Privacy Policy

This Privacy Policy explains what personal data Groomto collects through the Groomto customer app, the Groomto Partner app and groomto.com, why we collect it, who we share it with, and the choices and rights you have over it.

Last updated 24 August 2026Effective 24 August 2026
GroomtoCustomer app

Customers discovering and booking salon, spa, makeup, tattoo and grooming services.

Groomto PartnerPartner app

Salon, spa, studio and grooming business owners and their staff managing bookings.

1. Who this policy covers

Groomto operates a technology platform that connects customers with independent salon, spa, makeup, tattoo and grooming businesses ("Partners"). This single policy applies to all of the following:

  • The Groomto customer app for Android — used to discover Partners, book appointments and pay.
  • The Groomto Partner app for Android — used by Partner businesses and their staff to list services, accept bookings and run offers.
  • Our website at groomto.com.

Where a section applies to only one of the two apps, we say so explicitly. In this policy "we", "us" and "Groomto" mean the entity named in the Contact section, which is the data fiduciary responsible for your personal data.

2. The short version

  • We collect what a booking actually needs: your name, phone number, email, approximate or precise location, and your booking history.
  • We share your name, phone number and booking details with the specific Partner you book with — they need it to serve you.
  • We never sell your personal data, and we do not use it for third-party advertising.
  • Card and UPI credentials are entered on our payment gateway's screens. Groomto never sees or stores them.
  • You can delete your account and its data at any time from inside the app, or by requesting it at groomto.com/delete-account.

3. Data we collect

3.1 Data you give us — customer app

  • Account details: name, mobile number, email address and (optionally) a profile photo and gender.
  • Booking details: the Partner, services, date and time slot you choose, and any notes you add to a booking.
  • Payment preference: whether you chose "Pay at venue" or "Pay now", and the transaction reference returned by the gateway.
  • Reviews and ratings: your star rating, review text and any photos you attach. These are shown publicly next to your display name.
  • Favourites and saved Partners.
  • Support correspondence: messages, screenshots and contact details you send when you contact us.

3.2 Data you give us — Partner app

  • Business profile: business name, category, description, address and map location, contact number, working hours and photos of the premises.
  • Service catalogue: services, durations and prices, plus any offers or discount codes you create.
  • Owner and staff details: name, mobile number, email address and role for each account with access to the business.
  • Payout and tax details: bank or UPI settlement details, PAN and GSTIN. We do not ask you to upload registration, licence or identity documents, and the apps have no document upload.
  • Booking activity: requests received, approvals, declines, completions, cancellations and no-shows.

3.3 Data collected automatically (both apps)

  • Device and app data: device model, operating system version, app version, language, time zone and a generated installation identifier.
  • Location: approximate or precise device location, used to find Partners near you and to show distance. Collected only while you use the relevant screens, and only if you grant the permission — see Permissions below.
  • Usage data: screens opened, features used, searches run and taps on offers, in aggregate form.
  • Diagnostics: crash reports, error logs, and performance traces.
  • Push token: the Firebase Cloud Messaging token for your installation, so we can deliver booking notifications.
  • Server logs: IP address, request timestamps and user agent, retained for security and abuse prevention.

3.4 Data we receive from others

  • From our payment gateway: the status of a payment, a masked instrument description (for example "UPI" or "card ending 4242") and a transaction ID. We do not receive full card numbers, CVV or UPI PIN.
  • From a Partner: confirmation that you attended, plus completion or no-show status for a booking you made.
  • From Google, where you choose Google sign-in: your name, email address and profile picture, as permitted by the consent screen you see.

We do not knowingly collect biometric data, precise health data, caste, religion, political opinion or sexual orientation. Please do not put such information into free-text fields such as booking notes or reviews.

4. Android permissions we request

Both apps request permissions only when the feature that needs them is used, and both work — with reduced functionality — if you decline. You can change any of these later in Android Settings › Apps › Groomto › Permissions.

