Privacy Policy

Last updated: September 29, 2026  ·  Effective September 22, 2026 (TDS reference corrected September 29, 2026)

What changes on September 22, 2026: new Section 3.1 (Access Logging on Provider Nodes), with related changes to Sections 2, 5, 8 and 9. Until then the previous wording applies; ask support@gridshare.in for a copy.

Plain English summary: We collect only what's necessary to run the marketplace. For Buyers that is name and email. For Providers who receive payouts it also includes bank account details (account number, IFSC and account name, stored encrypted) and PAN — we are required to hold these to pay you and to deduct TDS. We never collect Aadhaar, and we never see or store card numbers, CVVs or OTPs. We don't sell your data. Account and billing data is stored in India; encrypted workspace backups are stored in Singapore (see §7). You can request deletion at any time. GridShare does not inspect the contents of your compute workloads.

1. Who We Are

This Privacy Policy applies to Quartusbrain Ideas Private Limited ("GridShare", "we", "our", "us"), operating the Platform at gridshare.in and relay.gridshare.in, incorporated under the Companies Act, 2013, India.

GridShare is a data fiduciary as defined under the Digital Personal Data Protection Act, 2023 (DPDPA 2023) with respect to the personal data it processes. For privacy queries, contact our Privacy Officer at: support@gridshare.in.

2. Data We Collect and Why

2.1 Providers (GPU node owners)

DataWhy We Collect ItRequired?
Full nameIdentity for payout records, TDS compliance, and supportYes
PAN (Permanent Account Number)TDS on payments to contractors under Indian income-tax law — 1% with PAN, or 20% without PANStrongly recommended
Bank account (number, IFSC, account name)To send your earnings by bank transfer — the payout method in use today. Stored encrypted.Yes
UPI ID (VPA)Optional. UPI payouts are coming soon; today you are paid by bank transfer.Optional
Email addressPayout receipts, tax certificates, and account alertsOptional but recommended
Phone numberAccount contact for support, payout and KYC queries. We do not send marketing or automated messages to it.Optional
City / LocationDisplayed on marketplace to help Buyers choose nearby nodesOptional
GPU hardware specsAutomatic tier assignment, pricing, and marketplace listingYes (auto-detected by agent)
Node uptime and performance metricsReliability score calculation, per-second billing verification, and deciding refunds and pay when a node goes offline during a rental (Provider Agreement Section 3)Yes (auto-collected)
Container access reportsA record of certain entry, made through Docker, into Buyer containers on your node that GridShare’s software did not itself perform — see Section 3.1Yes (auto-collected on Docker nodes)

2.2 Buyers

DataWhy We Collect ItRequired?
Full nameAccount identity and GST invoice generationYes
Email addressLogin, billing receipts, instance alerts, and account securityYes
Phone numberNot collected from new Buyer accounts. If you gave one before 6 September 2026 it is kept only as an account contact for support — ask us to delete it at any time (see Section 9).No
Company name & GSTINGST-compliant tax invoice generation for business customersOptional
SSH public keysInjected into instances for passwordless SSH access — stored as plain public keysOptional
Wallet balance and transaction recordsPrepaid compute billing, refund processing, and financial complianceYes
Instance launch history and compute usageBilling, fraud detection, and supportYes (auto-collected)
Container access reportsA record naming your workload (and, for an instance, your account) when a Provider uses Docker to enter your container outside GridShare’s own operations — see Section 3.1Yes (auto-collected)
Browser fingerprint hash (SHA-256)Multi-account fraud detection — stored as a hash, never the raw fingerprintOptional (client-side)
Workspace contents (continuous autosave)To protect your work from interruption, restart, or node failure, we continuously back up your instance's /workspace (code, scripts, notebooks, configs, small outputs). Large regenerable files (model weights, caches, datasets) are excluded. We do not inspect or analyse the contents, and you can delete these backups at any time.Yes (auto, while running) — deletable

2.3 What We Do NOT Collect

3. Important Limitation — Provider Hardware

Note on Provider nodes: Compute workloads run on hardware owned and operated by independent Providers, not GridShare. GridShare has no technical ability to inspect or control what occurs on Provider hardware at the OS or hardware level. While Providers are contractually prohibited from accessing Buyer data, GridShare cannot technically guarantee that a Provider cannot access unencrypted data on their own hardware. Do not process highly sensitive, classified, or regulated data on Community-tier nodes. Use encrypted containers and in-instance encryption for sensitive workloads. For sensitive workloads we recommend encrypting data before upload and using checkpoints encrypted client-side. Buyer secrets injected into instances may be technically visible to the host machine owner; do not inject production credentials into Community-tier instances.

