PRIVACY POLICY
The Goodwill Network
Last Updated: May 09, 2026
INTRODUCTION
The Goodwill Network ("Company", "we", "our", or "us") respects your privacy and is committed to protecting the personal information of users ("User", "you", or "your") who access or use our website, applications, tools, and services (collectively, the "Platform"). This Privacy Policy explains how we collect, use, store, share, and protect your information when you use the Platform. By accessing or using the Platform, you consent to the practices described in this Privacy Policy.APPLICABLE LAW
This Privacy Policy is governed by and compliant with:
(a) the Information Technology Act, 2000;
(b) the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011;
(c) the Digital Personal Data Protection (DPDP) Act, 2023; and
(d) all applicable rules and regulations notified thereunder.
In the event of any conflict between this Privacy Policy and applicable law, the applicable law shall prevail.
INFORMATION WE COLLECT
3.1 Personal Information: We collect your full name, email address, phone number, profile photograph, and professional details (including role, skills, and portfolio content) to create and maintain your professional identity on the Platform.3.2 Financial & Tax Identifiers: We collect Permanent Account Number (PAN), GSTIN, and banking details solely to facilitate professional transactions, invoicing, and tax compliance. This information is used only for the purposes for which it is provided and is not shared with third parties except as necessary for payment processing or as required by law.
3.3 Agreement & Transactional Data: We collect agreement details created using the Platform, project terms, payment history, and electronic signature metadata. Electronic signature processing and audit logs are facilitated through DocuSeal. The DocuSeal audit log for each agreement constitutes a legally significant document and is retained in accordance with the retention schedule in Clause 8.
3.4 Technical & Usage Data: We collect IP addresses, browser types, device identifiers, and usage activity to improve service delivery, maintain platform security, and diagnose technical issues.
3.5 Data Provided by Other Users: Where a Platform member creates an agreement involving an external party, that external party's personal data (name, email address, and other details entered in the agreement form) is processed by the Platform solely for the purposes of creating, delivering, and storing that agreement.
3.6 Signature Data: Where a User enables the invoice creation feature, we collect and store the User's signature for the sole purpose of applying it to GST-compliant tax invoices and receipt vouchers created through the Platform. Signature data is treated as sensitive personal data and is stored with encryption. It is used exclusively for document creation and is never shared with third parties except as necessary to render the document for delivery to the counterparty. The User's consent to this use is given upon enabling the invoice creation feature and may be revoked at any time in accordance with Clause 11.5.
3.7 Conduct & Reputational Data: We collect and store peer ratings submitted by Platform members, Goodwill Score history, dispute records, and conduct reports. This data is used to operate the Goodwill Score system and maintain network integrity. It is not shared with third parties except as part of a User's profile where the Platform displays scores and badges.
3.8 Booking & Scheduling Data: We collect and store records of Pencil Hold requests made through the Platform, including hold type (First or Second Pencil), hold status (pending, accepted, declined, expired, or lost), the dates requested, and booking history between Users. This data is used to operate the scheduling and availability system, display hold status on Freelancer profiles and calendars, apply subscription tier priority logic where applicable, and maintain a record of the professional scheduling history between Platform members.
3.9 Subscription & Billing Data: We collect and store your subscription tier, billing cycle, subscription status, and payment transaction metadata, including payment confirmation references generated by Razorpay. Full payment card or banking details are processed exclusively by Razorpay and are not stored by the Company. This data is used to manage your access to Platform features, apply and enforce subscription-tier usage caps, and maintain billing records in accordance with applicable law.
3.10 Notification Data: The Platform generates and stores in-app notifications relating to booking requests, Pencil Hold status changes, agreement updates, project activity, Goodwill Score events, and other Platform activity. We retain notification content, timestamps, and read or unread status solely for the purpose of delivering notifications to the relevant User. Notification data is not shared with third parties.GOOGLE API DATA DISCLOSURE (CALENDAR SYNC)
4.1 Access & Purpose: The Platform requests access to your Google Calendar via OAuth to provide bidirectional synchronisation, including identifying availability blocks and managing project scheduling.4.2 Limited Use: Our use and transfer of information received from Google APIs will adhere strictly to the Google API Service User Data Policy, including the Limited Use requirements. Data obtained via Google APIs is used solely for the calendar synchronisation feature and for no other purpose.
