Groove It — Privacy Policy (India)
Last updated: 9 September 2026
1. Operator and scope
Groove It is operated by Luvkush Sharma, an individual operating under the business/app name Groove it. Groove It is not described in this Policy as an incorporated private limited company.
Website: grooveit.in
Business address: SBI Colony, 1st Phase, J. P. Nagar, Bengaluru, Karnataka 560078, India
Contact: support@grooveit.in
This Policy concerns personal information handled through Groove It’s workshop-discovery app and related services in India. It covers app users, people contacting us, and identifiable artists, organisers, and studio representatives appearing in listings, even if they do not have a Groove It account.
External studios and payment providers separately handle information you give them. We remain responsible for information Groove It itself collects or discloses in connection with those services.
2. Information collected
| Category | Information | Purpose |
|---|---|---|
| Adult account information | An adult account holder’s name and email address, together with the account identifiers and authentication information needed for Google or Apple sign-in | Create, authenticate, and manage an adult Groove It account. |
| Adult usage information | An adult account holder’s clicks, interactions with listings and registration links, time spent, search terms, registration destination URLs, internal account ID, name, email address, device or installation ID, IP address, timestamps, session ID, app and operating-system versions, and city or location information | Measure use and help improve Groove It through our in-house analytics system. |
| Anonymous listing statistics | Aggregated counts such as listing views or Register-button taps, designed so Groove It does not retain a child’s identity, device identifier, IP address, account identifier, search history, click history, or time spent | Understand general listing popularity and improve the discovery service. |
| Limited child information, if supplied by an adult to Groove It | Only the information necessary for the specific child-access or workshop-related purpose explained at collection | Provide that specific service, keep it safe, and respond to the parent or guardian. |
| Notification information | Push-notification token, account or device association, notification content/metadata, and delivery or interaction status | Send and manage push notifications using our self-hosted Novu system and the applicable Apple or Google push-delivery service. |
| Crash and diagnostic information | Sentry error and crash logs, which can include error messages, stack traces, app/device information, IP address, account or email identifiers, and actions occurring before an error, depending on configuration | Identify and repair crashes, errors, performance problems, and security issues. |
| Email-delivery information | Email address, message content/metadata, and delivery status required to send account and service emails | Send authentication, account, support, and other service messages using our email-delivery service. |
| Support correspondence | Your contact details and the information you include when contacting us | Answer enquiries and handle corrections, complaints, and privacy requests. |
| Listing information | Workshop, artist, and studio details compiled from publicly accessible Instagram posts | Display discovery information and links to external registration. |
Information in adult usage records is identifiable and is not anonymous merely because Groove It uses it only internally. Groove It does not use an identifiable individual’s activity to create a child profile or to measure a child’s clicks, search history, or time spent.
We do not ask you to send card numbers, CVVs, UPI PINs, bank passwords, or identity documents in ordinary support messages.
3. Google and Apple sign-in
Google. Choosing Sign in with Google allows Groove It to receive a Google-issued account identifier and, according to the permission and response, your name, email address, and email-verification information. Standard profile responses can contain additional basic profile fields such as a profile-picture URL. The actual fields Groove It retains must be checked against the account-data inventory. Authentication information is used to validate sign-in and establish your app session. Basic sign-in permission does not itself grant access to Gmail messages, Drive files, contacts, or calendars. Google’s own processing is explained in its Privacy Policy.
Apple. Choosing Sign in with Apple allows Groove It to receive an Apple-issued user identifier, authentication information, and name/email information you authorise Apple to share where available. Name information may be supplied only on initial authorisation. If you choose Hide My Email, Groove It receives a relay email address rather than your underlying email. The relay remains personal information associated with your account. Apple explains its processing in Sign in with Apple & Privacy.
Groove It does not receive your Google or Apple password through these sign-in flows. The providers process authentication requests and connection information under their own policies; Groove It is responsible for the information it receives and uses.
Google and Apple sign-in are for adult account holders. Successful social sign-in does not itself establish that a person is an adult or that they are a child’s parent or guardian. Groove It must use an appropriate age and adult-confirmation flow before enabling an account or an adult-managed child-registration feature.
You can manage the connection in your Google or Apple settings. Disconnecting it may affect future sign-in, but does not necessarily delete information already held by Groove It. Deleting Groove It does not delete your Google or Apple account. Groove It processes account-deletion requests within the period in section 9. Before publication, verify that deletion invalidates Groove It sessions and revokes applicable provider authorisations, including Apple’s required token-revocation process.
