A structured, comprehensive journey through your entire financial life — from who you are today to every goal you dream of achieving.
Whether you are an artist or an accountant, you can do this yourself. Every step explains itself as you go, and an i sits beside anything worth a word more.
One payment. No auto-renewal.
No hidden fees. Everything the plan
you choose includes, for its full validity.
No finance background needed. Every step explains itself as you go, and an i sits beside anything worth a word more.
Bulliebear.com ("Company," "we," "our," or "us") operates the Comprehensive DIY Financial Planner tool (the "Service," "Platform," or "Tool") accessible via bulliebear.com. This Privacy Policy ("Policy") constitutes a legally binding instrument governing the collection, processing, storage, transfer, disclosure, and deletion of Personal Data and Sensitive Personal Data or Information ("SPDI") in connection with your use of the Service.
This Policy applies universally to all natural persons who access, browse, register for, or otherwise utilise the Service, irrespective of their geographical domicile or nationality (collectively, "Data Subjects," "Users," "you," or "your"). The Company acts as the Data Controller within the meaning of the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the UK General Data Protection Regulation ("UK GDPR"), and the analogous Data Fiduciary within the meaning of the Digital Personal Data Protection Act, 2023 ("DPDP Act") of India.
This Policy is designed to comply simultaneously with the following legislative instruments and regulatory frameworks:
In the event of any conflict between the provisions of this Policy and the mandatory statutory requirements applicable to your jurisdiction of residence, the stricter of the applicable legal provisions shall prevail.
For the purposes of this Policy, the following terms shall bear the meanings ascribed to them below:
"Personal Data" means any information relating to an identified or identifiable natural person, including without limitation any data that could directly or indirectly identify a Data Subject.
"Sensitive Personal Data or Information (SPDI)" means Personal Data pertaining to passwords, financial information, health data, sexual orientation, medical records, biometric information, and any other category designated as sensitive under applicable law, including without limitation Sections 43A and 72A of the Information Technology Act, 2000 and Rule 3 of the SPDI Rules, 2011.
"Processing" means any operation or set of operations performed upon Personal Data, whether or not by automated means, including collection, recording, organisation, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure by transmission, dissemination, or otherwise making available, alignment or combination, restriction, erasure, or destruction.
"Data Fiduciary / Data Controller" means the entity that alone or jointly with others determines the purposes and means of Processing of Personal Data, being Bulliebear.com in the context of this Policy.
"Data Principal / Data Subject" means the natural person to whom the Personal Data relates.
"Consent" means any freely given, specific, informed, and unambiguous indication of the Data Subject's wishes, by which they signify, either by a statement or by a clear affirmative action, agreement to the Processing of their Personal Data.
"Third Party" means any natural or legal person, public authority, agency, or body other than the Data Subject, Data Controller, and persons who, under the direct authority of the Data Controller or the Data Processor, are authorised to process Personal Data.
"Data Processor" means any natural or legal person, public authority, agency, or other body that processes Personal Data on behalf of the Data Controller pursuant to a legally binding data processing agreement.
"Inferred Data" means data created by the Company through logical deduction, algorithmic inference, or statistical modelling applied to Personal Data or usage data, including without limitation financial health scores, life-stage classifications, and product affinity profiles.
3.1 Financial Information Voluntarily Provided by You
In the ordinary course of your engagement with the Service, we collect and process the following categories of financial information that you voluntarily input into the Platform:
3.2 Behavioural and Usage Analytics Data
Subject to the tracking technologies described in Section 10 hereof, we or our authorised service providers may automatically collect the following categories of data pertaining to your interaction with the Service:
3.3 Inferred and Derived Data
Based upon the Personal Data and financial information you provide, and the behavioural data we collect, we may generate inferred or derived data concerning you, including without limitation:
3.4 Data We Do Not Collect
We expressly confirm that we do not knowingly or intentionally collect government-issued identity numbers (e.g., Aadhaar, PAN, Passport), bank account numbers, credit or debit card details, passwords, biometric identifiers, or any Personal Data from individuals below the age of eighteen (18) years. The Service is intended exclusively for adults of full legal capacity.
The Company processes your Personal Data for the following purposes, subject to the identified legal bases:
5.1 The financial data you input into the Service is stored exclusively within your browser's local storage ("localStorage") on your personal device. Such data is not transmitted to, stored upon, or processed by any server owned, operated, or controlled by Bulliebear.com or its affiliates, unless you explicitly trigger a data-sharing action or until your device's localStorage is cleared by you or your browser.
