PureGPL PureGPL
Log in Cart
Skip to page content
Legal

Privacy Policy

Last updated: 18 September 2026
Effective from: 18 September 2026

This policy explains what personal data PureGPL collects, why, who we share it with, how long we keep it and what you can do about it. It applies to puregpl.com, to your customer account, and to the support and messaging channels we operate.

We are the data fiduciary (under India’s Digital Personal Data Protection Act, 2023) and the data controller (under the EU/UK GDPR) for this data.

  • Business name: PureGPL
  • Address: 15A, 4th Floor, CITY VISTA, Vadgaon Sheri, Pune City, Maharashtra 411014, India
  • Privacy contact: [email protected]

What we collect

1.1 Information you give us

  • Account details — name, email address, password (stored hashed, never in readable form), and optionally a phone number and billing address.
  • Order details — the products you buy, order value, currency, invoice and billing information, coupon use, and any tax identifier you supply.
  • Support content — the messages, screenshots, log files, site URLs and any attachments you send us in a support ticket. Please do not send us admin passwords, FTP credentials or database dumps unless we specifically ask, and change them afterwards if you do.
  • Communications — emails, WhatsApp messages, and any enquiry form you complete.
  • Reports and takedown notices — the contact details and statements you provide when reporting a product.

1.2 Information we collect automatically

  • Technical and log data — IP address, browser type and version, operating system, device type, language, referring page and the pages you view.
  • Download activity — which files you download, when, and how many, so we can apply membership allowances and detect account sharing or automated scraping.
  • Security data — login times, failed login attempts, and signals used to detect fraud and abuse.
  • Cookies and similar technologies — see Section 5.

1.3 Information we receive from others

  • Payment processors — confirmation of payment, the last four digits and brand of a card, the payment status, and fraud/risk signals. We never receive your full card number or CVV.
  • Advertising platforms — aggregated campaign and conversion data from Google and Meta.
  • Messaging platforms — your WhatsApp display name and phone number when you message us there.

1.4 What we do not collect

We do not intentionally collect sensitive categories of personal data — health, religion, political opinions, biometrics, caste, sexual orientation or government ID numbers. Please do not send them to us. If you do, we will delete them.

Why we use it, and our lawful basis

Purpose Data used Lawful basis (GDPR) / ground (DPDP)
Creating and running your account Account details Performance of a contract / certain legitimate uses
Processing orders, delivering downloads, issuing invoices Order and account details Performance of a contract
Providing support Support content, order details Performance of a contract
Applying membership download limits Download activity Performance of a contract
Preventing fraud, abuse and account sharing Technical, security and download data Legitimate interests
Complying with tax, accounting and legal obligations Order and invoice data Legal obligation
Service emails (order confirmation, renewal notice, security notice) Email address Performance of a contract
Marketing emails and offers Email address, purchase history Consent (withdrawable at any time)
Analytics and improving the site Technical data, cookies Consent, where required
Advertising and remarketing Cookies, device and conversion data Consent, where required
Handling reports, takedowns and disputes Report content, order records Legal obligation / legitimate interests

Payment data

Payments are processed by third-party payment gateways. Card numbers, CVV codes, UPI PINs and net-banking credentials are entered on the payment provider’s own systems and never reach or pass through PureGPL’s servers. We store only what we need to identify a transaction: the amount, currency, timestamp, provider reference, payment status and, where the provider supplies it, the card brand and last four digits.

Each payment provider is an independent controller of the data you give it, and its own privacy policy applies. We currently use Razorpay, PayPal, and Stripe — see the links in the checkout footer.

WhatsApp and messaging

We operate a WhatsApp Business channel for pre-sales enquiries and support, including an automated reply flow.

  • When you message us on WhatsApp we receive your phone number, WhatsApp display name and the content of your messages.
  • Messages may be handled by an automated assistant before a human agent replies. Automated replies are for routing and information only; a human reviews anything that needs a decision.
  • Conversations are stored so we can continue the thread, resolve disputes and improve our replies.
  • WhatsApp is operated by Meta, and Meta processes message metadata under its own terms. We do not control that.
  • You can ask us to delete your conversation history at any time by writing to [email protected].
  • If you message us first, we may reply. We send marketing messages on WhatsApp only where you have opted in, and every such message carries a way to stop.

Cookies and tracking

We use cookies and similar technologies in four groups:

  • Strictly necessary — login sessions, shopping cart, checkout, security and load balancing. These cannot be switched off without breaking the site.
  • Functional — remembering your currency, language and display preferences.
  • Analytics — understanding which pages are used and where people get stuck, so we can improve the site.
  • Advertising — measuring ad performance and showing you relevant ads on other platforms.

Analytics and advertising cookies are set only with your consent where the law requires it. You can change your choice at any time through our cookie banner or your browser settings. Blocking cookies in your browser will not affect your ability to buy or download, except for strictly necessary cookies.

Advertising and analytics

We advertise PureGPL on Google and on Meta platforms (Facebook and Instagram), and we measure the results.

  • Google Analytics / Google Ads — page views, traffic sources and conversions. Google may set cookies and use this data under its own privacy policy. You can opt out with the Google Analytics opt-out add-on.
  • Meta Pixel and Conversions API — we send Meta signals about page views and purchases so we can measure and target advertising. Where events are sent from our server, identifiers such as an email address or phone number are hashed before transmission. You can manage this in your Facebook and Instagram ad settings.

