Privacy Policy
Effective 22 July 2026
GrabToGo ("we", "us", "our") is committed to protecting your personal data in accordance with the Digital Personal Data Protection (DPDP) Act, 2023 of India. This policy explains how we collect, use, store and protect your information.
1. Data we collect
| Data type | Details | Purpose |
|---|---|---|
| Account information | Full name, email address, phone number, profile photo | Account creation, communication |
| Location data | GPS coordinates, with your permission. Your most recent location is stored on your profile | Show nearby offers within your chosen radius; notify you of offers from shops near you |
| Shop information (vendors) | Shop name, category, address, GSTIN, FSSAI licence, business documents | Vendor verification, listing creation |
| Payment information | Transaction IDs, subscription plan, billing cycle | Payment processing, subscription management |
| Device information | Push notification token, device type, OS version | Push notifications, crash reporting |
| Usage data | App interactions, offers viewed, items saved | Service improvement, personalised experience |
| Messages | Chat messages between you and a shop, including any images sent | Enabling customer–vendor conversations |
| Reviews and ratings | Your rating, review text and any review photos | Public shop reviews |
We do not collect payment card numbers, UPI IDs or bank details. Those are entered directly into Razorpay's secure checkout and never reach our servers.
2. Why we collect it
- Providing hyperlocal offer discovery
- Processing vendor registration and verification
- Managing subscriptions and payments via Razorpay
- Sending push notifications about nearby offers and account activity
- Enabling customer–vendor chat where the shop's plan includes it
- Platform safety, moderation and fraud prevention
- Crash reporting and stability monitoring
- Compliance with legal obligations
3. Consent
By registering and using GrabToGo you consent to the collection and processing of your personal data as described here. You may withdraw consent at any time by deleting your account: Settings → Data & Privacy → Delete My Account.
Location access is optional and requested separately. You can decline or revoke it in your device settings; the app remains usable, but nearby-offer features will be limited.
4. How long we keep it
| Data type | Retention period |
|---|---|
| Account data | Until account deletion, plus 30 days for processing |
| Payment records | 7 years, as required by Indian tax law |
| Vendor documents | Until account deletion or vendor deactivation |
| Location data | Most recent location retained on your profile until you delete your account or revoke permission |
| Chat messages | Until either participant deletes their account |
| Push notification tokens | Until token refresh or account deletion |
| Crash reports | 90 days (Sentry retention policy) |
5. Your rights under the DPDP Act
- Right to access — request a copy of your personal data: Settings → Data & Privacy → Export My Data
- Right to correction — update your information in profile settings at any time
- Right to erasure — Settings → Data & Privacy → Delete My Account
- Right to data portability — export your data in machine-readable JSON
- Right to withdraw consent — by deleting your account; some data is retained where law requires
- Right to grievance redressal — contact our Data Grievance Officer below
6. Who we share it with
| Service | Data shared | Purpose | Data location |
|---|---|---|---|
| Supabase | Application data, authentication, uploaded files | Database, authentication, storage | India (AWS ap-south-1, Mumbai) |
| Razorpay | Payment details, name, email, phone | Payment processing | India |
| Google (Firebase Cloud Messaging) | Push notification token, device info | Push notification delivery | Global |
| Google Sign-In | Name, email, profile photo | Optional sign-in method | Global |
| Google Maps | Approximate location | Maps and place display | Global |
| Expo (EAS) | Device info, app version | App updates and builds | United States |
| Sentry | Crash data, device info | Error monitoring | United States |
We do not sell your personal data to anyone.
Shop owners can see the name and profile photo of customers who message or review them. Reviews you post are public.
7. Cross-border data transfer
Your core application data is stored in India (Mumbai region). Limited technical data — crash reports, device and build information — is processed in the United States by Sentry and Expo. These transfers are necessary to operate and maintain the service, and are carried out with appropriate safeguards as required by the DPDP Act.
8. Data security
- All data transmitted over HTTPS/TLS
- Row Level Security enforced at the database level, so each account can reach only its own data
- Authentication tokens stored securely on your device
- Vendor documents held in access-controlled storage
- Rate limiting on sensitive endpoints
- Regular security review of data access rules
9. Children's data
GrabToGo is not intended for users under 18. We do not knowingly collect data from minors. If you believe a minor has provided us personal data, contact our Grievance Officer immediately.
10. Changes to this policy
We may update this policy from time to time. Significant changes will be communicated by in-app notification. Continued use after changes constitutes acceptance.
11. Data Grievance Officer
GrabToGo Data Grievance Officer — info@grabtogo.in. We respond within 72 hours and aim to resolve within 30 days, as required by the DPDP Act.