3.1 Access Logging on Provider Nodes

To protect Buyer data on Provider machines, and to help detect entry into a Buyer’s container made through Docker, the GridShare node software keeps a record of certain actions on the Buyer containers it runs. Node software released since 7 September 2026 already keeps this record; this section sets out what it contains and how it is handled.

ItemDetails
What is recordedEach time anyone, through the Docker daemon on a Provider’s machine, runs a command or opens a shell inside a Buyer’s container, attaches to it, copies files into or out of it, exports it, or saves it as an image. The GridShare software’s own automated operations are not recorded. On node software released since 10 September 2026, health checks that Docker runs by itself on a container’s regular schedule are not recorded either, and a health check that runs outside that schedule is recorded and marked as one; the report then contains the health-check command set by the Buyer’s container image.
What a report containsThe type of action; for a command, its first 200 characters (never its output) and Docker’s reference for it; the container and the Buyer workload (instance, serverless worker or job); the time; and the node software version. We link each report to the Provider’s node and account and, for a rented instance, to the Buyer account that rented it. A command is recorded as typed, so it can include the name of a file or folder in the Buyer’s container or, if one was typed, a password or key. No report contains the contents of a file or the output of a command.
Whose personal dataProviders: the report describes an action on their machine and is linked to their account. Buyers: the report names their workload and, for an instance, their account.
What it does not seeReading a container’s logs, listing its processes, inspecting it or viewing its resource use; reading files directly from the Provider’s disk; tools that bypass the Docker daemon; workloads that do not run in Docker; nodes still running older node software that does not keep this record; and anything done while the node software or Docker is stopped or the node is offline. A report can also be lost before it reaches us. The limitation described above therefore still applies.
Why we process itTo protect Buyer data on Provider hardware, to enforce Sections 6 and 7 of the Provider Agreement, to resolve disputes, and to meet legal obligations.
BasisYour consent, given when you accept this Policy (Providers also when accepting the Provider Agreement). We may also keep and use a report without consent where the Digital Personal Data Protection Act, 2023 allows it: to enforce a legal right or claim (Section 17(1)(a)), to prevent, detect or investigate an offence (Section 17(1)(c)), or where a law requires us to disclose it to the government or a court orders it (Section 7(d) and (e)).
How it is decidedNo action is taken on a report until a member of GridShare’s team has reviewed it. Nothing is decided against anyone automatically, and a report on its own is not a finding against anyone.
Who can see itGridShare staff who review reports, and our hosting and email providers, which store the reports and carry the internal alerts they generate (see Section 6). A copy of each report also stays in a log file on the Provider’s own machine. We give a report to a law-enforcement or regulatory authority where the law requires it (for example, reporting a cyber-security incident to CERT-In), in answer to a lawful request, or when we report a suspected offence under Section 6 of the Provider Agreement. If a review finds that a Provider accessed your data, we will tell you as required by law (see Section 7). Reports are not shown to other Buyers or Providers.
How long we keep itThree years from the date of the report, including after an account is closed; longer while a related dispute, investigation or legal claim is open and, where a report supports a decision to withhold or recover money, for as long as the related financial records are kept (Section 8); then deleted or anonymised. The copy on the Provider’s machine is kept until the log file passes about 1 MB, when it is cleared and started again.
Your rightsYou can ask for access to, correction of, or erasure of reports about you, subject to the retention above (Section 9), and raise a grievance with our Grievance Officer (Section 15). If you are not satisfied with our response, you may complain to the Data Protection Board of India in the manner the Board specifies (Section 9). Providers can withdraw consent at any time by writing to support@gridshare.in; because this record is a condition of hosting Buyer workloads, their nodes will then be removed from the marketplace. Withdrawal does not affect reports already made.

