of six (6) years. These records are restricted to dedicated, encrypted fiscal audit archives accessible solely for official revenue audits.
- Active Commercial Disputes & Warranty Windows: If an account is party to an ongoing product return, an unresolved financial refund claim, an open dispute mediation ticket, or an active investigation by the Directorate of National Consumer Rights Protection (DNCRP), account deletion is deferred until the commercial dispute lifecycle is officially resolved and all escrow funds are disbursed.
- Anti-Money Laundering & Financial Intelligence: In accordance with the Money Laundering Prevention Act, 2012, digital wallet transaction logs and merchant identity verification files must be retained for the prescribed statutory duration to support lawful financial intelligence inquiries.
- Security Quarantine for Malicious & Banned Actors: When an account is terminated or banned for severe platform violations—such as terrorist financing, doxxing, identity theft, commercial fraud, or repeated harassment—The Near Buy maintains a restricted security quarantine containing hashed identifiers (such as National ID hashes, trade license registration numbers, and device hardware signatures) under the Cyber Security Act, 2023 to prevent malicious actors from circumventing platform bans through re-registration.
3.6.6 Deceased Accounts & Estate Succession Procedures
In the event of the death of a registered account holder or merchant sole proprietor, The Near Buy maintains a compassionate, legally structured succession protocol:
- Notice of Decease: Immediate family members, legal heirs, or court-appointed executors may notify the platform compliance team to request account closure, suspension of recurring notifications, or succession of commercial storefront assets.
- Required Documentation: To protect the estate and prevent fraudulent asset liquidation, claimants must submit:
- An official Death Certificate issued by the relevant City Corporation, Municipality, or Union Parishad.
- Proof of kinship or a lawful Succession Certificate / Letter of Administration issued by a competent civil court having jurisdiction in Bangladesh.
- A verified copy of the claimant’s National Identity Card (NID).
- Escrow Wallet Settlement & Commercial Transition: Upon formal legal verification, any net escrow wallet balances belonging to the deceased merchant will be disbursed to the lawful estate in accordance with the court succession order. If the legal heirs elect to continue operating the neighborhood retail storefront, a new merchant verification agreement must be executed under the heir’s verified credentials.
Section 3.7: System Security, Anti-Scraping & API Protection (Clause PP-3.7)
The Near Buy maintains an institutional-grade cybersecurity posture designed to protect consumer personal information, merchant commercial ledgers, and proprietary neighborhood catalog data from unauthorized access, digital espionage, automated exploitation, and malicious disruption. In accordance with the Cyber Security Act, 2023, this Section outlines our technical defense architecture, strict anti-scraping prohibitions, API abuse prevention rules, and responsible vulnerability disclosure standards.
3.7.1 Multi-Layered Technical Defense & Cryptographic Standards
The platform deploys modern cryptographic controls and defense-in-depth methodologies across all infrastructure layers:
- Encryption in Transit: All communications between user browsers, mobile applications, merchant dashboard terminals, and platform servers are enforced exclusively over Transport Layer Security (TLS 1.3) with Perfect Forward Secrecy. Unencrypted HTTP connections are categorically rejected, and HTTP Strict Transport Security (HSTS) is enforced across all platform domains.
- Encryption at Rest: All production databases, secondary replicas, automated snapshot backups, cloud storage buckets, and confidential merchant verification documents are encrypted at rest using high-assurance AES-256 cryptographic standards.
- Irreversible Credential Hashing: Passwords, authentication secrets, and sensitive verification tokens are protected using salted, one-way cryptographic hashing algorithms. Plaintext passwords are never transmitted across internal networks, logged in telemetry, or accessible to platform staff, system administrators, or software engineers.
3.7.2 Database Access Isolation & Role-Based Authorization
Data access within platform storage systems is restricted by strict, automated authorization boundaries:
- Tenant Isolation at the Data Layer: The platform enforces strict row-level authorization rules directly at the database engine layer. Verified merchants can only query and manipulate their own inventory, sales transactions, and customer fulfillment records. Consumers can access exclusively their own profile details, active carts, purchase histories, and direct message threads. Cross-tenant data leakage is structurally impossible under automated database access policies.
- Least Privilege Administrative Access: Platform personnel access administrative consoles strictly on a need-to-know basis partitioned by operational role. For example, customer service personnel can view order issue tickets but cannot access merchant payout banking details or raw National ID files.
- Mandatory Multi-Factor Authentication (MFA): Multi-factor authentication is mandatory for all platform administrators, operations managers, and compliance officers accessing internal management consoles.
- Tamper-Evident Audit Logging: All administrative modifications, dispute resolutions, KYC approvals, and sensitive data access events are permanently recorded in append-only, cryptographically verifiable audit logs to guarantee non-repudiation.
