We i.e., 'Megraa Pvt Ltd' (the 'Company'), operators of graame.com, are committed to protecting the privacy and security of your personal information. Your privacy is important to us and maintaining your trust is paramount.
This privacy policy explains how we collect, use, process and disclose information about you. By using our website/app/platform and affiliated services, you consent to the terms of our privacy policy ('Privacy Policy') in addition to our Terms of Use. We encourage you to read this privacy policy to understand the collection, use, and disclosure of your information from time to time, to keep yourself updated with the changes and updates that we make to this policy.
This privacy policy describes our privacy practices for all websites, products and services that are linked to it. However, this policy does not apply to those affiliates and partners that have their own privacy policy. In such situations, we recommend that you read the privacy policy on the applicable site.
Should you have any clarifications regarding this privacy policy, please write to us at [email protected]
1. Applicability and Scope
1.1 Company Information
Megraa Pvt Ltd, operators of graame.com ('Graame,' the 'Company,' 'we,' 'us,' and 'our') respects your privacy and is committed to protecting it. This policy sets out:
- The types of information that Graame may collect from you directly or through automated means when you access or use its website, application and other online services (collectively, referred as 'Services'); and
- Its practices for collecting, using, maintaining, protecting and disclosing that information.
1.2 Service Coverage
This policy applies only to the information Graame collects through its Services, in email, text and other electronic communications sent through or in connection with the Services. This policy does not apply to information that you provide to, or that is collected by, any third-party that you use in connection with its Services. Graame encourages you to consult directly with such third-parties about their privacy practices.
1.3 Consent and Agreement
Please read this policy carefully to understand Graame's policies and practices regarding your information and how Graame will treat it. By accessing or using its Services and/or registering for an account with Graame, you agree to this privacy policy and you are consenting to Graame's collection, use, disclosure, retention, and protection of your personal information as described here. If you do not provide the information Graame requires, Graame may not be able to provide all of its Services to you.
1.4 Policy Updates
This policy may change from time to time, and your continued use of Graame's Services after it makes any change is deemed to be acceptance of those changes, so please check the policy periodically for any updates.
1.5 Age Restrictions
Permissible Age: The Services are not intended for users under the age of 18, unless permitted under applicable local laws ('Permissible Age'). We do not knowingly collect any personal information from users or market to or solicit information from anyone under the Permissible Age.
2. The Information We Collect and How We Use It
Graame collects several types of information from and about users of our Services, which includes:
- Your Personal Information - personal information is the information that can be associated with a specific person and could be used to identify that specific person whether from that data, or from the data and other information that we have; and
- Non-Personal Information – which includes data about your internet connection, the device(s) you use to access our Services, your usage details and other such information that does not pertain to your identity.
We collect this information directly from you when you provide it to us; indirectly from third-parties (such as social media websites authorised by you); and/or automatically as you navigate through our Services (such as usage details, IP addresses, cookies, web beacons and other tracking technologies).
3. Information You Provide to Us
The information we collect on or through our Services may include:
3.1 Personal Information Categories
Identity and Contact Information:
- Name, address, email address, postal code, password and other information you may provide with your account
- Gender, mobile phone number, date of birth, anniversary date, user bio and website
- Alternative contact numbers and emergency contact details
- Government-issued identification documents for verification purposes
- Professional information and occupation details (where relevant)
Your Content and Communications:
- Information you provide through our Services, including ordering details and history
- Contact information of people you provide to us for various features
- Other information you provide on our Services or your account profile
- You have the option to provide contacts including that of your friends or other parties to avail certain Services
- By providing any such information you confirm that you have such individual's consent to share their personal information with Graame
Usage and Activity Data:
- The search terms you have looked up and results you selected
- Your browsing information: How long you used our Services and which features you used; the ads you clicked on
- Your searches and other activities on the platform
- Product preferences, wishlist items, and shopping behavior patterns
- Frequency of app usage and session duration
3.2 Communication Records
Customer Interactions:
- Communications between you and delivery partners, or sellers through our Services, some of which may be recorded for internal purposes
- Your participation in a survey, poll, sweepstakes, contest or promotion scheme
- Your request for certain features (e.g., newsletters, updates or other products)
- Your correspondence with our customer service and other grievance redressal mechanisms
- If you send information from the Services via SMS text message, we may log your phone number, phone carrier, and the date and time that the message was processed
- Carriers may charge recipients for texts that they receive
Feedback and Reviews:
- If you provide specific feedback to us via any mode of communication including emails, we may forward your information to the relevant third party seller, manufacturer or service provider for improving the Services provided to you
- Product reviews, ratings, and feedback submitted through the platform
- Customer service ratings and feedback about delivery experiences
3.3 Transaction and Financial Information
Payment Information:
If you make purchases through our Services, we may collect and store information about you to process your requests and automatically complete forms for future transactions, including (but not limited to):
- Your mobile phone number, address, email, billing information and payment information
- Credit/debit card details, bank account information, and payment preferences
- Transaction history, purchase patterns, and spending behavior
- Payment gateway information and digital wallet details
- This information may be shared with third-parties which assist in processing and fulfilling your requests, including PCI compliant payment gateway processors
- When you submit credit or payment card information, we encrypt the information using industry standard technologies
Order and Delivery Data:
- Detailed order history including items purchased, quantities, prices, and timestamps
- Delivery addresses, delivery preferences, and special instructions
- Delivery tracking information and real-time location during delivery
- Return and refund history with associated reasons and outcomes
- Promotional code usage and discount redemption patterns
3.4 Visual and Audio Data
Image and Video Data:
We may collect and process images and video recordings of individuals attending live events or visiting our office/store/other premises for security and safety purposes. This includes:
- The use of closed-circuit television (CCTV) systems at our facilities
- CCTV footage may capture individuals' images, vehicle information, and other identifying details
- We may also collect photographs or videos during events for promotional or documentation purposes which may be shared with business and/or event partners
- Profile pictures and images uploaded by users to their accounts
- Product photos uploaded in reviews or customer service interactions
Voice Recordings:
- Customer service call recordings for quality assurance and training purposes
- Voice commands and interactions with voice-enabled features
- Audio feedback and complaints recorded through various communication channels
4. Information We Collect Through Automatic Data Collection Technologies
Our Services automatically collect certain information when you access or use them. This includes technical data about your devices, usage patterns, and interaction with our platform through various automated technologies.
