Privacy Policy
Last updated: 8 June 2026
This Privacy Policy describes how OPTICGAMMA ("we", "us") collects, uses, and shares your personal data under the Digital Personal Data Protection Act, 2023 ("DPDP Act").
1. Who we are (Data Fiduciary)
OPTICGAMMA is operated by the entity behind glaumtac.com. For purposes of the DPDP Act, we act as the Data Fiduciary for the personal data described below.
Contact for privacy queries: support@glaumtac.com
2. What personal data we collect
| Category | Examples | Source |
|---|---|---|
| Account data | Email, name, hashed password (via Supabase Auth) | You |
| Subscription data | Razorpay subscription id, billing email, plan | You / Razorpay |
| Product data | Watchlist symbols, journal entries, API keys (hashed) | You |
| Telemetry | IP address, user agent, request timestamps, error reports (Sentry) | Automatic |
| Communication preferences | Email opt-ins, push tokens | You |
We do not collect: bank account numbers, broker credentials, PAN, Aadhaar, biometrics, or device contacts.
3. Why we process it (purposes)
- Service delivery — authenticate you, persist your settings, send you the analytics you requested.
- Billing — invoice you and process renewals via Razorpay.
- Communication — service emails (always), product updates (opt-in).
- Safety & abuse prevention — rate-limiting, fraud detection, security monitoring.
- Improvement — aggregate, anonymous analytics to improve the product (no individual profiling).
We never sell your data or use it for third-party advertising.
4. Lawful basis
We rely on your consent (for marketing and push notifications) and on legitimate uses under the DPDP Act for account, billing, security, and compliance processing.
5. Sharing
| Recipient | Purpose | Location |
|---|---|---|
| Supabase | Database + authentication | Singapore / EU |
| Razorpay | Payments | India |
| Vercel | Frontend hosting | Global |
| Render | Backend hosting | Singapore |
| Sentry | Error reporting | EU/US |
Each processor handles data under its own DPA and contractual privacy obligations. We use standard contractual clauses where data leaves India.
6. Retention
| Data | Retention |
|---|---|
| Active account | While your account exists |
| Closed account | 30 days after closure (then deleted) |
| Billing records | 8 years (tax law) |
| Telemetry / logs | 90 days |
| Sentry error reports | 30 days |
7. Your rights (DPDP Act)
You have the right to:
- Access the personal data we hold about you.
- Correction of inaccurate data.
- Erasure of your data (except where retention is legally required).
- Grievance redressal via our DPO (support@glaumtac.com).
- Nominate another person to exercise your rights in the event of death or incapacity.
We respond to verified requests within 30 days. You can delete your account at any time from Settings → Account → Delete account.
8. Security
- Passwords are hashed by Supabase Auth (bcrypt).
- API keys are stored as SHA-256 hashes only — the raw secret is shown to you exactly once.
- All traffic uses TLS 1.2+.
- Service-role database access is restricted to the backend; client access is governed by Row Level Security.
- Sentry strips PII server-side.
9. Children
OPTICGAMMA is not directed to anyone under 18. If you believe a minor has provided us data, contact us and we will delete it.
10. Cookies
See the Cookie Notice. In short: essential cookies, plus optional Google Analytics that loads only after you opt in via the cookie banner. No third-party advertising or cross-site tracking.
11. Changes
We will notify material changes via email at least 14 days in advance.
12. Grievance Officer
Per the DPDP Act and applicable rules:
- Email: support@glaumtac.com
- Response SLA: 30 days