Wealth Vision Research (SEBI Research Analyst Reg. No. INH000029379, BSE Enlistment No. 7419) respects your privacy. This Privacy Policy covers the Wealth Vision Research Android app (package com.wealthvisionresearch.wealthapp), https://wealthvisionresearch.com and our related research services. It explains the data we collect, why we use it, who receives it, how it is protected and retained, and how you can exercise your rights.
If the app is distributed by a verified Google Play organization account with a legal name different from Wealth Vision Research, that organization acts as the authorized app publisher identified on the Play listing. Wealth Vision Research remains the Research Analyst service provider and is responsible for the app data practices described here.
1. Information We Collect
App account and authentication data
- Phone and sign-in: Indian mobile/WhatsApp number, OTP challenge status, verification time and security attempt records. OTP values are stored only as protected digests and are invalidated after successful use.
- Account and profile: internal client/account identifier, full name, customer type, optional email where provided, consent versions and acceptance times.
- Device and session: app-generated device identifier, device name/platform, session creation and last-use times, refresh-token digest, IP-derived security digest and session revocation status.
KYC, payment and service data
- KYC/PAN: PAN number, name as printed on the PAN card, date of birth and, when you choose photo-based review, a PAN card photograph taken with the camera or selected through the system photo picker. We also collect the PAN-holder name returned by the verification provider, verification reference, status, review notes and dates. PAN numbers and uploaded card photographs are stored using authenticated encryption. Authorized compliance staff can review the submitted photograph; routine PAN-number displays use only the last four characters. You can use PAN-number verification instead of uploading a photograph.
- Payments and subscriptions: selected product/plan, price, currency and service duration, order and subscription/mandate references, payment status/time and entitlement records. Cashfree processes the checkout and subscription authorization in Cashfree-enabled app releases. Where Google Play billing is enabled, we record Play product/order identifiers and a keyed hash of the purchase token. The payment provider processes your payment method under its applicable terms; our account and advertising-event code does not collect card numbers, CVV, UPI PIN, banking passwords or Google passwords.
- Research service: subscription, entitlement, research delivery history where recorded, and related consent, support, complaint and audit records.
Communications and notifications
- Support and enquiries: name, email address, phone number, subject, message, attachments or references you choose to provide, and our response/resolution record.
- Push notifications: app-generated device identifier, Firebase Cloud Messaging or Expo push token, platform, enabled status and delivery results. Notification permission is optional.
- Correspondence: emails, WhatsApp messages and legally verifiable records of service-related communications.
Technical, website and campaign data
- Technical logs: IP address, browser or app user-agent, requested URL/API route, timestamp, app/runtime version and diagnostic/security events generated by our systems or infrastructure.
- Website cookies: an essential session cookie secures forms. The
/biocampaign page uses Meta Pixel identifiers and Google Ads click identifiers. The/liveclasspage retains advertisement identifiers long enough to measure a verified payment. - Mobile analytics and advertising measurement: Android releases with measurement enabled use Firebase Analytics and Meta App Events to measure installation/app activation, completed registration, checkout initiation, trial authorization and confirmed paid purchases. These SDKs may process device/app identifiers, the Android advertising identifier when available, IP address, IP-derived coarse location, app/device information and event timestamps. Registration events include the sign-up method without your phone number. Purchase events include plan/product identifiers, an order/transaction identifier, the confirmed amount and currency. Our event code does not send names, phone numbers, date of birth, PAN, PAN photos, payment tokens or sign-in credentials to these analytics SDKs.
2. Android Permissions and Data Not Requested
The Android app requests notification permission so it can deliver optional research alerts. For PAN-photo KYC, it may request camera access or let you choose a photo through the system picker. Releases with advertising measurement enabled may access the Android advertising identifier when available. The app does not request access to contacts, SMS, call logs, precise or approximate location, or the microphone. It does not connect to a broker, trading, demat or bank account and does not collect those account passwords or OTPs.
3. Why We Use Information
- authenticate users, secure accounts, maintain signed-in devices and prevent fraud or abuse;
- provide free and paid research content, verify payment and subscription status and maintain entitlements;
- send optional research and account notifications;
- complete Research Analyst client onboarding, PAN verification and KYC obligations;
- record consent, research delivery, payments, refunds, support and complaints as required by law;
- operate, diagnose, secure and improve the app, website and related infrastructure;
- respond to enquiries, deletion requests, grievances and legal or regulatory requests; and
- measure the website campaigns and enabled mobile advertising events described in section 9.
We do not sell or rent personal information. We do not send personal account details or KYC/PAN data through our mobile advertising-event code. In measurement-enabled releases, limited confirmed purchase-event data is used to measure and optimize advertising as described below.
4. Legal Basis and Consent
We process data with your consent, to perform the service agreement, for legitimate security and operational purposes, and to comply with Research Analyst, tax, accounting, payment, grievance and other Indian legal obligations. You may withdraw consent where processing depends on consent, but this does not override records we are legally required to retain.