4. In-house analytics and browsing controls
Anyone may explore workshop listings without creating an account. Groove It uses an in-house system to measure adults’ clicks and time spent after adult account access. This information is used internally to understand app use and improve the service. We do not give individual-user analytics or browsing records to studios, organisers, or other businesses, and we do not sell them.
For users known or reasonably likely to be under 18, Groove It does not retain or use identifiable click histories, search histories, session-duration information, registration-link histories, device identifiers, IP addresses, account identifiers, or behavioural profiles. It does not use child information for marketing, targeted advertising, or other secondary purposes. Before a user’s age status is resolved, Groove It must apply the same child-protective analytics setting.
Groove It may keep aggregate listing totals, such as the total number of views or Register-button taps, only where the measurement is designed so that it does not identify, single out, or track a child. A Register-button tap is not proof of a completed payment, registration, or attendance.
For adult analytics, registration destination URLs should be limited to the destination domain and path needed for measurement, with unnecessary query parameters removed. Groove It must not place sign-in tokens, names, email addresses, child information, or payment information in URLs or analytics events.
Our in-house analytics and app database are stored on Hostinger infrastructure in India, as configured by the operator. Hosting-provider processing remains relevant even though analytics are developed in-house and used only internally.
Adults are shown a clear notice about account-linked analytics before it starts and can contact us about their analytics information, correction, or deletion. If Groove It offers an analytics setting, it will explain how to use it in the app. Internal use and disclosure in this Policy are not substitutes for any permission required by law.
5. External registration and payment
Tapping Register opens the studio’s, organiser’s, or booking provider’s website, potentially in an in-app browser. Payment is collected by that external provider, not by Groove It. Their terms and privacy notices govern information they independently collect.
Opening an external website ordinarily exposes connection information, such as IP address and browser information, to that website. It may use cookies and similar technologies. Groove It may measure an adult user’s Register click as described above; it does not retain a child’s Register-click history.
Before publication, verify whether the in-app browser intercepts form fields, passes user identifiers to the organiser, shares app cookies, or receives booking/payment callbacks. The final Policy must accurately describe those functions. Groove It does not infer that none occurs solely because payment is made externally.
Before an under-18 user can open an external registration page, Groove It requires the parent or lawful guardian managing that child’s access to confirm the action. The adult must review the organiser, age suitability, privacy practices, payment terms, and any required consent directly with the organiser. Groove It does not collect the workshop payment.
6. Public Instagram listings
Groove It independently compiles workshop, artist, and studio information from publicly accessible Instagram posts. A listing may appear without the artist or studio having an account, submitting the listing, or approving a relationship with Groove It. Inclusion does not itself indicate partnership or endorsement.
Groove It copies workshop posters, photographs, captions, and logos from publicly accessible Instagram posts, embeds Instagram videos, manually enters factual dance-video and event details, and displays or links to the original Instagram source. Groove It does not currently charge for this listing activity. Displaying the source is attribution; it does not by itself establish permission to reproduce protected media. The app must not claim that the media is authorised unless supporting permission or another valid basis exists.
Public visibility does not automatically authorise reuse of copyrighted material, private information, or someone’s identity in a way that implies endorsement. This Policy does not grant Groove It rights belonging to the person who posted the information, the subject of the post, or a photographer or other rights holder.
Contact support@grooveit.in with the listing concerned to request a correction, source explanation, or removal, or report a privacy/copyright concern. You do not need an account. We may seek proportionate evidence of identity or authority and will review the source, issue, and rights involved. Mark urgent safety or private-data exposure concerns clearly. Proposed response commitments are set out below and require an operational process.
Listing information is publicly visible. Other people may copy it; removal from Groove It does not guarantee removal of independent copies. Account names/emails and analytics are collected for account operation and internal use, not as part of these public workshop listings.
7. Recipients and hosting
- Hostinger: Provides hosting for the app, database, and in-house analytics. Its infrastructure processes the information necessary to host and operate those systems.
- Google and Apple: Provide their respective sign-in services. Provider processing is described in their own privacy notices.
- Novu: Groove It self-hosts Novu on its Hostinger infrastructure to manage push notifications. Push delivery still involves Apple Push Notification service or Firebase Cloud Messaging/Google, depending on the user’s device.
- Sentry: Processes crash and diagnostic logs for error monitoring. Groove It’s Sentry logs receive user email addresses or account identifiers. They may also contain IP addresses, device/app information, stack traces, and actions leading to an error depending on configuration. The configured retention period and data region must still be confirmed. Sentry’s Privacy Policy describes Sentry’s own processing.
