Privacy notice
Version 2, effective 5 Oct 2026
This version takes effect on 5 Oct 2026
In short: What personal data we collect from customers and partners, why, who we share it with, how long we keep it, and how you can see, correct, delete or withdraw it. We collect the minimum, never sell your data, and do not use advertising cookies.
This notice explains how Mysuru Grandeur ("Mysuru Grandeur", "we", "us") handles personal data on this website, in the partner dashboard, and on WhatsApp and email. It is complete on its own: you don't need to read any other document to understand it.
It has three parts: Part A for customers, Part B for partners, and Part C for everyone (sharing, retention, security and your rights).
At a glance
- We collect only what we need to sell, deliver and support your order, or to run your partner account and pay you.
- We never sell personal data, and we don't use advertising or tracking cookies.
- Partners see only a short form of a customer's name and city (for example "Rahul M., Bengaluru"), never their phone number, address or payment details.
- We never see or store your card number, CVV or UPI PIN.
- We do not collect Aadhaar.
- You can ask for a copy of your data, correct it, delete it or withdraw consent. Withdrawing consent is as easy as giving it. Write to [to be published] or use /support.
1. Who we are
We decide why and how your personal data is used, so we are the Data Fiduciary under the Digital Personal Data Protection Act, 2023.
- Name: Mysuru Grandeur
- Registered office: [to be published]
- GSTIN: [to be published]
- CIN / LLPIN: [to be published]
- Privacy questions: [to be published]
- Grievance Officer: [to be published], Grievance Officer. Email [to be published], phone [to be published].
The same company collects your data and keeps it. This notice is also our privacy policy under rule 4 of the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 ("SPDI Rules").
2. The law we follow
The Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025 are being brought into force in stages (notification G.S.R. 843(E) of 13 November 2025). Most duties of businesses start on 13 May 2027. Until then, section 43A of the Information Technology Act, 2000 and the SPDI Rules apply. We already follow the stricter DPDP standard, so nothing about how we treat your data will change when the remaining provisions start.
Part A: If you are a customer
A1. What we collect and why
| Data | Why we use it | Legal basis | How long we keep it |
|---|---|---|---|
| Name, mobile number, email (optional) | To take and confirm your order, contact you about it and send your invoice | You give it for your order (DPDP s.7(a)) | 3 years after your last order. Copies on invoices are kept as below. |
| Delivery address, PIN code, gift message | To deliver your box and issue a GST invoice | You give it for your order (s.7(a)) | On the invoice: 8 years from the end of the financial year |
| Order details: boxes, prices, invoice, payment status and reference | To fulfil, account for and support your order, and meet tax law | For your order (s.7(a)); tax and accounting law | 8 years from the end of the financial year |
| The partner code used, and your link to the partner who introduced you | To pay that partner their commission (see A3) | For your order (s.7(a)); you can remove the link | Until the link ends (3 years after your last order) or your profile is deleted, whichever is sooner, or earlier if you ask |
| Messages and complaints you send us | To answer and resolve them | You give it to us (s.7(a)) | 3 years after the ticket is closed |
| Device and log data: IP address, browser type, times | To keep the website secure, prevent fraud and meet legal log-keeping duties | Legal duty (CERT-In Directions, 2022) | 1 year |
| Your choices: what you agreed to and when | To prove what you agreed to | Legal duty (DPDP s.6(10)) | While you are a customer, plus 3 years |
| WhatsApp updates and offers | To send them, only if you ticked the box | Your consent (s.6) | Until you withdraw |
Our shop is for adults. We don't collect any data we don't need, such as your date of birth or ID documents.
A2. If you send a gift
When you send a box to someone else, you give us their name, phone number and address. We use these only to deliver the gift. They appear on the shipping label and the invoice, and we don't contact the recipient for anything else. Please make sure they are happy for you to share their details with us.
A3. Partners and referrals
Many customers reach us through an independent partner, such as a guide, driver, hotel or shop. Partners earn a commission from us, paid by us. Your price is the same either way.
- When you scan a partner's QR code or open their link, we count the scan for that partner (time only; we don't record who scanned). We save the partner's code in a cookie on your device for 30 days, so the right partner is credited if you order later.
- When your first order with a partner's code is paid, your mobile number is linked to that partner. If you order again within 3 years of your most recent order, that partner may be credited again. If another partner helps you with a later order, both may be credited.
- What a partner sees about you: your first name, the initial of your last name and your city (for example "Rahul M., Bengaluru"), plus the order number, the boxes, the amount and the date. Partners never see your phone number, address, email or payment details. If two partners share a sale, neither is told who the other is.
- To remove the link at any time, write to [to be published] or use /support. Future orders will then not be credited to any partner. It does not change your price or your order.