4.1 Device and Technical Information
Device Specifications:
- Hardware model, operating system and version, software and file names and versions
- Device identifiers (including advertising identifiers such as Google Advertising ID and IDFA)
- Browser type and version, browser plug-in types and versions
- Time zone setting, operating system, and platform information
- Screen resolution, device orientation, and display characteristics
- Available storage space, RAM specifications, and processing capabilities
Network and Connection Data:
- Internet service provider (ISP) information
- IP address and geolocation data derived from IP address
- Network connection type (WiFi, cellular, etc.) and carrier information
- Connection speed and network quality metrics
- Proxy settings and VPN usage detection
4.2 Usage Data and Behavioral Analytics
Location Information:
- Our applications collect real-time information about the location of your device, as permitted by you
- GPS coordinates, including latitude, longitude, and altitude information
- Location accuracy and precision data
- Historical location patterns and frequently visited places
- Geofenced area entry and exit notifications
Browsing and Navigation Data:
- Last URL visited: The URL of the last web page you visited before visiting our websites
- Page views, time spent on pages, and bounce rates
- Search queries within the platform and external search engines
- Product view history and category browsing patterns
- Cart abandonment data and checkout process analytics
4.3 Mobile Device Identifiers and Analytics
Device Identification:
- Unique mobile device identifier (e.g. IDFA or other device IDs on Apple devices like the iPhone and iPad)
- If you're using our Services on a mobile device, we may use mobile device IDs (the unique identifier assigned to a device by the manufacturer), instead of cookies, to recognize you
- We may do this to store your preferences and track your use of our applications
- Unlike cookies, mobile device IDs cannot be deleted
- Advertising companies may use device IDs to track your use of our applications, track the number of advertisements displayed, measure advertising performance and display advertisements that are more relevant to you
- Analytics companies may use mobile device IDs to track your usage of our applications
Preferences and Settings:
- Your preferences/settings such as time zone and language
- Notification preferences and permission settings
- Accessibility settings and customizations
- Theme preferences and display options
- Communication preferences and opt-in/opt-out choices
4.4 Application and Platform Analytics
Usage Analytics:
- Your activity on the Services, such as your search queries, comments, domain names, search results selected
- Number of clicks, pages viewed and the order of those pages, how long you visited or engaged with our Services
- The date and time you used the Services, error logs, and other similar information
- Feature usage statistics and user journey mapping
- A/B test participation and variant assignments
Mobile Status and Performance:
- For mobile application users, the online or offline status of your application
- App crash reports and performance metrics
- Loading times and response speeds
- Memory usage and storage consumption
- Battery impact and resource utilization
Application Environment:
- If you use the Graame application, Graame may collect information about the presence and/or absence and/or details pertaining to other applications on your mobile phone
- The applications we gather information for, may vary across categories including, without limitation, shopping, fashion, food and travel
- This will help us understand you and your preferences better and enable Graame to provide you with a personalized experience
- Operating system version and security patch levels
- System fonts, languages, and regional settings
4.5 Advanced Tracking Technologies
Cookies and Similar Technologies:
Graame and its third parties with whom we partner, may use cookies, pixel tags, web beacons, mobile device IDs, 'flash cookies' and other similar files or technologies to collect and store information in respect to your use of the Services and third party websites. This enables us to:
- Recognize you (for example, as a registered user)
- Store your preferences and settings
- Enhance your experience by delivering content and advertising specific to your interests
- Perform research and analytics, track your use of our Services
- Assist with security and administrative functions
- Graame may use pixel tags to measure the popularity of our various pages, features and services
- We also may include web beacons in e-mail messages or newsletters to determine whether the message has been opened and for other analytics
Cross-Device Tracking:
- Linking multiple devices used by the same user
- Synchronizing preferences and data across devices
- Cross-platform behavior analysis and user journey mapping
- Multi-device advertising and personalization
- Device fingerprinting and identity resolution
5. Information We Collect From Third Parties
5.1 Social Media Integration
Social Media Account Information:
We may collect, process and store your user ID associated with any social media account (such as your Facebook and Google account) that you use to sign into the Services or connect with or use with the Services. When you sign in to your account with your social media account information, or otherwise connect to your social media account with the Services, you consent to our collection, storage, and use, in accordance with this Privacy Policy, of the information that you make available to us through the social media interface. This could include, without limitation:
- Any information that you have made public through your social media account
- Information that the social media service shares with us
- Information that is disclosed during the sign-in process
- Social media profile information, posts, and interaction history
- Friend lists and social connections
- Please see your social media provider's privacy policy and help center for more information about how they share information when you choose to connect your account
5.2 Third-Party Data Sources
External Data Providers:
We may also obtain information about you from third parties such as:
- Partners, marketers, third-party websites, and researchers
- Data aggregators and marketing companies
- Credit bureaus and financial institutions (for creditworthiness assessment)
- Background verification agencies and identity verification services
- Public databases and government records
- Business intelligence and market research providers
- We combine that information with information which we collect from or about you
Business Partner Information:
- Merchant and supplier data about product preferences and purchase history
- Delivery partner feedback and ratings about user behavior
- Marketing partner data about engagement and campaign effectiveness
- Corporate client information for business-to-business services
- Affiliate program data and referral information
5.3 Data Enhancement and Enrichment
Profile Enrichment:
- Demographic data from market research companies
- Lifestyle and interest data from consumer profiling services
- Income and employment information from verified sources
- Property and asset information from public records
- Educational and professional background from career platforms
6. How We Use the Information We Collect
We primarily collect your data to provide you the Services that you opt for. Our Services are backed by a wide array of supporting services that directly or indirectly improve the Services offered to you. We use the information we collect from and about you for a variety of purposes, including to:
6.1 Core Service Operations
Platform Administration:
- Administer our Services by sharing information with third parties that are used to facilitate the Services, such as delivery partners, service providers and vendors
- Process and respond to your queries and complaints
- Verify your identity and prevent fraud or unauthorized access
- Maintain and improve the security and reliability of our platform
- Manage user accounts, profiles, and preferences
Order Processing and Fulfillment:
- Process orders, coordinate with merchants and delivery partners
- Manage inventory, pricing, and product availability
- Coordinate delivery logistics and real-time tracking
- Handle returns, refunds, and exchanges
- Generate invoices, receipts, and transaction records
6.2 Personalization and User Experience
Content and Service Personalization:
- Understand our users (what they do on our Services, what features they like, how they use them, etc.)