5. Service Providers and Disclosure
We limit disclosure to what is necessary for the stated purpose. Recipients may include:
- Meta/WhatsApp: delivery of requested sign-in OTP messages, disclosed website campaign measurement, and Meta App Events in measurement-enabled Android releases;
- Google: Google Play Billing and purchase verification where used, Firebase Cloud Messaging for Android notifications, Firebase Analytics in measurement-enabled Android releases, Google Fonts on the website and Google Ads campaign measurement where described below;
- Expo: app update delivery and iOS push routing where applicable;
- KYC and payment providers: PAN verification, and Cashfree payment/subscription/refund processing in enabled app releases and website services;
- Infrastructure providers: hosting, database, security, backup and communications services acting on our instructions;
- Professional and regulatory recipients: auditors, compliance advisers, SEBI, RAASB, courts or other lawful authorities where required; and
- Telegram: only when you choose to request access to our channel through the relevant website campaign.
These providers may process limited technical data such as IP address, device/app information and service logs as part of their operation. Their processing is also governed by their applicable terms and privacy notices. We do not share personal information with third parties for their own direct marketing.
6. Security
We use HTTPS in transit; authenticated encryption for stored PAN numbers and uploaded PAN card photographs; keyed hashes for PAN matching, purchase tokens, refresh tokens and selected security identifiers; short-lived access tokens; revocable device sessions; rate-limited, expiring and single-use OTP challenges; role-based access to administration; audit trails; server-side validation; restricted file permissions; and software/security maintenance.
No transmission or storage method is completely secure. Do not share an OTP, full PAN, payment secret, bank password or trading credential through an ordinary support message.
7. Data Retention
- Research Analyst client, KYC, consent, payment and service records: generally at least five years from the end of the relationship, and longer when litigation, a complaint or regulatory examination remains open.
- Account sessions and OTP records: retained only for their operational life and a limited security/audit period. Active sessions are revoked when the user logs out, revokes a device or deletes the account.
- Push tokens: retained while needed for requested notifications and disabled on account deletion or when no longer valid.
- Support and enquiry records: generally up to 24 months unless they become part of a client, complaint, transaction, security or legal record.
- Technical and campaign records: retained for limited security, diagnostics, attribution and deduplication periods, then deleted or anonymised.
When a retention period ends, data is deleted or anonymised using a reasonable operational process.
8. Account and Data Deletion
In the Android app, open Profile → Delete account and confirm the request. If you cannot access the app, use the public Account Deletion page. Account closure immediately revokes sessions and disables push delivery. Associated data not needed for a legal, payment, refund, complaint, fraud-prevention or security purpose is deleted or anonymised; legally required records remain restricted until their retention period ends.
9. Website Cookies and Mobile Campaign Measurement
The main statutory website uses an essential session cookie. The standalone /bio campaign page may load Meta Pixel and retain Google Ads click identifiers. A one-use Telegram invite can be associated with those identifiers long enough to measure a confirmed subscription. A Cashfree-verified /liveclass payment may produce a standard purchase event containing value, currency, campaign identifiers, IP address, browser user-agent and a one-way hash of the verified WhatsApp number. You may block website cookies or tracking; core statutory pages remain available.
Mobile measurement is separate from website measurement. When enabled in an Android release, Firebase Analytics and Meta App Events report the events described in section 1 to help us understand installations, registrations, checkout, trial uptake and paid subscriptions, and to measure and optimize app advertising through linked Google and Meta advertising accounts. A trial authorization is recorded as a trial rather than full subscription revenue; a purchase is recorded only after our API confirms a paid charge. Older or measurement-disabled app releases do not send these mobile events through our integration. Android's advertising-ID controls can limit use of that identifier, but do not by themselves stop all app analytics. Use our privacy contact below for questions or requests about this processing.
10. Your Choices and Rights
- request access to or correction of personal data;
- delete your app account and data not subject to required retention;
- withdraw consent for optional processing and disable notifications in Android settings;
- unsubscribe from non-essential communications; and
- raise a privacy complaint with our Grievance & Data Protection Contact.
Use our secure contact form. We aim to respond within 30 days after verifying identity. Research-service complaints also follow the process on our Grievance Redressal page.
11. Children
The app and research services are intended only for adults aged 18 or older. We do not knowingly collect app account data from children. If you believe a child has provided information, contact us so we can investigate and delete it where retention is not legally required.
12. International Processing and External Services
Some technology providers may process limited data on infrastructure outside your state or country, subject to their service arrangements and applicable law. Our website and app also link to external services, including Google Play, SEBI and grievance portals, which publish their own privacy practices.
13. Changes to This Policy
We may update this policy when the app, providers or legal requirements change. The revised version will appear here with a new date. Material changes affecting existing users will also be communicated through an appropriate available channel.
14. Privacy Contact
Arun Kumar S. — Grievance & Data Protection Contact
Wealth Vision Research, No. 25/1, Edwin Nagar, Ganapathy, Coimbatore, Tamil Nadu, 641006, India
Online contact: Secure contact form · Phone: +91 90956 79744
Last updated: 1 October 2026.