Privacy Policy
- Last updated
- 11 August 2026
- Effective from
- 11 August 2026
1.Introduction
Estrellingent Technology Private Limited (“Estrellingent”, “Company”, “we”, “us”, “our”), a company incorporated under the Companies Act, 2013, having CIN U74909WB2023PTC265098 and its registered office at A-60 Brahmapur South, Kolkata, West Bengal 700096, India, provides:
- (a) Business Intelligence Services — financial analytics, reconciliation, inventory optimisation, buffer management and decision-support software that integrates with accounting and enterprise systems including Tally; and
- (b) Advertising Technology Services — campaign analytics, audience and targeting optimisation, bid and budget management, creative generation and performance reporting, integrating with advertising platforms including Google Ads, Meta, Amazon Ads, LinkedIn, TikTok, Snap, Pinterest and similar platforms;
together with our website, applications, APIs, connectors and documentation (collectively, the “Services”).
This Privacy Policy explains how we collect, use, store, disclose, transfer and protect information in connection with the Services.
This Policy is published in accordance with the Digital Personal Data Protection Act, 2023 (“DPDP Act”), the Information Technology Act, 2000 and rules made thereunder, and, where applicable, the EU/UK General Data Protection Regulation (“GDPR”), the Australian Privacy Act 1988, and applicable United States state privacy laws.
By accessing our website or using the Services, you acknowledge that you have read and understood this Policy.
2.Our Role: Controller and Processor
Our role differs depending on the data involved. This distinction is central to how we handle information.
2.1 Where we act as a Data Fiduciary / Controller
We determine the purposes and means of processing for:
- Information you provide when creating an account, subscribing or contacting us
- Billing and payment records
- Website usage and product analytics data
- Marketing and communication preferences
- Support correspondence
2.2 Where we act as a Data Processor
We process on your documented instructions, and you remain the Data Fiduciary / Controller for:
- Business Data — all data synchronised from your Tally installation or other accounting, ERP or inventory systems, including ledgers, vouchers, stock records, purchase and sales registers, tax filings, and customer, vendor and employee master records
- Advertising Data — all data accessed through your advertising accounts, including campaign structures, spend, performance metrics, audience and segment definitions, conversion and pixel data, customer lists you upload to platforms, and creative assets
(together, “Customer Data”)
We do not determine the purpose of Customer Data. We process it solely to deliver the Services you have subscribed to.
You are responsible for ensuring you have a lawful basis to share Customer Data with us, including any notice, consent or opt-out required from your own customers, vendors, employees and website or app users.
3.Information We Collect
3.1 Information you provide directly
- Name, designation, business email address, telephone number
- Company name, GSTIN, PAN, registered address, business type and sector
- Login credentials (passwords stored only in salted, hashed form)
- Billing details, GST registration details and transaction records
- Content of support tickets, emails and communications with us
3.2 Business Data ingested from accounting and enterprise systems
Where you authorise a connection to Tally or a comparable system, we may ingest:
- Ledger masters, groups and cost centres
- Sales, purchase, payment, receipt, journal, contra, debit note and credit note vouchers
- Bill-wise details, outstanding receivables and payables
- Stock items, batches, godowns, movements and valuations
- Purchase orders, sales orders and delivery notes
- GST return and reconciliation data
- Bank ledger balances and reconciliation entries
- Payroll cost heads present in accounting data
3.3 Advertising Data ingested from advertising platforms
Where you authorise a connection to an advertising account, we may access:
- Account, campaign, ad set and ad structures and settings
- Spend, impressions, clicks, conversions, revenue and attribution data
- Bid strategies, budgets, schedules and placement settings
- Audience definitions, segments, lookalike and remarketing lists
- Creative assets, ad copy, landing page URLs and associated metadata
- Conversion tracking, pixel and server-side event data
- Product feeds and catalogue data
Important: Advertising platforms generally provide aggregated and pseudonymised data. Where any customer list, hashed identifier, conversion event or pixel data you have uploaded or configured contains or derives from personal data, you remain the controller of that data and are responsible for the lawful basis, notices and consents supporting it.
3.4 Information collected automatically
- IP address, device identifiers, browser type and version, operating system
- Pages accessed, features used, session duration, timestamps
- Log data, error reports, crash diagnostics and performance metrics
- Cookies and similar technologies (see Section 12)
3.5 Information from third parties
- Payment status from payment gateways
- Authentication data from identity providers where you use single sign-on
- Data from integrated third-party systems you authorise
3.6 Information we do not collect
We do not knowingly collect data from children or knowingly permit the Services to be used to target advertising to children. We do not collect biometric data, health data, or data relating to sexual orientation, political affiliation or religious belief. We do not store full payment card numbers, CVV codes or banking passwords — payment processing is handled by PCI-DSS compliant gateways.
