Legal
Privacy Policy
How QuantGrid collects, uses, shares, protects and deletes personal data, and how you exercise your rights under India's Digital Personal Data Protection Act, 2023.
- Last updated
- 6 August 2026
- Applies to
- quantgrid.in and the QuantGrid platform
The 30-second version
- We hold your account details, the broker accounts you link, and the order events we need to replicate and to keep an audit trail.
- We never collect your broker password or trading PIN. We use the API access token your broker issues, and only to run the replication rules you configured.
- We do not sell personal data, we do not trade on our own account, and we do not package your order flow as market data.
- Card details go straight to Razorpay. They never reach our servers.
- Your data is stored in India, in AWS's Mumbai region, backups included.
- You can ask for a copy of your data, correct it, delete it or withdraw consent by writing to privacy@quantgrid.in. We respond within 30 days.
This summary is for orientation only. The sections below govern.
1. Scope and who we are
This Privacy Policy explains how Tristack Technologies LLP ("we", "us") handles personal data when you visit quantgrid.in, create an account, link a broker account, or contact us. It applies to the marketing website and to the QuantGrid replication platform.
QuantGrid is the brand and the product. Tristack Technologies LLP is the limited liability partnership that operates it, contracts with you, issues your invoice and answers for the personal data described here. Where this policy says QuantGrid does or does not do something, it is Tristack Technologies LLP making that commitment.
Under the Digital Personal Data Protection Act, 2023 (the DPDP Act), we are the Data Fiduciary for the personal data described here, and you are the Data Principal. We are also an intermediary for the purposes of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, and we publish the Grievance Officer details those rules require in section 14. If you are in the European Economic Area or the United Kingdom, we act as the controller of your data, and section 9 sets out the equivalent rights we honour.
QuantGrid is a technology platform for order replication. It is not registered with SEBI, does not provide investment advice, and never holds your funds or securities. Your money, your holdings and your trading account remain with your own SEBI-registered broker at all times. See Compliance for the full position.
The Data Fiduciary, and how to reach it
- Legal entity
- Tristack Technologies LLP
- LLPIN
- ACP-3743
- GSTIN
- 07AAYFT2516N1ZF
- Registered office
- B-35, Vinoba Kunj Apartments, Sector 9, Rohini, Delhi 110085, India
- Privacy contact
- privacy@quantgrid.in
- Grievance Officer
- Devansh Dalmia, grievance@quantgrid.in (see section 14)
- Telephone
- call us
- Service status
- quantgrid.in/status
Write to privacy@quantgrid.in for anything about your personal data, and to the Grievance Officer in section 14 if a request is not handled to your satisfaction. We answer email Monday to Friday, 8:00 AM to 5:00 PM IST.
2. What we collect
We collect only what the service needs. The table below is the complete list of categories, what each one contains, and where it comes from.
| Category | What it includes | Where it comes from |
|---|---|---|
| Account data | Your name, email address, password (stored only as a one-way hash), the Google account identifier if you sign in with Google, and the record of when you verified your email address. | You, at sign-up. |
| Billing contact details | The details a GST invoice has to be made out to: mobile number, address line 1 and line 2, city, state and PIN code, plus your GSTIN if you have one. The GSTIN is optional, because only a registered business has one. The mobile number is also what the payment gateway pre-fills at checkout and where the payment OTP goes. | You, before your first payment. |
| Broker connection data | Broker name, broker account or client identifier, API key or app id, and the API access token your broker issues after you authorise QuantGrid. Also the master and child roles, copy factors, lot sizes and maximum-quantity limits you configure. | You, plus your broker at the point of authorisation. |
| Trading data | Order and execution events for the accounts you link: symbol, exchange, side, quantity, filled quantity, price, product type, order status, broker order id, timestamps, and the replication decisions QuantGrid took in response. | Your broker API, over the order WebSocket and REST order book. |
| Billing data | Your prepaid wallet balance, the history of every top-up and every deduction against it, the dedicated static IP addresses those deductions paid for, the GST tax invoice raised for each top-up, and the payment references Razorpay returns with the amount and status of each payment. Card, UPI and net-banking credentials are entered on Razorpay's own checkout and never reach us. | You and Razorpay. |
| Technical data | IP address, the dedicated static IP assigned to your account, device and browser information, timezone, and application and access logs including error traces. | Automatically, when you use the site or the platform. |
| Support correspondence | Emails, contact-form submissions, demo requests and any screenshots or logs you send us while we work on an issue. | You. |
| Website traffic metadata | Pages requested, the referring page, browser and device user agent, approximate city-level location derived from your IP address, and aggregate request counts for quantgrid.in. Read from the requests our CDN already handles in order to serve the page, not from an analytics cookie or a third-party tracking script. | Automatically, from the request itself. |
We do not collect special-category data, we do not run credit checks, and we do not buy personal data from data brokers or list vendors.