4.3 Restrictions: Data obtained via Google APIs is never shared with advertising platforms, data brokers, or third parties for marketing purposes, and is never used to train artificial intelligence or machine learning models.
PURPOSE OF DATA COLLECTION
Creating and managing user accounts and professional identities on the Platform.
Creating, storing, delivering, and managing legally binding agreements.
Creating GST-compliant tax invoices and receipt vouchers, including applying stored signatures with the User's consent.
Processing subscription payments to the Company via Razorpay.
Automating calendar management and preventing scheduling conflicts.
Operating the Goodwill Score system and processing conduct reports.
Complying with legal obligations, including tax and regulatory requirements under the Income Tax Act 1961 and the Central Goods and Services Tax Act 2017.
Detecting and preventing fraud, misuse, and security breaches.
Managing tentative booking holds and availability calendars, including applying subscription-tier priority logic where a Like a Boss Producer's hold takes precedence over a lower-tier Producer's existing hold.
Delivering in-app notifications related to bookings, agreements, projects, and Goodwill Score events.
LEGAL BASIS FOR PROCESSING
We process personal data on the following legal bases under the DPDP Act, 2023:Consent: Where you have provided explicit consent, including at registration, at the point of agreement creation, and upon enabling the invoice creation feature.
Contractual necessity: Where processing is necessary to provide the services you have requested, including agreement creation, invoice creation, and related document management.
Legal obligation: Where processing is required to comply with applicable law, including tax and financial regulations under the Income Tax Act 1961 and the CGST Act 2017.
Legitimate interests: Where processing is necessary for our legitimate interests in operating and improving the Platform, provided those interests do not override your privacy rights.
DATA SHARING AND DISCLOSURE
We do not sell personal data. We share information only in the following circumstances:With trusted infrastructure providers — Convex, Clerk, Razorpay, DocuSeal, Railway, n8n, and ZeptoMail — strictly for the purposes of operating the Platform. Each provider is engaged under contractual terms requiring appropriate data protection.
With the other party to an agreement, to the extent their details are included in an agreement you create or sign.
With the recipient of a tax invoice or receipt voucher, to the extent their details appear on that document.
With Legal Partners, only where you have initiated contact through the Legal Help feature and provided explicit consent to share relevant information.
With regulatory or law enforcement authorities, where required by applicable law or court order, including tax authorities in respect of GST records.
DocuSeal Processing: DocuSeal processes and stores electronic signature metadata and agreement audit logs on our behalf. Users and external parties whose data is processed through DocuSeal should refer to DocuSeal's Privacy Policy for further information.
Cross-Border Transfers: Some infrastructure providers (including Convex and Railway) may store or process data on servers located outside India. Where such transfers occur, they are governed by contractual safeguards with the relevant provider and are conducted in accordance with applicable law.
User-to-User Sharing: By maintaining an active profile on the Platform, you consent to your professional profile information — including your name, contact details (phone number and email address), professional biography, skills, portfolio links, work showcase content, availability status, and Goodwill Score — being visible to other verified Platform members in the ordinary course of using the Platform. Producers may access Freelancer profiles through the crew directory to identify and contact potential collaborators. Freelancers may view Producer company information when they receive a pencil hold request or agreement invitation. Availability status derived from Google Calendar synchronisation is displayed as a general indicator only; underlying calendar event content is never shared with other Users.
DATA RETENTION
We retain personal data for the following periods:
Account data (name, email, profile)
Financial & tax identifiers (PAN, GSTIN, banking)
Agreement & signature data (content, DocuSeal audit logs)
Invoice & receipt voucher data (including applied signatures)
Signature data (stored for invoice creation)
Conduct & reputational data (ratings, score history, reports)
Technical & usage data (IP logs, activity)
Google Calendar access tokens & sync data
External party data (non-member signatories)
Booking & scheduling data (hold requests, status history)
Subscription & billing metadata
Notification data
Duration of account + 2 years
7 years from last transaction (Income Tax Act)
7 years from execution date
7 years from annual GST return due date
(Section 36, CGST Act 2017)
Until revocation of consent or account closure;
created documents retained per GST requirements
Duration of account + 2 years
12 months
Until revocation of access
7 years from agreement execution
2 years from hold creation date, or duration of
associated project if longer
7 years from last transaction (Income Tax Act 1961)
12 months from notification date
Upon expiry of the relevant retention period, personal data will be deleted or anonymised, unless retention is required by applicable law
or for the purpose of defending legal claims.