If a partner places an order on your behalf, they act for us and may use your details only for that order. We then send you a link so you can check the order and pay on our website yourself.
A4. Messages we send you
- Order messages: order confirmation, payment receipt, invoice, dispatch, tracking and delivery updates. We send these by email or SMS, or on WhatsApp if you ticked "Send me order updates on WhatsApp".
- Offers: only if you ticked the box for offers. Every offer message tells you how to stop them.
Part B: If you are a partner
B1. What we collect and why
| Data | Why we use it | Legal basis | How long we keep it |
|---|---|---|---|
| Name, date of birth, WhatsApp number, email, sign-in details (including your Google account ID if you use Google sign-in) | To create and secure your account and confirm you are 18 or older | You give it to join (DPDP s.7(a)) | While your account is open, plus 3 years |
| Your photo | For your partner card and the public check page, so customers know it's you | You give it to join (s.7(a)) | While your account is open, plus 90 days |
| Partner type, business name, city, area, tourism licence number (if any), GSTIN (if any) | For your partner card, leagues and GST invoices | You give it to join (s.7(a)) | While your account is open, plus 3 years. GSTIN on tax records: 8 years. |
| Identity document: type, last few characters, images | To verify who you are | You give it to join (s.7(a)) | Images deleted 30 days after review. Type, last characters and our decision: while your account is open, plus 3 years. |
| PAN | To deduct and report income tax on your commission, as the Income-tax Act, 2025 requires | Legal duty; you give it (s.7(a)) | 8 years from the end of the financial year of your last payout |
| Bank account number, IFSC, account name, or UPI ID, and the verification result | To pay your commission to your own account | Your consent (SPDI Rules r.5(1)) | While your account is open. After closure, only the last 4 digits stay with payout records, for 8 years. |
| Your code, QR scan counts, orders credited to you, commission, payouts, tax deducted, rewards, streaks and ranks | To calculate and pay what you earn, accurately | For your partner account (s.7(a)) | 8 years from the end of the financial year |
| Leaderboard, website feature and WhatsApp offer choices | To show your name or send offers only if you switched them on | Your consent (s.6) | Until you switch them off |
| Support messages, disputes, payout confirmations | To resolve questions about your earnings | You give it to us (s.7(a)) | 3 years after the ticket is closed |
| Device and log data | Security and fraud prevention | Legal duty (CERT-In Directions, 2022) | 1 year |
B2. Identity documents
We accept a PAN card, driving licence, voter ID or passport. We do not accept Aadhaar and never ask for an Aadhaar number. Images are kept in private storage that only our verification staff can open, and every view is logged. We delete them 30 days after we review them.
B3. Bank details and PAN
Bank account and payment details are "sensitive personal data" under the SPDI Rules. We collect them only with your consent, which you give when you add them. We encrypt your PAN and bank account number separately from other data, and show them only in masked form (for example XXXXXX1234), including to our own staff. You can withdraw this consent, but we cannot then pay you until you give payout details again.
B4. Leaderboards and website features
Other partners see your first name, initial and area on a leaderboard only if you switch that on. Otherwise you appear as "A partner". Your earnings are never shown to other partners. We feature you on our public website (for example as Partner of the Month) only if you separately agree. You can switch either off at any time in your profile.
B5. Customer details you handle
When you place an order for a customer, you handle their details for us, and only for that order. Please don't keep copies or use them for anything else. Section 14 of the Partner terms explains this.
Part C: For everyone
C1. Who we share data with
We share only what each party needs to do its job. Our service providers process data only on our instructions, under written contracts that include security duties. We do not sell personal data.
| Who | What they do | Where |
|---|---|---|
| Supabase Inc. | Database, sign-in and file storage | South Korea (AWS Seoul region) |
| Hostinger International Ltd. | Hosts the website. Our server code runs in Mumbai. | India |
| Razorpay Software Private Limited | Online payments and refunds | India |
| Twilio Inc. and Meta Platforms (WhatsApp) | One-time sign-in codes and messages | May be processed outside India |
| Resend | Email delivery | May be processed outside India |
| Google LLC | Sign in with Google, only if you choose it | May be processed outside India |
| Courier companies | Your name, phone number and address, to deliver your parcel | India |
| The partner who introduced you (customers) | Short name and city, order number, boxes, amount and date only | India |
| Tax authorities (partners) | PAN, commission and tax deducted, as the law requires | India |
| Police, courts and regulators | Only when we receive a lawful written request or order | India |
C2. Data processed outside India
The website runs on servers in India, but your account, order and payment records are stored by Supabase in South Korea (Seoul). Some of our other providers (messaging, email and Google sign-in) may process data in other countries, such as the United States. We use only established providers that protect data to standards at least as strong as Indian law requires. Indian law currently allows these transfers, and we will follow any restriction the Government notifies under section 16 of the DPDP Act.