3. Why we process it, and on what basis
The DPDP Act allows processing either with your consent or for certain legitimate uses. Each purpose below names the categories from section 2 that it draws on, and the basis we rely on. Where we rely on consent, you can withdraw it, and section 9 explains how.
| Purpose | Categories used | Basis |
|---|---|---|
| Create and operate your account, authenticate you, and provide support | Account data, support correspondence | Performance of the contract you enter into under our Terms, which is a legitimate use under the DPDP Act because you voluntarily provided the data for this service. |
| Connect to your broker and run replication exactly as you configured it | Broker connection data, trading data | Your explicit consent, given when you authorise QuantGrid on the broker consent screen, together with performance of the contract. |
| Maintain the audit trail: every event received, every decision taken, every broker response | Trading data, technical data | Performance of the contract, and our own legitimate use in keeping records that let either of us reconstruct what happened. |
| Reserve and route your dedicated static IP, and keep the platform available and secure | Technical data | Legitimate use for the security of the service and prevention of misuse. |
| Send you the alerts you switch on, such as Telegram notifications for fills, rejections and connection loss | Account data, trading data | Your consent, which you can withdraw by turning the alert off. |
| Take payment, issue a GST invoice made out to you, and meet tax and accounting obligations | Billing contact details, billing data, account data | Performance of the contract, and compliance with Indian tax and GST law, which requires an invoice to carry the customer's name and address and, where you have one, your GSTIN. Your mobile number goes to the payment gateway so checkout can pre-fill it and the payment OTP can reach you. |
| Send service messages: renewal and low-balance notices, incident notices, changes to these documents | Account data | Legitimate use. These are not marketing messages and cannot be switched off while your account is open. |
| Measure in aggregate how the public website is used, and keep it available and free of abusive traffic | Website traffic metadata, technical data | Legitimate use for the security and availability of the service. The measurement is aggregate and derived from requests we have to handle anyway to serve the page, not from a tracking cookie. |
We do not use your data for automated decisions that produce a legal effect on you, and we do not profile you for advertising. Replication itself is automated, but it executes the rules you set: your chosen master account, your copy factor, your lot size, your maximum quantity.
4. Broker API data
This is the most sensitive thing you entrust to us, so we will be exact about it.
What we fetch
Once you authorise QuantGrid on your broker consent screen, we hold the access token that broker issues. Using it, we subscribe to the order-update stream for the accounts you have linked and read the order book over REST as a fallback when a socket drops. From those sources we take order and execution events: symbol, exchange, side, quantity, filled quantity, price, product type, order status, broker order id and timestamps. We read positions and holdings when you open a positions view or use square-off. We place child orders on the accounts you have designated as children, at the quantity your configuration produces.
What we do with it
Broker API data is used for exactly three things: running replication for your own linked accounts, showing you your own trade log and positions, and writing the audit trail that lets you reconstruct what happened and when. Nothing else.
What we never do with it
- We never sell it. Not to data buyers, not to brokers, not to research firms, not to anyone.
- We never trade on it. QuantGrid does not operate a proprietary trading book. Your orders are not a signal we act on, front-run or hedge against.
- We never aggregate and sell it as market data. Your order flow is not packaged, anonymised and resold as sentiment, flow or analytics products.
- We never use it to trade for anyone else. One subscriber's order events reach only that subscriber's replication engine, enforced by tenant isolation at the point the broker stream is opened.
Access tokens are encrypted at rest and are never written to application logs. You can revoke our access from your broker console at any time, and the connection stops immediately. You can also disconnect a broker account inside QuantGrid, which deletes the stored token straight away. Historical order records for orders already placed are kept for the retention period in section 7, because they are the audit trail for trades that really happened in your account.
