FTWallthingswtf.club

Legal

Privacy Policy

Last updated 01 July 2026Effective 01 July 2026

This Privacy Policy explains how WTF GLOBAL PRIVATE LIMITED (“WTF Circle,” “we,” “us,” or “our”) collects, uses, shares, and protects personal data when you access the WTF Circle platform, including our website, apps, and related services (the “Platform”). This Policy is a standalone privacy notice separate from our Terms of Service, and is intended to comply with the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 (together, “DPDP Law”), as they come into force in India, and other applicable law.

By using the Platform, you acknowledge this Policy. Where DPDP Law requires your consent for a specific processing activity, we will seek that consent separately, in clear language, before collecting the relevant data.

01 Who we are

WTF Circle is operated by WTF GLOBAL PRIVATE LIMITED, registered in Mumbai, India (“Data Fiduciary” under DPDP Law). For any privacy questions or to exercise your rights, contact our Grievance Officer (Section 12).

02 Personal data we collect

We collect the following categories of personal data, only to the extent relevant to the feature you use:

2.1 Identity and contact data: name, mobile number, professional email address, city, and photograph.

2.2 Verification data:

  • LinkedIn profile data (role, seniority, employment history) if you connect your LinkedIn account;
  • Instagram profile data (username, account type, biography, website, follower and post counts, and the captions and images of your recent posts) if you connect your Instagram account;
  • DigiLocker-issued education credentials, if you choose to verify your degree;
  • Corporate email domain verification;
  • Professional licence numbers (for example, Bar Council, Medical Council, ICAI), if you verify a licensed profession;
  • Credit bureau data, specifically a credit score band (for example, CIBIL 700+), obtained through a licensed credit information company with your specific consent, used only to gate eligibility for Group Buying and credit-linked offers — we do not receive or store your full credit report;
  • The first six digits (BIN) of a payment card you choose to submit, used only to infer card tier for premium-tier signalling; we do not collect or store full card numbers.

2.3 Profile and preference data: your declared persona (Founder/Executive/Creative), interest graph, utility preferences, and any other onboarding responses.

2.4 Community and engagement data: Vouch Codes issued and redeemed, Core Group participation and attendance, Exchange posts and inline analyses, and poll and quiz responses.

2.5 Connection data: Bridge intents and categories you select, mutual-consent connection outcomes, and Digital Name Card exchange records (only between Members who mutually complete a QR exchange).

2.6 WTF Bot interaction data: your queries to WTF Bot, voice notes you record in response to the Daily Challenge, and business context you choose to share for personalised responses.

2.7 Transactional data: Collective Orderbook pledges, Commitment Fee payments, event registrations and attendance, and perk redemptions. Full payment card and bank details are collected and processed directly by our RBI-authorised payment gateway partners, not stored by us.

2.8 Device and usage data: IP address, device identifiers, app version, log data, and analytics events, collected via cookies and SDKs as described in Section 8.

2.9 Data from others. If another Member vouches for you, shares your contact details via a Digital Name Card, or refers you, their referral generates a record linking their account to yours for the purposes described in Section 3.

03 How we use your data

We process personal data for the following purposes:

  • (a) to verify your identity and eligibility for Membership, specific communities, and credit-linked features, and to prevent fraud;
  • (b) to operate core features: onboarding, community placement, Core Group matching, the Bridge’s dual-consent matching, the Exchange, the Collective Orderbook, events, and Premium Perks;
  • (c) to personalise WTF Bot responses and Daily Challenge content using your business context and activity;
  • (d) to communicate with you about your account, events, and Platform updates;
  • (e) to detect, investigate, and prevent fraud, abuse of Vouch Codes, and violations of our Terms of Service;
  • (f) to comply with legal obligations, including responding to lawful requests from government or regulatory authorities;
  • (g) to improve the Platform through aggregated or de-identified analytics.

We do not use your credit score or professional licence data for any purpose beyond the specific verification gate for which it was collected, and we do not sell this data to advertisers.

04 Legal basis for processing

Under DPDP Law, we process your personal data on the basis of your consent, given at the point you provide the data or connect a third-party account, except where processing falls under a “legitimate use” recognised by DPDP Law (for example, where you have voluntarily provided data for a specified purpose and have not indicated you do not consent, or where processing is necessary to comply with a legal obligation or to respond to a medical emergency). You may withdraw consent at any time as described in Section 11; withdrawal does not affect the lawfulness of processing carried out before withdrawal, and may result in loss of access to the feature that required that data.

05 How we share your data

We share personal data only as needed, and never sell it to third parties for their own marketing purposes. Categories of recipients include:

5.1 Verification partners: licensed credit information companies (for CIBIL-band checks), LinkedIn and Instagram (each via its API, subject to your authorisation), and DigiLocker (via your authorisation).

5.2 Matching and personalisation vendors: third-party matchmaking and recommendation providers (for example, Qloo) may receive limited profile and interest-graph data to power Bridge, Core Group, and Exchange matching; these vendors are contractually restricted from using your data for any purpose other than providing the matching service to us.

5.3 Partner brands: for Premium Perks, we share the minimum data needed (typically a verification token or unique digital signature) to confirm your eligibility for an offer; we do not share your full profile with partner brands unless you separately consent.

5.4 Payment processors: RBI-authorised payment gateways process transactions for Commitment Fees, membership fees, and event payments.

5.5 Cloud and infrastructure providers: hosting, storage, and analytics vendors who process data on our behalf under data processing agreements, including reasonable security safeguards required under DPDP Law.

