Privacy Policy
What we collect, why, the legal basis, who we share it with, where it is stored, how long we keep it and how you can exercise your rights — in India and abroad.
Last updated · ScaleDesk Technology Pvt Ltd
GramForGrow is a product of SCALEDESK TECHNOLOGY PRIVATE LIMITED. This policy explains how SCALEDESK TECHNOLOGY PRIVATE LIMITED ("GramForGrow", "we", "us", "our") collects, uses, shares and protects personal data when you visit our website, create an account or use the GramForGrow service.
We wrote it to meet India's Digital Personal Data Protection Act, 2023 and Digital Personal Data Protection Rules, 2025 ("DPDP"), the Information Technology Act, 2000 and the rules made under it, and, where they apply to you, the EU General Data Protection Regulation ("GDPR"), the UK GDPR and Data Protection Act 2018, and US state privacy laws such as the California Consumer Privacy Act as amended by the CPRA ("CCPA").
In short
We use your data only to run GramForGrow. We do not sell or rent personal data. We do not use Instagram data or your customers' conversations for advertising, and we do not use them to train AI models. You can access, correct, export or delete your data at any time by emailing us.1. Who we are
GramForGrow is owned and operated by SCALEDESK TECHNOLOGY PRIVATE LIMITED, a company incorporated in India. For account data we are the Data Fiduciary under DPDP and the controller under the GDPR and UK GDPR. You can reach us at support@gramforgrow.com.
2. Our two roles
- Account data — information about you, your team members and your business that we collect to run and bill your account, plus data about visitors to our website. Here we decide why and how data is used (Data Fiduciary / controller / "business" under the CCPA).
- Workspace data — Instagram comments, direct messages, profile details of people who interact with your account, contacts, deals, automations, knowledge-base content and files that your business brings into GramForGrow. Here we process data on your behalf and only on your documented instructions (Data Processor / processor / "service provider"). You are the Data Fiduciary or controller and are responsible for having a lawful basis, giving notice to your customers and obtaining any consent needed to message them.
If you are a customer or follower of a business that uses GramForGrow, that business controls your data. Please send requests to them first; we will help them respond.
3. What we collect
| Category | Examples | Source |
|---|---|---|
| Account and profile | Name, work email, phone, company name, role, hashed password, team invitations, login times | You and your administrators |
| Connected Instagram account | Instagram professional account ID, username, profile picture, linked Facebook Page, access tokens and granted permissions | Meta, when you connect your account |
| Workspace data | Usernames and public profile details of people who comment or message, comments, direct messages, story replies, media links, tags, notes, deals, contact details you collect, knowledge-base content | Meta's Instagram API and your team |
| Billing | Business name, GSTIN, billing address, plan, invoices, payment status and Razorpay identifiers. Card, UPI and bank details are entered on Razorpay and never reach our servers | You and Razorpay |
| Support and communications | Emails, WhatsApp chats, contact-form and newsletter submissions | You |
| Technical and usage | IP address, device and browser type, pages and features used, timestamps, error and security logs | Your browser and our servers |
We do not ask for, and ask you not to upload, sensitive data such as health, financial account, biometric, religious, caste, sexual-orientation or government-ID data, apart from the GSTIN and billing details we need for tax invoices.
4. Why we use it and our legal basis
| Purpose | India (DPDP) | EU / UK (GDPR) |
|---|---|---|
| Create and run your account, provide the features you use, process workspace data on your instructions | Consent given at sign-up; data you voluntarily provide for a specified purpose (s. 7(a)) | Performance of a contract (Art. 6(1)(b)) |
| Take payment, issue GST invoices, keep accounting records | Consent; compliance with law (s. 7) | Contract; legal obligation (Art. 6(1)(b), (c)) |
| Security, fraud and abuse prevention, debugging, service logs | Consent; reasonable security safeguards required by s. 8(5) | Legitimate interests (Art. 6(1)(f)) |
| Support and service notices | Consent | Contract; legitimate interests |
| Improve the product using aggregated or de-identified usage statistics | Consent | Legitimate interests |
| Product news and marketing emails | Consent (withdraw at any time) | Consent (Art. 6(1)(a)) or, for existing customers, legitimate interests with an opt-out |
| Respond to legal requests, enforce our terms, protect rights and safety | Legitimate uses under s. 7 (compliance with law, court orders) | Legal obligation; legitimate interests |
Where we rely on consent, you can withdraw it as easily as you gave it — by emailing us, using the unsubscribe link or disconnecting your Instagram account. Withdrawal does not affect processing already carried out, but we may no longer be able to provide the parts of the service that depend on it. Where we rely on legitimate interests, you can object (see section 11).
