Privacy Policy

1. INTRODUCTION AND SCOPE

1.1 About This Policy

InspireLabs Solutions Pvt. Ltd. ("Company," "GrabOn," "we," "us," or "our") operates the GrabShare affiliate marketing platform ("Platform"). This Privacy Policy explains how we collect, use, disclose, and protect your personal information when you use our Platform and services.

1.2 Legal Framework

This Privacy Policy is drafted in compliance with:

  • Information Technology Act, 2000
  • Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011
  • Consumer Protection Act, 2019
  • Prevention of Money Laundering Act, 2002
  • Upcoming Personal Data Protection Bill provisions

1.3 Consent and Agreement

By using our Platform, you consent to the collection, use, and disclosure of your personal information as described in this Privacy Policy. If you do not agree with this Privacy Policy, please do not use our Platform.

1.4 Updates to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the "Last Updated" date. Your continued use of the Platform after any modifications indicates your acceptance of the updated Privacy Policy.

2. INFORMATION WE COLLECT

2.1 Personal Information

We collect the following categories of personal information:

  • Identity Information: Full name, Date of birth, Government-issued identification numbers (Aadhaar, PAN, Passport, Driver's License), Photographs (for KYC verification), Digital signatures
  • Contact Information: Email address, Phone number (mobile and landline), Postal address, Emergency contact details
  • Financial Information: Bank account details (account number, IFSC code, account holder name), Payment instrument information, UPI IDs, Transaction history, Commission earnings and payment records, Tax-related information (TDS certificates, GST details)
  • Professional Information: Employment status and details, Business information (for business accounts), Income details, Professional qualifications and certifications

2.2 Technical Information

  • Device and Browser Information: IP address, Device type, model, and operating system, Browser type and version, Screen resolution and device settings, Unique device identifiers
  • Usage Information: Pages visited and time spent on Platform, Click-through rates and conversion data, Search queries and preferences, Feature usage patterns, Session recordings (where consent is provided)
  • Location Information: Approximate location based on IP address, Precise location (only with explicit consent), Location history for fraud prevention

2.3 Information from Third Parties

  • KYC and Verification Services: Identity verification results from authorized agencies, Credit information from credit bureaus (where applicable), Government database verifications
  • Social Media and Partners: Information from social media platforms (when you connect accounts), Data from merchant partners, Referral information from other users

2.4 Sensitive Personal Data

In accordance with Indian law, we may collect the following sensitive personal data:

  • Financial information (bank account details, payment history)
  • Government-issued identification numbers
  • Biometric information (for video KYC when applicable)
  • Any other data classified as sensitive under applicable law

3. HOW WE USE YOUR INFORMATION

3.1 Primary Purposes

  • Account Management: Creating and maintaining user accounts, Verifying identity and completing KYC processes, Authenticating users and securing accounts, Managing user preferences and settings
  • Service Provision: Processing affiliate registrations and applications, Tracking affiliate performance and calculating commissions, Facilitating payments and financial transactions, Providing customer support and technical assistance
  • Legal and Regulatory Compliance: Meeting KYC and AML requirements, Complying with tax obligations and TDS requirements, Responding to legal requests and regulatory inquiries, Preventing fraud and ensuring Platform security

3.2 Secondary Purposes

  • Business Operations: Analyzing Platform usage and performance, Conducting market research and analytics, Developing and improving our services, Planning business strategy and growth
  • Marketing and Communication: Sending service-related notifications, Providing promotional offers and updates, Conducting surveys and feedback collection, Personalizing user experience

3.3 Legal Basis for Processing

  • Your consent (explicitly provided)
  • Contractual necessity (to perform our services)
  • Legal obligations (regulatory compliance)
  • Legitimate interests (fraud prevention, service improvement)
  • Vital interests (security and safety)

4. INFORMATION SHARING AND DISCLOSURE

4.1 Merchant Partners

We share relevant information with merchant partners for:

  • Transaction processing and validation
  • Commission calculation and payment
  • Fraud prevention and dispute resolution
  • Performance reporting and analytics

Information shared may include:

  • Affiliate identification details
  • Transaction data and conversion metrics
  • Performance statistics
  • Compliance status

4.2 Service Providers

We engage third-party service providers for:

  • Payment processing and banking services
  • KYC verification and identity authentication
  • Technology infrastructure and cloud services
  • Customer support and communication services
  • Analytics and marketing tools

Safeguards:

  • All service providers are bound by strict confidentiality agreements
  • Data processing agreements ensure compliance with privacy standards
  • Regular audits and security assessments are conducted
  • Minimal data necessary for service provision is shared

4.3 Regulatory Authorities

  • Reserve Bank of India (RBI) for payment system compliance
  • Financial Intelligence Unit (FIU-IND) for AML compliance
  • Income Tax Department for TDS and tax compliance
  • Securities and Exchange Board of India (SEBI) where applicable
  • Other regulatory bodies as legally required

4.4 Legal Disclosures

Information may be disclosed for:

  • Compliance with legal obligations
  • Response to court orders, subpoenas, and legal processes
  • Protection of our rights, property, and safety
  • Prevention and investigation of fraud or illegal activities
  • Enforcement of our Terms and Conditions

4.5 Business Transfers

In the event of a merger, acquisition, or sale of assets, your information may be transferred to the acquiring entity, subject to the same privacy protections.