5. Sharing and processors
We do not sell personal data, and we do not share it for anyone else's marketing. We share it only with the processors below, each bound by contract to process it only on our instructions, and only for the function named.
| Processor | What it handles | Location |
|---|---|---|
| Amazon Web Services (AWS) | Provides the infrastructure the whole platform runs on: the application servers, the PostgreSQL database, the Redis cache and the encrypted database backups in S3. Every category in section 2 sits on it, encrypted at rest. AWS supplies capacity and does not use your data for its own purposes. | India. The ap-south-1 (Mumbai) region, backups included. |
| Razorpay | Takes the one-time payments by which you top up your prepaid wallet balance. No recurring mandate, standing instruction or auto-debit is ever created: each top-up is a separate payment you start, and address fees are then deducted from a balance you have already paid for rather than from any payment instrument. Razorpay receives your name, email address and mobile number, the amount, and an internal reference that lets us match a payment to your account. Card, UPI and net-banking credentials are entered on Razorpay's own checkout and never reach us: we get back a payment reference, the amount and the status. Razorpay also emails you its own payment receipts. | India. |
| Zoho Mail | Delivers our transactional email: address verification, password resets, invoices, renewal reminders and incident notices. Receives your name, your email address and the contents of those messages. | India. Our mailbox is on Zoho's India region (smtp.zoho.in). |
| Telegram | Delivers trade alerts and order-approval prompts, and only where you have linked a Telegram chat to your account. Receives the chat identifier you linked and the alert text, which carries order details for your own accounts: symbol, side, quantity and status. Link no chat and Telegram receives nothing about you. | Outside India. |
| Cloudflare | DNS and reverse proxy in front of our sites. Every request passes through it, so it terminates TLS and processes request metadata: your IP address, the page requested, the user agent and the timing. It also absorbs automated and abusive traffic. It carries traffic rather than storing your account records. | Global edge network. Your request is served by the Cloudflare location nearest you, which may be outside India. |
Beyond those processors, we disclose personal data only when:
- you tell us to, for example by connecting a Telegram chat or asking us to talk to your broker about a connection problem;
- a law, a court order, a regulator, or a lawful request from a government agency requires it, in which case we disclose the minimum the request covers and, unless we are legally barred, we tell you;
- it is needed to establish, exercise or defend a legal claim, or to investigate fraud or abuse of the platform;
- the business is merged, acquired or reorganised, in which case data moves to the successor under this same policy and we notify you before it takes effect.
Your broker also receives data from us: the orders we place on your instruction. That is the whole point of the service, and your relationship with your broker is governed by the broker agreement and the broker privacy policy, not by this one.
If you sign in with Google, you authenticate on Google's own page and Google tells us your email address and account identifier. That is data flowing from Google to us, not from us to Google, and your use of Google is governed by Google's privacy policy. Sign in with an email address and password instead and Google is not involved at all.
6. Cookies and local storage
We keep cookies to a minimum, and the public website at quantgrid.in sets none of its own. We run no analytics scripts, no advertising cookies, no cross-site tracking pixels, no retargeting tags and no social-media trackers, and we do not sell or share cookie data with anyone. There is no cookie banner because there is nothing optional to consent to. The Cookie Policy sets the same position out in full, item by item; this section is the summary, and the two are revised together.
| Name | Purpose | Type | Control |
|---|---|---|---|
| Cloudflare security cookie | Cloudflare, the CDN in front of our sites, may set a cookie such as __cf_bm to tell automated traffic apart from human visitors and keep abusive traffic off the site. It carries no advertising or cross-site tracking function. | Strictly necessary | Expires on its own shortly after your last request. Blocking it can stop the site loading. |
| Sign-in session | Not a cookie. The application keeps your signed-in session in your browser's own local storage, and the token is sent only to our API. | Not a cookie | Signing out removes it, as does clearing site data in your browser. |
We do measure traffic, but from the aggregate request counts our CDN reports rather than from a cookie or a script in your browser. Those counts are pages and volumes, not people, and section 2 describes what the underlying request metadata contains.
You can block or delete cookies in your browser settings at any time. Blocking the security cookie can stop the site from loading, and clearing site data signs you out of the application. Nothing else changes: every page, price and document stays fully readable. If we ever add an optional cookie or a third-party analytics script, we will ask for your consent before it runs and revise this section under section 13. If you have a question about a specific cookie, write to privacy@quantgrid.in and we will tell you precisely what it does.
