Privacy Policy
Last updated: August 27, 2026
1. Who We Are
IndiTrace is an agricultural supply chain traceability platform operated by Griiken ("we", "us"). Under India's Digital Personal Data Protection Act, 2023 ("DPDP Act") we act as the Data Fiduciary for personal data processed through the platform at inditrace.com. You can reach us at privacy@griiken.com or +91 70235 70592.
This policy explains what personal data we collect, why, how long we keep it, who we share it with, and the rights you have. It applies to organisations and their users on the platform, farmers whose details are entered, and anyone who visits our public pages.
2. Data We Collect
Data you or your organisation give us
- Account data: name, email address, phone number (verified by OTP), password (stored only as a cryptographic hash), organisation name and details, and GSTIN if provided for invoicing;
- Farmer and farm data: names, phone numbers, village and location details, land or plot information, and photographs of farmers, farms, and produce that you enter;
- Batch and supply chain data: crop and product details, quantities, dates, processing steps, custody and shipment records, geolocation coordinates captured at events, and uploaded photos and documents;
- Billing data: plan purchases, payment status and references from our payment gateway, and invoice details;
- Communications: messages you send us through contact forms, email, WhatsApp, booked calls, or newsletter subscriptions.
Data collected automatically
- Technical logs: IP address, request timestamps, browser type, and error logs, kept for security and troubleshooting;
- Authentication tokens: when you log in, access and refresh tokens are stored in your browser's local storage to keep you signed in — these can be cleared any time by logging out;
- Usage data: how the platform is used, in aggregated form, to improve the service.
Data from public pages
Public trace pages are viewable without an account. We log only minimal, aggregated request data for these pages (needed to keep them fast and available).
3. Why We Process It (Purposes and Bases)
- To provide the platform — accounts, batch registration, trace pages, QR codes, anchoring, notifications (emails/SMS about batches and account activity). Basis: performance of your contract with us.
- To process payments and comply with tax law — collecting payments via the gateway, issuing GST invoices, maintaining accounting records. Basis: contract and legal obligation.
- To keep the service secure and available — fraud prevention, rate limiting, abuse detection, debugging, backups. Basis: our legitimate interest in operating a safe service, and legal obligation where applicable.
- To communicate with you — support, onboarding help, transactional notices (e.g. batch anchored, plan expiring), and — only with your consent — newsletters and product updates.
- To improve the platform — aggregated usage analysis, feature development.
We do not sell personal data. We don't use your data for behavioural advertising. We don't make solely automated decisions with legal or similarly significant effects about you.
4. Public Trace Pages and Blockchain — Please Read
Two features of IndiTrace intentionally make certain data public. If you are an organisation entering farmer or batch data, you control what gets published:
- Public trace pages: information you publish on a batch's trace page is visible to anyone who scans its QR code or opens its link — no account needed. Choose deliberately what farmer details and photos you publish.
- Blockchain anchoring: a cryptographic hash of batch records is written to the public Polygon blockchain. On-chain data is immutable — it can never be edited or deleted, by us or anyone. The hash does not itself reveal personal details, but it permanently and publicly proves that the batch record existed at a timestamp.
Because of these features, deletion or correction of data already published on-chain or on live trace pages is technically limited: we can update or unpublish platform data, but cannot alter blockchain history. We will clearly explain these limits when you make a correction or erasure request.
5. Who We Share Data With
We share personal data only with processors and sub-processors that help us run the platform, under contract, limited to their function:
- Cloud hosting and database: Amazon Web Services (India region);
- File and media storage: Supabase (batch photos and documents);
- Payments: Cashfree (to collect your payments and issue receipts — they process card/UPI details, we never see them);
- Email and SMS delivery: transactional email (e.g. Resend) and SMS providers (for OTPs and batch notifications);
- Blockchain network: Polygon (batch hashes, as described above);
- Scheduling: Calendly, when you book a call with us;
- Professional advisers (accounting, legal) and authorities, where required by law.
Cross-border note: some providers may process data outside India. Where they do, we rely on the DPDP Act's permitted-transfer conditions and contractual safeguards. We do not otherwise transfer personal data out of India.
6. Retention
- Active accounts: for as long as your organisation uses the platform, plus a short grace period;
- Billing and invoices: as required by Indian tax law (typically 8 years for GST records);
- Security logs: up to 12 months, then deleted or anonymised;
- Closed accounts: platform data is deleted or anonymised within a reasonable period after closure, except data we must keep for law, disputes, or the blockchain/trace-page limits described in Section 4;
- Published trace pages and on-chain hashes: trace pages stay online while the underlying batch is published (batch records intentionally remain publicly verifiable even after plans expire); on-chain hashes are permanent by nature.
7. Your Rights
Under the DPDP Act you can ask us to: access your personal data; correct or complete inaccurate or incomplete data; erase it (subject to legal retention and the blockchain limits above); nominatesomeone to exercise rights on your behalf; and withdraw consent or opt out of marketing at any time (grievance redressal below). Organisations can also request an export of their platform data in standard formats.
Email privacy@griiken.com from your registered address with your request; we respond within a reasonable period and may need to verify your identity first. If you are unsatisfied with our response, you may escalate to the Data Protection Board of India.
8. Security
We apply measures appropriate to the sensitivity of the data: HTTPS/TLS for all traffic, passwords stored as salted hashes, short-lived authentication tokens, role-based access within organisations, least-privilege access for staff, audit logging of batch changes, and periodic security review. No system is perfectly secure; if a breach likely affects you, we will notify you and the regulator as required by the DPDP Act.
9. Children
The platform is not directed at children under 18, and we do not knowingly collect their data. If you believe a child's data was entered, contact privacy@griiken.com and we will remove it.
10. Changes and Contact
We may update this policy; the "Last updated" date will change and significant updates will be announced in the platform or by email. Questions, requests, or complaints: privacy@griiken.com, or Griiken, +91 70235 70592, or our Contact Page. Our Terms of Service also apply.