5. DATA SECURITY AND PROTECTION

5.1 Technical Safeguards

  • Encryption: Industry-standard encryption for data transmission (TLS/SSL), Advanced encryption for data storage (AES-256), End-to-end encryption for sensitive communications, Encrypted backup and recovery systems
  • Access Controls: Role-based access controls (RBAC), Multi-factor authentication for system access, Regular access reviews and deprovisioning, Privileged access management (PAM)
  • Infrastructure Security: Secure cloud hosting with certified providers, Network segmentation and firewalls, Intrusion detection and prevention systems, Regular security patching and updates

5.2 Operational Safeguards

  • Personnel Security: Background checks for employees with data access, Regular privacy and security training, Confidentiality agreements and code of conduct, Clear data handling procedures and protocols
  • Incident Response: 24/7 security monitoring and alerting, Comprehensive incident response plan, Regular drills and response testing, Breach notification procedures as per law

5.3 Physical Security

  • Restricted access to data centers and offices
  • Biometric authentication for sensitive areas
  • CCTV monitoring and security personnel
  • Secure disposal of physical media

5.4 Compliance and Auditing

  • Regular security assessments and penetration testing
  • Compliance audits by third-party security firms
  • ISO 27001 and other security certifications
  • Continuous monitoring and improvement processes

6. DATA RETENTION AND DELETION

6.1 Retention Periods

  • Active Account Data: Personal information retained while account is active plus 7 years, Financial records: 10 years as per regulatory requirements, Transaction data: 10 years for audit and compliance purposes, Communication records: 3 years for customer service purposes
  • Closed Account Data: Basic profile information: 1 year after account closure, KYC documents: 5 years as per AML requirements, Financial records: 10 years for tax and regulatory compliance, Dispute-related data: Until resolution plus 2 years

6.2 Deletion Process

Upon expiry of retention periods:

  • Automated deletion systems remove expired data
  • Manual review for data with legal holds
  • Secure destruction of physical documents
  • Certificate of destruction for sensitive data

6.3 User-Requested Deletion

Users may request deletion of their data, subject to:

  • Legal and regulatory retention requirements
  • Ongoing business needs (e.g., dispute resolution)
  • Technical limitations of legacy systems
  • Verification of user identity and authority

7. YOUR RIGHTS AND CHOICES

7.1 Access Rights

  • Request copies of your personal information
  • Obtain information about how your data is processed
  • Receive data in a structured, machine-readable format
  • Request details of third parties with whom data is shared

7.2 Correction and Update Rights

  • Update your profile information through the Platform
  • Request correction of inaccurate or incomplete data
  • Provide additional documentation for verification
  • Update communication preferences

7.3 Deletion and Restriction Rights

  • Request deletion of your personal information (subject to legal limitations)
  • Ask for restriction of processing for specific purposes
  • Object to processing based on legitimate interests
  • Withdraw consent for optional data processing

7.4 Portability Rights

  • Receive your data in a portable format
  • Transfer data to another service provider
  • Request direct transfer where technically feasible

7.5 Communication Preferences

  • Marketing communications (opt-out available)
  • Service notifications (limited opt-out for essential communications)
  • Promotional offers and surveys
  • Newsletter subscriptions

7.6 Cookie and Tracking Controls

  • Browser settings for cookie management
  • Opt-out links for analytics and advertising cookies
  • Do Not Track signal recognition
  • Third-party tracking protection options

8. COOKIES AND TRACKING TECHNOLOGIES

8.1 Types of Cookies

  • Essential Cookies: Authentication and session management, Security and fraud prevention, Platform functionality and performance, Load balancing and system optimization
  • Analytics Cookies: Usage statistics and performance metrics, User behavior analysis and heatmaps, A/B testing and feature optimization, Error tracking and debugging
  • Marketing Cookies: Personalized content and recommendations, Advertising effectiveness measurement, Cross-platform tracking for attribution, Social media integration

8.2 Third-Party Tracking

We use services from:

  • Google Analytics for website analytics
  • Facebook Pixel for advertising optimization
  • Payment processors for transaction tracking
  • Customer support tools for service delivery

