Legal
Privacy policy
What we collect, why, how long we keep it, and how to have it removed. Written against what the apps actually do — if a sentence here is not true of the software, it is a bug and we want to hear about it.
Last updated 31 August 2026
1Who we are
JustSell buys, repairs and resells consumer electronics in India. This policy covers the JustSell website and the JustSell apps for iOS and Android.
JustSell is the trade name of a proprietorship registered in Karnataka. The proprietor is the data fiduciary for everything described here, under India’s Digital Personal Data Protection Act, 2023. Our legal name, principal place of business and GSTIN are at the foot of this page and on every page of the site.
2What we collect, and when
To identify you. A mobile number or an email address — whichever you sign in with. We never ask for a password and never store one. Sign-in uses a one-time code, held only as a cryptographic hash, valid for ten minutes, usable once.
To value your device. The model and storage size, and your answers to the condition questions. In the apps, the on-device diagnostic also produces readings — whether the touchscreen responded across the display, whether a played tone was heard by the microphone, whether each camera produced a live image, whether the motion sensors and biometric hardware responded, and the battery’s charge level. Those readings are sent with your valuation and stored against it, so the person who collects the device can check the grade against what the phone measured rather than take it on trust.
To collect and pay for it. A name, a contact number for the visit, and either a collection address or the counter you have chosen to bring it to. Your chosen settlement method.
To keep your history. Your valuations, orders, repair bookings and vault credit balance.
3What the diagnostics do not do
The camera test captures frames from each lens, measures whether the sensor produced a live image, and discards them immediately. They are never shown to you, never written to storage and never uploaded. The speaker test plays a tone and measures its loudness through the microphone; the recording is discarded the moment the measurement is taken. No photograph and no audio recording ever leaves your device.
We also cannot read your serial number, IMEI or device UDID. Apple closed that to third-party apps in iOS 7 and Android restricted the equivalent in Android 10. Any service claiming to read them is either asking you to type them in or is managing your device.
4What we never collect
We do not take card numbers, bank credentials, UPI PINs or net-banking logins. We are paying you, not charging you: your payout details are taken at collection by the person handling the device, and are not entered into the app. Anyone asking you for a PIN or an OTP for your bank in our name is not us.
We do not sell your data, and we do not share it with advertising networks or data brokers.
5Messages you receive
Transactional messages — a sign-in code, a collection confirmation, an erasure certificate — are part of the service and are sent because you asked for something. Marketing is separate, defaults to off, and stays off until you turn it on. You can change it at any time in Account → Preferences in the app, and withdrawing consent is as easy as giving it.
6How long we keep it
Sign-in codes expire in ten minutes and are deleted on use. Sessions expire and can be revoked by signing out.
Records of a completed transaction — what we bought, what we paid and where we collected it — are kept while we are required to keep them under Indian tax and accounting law, and for as long as any warranty or dispute on that transaction can still be raised. We do not delete them on a timer, and we would rather say so than describe an automatic erasure we do not perform.
Everything else can be deleted on request. See deleting your data.
7Your rights
Under the DPDP Act you may ask us for a copy of what we hold on you, ask us to correct anything wrong, ask us to delete it, withdraw a consent you gave, and nominate someone to exercise these rights if you cannot. Write to us and we will answer.
8How it is protected
The site and apps talk to us over HTTPS only. Session tokens are stored as hashes rather than as the tokens themselves, so a copy of our database is not a set of live logins. Staff passwords use a memory-hard hash. Staff access is graded by role, and every change a member of staff makes to a price, a booking or an account is recorded with who made it and when.
No system is perfect. If you believe your account has been accessed by someone else, write to us and we will revoke every active session on it.
9Children
JustSell is not for under-18s. We do not knowingly collect data from a child, and selling a device to us requires an adult.
10Changes
If we change this policy we will change the date at the top. If a change materially affects what we do with your data, we will tell you rather than rely on you re-reading the page.
Who to contact
Write to concierge@justsell.in or call +91 80 4718 2200, Mon–Sat, 9 am – 9 pm IST.