These platforms act as independent or joint controllers for the data they receive. We do not send them the contents of your support tickets, your password, or your download library.

Who we share data with

We share personal data only with the categories below, only as far as needed, and under contracts that require them to protect it:

  • Payment processors — to take payment and issue refunds.
  • Hosting, CDN and storage providers — to run the site and deliver download files.
  • Email and messaging providers — to send transactional and, where you have opted in, marketing messages.
  • Analytics and advertising platforms — as described in Section 6.
  • Support and ticketing systems — our own support plugin, hosted on our infrastructure.
  • Professional advisers — accountants and lawyers, where necessary.
  • Authorities — where we are legally required to disclose, or where disclosure is necessary to establish, exercise or defend legal claims. We will tell you unless the law prevents us.
  • A buyer of our business — if PureGPL is sold or merged, under the same protections as this policy.

We do not sell your personal data, and we do not share it with data brokers.

International transfers

PureGPL is based in India. Some of our providers are located outside India, including in the United States and the European Union. Where we transfer personal data internationally we rely on appropriate safeguards — Standard Contractual Clauses or an adequacy decision for EU/UK data, and transfers permitted under the DPDP Act for Indian data. You can ask us for details at [email protected].

How long we keep it

  • Account data — while your account is open, then up to 12 months after closure in case you return, unless you ask us to delete it sooner.
  • Order, invoice and tax records — 8 years, as required by Indian tax and accounting law. We cannot delete these on request.
  • Support tickets — 24 months after the ticket closes.
  • WhatsApp conversations — 24 months, or until you ask for deletion.
  • Server and security logs — 12 months.
  • Marketing consent records — until you withdraw consent, plus a suppression record so we do not contact you again by mistake.
  • Takedown notices and disputes — for the duration of any limitation period that applies.

How we protect it

  • HTTPS/TLS encryption across the whole site, including checkout and downloads.
  • Passwords stored using a one-way salted hash. Nobody at PureGPL can read your password.
  • Card data never touches our servers.
  • Support attachments stored in a private directory that is not publicly reachable.
  • Access to customer data restricted to the staff who need it, with individual accounts.
  • Regular malware scanning of the site and of the product files we publish.
  • Server patching, firewall and rate limiting.

No system is perfectly secure. We cannot guarantee absolute security, and you are responsible for using a strong, unique password and keeping it private.

If something goes wrong

If a personal data breach occurs that is likely to affect you, we will notify the Data Protection Board of India and, where the GDPR applies, the relevant supervisory authority, within the timeframes the law requires. We will notify affected users by email without undue delay, describing what happened, what data was involved, what we are doing about it and what you should do.

Your rights

If you are in India (DPDP Act, 2023), you have the right to:

  • access a summary of the personal data we process about you and who we have shared it with;
  • have inaccurate or incomplete data corrected, updated or completed;
  • have your data erased, where we no longer need it for the purpose it was collected and no law requires us to keep it;
  • withdraw consent you previously gave, as easily as you gave it;
  • nominate another person to exercise your rights if you die or become incapacitated;
  • a readily available grievance redressal mechanism — see Section 18.

If you are in the EU, EEA or UK (GDPR), you also have the right to: restriction of processing, data portability in a machine-readable format, objection to processing based on legitimate interests, objection to direct marketing at any time, and to lodge a complaint with your national supervisory authority.

If you are in California (CCPA/CPRA), you have the right to: know what we collect and why, request deletion, request correction, and not be discriminated against for exercising these rights. We do not sell or share personal information for cross-context behavioural advertising as those terms are defined under the CPRA beyond the advertising cookies described in Section 6, which you can decline.

How to exercise your rights

  • Much of it you can do yourself: update your details in your account, and unsubscribe using the link in any marketing email.
  • For anything else, write to [email protected] from the email address on your account.
  • We may ask you to verify your identity before we act, to make sure we are not disclosing your data to someone else.
  • We respond within 30 days. If a request is complex we may extend this and will tell you why.
  • There is no charge, unless a request is manifestly unfounded or repetitive.
  • Note: deleting your account also ends access to your download library and any active membership. We cannot reverse it.

Children

PureGPL is not intended for children. We do not knowingly collect personal data from anyone under 18. If you believe a child has given us personal data, write to [email protected] and we will delete it.

Automated decisions

We use automated checks for fraud screening, download-limit enforcement and abuse detection. These can result in an order being declined or an account being temporarily restricted. You can ask for a human review of any such decision by contacting support, and we will look at it properly.

We do not sell your data

We have never sold customer data and we will not. We do not rent, trade or transfer your personal data to third parties for their own marketing.

Changes to this policy

We may update this policy. The “Last updated” date at the top shows when it last changed. Where a change materially affects how we use your data, we will notify you by email or with a prominent notice on the site before it takes effect.

Grievance Officer and complaints

In accordance with the Information Technology Act, 2000, the rules made under it, and the Digital Personal Data Protection Act, 2023:

  • Name: Varun
  • Designation: Grievance Officer & Data Protection Contact, PureGPL
  • Email: [email protected]
  • Address: 15A, 4th Floor, CITY VISTA, Vadgaon Sheri, Pune City, Maharashtra 411014, India

We acknowledge every grievance within 48 hours and aim to resolve it within one month.

If you are not satisfied with our response, you may complain to the Data Protection Board of India, or — if you are in the EU, EEA or UK — to your national data protection supervisory authority.