Legal
Last updated: July 2026
This policy explains what information Griffy Tech Services Pvt. Ltd. ("Griffy", "we") collects when you use griffy.in, and how we use, share, and protect it. It applies to homeowners, contractors, labour, service experts, material suppliers, and anyone else using the platform, and is framed around the Digital Personal Data Protection Act, 2023 (DPDP Act) and other applicable Indian law.
We collect information you give us directly β name, email, phone number, and city when you sign up; project details when you post a project or request a quote, including site location, budget, timeline, and any photos or descriptions you choose to add; and profile information (business name, service areas, portfolio, licenses, pricing) if you register as a contractor, labourer, service expert, or material supplier.
We do not collect or store any payment details. Bookings and orders are settled in cash directly between you and the professional or supplier, so no card, UPI, or bank information passes through Griffy at all.
We also collect information automatically: pages you visit, searches you run, and device/browser information, used to keep the platform working and to improve search relevance.
To operate the marketplace β matching your project or search with relevant contractors, materials, or listings; to record and manage your bookings and orders; to send you booking confirmations, order updates, and notifications about bids on projects you've posted; to verify professional profiles before they go live; and to detect fraud, spam, and abuse (including scanning bid/enquiry messages for shared contact information, which we block to keep conversations on-platform).
We do not sell your personal data to third parties.
With the other party in a transaction β e.g., a contractor you book sees your name, phone number, and project details; a homeowner who posts a project sees the name and profile of anyone who bids on it. Because Griffy is a marketplace connecting you with independent suppliers and professionals (see our Terms of Service), once that data reaches them, they are independently responsible for how they handle it in connection with the job or order β the same way a seller on Amazon or a driver on Uber independently handles the customer contact details needed to complete that transaction.
With service providers who help us run Griffy: Supabase (authentication and database hosting), AWS (file and image storage), Resend (transactional email), Firebase (Google, for account security), and Sentry (error monitoring). Each only receives the data it needs to do its job, under contractual confidentiality obligations. We do not currently use Twilio or any SMS/WhatsApp provider, and we do not send you SMS or WhatsApp messages.
With law enforcement or regulators, only if legally required.
We do not sell personal data, and we do not share more than the minimum needed for the other party to complete your transaction or booking.
You can view and edit your profile information at any time from your Profile page. You can request account deletion by contacting team@griffy.in β we'll remove your personal data except where we're legally required to retain records (e.g., completed payment transactions).
You can opt out of non-essential notifications from your account settings; transactional notifications (order status, booking confirmations) can't be turned off since they're necessary to use the service.
Under India's Digital Personal Data Protection Act, 2023, you have the right to access the personal data we hold about you, request correction of inaccurate data, request erasure (subject to legal retention requirements described in Section 6), withdraw consent for non-essential processing, and file a grievance if you believe we've mishandled your data.
To exercise any of these rights, contact our Grievance Officer at team@griffy.in. We aim to acknowledge requests within 7 days and resolve them within 30 days, as required by law.
We retain account data for as long as your account is active, and transaction records for as long as required by Indian tax and consumer-protection law. Passwords are never stored in plain text β authentication is handled by Supabase using industry-standard hashing. We hold no card or bank details at all, because we take no online payment.
Griffy is not directed at anyone under 18. We don't knowingly collect data from minors.
We'll post updates here and, for material changes, notify account holders by email. Continued use of Griffy after a change means you accept the updated policy.
Questions about this policy or your data β email team@griffy.in, or write to our Grievance Officer at the same address. You can also use our Contact page.
This is a general-purpose draft policy and not a substitute for legal advice specific to your business and jurisdiction β have it reviewed by counsel before relying on it in production.