Legal & Transparency

Privacy Policy

Last Updated: 19 August 2026 | Effective Date: 19 August 2026

1. Who we are

Glacro is a cloud hosting and deployment platform operated by Rajan Kumar, registered at 147 Thadagam Main Road, Venkatapuram, Velandipalayam, Sri Sai Complex, Coimbatore, Tamil Nadu 641025, India.

For the purposes of the Digital Personal Data Protection Act, 2023 (“DPDP Act”) we are the Data Fiduciary for the personal data described below. You are the Data Principal.

This notice describes what our systems actually do, not merely what we are permitted to do.

2. What we collect, and why

We collect the following, and nothing else:

DataWhy we need itWhere it is stored
Full nameTo identify your account and address you in emailGlacro Auth, Glacro DB
Email addressLogin identity, verification codes, billing receipts, deployment notificationsGlacro Auth, Glacro DB
PasswordAuthentication. Handled entirely by Glacro Auth Engine. We never see, store or transmit it, and cannot recover it for youGlacro Auth Engine
Phone number (optional)SMS one-time codes for verification and account recoveryGlacro Auth, Glacro DB
One-time codesVerification. Stored only as a cryptographic hash and deleted automatically after 10 minutesGlacro DB
IP addressRate limiting, to block brute-force login and signup abuse. Held in memory only, never written to our databaseApplication memory (transient)
GitHub username and access tokenOnly if you connect GitHub. To list your repositories and clone the one you choose to deployGlacro DB
Google account id, name, emailOnly if you sign in with GoogleGlacro Auth, Glacro DB
Project settingsRepository URL, branch, framework, build command, output directory and any environment variables you enter, so we can build and host your siteGlacro DB, passed to Glacro Build Engine
Deployment records and build logsBuild status, duration, timestamps and log output, so you can debug failuresGlacro DB, Glacro Object Storage
Your built site filesTo serve your website to visitorsGlacro Object Storage
Custom domain namesTo issue TLS certificates and route traffic to your siteGlacro DB, Glacro Global DNS Engine, Glacro Certificate Manager
Plan, credit balance, transaction historyTo meter usage and enforce plan limitsGlacro DB
Payment identifiers and invoicesAmount, currency, gateway and payment reference, for accounting and tax complianceGlacro DB
Support and contact messagesTo answer your queryGlacro DB, Glacro Mail Delivery
Cookie consent choiceTo record what you agreed toBrowser cookie, Glacro DB

We do not collect your card number, CVV, UPI PIN or bank credentials. Those are entered directly into Razorpay or Stripe and never reach our servers. We run no advertising trackers, we do not sell personal data, and we do not use your data or your source code to train machine-learning models.

3. Your consent

We rely on the consent you give by ticking the box at sign-up, and on the legitimate uses permitted by section 7 of the DPDP Act, such as issuing invoices you have asked for and complying with law.

Your consent covers only the purposes listed in section 2. We will ask again before using your data for any new purpose.

You may withdraw consent at any time, and withdrawing must be as easy as giving it. Do it from Settings, or write to our Grievance Officer. Because we cannot run a hosting account without this data, withdrawal means we delete your personal data and close your account. Withdrawal does not undo processing already carried out lawfully.

4. Who we share it with

We share personal data only with the processors below, only as far as each needs to do its job, and never for their own marketing.

RecipientWhat they receiveWhy
Glacro Global Infrastructure (Mumbai Region)All account, project and site dataHosting, authentication, database, storage, email and build infrastructure
RazorpayName, email, amountTo take payments from customers in India
StripeEmail, amountTo take payments from customers outside India
GitHubYour access tokenTo read the repositories you ask us to deploy
GoogleYour Google profile, if you sign in with GoogleAuthentication
Google reCAPTCHAIP address and browser signalsTo tell real users from automated abuse at sign-up and login

We may also disclose data where Indian law, a court order or a lawful government request requires it. We will tell you when that happens unless we are legally barred from doing so.

5. Where your data is stored

Your account, project, deployment and billing data is stored in the Glacro Asia-South (Mumbai) glacro-asia-south region, in India.

Some processors named above operate outside India, so limited data crosses borders — the details Stripe needs for an international card, or the request reCAPTCHA inspects. The DPDP Act permits such transfers except to countries the Central Government restricts by notification.

6. How long we keep it

DataRetention
Account profileWhile your account is open, then deleted within 30 days of closure
One-time codes10 minutes, then deleted automatically
IP addressesIn memory for the rate-limit window only; never written to disk
Deployment records and build logs90 days
Site filesUntil you delete the project or close your account
Invoices and payment records8 years, as Indian tax and companies legislation requires. This is a legal obligation and survives both account closure and withdrawal of consent
Support correspondence3 years

7. How we protect it

Passwords are managed by Glacro Auth Engine and never reach our systems. Data is encrypted in transit over TLS and at rest by Glacro Cloud. Session tokens live in HttpOnly cookies that JavaScript cannot read. Every read of your account data is keyed to your own authenticated identity, so one customer cannot reach another’s. Payment webhooks are cryptographically signature-verified. One-time codes are stored hashed, are single-use, and expire.

No system is perfectly secure. If a breach affects your personal data we will notify you and the Data Protection Board of India as the DPDP Act requires.

8. Your rights

Under the DPDP Act you may:

  • Ask what personal data we hold about you, and who we have shared it with
  • Have inaccurate or incomplete data corrected or completed
  • Have your data erased, except where law requires us to keep it (see invoices above)
  • Withdraw your consent at any time
  • Nominate someone to exercise these rights for you on death or incapacity
  • Complain to our Grievance Officer, and escalate to the Data Protection Board of India

We respond to any request within 30 days, free of charge.

9. Children

Glacro is not offered to anyone under 18, and we do not knowingly collect a child’s data. If we learn we hold one without verifiable parental consent we will delete it. We carry out no behavioural tracking or targeted advertising directed at children.

10. Cookies

We set only cookies that are strictly necessary to run the service: a session cookie to keep you signed in, a refresh cookie to renew that session, and a cookie recording your consent choice. We use no advertising or cross-site tracking cookies. Blocking the necessary cookies will prevent you from signing in.

11. Grievance Officer

As the DPDP Act and the Information Technology Act, 2000 require, you can reach our Grievance Officer:

Rajan Kumar
glacro.com@gmail.com
147 Thadagam Main Road, Venkatapuram, Velandipalayam, Sri Sai Complex, Coimbatore, Tamil Nadu 641025, India

We acknowledge complaints within 24 hours and resolve them within 15 days. If you remain unsatisfied you may complain to the Data Protection Board of India.

12. Changes

If we change how we use your personal data we will update this page, change the date at the top, and tell you by email before the change takes effect. Where the change requires it, we will ask for fresh consent.