5. Instagram and Meta platform data
GramForGrow connects to Instagram only through Meta's official Instagram API, with permissions you grant and can revoke at any time. We use Instagram platform data only to provide the features you enable — receiving comments and messages, sending replies and DMs, showing conversations in your inbox and reporting on them.
- We do not sell, license or buy Instagram platform data, and we do not use it for advertising, for profiling people across businesses or to build data sets for third parties.
- We share it only with the sub-processors in section 7 that help us provide the service, or when the law requires.
- We comply with Meta's Platform Terms and Developer Policies, including their data-use and deletion requirements.
- When you disconnect an Instagram account, we stop collecting new data from it and delete our stored access token. You can also remove GramForGrow from the apps and websites connected to your Instagram or Facebook account in their settings.
6. AI features
If your workspace turns on the AI agent or an AI step, the relevant message, conversation context and knowledge-base content are sent to our AI provider (Anthropic) to generate a reply. Under its commercial terms the provider does not use this data to train its models, and we do not use workspace data to train AI models either. AI replies are sent on your behalf under your settings; they do not make decisions with legal or similarly significant effects on anyone, and you can hand any conversation to a human at any time.
7. Who we share data with
We share personal data only with service providers (sub-processors) who process it for us under written contracts that require confidentiality, security and use only on our instructions.
| Provider | Purpose | Location |
|---|---|---|
| Meta Platforms (Instagram API) | Receiving comments and messages and sending replies through your connected account | USA / Ireland |
| Razorpay | Payments for GramForGrow plans, and payment links if you connect your own Razorpay account | India |
| Anthropic | Generating AI replies, only when AI features are enabled | USA |
| Vercel | Hosting the website and dashboard front end | Global edge network |
| Railway | Hosting the application servers and database | USA / EU |
| Resend | Transactional email such as invitations, password resets and receipts | USA |
We may also disclose data (a) when required by law, a court order or a lawful request from a government authority, including under the IT Act; (b) to protect the rights, property or safety of our users, the public or us; or (c) in a merger, acquisition or sale of assets, in which case the recipient must honour this policy and we will notify you. We will update the list above before adding a new sub-processor that handles workspace data.
We do not sell personal data and do not "share" it for cross-context behavioural advertising as those terms are defined in the CCPA, and we have not done so in the past 12 months.
8. International transfers
We are based in India and some of our providers process data in other countries, including the USA and the EU. Under DPDP, transfers outside India are permitted except to countries the Government of India restricts by notification; we will stop any transfer to such a country. For personal data from the EU, EEA, UK or Switzerland, we rely on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or the recipient's certification under the EU-US Data Privacy Framework and its UK and Swiss extensions, with additional safeguards where needed. You can ask us for a copy of the relevant safeguards.
9. How long we keep it
| Data | Retention |
|---|---|
| Account and workspace data | While your account is active. After you close your account or delete your workspace, we delete or anonymise it within 90 days, and remove it from backups within a further 30 days |
| Data from a disconnected Instagram account | Access token deleted immediately; related workspace data kept until you delete it or close your account |
| Invoices, GST and accounting records | 8 years, as required by Indian tax and company law |
| Security and access logs | At least 1 year, as required by the DPDP Rules and CERT-In directions, then deleted |
| Marketing preferences | Until you unsubscribe; we then keep only a suppression record so we do not email you again |
| Support conversations | Up to 3 years after the conversation ends |
Once the purpose is served and no law requires us to keep the data, we erase it and instruct our processors to do the same.
10. Security and breaches
We maintain reasonable security practices and procedures as required by section 43A of the IT Act and section 8(5) of the DPDP Act, including encryption in transit (TLS), encryption of stored credentials (Instagram access tokens, AI keys, payment keys), hashed passwords, webhook signature verification, tenant isolation, role-based access, access logging and regular backups. See our Security page.
