Skip to content

Privacy Policy

What we collect, why, the legal basis, who we share it with, where it is stored, how long we keep it and how you can exercise your rights — in India and abroad.

Last updated · ScaleDesk Technology Pvt Ltd

GramForGrow is a product of SCALEDESK TECHNOLOGY PRIVATE LIMITED. This policy explains how SCALEDESK TECHNOLOGY PRIVATE LIMITED ("GramForGrow", "we", "us", "our") collects, uses, shares and protects personal data when you visit our website, create an account or use the GramForGrow service.

We wrote it to meet India's Digital Personal Data Protection Act, 2023 and Digital Personal Data Protection Rules, 2025 ("DPDP"), the Information Technology Act, 2000 and the rules made under it, and, where they apply to you, the EU General Data Protection Regulation ("GDPR"), the UK GDPR and Data Protection Act 2018, and US state privacy laws such as the California Consumer Privacy Act as amended by the CPRA ("CCPA").

In short

We use your data only to run GramForGrow. We do not sell or rent personal data. We do not use Instagram data or your customers' conversations for advertising, and we do not use them to train AI models. You can access, correct, export or delete your data at any time by emailing us.

1. Who we are

GramForGrow is owned and operated by SCALEDESK TECHNOLOGY PRIVATE LIMITED, a company incorporated in India. For account data we are the Data Fiduciary under DPDP and the controller under the GDPR and UK GDPR. You can reach us at support@gramforgrow.com.

2. Our two roles

  • Account data — information about you, your team members and your business that we collect to run and bill your account, plus data about visitors to our website. Here we decide why and how data is used (Data Fiduciary / controller / "business" under the CCPA).
  • Workspace data — Instagram comments, direct messages, profile details of people who interact with your account, contacts, deals, automations, knowledge-base content and files that your business brings into GramForGrow. Here we process data on your behalf and only on your documented instructions (Data Processor / processor / "service provider"). You are the Data Fiduciary or controller and are responsible for having a lawful basis, giving notice to your customers and obtaining any consent needed to message them.

If you are a customer or follower of a business that uses GramForGrow, that business controls your data. Please send requests to them first; we will help them respond.

3. What we collect

CategoryExamplesSource
Account and profileName, work email, phone, company name, role, hashed password, team invitations, login timesYou and your administrators
Connected Instagram accountInstagram professional account ID, username, profile picture, linked Facebook Page, access tokens and granted permissionsMeta, when you connect your account
Workspace dataUsernames and public profile details of people who comment or message, comments, direct messages, story replies, media links, tags, notes, deals, contact details you collect, knowledge-base contentMeta's Instagram API and your team
BillingBusiness name, GSTIN, billing address, plan, invoices, payment status and Razorpay identifiers. Card, UPI and bank details are entered on Razorpay and never reach our serversYou and Razorpay
Support and communicationsEmails, WhatsApp chats, contact-form and newsletter submissionsYou
Technical and usageIP address, device and browser type, pages and features used, timestamps, error and security logsYour browser and our servers

We do not ask for, and ask you not to upload, sensitive data such as health, financial account, biometric, religious, caste, sexual-orientation or government-ID data, apart from the GSTIN and billing details we need for tax invoices.

PurposeIndia (DPDP)EU / UK (GDPR)
Create and run your account, provide the features you use, process workspace data on your instructionsConsent given at sign-up; data you voluntarily provide for a specified purpose (s. 7(a))Performance of a contract (Art. 6(1)(b))
Take payment, issue GST invoices, keep accounting recordsConsent; compliance with law (s. 7)Contract; legal obligation (Art. 6(1)(b), (c))
Security, fraud and abuse prevention, debugging, service logsConsent; reasonable security safeguards required by s. 8(5)Legitimate interests (Art. 6(1)(f))
Support and service noticesConsentContract; legitimate interests
Improve the product using aggregated or de-identified usage statisticsConsentLegitimate interests
Product news and marketing emailsConsent (withdraw at any time)Consent (Art. 6(1)(a)) or, for existing customers, legitimate interests with an opt-out
Respond to legal requests, enforce our terms, protect rights and safetyLegitimate uses under s. 7 (compliance with law, court orders)Legal obligation; legitimate interests

Where we rely on consent, you can withdraw it as easily as you gave it — by emailing us, using the unsubscribe link or disconnecting your Instagram account. Withdrawal does not affect processing already carried out, but we may no longer be able to provide the parts of the service that depend on it. Where we rely on legitimate interests, you can object (see section 11).

