Skip to content
Grailforus

Legal

Privacy policy

What personal data we collect, why, who sees it, how long we keep it and how to exercise your rights under the Digital Personal Data Protection Act, 2023.

Draft for legal review — not yet in force. Highlighted items are placeholders.

Last updated 30 September 2026 · Effective [effective date] · Version 2026-09-draft-1

1. Who we are

Grailforus is operated by [Company legal name] Private Limited (CIN [CIN], GSTIN [GSTIN]), registered office [Registered office address, City, State, PIN]. In these documents, “Grailforus”, “we” and “us” mean that company.

We are the data fiduciary for the personal data described here, under the Digital Personal Data Protection Act, 2023 (“DPDP Act”). This policy explains what we collect, why, who we share it with, how long we keep it and the rights you have. It applies to grailforus.com and the emails and messages we send.

2. What we collect and why

We collect only what we need to run a safe marketplace:

DataWhatWhy
AccountName, email, mobile number (Indian or US), password (stored only as a one-way hash), two-factor settings, public display name, city and state.To run your account, verify it's you, and show buyers a seller's public name and city.
Seller verification (KYC)Legal name, entity type, PAN, GSTIN (for businesses), registered address, bank account number and IFSC.To verify sellers, pay them, and withhold and report taxes. PAN is stored encrypted; we keep only the last 4 digits of the bank account — the full number goes to our payment partner.
AddressesDelivery name, phone number and address.To deliver watches. Sellers see only the buyer's city and state.
ListingsWatch details, condition, price, and photos (location and camera data are removed from every photo on upload).To publish and review listings.
Offers and messagesOffers you make or receive and messages with other users.To run negotiations. Messages are checked automatically for phone numbers, emails and payment details to prevent off-platform fraud, and may be read by our team when investigating a problem.
Purchases and salesWhat you bought or sold, amounts, fees, taxes, payment method type, payment and refund references, custody and delivery records, hub photos, and the IP address and browser used at checkout.To process the sale, provide receipts, resolve disputes and chargebacks, meet accounting and tax law, and prevent fraud. We never receive or store card numbers.
TechnicalIP address, browser and device type, pages requested, and error reports.To keep the site secure (for example rate limits and sign-in protection), fix problems and measure performance.

We collect this from you, from your use of the site, from our payment partner (payment and verification results) and our shipping partner (delivery status and proof of delivery).

3. Consent and legal grounds

We process personal data with your consent, which you give when you create an account, verify your mobile, list a watch or buy one — and for the legitimate uses the DPDP Act allows, including complying with the law (for example income-tax, GST and accounting records) and responding to legal requests.

You can withdraw consent at any time (section 8). This doesn’t affect processing already done, and we may need to close your account or cancel open listings if the data is needed to provide the service. We keep what the law requires us to keep.

4. Who we share it with

  • Other users, minimally. Buyers see a seller’s public name (“First L.” or a dealer’s trading name), city and listings. Sellers see a buyer only as “a buyer in <city>”. Email addresses and phone numbers are never shown to other users. [Dealer business details may need to be displayed under the E-Commerce Rules — pending counsel.]
  • Service providers who process data for us under contract and only on our instructions (below).
  • Authorities — tax authorities (TDS and TCS returns), law enforcement or courts — when the law requires it or to prevent fraud or crime.
  • A buyer of our business, if Grailforus is sold or merged, under this policy.

We don’t sell personal data and don’t share it for advertising.

ProviderPurposeLocation
Razorpay Software Private LimitedPayments, refunds, holding and settling seller payouts, seller KYC checksIndia
MSG91 (Walkover Web Solutions Private Limited)Verification codes by SMS to Indian numbersIndia
Twilio Inc.Verification codes by SMS to US numbersUnited States
ResendTransactional email (receipts, updates)United States
Amazon Web ServicesOur database (accounts, listings, orders, encrypted seller KYC) and photo storage; listing photos are delivered through its CloudFront networkIndia (Mumbai)
Cloudflare, Inc.Directing visitors to our website (DNS)Global
[Website hosting provider]Running the website[India (Mumbai)]
Sentry (Functional Software, Inc.)Error reports (no passwords, cookies or payment data)[United States / European Union]
GoogleOnly if you choose “Sign in with Google”Global
[Insured shipping partner]Collecting and delivering watchesIndia

5. Where your data is kept

Our database and photo storage — including accounts, orders, encrypted seller verification data and authentication photos — are hosted in India (Mumbai). Public listing photos are copied to delivery servers worldwide so pages load quickly. A few providers above process limited data outside India: email delivery, US text messages and error reports. The DPDP Act permits this except to countries the Government restricts; we check that list and require equivalent protection from those providers.

6. How long we keep it

  • Account and profile: while your account is open, and deleted or anonymised within [90 days] of closure — except as below.
  • Transactions, invoices, tax deductions and seller KYC: 8 years after the end of the financial year of the sale, as required by the Companies Act, 2013, the Income-tax Act and GST law.
  • Authentication photos, custody records and messages linked to a sale: for the life of the transaction and any dispute, then [3 years] to defend claims and prevent fraud.
  • Security logs: rate-limit counters for 24 hours; server and access logs for 180 days, as required by CERT-In’s cyber-security directions.
  • Unsold listing drafts you delete, and photos you replace, are deleted straight away.

7. How we protect it

  • Encryption in transit (HTTPS everywhere) and encryption of sensitive fields such as PAN at rest.
  • Authentication photos kept in private storage and shown only to the parties to that sale and our staff, through links that expire within a minute.
  • Staff access limited by role, with two-factor authentication required and every administrative action logged.
  • Card and UPI details are entered only in our payment partner’s secure checkout — we never see them.
  • If a personal data breach occurs, we will inform you and the Data Protection Board of India as the DPDP Act requires.

8. Your rights

Under the DPDP Act you can:

  • get a summary of the personal data we hold about you and the processing, and the identities of those we’ve shared it with;
  • have inaccurate or incomplete data corrected or updated (most of it you can edit in your account);
  • have your data erased when it’s no longer needed, unless the law requires us to keep it;
  • withdraw consent;
  • nominate someone to exercise your rights if you die or become incapacitated;
  • have a complaint resolved by us, and if you’re not satisfied, complain to the Data Protection Board of India.

Write to gfsjana@gmail.com from the email on your account. We’ll confirm who you are and respond within [30 days].

9. Children

Grailforus is only for people aged 18 or over. We don’t knowingly collect data from children. If you believe a child has created an account, tell us and we’ll delete it.

10. Cookies

We use only cookies that are needed for the site to work: a secure sign-in session cookie, and short-lived cookies for two-factor sign-in. We don’t use advertising or cross-site tracking cookies. Your browser may store small preferences (such as a dismissed notice) on your device only.

11. Changes and contact

We’ll post changes here with a new date and email account holders about significant ones before they take effect.

Privacy questions and requests: gfsjana@gmail.com. Complaints: our Grievance Officer, [Grievance Officer name].