Reference

How grummy Handles Your Personal Data

At grummy, your personal data belongs to you, and we want you to understand exactly how we collect, use and protect it.

Data encrypted at rest and in transitNo sale of personal data to third partiesAccess requests honoured within 30 daysIndia-account data handled per applicable lawContact our privacy team any time
grummy How grummy Handles Your Personal Data
PRIVACY CONTACT PATHS

Reach Our Privacy Team Directly

If you have a question about your data, want to request a copy of what we hold, or need to correct or delete information tied to your grummy account, our privacy team…

Email Privacy Team Send your data request or privacy concern to our dedicated privacy address. Include your registered email and the nature of your request so we can locate your account records quickly.
In-App Support Chat Open the help panel from your account dashboard and select the Privacy category. Our support agents are available through the chat window and can escalate data requests to the privacy team on your behalf.
Postal Address For formal written requests, you may send a letter to our registered correspondence address. Include a copy of your account verification document so we can confirm your identity before processing.
DATA HANDLING PRACTICES

Six Ways We Protect Your Account Data

Security and transparency are not afterthoughts at grummy — they are built into how the platform processes every piece of data you share.

Encryption in Transit

All data exchanged between your device and our servers travels over TLS 1.2 or higher. This includes payment instructions sent through UPI, Paytm or PhonePe, so your transaction details cannot be intercepted in transit.

Cookie Policy

We use strictly necessary cookies to keep your session active, and optional analytics cookies to understand how pages are used. You can manage cookie preferences from the settings panel in your account at any time.

Account Security

Your password is stored as a salted hash — we never hold it in plain text. We also offer two-factor authentication via SMS to your registered mobile number, adding a second layer before any login is confirmed.

Data Retention

Active account data is retained while your account remains open. If you close your account, we retain transaction and identity records for the period required under applicable Indian financial regulations, after which they are securely deleted.

Third-Party Sharing

We share data only with processors essential to running the platform — payment gateways for UPI and Paytm settlements, identity verification services, and fraud-detection providers. We do not sell or rent your data to advertisers.

Your Right to Request Changes

You may request a copy of your data, ask us to correct inaccurate records, or submit a deletion request by contacting our privacy team. We confirm receipt within 72 hours and complete verified requests within 30 days.

Common Questions About Your Data on grummy

The questions below cover the data rights and privacy topics we hear about most from account holders in India. If your question is not here, reach out via the support chat or privacy email and we will respond within 72 hours.

We collect your name, email address, mobile number and the payment identifiers you use — such as your UPI handle or Paytm number. We also log device details and session activity to maintain account security and process transactions correctly.

Payment instructions travel over encrypted connections directly to the relevant gateway. We store only a reference token and transaction status — never your full UPI or PhonePe credentials — so your financial details remain under the control of your payment provider.

Yes. Contact our privacy team by email or in-app chat with your registered email address. We will verify your identity and send a structured data export within 30 days of your confirmed request, at no charge.

Transaction records and identity documents are retained for the period required under applicable Indian financial and anti-money-laundering regulations. Once that period expires, all retained records are deleted from our systems securely.

No. We share data only with essential processors — payment gateways, identity verifiers and fraud-detection services — who are contractually bound to handle it only for the stated purpose. Your data is never sold or shared for advertising.

Submit a deletion request through the in-app support chat or by emailing our privacy team. Include your registered email and account identifier. We acknowledge within 72 hours and complete the deletion within 30 days, subject to any legal retention obligations.

We set strictly necessary session cookies that keep you logged in, and optional analytics cookies to understand page usage. You can review and adjust your cookie preferences at any time from the privacy settings panel inside your account dashboard.