Privacy policy

What we collect, why we collect it, who it reaches and how long we keep it.

Last updated: 2 September 2026

Who this covers

This policy applies to GRAV CLOTHING PVT LTD and to the websites and applications we operate, including this site and the management system it signs you in to. We are the data controller for the information described here.

What we collect

We collect three kinds of information, for three different reasons.

  • Business contact and order information — the name, organisation, address, phone number, email address, GSTIN and billing details of the people and businesses we trade with, together with the orders, invoices and payments between us.
  • Employee and workforce information — for people we employ: identity and contact details, statutory identifiers such as PAN, Aadhaar, UAN and ESI numbers, bank details for salary payment, attendance records, leave, and pay.
  • Face data, only where an employee has agreed — photographs of the face and the patterns derived from them, used to record attendance and confirm a sign-in. Voluntary, separately consented, and deletable on request; see the section below.
  • Technical information — sign-in records, the pages and records an account opens or changes, device tokens used to send notifications, and ordinary server logs.

We do not collect information from children, and our services are not directed at them.

Face data, and how you can refuse it

We operate an optional face-recognition system for attendance and for confirming who is signing in. Where an employee takes part, we hold photographs of their face and the mathematical patterns derived from them. Under India's Digital Personal Data Protection Act this is biometric personal data, and we treat it as the most sensitive information we hold.

It is voluntary. Taking part is a choice, not a condition of employment. Attendance can be recorded by the other methods we already use, and nobody is penalised for declining.

  • Consent is asked for separately from every other permission, in plain terms, before a single photograph is taken.
  • You can withdraw at any time, from the settings in the employee app or by asking HR. Withdrawing is as easy as consenting: one switch.
  • Withdrawal deletes the data. Your photographs and the patterns derived from them are erased, not merely deactivated.
  • It is used for nothing else. Not for monitoring productivity, not for tracking movement around the premises, not for emotion or demographic inference, and it is never sold, shared or given to any third party.
  • Matching happens on our own systems. The recognition service runs on our infrastructure; face images are not sent to an outside face-recognition provider.
  • It is deleted when you leave. Face data is erased when employment ends — it is not kept with the employment records that tax law obliges us to retain.

To withdraw consent or ask what face data we hold about you, use the employee app's settings or contact us using the details at the end of this policy.

Payment information

Card numbers, UPI credentials, net-banking passwords and similar payment credentials are never collected or stored by us. Payments are taken by a regulated payment gateway, and those details are entered on the gateway's own page and handled by them. We receive only the outcome of a payment — whether it succeeded, when, for how much, and a reference we can match to an invoice.

Why we use it

  • To quote for, produce, invoice and deliver orders.
  • To take and reconcile payments, and to meet tax and GST obligations.
  • To employ people, pay them, and meet statutory obligations such as provident fund and employees' state insurance.
  • To keep the record of who changed what, so that a disputed figure can be traced to a person and a time.
  • To secure our systems and investigate misuse.

We do not sell personal information, and we do not use it for advertising or profiling.

How it is protected

Access is controlled by account and by role: a person sees the department they work in and the records their role permits. Changes to significant records are recorded in an audit log naming the account that made them.

Pay information is encrypted at rest: salary figures are stored encrypted rather than in plain text, and are decrypted only when a permitted account reads them. Passwords are stored as one-way hashes and cannot be read back by us or by anyone else. Traffic between your browser and our servers travels over HTTPS.

Who else it reaches

We use a small number of service providers to run the system. They process information on our instructions and for no purpose of their own:

  • Cloud hosting and databases — to run the application and store its data.
  • Google Firebase and Google Cloud — sign-in, the workspace and messaging features, file storage, and push notifications.
  • Cloudinary — storage and delivery of uploaded images and documents.
  • Brevo — sending transactional email, such as an account invitation.
  • LiveKit — audio and video for internal meetings.
  • A regulated payment gateway — taking and settling payments.

We also disclose information where the law requires it, to our professional advisers, and to a buyer if the business is sold — in which case this policy continues to apply to the information transferred.

Where it is kept

Our data is hosted on infrastructure that may be located outside India. Where information is transferred out of India we take contractual steps with our providers to keep it protected to the standard described here.

How long we keep it

Business and financial records are kept for as long as tax, company and GST law requires — generally at least eight years from the end of the relevant financial year. Employment records are kept for the duration of employment and for as long afterwards as statutory obligations require. Audit and change records are kept for the life of the record they describe. Technical logs are kept for a shorter period and then discarded.

Face data is the exception to all of the above. It is kept only while an employee is taking part and only while they are employed. It is deleted when consent is withdrawn or when employment ends, whichever comes first, and it is not retained alongside the financial records that tax law requires us to keep.

Your rights

You may ask us for a copy of the personal information we hold about you, ask us to correct it if it is wrong, ask us to delete it where we are not required to keep it, and object to a particular use. Write to us at the address below and we will respond within 30 days.

If you are an employee, most of your own record is visible to you in the system, and corrections can be requested through your HR department.

Cookies

We use cookies and similar browser storage only to keep you signed in and to remember interface preferences such as your theme. We do not use advertising or third-party tracking cookies. Blocking the sign-in cookie will prevent you from signing in.

Changes

We update this policy when what we do changes. The date at the top is the date of the current version, and material changes will be notified to account holders.

Contact

Questions about this policy, or a request about your information, should go to GRAV CLOTHING PVT LTD, 8B, Mayfair Lagoon Campus, Jaydev Vihar, Bhubaneswar, Odisha, 751013, India, or by phone on +91 93302 88560.