Glymp

Privacy Policy

Last updated — April 2026

This Privacy Policy explains how Glymp ("Glymp", "we", "us", or "our") collects, uses, stores, discloses, and protects your personal information when you access or use our services ("Services").

  • Visiting our website https://glymp.app
  • Downloading and using the Glymp mobile application (User App or Business App)
  • Discovering nearby products, stores, and services
  • Posting content, reviews, or engaging with businesses
  • Earning or redeeming Glymp Coins
  • Engaging with us through marketing, promotions, or customer support

This policy is published in compliance with the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 ("SPDI Rules"), and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 ("IT Rules 2021").

If you do not agree with this Privacy Policy, please do not use our Services. For questions, contact us at support@glymp.app.

Summary of Key Points

  • We collect personal information you provide and some information automatically (device, location, usage).
  • We use your data to personalize discovery, show recommendations, and serve relevant promotions.
  • We do not sell your personal data to third parties.
  • We use cookies and tracking technologies for analytics and performance.
  • We may share data with trusted service providers under contractual obligations.
  • You have rights to access, correct, and delete your data.
  • We implement reasonable security measures compliant with Indian IT law.
  • Users aged 12–17 may use the app with parental consent.

1. Information We Collect

1.1 Personal Information You Provide

When you register, create a profile, or use our Services, we may collect:

  • Full name and display name
  • Email address
  • Phone number
  • Profile photo
  • Date of birth (for age verification)
  • Gender (optional)
  • Delivery or billing address
  • Business details (for business accounts: store name, category, GST number, bank details)
  • Payment information (processed securely via third-party payment gateways)

1.2 User-Generated Content

When you interact with Glymp, we collect:

  • Photos and videos you post
  • Reviews, ratings, and comments
  • Collections you create or follow
  • Likes, saves, and engagement activity
  • Search queries and browsing history within the app

1.3 Device and Technical Information

We automatically collect:

  • Device type, model, operating system, and version
  • Unique device identifiers (device ID, advertising ID)
  • IP address
  • Browser type and version (for web access)
  • App version and build number
  • Network information (Wi-Fi, cellular)
  • Crash logs and diagnostic data

1.4 Location Data

As a hyperlocal discovery platform, location is central to our Services:

  • Precise location (GPS) — with your explicit permission, used to show nearby stores, products, and services
  • Approximate location — derived from IP address or network data
  • Saved locations — locations you manually save or set as preferred areas

You can disable location access through your device settings at any time. Disabling location may limit the accuracy of discovery features.

1.5 Behavioral and Usage Data

We collect data about how you interact with the platform:

  • Pages and screens viewed
  • Time spent on content
  • Tap and scroll patterns
  • Feature usage frequency
  • Referral sources (how you found us)
  • Glymp Coins earned, redeemed, and balance

1.6 Sensitive Personal Data

We do not intentionally collect sensitive personal data as defined under the SPDI Rules (e.g., passwords, financial information stored on our servers, health data, biometric data, sexual orientation, political opinions, or religious beliefs). Payment information is processed directly by PCI-DSS compliant payment gateways, and we do not store card details on our servers.

2. How We Use Your Information

2.1 Core Service Delivery

  • Create and manage your account
  • Enable hyperlocal discovery of stores, products, and services
  • Process and display your content (posts, reviews, photos, videos)
  • Facilitate follows, likes, and social interactions
  • Manage Glymp Coins rewards program

2.2 Personalization and Recommendations

  • Show relevant stores and products based on your location and interests
  • Personalize your feed and discovery experience
  • Recommend collections and businesses you may like
  • Tailor search results and suggestions

2.3 Advertising and Promotions

  • Serve relevant promoted listings from businesses
  • Measure advertising effectiveness
  • Enable businesses to reach potential customers in their vicinity

2.4 Communication

  • Send push notifications (offers, updates, activity alerts)
  • Respond to your inquiries and support requests
  • Send transactional emails (account verification, password reset)
  • Marketing communications (with your consent; opt-out available)

2.5 Safety and Security

  • Detect and prevent fraud, spam, and abuse
  • Enforce our Terms and Conditions and Community Guidelines
  • Monitor for security threats
  • Comply with legal obligations

2.6 Analytics and Improvement

  • Understand usage trends and patterns
  • Improve app performance and features
  • Conduct research and development
  • Debug technical issues

3. Cookies and Tracking Technologies

We use the following technologies:

TechnologyPurpose
Essential CookiesAuthentication, session management, security
Analytics CookiesUsage tracking, performance monitoring (e.g., Cloudflare Analytics)
Functional CookiesRemembering preferences, location settings, language
Advertising IdentifiersServing relevant promoted content (mobile SDKs)
Local StorageCaching user preferences and location data on-device

You can manage cookie preferences through your browser settings. Disabling cookies may affect certain functionalities. On mobile, you can reset your advertising identifier or opt out of personalized ads through your device's privacy settings.

