How we collect, use, and protect your data.
Entity: Grocito Online Private Limited
Last Updated: May 29, 2026
Grocito Online Private Limited ("we", "us", "our") is committed to protecting the privacy of your data. This Privacy Policy outlines our practices regarding the collection, storage, processing, and protection of data when you use the Grocito CRM Platform.
This policy is designed to comply with the Digital Personal Data Protection (DPDP) Act, 2023 of India, alongside standard global data security practices, the Google API Services User Data Policy, and the YouTube API Services Developer Policies.
To clarify data ownership and legal responsibility under the DPDP Act, 2023, Grocito operates in a dual capacity:
Grocito as a Data Fiduciary: For your Account Data (business details, KYC, billing information, login credentials), Grocito acts as the Data Fiduciary because we determine the purpose and means of processing this data to provide our SaaS Platform to you.
Grocito as a Data Processor: For your Customer Data (the leads you upload into the CRM and end-consumer data generated on your E-Commerce storefronts), Grocito acts strictly as a Data Processor. You (the Tenant/Merchant) are the sole Data Fiduciary. It is your strict legal responsibility to obtain explicit, lawful consent from your leads and buyers before processing their data on our Platform.
We collect data through three primary categories:
When you register, we collect:
Business name and personal name
Email address and phone number
Billing address and payment details
Compliance documents (GSTIN/PAN for KYC verification)
This includes all information you input into the platform:
Lead details (names, phone numbers, emails, physical addresses, financial quotes, notes)
Files uploaded to the Document Manager
Communication logs (emails, call recordings, SMS)
To monitor platform performance, prevent unauthorized access, and debug errors, we collect:
System logs and usage metrics
IP addresses
Browser types and device identifiers
If you utilize our E-Commerce module, Grocito processes your buyers' data (names, shipping addresses, purchase history) solely as a Data Processor on your behalf. Additionally, Grocito utilizes strictly necessary cookies and session tokens on these storefronts to maintain shopping carts, user logins, and platform security. You are solely responsible for displaying a compliant Cookie and Privacy Notice to your buyers on your specific storefront.
We strictly use the collected data to:
Provide, operate, and maintain the Grocito CRM Platform.
Process subscription payments and wallet top-ups.
Facilitate omnichannel communications (routing messages through our telecom partners).
Provide AI-generated insights, summaries, and content drafting.
Investigate and prevent fraudulent transactions, spam, and unauthorized access.
Comply with Indian legal and regulatory obligations.
Crucial Guarantee: Grocito will NEVER sell, rent, trade, or expose your Customer Data (your leads/clients) to third-party marketers, competitors, or external data brokers.
To provide full CRM functionality, we utilize secure, enterprise-grade third-party sub-processors. By using Grocito, you consent to data routing through:
Google Cloud & Firebase (Mumbai/New Delhi, India Region): For database hosting, storage, and serverless computing.
AI Providers (Google Gemini): For processing text to generate AI insights. Note: We use Enterprise APIs. Your proprietary CRM data is NOT used by Google to train public foundation models.
Communication Gateways: Meta (WhatsApp API), Fast2SMS (DLT SMS), TeleCMI, Zoom Phone, and Google APIs.
Payment Gateways: Razorpay and Zoho Payments. We do not store raw credit card numbers or banking passwords on our servers.
When you integrate your WhatsApp Business Account (WABA) with Grocito, we access phone numbers, message templates, incoming/outgoing message content, and media solely to provide messaging functionality within your CRM. We explicitly guarantee that:
Data obtained through Meta / WhatsApp APIs is never sold, rented, or transferred to data brokers or third parties.
Meta API data is never used for advertising, marketing profiling, or targeting.
Meta API data is never used to train public or proprietary AI foundation models.
Grocito CRM integrates with Google APIs, including Google Ads API and YouTube API Services, to provide marketing analytics, conversion tracking, and social media scheduling features directly within your CRM dashboard.
