Privacy Policy

Last updated: 9 September 2026

This Policy explains how Gapsmiths handles personal data in the Bandobast platform. Bandobast is supplied to organisations — typically police and law-enforcement bodies. For the operational data held in the system, your organisation is the Data Fiduciary (the entity that decides why and how the data is processed) and Gapsmiths acts as a Data Processor on its instructions. If you are an officer whose details are in Bandobast, please raise requests with your own organisation in the first instance.

1. Who we are

Bandobast is operated by Gapsmiths, B 14 Munjal Nagar, Off Eastern Express Highway, Chembur, Mumbai 400071, Maharashtra, India (GSTIN 27AAPFG1889E1Z0). This Policy covers the website at bandobast.online, the web application at app.bandobast.online, the Bandobast mobile applications, and our backend services.

2. Our role in your data

Where an organisation uses Bandobast to plan deployments and manage its personnel, that organisation determines what data is entered and why. It is the Data Fiduciary. We process that data on its behalf and under its instructions, as its Data Processor, in line with our Terms of Use and the service agreement with it.

We are the Data Fiduciary for a limited set of data we control directly — for example enquiries sent to us through this website or by email, and our own billing and business records.

3. Data we process

3.1 Account and identity data

3.2 Personnel records

Records the organisation maintains about its personnel for deployment purposes: name, badge and belt number, rank and designation, force type and unit, contact number, email, address, reporting officer, parent unit, and where uploaded, a photograph.

3.3 Operational data

3.4 Technical and usage data

3.5 Audit records

The Service maintains an audit trail of significant actions — who created, changed, approved or deleted a record, when, from which IP address, and what the values were before and after. Audit entries are hash-chained so that tampering can be detected. These records exist to make deployments accountable and cannot be edited by users.

3.6 Enquiries

If you contact us, we process your name, contact details and the content of your message so that we can respond and keep a record of the exchange.

4. Biometric and location data

Two categories warrant specific mention because they are more sensitive than ordinary records.

4.1 Facial recognition data

Where an organisation enables the optional face enrolment feature, the Service derives a mathematical representation (an “embedding”) from a personnel photograph, to assist with verifying identity at deployment. In relation to that feature:

4.2 Location and vehicle tracking

The Service records coordinates for deployment locations, and — where an organisation uses the vehicle tracking feature — the position, speed and heading of tracked vehicles over time, together with the call sign, registration number and, where entered, the driver’s name and phone number. This is operational tracking of duty vehicles during an event. It is visible to authorised users within that organisation and is retained under the organisation’s retention settings.

5. Why we process it

PurposeData involved
Providing the Service — planning events, assessing locations, allocating personnel, running rosters Account, personnel and operational data
Authentication and access control Account and authentication data
Notifying personnel of duty and roster allocations, including over WhatsApp and push notifications Name, mobile number, allocation details, push tokens
Accountability and audit Audit records, IP address, timestamps
Security, fraud and abuse prevention, and diagnosing faults Technical and usage data, logs
Support, and communicating about the Service Account data, enquiry content
Billing, taxation and statutory records Customer contact and billing details

We do not sell personal data. We do not use Customer Data for advertising, and we do not use it to train machine-learning models for other customers.

6. Lawful basis

Where we act as a Processor, the lawful basis is determined by the organisation. Typically this is the performance of its statutory and public functions, its legitimate interests in managing its workforce and operations, compliance with legal obligations, or — where required — consent obtained by it.

Where we act as a Data Fiduciary in our own right, we rely on the performance of our contract with the customer, our legitimate business interests in operating and securing the Service, compliance with legal obligations, and consent where consent is the applicable basis.

7. Sharing and disclosure

We disclose personal data only in these circumstances:

8. Sub-processors

We use the following categories of sub-processor. Each is engaged under contract and receives only the data necessary for its function.

ProviderFunctionData involved
Microsoft Azure Cloud hosting of the application and database All hosted data
Amazon Web Services (CloudFront) Content delivery for static assets and uploads Stored files and images
Mapbox Maps, geocoding and map tiles Coordinates and search terms sent to render maps
Google Firebase Authentication and push notification delivery Identifiers, device tokens, notification content
Meta Platforms (WhatsApp Business) Delivery of duty and roster messages over WhatsApp Recipient number and message content

A current list is available on request from info@gapsmiths.com. We will give customers notice of a material change to this list so that they may object.

9. International transfers

We host the Service on infrastructure located in India wherever we reasonably can. Some sub-processors listed above operate globally, and limited data — such as push notification payloads, WhatsApp message delivery and map requests — may be processed outside India by them. Where that occurs, we rely on contractual protections with those providers and on transfers to jurisdictions not restricted under applicable Indian law.

10. Retention

Where we act as a Processor, we retain Customer Data for as long as the customer’s subscription is active and as instructed by the customer.

On termination, and on written request made within thirty (30) days, we will make Customer Data available for export. After that window we delete or irreversibly anonymise it within a further ninety (90) days, except where retention is required by law or is necessary to establish, exercise or defend a legal claim.

Backups are retained on a rolling cycle and are overwritten in the ordinary course, typically within thirty-five (35) days. Face embeddings are deleted as described in section 4.1. Audit records are retained for the period the customer specifies, because their purpose is accountability over time. Invoices and tax records are retained for the period required by Indian taxation law.

11. Security

We apply safeguards appropriate to the sensitivity of the data, including:

No method of transmission or storage is completely secure. We cannot guarantee absolute security, but we work to protect data using measures proportionate to the risk.

12. Your rights

Subject to applicable law, including the Digital Personal Data Protection Act, 2023, you may have the right to:

How to exercise them. If your data is in Bandobast because of your employment or posting, your organisation controls that record — please contact its administrator or nodal officer. If you approach us directly, we will refer your request to the relevant organisation and assist it in responding. For data we hold as Data Fiduciary — such as an enquiry you sent us — write to info@gapsmiths.com. We respond to requests within thirty (30) days, and will verify your identity before acting.

13. Children’s data

The Service is intended for use by adults acting in a professional capacity. It is not directed at children, and we do not knowingly collect personal data of children. If we learn that such data has been provided, we will delete it.

14. Cookies and local storage

This website uses no analytics, advertising or third-party tracking cookies.

The application at app.bandobast.online uses cookies and browser storage that are strictly necessary for it to work — to keep you signed in, to hold your session and authentication token, and to remember interface preferences such as language and selected filters. These are not used to track you across other websites. Blocking them will prevent the application from functioning.

15. Breach notification

If we become aware of a personal data breach affecting Customer Data, we will notify the affected customer without undue delay, with the information available to us about the nature of the breach, the data involved, its likely consequences and the steps taken. We will assist the customer with its own notification obligations to the Data Protection Board of India and to affected individuals.

16. Changes to this Policy

We may update this Policy from time to time. We will revise the “Last updated” date above and, where the change is material, notify customers by email or through the Service before it takes effect.

17. Grievance officer & contact

In accordance with the Information Technology Act, 2000 and the rules made under it, and the Digital Personal Data Protection Act, 2023, our grievance contact is:

If you are not satisfied with our response, you may complain to the Data Protection Board of India.