Privacy policy
Effective 26 September 2026 (updated the same day for the usage details above). RRCM is an IPO information app operated by Radhe Radhe Capital Market.
Information on your phone
The app stores followed IPOs, application records, family member names, optional last four demat digits, notification choices, and a local profile. Public IPO data is cached for offline use. If you ask your RM to apply, the details you enter (below) are kept on the phone encrypted with a key held in Android's secure keystore, so you only enter them once. The app never asks for a UPI PIN, bank password, broker password, or one-time code.
Applications placed by your RM
When you choose “Let my RM apply” and tick the consent box, the app sends RRCM's application desk exactly what an IPO bid needs: your full name, mobile number, email, PAN, demat account number (DP ID and client ID), UPI ID, and the IPO, lots and amount you chose. RRCM uses them to place that application through its partner broker and to contact you about it. They are encrypted on RRCM's servers; only RRCM's application desk staff can read them, and every view is logged. We keep them while you are an RRCM client and for as long as records of applications must be kept by law; ask [email protected] to delete them sooner where the law allows. We never sell them or use them for advertising.
After your RM places a bid, the app can listen for the bank SMS about your UPI mandate using Android's SMS consent prompt. Android asks you each time; only the single message you allow is read, only to see whether it is about this mandate, and it is not stored or sent to RRCM — the app only tells your RM that a mandate request or approval was seen.
Your RRCM account
To apply through RRCM you sign in with Google. Google tells RRCM your name, email address and a Google account number, and RRCM checks with Google that the sign-in is genuine. RRCM keeps those three things and a sign-in token (only a scrambled form of it) so your applications are tied to you and appear on any phone you sign in on. RRCM never sees your Google password and asks Google for nothing else. Signing out removes the token from your phone and from RRCM. “Delete my account” also deletes the RRCM account; applications already placed stay on record as the law requires, no longer linked to it.
Reading your PAN card and statement
If you choose “Scan my PAN card”, the photo is read on your phone to find your PAN (and name), then deleted; it is never uploaded. If you choose “Get it from my CAS”, the statement NSDL or CDSL emailed you is opened on your phone with the password you give (your PAN by default); the app only looks for your demat account numbers, and only the one you pick goes into your application. The statement and the holdings in it never leave your phone.
Information sent to RRCM
Market-data requests reach the RRCM server. Unless you turn off “Improve your experience”, the app shares app usage: a random installation ID and selected actions from fixed lists — IPOs viewed and followed, tabs and sections opened, how long an IPO page stayed open (in broad ranges), whether a search found results (never the words typed), steps in planning an application (never the amount), your broker choice from a fixed list, whether notifications are on, light or dark theme, text-size range, and network type; how you move through the lists (swipes, cards opened and folded, sort and view choices), which story cards and term explanations you open, whether you tapped to talk to RRCM or open a demat account, how long each visit lasted (in broad ranges), and if the app crashed, the broad kind of error and the part of the app (never its message). When you check allotment in the app, RRCM receives which registrar was used and what it answered (allotted, not allotted, not found, or could not check) and whether it was your PAN or a family member's; never the PAN itself or the number of shares. We use this to decide what to build, which IPOs people care about, and whether updates reach them. You may separately send structured issue-data feedback. Contact names and phone numbers are not accepted through the public analytics endpoint. Individual product events are deleted from the live server after 90 days. Before that, they are combined into daily totals per IPO and screen that contain no installation or session IDs; those totals are kept to understand long-term use. A daily summary per installation (how many actions, sessions and IPOs, and the app version) is kept for two years, so we can see how many people come back over time; it contains no IPO names, screens or choices. After two years it is reduced to monthly counts with no installation IDs. Server logs may contain routine network information needed to operate and protect the service.
Sources and supporting services
RRCM receives IPO data from IPO Guru and IPOAlerts and may use authorized exchange sources. The Android app talks to the RRCM server; IPO Guru credentials stay on the server. RRCM keeps a copy of the IPO data it receives, and a record of how it changed over time, to check its accuracy and improve the app; it is not passed on to anyone. Production builds use Google Firebase Crashlytics for crash diagnostics and Firebase Performance Monitoring for app and network performance. These services may receive device, app, diagnostic, and network information. Firebase Analytics follows the app's usage-sharing switch; it receives only selected event names, IPO IDs, and screen categories, without names, search text, or account numbers. Firebase Cloud Messaging is included for future remote alerts but automatic token generation is disabled in this release. Reminders currently come from the phone. No advertising SDK is included.
Your choices and deletion
Usage sharing (called “Improve your experience” in the app) is on for new installs. You can turn it off on the “Before you continue” note when you first open the app, or any time under You → Legal; turning it off deletes usage events still waiting on your phone and stops new ones. PAN, bank, UPI, demat and contact details, anything you type, and application amounts are never part of usage sharing; details you give for an RM application go only to RRCM's application desk. “Delete my account” (You → Legal) removes the local profile, saved application details, family, applications, follows, events, and notification history. It keeps the public IPO cache. It also asks RRCM's server to erase the usage history, daily summaries and any contact details held for this installation; if you are offline, the request is sent the next time the app connects. Backups expire after 35 days, and a deletion is re-applied if an older backup is ever restored. Monthly and daily totals that contain no installation ID are kept. Diagnostics already delivered to Google are not affected. Applications placed by your RM are kept as the law requires. For anything else, contact [email protected]. Do not email PAN or account credentials.
Contact
For privacy questions, email [email protected]. RRCM will update this policy when data processing changes.