5.2 Notwithstanding the foregoing, certain non-financial metadata, usage analytics, and device identifiers may be transmitted to third-party analytics and advertising platforms as described in Section 10 hereof.
5.3 Where data is transmitted to or held by us or our Data Processors, we implement appropriate technical and organisational measures to safeguard Personal Data, including without limitation: (a) encryption of data in transit using industry-standard Transport Layer Security (TLS 1.2 or higher) protocols; (b) access controls and authentication mechanisms restricting internal access to Personal Data on a strict need-to-know basis; (c) regular security assessments, penetration testing, and vulnerability analyses; and (d) incident response procedures compliant with applicable breach notification requirements, including 72-hour notification obligations under the GDPR and DPDP Act.
5.4 Notwithstanding our implementation of technical safeguards, you acknowledge that no method of transmission over the Internet or electronic storage is completely secure, and we cannot guarantee absolute security of your Personal Data.
6.1 We may share your Personal Data, including inferred and derived data, with the following broad categories of Third Parties for the purposes specified. We do not disclose the identities of individual partner entities in this Policy:
6.2 We do not sell your individual Personal Data to Third Parties for monetary consideration. However, aggregated, de-identified, and irreversibly anonymised datasets derived from collective user interactions may be licensed or disclosed to market research organisations, academic institutions, or fintech ecosystem participants, provided that such datasets cannot reasonably be used to re-identify any individual Data Subject.
7.1 In the interest of full transparency and in compliance with applicable consumer protection and financial services disclosure obligations, the Company hereby discloses that it may receive referral commissions, introducers' fees, lead-generation fees, or other forms of remuneration from Third Party financial service providers ("Partners") when a Data Subject, having been introduced to a Partner through the Service, subsequently acquires or subscribes to a financial product or service offered by such Partner.
7.2 The Service is designed as an educational and illustrative instrument. The existence of such commercial arrangements does not influence the objective presentation of financial planning data within the Tool. Any product suggestions facilitated through the Service represent commercial introductions and do not constitute regulated financial advice, investment recommendations, or any form of advisory service requiring regulatory authorisation.
7.3 You acknowledge and accept the Company's receipt of such referral remuneration as a condition of your use of the Service. You retain the absolute right to decline any third-party introduction or product recommendation without prejudice to your continued use of the core planning functionality of the Service, and without incurring any financial obligation to the Company.
7.4 Where required by applicable law (including SEBI (Investment Advisers) Regulations, 2013 and equivalent regulations), the Company shall make further disclosures regarding specific commercial arrangements at the time of any individual product introduction.
8.1 Your Personal Data may be transferred to, stored in, or processed in countries outside your jurisdiction of residence, including countries that may not afford the same level of data protection as your home jurisdiction. Such transfers may occur in connection with the operation of analytics and advertising platforms described in Section 10.
8.2 Where Personal Data originating from the European Economic Area ("EEA"), the United Kingdom, or Australia is transferred to a third country, we shall implement appropriate transfer safeguards in accordance with applicable law, including without limitation: (a) Standard Contractual Clauses ("SCCs") approved by the European Commission; (b) UK International Data Transfer Agreements ("IDTAs"); (c) Binding Corporate Rules ("BCRs"); or (d) reliance upon an adequacy decision issued by the relevant supervisory authority, as applicable.
8.3 For transfers of data originating from India, we comply with the cross-border transfer provisions of the DPDP Act, 2023 and any applicable rules or government notifications issued thereunder, including restrictions on transfers to notified countries.
8.4 You may request information regarding the specific safeguards applicable to international transfers of your Personal Data by contacting our Data Protection Officer at the details specified in Section 16.
9.1 Personal Data collected and processed by us shall be retained for a period not exceeding three (3) years from the date of your last active engagement with the Service ("Retention Period"), unless a longer retention period is mandated by applicable law (including Indian financial record-keeping requirements under the Income Tax Act, 1961, the Prevention of Money Laundering Act, 2002, and applicable SEBI regulations) or is necessary for the establishment, exercise, or defence of legal claims.
9.2 Upon expiry of the Retention Period, we shall automatically and irreversibly delete or anonymise all Personal Data attributable to you in our possession, custody, or control, including data held by our Data Processors, in accordance with industry-standard data destruction protocols certified to NIST SP 800-88 or equivalent standards.