Grocito utilizes YouTube API Services (including YouTube Data API v3 and YouTube Partner APIs). By connecting your YouTube channel to Grocito CRM, you acknowledge and agree that you are bound by:
Google Account Credentials & Profile (openid, email, profile): To verify your identity and link your organization's Google account securely.
Google Ads Data (adwords): Used exclusively to display advertising performance metrics (campaign spend, impressions, clicks, conversions) and sync offline/online conversion events from your CRM leads to your Google Ads account.
YouTube Data (youtube, youtube.readonly, youtube.upload): Used solely to display organic video and channel analytics, monitor engagement, and allow you to upload/publish marketing videos and YouTube Shorts directly to your authorized channel from the CRM social media calendar.
Grocito's use and transfer to any other app of information received from Google APIs will strictly adhere to the Google API Services User Data Policy, including the Limited Use requirements.
We never sell, rent, or transfer Google or YouTube user data to third parties, data brokers, or external advertising platforms.
We do not use Google or YouTube user data for serving personalized ads.
We do not use Google or YouTube user data to train, retrain, or improve machine learning or AI foundation models.
Human access to Google user data is strictly prohibited, except where explicit permission is provided for technical support, required by law, or necessary for security audits.
We employ a robust security architecture to safeguard your data:
Encryption: All data is encrypted in transit using TLS 1.2+ and encrypted at rest on Google Cloud servers using AES-256 encryption.
Multi-Tenant Isolation: Your data is logically separated from all other tenants using strict Firebase custom authentication claims and Firestore security rules.
Access Control: Grocito staff access to production environments is strictly limited to authorized engineering personnel for debugging and support, fully logged, and heavily restricted.
Merchants can revoke Grocito's access to their WhatsApp Business Account at any time via Meta Business Manager or inside the Grocito Dashboard (Settings > WhatsApp Integration > Disconnect).
Upon disconnection or account termination, all associated WhatsApp tokens, webhooks, and stored message logs will be permanently deleted from our servers within 30 days, unless retention is required by applicable law. Users may also submit a direct data deletion request by emailing support@grocito.com.
Media files (images, documents, audio) received via the WhatsApp API or uploaded for YouTube/social media scheduling are cached temporarily on our secure servers solely to display them within your CRM inbox/calendar and are purged automatically after 90 days.
Revoking Access via Google: In addition to disconnecting your account inside the Grocito Dashboard (Settings > Integrations), you can review and revoke Grocito's access at any time via Google Security Settings.
In-App Disconnection: Disconnecting your Google or YouTube account immediately erases and revokes all OAuth refresh tokens and temporary access credentials stored on our servers.
Cached Data Purge: Analytics data, video metadata, or ad statistics fetched from Google/YouTube APIs are cached only for performance purposes and are automatically refreshed or permanently deleted upon integration disconnection or account termination.
Direct Deletion Requests: Request immediate deletion of any Google-related data stored in your CRM account at any time by emailing support@grocito.com.
As a Data Principal regarding your Account Data, you possess the following statutory rights:
Right to Access & Correction: Access the personal data we hold about your organization and correct inaccuracies.
Right to Erasure: Request the deletion of your account and personal data (subject to tax/audit retention laws).
Right to Withdraw Consent: Withdraw processing consent at any time (withdrawing essential account data processing requires SaaS subscription termination).
Right to Nominate: Nominate another individual to exercise your data rights in the event of death or incapacity.
Right to Grievance Redressal: Raise concerns with our Grievance Officer regarding data processing.
Data Portability (Export): Export your Customer Data at any time using the in-app Backup/Export tool prior to account termination.
In accordance with Indian law, if you have privacy concerns, data breaches to report, or DPDP compliance queries, please contact our designated Grievance Officer:
Email: support@grocito.com
Address: Grocito Online Private Limited, J979, C/o Hanuman Sahay Gupta, Raja Colony, Dausa (303303), Rajasthan, India.
Response Time: We will respond to all legitimate privacy requests within 15–30 business days.