5. Instagram and Meta platform data

GramForGrow connects to Instagram only through Meta's official Instagram API, with permissions you grant and can revoke at any time. We use Instagram platform data only to provide the features you enable — receiving comments and messages, sending replies and DMs, showing conversations in your inbox and reporting on them.

  • We do not sell, license or buy Instagram platform data, and we do not use it for advertising, for profiling people across businesses or to build data sets for third parties.
  • We share it only with the sub-processors in section 7 that help us provide the service, or when the law requires.
  • We comply with Meta's Platform Terms and Developer Policies, including their data-use and deletion requirements.
  • When you disconnect an Instagram account, we stop collecting new data from it and delete our stored access token. You can also remove GramForGrow from the apps and websites connected to your Instagram or Facebook account in their settings.

6. AI features

If your workspace turns on the AI agent or an AI step, the relevant message, conversation context and knowledge-base content are sent to our AI provider (Anthropic) to generate a reply. Under its commercial terms the provider does not use this data to train its models, and we do not use workspace data to train AI models either. AI replies are sent on your behalf under your settings; they do not make decisions with legal or similarly significant effects on anyone, and you can hand any conversation to a human at any time.

7. Who we share data with

We share personal data only with service providers (sub-processors) who process it for us under written contracts that require confidentiality, security and use only on our instructions.

ProviderPurposeLocation
Meta Platforms (Instagram API)Receiving comments and messages and sending replies through your connected accountUSA / Ireland
RazorpayPayments for GramForGrow plans, and payment links if you connect your own Razorpay accountIndia
AnthropicGenerating AI replies, only when AI features are enabledUSA
VercelHosting the website and dashboard front endGlobal edge network
RailwayHosting the application servers and databaseUSA / EU
ResendTransactional email such as invitations, password resets and receiptsUSA

We may also disclose data (a) when required by law, a court order or a lawful request from a government authority, including under the IT Act; (b) to protect the rights, property or safety of our users, the public or us; or (c) in a merger, acquisition or sale of assets, in which case the recipient must honour this policy and we will notify you. We will update the list above before adding a new sub-processor that handles workspace data.

We do not sell personal data and do not "share" it for cross-context behavioural advertising as those terms are defined in the CCPA, and we have not done so in the past 12 months.

8. International transfers

We are based in India and some of our providers process data in other countries, including the USA and the EU. Under DPDP, transfers outside India are permitted except to countries the Government of India restricts by notification; we will stop any transfer to such a country. For personal data from the EU, EEA, UK or Switzerland, we rely on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or the recipient's certification under the EU-US Data Privacy Framework and its UK and Swiss extensions, with additional safeguards where needed. You can ask us for a copy of the relevant safeguards.

9. How long we keep it

DataRetention
Account and workspace dataWhile your account is active. After you close your account or delete your workspace, we delete or anonymise it within 90 days, and remove it from backups within a further 30 days
Data from a disconnected Instagram accountAccess token deleted immediately; related workspace data kept until you delete it or close your account
Invoices, GST and accounting records8 years, as required by Indian tax and company law
Security and access logsAt least 1 year, as required by the DPDP Rules and CERT-In directions, then deleted
Marketing preferencesUntil you unsubscribe; we then keep only a suppression record so we do not email you again
Support conversationsUp to 3 years after the conversation ends

Once the purpose is served and no law requires us to keep the data, we erase it and instruct our processors to do the same.

10. Security and breaches

We maintain reasonable security practices and procedures as required by section 43A of the IT Act and section 8(5) of the DPDP Act, including encryption in transit (TLS), encryption of stored credentials (Instagram access tokens, AI keys, payment keys), hashed passwords, webhook signature verification, tenant isolation, role-based access, access logging and regular backups. See our Security page.

