Legal
Last updated: 1 August 2026
This Privacy Policy explains how GlobalSpatialWork ("we", "us") collects, uses, stores and protects your personal data when you use globalspatialwork.com. It is published in accordance with the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and the Digital Personal Data Protection Act, 2023 ("DPDP Act").
Account data: name, email address, password (stored as a salted bcrypt hash), role, profile details (skills, bio, hourly rate, location, portfolio).
KYC data (sensitive): identity documents such as PAN, Aadhaar, passport, address proof, and selfies — collected solely for identity verification and withdrawal compliance.
Transaction data: payment references, escrow and withdrawal records. Full card/banking details are processed by our payment partners (Razorpay, PayPal, Stripe) and never stored on our servers.
Content: projects, bids, jobs, applications, resumes, messages and uploaded files.
Technical data: IP address, browser/user-agent, approximate location (for currency defaults), and activity logs used for security auditing.
We use your data to: operate the marketplace (matching, contracts, escrow, messaging); verify identity (KYC) and prevent fraud; process payments and withdrawals; send transactional emails (e.g., password resets, escrow notifications); improve the Platform; and comply with legal obligations, including tax and AML requirements.
We process personal data with your consent given at registration and upload, for the performance of the contract between you and the Platform, and for compliance with law. You may withdraw consent by closing your account, subject to data we must retain by law.
We share data only with: payment gateways (for processing payments/payouts); cloud infrastructure and object-storage providers (for hosting and file storage); email delivery providers (for transactional email); Google (if you sign in with Google); and law-enforcement or regulators where required by law. We do not sell your personal data.
We follow reasonable security practices under the SPDI Rules, 2011: encrypted transport (HTTPS), hashed passwords, role-based access controls, immutable audit logging of sensitive actions, rate-limited authentication, and restricted access to KYC documents (owner and authorised administrators only).
Account data is retained while your account is active. Transaction and KYC records are retained as required by financial regulations (typically up to 8 years under Indian law) even after account closure. Messages and files linked to disputes are retained until the dispute and appeal window closes.
Under the DPDP Act you may request: access to your personal data; correction of inaccurate data; erasure of data no longer required; and grievance redressal. Send requests to our Grievance Officer (see Grievance Officer page). We respond within statutory timelines.
We use strictly necessary cookies for authentication (httpOnly JWT session cookies) and a small number of preference cookies (e.g., selected currency). We do not use third-party advertising cookies.
The Platform is not intended for persons under 18. We do not knowingly collect data from minors.
We may update this policy from time to time; material changes will be notified on the Platform.