No system is perfectly secure. If a personal data breach occurs, we will, as the law requires, inform affected people without undue delay, notify the Data Protection Board of India (with a detailed report within 72 hours), report cyber-security incidents to CERT-In within 6 hours, and notify the relevant EU or UK supervisory authority within 72 hours where the GDPR applies. For workspace data, we will notify you without undue delay so you can meet your own obligations.
11. Your rights
Everyone
Wherever you are, you can ask us to access, correct, update, complete, export or delete your personal data, withdraw consent and opt out of marketing. We will not discriminate against you or charge you for exercising your rights.
India (DPDP Act)
- Obtain a summary of the personal data we process, our processing activities and the other fiduciaries and processors we share it with
- Correction, completion, updating and erasure of your personal data
- Withdraw consent at any time
- Grievance redressal (section 16), with escalation to the Data Protection Board of India if you are not satisfied
- Nominate another person to exercise your rights if you die or become incapable
EU, EEA, UK and Switzerland (GDPR)
- Access, rectification and erasure
- Restriction of processing and data portability
- Object to processing based on legitimate interests or used for direct marketing
- Not to be subject to decisions based solely on automated processing that significantly affect you (we do not make such decisions)
- Lodge a complaint with your local data protection authority or, in the UK, the Information Commissioner's Office
United States (California and other states)
- Know the categories and specific pieces of personal information we collect, and their sources, purposes and recipients (described in sections 3, 4 and 7)
- Delete and correct personal information
- Opt out of sale, sharing and targeted advertising — we do none of these, and we honour Global Privacy Control signals
- Limit the use of sensitive personal information — we do not use it beyond what is needed to provide the service
- Appeal our decision on your request by replying to our response
How to make a request
Email support@gramforgrow.com with the subject "Privacy request", or ask an authorised agent to do so for you. We may need to verify your identity before acting. We respond within 30 days (DPDP and GDPR, extendable where the law allows) or 45 days (CCPA), and always within 90 days. If the request concerns a business's workspace data, we will pass it to that business and help them answer.
12. Children
GramForGrow is a business tool and is not directed at children. You must be at least 18 years old to create an account. We do not knowingly collect personal data from anyone under 18 (a child under DPDP), under 16 in the EU or under 13 in the USA, and we do not track children or target advertising at them. If you believe a child has given us personal data, contact us and we will delete it. Businesses must not use GramForGrow to target children or to process their data without verifiable parental consent.
13. Cookies and tracking
We use only the cookies and local storage needed to sign you in, keep you secure and remember your preferences. We do not use advertising cookies or sell browsing data. See our Cookie Policy.
14. Deleting your account and data
- Disconnect your Instagram account in the dashboard, or remove GramForGrow in your Instagram or Facebook app settings. We stop collecting data from it immediately.
- To delete your workspace or account and all related data, email support@gramforgrow.com from your account email with the subject "Delete my data". Owners can export contacts and deals from the dashboard first.
- We confirm your request, delete the data within the periods in section 9 and tell you when it is done, apart from records the law requires us to keep.
If you messaged or commented on a business that uses GramForGrow, ask that business to delete your data, or email us with your Instagram username and the business's name and we will forward and support the request.
15. Changes to this policy
We may update this policy as our service or the law changes. The date at the top shows the current version. For material changes we will notify account owners by email or in the dashboard at least 15 days before they take effect and, where the law requires, ask for fresh consent.
16. Contact and Grievance Officer
Questions, requests and complaints about personal data can be sent to our Grievance Officer. This person answers questions about personal data on our behalf under the DPDP Rules and is also our Grievance Officer under the IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021.
- Company: SCALEDESK TECHNOLOGY PRIVATE LIMITED
- Email: support@gramforgrow.com (subject "Grievance Officer")
- Hours: Monday to Friday, 10:00–18:00 IST
We acknowledge grievances within 48 hours and resolve them within 30 days, and in any case within the 90 days the DPDP Rules allow. If you are not satisfied, you may complain to the Data Protection Board of India or, if you are in the EU or UK, to your data protection authority.