No system is perfectly secure. If a personal data breach occurs, we will, as the law requires, inform affected people without undue delay, notify the Data Protection Board of India (with a detailed report within 72 hours), report cyber-security incidents to CERT-In within 6 hours, and notify the relevant EU or UK supervisory authority within 72 hours where the GDPR applies. For workspace data, we will notify you without undue delay so you can meet your own obligations.

11. Your rights

Everyone

Wherever you are, you can ask us to access, correct, update, complete, export or delete your personal data, withdraw consent and opt out of marketing. We will not discriminate against you or charge you for exercising your rights.

India (DPDP Act)

  • Obtain a summary of the personal data we process, our processing activities and the other fiduciaries and processors we share it with
  • Correction, completion, updating and erasure of your personal data
  • Withdraw consent at any time
  • Grievance redressal (section 16), with escalation to the Data Protection Board of India if you are not satisfied
  • Nominate another person to exercise your rights if you die or become incapable

EU, EEA, UK and Switzerland (GDPR)

  • Access, rectification and erasure
  • Restriction of processing and data portability
  • Object to processing based on legitimate interests or used for direct marketing
  • Not to be subject to decisions based solely on automated processing that significantly affect you (we do not make such decisions)
  • Lodge a complaint with your local data protection authority or, in the UK, the Information Commissioner's Office

United States (California and other states)

  • Know the categories and specific pieces of personal information we collect, and their sources, purposes and recipients (described in sections 3, 4 and 7)
  • Delete and correct personal information
  • Opt out of sale, sharing and targeted advertising — we do none of these, and we honour Global Privacy Control signals
  • Limit the use of sensitive personal information — we do not use it beyond what is needed to provide the service
  • Appeal our decision on your request by replying to our response

How to make a request

Email support@gramforgrow.com with the subject "Privacy request", or ask an authorised agent to do so for you. We may need to verify your identity before acting. We respond within 30 days (DPDP and GDPR, extendable where the law allows) or 45 days (CCPA), and always within 90 days. If the request concerns a business's workspace data, we will pass it to that business and help them answer.

12. Children

GramForGrow is a business tool and is not directed at children. You must be at least 18 years old to create an account. We do not knowingly collect personal data from anyone under 18 (a child under DPDP), under 16 in the EU or under 13 in the USA, and we do not track children or target advertising at them. If you believe a child has given us personal data, contact us and we will delete it. Businesses must not use GramForGrow to target children or to process their data without verifiable parental consent.

13. Cookies and tracking

We use only the cookies and local storage needed to sign you in, keep you secure and remember your preferences. We do not use advertising cookies or sell browsing data. See our Cookie Policy.

14. Deleting your account and data

  1. Disconnect your Instagram account in the dashboard, or remove GramForGrow in your Instagram or Facebook app settings. We stop collecting data from it immediately.
  2. To delete your workspace or account and all related data, email support@gramforgrow.com from your account email with the subject "Delete my data". Owners can export contacts and deals from the dashboard first.
  3. We confirm your request, delete the data within the periods in section 9 and tell you when it is done, apart from records the law requires us to keep.

If you messaged or commented on a business that uses GramForGrow, ask that business to delete your data, or email us with your Instagram username and the business's name and we will forward and support the request.

15. Changes to this policy

We may update this policy as our service or the law changes. The date at the top shows the current version. For material changes we will notify account owners by email or in the dashboard at least 15 days before they take effect and, where the law requires, ask for fresh consent.

16. Contact and Grievance Officer

Questions, requests and complaints about personal data can be sent to our Grievance Officer. This person answers questions about personal data on our behalf under the DPDP Rules and is also our Grievance Officer under the IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021.

  • Company: SCALEDESK TECHNOLOGY PRIVATE LIMITED
  • Email: support@gramforgrow.com (subject "Grievance Officer")
  • Hours: Monday to Friday, 10:00–18:00 IST

We acknowledge grievances within 48 hours and resolve them within 30 days, and in any case within the 90 days the DPDP Rules allow. If you are not satisfied, you may complain to the Data Protection Board of India or, if you are in the EU or UK, to your data protection authority.