This Privacy Policy explains how Griomed Global Pvt. Ltd. (“Griomed”, “we”, “us”) collects, uses, and protects your information when you use the Griomed Franchise Partner mobile app and the franchise portal at franchise.griomedglobal.com.
1. Who this policy applies to
This policy applies to anyone who:
- Submits a franchise application through the mobile app or website
- Holds a franchise owner or staff account in the Griomed Franchise System
- Pays a booking amount or invoice through our integrated payment gateway
- Receives transactional communications (SMS, email) from Griomed
2. Information we collect
Information you provide directly
- Identity: Full name, phone number, email address
- Location: City, state (used to match you with a regional manager)
- Business profile: Investment budget, preferred franchise plan, outlet location once activated
- Account credentials: Password (stored as a one-way hash; we never see it in plain text)
- Support content: Tickets, replies, uploaded documents
Information collected automatically
- Device data: Operating system, app version, device model (for crash diagnostics)
- Usage data: Screens viewed, actions taken, last-login timestamp
- Network data: IP address and approximate region from request headers
Information from third parties
- Razorpay (payment gateway): Transaction status, payment ID, signature. We never store your card or UPI details — those are handled entirely by Razorpay’s PCI-DSS-compliant servers.
- MSG91 (SMS provider): Delivery receipts for OTPs and notifications we send to your phone.
3. How we use your information
- To process your franchise application and verify your identity
- To create and operate your franchise account, including invoices, orders, and onboarding
- To send transactional OTPs, payment receipts, and important account updates
- To improve the product (anonymised usage analytics)
- To comply with legal obligations (tax, GST, audit trails)
4. How we share your information
We share data only when necessary:
- Service providers: Razorpay (payments), MSG91 (SMS), our cloud hosting provider — all bound by strict data-processing terms.
- Internal Griomed teams: Sales, Operations, Accounts — on a need-to-know basis to support your franchise.
- Legal & regulatory: When required by law, court order, or to protect Griomed’s legitimate interests.
We do not sell your data. We do not share data with advertisers.
5. How long we keep your data
- Active franchise accounts: For as long as your franchise is operational.
- Closed accounts: Up to 7 years after closure (required by Indian tax/accounting law).
- Unconverted leads: Up to 24 months from last activity, then deleted.
6. Your rights
You can, at any time:
- Access the data we hold about you
- Correct inaccurate information (via the in-app Profile section or by emailing us)
- Request deletion of your account (subject to legal retention requirements)
- Withdraw consent for non-essential communications
7. Security
All data in transit uses TLS 1.2+. Passwords are hashed with bcrypt. Payment data never touches our servers — Razorpay handles it on PCI-DSS-certified infrastructure. Authentication tokens on the mobile app are stored in encrypted secure storage (Keystore on Android, Keychain on iOS).
8. Children
The Griomed Franchise System is intended for business owners aged 18 and above. We do not knowingly collect data from children under 18.
9. Changes to this policy
We will notify you of material changes through the app or by email. The “Last updated” date at the top of this page reflects the most recent revision.
10. Contact us
Questions about this policy or your data:
Email: privacy@griomedglobal.com
Address: Griomed Global Pvt. Ltd., Patna, Bihar, India