4.Purposes of Processing
| Purpose | Categories used |
|---|---|
| Creating and administering your account | Account and contact data |
| Delivering Business Intelligence Services — analytics, reconciliation, alerts, buffer status, recommendations | Business Data |
| Delivering Advertising Technology Services — targeting, bid and budget optimisation, creative generation, reporting | Advertising Data |
| Maintaining the audit and activity log of changes made and value identified | Customer Data, usage data |
| Providing technical support and resolving issues | Account data, logs, Customer Data on request |
| Billing, invoicing, tax compliance and collections | Account and billing data |
| Improving reliability, performance and accuracy of the Services | Usage data, aggregated and de-identified data |
| Security monitoring, fraud prevention and abuse detection | Log and usage data |
| Communicating service updates, outages and changes | Contact data |
| Marketing communications, where permitted | Contact data, subject to opt-out |
| Complying with legal, regulatory and statutory obligations | As required by law |
4.1 Legal bases (where GDPR or comparable law applies)
- Performance of a contract — providing the Services you have subscribed to
- Legitimate interests — security, service improvement, fraud prevention, direct marketing to business contacts
- Legal obligation — tax, accounting and statutory retention requirements
- Consent — non-essential cookies, and marketing where consent is required
Where processing relies on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
5.Use of Data for Model Training and Benchmarking
We state our position explicitly because we consider it material.
5.1 We do not use identifiable Customer Data to train models deployed for any customer other than you. Your financial data, campaign performance, audience definitions and creative assets are not used to improve outcomes for your competitors.
5.2 We may use aggregated, anonymised and de-identified data derived from the Services to develop industry benchmarks, improve algorithms and publish research. Such data is stripped of company names, account identifiers, GSTINs, PANs, contact details and individual transaction or campaign identifiers, and is aggregated across a minimum of twenty-five (25) distinct customers before use.
5.3 You may opt out of inclusion in aggregated benchmarking by written notice to Hello@growthrush.ai, without affecting your access to the Services.
5.4 We do not sell Customer Data. We do not share Customer Data with advertisers, data brokers, or your competitors.
5.5 Generative features. Where the Services generate advertising creative, copy or recommendations using machine learning models, prompts and inputs derived from your Customer Data are not used to train third-party foundation models except where a sub-processor is contractually bound not to train on customer inputs. Current generative sub-processors are listed at growthrush.ai/legal/subprocessors.
6.Advertising Platform Data and Platform Terms
6.1 Access to advertising platform data is governed by the terms of the relevant platform in addition to this Policy — including the Google Ads API Terms, Meta Platform Terms, and equivalent terms of other platforms.
6.2 We handle platform data in accordance with those terms, which may impose restrictions on retention, aggregation, onward transfer and use that are stricter than those in this Policy. Where a platform’s terms conflict with this Policy in relation to that platform’s data, the platform’s terms prevail.
6.3 You are responsible for compliance with platform policies applicable to you as an advertiser, including policies on prohibited content, sensitive categories, customer list uploads, consent for tracking, and restricted targeting.
6.4 We do not create, sell or license audience segments derived from one customer’s data for use by another customer.
7.Disclosure of Information
7.1 Sub-processors and service providers — cloud hosting, database, monitoring, email delivery, payment processing, machine learning inference and customer support providers, each bound by written agreements imposing confidentiality and security obligations no less protective than this Policy. A current list is available at growthrush.ai/legal/subprocessors or on written request.
7.2 Advertising platforms — where you instruct us to apply changes to your advertising accounts, relevant data is transmitted to the applicable platform under your account credentials and subject to that platform’s own privacy terms.
7.3 Professional advisers — auditors, lawyers and accountants under duties of confidentiality.
7.4 Legal and regulatory disclosure — where required by applicable law, court order, or a lawful government or regulatory request. Where legally permitted, we will notify you before disclosing Customer Data so that you may seek protective relief.
7.5 Corporate transactions — in connection with a merger, acquisition, financing, reorganisation or sale of assets, subject to the recipient being bound by terms consistent with this Policy. You will be notified of any change in the controlling entity.
7.6 With your instruction — where you direct us to share data with a third party, including your own advisers, agencies or integration partners.
We do not otherwise disclose Customer Data to third parties.
8.Cross-Border Transfers
Our infrastructure may be hosted in India and in other jurisdictions including India and the United States. Where we transfer personal data outside the country of collection, we do so subject to appropriate safeguards, which may include Standard Contractual Clauses, adequacy determinations, or equivalent contractual protections.
Transfers from India are made in accordance with Section 16 of the DPDP Act and any restrictions notified by the Central Government.
Advertising platforms are themselves global and will process data in their own jurisdictions under their own terms.
Customers may request that Customer Data be hosted exclusively within a specified region, subject to availability and commercial terms.
9.Data Retention
| Data category | Retention period |
|---|---|
| Account and contact data | Duration of the relationship, plus 3 years |
| Business Data | Duration of the subscription, plus 30 days for retrieval, then deleted |
| Advertising Data | Duration of the subscription, plus 30 days, subject to shorter periods required by platform terms |
| Generated creative assets | Duration of the subscription, plus 30 days |
| Billing, invoicing and tax records | 8 years, as required under Indian tax and companies law |
| Security and access logs | 12 months |
| Change and audit logs for actions taken in your accounts | 24 months |
| Support correspondence | 3 years |
| Aggregated anonymised data | Retained indefinitely; not personal data |
| Backups | Purged on the rolling backup cycle, not exceeding 90 days |
On termination, Customer Data is available for export for 30 days, after which it is deleted from active systems within 30 days and from backups within 90 days. Deletion certificates are available on request.
We may retain data beyond these periods where required to comply with a legal obligation, resolve a dispute, or enforce our agreements.
10.Security
We maintain reasonable security practices and procedures as required under the IT Act and the DPDP Act, including:
- Encryption in transit (TLS 1.2 or above) and at rest (AES-256 or equivalent)
- Role-based access control and least privilege
- Multi-factor authentication for administrative access
- Logical segregation of each customer’s data
- Encrypted storage of OAuth tokens and platform credentials, with scope limited to what each feature requires
- Audit logging of all access to Customer Data and of all changes made to connected accounts
- Periodic vulnerability assessment and penetration testing
- Background verification of personnel with access to production systems
- Documented incident response and business continuity procedures
- Contractual confidentiality obligations binding all employees and contractors
10.1 Accounting connector. Where the Services connect to an on-premise Tally installation, the connection operates on a read-only basis. We do not write to, alter or delete data in your accounting system.
10.2 Advertising connector. Advertising platform connections may operate on a read-and-write basis where you enable optimisation features. Changes are logged, attributable and reversible where the platform supports rollback. You control the scope of authorisation and may revoke it at any time through the platform’s own permission settings.
10.3 You are responsible for the security of your own network, servers, accounting installation, advertising accounts and the credentials used to authorise any connection.
10.4 Breach notification. In the event of a personal data breach we will notify the Data Protection Board of India and affected Data Principals in the manner and within the timelines prescribed under the DPDP Act, and will notify affected customers without undue delay.
10.5 No system is entirely secure. We do not warrant absolute security, and you acknowledge the inherent risks of transmitting data over the internet.
11.Your Rights
Subject to applicable law and verification of identity, you have the right to:
- Access — confirmation of processing and a summary of personal data processed
- Correction — correction of inaccurate or incomplete data
- Erasure — deletion where data is no longer necessary and no legal obligation requires retention
- Portability — receipt of your data in a structured, commonly used, machine-readable format
- Withdraw consent — where processing is based on consent
- Object or restrict — where processing is based on legitimate interests
- Grievance redressal — complaint to us and, if unresolved, to the Data Protection Board of India
- Nominate — nomination of an individual to exercise your rights in the event of death or incapacity, as provided under the DPDP Act
11.1 Requests concerning Customer Data. Where a request relates to personal data within Customer Data, we act as a Processor. Please direct such requests to the customer organisation that holds the relationship with you. If a request reaches us directly, we will forward it to the relevant customer and assist them in responding, but will not act on it independently.
11.2 Advertising opt-outs. If you are an individual seeking to opt out of advertising served by one of our customers, the opt-out is exercised through the relevant advertising platform’s own controls or through the advertiser directly. We do not serve advertisements and cannot suppress delivery on any platform.
To exercise any right, contact Hello@growthrush.ai. We will respond within the timelines prescribed by applicable law, and in any event within 30 days.
13.Third-Party Links and Integrations
The Services may link to or integrate with third-party systems, including accounting platforms, advertising platforms, banks, government portals and payment gateways. We are not responsible for the privacy practices of those third parties. Their handling of data is governed by their own policies, which you should review.
Our integrations do not imply endorsement by, or affiliation with, Tally Solutions Private Limited, Google LLC, Meta Platforms, Inc. or any other platform provider.
14.Changes to this Policy
We may update this Policy from time to time. Material changes will be notified by email to registered account holders and by prominent notice on the Services at least 15 days before taking effect. Continued use after the effective date constitutes acceptance.
Version history is available at growthrush.ai/legal/versions.
15.Grievance Officer
In accordance with the Information Technology Act, 2000 and the DPDP Act, 2023:
Grievance Officer
Name: [INSERT NAME]
Designation: [INSERT DESIGNATION]
Estrellingent Technology Private Limited
A-60 Brahmapur South, Kolkata, West Bengal 700096, India
Email: Hello@growthrush.ai
Telephone: [INSERT NUMBER]
Hours: 10:00 to 18:00 IST, Monday to Friday, excluding public holidays
Grievances will be acknowledged within 24 hours and resolved within 15 days of receipt.
Data Protection Officer (where appointed)
Name: [INSERT NAME]
Email: Hello@growthrush.ai
16.Contact
Estrellingent Technology Private Limited
A-60 Brahmapur South, Kolkata, West Bengal 700096, India
CIN: U74909WB2023PTC265098
Email: Hello@growthrush.ai
Website: growthrush.ai
This document is a template prepared for Estrellingent Technology Private Limited and requires review and adaptation by qualified legal counsel before publication. It does not constitute legal advice.