4. How We Use Your Data

5. Lawful Basis for Processing

Under the Digital Personal Data Protection Act, 2023 (DPDPA 2023), GridShare processes your personal data on the following bases:

6. Third Parties We Share Data With

ServiceData SharedPurposeLocation
Razorpay Software Pvt. Ltd.Name, UPI VPA, transaction amount, order IDProcessing Buyer payments and Provider payoutsIndia
DigitalOcean LLC (Cloud infrastructure)Core account, billing, and operational data (application server + database)Infrastructure hostingIndia (Bangalore region)
DigitalOcean Spaces (Object storage)Workspace autosave snapshots of your /workspaceEncrypted backup storageSingapore (SGP1) — see Section 7
Zoho (Transactional email)Email address and message contentSending transactional emails (receipts, alerts, verification)As per Zoho's India data-centre region
Competent legal authoritiesAs required by lawful orderLegal compliance — CERT-In, tax authorities, courtsIndia

We do not sell, rent, licence, or share your personal data with advertisers, data brokers, marketing firms, or any third party for commercial purposes.

We require all third-party data processors to maintain appropriate security and confidentiality standards. We are not responsible for the independent privacy practices of Razorpay or the other processors listed above — please review their respective privacy policies.

7. Data Storage and Security

Despite these measures, no internet transmission or storage system is 100% secure. GridShare cannot guarantee absolute security of your data. In the event of a data breach affecting your personal data, we will notify you as required by applicable law.

8. Data Retention

CategoryRetention PeriodReason
Active account dataUntil account closurePlatform operation
Personal data after account closureDeleted within 90 days — except the categories listed in this table with a longer periodDPDPA 2023 compliance
Financial transaction records8 years from the end of the financial year of the transactionCompanies Act 2013, GST Act and Income Tax Act requirements
TDS records and Form 16A8 years from the end of the financial yearIncome Tax Act 1961
Node heartbeat / performance data7 days rollingReliability score calculation, billing verification, and refund/dispute resolution; the outcome of each node-drop refund decision is kept as long as the related financial records
Container access reports (Provider nodes)3 years from the report; longer while a related dispute, investigation or legal claim is open, and, where a report supports a decision to withhold or recover money, as long as the related financial recordsProtecting Buyer data, enforcing the Provider Agreement, and legal claims (the limitation period for contract claims is 3 years) — this period applies after an account is closed too — see Section 3.1
Workspace autosave backupsRetained while your instance is active or the workspace is funded (positive balance); reclaimed when the instance is terminated and no longer funded, or on your requestCrash recovery and resume
Security logs (IP, login events)90 daysFraud investigation and CERT-In compliance
Support correspondence3 years from last interactionDispute resolution

9. Your Rights Under DPDPA 2023

Under the Digital Personal Data Protection Act, 2023, you have the following rights with respect to your personal data held by GridShare:

To exercise any of these rights, email support@gridshare.in with subject "Privacy Request — [your full name]" from your registered email address. We will respond within 30 days.

10. Cookies and Local Storage

GridShare uses minimal browser storage:

11. Business Transfers

In the event of a merger, acquisition, restructuring, or sale of all or substantially all of GridShare's assets, personal data held by GridShare may be transferred to the acquiring entity as part of that transaction. You will be notified via email and/or prominent notice on the Platform at least 30 days before any such transfer, and the new entity will be bound to honour this Privacy Policy or provide notice of material changes. If you do not accept the new entity's privacy terms, you may close your account before the transfer takes effect.

12. Children's Privacy

GridShare is not intended for users under 18 years of age. We do not knowingly collect personal data from minors. If you believe a person under 18 has registered an account, contact support@gridshare.in and we will promptly delete the account and associated data.

13. Third-Party Links and Services

The Platform may contain links to third-party websites or services (e.g., Razorpay, DigitalOcean, GitHub). GridShare is not responsible for the privacy practices or content of those third parties. Visiting those sites is governed by their own privacy policies, which we encourage you to review.

14. Changes to This Policy

We may update this Privacy Policy as required. For material changes that meaningfully affect your rights, we will provide at least 7 days' advance notice via email. The updated date at the top of this page will always reflect when the Policy was last revised. Continued use of the Platform after the effective date constitutes acceptance of the revised Policy.

15. Grievance Officer

In accordance with the Digital Personal Data Protection Act, 2023 and applicable consumer-protection rules, GridShare has appointed a Grievance Officer to address user complaints: