Contents
1. Overview 2. What We Collect 3. How We Use It 4. Legal Basis 5. Data Sharing 6. Data Retention 7. Security 8. Your Rights 9. Cookies 10. Children 11. Third-Party Services 12. Changes 13. Contact & Grievances
Legal Document

Privacy Policy

๐Ÿ“… Effective: 26 May 2026 ๐Ÿ”„ Updated: 26 May 2026 โš–๏ธ DPDP Act 2023 compliant
Our commitment in plain language: We collect only what we need to run your account. We never sell your data. We never share it with advertisers. You can delete your account and all your data at any time. We comply with India's Digital Personal Data Protection Act, 2023.

1. Overview

This Privacy Policy explains how GSTMind ("we," "us," "our") collects, uses, stores, and protects your personal data when you use GSTMind Docs at docs.gstmind.in (the "Platform").

This policy is drafted in compliance with the Digital Personal Data Protection Act, 2023 (DPDP Act) and rules notified thereunder, as well as the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.

By creating an account, you provide your free, specific, informed, and unambiguous consent to the processing of your personal data as described in this Policy.

2. What We Collect

2.1 Information you provide

DataWhy collectedRequired?
NameTo personalise your experience and communicationsYes
Email addressAccount verification (OTP), login, service communicationsYes
Mobile numberAccount security, future SMS OTP verificationYes
ProfessionTo understand our user base and improve the serviceNo (optional)

2.2 Information collected automatically

DataWhy collected
IP addressSecurity, fraud prevention, rate limiting
Browser & device infoSession management, debugging
Document view historyRecently viewed feature, analytics
Session tokensTo keep you logged in securely
Login timestampsAccount security monitoring

2.3 What we do NOT collect

  • We do not collect payment card details (handled by payment processor when billing is enabled)
  • We do not collect government identity numbers (Aadhaar, PAN, etc.)
  • We do not track your activity outside our Platform
  • We do not use advertising trackers or third-party analytics pixels

3. How We Use Your Data

  • Account creation and management โ€” To set up, maintain, and secure your account
  • Authentication โ€” To send OTP codes for login and verification
  • Service delivery โ€” To provide access to documents and personalised features (recently viewed, etc.)
  • Communications โ€” To send service emails including trial expiry notices, new document alerts (if opted in), and important policy updates
  • Security โ€” To detect and prevent fraud, abuse, and unauthorised access
  • Analytics โ€” To understand how the Platform is used and improve it (aggregated, non-identifiable where possible)
  • Legal compliance โ€” To comply with applicable laws, court orders, or regulatory requirements

We do not use your data for automated decision-making or profiling that produces legal or similarly significant effects.

5. Data Sharing & Disclosure

We do not sell your personal data. Ever. We do not share your data with advertisers, data brokers, or marketing companies.

5.1 Service providers

We share limited data with the following service providers solely for operating the Platform:

ProviderPurposeData sharedLocation
Database providerSecure database hostingAccount dataCloud infrastructure, Asia-Pacific region
Email delivery providerSending OTP codes and notificationsEmail address, email contentCloud infrastructure
Application hosting providerRunning the PlatformServer logs, IP addressesCloud infrastructure
Document storageStoring and serving documentsDocuments only (no personal data)Cloud infrastructure

All service providers are contractually bound to process your data only for the specified purpose and to maintain appropriate security measures.

5.2 Legal disclosure

We may disclose your personal data where required by:

  • A court order, subpoena, or other legal process
  • A lawful request from a government or regulatory authority
  • To protect the rights, property, or safety of GSTMind, our users, or the public

We will notify you of such requests where permitted by law.

5.3 Business transfers

In the event of a merger, acquisition, or sale of assets, your data may be transferred to the acquiring entity, subject to the same privacy protections. You will be notified of any such transfer.

