Privacy Policy
Last updated: 23 July 2026
GUAPD PRIVATE LIMITED (“Guap’d”, “we”). Registered office: Plot No 307, Kh. No. 137/9, 1st Floor, Ishwar Colony, Bawana, Delhi, North West Delhi – 110039, Delhi, India.
Grievance Officer / Data protection contact: Palak Jain, contact@guapd.com
Support: help@guapd.com
This policy is framed under India’s Digital Personal Data Protection Act, 2023. We are the Data Fiduciary.
What we collect
Creators: name, phone number (used for OTP login), email, Instagram/YouTube handles and profile links, self-reported audience statistics, rate card and pricing, profile photo, content samples uploaded to the platform, PAN (optional, required only for tax-compliant payouts and TDS), deal history, messages sent through the platform, uploaded deliverable files.
Brands: name, work email, company name, GSTIN (optional, required only to issue a GST-compliant invoice), team member names and emails, deal history, messages, payment status records, subscription plan, billing history and invoices.
Anonymous visitors to a creator’s shopfront: if you begin an offer and choose to sign up, the details you entered are carried into your new account. We do not store anything you type before you create an account.
Automatically: IP address, device and browser information, pages viewed, and product analytics events (see Cookies).
We do not collect or store: card numbers, bank account details, or UPI IDs. All payment instruments are handled by our payment processor and never reach our systems.
Why we collect it
Operating the deal workflow; verifying identity and vetting creators; sending notifications about your deals over WhatsApp, email and push; generating invoices and meeting tax obligations; managing subscriptions and billing; maintaining an audit record of every change to a deal so that disputes can be resolved fairly; improving the product; security and fraud prevention; complying with law.
Legal basis
We process personal data on the basis of your consent, given when you create an account and when you take specific actions (publishing a storefront, sending an offer), and for legitimate uses permitted under the DPDP Act, including performing our contract with you and complying with legal obligations.
Public information
If a creator publishes a storefront, the information on that page (name, photo, handle, bio, categories, self-reported statistics, and, if the creator enables it, rates and past brand collaborations) becomes publicly visible to anyone with the link. Publishing is off by default and entirely the creator’s choice. A brand’s name appears on a creator’s storefront only if that brand has separately opted in to public attribution. Creators can unpublish at any time, though pages already viewed or cached elsewhere may persist outside our control.
Who we share it with
- Supabase: database, authentication, file storage. Data hosted in Mumbai, India.
- Vercel: application hosting and delivery.
- Razorpay: payment and subscription processing.
- Interakt / WhatsApp Business API (Meta): deal notifications sent to your phone number.
- Meta Platforms: if you connect an Instagram account, to retrieve your own account statistics.
- PostHog: product analytics and session replay, hosted in the EU (Frankfurt). Only with your consent (see Cookies).
- Professional advisers and authorities: where required by law, tax, or legal process.
We do not sell personal data. We do not share your data with other users except as required to run a deal you are party to, or as published on a storefront you have chosen to make public.
Where data is stored
Primarily in India (Mumbai). Some processors listed above may process data outside India; where they do, we rely on their contractual safeguards. Specifically, if you consent to analytics, PostHog stores that analytics and session-replay data in the European Union (Frankfurt).
Retention and deletion
You may request deletion of your account by emailing contact@guapd.com. On deletion we remove your profile, storefront, contact details and uploaded content.
We retain records of completed transactions: deal terms, invoices, payment status and the associated audit log, for as long as required by tax, accounting and legal obligations, and to resolve any dispute between the parties to that deal. This is because a deal is an agreement between two people: one party cannot erase the shared record of it. Retained records are dissociated from your profile where possible.
Your rights under the DPDP Act
Access a summary of the personal data we hold about you; correct or complete inaccurate data; request erasure (subject to the retention terms above); nominate another person to exercise these rights in the event of death or incapacity; withdraw consent, which will end your ability to use the platform; and file a grievance with our Grievance Officer.
To exercise any of these, email contact@guapd.com. We will respond within the timelines required by law.
Grievance redressal
Grievance Officer: Palak Jain, contact@guapd.com. If you are not satisfied with our response, you may escalate to the Data Protection Board of India.
Cookies and analytics
We use essential cookies to keep you signed in. These are required for the platform to work and cannot be switched off. With your consent we also use PostHog for product analytics, to understand how the platform is used and improve it. Analytics cookies are not set until you accept them, and you can change your choice at any time using the link in our footer.
If you accept analytics, PostHog also records session replays, a reconstruction of how pages were used, such as clicks and navigation. What you type is masked: passwords, one-time codes, email and phone fields are never captured, and screens showing personal details are hidden from recordings. Replays are stored in the EU and are used only to diagnose problems and improve the product. Decline analytics and no replay is recorded at all.
Children
Guapd is not intended for anyone under 18. We do not knowingly process the personal data of children.
Security
Access to data is restricted by row-level security policies enforced at the database layer; uploaded files are stored privately and served only through short-lived signed links; payment instruments never touch our systems. No system is perfectly secure, and we will notify affected users and the Data Protection Board of any personal data breach as required.
Changes
We will update the “Last updated” date and, for material changes, notify you in the product or by email.