3.7.3 Absolute Prohibition on Data Scraping & Catalog Harvesting
The Near Buy’s digital storefronts, neighborhood product catalogs, real-time inventory indices, bargaining algorithms, merchant directories, customer reviews, and physical retail coordinates represent valuable proprietary commercial assets and trade secrets protected under the Copyright Act, 2000 and the Cyber Security Act, 2023:
- Prohibited Automated Extraction: The use of automated spiders, crawlers, scrapers, bots, headless browsers, data-mining scripts, or automated software tools to extract, compile, harvest, or mirror platform catalogs, pricing feeds, merchant rosters, or customer feedback is strictly prohibited.
- Ban on Competitive Price Harvesting: Competitors, retail aggregators, and commercial entities are strictly forbidden from harvesting neighborhood retail prices, bargaining discounts, or inventory availability to construct derivative price comparison databases or engage in predatory market manipulation.
- Enforcement & Civil Remedies: Unauthorized data scraping is treated as a malicious computer system breach under Section 17 of the Cyber Security Act, 2023. The Near Buy vigorously pursues injunctive relief, statutory damages, and criminal prosecution against individuals, commercial competitors, or botnet operators attempting to harvest platform assets.
3.7.4 Edge Protection, Rate Limiting & Anti-Abuse Controls
To guarantee high service availability and defend our infrastructure against malicious actors:
- Web Application Firewall (WAF) & DDoS Mitigation: The platform operates behind enterprise edge firewalls that continuously filter traffic to intercept Distributed Denial of Service (DDoS) floods, SQL injection attacks, Cross-Site Scripting (XSS) vectors, and anomalous network patterns before requests reach core application servers.
- Dynamic Automated Rate Limiting: All public and authenticated API endpoints are bounded by automated rate limiters. Request frequency caps are strictly enforced on authentication endpoints (to block brute-force password guessing and credential stuffing), OTP verification services (to prevent telecommunication fraud), interactive bargaining submissions (to prevent negotiation bot manipulation), and catalog search queries.
- Ban on Reverse-Engineering & Handshake Interception: Decompiling, disassembling, reverse-engineering, or tampering with the platform’s mobile application binaries, network communication protocols, or cryptographic verification handshake algorithms (including the 8-digit Cash Confirmation QR generation logic) is strictly prohibited.
3.7.5 Responsible Vulnerability Disclosure Program & Safe Harbor
The Near Buy values the independent security research community and is dedicated to fostering responsible disclosure of technical vulnerabilities:
- Rules of Engagement for Security Researchers: Security researchers and ethical hackers who discover potential vulnerabilities in platform systems are requested to act in accordance with these standards:
- Promptly submit an encrypted, detailed vulnerability report directly to the platform security team without publicly disclosing or discussing the issue.
- Avoid any action that causes service degradation, data corruption, or denial of service to actual users.
- Never access, view, modify, download, or exfiltrate the personal or financial data of any real-world consumer or merchant.
- Grant the platform engineering team a reasonable remediation window of at least thirty (30) calendar days to patch and verify the vulnerability prior to any public disclosure.
- Legal Safe Harbor Covenant: If an independent security researcher adheres fully to these Rules of Engagement and acts in good faith, The Near Buy covenants that it will not initiate civil litigation or file criminal complaints under the Cyber Security Act, 2023 against the researcher.
3.7.6 Security Incident Containment & 72-Hour Breach Notification
Despite advanced defenses, if a security anomaly or unauthorized system breach occurs, The Near Buy operates a standardized incident containment and notification protocol:
- 24/7 Security Incident Response Team (SIRT): A dedicated technical response team is on continuous standby to isolate affected servers, revoke compromised credentials, patch technical vulnerabilities, and initiate forensic investigation within minutes of an alert.
- 72-Hour Statutory Breach Notification: In the event of a verified data breach involving the unauthorized acquisition, access, or exposure of unencrypted Personally Identifiable Information (PII) belonging to consumers or merchants:
- The platform will notify all affected users via direct email and SMS within seventy-two (72) hours of breach confirmation, outlining the specific data categories involved and providing actionable guidance to safeguard their accounts.
- A formal regulatory notification will be submitted to the National Cyber Security Agency and the Directorate of National Consumer Rights Protection (DNCRP) detailing the nature of the breach, immediate containment measures implemented, and ongoing remedial actions.
Section 3.8: Law Enforcement Warrants & Regulatory Audits (Clause PP-3.8)
As a licensed digital commerce platform operating in Bangladesh, The Near Buy cooperates with legitimate law enforcement investigations, judicial mandates, and statutory regulatory inquiries while fiercely defending the constitutional and statutory privacy rights of our users. This Section outlines the rigorous legal standards, verification protocols, and procedural safeguards governing all government disclosures and regulatory audits.