8.3 Cookie Management

Users can control cookies through:

  • Browser settings and preferences
  • Platform cookie consent management
  • Third-party opt-out tools and services
  • Direct communication with our privacy team

9. INTERNATIONAL DATA TRANSFERS

9.1 Data Localization

In compliance with Indian regulations:

  • Payment data is stored within India
  • Critical personal data remains in Indian jurisdiction
  • Mirror copies may be maintained locally for business continuity

9.2 Cross-Border Transfers

When data is transferred internationally:

  • Adequate protection measures are implemented
  • Standard contractual clauses are used
  • Recipient countries have adequate data protection laws
  • User consent is obtained where required

9.3 Cloud Services

We use cloud services that may involve:

  • Data processing in multiple jurisdictions
  • Strict data residency controls where required
  • Contractual guarantees for data protection
  • Regular compliance monitoring and audits

10. CHILDREN'S PRIVACY

10.1 Age Restrictions

  • Our Platform is not intended for users under 18 years of age
  • We do not knowingly collect information from minors
  • Parental consent is required for users under 18
  • Age verification processes are implemented during registration

10.2 Protection Measures

  • If we discover we have collected information from a minor: We will immediately cease collection and use, The information will be securely deleted, Parents will be notified if contact information is available, Account access will be restricted until age verification

11. GRIEVANCE REDRESSAL

11.1 Grievance Officer

Name: [Insert Name] Designation: Data Protection Officer Email: [email protected] Phone: [Insert Phone Number] Address: 21st Floor, OneWest Building, Financial District, Gachibowli, Hyderabad, Telangana 500032

11.2 Complaint Process

  • Step 1 - Initial Contact: Submit complaint via email or online form, Provide detailed description of the privacy concern, Include relevant documentation and evidence, Specify desired resolution or remedy
  • Step 2 - Acknowledgment: Acknowledgment within 48 hours of receipt, Assignment of complaint reference number, Initial assessment of complaint complexity, Estimated timeline for resolution
  • Step 3 - Investigation: Thorough investigation of the complaint, Consultation with relevant teams and departments, Review of applicable policies and procedures, Collection of additional information if needed
  • Step 4 - Resolution: Proposed resolution communicated within 30 days, Implementation of corrective measures, Follow-up to ensure issue is resolved, Documentation of complaint and resolution

11.3 Escalation Process

  • If unsatisfied with our response: Contact senior management for review, Approach industry ombudsman or regulatory body, File complaint with appropriate government authority, Seek legal remedies through courts

12. REGULATORY COMPLIANCE

12.1 Information Technology Act, 2000

  • Reasonable security practices for personal data
  • Notification requirements for data breaches
  • Consent mechanisms for data collection
  • Compensation provisions for data breaches

12.2 Consumer Protection Act, 2019

  • Transparent data collection and use
  • Clear privacy notices and consent mechanisms
  • Effective grievance redressal procedures
  • Protection against unfair trade practices

12.3 Prevention of Money Laundering Act, 2002

  • Customer identification and verification records
  • Transaction records for specified periods
  • Suspicious transaction reporting mechanisms
  • Regular compliance audits and training

12.4 Upcoming Personal Data Protection Bill

  • Enhanced consent management systems
  • Data protection impact assessments
  • Appointment of data protection officers
  • Implementation of privacy by design principles

13. UPDATES AND AMENDMENTS

13.1 Policy Updates

  • Changes in applicable laws and regulations
  • Evolution of our business practices
  • Introduction of new technologies and services
  • Feedback from users and regulatory authorities

13.2 Notification Process

For material changes:

  • Email notification to registered users
  • Prominent notice on Platform homepage
  • Pop-up notifications during Platform use
  • Social media and other communication channels

13.3 User Response Options

  • Continue using Platform to accept changes
  • Update consent preferences if needed
  • Contact us with questions or concerns
  • Close account if you disagree with changes

14. CONTACT INFORMATION

14.1 General Inquiries

  • Email: [email protected]
  • Phone: [Insert Phone Number]
  • Address: Inspirelabs Solutions Pvt Ltd, 21st Floor, OneWest Building, Financial District, Gachibowli, Hyderabad, Telangana 500032

14.2 Data Protection Officer

14.3 Legal Department

15. EFFECTIVE DATE AND VALIDITY

This Privacy Policy is effective from [Insert Date] and remains valid until superseded by an updated version. Regular reviews are conducted to ensure continued compliance with applicable laws and best practices.

By using the GrabShare Platform, you acknowledge that you have read, understood, and agree to the collection, use, and disclosure of your personal information as described in this Privacy Policy.

For the most current version of this Privacy Policy, please visit our Platform regularly or contact us directly.