Privacy Policy

Protecting your data, compliance standards, and information security frameworks at Grapino Technology.

Privacy Policy

Effective Date: August 17, 2026


1. Introduction & Compliance

Grapino Technology ("we", "our", or "us") is deeply committed to protecting the privacy and security of our users, vendors, and marketplace participants. This Privacy Policy outlines how we collect, use, store, and safeguard your information in compliance with the Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (SPDI Rules).

2. Strict Zero-Data-Selling Guarantee
Explicit Commitment: Grapino Technology does not sell, rent, trade, or commercialize personal profiles, customer transactional data, vendor banking archives, or contact details to third-party data brokers, marketers, or unauthorized entities under any circumstances.
3. Information We Collect
  • Personal & Business Identification: Legal name, business name, address, email address, and phone numbers.
  • Statutory & Financial Records: PAN, GSTIN, Udyam Registration details, and verified bank account credentials required for weekly payouts and automated tax deductions (TCS/TDS).
  • Technical Data: IP addresses, browser types, device information, and session tokens managed via secure database storage drivers.
4. Data Security & Protection Safeguards

We deploy robust technical, administrative, and physical security measures—including SSL/TLS encryption protocols, hashed credentials, and secure server access permissions—to protect your Sensitive Personal Data or Information (SPDI) against unauthorized access, alteration, disclosure, or destruction.

5. Grievance Redressal Mechanism

In accordance with applicable Indian cyber laws, if you have any questions, concerns, or grievances regarding your data privacy or security practices on Grapino Technology, you can reach out to our designated Grievance Officer through our support portal. All privacy requests are acknowledged within 48 hours and resolved within the statutory timeline of 30 days.