Privacy
Your details, handled with care.
What personal data we collect, why, where it's kept, who can see it, and the rights you have under Indian law. Last updated: 22 September 2026.
1. Who we are
LetsGeko.com ("LetsGeko", "we", "us") is a studio for local businesses in India, offering branding, social media and reels, production, paid ads, SEO, websites, creator campaigns and HR & compliance services. For the personal data described here, we are the Data Fiduciary: we decide why and how it's used.
This policy covers letsgeko.com, our forms, our team dashboard, and the emails we exchange with you. It should be read together with our Terms and Conditions.
2. Laws we follow
- the Digital Personal Data Protection Act, 2023 ("DPDP Act") and the Digital Personal Data Protection Rules, 2025;
- the Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011;
- the CERT-In directions under section 70B of the IT Act on reporting cyber security incidents;
- the Consumer Protection Act, 2019 and the CCPA Guidelines for Prevention and Regulation of Dark Patterns, 2023 (so we never use tricks to get your consent);
- tax and accounting laws that require us to keep certain business records.
3. What we collect
We only collect what you choose to send us, plus a small amount of technical data to keep the website safe.
- Contact form: your name, business name, email, phone or WhatsApp number (optional), type of business, the services you're interested in, and your message.
- Creator application: your name, Instagram handle, follower count, niche, city, email, phone number (optional), a note about your content, and a record that you agreed to the creator terms (with the date and time).
- Staffing request: your business name, your name, email, phone number, city, the roles and headcount you need, a start date (optional) and any details you add.
- Emails and messages: what you write to hello@letsgeko.com or support@letsgeko.com, or to us on WhatsApp or Instagram.
- Clients: billing details (business name, address, GSTIN, PAN), and access you give us to your social media, ad or website accounts while we work for you.
- Team dashboard: for LetsGeko team members who sign in with their Google account, we record their name, email address, Google account ID and sign-in times.
- Technical data: the page a form was sent from, any campaign tags in the link you arrived through (such as
utm_source), and a scrambled one-way code made from your internet (IP) address, used only to stop spam and repeated submissions. That code can't be turned back into your address. Our hosting provider also keeps standard server logs (IP address, browser type, pages requested and time) for security for a short time.
We don't ask for sensitive details such as passwords, bank account or card numbers, health records, biometric data or Aadhaar numbers through the website. Please don't include them in a form.
4. Creators: your photos, face and profile
If you join our creator community, and only with the consent you give by ticking the terms box, we show your name, Instagram handle, profile photo, photos or videos of you (including your face and likeness), niche, city and public follower count on our website, social media, proposals and pitch decks, to feature you and help brands discover you.
- We only use public profile information or content you've shared with us for this purpose.
- We don't sell your data, and we don't give your email or phone number to a brand without asking you first.
- You can withdraw this consent at any time by emailing support@letsgeko.com. We'll remove your profile and images from our website within 7 working days and stop using them in new material. Withdrawing doesn't affect use before you withdrew, or posts already published under a paid campaign you agreed to.
5. Why we use it
We use personal data only for the purposes we collected it for, and only on a lawful basis under the DPDP Act:
- With your consent (DPDP Act, section 6): to reply to your enquiry, send a proposal, review your creator application, feature creators, and handle staffing requests. You give this consent by sending a form, and for creators by ticking the terms box.
- For legitimate uses (DPDP Act, section 7): to provide the services you've asked for and voluntarily shared data for, to meet our legal duties (such as tax and accounting records), and to respond to lawful requests from authorities.
- To keep things safe: to protect the website and dashboard from spam, fraud and misuse.
We don't sell or rent personal data, we don't use it for automated decisions about you, and we won't send you marketing emails unless you ask us to. You can stop any messages from us at any time.
6. Cookies and browser storage
- We don't use advertising, tracking or analytics cookies on the public website.
- While you browse, your browser keeps two small notes for that visit only (session storage): one so the intro animation doesn't replay, and one so campaign tags reach the form. They're deleted when you close the tab.
- On the team dashboard only, Google's "Sign in with Google" sets its own cookies to sign team members in, and the dashboard keeps a sign-in token in session storage that ends after 12 hours or when the tab is closed.
- Embedded or linked services (such as Instagram or WhatsApp) may set their own cookies when you use them. Their privacy policies apply.