C3. How long we keep data
We keep data only as long as we need it, or as long as the law requires, and then delete or anonymise it.
| Record | How long |
|---|---|
| Orders, invoices, payment and refund records | 8 years from the end of the financial year of the order (GST and company law) |
| Customer profile (name, phone, email) and partner link | 3 years after your last order, then deleted or anonymised |
| Partner ID document images | 30 days after review |
| PAN, tax deducted, commission and payout records | 8 years from the end of the financial year of the last payout |
| Partner profile | While your account is open, plus 3 years |
| Security and access logs | 1 year |
| Consent records | While you use our services, plus 3 years |
| Support tickets and complaints | 3 years after closure |
| Backups | Erased data disappears from backups as they roll over, within 30 days |
If there is an open dispute, investigation or legal claim, we keep the relevant records until it is closed.
C4. How we protect your data
- All connections use encryption (HTTPS), and data is encrypted where it is stored.
- PAN and bank account numbers are encrypted again with a separate key, and shown only masked.
- Staff can see only what their role needs (for example, only verification staff can open ID images). Every change staff make, and every time ID images are opened, is logged.
- Database rules stop anyone from reading another person's data. Partners can read only their own records.
- Staff sign in with one-time codes or Google sign-in, never shared passwords. We keep backups and security logs and review access regularly.
C5. If something goes wrong
If a breach affects your data, we will tell you without delay by WhatsApp, SMS or email. We will explain what happened and when, what it may mean for you, what we are doing about it, steps you can take, and whom to contact. We will also report it to CERT-In within 6 hours and to the Data Protection Board of India, as the law requires.
C6. Your rights
You have the right to:
- get a summary of your personal data, how we use it, and who we have shared it with;
- correct, complete or update your data;
- erase your data, except what the law requires us to keep (such as invoices and tax records, for the periods in C3);
- withdraw consent at any time (see C7);
- nominate someone to use these rights for you if you die or become unable to act (see C8); and
- complain to us and, if you are not satisfied, to the Data Protection Board (see C9).
How to use them: write to [to be published], use /support, or message us on WhatsApp at [to be published]. Partners can also use their dashboard profile. To help us find your records, tell us your registered mobile number, and your order number or partner code if you have one. We may confirm it's you with a one-time code.
How fast: we acknowledge within 48 hours and respond within 30 days, and in no case later than 90 days. There is no charge.
C7. Withdrawing consent
Where we rely on your consent, withdrawing it is as easy as giving it:
- WhatsApp updates and offers: reply STOP to any message, untick the option in your profile, or write to us.
- Leaderboards and website features (partners): switch them off in your profile.
- Bank or UPI details (partners): remove them in your profile or write to us.
- Partner link (customers): write to [to be published].
Withdrawal doesn't affect anything we did lawfully before it. We will stop, and make our providers stop, within a reasonable time, normally 7 days.
C8. Nominating someone
You can name a person to use your rights if you die or become unable to act. Write to [to be published] with their name and contact details, from your registered mobile number or email.
C9. Complaints
Please talk to us first. Our Grievance Officer is [to be published], Grievance Officer, at [to be published]. Email [to be published], phone [to be published]. You will get a ticket number within 48 hours and a resolution within one month. See our Grievance redressal page.
If you are not satisfied, you can complain to the Data Protection Board of India, set up under section 18 of the DPDP Act, once its complaint process is available. We will add a direct link here when the Board publishes one.
C10. Children
Our services are only for people aged 18 or older, and partners must be 18 or older. We do not knowingly collect children's data. If we learn that we have, we delete it.
C11. Cookies and similar technology
We use only what the website needs to work:
- Sign-in cookies, which keep partners and our staff signed in;
- mg_ref, which stores a partner's code for 30 days after you scan their QR code, so the right partner is credited; and
- cart storage on your device, which remembers the boxes in your cart.
We do not use advertising, tracking or third-party analytics cookies. If we ever want to, we will ask first, and saying no will be just as easy as saying yes.
C12. Payments
Online payments are processed by Razorpay, an RBI-authorised payment aggregator. We never receive or store your card number, CVV, UPI PIN or net-banking password. We keep only the payment reference and status. If you pay by UPI transfer, we keep the transaction reference (UTR) you give us.
C13. Language
This notice is in English. A Kannada version is being prepared and is available on request in the meantime. If the versions differ, the English version applies, but no translation will reduce your rights.
C14. Changes to this notice
If we change this notice, we will update the version and date on this page. If a change affects how we use data you have already given us, we will tell you by email or WhatsApp before it applies, and ask for fresh consent where the law requires.
| Version | Date | What changed |
|---|---|---|
| 1 | 5 October 2026 | First published |