DATA SECURITY
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, disclosure, alteration, or destruction. These measures include encrypted data transmission, encryption of sensitive data including signature data at rest, access controls, and regular security reviews. No system is completely secure and we cannot guarantee the absolute security of your data. In the event of a personal data breach that poses a risk to your rights, we will notify you and relevant authorities as required under the DPDP Act, 2023.COOKIES & TRACKING
The Platform's applications store session data using browser localStorage (not cookies) to maintain your login state across visits. However, third-party services integrated into the Platform — including Clerk (authentication), Razorpay (billing), and DocuSeal (e-signatures) — may set cookies or similar tokens on your device as strictly necessary for those services to function. These cookies are not used for targeted advertising or behavioural tracking. You may configure your browser to block cookies, but this may prevent authentication and payment features from working correctly. The Platform's marketing website (thegoodwill.network) may use separate analytics tools subject to their own cookie disclosures.USER RIGHTS & DATA PORTABILITY
11.1 Access & Correction: You have the right to access and correct your personal data held by the Company. You may view and edit your
personal data via your Profile settings at any time.
11.2 Data Portability: You have the right to request a copy of your personal data in a structured, machine-readable format. To make a
portability request, contact admin@thegoodwill.network.
11.3 Deletion and Account Closure: You may initiate permanent account deletion at any time through your account settings. Upon
deletion, the following personal data is immediately and permanently erased from your account record: your name, contact details,
professional biography, portfolio and showcase content, banking and tax information (PAN, GSTIN, account details), profile picture,
stored signature, emergency contact information, and Google Calendar credentials. The following data is retained following deletion:
(a) your email address and user identifier — retained to link your account record to previously created agreements, invoices, and tax
documents, and to support score continuity if you re-register; (b) your Goodwill Score and conduct history — retained for platform
integrity and to prevent reputation manipulation through repeated account deletion; and (c) agreements, invoices, tax invoices, and
receipt vouchers previously created or signed through the Platform — retained for the statutory periods set out in Clause 8. GST records
cannot be deleted prior to expiry of the 72-month retention period under Section 36 of the CGST Act 2017. If you re-register using the
same email address following account deletion, your previous Goodwill Score will be restored to your new account.
11.4 Withdrawal of Consent: Where processing is based on your consent, you may withdraw consent at any time. Withdrawal of consent
does not affect the lawfulness of processing carried out prior to withdrawal.
11.5 Signature Data Revocation: You may revoke your consent to the storage and use of your signature for invoice creation at any time
through your account settings. Following revocation, your signature will not be applied to any subsequently created documents.
Previously created tax invoices and receipt vouchers bearing your signature will not be altered, as they constitute GST records that
must be retained in their original form under applicable law.
11.6 Google Calendar Access: You may revoke Google Calendar access at any time via your Platform settings or through your Google
Security Dashboard. Revocation does not affect previously synchronised data retained within the Platform's retention schedule.
CHILDREN'S PRIVACY
The Platform is not directed at or intended for use by persons under the age of 18. We do not knowingly collect personal data from minors. If we become aware that a minor has provided personal data, we will delete it promptly.THIRD-PARTY LINKS
The Platform may contain links to third-party websites or services, including those of our infrastructure providers and Legal Partners. We are not responsible for the privacy practices, content, or security of such third-party sites. We encourage Users to review the privacy policies of any third-party services they access through the Platform.GOVERNING LAW
This Privacy Policy shall be governed by and construed in accordance with the laws of India. Subject to applicable dispute resolution mechanisms, courts at Mumbai, India shall have jurisdiction over any disputes arising from this Privacy Policy.CHANGES TO THIS PRIVACY POLICY
We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. Material changes will be notified to registered Users by email at least 14 days before taking effect. Continued use of the Platform after the effective date of an updated Privacy Policy constitutes acceptance of that policy.CONTACT INFORMATION
For questions, concerns, data requests, or to exercise your rights under this Privacy Policy, contact: admin@thegoodwill.network
We will acknowledge data requests within 5 Business Days and respond within 30 days.