5.6 Other Members: certain data is visible to other Members by design and by your own action — for example, your public profile, Exchange posts, and Digital Name Card details you choose to exchange. Contact details are shared with another Member only after mutual, dual consent through the Bridge or an in-person QR exchange you initiate.

5.7 Legal and regulatory disclosures: we may disclose personal data where required by law, court order, or a competent government or regulatory authority, including the Data Protection Board of India.

We do not currently transfer personal data outside India except where a vendor’s processing infrastructure requires it under a data processing agreement with contractual safeguards; we will update this Policy if the Central Government notifies country-specific transfer restrictions under DPDP Law and any such restriction applies to us.

06 Data retention

We retain personal data only for as long as necessary for the purpose it was collected, or as required by law. Indicative retention periods:

  • Account and verification data: for the duration of your Membership, plus a period after account closure to handle disputes, fraud investigation, and legal requirements.
  • Transaction records (Commitment Fees, event payments): as required under applicable financial and tax record-keeping law.
  • Traffic and log data: retained for at least one year, as required under DPDP Law, for security and grievance-resolution purposes.
  • WTF Bot interaction data: retained for the period needed to provide personalised responses, after which it may be aggregated or deleted.

Where you close your account, we will erase or anonymise personal data that is no longer needed for a specified purpose, subject to our legal retention obligations.

07 Your rights

Subject to DPDP Law, as a Data Principal you have the right to:

  • (a) obtain a summary of the personal data we hold about you and the processing activities carried out on it;
  • (b) request correction, completion, or updating of inaccurate or incomplete personal data;
  • (c) request erasure of personal data that is no longer necessary for the purpose it was collected, unless we are required to retain it by law;
  • (d) withdraw consent at any time for processing based on consent, with effect for future processing only;
  • (e) nominate another individual to exercise your rights on your behalf in the event of death or incapacity;
  • (f) register a grievance with us and, if unresolved, approach the Data Protection Board of India.

To exercise these rights, contact our Grievance Officer (Section 12). We will resolve grievances within a reasonable period and, in any case, no later than the timeline prescribed under DPDP Law.

08 Cookies and tracking

We use cookies, SDKs, and similar technologies to keep you signed in, remember preferences, measure engagement (for example, Flash Perk views, Daily Challenge completion), and detect fraud. You can manage cookie preferences through your browser or device settings; disabling certain cookies may affect Platform functionality.

09 Children’s data

The Platform is intended for adults aged 18 and above. We do not knowingly collect personal data from anyone under 18. If we learn that we have inadvertently collected data from a minor, we will delete it promptly.

10 Security

We implement reasonable technical and organisational safeguards appropriate to the sensitivity of the data involved, including encryption of data in transit, access controls limiting who within our organisation can view verification data (such as credit score bands), and contractual security obligations on our processors, consistent with the safeguards required under DPDP Law. No system is completely secure, and we cannot guarantee absolute security.

In the event of a personal data breach, we will notify the Data Protection Board of India and affected Members as required under DPDP Law.

11 Withdrawing consent

You may withdraw consent for a specific processing activity (for example, disconnecting your LinkedIn account) through your account settings, or by contacting us at admin@allthingswtf.club. Withdrawing consent for a feature that requires certain data will result in loss of access to that feature, but will not affect features that do not depend on it.

12 Grievance Officer

In accordance with DPDP Law and applicable Indian information technology regulations, our Grievance Officer can be reached at:

WTF GLOBAL PRIVATE LIMITED
Email: admin@allthingswtf.club

13 Changes to this Policy

We may update this Policy from time to time to reflect changes in our practices or in applicable law, including as further provisions of DPDP Law come into force. We will notify you of material changes in-app or by email at least 30 days before they take effect.

14 Third-party verification and enrichment

When you connect your LinkedIn account or your Instagram account, we engage a third-party verification partner — a specialist verification and background-check vendor — to help us assess your eligibility for Membership. Connecting either account triggers the same processing, described below; connecting both does not repeat checks that have already completed. This section describes that processing in more detail; see also Section 2.2 for the verification data we collect generally, and Section 5.1 for how we work with verification partners.

Categories processed. Connecting either account allows our verification partner to process the following categories of data about you:

  • identity and contact details;
  • mobile-intelligence data, including phone numbers, email addresses, and physical addresses associated with you, and your address history;
  • employment and professional history;
  • social and professional profile analysis; and
  • public-record and data-breach-exposure information.

Purpose. We use this data solely to vet and review your eligibility for Membership — to confirm your identity and professional background before you are admitted. We do not use it for advertising, and we do not use it for any purpose beyond membership review.

Legal basis. We rely on your consent, given when you choose to connect LinkedIn or Instagram and see the on-screen disclosure at that step. Each connection is a separate consent, recorded separately. Consistent with the consent basis described in Section 4.

Who sees it. Access to this data is restricted to authorised administrators involved in membership review. We do not sell this data, and we do not share it for marketing.

Retention and your rights. We retain this data only for as long as needed to vet and review your Membership. You may withdraw consent or request deletion at any time by contacting us, as described in Section 11, and you have the rights set out in Section 7.

This section is a summary and is subject to this Policy as a whole; the specific verification categories and partners we use may be updated from time to time, as described in Section 13.

15 Contact us

If you have questions about this Policy or how we handle your personal data, contact:

WTF GLOBAL PRIVATE LIMITED
Email: admin@allthingswtf.club

Privacy PolicyTerms of ServiceRefund Policy
© 2026 WTF Global Private Limited