Privacy Policy
Last updated: 28 September 2025
EarnNGrow is operated from India. This policy explains what we collect and why, and is written to comply with the Information Technology Act 2000 and its Reasonable Security Practices rules, and with the Digital Personal Data Protection Act 2023.
1. What we collect
- Account data: username, email address and a bcrypt hash of your password. We never store your password itself.
- Campaign data: the public post or profile URLs you submit, the platform and action, your budget and pacing settings.
- Activity data: credits earned and spent, tasks completed, and the IP address recorded with a completed task. The IP is kept solely to detect fraud and multiple accounts.
- Payment data: the package, amount in rupees and Razorpay order and payment identifiers. Card numbers, UPI PINs and bank credentials are handled entirely by Razorpay and never reach our servers.
2. What we do not collect
We never ask for the password to your Instagram, YouTube, TikTok, Facebook or X account, and you should never give it to us or to anyone claiming to be us. We do not read your private messages and we have no access to your social accounts. Every action is performed by a human member in their own browser.
3. Why we process it
- To operate your account, campaigns and credit ledger.
- To prevent fraud, false task confirmations, bots and duplicate accounts.
- To process payments and issue refunds.
- To send transactional email such as a password reset.
We do not sell your personal data, and we do not share it for advertising.
4. Who we share it with
- Razorpay — payment processing.
- Hosting and database providers — to run the service.
- Law enforcement — only where we are legally required to.
Other members see only the public post or profile URL of a campaign they work on. They never see your email, your balance or your identity.
5. Retention
Account and ledger records are kept while your account exists and for as long afterwards as Indian financial record-keeping rules require. Task IP addresses are retained for fraud review and then discarded.
6. Security
Passwords are hashed with bcrypt. Sessions use short-lived JWT access tokens with separate refresh tokens. Traffic is served over HTTPS. Payment webhooks are verified with an HMAC-SHA256 signature. No system is perfect, so please use a unique password and tell us immediately if you suspect a problem.
7. Your rights
You may access, correct or delete your personal data, or withdraw consent, by contacting us through the FAQ page. Deleting your account removes your personal data; anonymised ledger rows may be retained for accounting integrity. Unspent credits are forfeited on deletion.
8. Children
The service is not directed at children under 13. If you believe a child has given us personal data, contact us and we will remove it.
9. Cookies and local storage
We store your login tokens in your browser's local storage so you stay signed in. We do not use third-party advertising or tracking cookies.
10. Changes
We will post any change to this policy on this page and update the date above. Material changes will also be announced in the app.