- Improve the content and features of our Services (such as by personalizing content to your interests)
- Process and complete your transactions
- Offer customised deals and other services tailored on the basis of your preferences
- Provide personalized product recommendations and search results
- Customize the user interface and experience based on usage patterns
Analytics and Insights:
- Generate and review reports and data about, and to conduct research on, our user base and Service usage patterns
- Analyze user behavior to improve product offerings and service quality
- Conduct A/B testing and experimentation to optimize platform features
- Market research and competitive analysis
- Predictive modeling for demand forecasting and inventory management
6.3 Communication and Marketing
Customer Communications:
- Send you communications that you have requested or that we determine to be of interest to you by way of emails, courier, registered post, telephone calls, SMS, WhatsApp messages or any other mode of communication
- This includes customer support and grievance redressal
- Send order confirmations, delivery updates, and service notifications
- Provide important account and security-related communications
- Share product updates, feature announcements, and service changes
Marketing and Promotional Activities:
- Enable us to show you ads that are relevant to you
- Send promotional offers, discounts, and special deals
- Conduct marketing campaigns and measure their effectiveness
- Implement referral programs and loyalty schemes
- Cross-sell and upsell relevant products and services
6.4 Business Operations and Compliance
Legal and Regulatory Compliance:
- Carry out our obligations and enforce our rights arising from any contracts entered into between you and us
- Enforce or apply our Terms of Service and other agreements, including for billing and collection purposes
- Comply with legal requirements and obligations
- Respond to legal processes, court orders, and government requests
- Cooperate with law enforcement and regulatory authorities
Risk Management and Security:
- Detect and prevent fraud, abuse of promotional activities, violation of our terms of service
- Monitor and prevent security breaches and unauthorized access
- Conduct background checks and identity verification
- Assess creditworthiness and financial risk
- Implement anti-money laundering and know-your-customer procedures
6.5 Advanced Analytics and Business Intelligence
Data Analytics and Research:
- Diagnose technical problems, platform issues and other such diagnostic measures as may be required to offer the Services in a stable and functional manner
- Conduct market research and consumer behavior analysis
- Develop predictive models for business optimization
- Analyze supply chain efficiency and logistics optimization
- Study user acquisition, retention, and lifetime value metrics
Machine Learning and AI:
- Train and improve machine learning algorithms
- Develop recommendation engines and personalization systems
- Implement chatbots and automated customer service systems
- Optimize pricing strategies and dynamic pricing models
- Enhance fraud detection and prevention systems
6.6 Third-Party Services Integration
We integrate with various third-party services to enhance our platform functionality and provide comprehensive services to our users. This may involve sharing certain information with trusted partners and service providers under strict confidentiality agreements.
7. Information Sharing and Disclosure
We use personal information to provide you with the services that you have opted to receive through the use of our platform and services. For facilitation of this, we may disclose personal information that we collect, or you provide, as described in this privacy policy, in the following ways:
7.1 General Information Disclosures
Corporate Family:
- To our subsidiaries and affiliates, which are entities under common ownership or control of our ultimate parent company
- Information sharing within corporate group for administrative, technical, and business purposes
- Consolidated customer support and service delivery across group companies
- Shared technology platforms and infrastructure management
- Joint marketing and promotional activities across the corporate family
Service Providers and Vendors:
To contractors, sellers, suppliers, advertisers/service providers who are typically bound by contractual obligations to keep personal information confidential and use it only for the purposes for which we disclose it to them, including:
- Payment processors and financial institutions
- Cloud computing and data storage providers
- Customer service and call center operators
- Marketing agencies and advertising networks
- Technology development and maintenance vendors
- Legal, accounting, and professional service providers
7.2 Business Transactions and Corporate Changes
Mergers and Acquisitions:
To an actual or potential buyer or other successor in the event of a merger, divestiture, restructuring, reorganization, dissolution or other sale or transfer of some or all of Graame's assets, whether as a going concern or as part of bankruptcy, liquidation or similar proceeding, in which personal information held by Graame about the users of our Services are among the assets transferred.
Due Diligence and Investment:
- Information sharing with potential investors, partners, and acquirers
- Due diligence processes for corporate transactions
- Valuation exercises and business assessments
- Integration activities following corporate changes
- Regulatory approvals and compliance reviews
7.3 Commercial Partners and Third Parties
Marketing and Promotional Partners:
To third-parties, including suppliers, to market their products or services to you if you have consented to receive the promotional updates. We contractually require these third-parties to keep personal information confidential and use it only for the purposes for which we disclose it to them.
Business Partner Collaboration:
- Allow you to participate in interactive features offered through our Services such as promotions, contests and sweepstakes for which we may share your data with third parties that run such promotional activities on our platform
- Facilitate partnerships with merchants, suppliers, and vendors
- Enable integration with third-party loyalty programs
- Support affiliate marketing and referral programs
- Coordinate with insurance and warranty providers
7.4 Data Anonymization and Aggregation
Anonymous and Aggregate Data:
We may anonymize and/or de-identify information collected from you through the Services or via other means, including via the use of third-party web analytic tools as described below. As a result, our use and disclosure of aggregated and/or de-identified information is not restricted by this Privacy Policy, and it may be used and disclosed to others without limitation.