PermissionWhy we askIf you decline
Location (approximate / precise)To sort Partners by distance, show them on the map and power "near me" search.You can still search by area or city name manually.
CameraTo take a photo for a review, a profile picture, or — in the Partner app — photos of your premises and services.You can pick an existing image from your gallery instead.
Photos and mediaTo upload images you select for reviews, profiles and business galleries.Image upload is unavailable; everything else works.
NotificationsTo send booking confirmations, reminders, and — in the Partner app — new booking request alerts.You will need to open the app to check booking status.
Network stateTo detect connectivity and queue actions while you are offline.Not applicable — this permission does not involve personal data.

Neither app requests access to your contacts, SMS messages, call logs or files outside the images you explicitly pick. Neither app collects location in the background or while it is closed.

5. How we use your data

  • To create and secure your account, and to sign you in.
  • To take, confirm, reschedule and cancel bookings, and to pass the booking to the Partner you selected.
  • To process payments, issue receipts and handle refunds and chargebacks.
  • To operate promo codes and loyalty points, and to detect abuse of them.
  • To send transactional messages you cannot opt out of while you hold an account — booking confirmations, changes, reminders and receipts — by push notification, email or SMS.
  • To send optional marketing about offers and new features, only where you have opted in. Every such message carries an unsubscribe or opt-out.
  • To publish your rating and review against the Partner you visited.
  • To provide customer support and resolve disputes between customers and Partners.
  • To verify Partner businesses, including reviewing the documents they submit, before they go live.
  • To keep the platform safe: preventing fraud, fake reviews, spam bookings and unauthorised access.
  • To measure and improve the product using aggregated, de-identified analytics.
  • To comply with applicable law, tax obligations and lawful requests from authorities.

We do not use your personal data to train machine-learning models that are made available to third parties, and we do not run third-party advertising networks inside either app.

6. Our legal basis

For users in India we process personal data under the Digital Personal Data Protection Act, 2023, relying on:

  • Your consent, given at sign-up and at each permission prompt, for collection and use as described here. You may withdraw consent at any time (see Your rights).
  • Certain legitimate uses recognised under the Act, including data you voluntarily provide for a purpose you have not objected to, compliance with law, and responding to legal claims.

Where the GDPR or UK GDPR applies to a user, we rely on: performance of a contract (delivering a booking you asked for), legitimate interests (platform safety, product improvement, dispute resolution), consent (optional marketing, precise location) and legal obligation (tax and accounting records).

7. Who we share data with

7.1 With Partners you book

When you confirm a booking, the Partner receives your name, mobile number, the services booked, your chosen slot, your payment method choice and any note you added. Partners are contractually required to use this only to deliver and support your appointment, and not for their own marketing without your separate consent. Once served, the Partner also sees the review you leave.

7.2 With customers, if you are a Partner

Your business name, category, address and map pin, photos, services, prices, working hours, offers, aggregate rating and reviews are shown publicly in the customer app. Your bank details, PAN and GSTIN are never shown to customers.

7.3 With service providers

We use the processors below, each bound to use the data only for the purpose we specify:

Google Firebase (Authentication, Cloud Firestore, Cloud Storage)

Account sign-in, app data storage and uploaded images.

Their privacy policy

Firebase Cloud Messaging

Booking and reminder push notifications.

Their privacy policy

Google Analytics for Firebase & Crashlytics

Aggregate usage analytics and crash diagnostics.

Their privacy policy

Google Maps Platform

Maps, place search and distance to nearby partners.

Their privacy policy

[Payment gateway — e.g. Razorpay]

Processing 'Pay now' online payments. Card and UPI credentials are entered on the gateway and never reach Groomto's servers.

Their privacy policy

7.4 Other disclosures

  • Legal and safety: where required by law, court order or a valid request from a government authority, or to establish, exercise or defend legal claims.
  • Corporate transactions: if Groomto is involved in a merger, acquisition or asset sale, your data may transfer to the successor, which remains bound by this policy or a policy at least as protective. We will notify you before your data becomes subject to a materially different policy.
  • Aggregated data: we may publish statistics — such as total bookings or average ratings by city — that cannot identify you.

We do not sell personal data, and we do not share it with data brokers or advertising networks.