7. How long we keep it
We keep personal data only as long as the purpose in section 3 lasts, or as long as a law requires, whichever is longer. When a period ends, data is deleted or irreversibly aggregated.
| Data | Retention period |
|---|---|
| Account data | For as long as your account is open, then 12 months after closure. |
| Broker access tokens | Until they expire, which for most brokers is the same trading day. Deleted immediately when you disconnect the account or revoke access at the broker. |
| Trading data and the replication audit trail | At least 5 years, because it is the record of what was placed in your account and why. |
| Billing contact details | For as long as your account is open, then 12 months after closure. Details already printed on an issued invoice stay on that invoice for the period below. |
| Billing records and invoices | 8 financial years, as required by Indian tax and company law. |
| Technical and access logs | 180 days, then deleted or aggregated beyond re-identification. |
| Support correspondence | 24 months after the conversation closes. |
| Website traffic metadata | Aggregate counts only, kept no longer than 14 months. The underlying request logs follow the 180 day period above. |
Audit and financial records are the exception to erasure. Where Indian tax, company or information-technology law obliges us to retain a record, we retain it for the statutory period even if you close your account and ask for deletion. In that case we restrict the record so it is used for nothing except meeting that obligation, and we delete it when the period expires.
8. How we protect it
We apply reasonable security safeguards appropriate to the sensitivity of the data, as the DPDP Act requires. In concrete terms:
- Encryption in transit and at rest. All traffic runs over TLS. Broker tokens and account secrets are encrypted at rest.
- Tokens are never logged. Access tokens and secrets are excluded from application logs, error traces and telemetry, including the WebSocket handshake URLs that would otherwise carry a token.
- Tenant isolation. Each account's data is bound to its own tenant where the broker stream is opened, so one subscriber's order events cannot reach another subscriber's replication engine.
- A dedicated static IP per account. Your broker API traffic leaves from an address reserved to you and never shared with another customer.
- Backups that stay in India. Database backups are encrypted, versioned so a bad write cannot overwrite the good copies, and stored in the same Indian AWS region as the database itself.
- Access control. Passwords are stored only as one-way hashes. Production access is limited to the people who need it to operate the service, over authenticated sessions, and administrative actions are logged.
- Append-only audit trail. Every event received, decision taken and broker response is recorded, which is also how we detect anything anomalous.
We hold no security certification and we do not claim one. Security describes these controls in more detail. No system is perfectly secure, so please use a strong unique password, keep your broker 2FA to yourself, and disconnect broker accounts you no longer use.
9. Your rights
As a Data Principal under the DPDP Act you have the following rights. Exercise any of them by emailing privacy@quantgrid.in from the address registered on your account, or by using the contact form at Contact. We acknowledge within 3 working days and respond substantively within 30 days of verifying who you are.
Right to access information
Ask for a summary of the personal data we hold about you, what we are doing with it, and which processors have received it. We return it in a readable format, and your trade log and audit trail are exportable from the application at any time without asking us.
Right to correction and erasure
Ask us to correct anything inaccurate, complete anything incomplete, update anything stale, or erase personal data that is no longer needed for the purpose it was collected for. Account and broker-connection details can be corrected directly in the application. Erasure is subject to the statutory retention in section 7.
Right to withdraw consent
Where we rely on consent, you can withdraw it as easily as you gave it: disconnect a broker account to stop broker data processing, unlink your Telegram chat to stop alert delivery, or write to us. Withdrawal takes effect going forward and does not make earlier processing unlawful. Withdrawing consent for broker access necessarily stops replication on that account.
Right of grievance redressal
If any request is not handled to your satisfaction, escalate to our Grievance Officer in section 14 before approaching the Data Protection Board of India. You may complain to the Board if we fail to resolve it.
Right to nominate
You may nominate another individual to exercise these rights on your behalf if you die or become incapacitated. Send the nominee name, relationship and contact details to privacy@quantgrid.in and we will record it against your account. Note that a nomination here covers your personal data with us only. It has no effect on the funds or securities held at your broker, which follow the broker nomination process.
If you are in the EEA or the UK
We honour the equivalent GDPR rights for visitors in the European Economic Area and the United Kingdom: access, rectification, erasure, restriction of processing, data portability, objection to processing based on legitimate interests, and the right to lodge a complaint with your local supervisory authority. Where we rely on a legitimate interest, it is the operation and security of a service you asked for. QuantGrid is built for Indian markets and Indian brokers, and it is not offered to residents of jurisdictions where it would need a licence we do not hold.
Duties that come with these rights
The DPDP Act asks Data Principals not to file false or frivolous complaints, not to impersonate another person when providing data, and to give authentic information when exercising the right to correction. We may refuse a request that is manifestly unfounded or repetitive, and we will say why.
10. Children
QuantGrid is not for anyone under 18. You must be 18 or older to open an account, which matches the requirement to hold a trading account with an Indian broker. We do not knowingly collect personal data from a child, we do not profile children, and we do not direct advertising at them.
