Last updated: September 25, 2026
Who we are
grewray is a product of Arihance System Private Limited, which trades as Vanvora (“we”, “us”, “our”). This policy explains how we handle personal data when you visit the grewray website and when you, or the business you work for, use the grewray app. It is written to meet India's Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 (together, the DPDP law), the Information Technology Act, 2000 and its rules, and, for people outside India, the data protection laws that apply to them, including the GDPR in the European Union and the United Kingdom.
This policy and our consent notice together are the notice we give you before asking for your consent. One consent covers the website and the app.
- Company
- Arihance System Private Limited, trading as Vanvora
- Registered office
- DPT 808B, F-79/80, 8th Floor, DLF Prime Tower, Okhla Industrial Area Phase 1, New Delhi, Delhi 110020, India
- Grievance officer
- Ayush Jain, Grievance Officer and Founder
- Contact
- hello@grewray.com
Our two roles
The law treats us differently depending on whose data it is:
- We are the data fiduciary (the controller, under the GDPR) for the personal data of people who visit this website, who create a grewray account, who pay for a subscription, or who contact us. We decide why and how that data is used, and this policy describes it.
- We are a data processor for the business data a customer enters into grewray: its own customers, leads, jobs, bookings, invoices, files and notes. The customer business is the data fiduciary for that data and decides what goes in. We process it only on its instructions, under our data processing addendum. If you are a customer of a business that uses grewray, contact that business about your data first.
What we collect
When you visit the website
This website sets no cookies and runs no analytics, advertising or tracking scripts; nothing on it loads from a third party. The servers that deliver it record standard request logs (your IP address, browser type, the page requested and the time), which our hosting provider keeps briefly to deliver the site and protect it from abuse. The free tools and the interactive demo run entirely in your browser: nothing you type into them is sent to us or stored.
When you create an account
- your full name, work email address and company name;
- your phone number, if you choose to give it;
- your password, which we store only as a salted hash, never in a form anyone can read;
- your two-factor sign-in settings, protected at rest;
- the date and the version of the terms and this policy you agreed to.
When you set up and use a business
- the business's name, web address, industry, country and time zone;
- the business data your team enters, which we process as a data processor (see above);
- the messages the service sends on the business's behalf, and whether they arrived.
To keep accounts secure
- sign-in events, the devices and browsers they came from, their IP addresses, and changes to sensitive settings, kept in an append-only security record;
- the result of a bot check on the sign-up and password-reset forms, provided by Cloudflare Turnstile;
- a check that a new password has not appeared in a known data breach. Only the first five characters of a one-way hash of the password leave our servers; the password itself never does, and nothing about you is sent with it.
When you pay
Your plan, your billing contact and your invoices. Card and bank details are collected by our payment providers, Paddle and Razorpay, directly; we never see or store your full card details.
When you contact us
Your email address and what you tell us, used to reply and to keep a record of it.
Why we use it, and on what basis
- To provide the service you signed up for, including service emails such as verification, security alerts and receipts. Basis: your consent under the DPDP law; under the GDPR, our contract with you.
- To keep accounts and data secure, and to prevent fraud and abuse. Basis: your consent, and our legal obligations to keep data secure; under the GDPR, our legitimate interest in a secure service.
- To meet legal obligations, such as keeping tax records or answering a lawful order. Basis: the legitimate uses the DPDP law allows for complying with the law; under the GDPR, legal obligation.
- To answer you when you write to us. Basis: the purpose you contacted us for.
- To send product news, only if you have separately asked for it. Basis: consent, which you can withdraw at any time from the email itself.
We never sell personal data, never use it for advertising, and never use a business's data for anything except providing grewray to that business.
Who we share it with
A small number of service providers help us run grewray: hosting, email delivery, the bot check, the breached-password check and payments. Each is bound to process data only for us and only for that purpose. The current list, with what each one does and where, is on our sub-processors page.
Services you choose to connect, such as your accounting software or the payment provider behind your Pay now links, receive the data you send them, under their own terms.
We disclose personal data to authorities only when the law requires it, such as a lawful order under Indian law, and only what is required. Where the law allows, we tell the affected customer first. We never share one business's data with another.
Where it is processed
Our providers process data in India and in other countries. The DPDP law allows personal data to be processed outside India except in countries the Government of India restricts, and we do not use providers in any restricted country. For people in the European Union or the United Kingdom, transfers rely on the safeguards those laws recognize, such as standard contractual clauses.
How long we keep it
- Account and business data: while the account is open. When a paid period ends without renewal, the business becomes read-only and its data stays available to export for 30 days. We email the owners before it is deleted. It then leaves our rolling backups within a further 30 days.
- Security records: for as long as they are needed to protect the service, and at least 180 days, as Indian law requires.
- Billing records: for as long as tax and company law requires.
- Website request logs: briefly, by our hosting provider.
- Messages you send us: until the matter is resolved, and for a reasonable time afterwards as a record.
When the purpose for keeping data ends and no law requires us to keep it, we erase it.
How we protect it
We follow reasonable security practices as the Information Technology Act requires. Every business's data is kept separate by four independent layers, from the application down to the database itself, and is encrypted in transit and at rest. Owners and admins must use two-factor sign-in, access inside a business is decided by role, and every sensitive change is recorded. Backups allow a restore to within five minutes and are tested every quarter. The details are on our security page.
If something goes wrong
If a personal data breach affects your data, we will tell you without delay: what happened, what it may mean for you, what we are doing and what you can do. We will also inform the Data Protection Board of India and CERT-In as the law requires, and, for a business's data, the business itself, which may need to tell its own customers.
Your rights
Under the DPDP law, you can ask us:
- for a summary of your personal data we process, how, and who we have shared it with;
- to correct, complete or update it, or to erase it;
- to stop processing it, by withdrawing your consent;
- to hear and resolve a grievance about how we handle it;
- to let a person you nominate exercise these rights if you die or become unable to.
If you are in the European Union or the United Kingdom, you also have the rights to restrict or object to processing and to receive your data in a portable form. If you are in a US state with a privacy law, such as California, you can ask what we collect, ask us to delete or correct it, and you have the right to opt out of its sale or sharing, although we do neither.
To use any of these rights, email hello@grewray.com from the address on your account, so we can confirm it is you. We reply within 1 business day and complete requests within the time the law sets. Exporting your business's data is free and always available inside the product.
Children
grewray is a business service for people aged 18 or over, the age of adulthood under the DPDP law. We do not knowingly collect personal data from children.
If your business records data about children in grewray, such as students at a tutoring business, your business is the data fiduciary for it and must obtain the verifiable consent of a parent or guardian, as the DPDP law requires.
Grievances and complaints
Our grievance officer is Ayush Jain, Grievance Officer and Founder. Write to hello@grewray.com. We acknowledge every grievance within 1 business day and resolve it within 15 days. If you are not satisfied with our answer, you can complain to the Data Protection Board of India, or to the data protection authority where you live. The full process is on our grievance redressal page.
Changes to this policy
When this policy changes, we update the date at the top. If a change is material, we tell account owners by email at least 30 days before it takes effect, and where the law requires your consent to the change, we ask for it again.