Commercial Use of Aggregate Data:
- Create industry reports and market analysis
- Develop benchmarks and performance metrics
- Conduct academic research and publish findings
- Share insights with business partners and stakeholders
- Support product development and innovation initiatives
7.5 Advertising and Marketing Data Usage
Targeted Advertising:
We may also use your information to contact you to market our own and third-party goods and services that may be of interest to you. We may use the information we have collected from you to enable us to display advertisements to third party advertisers'/service providers' target audiences. Even though we do not disclose your personal information for these purposes without your consent, if you click on or otherwise interact with an advertisement, the advertiser may assume that you meet its target criteria.
Third-Party Advertising Networks:
Third-parties whose products or services are accessible or advertised via the Services may also use cookies or similar technologies to collect information about your use of the Services. This enables them to:
- Report how our ad impressions, other uses of ad services, and interactions with these ad impressions
- We also allow other third parties (e.g., ad networks and ad servers such as Google Analytics, OpenX, Pubmatic, DoubleClick and others) to serve tailored ads to you on the Services
- Access their own cookies or similar technologies on your computer, mobile phone, or any other device you use to access the Services
- We neither have access to, nor does this Privacy Policy govern, the use of cookies or other tracking technologies that may be placed by such third parties
- When accessing the Services from a mobile application you may also receive tailored in-application advertisements
8. Legal and Regulatory Disclosures
8.1 Sellers and Brand Partnerships
In cases where you provide us with feedback regarding the quality of products or services received by you, we may share this feedback with the relevant brand/seller or other third party as the case may be, along with your personal data, to ensure timely grievance redressal and preventing recurrence of similar issues. We may also run contests and campaigns on the platform in collaboration with or on behalf of brands. Participation in such campaigns is voluntary, and customer details may be shared with the brand to administer such events, additionally subject to their terms and conditions and privacy policy.
8.2 Operational Service Providers
Delivery and Logistics Partners:
- Real-time location sharing for delivery coordination
- Contact information for delivery communication
- Order details and delivery preferences
- Delivery feedback and ratings
- Route optimization and logistics planning
Technology Service Providers:
We may share your information with third party service providers that we use for a variety of purposes, such as:
- Send you communications via emails, messages or tele-call to inform you about our products and Services that may be of interest to you
- Push notifications to your mobile device on our behalf
- Provide voice recognition services to process your spoken queries and questions
- Help us analyze use of our Services
- Process and collect payments
- Some of our products, Services and databases are hosted by third party hosting services providers
- We may also use third party service providers for other projects, such as conducting surveys, organizing sweepstakes or providing services and business/commercial solutions for us whether permanently or on an ad hoc basis
- We may share information about you with these service providers to enable them to perform their services
8.3 Government and Legal Authority Disclosures
Legal Compliance:
We may share your information when we believe in good faith that such sharing is reasonably necessary in order to:
- Investigate, prevent, or take action regarding possible illegal activities or to comply with legal processes
- This may involve the sharing of your information with law enforcement, government agencies, courts, and/or other organizations on account of legal requests such as notices, summons, court order or government demand to comply with applicable laws
- Respond to subpoenas, court orders, or legal processes
- Comply with regulatory requirements and government investigations
- Assist in law enforcement activities and criminal investigations
Safety and Security:
We may also share your information to:
- Investigate and address threats or potential threats to the safety of any person
- Investigate and address violations of this Privacy Policy or the Terms of Service
- Investigate and address violations of the rights of third parties and/or to protect the rights, property and safety of Graame, our employees, other users, or the public
- We may also share information with internal and external audit teams and various stakeholders across our ecosystem, including affiliated entities, payment gateways, banks and other financial entities for fraud detection, prevention, mitigation, auditing and assurance purposes
Emergency Situations:
In exceptional circumstances, if we believe disclosure is necessary or appropriate to protect the rights, property, or safety of Graame, our customers or others we may share limited data to the extent necessary to ensure safety of the platform. This includes exchanging information with other companies and organizations for the purposes of fraud protection and credit risk reduction.
8.4 User Consent and Special Circumstances
Explicit Consent:
We may additionally share your information with third parties in any other circumstances where we have your consent to do so.
Public Information:
Information that you make publicly available through your use of the Services (such as reviews, ratings, or profile information) may be accessed and used by others.
Research and Analytics:
- Anonymized and aggregated data sharing with research institutions
- Market research and consumer behavior studies
- Academic research and publications
- Industry benchmarking and analysis
- Public policy research and development
9. Your Information and User Rights
9.1 Communication Preferences and Controls
Correspondence Management:
When you sign up for an account, you are opting to receive correspondence from other Graame users and Graame. You can manage your email and notification preferences and follow the 'unsubscribe' instructions for commercial email messages. Note that you cannot opt out of receiving certain administrative policy, service policy, or legal policy related correspondences from Graame.
Notification Controls:
- Email marketing preferences and frequency settings
- Push notification categories and timing controls
- SMS and text message preferences
- Phone call preferences for promotional content
- WhatsApp message preferences and opt-outs
- Social media communication preferences
9.2 Data Access and Portability
Account Information Access:
You can access and update most of your account information through your user profile settings. This includes:
- Personal information such as name, email, and phone number
- Delivery addresses and contact preferences
- Payment method information (limited for security)
- Communication preferences and settings
- Privacy controls and data sharing preferences
Data Portability:
Upon request and subject to verification of identity, we can provide you with a copy of your personal information in a commonly used electronic format. This may include:
- Account profile information
- Order history and transaction records
- Communication history and preferences
- Device and usage information (where technically feasible)
- User-generated content such as reviews and ratings
9.3 Data Correction and Updates
Information Accuracy:
You are responsible for keeping your account information current and accurate. You can update most information directly through your account settings, or by contacting our customer support team.
