Privacy Policy
Last Updated: 19 August 2026 | Effective Date: 19 August 2026
1. Who we are
Glacro is a cloud hosting and deployment platform operated by Rajan Kumar, registered at 147 Thadagam Main Road, Venkatapuram, Velandipalayam, Sri Sai Complex, Coimbatore, Tamil Nadu 641025, India.
For the purposes of the Digital Personal Data Protection Act, 2023 (“DPDP Act”) we are the Data Fiduciary for the personal data described below. You are the Data Principal.
This notice describes what our systems actually do, not merely what we are permitted to do.
2. What we collect, and why
We collect the following, and nothing else:
| Data | Why we need it | Where it is stored |
|---|---|---|
| Full name | To identify your account and address you in email | Glacro Auth, Glacro DB |
| Email address | Login identity, verification codes, billing receipts, deployment notifications | Glacro Auth, Glacro DB |
| Password | Authentication. Handled entirely by Glacro Auth Engine. We never see, store or transmit it, and cannot recover it for you | Glacro Auth Engine |
| Phone number (optional) | SMS one-time codes for verification and account recovery | Glacro Auth, Glacro DB |
| One-time codes | Verification. Stored only as a cryptographic hash and deleted automatically after 10 minutes | Glacro DB |
| IP address | Rate limiting, to block brute-force login and signup abuse. Held in memory only, never written to our database | Application memory (transient) |
| GitHub username and access token | Only if you connect GitHub. To list your repositories and clone the one you choose to deploy | Glacro DB |
| Google account id, name, email | Only if you sign in with Google | Glacro Auth, Glacro DB |
| Project settings | Repository URL, branch, framework, build command, output directory and any environment variables you enter, so we can build and host your site | Glacro DB, passed to Glacro Build Engine |
| Deployment records and build logs | Build status, duration, timestamps and log output, so you can debug failures | Glacro DB, Glacro Object Storage |
| Your built site files | To serve your website to visitors | Glacro Object Storage |
| Custom domain names | To issue TLS certificates and route traffic to your site | Glacro DB, Glacro Global DNS Engine, Glacro Certificate Manager |
| Plan, credit balance, transaction history | To meter usage and enforce plan limits | Glacro DB |
| Payment identifiers and invoices | Amount, currency, gateway and payment reference, for accounting and tax compliance | Glacro DB |
| Support and contact messages | To answer your query | Glacro DB, Glacro Mail Delivery |
| Cookie consent choice | To record what you agreed to | Browser cookie, Glacro DB |
We do not collect your card number, CVV, UPI PIN or bank credentials. Those are entered directly into Razorpay or Stripe and never reach our servers. We run no advertising trackers, we do not sell personal data, and we do not use your data or your source code to train machine-learning models.
3. Your consent
We rely on the consent you give by ticking the box at sign-up, and on the legitimate uses permitted by section 7 of the DPDP Act, such as issuing invoices you have asked for and complying with law.
Your consent covers only the purposes listed in section 2. We will ask again before using your data for any new purpose.
You may withdraw consent at any time, and withdrawing must be as easy as giving it. Do it from Settings, or write to our Grievance Officer. Because we cannot run a hosting account without this data, withdrawal means we delete your personal data and close your account. Withdrawal does not undo processing already carried out lawfully.
4. Who we share it with
We share personal data only with the processors below, only as far as each needs to do its job, and never for their own marketing.
| Recipient | What they receive | Why |
|---|---|---|
| Glacro Global Infrastructure (Mumbai Region) | All account, project and site data | Hosting, authentication, database, storage, email and build infrastructure |
| Razorpay | Name, email, amount | To take payments from customers in India |
| Stripe | Email, amount | To take payments from customers outside India |
| GitHub | Your access token | To read the repositories you ask us to deploy |
| Your Google profile, if you sign in with Google | Authentication | |
| Google reCAPTCHA | IP address and browser signals | To tell real users from automated abuse at sign-up and login |
We may also disclose data where Indian law, a court order or a lawful government request requires it. We will tell you when that happens unless we are legally barred from doing so.
5. Where your data is stored
Your account, project, deployment and billing data is stored in the Glacro Asia-South (Mumbai) glacro-asia-south region, in India.
Some processors named above operate outside India, so limited data crosses borders — the details Stripe needs for an international card, or the request reCAPTCHA inspects. The DPDP Act permits such transfers except to countries the Central Government restricts by notification.
6. How long we keep it
| Data | Retention |
|---|---|
| Account profile | While your account is open, then deleted within 30 days of closure |
| One-time codes | 10 minutes, then deleted automatically |
| IP addresses | In memory for the rate-limit window only; never written to disk |
| Deployment records and build logs | 90 days |
| Site files | Until you delete the project or close your account |
| Invoices and payment records | 8 years, as Indian tax and companies legislation requires. This is a legal obligation and survives both account closure and withdrawal of consent |
| Support correspondence | 3 years |
7. How we protect it
Passwords are managed by Glacro Auth Engine and never reach our systems. Data is encrypted in transit over TLS and at rest by Glacro Cloud. Session tokens live in HttpOnly cookies that JavaScript cannot read. Every read of your account data is keyed to your own authenticated identity, so one customer cannot reach another’s. Payment webhooks are cryptographically signature-verified. One-time codes are stored hashed, are single-use, and expire.
No system is perfectly secure. If a breach affects your personal data we will notify you and the Data Protection Board of India as the DPDP Act requires.
8. Your rights
Under the DPDP Act you may:
- Ask what personal data we hold about you, and who we have shared it with
- Have inaccurate or incomplete data corrected or completed
- Have your data erased, except where law requires us to keep it (see invoices above)
- Withdraw your consent at any time
- Nominate someone to exercise these rights for you on death or incapacity
- Complain to our Grievance Officer, and escalate to the Data Protection Board of India
We respond to any request within 30 days, free of charge.
9. Children
Glacro is not offered to anyone under 18, and we do not knowingly collect a child’s data. If we learn we hold one without verifiable parental consent we will delete it. We carry out no behavioural tracking or targeted advertising directed at children.
10. Cookies
We set only cookies that are strictly necessary to run the service: a session cookie to keep you signed in, a refresh cookie to renew that session, and a cookie recording your consent choice. We use no advertising or cross-site tracking cookies. Blocking the necessary cookies will prevent you from signing in.
11. Grievance Officer
As the DPDP Act and the Information Technology Act, 2000 require, you can reach our Grievance Officer:
Rajan Kumar
glacro.com@gmail.com
147 Thadagam Main Road, Venkatapuram, Velandipalayam, Sri Sai Complex, Coimbatore, Tamil Nadu 641025, India
We acknowledge complaints within 24 hours and resolve them within 15 days. If you remain unsatisfied you may complain to the Data Protection Board of India.
12. Changes
If we change how we use your personal data we will update this page, change the date at the top, and tell you by email before the change takes effect. Where the change requires it, we will ask for fresh consent.