GrabToGo

Privacy Policy

Effective 22 July 2026

GrabToGo ("we", "us", "our") is committed to protecting your personal data in accordance with the Digital Personal Data Protection (DPDP) Act, 2023 of India. This policy explains how we collect, use, store and protect your information.

1. Data we collect

Data typeDetailsPurpose
Account informationFull name, email address, phone number, profile photoAccount creation, communication
Location dataGPS coordinates, with your permission. Your most recent location is stored on your profileShow nearby offers within your chosen radius; notify you of offers from shops near you
Shop information (vendors)Shop name, category, address, GSTIN, FSSAI licence, business documentsVendor verification, listing creation
Payment informationTransaction IDs, subscription plan, billing cyclePayment processing, subscription management
Device informationPush notification token, device type, OS versionPush notifications, crash reporting
Usage dataApp interactions, offers viewed, items savedService improvement, personalised experience
MessagesChat messages between you and a shop, including any images sentEnabling customer–vendor conversations
Reviews and ratingsYour rating, review text and any review photosPublic shop reviews

We do not collect payment card numbers, UPI IDs or bank details. Those are entered directly into Razorpay's secure checkout and never reach our servers.

2. Why we collect it

  • Providing hyperlocal offer discovery
  • Processing vendor registration and verification
  • Managing subscriptions and payments via Razorpay
  • Sending push notifications about nearby offers and account activity
  • Enabling customer–vendor chat where the shop's plan includes it
  • Platform safety, moderation and fraud prevention
  • Crash reporting and stability monitoring
  • Compliance with legal obligations

3. Consent

By registering and using GrabToGo you consent to the collection and processing of your personal data as described here. You may withdraw consent at any time by deleting your account: Settings → Data & Privacy → Delete My Account.

Location access is optional and requested separately. You can decline or revoke it in your device settings; the app remains usable, but nearby-offer features will be limited.

4. How long we keep it

Data typeRetention period
Account dataUntil account deletion, plus 30 days for processing
Payment records7 years, as required by Indian tax law
Vendor documentsUntil account deletion or vendor deactivation
Location dataMost recent location retained on your profile until you delete your account or revoke permission
Chat messagesUntil either participant deletes their account
Push notification tokensUntil token refresh or account deletion
Crash reports90 days (Sentry retention policy)

5. Your rights under the DPDP Act

  • Right to access — request a copy of your personal data: Settings → Data & Privacy → Export My Data
  • Right to correction — update your information in profile settings at any time
  • Right to erasure — Settings → Data & Privacy → Delete My Account
  • Right to data portability — export your data in machine-readable JSON
  • Right to withdraw consent — by deleting your account; some data is retained where law requires
  • Right to grievance redressal — contact our Data Grievance Officer below

6. Who we share it with

ServiceData sharedPurposeData location
SupabaseApplication data, authentication, uploaded filesDatabase, authentication, storageIndia (AWS ap-south-1, Mumbai)
RazorpayPayment details, name, email, phonePayment processingIndia
Google (Firebase Cloud Messaging)Push notification token, device infoPush notification deliveryGlobal
Google Sign-InName, email, profile photoOptional sign-in methodGlobal
Google MapsApproximate locationMaps and place displayGlobal
Expo (EAS)Device info, app versionApp updates and buildsUnited States
SentryCrash data, device infoError monitoringUnited States

We do not sell your personal data to anyone.

Shop owners can see the name and profile photo of customers who message or review them. Reviews you post are public.

7. Cross-border data transfer

Your core application data is stored in India (Mumbai region). Limited technical data — crash reports, device and build information — is processed in the United States by Sentry and Expo. These transfers are necessary to operate and maintain the service, and are carried out with appropriate safeguards as required by the DPDP Act.

8. Data security

  • All data transmitted over HTTPS/TLS
  • Row Level Security enforced at the database level, so each account can reach only its own data
  • Authentication tokens stored securely on your device
  • Vendor documents held in access-controlled storage
  • Rate limiting on sensitive endpoints
  • Regular security review of data access rules

9. Children's data

GrabToGo is not intended for users under 18. We do not knowingly collect data from minors. If you believe a minor has provided us personal data, contact our Grievance Officer immediately.

10. Changes to this policy

We may update this policy from time to time. Significant changes will be communicated by in-app notification. Continued use after changes constitutes acceptance.

11. Data Grievance Officer

GrabToGo Data Grievance Officer — info@grabtogo.in. We respond within 72 hours and aim to resolve within 30 days, as required by the DPDP Act.