8. How long we keep data

DataRetention
Account profileUntil you delete your account. Deletion is immediate — the record is anonymised in a single transaction.
Booking and transaction records6 years (72 months) after the booking, as required by GST record-keeping rules. Held in a restricted financial ledger and detached from your profile once the account is deleted.
Reviews and ratingsRetained after account deletion but anonymised — your name is replaced with "Groomto user" — so Partner ratings stay accurate. Tell us if you want the review text removed entirely.
Profile photoCleared immediately on account deletion. Photos attached to reviews follow the review row below.
Support tickets3 years from resolution.
Crash and diagnostic logsUp to 90 days.
Server and security logsUp to 180 days.
Partner tax identifiers (PAN, GSTIN)Kept in a restricted audit record for 6 years (72 months), alongside the financial records they relate to.
Encrypted backupsPurged on a rolling cycle, no later than 90 days after deletion.

9. How we protect data

  • All traffic between the apps and our servers is encrypted with TLS. Data at rest is encrypted on our infrastructure providers.
  • Access to production data is restricted to authorised personnel on a need-to-know basis, and is logged.
  • Payment credentials are handled entirely by a PCI-DSS compliant gateway; they never touch Groomto systems.
  • We review our dependencies and Firebase security rules, and we require authentication on every data path.

No system is perfectly secure. If a personal data breach affects you, we will notify you and the Data Protection Board of India as required by the DPDP Act. Please report any vulnerability you find to the privacy contact below.

10. Your rights and choices

  • Access: request a summary of the personal data we hold about you and who we have shared it with.
  • Correction: fix inaccurate or incomplete data. Most fields are editable directly in the app under Profile.
  • Erasure: delete your account and associated data — see the account deletion page for exactly what is removed and what we must keep.
  • Withdraw consent: turn off any permission in Android Settings, or opt out of marketing from the link in any marketing message. Withdrawing consent does not affect processing already carried out.
  • Nominate: nominate another person to exercise these rights on your behalf in the event of death or incapacity, as provided under the DPDP Act.
  • Grievance redressal: raise a complaint with our Grievance Officer, who will respond within the window stated below. If you are unsatisfied, you may escalate to the Data Protection Board of India.

To exercise any of these, email the privacy contact below from the address or with the phone number registered on your account. We may ask you to verify your identity before acting, and we will respond within 30 days.

11. Children

Groomto is not directed at children. You must be 18 or older to hold an account. A parent or legal guardian may book a service for a child using their own account, and by doing so confirms they consent on the child's behalf. We do not knowingly collect personal data from anyone under 18, do not track or profile children, and do not serve them advertising. If you believe a child has created an account, contact us and we will delete it.

12. Where your data is processed

We aim to store personal data in data centres located in India. Some of our processors — Google and our analytics providers among them — may process or back up data in other countries. Where that happens we rely on the transfer mechanisms those providers offer, such as standard contractual clauses, and we transfer only to jurisdictions not restricted by the Government of India.

13. Cookies on groomto.com

Our website uses only what it needs to function, plus privacy-respecting aggregate analytics to count page views. We do not run advertising or cross-site tracking cookies on groomto.com. The mobile apps do not use cookies; the identifiers they use are described in section 3.3.

14. Changes to this policy

We may update this policy as the apps change. The "Last updated" date at the top always reflects the current version. For material changes — a new purpose, a new category of recipient — we will notify you in the app or by email before the change takes effect, and where the law requires it, ask for fresh consent.

15. Contact us

  • Data fiduciary
    [Registered legal entity name — e.g. Groomto Technologies Pvt. Ltd.]
  • Registered office
    [Registered office address, City, State, PIN — India]
  • Privacy contact
  • General support
  • Grievance Officer — [Grievance Officer name]
    Responds within 15 days.
  • Jurisdiction
    [City], India

This policy is published by Groomto and applies to the Android apps listed above. If any translated version of this policy conflicts with the English version, the English version prevails.

Want your data removed?

You can delete your account and its data from inside either app, or send us a request from our deletion page. It explains exactly what gets erased, what we are legally required to keep, and how long each step takes.