Data Correction Requests:
If you identify inaccuracies in your personal information, you may:
- Update information directly through account settings
- Contact customer support for assistance with complex corrections
- Provide supporting documentation for significant changes
- Request verification of corrected information
9.4 Account Deletion and Data Retention
Account Deletion:
You can permanently delete your account directly within the app. Open the Orders & Account menu, tap Profile, then scroll to the bottom and tap Delete your Graame account. Check the confirmation checkbox, tap Continue, and confirm the deletion dialog. Once deletion is complete, we will not be able to restore your account or any of its associated data.
What Gets Deleted:
When you delete your account, Graame will delete the data and content associated with your account in accordance with applicable law, including communication records, files, images, unused coupons, and credits. Once deleted, your account cannot be restored and you will no longer be able to make purchases on the Graame app or Graame.com.
Before You Delete:
- Ensure there are no incomplete or post-sale orders or ongoing processes in your account
- Use any available coupons and credits, as they will not be available after deletion
- Save any information from your account that you need for your records
Data Retained After Deletion:
Some information may be retained as required by applicable law and for legitimate business purposes, including financial compliance, fraud prevention, and dispute resolution.
9.5 Privacy Rights Limitations
Rights Restrictions:
Your rights regarding your personal information may be limited, subject to the law of your jurisdiction, particularly:
- If your requests are abusive or unreasonably excessive
- Where the rights or safety of another person or persons would be encroached upon
- If the information or material you request relates to existing or anticipated legal proceedings between you and us, or providing access to you would prejudice negotiations between us or an investigation of possible unlawful activity
- Your right to review, update, correct, and delete your information is subject to our records retention policies and applicable law, including any statutory retention requirements
Processing Restrictions:
You may request restriction of processing of your personal information in certain circumstances, including:
- When you contest the accuracy of the information
- When processing is unlawful but you prefer restriction over deletion
- When we no longer need the information but you require it for legal claims
- When you have objected to processing pending verification of grounds
9.6 Consent Withdrawal and Objections
Consent Management:
For processing based on consent, you have the right to withdraw your consent at any time. This includes:
- Marketing communications and promotional content
- Location tracking and geolocation services
- Social media integration and sharing
- Third-party data sharing for marketing purposes
- Analytics and personalization features
Objection Rights:
You may object to processing of your personal information in certain circumstances, including:
- Processing for direct marketing purposes
- Processing based on legitimate interests
- Automated decision-making and profiling
- Cross-border data transfers
- Sharing with specific categories of third parties
10. Security: How We Protect Your Information
10.1 Technical Safeguards
Data Protection Measures:
We have implemented appropriate physical, electronic, and managerial procedures to safeguard and help prevent unauthorized access to your information and to maintain data security. These safeguards take into account the sensitivity of the information that we collect, process and store and the current state of technology.
Industry Standards:
We follow generally accepted industry standards to protect the personal information submitted to us, both during transmission and once we receive it. The third party service providers providing payment gateway and payment processing services are all validated as compliant with the payment card industry standard (generally referred to as PCI compliant service providers).
Encryption and Security:
- SSL/TLS encryption for data transmission
- AES encryption for data storage
- Tokenization of sensitive payment information
- Secure API endpoints with authentication
- Regular security audits and penetration testing
- Multi-factor authentication for administrative access
10.2 Organizational Security Measures
Access Controls:
- Role-based access controls limiting data access to authorized personnel only
- Regular access reviews and permission audits
- Employee background checks and security training
- Confidentiality agreements and security policies
- Incident response procedures and breach notification protocols
Physical Security:
- Secure data centers with restricted access
- Surveillance systems and security monitoring
- Environmental controls for server protection
- Backup and disaster recovery procedures
- Secure disposal of hardware and storage media
10.3 User Responsibility and Account Security
Shared Responsibility:
We assume no liability or responsibility for disclosure of your information due to errors in transmission, unauthorized third-party access, or other causes beyond our control. You play an important role in keeping your personal information secure.
Account Protection:
You should not share your user name, password, or other security information for your Graame account with anyone. If we receive instructions using your username and password, we will consider that you have authorized the instructions and will not be liable for any breach or subsequent loss arising out of such perceived authorisation.
11. International Data Transfers and Cross-Border Processing
11.1 Global Operations
Data Transfer Necessity:
Due to the global nature of our business operations, your personal information may be transferred to, stored in, and processed in countries other than your country of residence. These countries may have different data protection laws than your country of residence.
Transfer Destinations:
Your information may be transferred to and processed in:
- Countries where our service providers operate
- Jurisdictions where our group companies are located
- Locations of our cloud computing and data storage providers
- Countries where our business partners and vendors operate
- Jurisdictions required for legal compliance or business operations
11.2 Transfer Safeguards and Protections
Adequacy Decisions:
Where possible, we transfer data to countries that have been recognized by Indian authorities as providing adequate protection for personal data.
Contractual Protections:
For transfers to countries without adequacy decisions, we implement appropriate safeguards including:
- Standard Contractual Clauses approved by relevant authorities
- Binding Corporate Rules within our corporate group
- Certification schemes and codes of conduct
- Explicit consent where legally required
- Other legally recognized transfer mechanisms
Due Diligence:
We conduct due diligence on international service providers to ensure:
- Adequate data protection measures
- Compliance with local data protection laws
- Contractual commitments to data security
- Regular audits and compliance monitoring
- Incident response and breach notification procedures
11.3 Data Localization and Compliance
Local Data Storage:
In accordance with Indian data protection regulations, certain categories of personal data may be required to be stored and processed within India. We maintain appropriate systems and procedures to ensure compliance with these requirements.
Cross-Border Compliance:
- Regular review of international transfer practices
- Monitoring of changes in data protection laws
- Updates to transfer mechanisms as required
- Training for staff on international data transfer requirements
- Documentation of transfer decisions and safeguards
12. Third-Party Services and External Links
12.1 Third-Party Service Integration
External Service Providers:
The Services may contain links to third-party websites or integrate with third-party services. Your use of these features may result in the collection, processing or sharing of information about you, depending on the feature. Please be aware that we are not responsible for the content or privacy practices of other websites or services which may be linked to our services.