3.8.1 Legal Process & Constitutional Thresholds for Government Disclosure
The Near Buy does not volunteer user data to government authorities, law enforcement agencies, or intelligence bodies. Government requests for subscriber identities, order histories, geolocation traces, or communication logs are entertained strictly when supported by valid, binding legal process:
- Constitutional Protections: Disclosures are strictly evaluated under Article 43(b) of the Constitution of the People’s Republic of Bangladesh, which guarantees the fundamental right to the privacy of personal correspondence and communication except where restricted by law for state security, public order, public morality, or public health.
- Statutory Threshold: The platform requires a formal written summons issued by an authorized officer under Section 94 of the Code of Criminal Procedure, 1898 (CrPC), a lawful search warrant issued by a competent Judicial Magistrate under Section 96 of the CrPC, or a binding judicial order issued by a court of competent jurisdiction.
- Rejection of Informal Requests: Platform personnel are strictly prohibited from complying with informal, oral, telephonic, or unauthenticated email requests from police officers, security agencies, or government officials. All demands must be submitted through our formal legal process portal on official statutory letterhead.
3.8.2 Authorized Law Enforcement & Investigative Authorities
The platform recognizes and processes formal legal requests originating exclusively from statutory agencies exercising lawful investigative jurisdiction in Bangladesh:
- Bangladesh Police:
- The Criminal Investigation Department (CID) for major crimes, criminal fraud, and forensic investigations.
- The Cyber Crime Investigation Division / Cyber Police Centre (CPC) for cyber harassment, identity theft, financial hacking, and offenses under the Cyber Security Act, 2023.
- The Counter Terrorism and Transnational Crime (CTTC) unit for national security and anti-terrorism inquiries under the Anti-Terrorism Act, 2009.
- Local police stations (Thana Police) acting pursuant to a verified First Information Report (FIR) or general diary under an authorized Section 94 CrPC summons.
- Statutory Regulatory & Consumer Bodies:
- The Directorate of National Consumer Rights Protection (DNCRP): Authorized Assistant Directors and Deputy Directors investigating formal consumer fraud, adulteration, or unfair trade complaints under the Consumer Rights Protection Act, 2009.
- The Bangladesh Telecommunication Regulatory Commission (BTRC): Directives relating to telecom equipment certification and lawful compliance under the Bangladesh Telecommunication Regulation Act, 2001.
- Fiscal & Revenue Authorities:
- The National Board of Revenue (NBR): Value Added Tax (VAT) commissioners and tax audit officers conducting lawful turnover audits and tax assessments under the Value Added Tax and Supplementary Duty Act, 2012 and the Income Tax Act, 2023.
- Anti-Money Laundering & Financial Intelligence:
- The Bangladesh Financial Intelligence Unit (BFIU) and the Anti-Corruption Commission (ACC): Inquiries concerning digital wallet money laundering, suspicious financial movements, or terrorist financing under the Money Laundering Prevention Act, 2012.
Every incoming law enforcement demand is routed directly to the Platform Legal Counsel and Compliance Bureau for strict judicial scrutiny:
- Mandatory Evidentiary Elements: A legal demand must specify:
- The exact statutory provision authorizing the request.
- The registered FIR, Complaint Register (CR), General Register (GR), or official case crime number.
- The full legal name, rank, badge number, official station, and contact details of the investigating officer.
- The official signature and verifiable seal of the issuing officer or presiding Magistrate.
- The specific account identifier, mobile phone number, order number, or transaction date range under investigation.
- Rejection of Overbroad “Fishing Expeditions”: The Near Buy will rigorously challenge, narrow, or reject any government demand that is overbroad, vague, or constitutes an exploratory fishing expedition. The platform categorically refuses blanket requests for entire neighborhood customer registries, bulk phone directories, or uninhibited access to production databases.
- Judicial Review: If a request appears unconstitutional, procedurally defective, or lacking statutory authority, The Near Buy reserves the right to file formal motions before the competent Court of Sessions or High Court Division of the Supreme Court of Bangladesh to quash or modify the subpoena.
3.8.4 Emergency & Exigent Threat-to-Life Disclosures
In extreme, life-threatening circumstances where ordinary judicial processes would cause catastrophic delay, The Near Buy operates a specialized emergency disclosure pathway:
- Qualifying Exigent Circumstances: Emergency disclosures are permitted exclusively in situations involving:
- Imminent threat of death or severe physical violence against any person.
- Active kidnapping, abduction, or hostage situations.
- Imminent terrorist attacks or catastrophic sabotage of public infrastructure.
