Legal

Privacy Policy

Last updated: 28 May 2026

At GrihSwami — operated by UPYOGI MEDIA AND ADVERTISEMENT (OPC) PRIVATE LIMITED — your privacy matters. This policy explains what personal information we collect when you use our website and mobile app, how we use it, and the choices you have. Please read it carefully.

By using Grihswami, you agree to the collection and use of information in accordance with this policy.

1. Information We Collect

Account Information

When you register, we collect your name, email address, and phone number. Phone numbers are verified via OTP before account activation.

Identity Verification (KYC)

If you choose to complete KYC, we collect your Aadhaar number. This is encrypted using AES-256-GCM encryption and is never stored in plain text. PAN number is optionally collected for verified agents.

Property & Listing Data

Sellers and agents provide property details including address, photos, floor plans, RERA certificates, and other documents when creating listings.

Usage Data

We collect information about how you use the platform — searches, listings viewed, favourites saved, inquiries sent — to improve recommendations and platform performance.

Device & Technical Data

We collect device type, operating system version, app version, and IP address for security and fraud prevention purposes.

Payment Information

Payments are processed by Razorpay. We do not store your card or bank details. We retain transaction IDs and invoice data for GST compliance.

2. How We Use Your Information

Platform Services

To create and manage your account, show you relevant property listings, connect buyers with sellers, and facilitate property visits and inquiries.

Notifications

To send transactional messages — OTPs, inquiry alerts, visit confirmations, and review notifications. You can manage email notification preferences in Settings.

Saved Search Alerts

If you save a search, we send daily email alerts when new matching properties are listed. You can delete saved searches at any time.

Billing & Invoicing

To process subscription payments, generate GST-compliant PDF invoices, and send payment confirmations.

Security

To detect fraudulent activity, enforce rate limits, and protect user accounts from unauthorised access.

Platform Improvement

Aggregated, anonymised usage data helps us understand feature usage and improve the platform.

3. Data Sharing

We do not sell your data

We never sell, rent, or trade your personal information to third parties for marketing purposes.

With Other Users

When you send an inquiry or schedule a visit, your name and contact information is shared with the relevant seller or agent to facilitate communication.

Payment Processor

Razorpay receives payment details necessary to process transactions. Their privacy policy applies to data they handle.

Cloud Infrastructure

Property photos and documents are stored on secure cloud storage. Data is encrypted in transit and at rest.

Legal Requirements

We may disclose information if required by law, court order, or to protect the rights and safety of our users.

4. Data Security

Encryption

All data is transmitted over HTTPS/TLS. Aadhaar numbers are encrypted with AES-256-GCM. Passwords are hashed using bcrypt and never stored in plain text.

Authentication

We use short-lived JWT tokens with secure refresh token rotation. Refresh tokens are stored as SHA-256 hashes.

Rate Limiting

Login, OTP send, and OTP verify endpoints are rate-limited to prevent brute-force attacks.

Access Controls

Access to user data is role-based. Agents are admin-verified before they can access escrow or bulk features.

5. Your Rights

Access & Correction

You can view and update your profile information at any time from the Profile section of the app or website.

Data Deletion

You may request deletion of your account and all associated personal data by emailing support@grihswami.com. Deletion is completed within 30 days. Note: transaction records may be retained for the period required by Indian tax law (typically 7 years).

Notification Preferences

You can opt out of non-essential email notifications from Settings → Notification Preferences.

Withdraw Consent

You may withdraw consent for KYC data processing at any time; this will revert your account to unverified status.

6. Data Retention

Account Data

Retained while your account is active, and for up to 30 days after deletion request is processed.

Transaction Records

Payment and invoice records are retained for 7 years as required by Indian GST regulations.

Usage Logs

Server access logs are retained for up to 90 days for security and debugging purposes.

7. Cookies & Local Storage

Authentication

We store your authentication token in browser local storage to keep you logged in across sessions. No third-party tracking cookies are used.

Preferences

Local storage is used to remember UI preferences such as your active role (buyer/agent/admin).

8. Children's Privacy

Age Restriction

Grihswami is not intended for users under 18 years of age. We do not knowingly collect personal data from minors. If you believe a minor has registered, please contact us and we will delete the account promptly.

9. Changes to This Policy

Updates

We may update this Privacy Policy from time to time. The "Last updated" date at the top of this page reflects the most recent revision. Continued use of the platform after changes constitutes acceptance of the updated policy.

10. Contact Us

Privacy Requests & Complaints

For any privacy-related questions, data requests, or complaints, please contact us at support@grihswami.com. We aim to respond within 5 business days.

Questions about your privacy?

We're here to help — reach out any time.

support@grihswami.com