9.3 Financial data stored in your browser's localStorage resides entirely on your personal device and is within your exclusive control. Such data is automatically cleared when you clear your browser data. We have no technical ability to recover or restore locally stored data on your behalf once deleted.
9.4 You may exercise your right to erasure at any time prior to the natural expiry of the Retention Period by submitting a verified deletion request to our Data Protection Officer (see Section 16). We shall process such requests within thirty (30) calendar days of receipt, subject to any lawful grounds for continued retention.
10.1 The Service utilises the following tracking and data collection technologies:
(a) Browser localStorage — The primary repository for your financial planning data. No data stored in localStorage is transmitted to external servers by the core Service functionality. You may clear localStorage at any time via your browser settings without affecting the availability of the Service (though your planning data will be irrecoverably deleted from your device upon doing so).
(b) Essential Session Cookies — Strictly necessary cookies deployed solely for the purpose of maintaining session continuity, authenticating your access, and enabling core Service functionality. These cookies do not collect Personal Data for marketing or profiling purposes and do not require explicit consent under applicable law, including the GDPR's Cookie Exemption for strictly necessary cookies.
(c) Google Analytics — We deploy Google Analytics, a web analytics service provided by Google LLC ("Google"), which utilises cookies and similar tracking technologies to collect anonymised and aggregated usage statistics, including session counts, user flows, geographic distribution, device categories, and feature engagement metrics. Data collected via Google Analytics is processed by Google in accordance with Google's Privacy Policy and the Google Measurement Data Processing Terms. IP addresses are anonymised prior to transmission where technically feasible. You may opt out of Google Analytics tracking by installing the Google Analytics Opt-out Browser Add-on. You may also manage your Google advertising settings via your Google Account preferences.
(d) Meta Pixel (Facebook Pixel) — We deploy the Meta Pixel, an advertising measurement and audience-building technology provided by Meta Platforms, Inc. ("Meta"), which enables us to measure the effectiveness of our advertising campaigns, build custom and lookalike audiences, and display relevant advertisements to you on Meta's platforms (including Facebook and Instagram). The Meta Pixel may collect certain device identifiers, browser information, and behavioural event data including page views, feature interactions, and conversion events. Data is processed by Meta in accordance with Meta's Data Policy. You may manage your advertising preferences via Meta's Ad Preferences settings and may opt out of interest-based advertising via the Digital Advertising Alliance's opt-out portal.
10.2 By continuing to use the Service after being presented with this Policy, you consent to the use of non-essential cookies and tracking technologies as described herein to the extent required by applicable law. Where explicit prior consent is mandated (e.g., under the GDPR or UK GDPR for non-essential cookies), we shall obtain such consent via a cookie consent mechanism prior to deploying tracking technologies.
11.1 Subject to applicable law, the Company and its authorised Partners may contact you via email, SMS, WhatsApp, push notifications, and other electronic communication channels for the purpose of providing you with information concerning financial products, services, offers, educational content, and promotional materials that may be of interest to you based upon your financial profile and inferred preferences.
11.2 Such marketing communications shall be transmitted to you on an opt-out basis, meaning that they will be sent to you by default unless and until you exercise your right to object or withdraw consent. You may opt out of receiving marketing communications at any time, without charge, by:
11.3 We shall honour all opt-out requests within ten (10) business days of receipt. Notwithstanding your opt-out from marketing communications, we reserve the right to transmit transactional and service communications necessary for the operation of the Service, including service updates, policy amendments, security notices, and account-related notifications, as these are exempt from marketing opt-out requirements under applicable law.
11.4 Please note that Partner entities to whom your data is disclosed pursuant to Section 6 may independently contact you subject to their own privacy policies and consent frameworks. We recommend reviewing the privacy policies of any Partner with whom you engage directly. You may request that we instruct relevant Partners to cease contacting you by submitting a request to our Data Protection Officer.
12.1 Subject to applicable law and any lawful limitations or exemptions thereunder, you are entitled to exercise the following rights in relation to your Personal Data processed by us:
12.2 To exercise any of the foregoing rights, please submit a written request to our Data Protection Officer at the contact details specified in Section 16. We shall acknowledge receipt of your request within seventy-two (72) hours and shall respond substantively within thirty (30) calendar days, or such shorter period as mandated by applicable law. We may require verification of your identity prior to processing your request, in order to safeguard against unauthorised disclosure of your Personal Data.
