Privacy Policy
Last updated: 1 May 2026
This Privacy Policy explains how GeminiSoft Technologies ("GeminiSoft", "we", "us") collects, uses, and protects information when you visit geminisoft.in, engage our services, or interact with our platforms.
We follow the principles of India's Digital Personal Data Protection Act, 2023 (DPDP Act), and align with Meta Platform Terms, Google API Services User Data Policy, and applicable global standards including GDPR Article 17 and CCPA where relevant.
1. Who we are
GeminiSoft Technologies is a software company registered in Bangalore, Karnataka, India. The data controller for any personal information collected on this site is GeminiSoft Technologies. You can reach us at privacy@geminisoft.in or via the contact form at geminisoft.in/contact.
2. What we collect
2.1 Information you give us directly
- Identity and contact data — name, email, phone number, company name when you fill in our contact form, request a demo, or sign up for a product trial.
- Account information — credentials and profile details when you register for one of our products.
- Communications — messages, emails, and feedback you send us.
2.2 Information collected through connected platforms
When you authorise GeminiSoft (or one of our products such as Karvo Local) to act on behalf of your business via OAuth, we receive limited data from those platforms:
- Google Business Profile — business profile information, review data, and posting permissions, used solely to publish updates and respond to reviews on your behalf as you have configured.
- Meta Instagram (Instagram Graph API) — your Instagram Business or Creator account ID, profile name, linked Facebook Page, and content publishing permission, used solely to schedule and post content on your behalf.
- OAuth access and refresh tokens — securely encrypted and used only to make authorised API calls on your behalf.
We do not sell, lend, or share this data with third parties for advertising or analytics purposes.
2.3 Information collected automatically
When you visit geminisoft.in we collect basic technical data — IP address, browser type, pages viewed, referrer — to understand site usage and improve performance. We do not run third-party advertising trackers.
Specifically, we use two privacy-respecting analytics tools:
- Google Analytics 4 — to measure aggregate page views, traffic sources, and basic device/region information. We use Google's IP anonymisation and have advertising signals disabled.
- Microsoft Clarity — to record anonymous heatmaps and session replays of how visitors interact with the site (clicks, scrolls, dead clicks). Form fields and any sensitive content are automatically masked. Microsoft does not use Clarity data for advertising.
You can opt out of Google Analytics by installing the Google Analytics Opt-Out Browser Add-on, and disable both tools by enabling Do Not Track or a content blocker (e.g. uBlock Origin) in your browser.
3. How we use your information
- To provide, operate, and improve our products and services.
- To respond to enquiries, deliver demos, and onboard new clients.
- To publish content on your behalf to your authorised social and business profiles, exactly as you have configured in our product.
- To send service updates, security notices, and (only with consent) marketing communications you can unsubscribe from at any time.
- To meet legal, regulatory, and tax obligations.
4. Legal bases for processing
We process personal data on the basis of: your consent, performance of a contract with you, our legitimate business interests where balanced against your rights, and legal obligations. For data received from Meta and Google APIs, we additionally rely on the consent you grant via the OAuth authorisation screen.
5. Data sharing
We share data only with:
- Service providers who help us operate our infrastructure (cloud hosting, email delivery, customer support tooling) under contractual confidentiality obligations.
- Platforms you have explicitly connected (Google, Meta) — only as required to perform the publishing and engagement tasks you have authorised.
- Authorities when legally required.
We do not sell your personal data. We do not share it with advertisers.
6. Data retention
- OAuth access tokens — retained until you disconnect your account or revoke permissions, then deleted within 30 days.
- Posting history and engagement analytics — retained for 12 months, after which they are anonymised or deleted.
- Contact-form messages — retained for 24 months.
- Account data — retained for the duration of your account plus 30 days after closure, except where law requires longer.
7. Your rights
You have the right to access, correct, port, restrict, or delete your personal data, and to withdraw consent at any time. To exercise any of these rights, see our Data Deletion page or email privacy@geminisoft.in. We respond within 30 days.
8. Security
We use industry-standard measures including encryption in transit (TLS), encryption at rest for sensitive credentials, role-based access control, audit logging, and regular security reviews. No system is perfectly secure, but we treat your data with the care we would want for our own.
9. Children
Our services are not directed at children under 18 and we do not knowingly collect data from them. If you believe a child has provided us data, please contact us so we can remove it.
10. International transfers
Our infrastructure may store data in India and other regions where our cloud providers operate. Where data is transferred outside India, we apply appropriate safeguards including the EU Standard Contractual Clauses where relevant.
11. Changes to this policy
We may update this Privacy Policy as our products evolve. Material changes will be communicated via email (where we have your address) or a banner on this site at least 14 days before they take effect.
12. Contact
For any privacy question, request, or complaint, write to:
GeminiSoft Technologies
Attn: Privacy Officer
Bangalore, Karnataka, India
Email: privacy@geminisoft.in