4. Third-Party Integrations and Data Sharing

We share data with the following categories of service providers, bound by contractual data protection obligations:

  • Cloud Infrastructure — Hosting, storage, and content delivery (e.g., AWS, Google Cloud, Cloudflare)
  • Analytics Providers — Usage analysis and crash reporting (e.g., Firebase Analytics, Cloudflare Web Analytics)
  • Payment Gateways — Secure payment processing (e.g., Razorpay)
  • Push Notification Services — Delivering notifications (e.g., Firebase Cloud Messaging)
  • Media Processing — Image and video optimization (e.g., ImageKit)
  • AI/ML Services — Powering search, recommendations, and content understanding
  • Communication Tools — Email delivery and customer support

We may also share information:

  • With law enforcement or government authorities when required by law or legal process
  • During business transfers, mergers, or acquisitions
  • With business partners for joint promotions (with your consent)
  • With other users when you post content publicly
  • To protect the rights, safety, and property of Glymp and its users

5. Data Retention

We retain your personal data only as long as necessary for the purposes outlined in this policy:

  • Active account data — Retained for the duration of your account being active
  • Post-deletion — Core account data is deleted within 90 days of account deletion request. Some data may be retained in anonymized form for analytics.
  • Legal holds — Data may be retained longer if required for legal compliance, dispute resolution, or fraud prevention
  • Backups — Encrypted backups are purged on a rolling 30-day cycle
  • User-generated content — Publicly posted content (reviews, photos) is removed upon account deletion unless it has been reposted or referenced by others

Glymp Coins balances expire and are forfeited upon account termination.

6. Your Privacy Rights

Under the Indian IT Act, SPDI Rules, and in alignment with global best practices, you have the following rights:

  • Right to Access — Request a copy of the personal data we hold about you
  • Right to Correction — Update or correct inaccurate personal information
  • Right to Deletion — Request deletion of your account and associated data
  • Right to Withdraw Consent — Withdraw previously given consent for data processing
  • Right to Data Portability — Request your data in a structured, commonly used format
  • Right to Object — Object to processing for direct marketing purposes
  • Right to Grievance Redressal — File a complaint with our Grievance Officer

To exercise your rights, use the in-app account settings or email us at support@glymp.app with subject line "Data Rights Request". We will verify your identity and respond within 30 days.

7. Children and Minors

Glymp is rated 12+ on app stores.

  • Children under 12: We do not knowingly collect personal information from children under the age of 12. If we become aware that a child under 12 has provided us with personal data, we will take steps to delete it promptly.
  • Users aged 12–17: Minors between 12 and 17 may use Glymp with the consent and supervision of a parent or legal guardian. Parents/guardians assume responsibility for the minor's activity on the platform.
  • Content filtering: We implement age-appropriate content moderation. Content flagged as mature, violent, or inappropriate is restricted from users under 18.
  • No targeted advertising to minors: We do not serve behaviorally targeted advertisements to users identified as under 18.
  • Limited data processing: For minor users, we limit data collection to what is essential for the service and do not process their data for profiling or marketing purposes.

If you are a parent or guardian and believe your child has provided personal information to us without your consent, please contact us at support@glymp.app.

8. Security Practices

We implement reasonable security practices and procedures as required under the SPDI Rules, including:

  • Encryption of data in transit (TLS/SSL) and at rest (AES-256)
  • Secure authentication mechanisms (token-based, OTP verification)
  • Role-based access controls for internal systems
  • Regular security assessments and vulnerability testing
  • Firewalls, intrusion detection, and DDoS protection
  • Secure cloud infrastructure with SOC 2 compliant providers
  • Employee training on data protection and privacy

While we strive to protect your personal information, no method of transmission or electronic storage is 100% secure. We cannot guarantee absolute security and encourage users to also take precautions (e.g., strong passwords, not sharing credentials).

9. Cross-Border Data Transfer

Your data is primarily stored on servers located in India. However, some of our service providers may process data in other jurisdictions (e.g., United States, European Union). In such cases:

  • We ensure adequate data protection through contractual safeguards
  • Service providers are bound by data processing agreements
  • We comply with applicable Indian laws regarding data transfer
  • Your data receives substantially similar protection regardless of where it is processed

10. Artificial Intelligence Features

Glymp uses AI-powered features to enhance your experience:

  • AI-powered search and discovery
  • Content recommendations and personalization
  • Image recognition and content categorization
  • Automated content moderation

Personal data processed through AI features is handled in accordance with this Privacy Policy. AI decisions are not used as the sole basis for actions with legal or significant effects on you.

11. Do-Not-Track Signals

We do not currently respond to Do-Not-Track (DNT) browser signals due to the absence of a uniform industry standard. We will update this policy if a standard is adopted.

12. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.

  • Material changes will be communicated via in-app notification or email
  • The "Last updated" date at the top will be revised
  • Continued use of the Services after changes constitutes acceptance
  • We encourage you to periodically review this policy

13. Grievance Officer

In accordance with the Information Technology Act, 2000 and the IT Rules 2021, the details of our Grievance Officer are:

Name: Khushal Paliwal

Designation: Director

Email: khushal@glymp.app

Address: Powai, Mumbai, Maharashtra, India

Complaints will be acknowledged within 24 hours and resolved within 15 days.

14. Contact Information

Glymp

Powai, Mumbai, Maharashtra, India

General Support: support@glymp.app

Privacy Inquiries: support@glymp.app

Grievance Officer: khushal@glymp.app