Privacy Policy
Last updated: 21 April 2026
This Privacy Policy explains what personal data GlobeStack ("we", "us") collects, how we use it, and what rights you have. We operate from India and comply with the Digital Personal Data Protection Act, 2023 (DPDP Act).
Quick summary: We collect only the data we need to run your account, process payments, and deliver emails. We don't sell your data. We don't run ads. You can export or delete your data from account settings anytime.
1. Who we are (Data Fiduciary)
Data Fiduciary: GlobeStack (currently operated as a sole proprietorship in India; to be reconstituted as a private limited company during 2026).
Registered jurisdiction: India
Tax ID (GSTIN): 06GUIPM8148D1ZD
Udyam: UDYAM-HR-10-0109200
Contact:
support@globestack.app
Physical registered address provided on request for legal notices or to
the Data Protection Board when required.
2. Data we collect
2.1 Account data
- Name, email address, password (hashed with argon2 — we never store it in plain text)
- Organisation name, industry, role
- Profile picture (if uploaded)
2.2 Billing data
- Subscription plan, billing cycle, invoice history
- Payment method info (held by Razorpay — we only store the last 4 digits of cards and a payment reference, never full card/UPI details)
- Billing address for GST invoicing (once you register for GST)
2.3 Usage data
- IP address, device type, browser (for session security and fraud detection)
- Approximate location (derived from IP — city and country only)
- Feature-level usage counts (for billing metered features like WhatsApp messages)
2.4 Customer Data (your business records inside the product)
Contacts, orders, invoices, inventory, WhatsApp messages, etc. — data you enter or import. We process this strictly to provide the Service and never mine it for any other purpose.
2.5 Email engagement data
Transactional email opens and link clicks (via our email provider, Resend), used only to debug delivery issues and improve email templates. No marketing profile is built from this.
3. How we use your data
- Provide the Service — run your account, process payments, deliver features
- Communicate — account notifications, receipts, security alerts, product updates
- Improve — aggregated, de-identified analytics on feature usage and performance
- Security & fraud prevention — detect unusual sign-ins, abuse, spam
- Legal compliance — respond to valid law-enforcement requests within India
We do not:
- Sell your data to third parties
- Use your Customer Data to train any AI/ML model
- Share your data for advertising
4. Lawful basis (DPDP Act Sec 7)
We process personal data based on the consent you provide at signup, and for legitimate uses permitted under the DPDP Act including performance of contract (subscription), compliance with legal obligations (tax, law enforcement), and employment-related purposes for our own team.
5. Third parties (Data Processors)
We share personal data only with vendors who help us run the Service. They process data on our instructions under contract. Categories of processors we rely on:
- Payment processor — processes your card, UPI, and net-banking transactions (India-based, PCI-DSS certified)
- Cloud infrastructure — application hosting, DNS, CDN, and file storage (servers located in Mumbai, India)
- Managed database — stores your business data (India region)
- Email delivery provider — sends transactional emails (receipts, password resets, notifications)
- Business email host — hosts our support and billing inboxes (India-based)
- Messaging provider — WhatsApp Business API integration (only active if you enable the WhatsApp module)
- Identity provider — Google Sign-In (only if you choose to use it)
A full list of named sub-processors is available on request to support@globestack.app.
6. Cross-border transfers
Some of our vendors process data outside India (USA, Ireland). We only use vendors that meet our security standards and contractually agree to process data in line with this Policy. Per DPDP Act Section 16, the Government of India may restrict transfers to certain countries — we'll comply with any such restriction if it affects us.
7. Data retention
- Account data: retained while your account is active, plus 30 days after cancellation to allow reactivation
- Customer Data: same as above; exports available in-app anytime
- Billing records: retained for 8 years per Indian tax law (Companies Act, Income Tax Act)
- Server logs: 90 days, then automatically purged
- Email delivery logs: 30 days (Resend's retention)
8. Your rights (DPDP Act, Chapter III)
You have the right to:
- Access — view all data we hold about you (via account settings or email request)
- Correct — fix inaccurate data (directly in-app or by contacting us)
- Erase — delete your account and associated data (subject to legal retention)
- Withdraw consent — stop data processing (cancel subscription; account data retained per Section 7 for legal compliance)
- Grievance redressal — see Section 10 below
- Nominate a person to exercise your rights if you are deceased or incapacitated
Requests should be sent to support@globestack.app. We aim to respond within 7 working days.
9. Security
- Passwords hashed with argon2 (never stored plaintext)
- All traffic encrypted in transit (TLS 1.2+)
- Secrets encrypted at rest via Pulumi secret management
- DKIM, SPF, DMARC configured on all outbound email
- Role-based access control within our engineering team
- Incident response plan — we'll notify affected users and the Data Protection Board within 72 hours of a confirmed breach (DPDP Act Section 8(6))
10. Grievance Officer
Under DPDP Act Section 10, you can contact our Grievance Officer for complaints about data handling:
Grievance Officer (role): GlobeStack — Grievance Officer
Email:
support@globestack.app
— clicking this link pre-fills the subject so we route your
message correctly
Response SLA: acknowledgment within 48 hours, resolution
within 30 days
The natural person currently holding the Grievance Officer role will be named in any formal correspondence on request.
If unsatisfied with our response, you may escalate to the Data Protection Board of India once it is constituted.
11. Children
GlobeStack is a B2B product and not intended for users under 18. We do not knowingly collect data from minors. If we learn we have, we'll delete it promptly.
12. Cookies & tracking
We use only essential cookies (authentication token, session preferences). We don't use third-party analytics cookies or tracking pixels in emails beyond open/click tracking at the Resend level.
13. Changes to this Policy
We'll notify you of material changes at least 30 days before they take effect, via email and an in-app banner. The "Last updated" date at the top always reflects the current version.