Privacy Policy
Last updated 1 September 2026
This policy explains what Ginti collects, why, and what you can do about it. It applies to the Ginti application and website operated by[REGISTERED ENTITY NAME]. We are the data fiduciary for account data; for the business records you enter, you are the fiduciary and we process on your behalf.
1. What we collect
Account information
Your name, email address, phone number and business name, provided at sign-up. If you sign in with Google, we receive your name and email from Google — we never see your Google password.
Business records
Everything you enter to run your business: categories, products, stock levels, stock movements, prices, product photographs, and the customer and supplier contacts you choose to record. If you record a customer’s name or phone number, we store it because you asked us to.
Activity records
We log actions taken in your workspace — who changed what and when — so that Owners and Managers have an audit trail. We also record which features are visited, in order to understand what is used and what is not.
Technical information
Standard server logs: IP address, browser type, timestamps and error traces. These are used to keep the Service running and secure.
2. What we do not collect
- Card and bank details. Where payment is taken it is handled by a payment provider. We never see or store your card number.
- Passwords. Authentication is handled by Google Firebase; we never receive your password.
- Location. We do not track your device location.
- Advertising identifiers. We do not run advertising or sell data to anyone, ever.
3. How your data is separated
Each business is an isolated workspace. Access is enforced in two independent layers: every request is filtered by your business identity in the application, and the database additionally applies row-level security policies so that a query cannot return another business’s rows. Within your workspace, what a person sees is determined by their role.
4. Where your data is stored
Data is hosted on Google Cloud infrastructure in the Mumbai region (asia-south1), India. Product photographs are held in object storage in the same region. Authentication is operated by Google Firebase, which may process authentication data outside India under Google’s own terms.
5. Who we share it with
We do not sell your data. We share it only with providers needed to run the Service:
- Google Cloud Platform — hosting, database and file storage.
- Google Firebase — sign-in and transactional email such as password resets.
- A payment provider — where you pay for a plan, to process that payment.
If you use the voice feature, the words you speak are sent to a third-party language model to interpret the command. That feature is off unless it has been enabled for your business. No other feature sends your data to a language model.
We may disclose data if legally required to, and will tell you unless prohibited from doing so.
6. How long we keep it
For as long as your account is active. Categories, products and stock items you delete are moved to Trash and recoverable for a period before removal; transaction records are retained as the ledger they are. When you close your account we delete or anonymise your data within [RETENTION PERIOD, e.g. 90 days], except where law requires us to keep it longer.
7. Your rights
Under India’s Digital Personal Data Protection Act, 2023 you may:
- Access the personal data we hold about you.
- Correct anything inaccurate — most of it is editable in the app.
- Erase your data, subject to our legal retention obligations.
- Withdraw consent, by closing your account.
- Nominate another person to exercise these rights if you cannot.
- Complain to the Data Protection Board of India.
Export is built in — Excel and PDF, from the Reports and Export screens. For anything else, write to us and we will respond within [RESPONSE PERIOD, e.g. 30 days].
8. Security
Traffic is encrypted in transit. Database access is restricted and credential-gated, and the isolation described in section 3 is enforced at the database layer, not only in application code. No system is perfectly secure; if a breach affects your personal data we will notify you and the Data Protection Board as the Act requires.
9. Cookies and local storage
We use browser storage to keep you signed in and to remember your language and theme preference. We do not use advertising or cross-site tracking cookies.
10. Children
Ginti is a business tool and is not intended for anyone under 18. We do not knowingly collect data from children.
11. Changes
We will post any update here and change the date above. Material changes will be notified in the application or by email before they take effect.
12. Contact
Privacy questions, or to exercise any right above: [CONTACT EMAIL]. Grievance Officer: [NAME], [EMAIL], as required under the Digital Personal Data Protection Act, 2023.