If we learn that an account belongs to someone under 18, or to a person with a disability who has a lawful guardian, we will suspend it and delete the associated personal data unless a law requires us to keep a record. If you believe a child has given us personal data, write to privacy@quantgrid.in and we will act on it promptly.
11. Cross-border transfer
Your data is stored in India. The application servers, the PostgreSQL database, the Redis cache and the encrypted backups all sit in the AWS ap-south-1 (Mumbai) region. Your account, your broker connections, your order records and the replication audit trail are held there and nowhere else. Payments run through Razorpay in India, and our transactional email runs on Zoho's India region.
Two things do cross the border, and we would rather name them than claim nothing leaves India:
- Cloudflare is a global edge network. Requests to our sites are answered by whichever Cloudflare location is nearest you, which may be outside India, so TLS termination and the request metadata described in section 5 can be handled abroad while a page or an API call is in flight. Cloudflare carries the traffic; it does not hold your account records or your audit trail.
- Telegram operates outside India. It receives an alert only where you have linked a Telegram chat to your account, and only the alert text and the chat identifier. Unlink the chat and that transfer stops.
The DPDP Act permits transfer of personal data outside India except to countries the Central Government restricts by notification. We do not transfer personal data to any restricted territory, and if a territory becomes restricted we will move or stop that processing. Wherever data goes, the processor is bound by contract to the same confidentiality, security and purpose-limitation terms set out here, and the protections in this policy travel with your data.
12. Breach notification
If personal data in our care is breached, we will:
- contain the incident, preserve evidence and begin an investigation as soon as we detect it;
- notify the Indian Computer Emergency Response Team (CERT-In) within 6 hours of becoming aware, for incident classes the CERT-In directions cover;
- notify the Data Protection Board of India and every affected Data Principal without undue delay, in the form and manner the DPDP Act and its rules prescribe;
- tell you plainly what happened, which of your data was involved, what we have done, and what you should do, such as re-authorising broker connections or changing your password;
- publish a post-incident summary and the fixes made.
We will not quietly absorb an incident that affected you. If you suspect a security problem with your account, write to support@quantgrid.in immediately and revoke API access at your broker console, which stops all replication on that account at once.
13. Changes to this policy
We update this policy when the product, our processors or the law changes. The current version always carries a last-updated date at the top of this page. This version is effective 6 August 2026.
For a material change, meaning one that expands what we collect, adds a purpose, adds a category of recipient, or reduces your rights, we will give notice by email to your registered address and by a notice inside the application at least 14 days before it takes effect. Continuing to use QuantGrid after a change takes effect means you accept the updated policy. Where the change relies on consent, we will ask for consent again rather than assume it.
This policy sits alongside our Terms of Service, Refund and Cancellation Policy, Disclaimer and Risk Disclosure.
14. Grievance Officer
In accordance with the Information Technology Act, 2000, the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, and the Digital Personal Data Protection Act, 2023, the contact details of our Grievance Officer are published below. The Grievance Officer is the point of escalation for any complaint about how your personal data has been handled.
- Name
- Devansh Dalmia
- Designation
- Grievance Officer, Tristack Technologies LLP
- Telephone
- call us
- Address
- B-35, Vinoba Kunj Apartments, Sector 9, Rohini, Delhi 110085, India
- Hours
- Monday to Friday, 8:00 AM to 5:00 PM IST
Email is the route to the Grievance Officer, and a complaint sent to grievance@quantgrid.in is on the record from the moment it arrives. A complaint sent by post to the registered address above is equally valid.
Statutory response window. The Grievance Officer acknowledges every complaint within 24 hours of receipt and resolves it within 15 days, as the IT Rules, 2021 require. Data-protection requests under section 9 are answered within 30 days. Please include your registered email address, the account or broker connection concerned, and what outcome you are asking for, so we can act without a round trip.
If we do not resolve your grievance, you may complain to the Data Protection Board of India under the DPDP Act.
Questions about this document
Write to legal@quantgrid.in, or reach the Grievance Officer, Devansh Dalmia, at grievance@quantgrid.in or by phone: call us. Every policy on this site is published by Tristack Technologies LLP, which operates QuantGrid and is the entity you contract with.
Registered office: B-35, Vinoba Kunj Apartments, Sector 9, Rohini, Delhi 110085, India · LLPIN ACP-3743 · GSTIN 07AAYFT2516N1ZFSee also Terms, Privacy, Cookies, Refunds, Service delivery, Disclaimer and Risk disclosure.