- Brevo: Processes email addresses, message content and metadata, and delivery information needed to send Groove It account and service emails. Brevo’s Privacy Policy describes Brevo’s own processing.
- Google email services: Process correspondence sent to our Gmail support address.
- Authorities and professional advisers: Information may be disclosed where legally required or otherwise lawfully necessary to respond to a specific legal matter or security incident, limited to what is appropriate for that purpose.
Groove It does not share its user analytics with studios or other businesses for their independent use. This statement does not exclude necessary hosting, sign-in, email processing, or disclosures required by law. We do not currently receive listing or registration commissions; the service is free under the described model.
The operator has confirmed that Groove It’s app database, in-house analytics, and self-hosted Novu service are stored with Hostinger in India. Sentry crash reporting, Google and Apple authentication/push delivery, Gmail, and Brevo may process information outside Hostinger and outside India. Their actual configurations and locations must be reflected in the final notice.
8. Security
Protecting personal information requires access controls, protected credentials, appropriate transmission/storage security, software maintenance, and an incident-response process. The actual security configuration has not been inspected; the published notice must describe implemented safeguards rather than claim unverified encryption, multi-factor authentication, or certification.
No service can guarantee absolute security. This does not remove any legal obligation to protect information, investigate incidents, or notify affected people and authorities when required.
9. Retention and deletion periods
Account deletion is available from the Profile section of the app. When the deletion request is confirmed, the account becomes inaccessible immediately. Groove It completes deletion of the account and associated Groove It data within 180 days, except information that must be kept for a specific legal obligation, security investigation, or legal claim. Restricted backup copies may remain until they are overwritten within that same 180-day period and will not be returned to ordinary use. If a backup is restored, the deletion request must be reapplied.
Deletion includes account information, linked analytics, Novu notification records, applicable Sentry records, active sessions, and Google/Apple sign-in connections or tokens. Groove It instructs its processors to delete applicable information. Deletion cannot remove independent records held by a studio or payment provider under its own relationship with the user.
Before publication, confirm retention periods for ordinary analytics before deletion, Sentry logs, notification records, Brevo email records, support requests, and security logs. A 180-day outer period is unusually long for routine account deletion and may need to be shortened after legal and app-store review.
10. Requests and account deletion
Use Profile → Delete Account inside Groove It to initiate deletion. The account becomes inaccessible immediately after confirmation, and deletion is completed within the 180-day period described above. You can also contact support@grooveit.in for help, access/correction requests, or privacy concerns. Before publication, create or identify the public web deletion page required for the Google Play listing.
We may need proportionate information to verify the person making a request or their authority to act for someone else. Deleting the app from a device does not by itself delete server-held information. Deleting a Groove It account does not cancel an external workshop booking or erase records independently held by a studio, Google, Apple, or a payment provider.
The proposed service target is to respond to privacy requests within 30 days, subject to shorter applicable legal deadlines. This target requires a working support process and does not extend statutory deadlines. Statutory rights and escalation routes apply as their governing provisions take effect; this draft does not present future rights as already operational.
11. Children
Groove It’s general discovery service may be viewed by children only with a parent or lawful guardian’s supervision. Children do not create independent Groove It accounts. A parent or lawful guardian creates and controls an account, manages a child’s registration and payment actions, and provides any child information directly to Groove It only for the specific purpose explained at the time.
Groove It uses child information only for that specific purpose and does not use it to create a child profile, measure child clicks or time spent, perform behavioural analytics, market to a child, or target advertising to a child. If we discover that child information was collected or used outside this model, we will take appropriate steps to stop the relevant processing and delete it where appropriate.
A parent or lawful guardian may contact support@grooveit.in to ask about, correct, delete, or withdraw permission for information relating to their child. We may verify their identity and authority before acting. Withdrawing permission may mean we cannot continue providing the child-access or workshop-related feature.
This section does not reduce any protection required by applicable law. Groove It will obtain and record any verifiable parental consent required for its actual processing activities before those activities begin.
12. Contact and updates
Operator and Grievance Officer: Luvkush Sharma, Proprietor, operating Groove it
Email: support@grooveit.in
Telephone: +91 80805 26389
Website: grooveit.in
Address: SBI Colony, 1st Phase, J. P. Nagar, Bengaluru, Karnataka 560078, India
The proposed complaint-handling target is acknowledgement within 48 hours and resolution within one month, with any stricter applicable obligation taking priority. Establish that process before publishing the commitment.
We will date policy changes and provide notice and obtain permission where legally required before introducing affected processing. A revised policy alone does not establish consent or make a previously unauthorised practice lawful.