- Imminent danger or sexual exploitation involving minor children.
- Verification & Senior Authorization: Emergency requests must be submitted by a gazetted police officer (Assistant Superintendent of Police or above) and must be independently vetted and authorized by Platform Senior Legal Counsel.
- Post-Emergency Ratification: When emergency data is released, the investigating agency is legally obligated to submit a formal judicial warrant or Section 94 CrPC summons within forty-eight (48) hours of the disclosure to regularize the case file.
3.8.5 User Notification Policy & Statutory Gag Orders
The Near Buy champions transparent relationships with its users and operates under a strong presumption of user notification:
- Notice Prior to Disclosure: We will make reasonable commercial efforts to notify an affected user via their registered email address or SMS before disclosing their personal information to government authorities, allowing them an opportunity to seek legal counsel or protective judicial relief.
- Statutory Exceptions to Notice: The platform will delay or withhold notice to the affected user only where:
- A competent court or judicial magistrate has issued a binding non-disclosure order (statutory gag order) explicitly prohibiting notice for a prescribed time window; or
- The platform determines in good faith that providing immediate notice would create an imminent risk of death, physical violence, witness intimidation, or the destruction of critical criminal evidence.
- Notice Upon Expiration: Once a judicial non-disclosure restriction expires or is formally lifted, The Near Buy will notify the affected user regarding the records previously disclosed.
3.8.6 Forensic Chain of Custody, Evidentiary Certification & Transparency
To ensure that all electronic evidence produced is forensically valid and resistant to legal tampering:
- Forensic Data Extraction: Disclosed electronic records are extracted by certified forensic security engineers directly from immutable audit databases.
- Cryptographic Hash Verification: Every exported dataset, transaction record, and chat transcript is packaged with an SHA-256 cryptographic hash fingerprint to guarantee that records have not been altered, truncated, or fabricated.
- Evidentiary Certificate: Extracted records are accompanied by an official Certificate of Authenticity for Electronic Evidence executed by our designated Custodian of Records, admissible under Section 65B of the Evidence Act framework and the Information and Communication Technology Act, 2006.
- Annual Platform Transparency Reporting: The Near Buy publishes an annual public Transparency Report providing aggregated statistical data regarding:
- The total number of government and law enforcement requests received.
- The statutory classification of requesting authorities (Police, NBR, DNCRP, BFIU).
- The percentage of requests complied with, challenged, or rejected.
- The number of emergency exigent threat-to-life disclosures authorized.
10. Policy Governance, Version History & Data Protection Contact
10.1 Amendments & Material Modification Notices
The Near Buy reserves the right to amend, update, or revise this Privacy, Data Protection & System Security Policy to reflect evolving technological practices, operational enhancements, or legislative reforms enacted by the Government of the People’s Republic of Bangladesh.
- Notice of Material Changes: If we introduce material modifications that substantially alter user privacy rights, data processing categories, or law enforcement disclosure standards, we will provide at least fourteen (14) calendar days of advance notice via prominent banner notices across the web portal, mobile application notifications, and direct email communications prior to the changes taking effect.
- Continued Use as Acceptance: Continued use of The Near Buy following the effective date of an amended Policy constitutes full legal agreement to the updated terms. If a user disagrees with the revised provisions, they may terminate their account and request permanent data erasure in accordance with Section 3.6 prior to the effective date.
10.2 Administrative Interpretation & Conflict of Terms
- Harmonious Interpretation: This Policy forms an integral component of the comprehensive Platform Legal & Standards Suite and must be read in conjunction with the Community Standards & Code of Conduct, Platform & Commerce Policies, and Terms of Service & Platform Governance.
- Statutory Primacy: In the event of any irreconcilable conflict between the provisions of this Policy and mandatory statutory enactments of Bangladesh—including the Cyber Security Act, 2023, the Digital Commerce Operation Guidelines 2021, or the Consumer Rights Protection Act, 2009—the statutory provisions shall supersede to the extent of such inconsistency.
10.3 Designated Data Protection & Privacy Compliance Office
For inquiries, data access requests, rectification submissions, account deletion verifications, or security vulnerability disclosures, users and regulatory authorities may contact:
- Official Data Protection Officer: Chief Privacy & Compliance Officer
- Institutional Department: Platform Legal, Security & Regulatory Bureau
- Operating Entity: The Near Buy Marketplace Limited
- Physical Headquarters: 271, Nayatola, Ambagan, Moghbazar, Dhaka-1217, People’s Republic of Bangladesh
- Electronic Communications:
privacy@thenearbuy.com | compliance@thenearbuy.com
- Emergency SIRT Security Desk:
security@thenearbuy.com
- Statutory Law Enforcement Legal Desk:
legal-requests@thenearbuy.com