Boloy

Privacy Policy

Last updated: September 12, 2026

This policy explains what information Boloy collects from students who use the platform, how we use it, and the choices you have.

1. Information we collect

We collect the following categories of information:

  • Account information: your name, email address, and password (stored as a secure hash, never in plain text).
  • Profile information you add: university, phone number, department, batch, and bio.
  • Student verification: a photo of your student ID, which is stored privately and only visible to admins reviewing your verification request.
  • Task and bid content: titles, descriptions, locations, declared prices, and messages you post. Boloy never collects or processes the actual payment for a task — see Section 2.
  • Token purchase records: the pack you bought, and the bKash Transaction ID (TrxID) you submit for it. We do not collect or store your bKash PIN or full bKash account credentials.
  • Reports and reviews you submit or receive.
  • Basic technical data such as IP address and browser information, collected automatically for security and abuse prevention.

2. How we use your information

  • To operate the core marketplace: posting tasks, bidding, matching, and messaging. Payment for a task is arranged directly between a Poster and a Runner — Boloy is never a party to it.
  • To verify that you're a real student and to show a verified badge on your profile.
  • To process a Token purchase and credit your Token balance.
  • To send you account emails: OTP codes for sign-up and password reset, and notifications about your tasks.
  • To investigate reports, enforce our Community Guidelines, and keep the platform safe.

3. Who we share information with

We don't sell your data. We share the minimum necessary information with the service providers that run the platform:

  • Resend — to deliver account emails (OTP codes, notifications).
  • Vercel Blob — to store your student ID photo securely.
  • Neon (PostgreSQL) — our database provider.
  • bKash — you interact with bKash directly when sending a top-up payment; we only see the transaction reference, not your bKash credentials.

Other students can see your name, department, rating, and verification badge when you post or bid on a task. Your email, phone number, and student ID photo are never shown to other students.

4. Data retention

We keep your account and transaction data for as long as your account is active, and for a reasonable period afterward to resolve disputes, meet legal obligations, and prevent fraud. You can request deletion at any time — see Section 6.

5. Security

Passwords are hashed, not stored in plain text. Student ID photos are stored with private access and only reachable through an admin-authenticated route. Token balances are only ever modified through server-side, atomic transactions.

6. Your rights and account deletion

You can review and update most of your profile information from your account. To request that we delete your account and personal data, visit our account deletion page. This works whether or not you're able to log in. We'll confirm your request and process it within a reasonable time, retaining only what we're legally required to keep.

7. Changes to this policy

If we make material changes to this policy, we'll update the date at the top of this page and, where appropriate, notify you by email.

8. Contact

Questions about this policy? Email us at teamboloy@boloy.net.