13.1 The Service is strictly intended for use by individuals who are eighteen (18) years of age or older. We do not knowingly collect, solicit, or process Personal Data from minors below the age of eighteen (18) years, whether directly or indirectly.
13.2 If you are below the age of eighteen (18) years, you are expressly prohibited from using the Service or providing any Personal Data thereto. By using the Service and ticking the consent checkbox on the welcome screen, you represent and warrant that you are at least eighteen (18) years of age.
13.3 If we become aware that we have inadvertently collected Personal Data from a minor below the age of eighteen (18) years, we shall take immediate steps to delete such data from all our records and, where applicable, notify the relevant supervisory authority in accordance with the requirements of COPPA and the DPDP Act. If you believe or have reason to believe that we may have inadvertently collected Personal Data from a minor, please contact our Data Protection Officer immediately.
14.1 If you are a resident of the State of California, United States of America, you are entitled to the following additional rights under the California Consumer Privacy Act, 2018, as amended by the California Privacy Rights Act, 2020:
14.2 To exercise any of the above rights, please submit a verifiable consumer request to our Data Protection Officer as specified in Section 16.
15.1 We reserve the right to amend, revise, or update this Policy at any time to reflect changes in applicable law, regulatory guidance, our business practices, or the features and functionality of the Service.
15.2 Material amendments to this Policy shall be communicated to you via a prominent notice on the Service homepage or via direct communication to the contact details you have provided, at least thirty (30) calendar days prior to the effective date of such amendments, except where a shorter notice period is required by applicable law or is necessitated by an emergency relating to data security.
15.3 The date on which this Policy was last revised is indicated at the top of this document. We encourage you to review this Policy periodically to remain informed of our data practices. Your continued use of the Service following the effective date of any amendment shall constitute your deemed acceptance of the revised Policy. If you do not agree with any amendment, you must discontinue your use of the Service and may exercise your right to erasure as described in Section 12.
16.1 In accordance with Rule 5(9) of the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and Article 37 of the GDPR, we have appointed a designated Data Protection Officer ("DPO") / Grievance Officer to oversee our compliance with applicable data protection laws and to address grievances relating to the collection, storage, processing, transfer, and disclosure of your Personal Data.
16.2 Upon receipt of a written grievance, our DPO shall: (a) acknowledge receipt within twenty-four (24) hours; (b) commence investigation within seventy-two (72) hours of acknowledgement; and (c) provide a substantive resolution or reasoned response within thirty (30) calendar days of receipt of the grievance. In the event of complex matters requiring extended investigation, we shall communicate interim updates at intervals not exceeding fifteen (15) calendar days.
16.3 In the event that you remain dissatisfied with the resolution offered by our DPO, you may escalate your grievance to the Proprietor of Bharra Brothers at the registered office address, who shall personally review escalated complaints and provide a final determination within fifteen (15) calendar days of receipt of the escalation.
16.4 Your right to escalate a complaint to the relevant supervisory authority (including the Data Protection Board of India, the EU Data Protection Authorities, the ICO, the CPPA, or the OAIC) is entirely unaffected by the internal grievance process described in this Section, and may be exercised at any time without first pursuing internal remedies, except where applicable law requires exhaustion of internal remedies.
17.1 This Policy and any dispute, controversy, or claim arising out of or in connection with this Policy, the Service, or the processing of your Personal Data shall be governed by, construed, and enforced in accordance with the laws of the Republic of India, including without limitation the Information Technology Act, 2000, the Digital Personal Data Protection Act, 2023, and the Indian Contract Act, 1872, without prejudice to the mandatory data protection laws applicable in your jurisdiction of residence.
17.2 Subject to Section 17.3, any dispute, controversy, or claim arising out of or in connection with this Policy or the processing of your Personal Data that cannot be resolved through the grievance mechanism described in Section 16 shall be subject to the exclusive jurisdiction of the competent civil courts located in Mumbai, Maharashtra, India. You irrevocably submit to the personal jurisdiction of such courts for the purposes of litigating any such dispute.
17.3 Nothing in this Section shall be construed to limit your right to bring a complaint before or seek assistance from the relevant data protection supervisory authority in your jurisdiction of residence, including the Data Protection Board of India, the EU Data Protection Authorities, the UK Information Commissioner's Office, the California Privacy Protection Agency, or the Office of the Australian Information Commissioner. Such regulatory remedies are available concurrently and independently of any court proceedings.
For any queries, concerns, requests, or complaints relating to this Privacy Policy or the processing of your Personal Data, you may contact us through any of the following channels: