Privacy Policy
Effective Date: July 22, 2026 | Last Updated: July 2026
Compliant with the Digital Personal Data Protection Act, 2023 (DPDP Act) | Merchant: Rahul Singh
1. Introduction & Overview
At Corporate Gupshup (operated by Rahul Singh, "we", "us", or "our"), accessible via https://corporategupsup.online, protecting your privacy and maintaining absolute confidentiality of your professional identity is our highest priority.
This Privacy Policy explains how we collect, process, store, disclose, and safeguard your personal data in accordance with the Digital Personal Data Protection Act, 2023 ("DPDP Act") of India and other applicable data protection regulations. By registering for or using our Platform, you consent to the data practices described in this policy.
Your real corporate email domain (e.g., @companydomain.com) is used EXCLUSIVELY server-side to verify your corporate employee eligibility and to generate a randomized, deterministic company codename (e.g., "Chai Warriors"). YOUR REAL EMAIL ADDRESS AND COMPANY DOMAIN ARE NEVER DISPLAYED PUBLICLY ON THE PLATFORM TO OTHER USERS OR THIRD PARTIES.
2. Personal Data We Collect
We collect only the minimum necessary personal data ("Data") required to provide a secure and functional community platform:
- Identity & Account Data: Official corporate email address, email domain, account password (stored strictly as an encrypted bcrypt hash), and user-selected display name (optional).
- Profile & Demographic Data: Avatar image choice/upload URL, job role designation (optional), country code / language preference, and assigned company codename.
- User Content Data: Posts, topics, poll votes, comments, likes, friend connection graphs, direct messages, salary submissions, and referral board entries.
- Financial & Transaction Data: Subscription tier, transaction timestamp, payment amount, and Razorpay order/payment ID. Note: We do NOT store credit card numbers, debit card PINs, UPI IDs, CVVs, or banking passwords on our servers. All financial instrumentation is handled directly by Razorpay under PCI-DSS standards.
- Technical & Usage Data: IP address, device type, browser category, login timestamps, and session tokens for security auditing and authentication.
3. Purpose of Processing & Legal Basis under DPDP Act 2023
Under Section 4 and Section 6 of the DPDP Act 2023, we process your personal data for lawful, specified purposes based on your explicit consent provided during signup:
- Eligibility Verification: Validating that you are an active corporate employee eligible to access members-only lounges.
- Codename Generation: Generating deterministic, non-identifying company codenames.
- Service Provision: Enabling messaging, feed loading, salary analytics, and referral interactions.
- Transactional Communications: Sending essential One-Time Passwords (OTPs), password reset links, and billing receipts.
- Security & Abuse Prevention: Detecting fraudulent account registrations, spam, or malicious attacks.
4. Third-Party Data Processors & Integrations
We do not sell, rent, or trade your personal data. We share relevant data only with vetted third-party data processors who perform specific technical functions under strict data protection agreements:
| Data Processor | Purpose of Processing | Data Handled |
|---|---|---|
| Razorpay Software Pvt. Ltd. | Payment gateway processing | Payment order ID, billing amount, email |
| MongoDB Atlas | Encrypted cloud database hosting | Account records, posts, encrypted hashes |
| Pusher Ltd. | Real-time WebSocket event dispatch | Encrypted channel IDs for chat/notifications |
| Cloudinary Inc. | Cloud media storage | User uploaded profile avatar images |
| Nodemailer / SMTP Provider | Transactional OTP email delivery | Recipient email address, verification code |
5. Cookie Policy & Authentication
We utilize essential HTTP-only cookies solely for maintaining active session state (JWT authentication token) and referral tracking (ref cookie). We do NOT deploy third-party advertising cookies, cross-site tracking scripts, or analytics fingerprinting tools.
6. Data Security Measures
We implement industry-standard technical and organizational security controls to protect your data against unauthorized access, loss, or disclosure:
- Full Transport Layer Security (TLS/HTTPS) encryption for all web traffic in transit.
- AES-256 encryption at rest for database collections hosted on MongoDB Atlas.
- Bcrypt cryptographic hashing with 12 salt rounds for account passwords.
- Strict server-side privacy serializers that strip sensitive fields before returning JSON payloads to client applications.
7. Data Retention & Erasure
Your personal data is retained for as long as your account remains active. If you initiate account deletion via the Account Settings page:
- Your profile, posts, comments, direct messages, and credentials will be permanently deleted or anonymized within thirty (30) days of account deletion request.
- Transaction records and payment IDs are retained for 7 years solely to comply with Indian financial and legal auditing obligations.
8. Your Rights Under DPDP Act 2023
As a Data Principal under the DPDP Act 2023, you enjoy the following statutory rights:
- Right to Access: The right to request a summary of personal data being processed by us.
- Right to Correction & Erasure: The right to correct inaccurate or out-of-date personal data or request deletion of your account.
- Right to Grievance Redressal: The right to seek redressal for any data protection concern through our designated Grievance Officer.
- Right to Nominate: The right to nominate another person to exercise your data rights in the event of death or incapacity.
9. Children's Privacy Notice
Corporate Gupshup is strictly intended for individuals aged 18 and older. We do not knowingly solicit or collect personal data from minors. If we discover that an individual under 18 has registered, we will promptly delete the account and associated data.
10. Data Protection Officer & Grievance Officer Contact
In accordance with Section 10 of the Digital Personal Data Protection Act, 2023, you may contact our designated Grievance Officer for any privacy concerns, data erasure requests, or grievances:
Grievance & Data Protection Officer
Officer Name: Rahul Singh
Business Name: Corporate Gupshup
Grievance Email: account@corporategupsup.online
Phone: +91 83182 97569
Address: Bengaluru, Karnataka 560001, India
We commit to acknowledging all formal privacy grievances within 48 hours and resolving them within 30 calendar days as mandated by Indian law.