Privacy Policy
Last updated 14 August 2026
Badhat sends IPO application emails on an investor’s behalf, from that investor’s own Gmail account, using a permission the investor grants explicitly and can withdraw at any time. This policy describes exactly what data that involves.
1. Who we are
Badhat is an IPO application email automation tool. Investors are invited by an administrator — typically their broker or advisor — through a private, single-purpose link. Investors do not create a Badhat account or password.
2. Google user data we access
Badhat requests the following OAuth scopes and no others. Each is requested only at the moment an invited investor authorizes Badhat, and only for the purpose stated.
https://www.googleapis.com/auth/gmail.sendSENSITIVESend the IPO application email from the investor's own Gmail account to their admin's fixed delivery address. This scope can only send mail — it grants no ability to read, search, download, modify, or delete anything in the mailbox.
openid, email, profileConfirm that the Google account completing the authorization is the same address the invitation was issued to, so one investor's invitation cannot be used to authorize a different mailbox.
Badhat cannot read your email. The gmail.send scope is send-only. Badhat has no ability to open your inbox, list your messages, read their contents, download attachments, or delete anything. No Gmail message content is ever retrieved into Badhat.
3. Limited Use disclosure
Badhat’s use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, Badhat does not:
- Sell, rent, or trade Google user data to anyone, under any circumstances.
- Use Google user data for advertising, retargeting, or building advertising profiles.
- Use Google user data to train, fine-tune, or improve any generalized or artificial intelligence or machine learning model.
- Transfer Google user data to third parties except as strictly necessary to provide the service (see section 6), to comply with applicable law, or as part of a merger or acquisition with prior notice and consent.
- Allow humans to read Google user data, except with the user’s explicit consent for a specific issue they raised, where required by law, or where necessary for security purposes such as investigating abuse.
4. Other information we collect
- Identity given by your administrator: your name, email address, and WhatsApp number, entered by the administrator who invited you so that the invitation can reach you.
- Authorization records: your Google account identifier, the scopes you granted, and the timestamps of grant, expiry, and any renewal or revocation.
- Google OAuth tokens: the access and refresh tokens Google issues when you authorize Badhat.
- Delivery records: for each email sent on your behalf, the campaign it belonged to, the destination address, the Gmail message identifier, and whether it succeeded or failed.
- Audit events: a log of consent grants, campaign sends, and revocations, kept so that every action taken on your behalf can be accounted for.
Badhat does not collect, process, or store payment credentials of any kind. It never sees your UPI PIN, never holds funds, and never approves a bank transaction. Every fund-block request is reviewed and approved by you, in your own UPI app.
5. How the data is used
Google user data is used for exactly one purpose: sending an IPO application email from your Gmail account to your administrator’s delivery address when an IPO you are participating in opens. The destination address is fixed on the server and is set to the administrator’s own verified sign-in address — it cannot be changed from the dashboard, so your Gmail authorization cannot be redirected to an outside recipient.
The remaining data is used to deliver, secure, and account for that service: confirming an invitation belongs to you, showing your administrator whether your authorization is still live, and keeping an audit trail.
6. Storage, security, and sub-processors
- OAuth tokens are held encrypted at rest in Supabase Vault, separate from application tables, and are read only by the server-side function that sends your mail.
- Transport to Google and Supabase is over TLS.
- Access to your record is scoped to the single administrator who invited you. Administrators cannot see one another’s investors.
We rely on the following sub-processors, and no others:
- Google LLC — Gmail API delivery and OAuth.
- Supabase, Inc. — database, encrypted secret storage, and server-side functions.
- Vercel Inc. — application hosting.
- Resend — administrator invitation email only. No investor Google data is sent to Resend.
7. Retention and deletion
Your authorization expires automatically at most 90 days after you grant it, and Badhat stops being able to send on your behalf at that point unless you renew it. Google may end the underlying authorization sooner on its own — if that happens, sending simply stops and your administrator will send you a fresh link to authorize again. Badhat cannot extend either deadline without you granting permission again.
You may withdraw your authorization at any time, in either of two ways, and neither depends on us acting first:
- Remove Badhat’s access directly from your Google Account at myaccount.google.com/permissions. This takes effect immediately at Google.
- Ask your administrator to revoke you, or email us at support@badhat.example.
When a mandate is revoked through Badhat, we revoke the token at Google, destroy the stored secret in Supabase Vault, and delete your delivery and mandate records. Audit events recording that consent was granted and later withdrawn are retained, as the record of a permission that once existed is what makes the system accountable.
8. Your rights
You may request a copy of the data Badhat holds about you, ask for it to be corrected, or ask for it to be deleted, by writing to support@badhat.example. We will respond within 30 days.
9. Changes to this policy
If we change how Google user data is accessed, used, stored, or shared, we will update this page and its effective date before the change takes effect. Badhat will not use your data in a way this policy does not disclose.
10. Contact
Questions about this policy or about data Badhat holds: support@badhat.example