Integrated Services:
We may integrate with various third-party services including:
- Social media platforms for login and sharing
- Payment processors and digital wallets
- Mapping and location services
- Communication and messaging platforms
- Analytics and advertising networks
- Customer service and support tools
12.2 Third-Party Privacy Practices
Independent Privacy Policies:
We do not endorse or make any representations about third-party websites or services. Our Privacy Policy does not cover the information you choose to provide to or that is collected by these third parties. We strongly encourage you to read such third parties' privacy policies prior to sharing any personal information with such third parties.
Limited Control:
- We cannot control third-party data collection practices
- Third-party services may have different privacy standards
- Data sharing with third parties may be governed by their terms
- Third-party security measures may differ from ours
- We are not responsible for third-party data breaches
12.3 Social Media and Public Platforms
Social Media Integration:
When you connect your account with social media platforms:
- We may receive information from your social media profiles
- Your activities on our platform may be shared with social media platforms
- Social media privacy settings may affect information sharing
- You can control social media integration through account settings
Public Information:
Information you choose to make public through our Services may be:
- Visible to other users of the platform
- Indexed by search engines
- Shared through social media platforms
- Used by third parties for various purposes
13. Cookies, Tracking Technologies, and Digital Marketing
13.1 Comprehensive Cookie Usage
Types of Cookies We Use:
- Essential Cookies: Necessary for platform functionality and security
- Performance Cookies: Help us understand how users interact with our platform
- Functionality Cookies: Remember your preferences and settings
- Targeting Cookies: Used to deliver relevant advertising and content
- Analytics Cookies: Provide insights into user behavior and platform performance
Cookie Management:
You can control cookies through:
- Browser settings and preferences
- Cookie preference centers on our platform
- Third-party opt-out mechanisms
- Mobile device settings for app-based tracking
- Industry opt-out tools and platforms
13.2 Advanced Tracking and Analytics
Tracking Technologies:
In addition to cookies, we may use:
- Pixel tags and web beacons for email tracking
- Device fingerprinting for fraud prevention
- Session recording tools for user experience optimization
- Heat mapping tools to understand user behavior
- Cross-device tracking for personalized experiences
Analytics Platforms:
We use various analytics platforms including:
- Google Analytics for website and app analytics
- Facebook Analytics for social media performance
- Custom analytics tools for business intelligence
- Third-party attribution platforms for marketing measurement
- Customer data platforms for unified customer views
13.3 Digital Advertising and Marketing Technology
Advertising Networks:
We participate in various advertising networks and platforms:
- Google Ads and Google Display Network
- Facebook and Instagram advertising platforms
- Programmatic advertising exchanges
- Native advertising networks
- Retargeting and remarketing platforms
Marketing Automation:
- Email marketing platforms for communication
- Marketing automation tools for campaign management
- Customer relationship management (CRM) systems
- Lead scoring and nurturing platforms
- Personalization engines for content delivery
14. Children's Privacy and Family Accounts
14.1 Age Verification and Restrictions
Minimum Age Requirements:
Our services are not intended for individuals under the age of 18 years. We do not knowingly collect, use, or disclose personal information from children under 18 without parental consent.
Parental Supervision:
If you are under 18, you may only use our services:
- Under the supervision of a parent or legal guardian
- With explicit parental consent for account creation
- With parental approval for transactions and purchases
- Subject to parental control over privacy settings
14.2 Parental Controls and Family Safety
Family Account Management:
- Parents can create and manage accounts for minors
- Spending limits and purchase approval requirements
- Activity monitoring and usage controls
- Communication restrictions and privacy settings
- Educational resources for digital safety
Child Safety Measures:
- Age-appropriate content filtering
- Restricted communication features
- Enhanced privacy protections for minors
- Limited data collection from users under 18
- Parental notification requirements for policy changes
14.3 Educational and Safety Resources
Digital Literacy:
We provide resources for:
- Safe internet usage practices
- Privacy awareness and education
- Digital footprint management
- Cyberbullying prevention and response
- Financial literacy for online purchases
15. Contact Information and Grievance Redressal
Data Protection Officer
Name: Dinesh
Email: [email protected]
Address: Megraa Pvt Ltd, Subhash Nagar, Uttarakhand 263152
Phone: [Phone Number]
Grievance Officer
Name: Dinesh
Designation: Grievance Officer
Email: [email protected]
Address: Megraa Pvt Ltd, Subhash Nagar, Uttarakhand 263152
Office Hours: Monday to Friday, 9:00 AM to 5:00 PM IST
Response Time: 24 hours for acknowledgment, 30 days for resolution
General Privacy Inquiries
Privacy Team Email: [email protected]
Customer Support: [Customer Support Number]
Business Hours: Monday to Friday, 9:00 AM to 5:00 PM IST
Response Time: 2-3 business days for general inquiries
16. Data Retention and Deletion Policies
16.1 Retention Principles and Periods
General Retention Framework:
We retain personal information only for as long as necessary to fulfill the purposes for which it was collected, comply with legal obligations, resolve disputes, and enforce our agreements.
