Compliant with India's DPDP Act 2023
Last updated: July 2026
Privacy Policy
We take your privacy seriously. This Policy explains what data we collect, why we collect it, and how you can control it.
1. Overview
Groomsta Technologies Pvt. Ltd. ("Groomsta", "we", "our", or "us") is committed to protecting your personal data. This Privacy Policy explains how we collect, use, store, and share information when you use our platform — website, mobile app, and related services.
This Policy is compliant with India's Digital Personal Data Protection (DPDP) Act, 2023, and applies to all users of the Groomsta Platform.
By using Groomsta, you consent to the data practices described in this Policy. If you do not agree, please discontinue use of the Platform.
2. Data We Collect
We collect data that you provide directly and data generated by your use of the Platform:
Account Data: Name, email address, phone number, gender, and profile photo (if provided).
Booking Data: Service selections, preferred professionals, booking slots, addresses entered for home services, and booking history.
Payment Data: Transaction IDs, payment method type, and order amounts. We do not store card numbers, UPI IDs, or banking credentials — these are handled exclusively by Razorpay.
Location Data: When you use our home service booking feature, we collect the address you enter. With your permission, we may access your device's approximate location to suggest nearby professionals and salons. You can disable location access at any time in your device settings.
Usage Data: Pages visited, features used, session duration, device type, browser, OS version, and IP address.
Communications: Messages sent to our support team and any feedback or reviews you submit.
Cookies & Tracking: See Section 8 for our cookie policy.
3. How We Use Your Data
We process your personal data for the following purposes, each grounded in a legitimate legal basis:
Fulfilling your bookings and purchases (Contractual necessity)
Matching you with available professionals or partner salons (Contractual necessity)
Processing payments securely through Razorpay (Contractual necessity)
Sending booking confirmations, reminders, and service updates (Contractual necessity)
Providing customer support and resolving disputes (Legitimate interest)
Personalising your experience — e.g., recommended services, AI-matched professionals (Consent)
Sending marketing communications — offers, new services, platform updates (Consent — opt-in only)
Improving the Platform through analytics and A/B testing (Legitimate interest)
Complying with applicable laws and regulations (Legal obligation)
4. Authentication
Groomsta uses Supabase Auth to manage user authentication. Your login credentials are stored as salted, hashed values — we never store plain-text passwords.
Authentication sessions are protected using secure, httpOnly cookies and short-lived access tokens. You can sign out from any device, which immediately invalidates your active session.
Social login (Google, etc.) may be introduced in a future update. When enabled, we will only receive the data explicitly authorised by you through the third-party provider.
5. Payment Information
All payments are processed by Razorpay, a third-party payment processor that is PCI-DSS Level 1 certified — the highest standard for payment security.
Groomsta does not receive, store, or have access to your full card number, CVV, UPI PIN, or net banking credentials.
We store only the transaction ID, payment status, and amount for order records and support purposes. This data is retained for 7 years in accordance with Indian accounting and tax law.
7. Data Retention
We retain your personal data only as long as necessary for the purposes described in this Policy:
Account data: Retained while your account is active, plus 30 days after account deletion to allow for reactivation.
Booking and transaction records: Retained for 7 years to comply with Indian accounting and tax regulations.
Support communications: Retained for 2 years.
Usage and analytics data: Retained in aggregated, anonymised form for up to 3 years.
After the retention period, data is securely deleted or anonymised. You may request early deletion of your account and personal data by contacting hello@groomsta.in.
9. Marketing Communications
We will only send you marketing communications (offers, newsletters, platform updates) if you have explicitly opted in.
You can withdraw consent for marketing communications at any time by:
• Clicking "Unsubscribe" in any email we send
• Updating notification preferences in your account settings
• Emailing hello@groomsta.in with the subject line "Unsubscribe"
We will honour unsubscribe requests within 10 business days. You will continue to receive transactional communications (booking confirmations, support replies) regardless of marketing preferences.
10. Your Rights (DPDP Act 2023)
Under India's Digital Personal Data Protection Act, 2023, you have the following rights:
Right to Access: Request a copy of the personal data we hold about you.
Right to Correction: Request that inaccurate or incomplete data be corrected.
Right to Erasure: Request deletion of your personal data, subject to our legal retention obligations.
Right to Grievance Redressal: Raise concerns about how your data is handled. We will respond within 30 days.
Right to Nominate: Nominate a person to exercise these rights on your behalf in the event of your death or incapacity.
To exercise any of these rights, contact our Data Protection Officer at:
Email: privacy@groomsta.in
Subject: DPDP Rights Request — [Your Name]
We will acknowledge your request within 3 business days and respond within 30 days.
11. Security
We implement industry-standard technical and organisational measures to protect your personal data, including:
• End-to-end encryption for data in transit (TLS 1.3)
• Encrypted storage at rest for sensitive data
• Regular security audits and penetration testing
• Role-based access controls — only authorised personnel can access personal data
• Incident response procedures with mandatory user notification for material breaches
No security measure is 100% infallible. If we become aware of a data breach that affects your personal data, we will notify you within 72 hours as required by applicable law.
12. Children's Privacy
Groomsta is not directed at children under the age of 18. We do not knowingly collect personal data from minors. If we become aware that a minor has registered on the Platform, we will delete their account and associated data promptly.
If you believe a minor has used our Platform, please contact us at hello@groomsta.in.
13. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in law, technology, or our business practices. Material changes will be communicated via email or an in-app notice at least 15 days before taking effect.
Continued use of the Platform after the effective date constitutes acceptance of the updated Policy.
14. Contact Us
For privacy-related queries, rights requests, or complaints:
Data Protection Officer
Groomsta Technologies Pvt. Ltd.
Email: privacy@groomsta.in
General: hello@groomsta.in
Support hours: Monday – Sunday, 9 AM – 9 PM IST