7. Who we share it with
Only our team can open form submissions, and each team member only sees what their role needs (for example, creator applications are only visible to the people who handle them). We share personal data only with:
- Service providers who process data for us (Data Processors), under contracts that require them to keep it safe: Hostinger (website hosting and database) and Google Workspace (our business email and team sign-in).
- Businesses and brands, only when needed for what you asked for, for example introducing a creator to a brand with the creator's permission, or sharing candidate profiles with a client for a staffing request.
- Government authorities, courts or regulators, when the law requires it.
- A buyer or successor, if LetsGeko's business is ever transferred, who must keep protecting your data under this policy.
8. Where it's stored
The website and its database run on Hostinger servers in India (Mumbai data centre). Form submissions are stored in a private database that can't be reached from the internet, and a copy of each notification is sent to our Google Workspace inbox. Google may process email data on servers outside India. The DPDP Act allows this except to countries the Government of India restricts, and we'll follow any such restriction.
9. How long we keep it
- Enquiries and staffing requests: while we're talking or working together, and for up to 24 months afterwards, then deleted.
- Creator applications and profiles: for as long as you're in the community. If an application isn't accepted, we keep it for up to 12 months in case a good fit comes up, then delete it. After you leave, we delete your details within 30 days, except the record that you agreed to the terms, which we keep for up to 3 years as proof of consent.
- Invoices, contracts and tax records: for as long as tax, GST and accounting laws require, usually up to 8 years.
- Security data (scrambled IP codes, rate-limit records and server logs): usually a few days to a few months, or longer if needed to investigate a security incident as CERT-In directions require.
Under the DPDP Act, we'll also delete personal data once its purpose is served, or when you withdraw consent, unless the law requires us to keep it.
10. How we keep it safe
We follow reasonable security practices as required by the IT Act, 2000, the 2011 Rules and the DPDP Rules, 2025, including:
- serving the website only over secure HTTPS connections;
- keeping submissions in a private database, with passwords and secret keys stored outside the code;
- allowing dashboard access only to @letsgeko.com team accounts signed in with Google, with role-based access, sessions that end after 12 hours, and the ability to block an account instantly;
- checking and rate-limiting every form to stop spam and abuse, and storing IP addresses only as scrambled codes;
- giving team members access only to what their job needs, and requiring them to keep it confidential.
No system is perfectly secure. If a personal data breach happens, we'll inform the Data Protection Board of India and the affected people as the DPDP Act and Rules require, explaining what happened, the likely impact and what we're doing about it, and report cyber security incidents to CERT-In within the time its directions require.
11. Your rights
Under the DPDP Act, 2023, you have the right to:
- Access: get a summary of the personal data we hold about you, how we use it, and who we've shared it with;
- Correction and completion: have inaccurate or incomplete data corrected or updated;
- Erasure: have your data deleted when it's no longer needed or you withdraw consent, unless the law requires us to keep it;
- Withdraw consent: at any time, as easily as you gave it. This doesn't affect what we did before you withdrew;
- Grievance redressal: have your complaints handled by us, and then by the Data Protection Board of India if you're not satisfied;
- Nominate: name another person to use these rights for you if you die or can't act yourself.
To use any right, email support@letsgeko.com with the subject "Privacy request". We may ask you to confirm your identity before acting. We reply within 30 days at the latest. As the DPDP Act expects of you too, please give accurate information and don't file false or frivolous complaints.
12. Children
This website is meant for businesses and adult creators. Please don't send us a form if you're under 18. If a child under 18 wants to join our creator community, a parent or legal guardian must apply and give verifiable consent, as the DPDP Act requires. We don't track children, target ads at them, or knowingly collect their data without that consent. If you think a child has sent us data, email us and we'll delete it.
13. Grievance Officer and complaints
In line with the IT Act, 2000, the 2011 Rules and the DPDP Act, 2023, you can contact our Grievance Officer about any privacy concern or complaint:
- Grievance Officer, LetsGeko.com
- Email: support@letsgeko.com (subject: "Grievance")
- Phone: +91 79904 57825
- We acknowledge complaints within 48 hours and resolve them within 30 days.
If you're not happy with our response, you can complain to the Data Protection Board of India.
14. Changes to this policy
If we change how we handle personal data, we'll update this page and the date at the top. If a change is significant, or needs fresh consent, we'll tell you by email or on the website before it applies.