6. Data Retention

Data typeRetention period
Account data (name, email, mobile)Until account deletion, then purged from backups within a reasonable period
Session tokensUntil logout or natural expiry
OTP verification recordsDeleted promptly after use or expiry
Document view historyUntil account deletion
Server logs (IP, browser)90 days
Billing records (when applicable)7 years (as required by Indian accounting law)

Upon account deletion, we will delete or anonymise your personal data within 30 days, except where retention is required by law.

7. Security

We implement reasonable technical and organisational security measures to protect your personal data, including:

  • Encryption in transit โ€” All data transmitted between your browser and our servers is encrypted using industry-standard protocols
  • Encryption at rest โ€” Database data is encrypted at rest by our hosting infrastructure
  • Passwordless authentication โ€” We do not store passwords; login is via one-time codes only
  • Secure session management โ€” Session cookies are HTTP-only and inaccessible to client-side scripts
  • Abuse prevention โ€” Authentication endpoints are protected against automated abuse
  • Access controls โ€” Database access is restricted to our application backend only and is not publicly accessible
  • Administrative security โ€” Administrative functions require multi-factor authentication
No system is completely secure. While we take extensive precautions, we cannot guarantee absolute security. Please report any suspected security vulnerabilities to support@gstmind.in.

8. Your Rights Under the DPDP Act 2023

๐Ÿ“‹ Right to Access

Request a summary of the personal data we hold about you and how it is being used.

โœ๏ธ Right to Correction

Request correction of inaccurate or incomplete personal data. Update your profile directly from your account settings.

๐Ÿ—‘๏ธ Right to Erasure

Delete your account and all associated personal data at any time via your profile page โ†’ "Delete Account."

๐Ÿšซ Right to Withdraw Consent

Withdraw consent for optional processing (e.g., email alerts) at any time from your profile settings.

๐Ÿ“ฃ Right to Grievance Redressal

Raise a complaint with our Grievance Officer. We will respond within 72 hours on business days.

๐Ÿ›๏ธ Right to Data Protection Board

If unsatisfied with our response, you may approach the Data Protection Board of India once constituted under the DPDP Act.

To exercise any of these rights, email us at support@gstmind.in with the subject line "Privacy Request." We will respond within 30 days.

9. Cookies & Similar Technologies

We use cookies and similar technologies solely for operational purposes:

Cookie typePurposeDuration
User session cookieKeeps you securely logged in (HTTP-only, not accessible by JavaScript)Up to 30 days

We do not use advertising cookies, tracking pixels, or third-party analytics cookies. We do not participate in cross-site tracking of any kind.

You may disable cookies in your browser settings, but this will prevent you from logging in to the Platform.

10. Children's Privacy

The Platform is not directed at children under the age of 18. We do not knowingly collect personal data from children. If we become aware that a child under 18 has provided personal data, we will delete that information promptly. If you believe a child has registered on the Platform, please contact us at support@gstmind.in.

11. Third-Party Services

The Platform may contain links to third-party websites such as CBIC (cbic.gov.in) and ICAI (icai.org). When you leave our Platform, this Privacy Policy no longer applies. We encourage you to read the privacy policies of any third-party sites you visit.

We are not responsible for the privacy practices of third-party websites.

12. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or applicable law. When we make material changes, we will:

  • Update the "Last updated" date at the top of this page
  • Send an email notification to registered users
  • Where required by law, seek fresh consent for any new or changed processing activities

13. Contact & Grievance Officer

Under the DPDP Act 2023 and IT Rules 2011, we have designated a Grievance Officer to address your privacy concerns:

Grievance Officer โ€” GSTMind

Email: support@gstmind.in
Subject line: "Privacy Grievance" or "DPDP Request"
Response time: Within 72 hours (business days) for acknowledgement; resolution within 30 days

Platform: docs.gstmind.in
Company: GSTMind, India

If you are not satisfied with our resolution, you may approach the Data Protection Board of India once it is constituted under the DPDP Act 2023.