Category-Specific Retention:
- Account Information: Throughout account lifecycle plus 3 years
- Transaction Records: 7 years from transaction date for financial compliance
- Communication Records: 3 years for customer service quality assurance
- Marketing Data: Until opt-out plus 1 year for compliance verification
- Legal Compliance Data: As required by applicable laws (may be indefinite)
- Security Logs: 10 years for fraud prevention and investigation
16.2 Automated Deletion and Data Lifecycle
Automated Processes:
- Scheduled deletion of expired promotional data
- Automatic removal of temporary files and caches
- Regular cleanup of test and development data
- Automated archive of historical transaction records
- Periodic review and deletion of redundant backups
Data Lifecycle Management:
- Classification of data by sensitivity and retention requirements
- Migration of aging data to archival systems
- Regular review of retention policies and periods
- Compliance monitoring and audit trails
- Secure disposal of data upon expiration
16.3 Legal Holds and Exceptions
Legal Preservation Requirements:
Data retention periods may be extended when:
- Legal proceedings are pending or anticipated
- Regulatory investigations are ongoing
- Contractual obligations require extended retention
- Business critical analysis requires historical data
- Consent has been provided for extended retention
17. Grievance Redressal and Complaint Handling
17.1 Multi-Tier Grievance Mechanism
Level 1 - Customer Support:
For routine privacy concerns and data requests:
- Email: [email protected]
- Phone: [Customer Support Phone Number]
- In-App: Customer support chat feature
- Response Time: 24-48 hours for acknowledgment, 5-7 days for resolution
Level 2 - Data Protection Officer:
For complex privacy issues and data protection matters:
- Name: Dinesh
- Email: [email protected]
- Address: Megraa Pvt Ltd
- Response Time: 48 hours for acknowledgment, 15 days for resolution
Level 3 - Grievance Officer:
For escalated complaints and unresolved issues:
- Name: Dinesh
- Designation: Grievance Officer
- Email: [email protected]
- Address: Megraa Pvt Ltd
- Office Hours: Monday to Friday, 9:00 AM to 5:00 PM
- Response Time: 72 hours for acknowledgment, 30 days for resolution
17.2 Complaint Resolution Process
Step 1 - Complaint Submission:
- Detailed description of the privacy concern or data issue
- Relevant account information and transaction details
- Supporting documentation or evidence
- Preferred method of communication for updates
- Clear statement of desired resolution
Step 2 - Acknowledgment and Investigation:
- Automatic acknowledgment of complaint receipt
- Assignment of unique complaint reference number
- Initial assessment and categorization of complaint
- Investigation by appropriate department or officer
- Regular status updates to complainant
Step 3 - Resolution and Follow-up:
- Detailed response with findings and actions taken
- Implementation of corrective measures if required
- Compensation or remedial action where appropriate
- Follow-up to ensure satisfaction with resolution
- Documentation for future reference and improvement
17.3 External Escalation Options
Regulatory Authorities:
If unsatisfied with our internal resolution, you may approach:
- Data Protection Board of India: [Contact Details when established]
- Cyber Crime Investigation Cells: For data security breaches
- Consumer Forums: Under the Consumer Protection Act
- Telecom Regulatory Authority: For communication-related issues
- Reserve Bank of India: For payment-related data concerns
Legal Remedies:
- Civil remedies under the Information Technology Act, 2000
- Consumer protection complaints under Consumer Protection Act, 2019
- Criminal complaints for serious data breaches or misuse
- Compensation claims for damages resulting from privacy violations
18. Cross-Border Data Transfers and Global Compliance
18.1 International Data Processing Framework
Global Service Delivery:
Due to our international business operations and service provider network, your personal information may be transferred, stored, and processed in countries outside India, including:
- United States: Cloud computing services and technology platforms
- European Union: Data analytics and marketing services
- Singapore: Regional business operations and customer support
- United Kingdom: Financial services and payment processing
- Other Jurisdictions: As required for business operations and partnerships
Legal Basis for Transfers:
We ensure adequate protection for international data transfers through:
- Standard Contractual Clauses approved by relevant authorities
- Adequacy decisions where available
- Binding Corporate Rules within our corporate group
- Explicit consent for specific transfer purposes
- Derogations for specific situations under applicable law
18.2 Data Localization Compliance
Indian Data Residency Requirements:
In compliance with Indian data protection regulations:
- Critical personal data is stored within Indian territory
- Sensitive personal data processing follows localization requirements
- Financial and payment data maintains appropriate residency
- Regular audits ensure compliance with localization mandates
- Contingency plans for data repatriation when required
Cross-Border Oversight:
- Regular monitoring of international data flows
- Compliance assessments for overseas service providers
- Documentation of transfer decisions and safeguards
- Training for staff on cross-border data requirements
- Incident response procedures for international breaches
19. Emerging Technologies and Future Developments
19.1 Artificial Intelligence and Machine Learning
AI-Powered Services:
We may use artificial intelligence and machine learning technologies for:
- Personalized product recommendations and search results
- Fraud detection and risk assessment algorithms
- Chatbots and automated customer service systems
- Dynamic pricing optimization and demand forecasting
- Image recognition for product categorization and quality control
Algorithmic Transparency:
- Clear disclosure of automated decision-making processes
- Information about logic involved in algorithmic decisions
- Rights to human review of automated decisions
- Regular auditing of AI systems for bias and fairness
- Mechanisms to contest or appeal automated decisions
19.2 Emerging Data Types and Sources
Internet of Things (IoT):
As we expand into IoT-enabled services:
- Smart device integration and data collection
- Sensor data from delivery vehicles and warehouses
- Environmental data for product storage and delivery
- Wearable device integration for enhanced user experience
- Home automation system compatibility
Biometric and Behavioral Data:
Potential future collection may include:
- Voice recognition for customer authentication
- Facial recognition for secure access (with explicit consent)
- Behavioral biometrics for fraud prevention
- Gait analysis for delivery verification
- Keystroke dynamics for enhanced security
19.3 Privacy-Enhancing Technologies
Advanced Privacy Protection:
We are exploring implementation of:
- Differential privacy for analytics and research
- Homomorphic encryption for secure data processing
- Federated learning for collaborative AI without data sharing
- Zero-knowledge proofs for identity verification
- Secure multi-party computation for business intelligence
