IPO Tracker Privacy Policy
What IPO Tracker does
IPO Tracker displays public Indian IPO reference information and official resource links. A user may mark IPOs they applied for in a local list. The app is not a broker, exchange, registrar, or investment adviser; it does not place orders or recommend securities.
Information we do not ask for
The app requires no account or sign-in and does not ask for a name, email address, phone number, bank account, card, UPI PIN, or other payment credentials, contacts, location, photos, files, microphone, camera, advertising ID, or device identifier. It has no ads, third-party analytics, behavioural profiling, crash-reporting SDK, or social sign-in.
Public-data network processing
Public snapshot refreshes send ordinary HTTPS and cache-validation information to the IPO Tracker API. They never send PAN, Applied markers, or personalized allotment results. Cloudflare and network providers may process IP address and transport/security metadata to deliver HTTPS. IPO Tracker does not use it to identify a person, infer location, advertise, or sell data.
Scheduled backend ingestion obtains public IPO reference data from an authorized developer data source using a backend-only operator credential. User private profiles are not forwarded to any upstream data provider. Application telemetry is limited to bounded operational fields and excludes URLs/queries, bodies, authorization values, PAN, and personalized results.
Local Applied tracking
For IPOs the user marks Applied, the app stores the IPO identifier, marked time, requested-lot count, and limited public display fields such as lot size and relevant IPO dates. After the expected allotment date, the user may optionally record Allotted or Not allotted and, for Allotted, the allotted-lot count. This is visibly labelled as a user-entered note, not a source-verified result or proof of an application. These details are not synchronized to IPO Tracker, Cloudflare, an upstream data provider, a registrar, analytics, or crash reporting.
The app does not ask for or store PAN, application number, demat identifier, broker identity, bid price, payment credentials, or transaction history. Android Clear storage or uninstall removes local Applied details. Android backup is disabled. No server account or private cloud profile exists.
Public storage and server retention
The app separately keeps a replaceable SQLite read model of public IPO snapshots and bounded refresh metadata. Cloudflare KV holds public snapshots for delivery and rollback: immutable versions expire after up to 48 hours and compact run metadata after up to seven days. These are not user submissions.
External links and allotment status
Document links open externally; the app does not download or render their contents. When a user explicitly chooses Check allotment for an Applied IPO, the app can open a reviewed official registrar page in the external browser after explaining the handoff. The app sends no PAN, application number, demat identifier, Applied marker, or locally recorded result with that link. Anything entered after leaving IPO Tracker is submitted directly to the registrar under that website's terms and privacy practices; IPO Tracker does not receive or store it. Recording a result later is a separate manual action and does not import or verify anything from the registrar. A native automatic checker will not be enabled until its source supplies a documented contract and explicit permission and this policy is updated.
Buy me a Chai
The About screen offers an optional, voluntary contribution labelled Buy me a Chai. The labels and amounts are not food orders, subscriptions, purchases, or digital benefits; donors and non-donors receive identical app functionality. The fixed public recipient is dovah@upi. After the user chooses a preset or whole-rupee custom amount, optionally enters a short note, reviews the payee and amount, and explicitly continues, the app creates a temporary upi://pay URI and hands it to Android's generic UPI chooser. The selected UPI app and bank handle the transaction, PIN, status, disputes, and reversals.
The amount and note are held in memory only for this handoff. IPO Tracker does not send them to its API or Worker, read a UPI result, process or verify a payment, use a payment SDK, create a collect request, collect donor identity, store payment status, or claim settlement. A secondary QR is rendered locally on demand only for scanning from another device and is not uploaded or persisted. Copy UPI ID remains available as a fallback; the app never reads the clipboard. For payment status or disputes, use the selected UPI app or bank.
Security and limitations
Network traffic uses HTTPS in staging and production, and credentials are never embedded in the APK. Device controls cannot protect local data on an unlocked or compromised device.
IPO data can be delayed, incomplete, changed, or unavailable. Verify material details on official sites. IPO Tracker is not investment, financial, tax, or legal advice.
Children, changes, and contact
IPO Tracker is not directed to children and does not knowingly collect children's personal information. This policy will be updated when behavior or data handling changes. For privacy questions or infrastructure-record requests, use the developer contact email on the Google Play listing.