Privacy policy
Effective 3 September 2026
Two kinds of people appear in Icepik: our customers, and the business contacts our customers write to. This policy explains what we hold about each, who processes it for us, how long we keep it, and how to exercise your rights. It also serves as the data-processing terms between Icepik and its customers.
1. Who is responsible
Gander Ecommerce Solutions Private Limited (CIN U72900KA2022PTC166618), [Registered office address], Bengaluru, Karnataka, India, operates Icepik and is the data fiduciary (controller) for customer account data. For the business contacts our customers research and email (“leads”), the customer is the fiduciary and we are the data processor acting on their instructions. Grievance Officer under India’s Digital Personal Data Protection Act, 2023: Chetan Nagendra, Director, [email protected].
2. If you are a customer
What we collect
- Account: name, work email, password hash, team memberships, sign-in sessions, IP address and browser details for security and rate limiting.
- Company profile: your domain and the company information, documents, templates, facts and instructions you add.
- Billing: wallet balance, ledger of grants, charges and top-ups, and payment records (order and payment identifiers, amount, currency). Card and bank details are handled by Razorpay and never reach our servers.
- Usage: the actions the Service performs for you (emails sent, replies handled, steering messages), model and provider usage, and logs needed to run and secure the Service.
- Communications: support emails and the transactional emails we send you (welcome, password reset, billing notices).
Why and on what basis
To provide the Service under our contract with you; to bill you; to secure the Service and prevent abuse (legitimate interest); to send service notices; to comply with law. Marketing email to customers is sent only with consent and can be stopped from Account settings or the unsubscribe link.
3. If you are someone an Icepik customer contacted
A customer using Icepik asked us to find and write to people whose job makes the customer’s offer relevant. To do that we process, on the customer’s instructions:
- your name, job title, employer, work email address, business location and, where public, your professional profile link and phone number, obtained from Apollo.io, Google Maps business listings and the public web;
- public information about your employer used to make the email relevant (what the company does, recent public signals);
- the emails sent to you, your replies, and how the conversation was classified.
The lawful basis relied on by the customer is normally legitimate interest in business-to-business marketing (or the equivalent under local law). Every email carries the customer’s identity and a way to opt out; replying “unsubscribe” or using the link adds you to that customer’s suppression list immediately and stops all follow-ups. If you would rather be excluded from all Icepik customers, write to [email protected] and we will add you to a global suppression list.
To exercise rights of access, correction or erasure over data a customer holds about you, contact that customer (their name is in the email you received) or us, and we will pass the request on and assist.
4. Processors and sub-processors
We use the following providers, each under contract and only for the purpose stated. Some are outside India; transfers rely on the provider’s standard contractual terms.
- Apollo.io (US): business contact and company data.
- Apify (Czech Republic / US): collection of public web pages and Google Maps listings.
- Anthropic (US): language models that research, score, draft and classify. Prompts contain company facts, lead records and message text; Anthropic does not train on API data.
- Ollama cloud models (US), routed through infrastructure we operate: research summaries and fit scoring.
- Resend (US): sending and receiving email, webhook delivery.
- Razorpay (India): payments.
- Cloudflare (US): DNS, TLS, web application firewall, bot protection (Turnstile) on sign-in and sign-up forms.
- CRMs you connect (for example Zoho CRM): receive the leads and conversations you choose to push.
- Hosting: our own servers in India, and Google Cloud (region to be published when production moves there).
We will update this list before adding a sub-processor that handles personal data; customers may object by email within 14 days.
5. Retention
- Account and billing records: for the life of the account and 7 years after for tax and accounting law.
- Leads, drafts and conversations: until the customer deletes the campaign, project or account, after which they are erased within 30 days from live systems and 90 days from backups.
- Suppression lists: kept as long as needed to honour the opt-out, as hashed email addresses.
- Security and access logs: 90 days.
- Model provider retention is governed by their terms (Anthropic: zero data retention for API traffic where enabled; otherwise up to 30 days for abuse monitoring).
6. Security
Data is encrypted in transit (TLS) and at rest on our servers. Passwords are hashed. Access is limited to staff who need it, protected by hardware-backed authentication. Webhooks from providers are signature-verified. Sign-in, sign-up and password-reset forms are protected against automated abuse. We will notify affected customers, and the Data Protection Board of India or other authorities where required, without undue delay after becoming aware of a personal data breach.
7. Your rights
Depending on where you are, you may have rights to access, correct, erase, restrict or object to processing, to portability, to withdraw consent, and to complain to a supervisory authority (in India, the Data Protection Board; in the EU, your national authority; in the UK, the ICO). Customers can export leads and conversations from the app and delete projects or their account from Account settings. For anything else write to [email protected]; we respond within 30 days.
8. Cookies
We use only strictly necessary cookies: a session cookie to keep you signed in and a cookie remembering which project you last opened. Cloudflare may set a security cookie to protect the forms. We do not use advertising or cross-site tracking cookies.
9. Children
The Service is for business use by adults. We do not knowingly process data of anyone under 18 as a customer, and customers may not target minors.
10. Changes
We will post changes here with a new effective date and notify customers by email or in the app of material changes at least 14 days in advance. See also the Terms of service.