Blockchain and Distributed Ledger:
Potential applications include:
- Immutable audit trails for data processing activities
- Decentralized identity management systems
- Smart contracts for automated privacy compliance
- Transparent consent management platforms
- Supply chain transparency and traceability
20. Sector-Specific Privacy Considerations
20.1 Financial Services Integration
Payment and Financial Data:
Given our integration with financial services:
- Enhanced KYC (Know Your Customer) requirements
- AML (Anti-Money Laundering) compliance procedures
- Credit assessment and scoring mechanisms
- Financial fraud detection and prevention
- Regulatory reporting to financial authorities
Banking and Payment Partnerships:
- Data sharing agreements with banking partners
- PCI DSS compliance for payment card data
- Open banking API integration and data sharing
- Digital wallet and UPI transaction processing
- Cryptocurrency and digital asset considerations (if applicable)
20.2 Healthcare and Wellness Products
Health-Related Information:
For health and wellness product categories:
- Collection of health-related purchase patterns
- Integration with fitness and wellness apps
- Prescription and medication delivery services
- Health consultation and telemedicine features
- Dietary preference and allergy information
Healthcare Privacy Compliance:
- Enhanced consent mechanisms for health data
- Restricted sharing of health-related information
- Compliance with healthcare privacy regulations
- Specialized retention periods for health data
- Additional security measures for sensitive health information
20.3 Food Safety and Dietary Information
Food and Nutrition Data:
- Dietary preferences, restrictions, and allergies
- Food safety and quality feedback
- Nutritional information and calorie tracking
- Integration with health and fitness applications
- Religious and cultural dietary requirements
Food Safety Compliance:
- Traceability of food products and suppliers
- Allergen information management and alerts
- Food safety incident reporting and management
- Integration with food safety regulatory systems
- Cold chain and temperature monitoring data
21. Privacy Policy Updates and Version Control
21.1 Policy Amendment Framework
Amendment Authority:
We reserve the right to amend this Privacy Policy from time to time to reflect changes in:
- Applicable laws and regulatory requirements
- Our data collection and processing practices
- The features and functionality of our Services
- Technological advances and industry best practices
- Corporate structure and business operations
Version Control:
- Each version of the Privacy Policy is dated and archived
- Material changes are highlighted and explained
- Previous versions remain accessible for reference
- Change logs document specific modifications
- Legal basis for changes is documented
21.2 Notification and Communication
Update Notifications:
We will notify you of material changes through:
- Prominent notice on our website and mobile application
- Email notification to your registered email address
- Push notifications through our mobile application
- SMS alerts for significant privacy-related changes
- In-app announcements and pop-up notifications
Grace Period and Transition:
- Reasonable notice period before changes take effect
- Opportunity to review changes and ask questions
- Option to withdraw consent if changes are unacceptable
- Transition period for users to adjust settings and preferences
- Continued operation under previous terms during notice period
21.3 Consent and Acceptance
Continued Use Consent:
Your continued use of our Services after we post changes constitutes your acceptance of those changes. If you do not agree to the amended Privacy Policy, you may:
- Discontinue use of our Services
- Delete your account and personal information
- Contact us to discuss specific concerns
- Exercise your rights under applicable data protection laws
Active Consent Requirements:
For certain material changes, we may require active consent through:
- Explicit agreement before continued service access
- Updated consent forms and checkboxes
- Re-confirmation of privacy preferences
- New account verification processes
- Enhanced authentication for sensitive changes
22. Contact Information and Data Protection Contacts
22.1 General Privacy Inquiries
Privacy Team
For general questions about this Privacy Policy or our privacy practices:
Email: [email protected]
Phone: [Privacy Team Phone Number]
Mailing Address:
Megraa Pvt Ltd
Attention: Privacy Team
Business Hours: Monday to Friday, 9:00 AM to 5:00 PM IST
Response Time: 2-3 business days for general inquiries
22.2 Data Protection Officer
DPO Contact Information
Name: Dinesh
Designation: Data Protection Officer
Email: [email protected]
Phone: [DPO Direct Phone Number]
Office Address:
Megraa Pvt Ltd
Responsibilities:
- Oversight of data protection compliance
- Data subject rights management
- Privacy impact assessment coordination
- Regulatory liaison and communication
- Internal privacy training and awareness
22.3 Grievance and Escalation Contacts
Grievance Officer
As required by Indian law:
Name: Dinesh
Designation: Grievance Officer
Email: [email protected]
Phone: [Grievance Officer Phone]
Office Address:
Megraa Pvt Ltd
Office Hours: Monday to Friday, 9:00 AM to 5:00 PM IST
Response Timeline:
- Acknowledgment: Within 24 hours
- Resolution: Within 30 days of complaint receipt
23. Effective Date and Jurisdiction
23.1 Policy Effective Date
This Privacy Policy is effective as of September 2025 and applies to all personal information collected by Megraa Pvt Ltd through its Services on or after this date.
23.2 Governing Law and Jurisdiction
Applicable Law:
This Privacy Policy and all privacy-related matters are governed by:
- The laws of India
- Information Technology Act, 2000 and rules thereunder
- Digital Personal Data Protection Act, 2023
- Consumer Protection Act, 2019 and e-commerce rules
- Other applicable privacy and data protection legislation
Jurisdiction:
Any disputes arising from or related to this Privacy Policy shall be subject to the exclusive jurisdiction of the courts in Rudrapur, Uttarakhand, India.
23.3 Language and Translation
Primary Language:
This Privacy Policy is originally written in English. In case of any conflict between the English version and any translated version, the English version shall prevail.
Translation Accuracy:
While we may provide translations of this Privacy Policy in local languages for convenience, users are encouraged to refer to the English version for complete accuracy and legal clarity.
Acknowledgment and Acceptance
By using our Services, you acknowledge that you have read and understood this Privacy Policy and consent to our collection, use, disclosure, and processing of your personal information as described herein.
For any questions or concerns about this Privacy Policy, please contact us using the information provided above.
Policy Version: 2.0
Last Updated: September 2025
Next Review Date: September 2026
Governing Law: Laws of India
Jurisdiction: Courts of Rudrapur, Uttarakhand
Document Classification: Public
This Privacy Policy is designed to comply with applicable Indian privacy laws and international best practices. Regular updates ensure continued compliance with evolving legal requirements and business practices.