Last updated: 17 August 2026
This Privacy Policy ("Policy") describes how Korpo ("Korpo", "Company", "we", "us", "our") collects, uses, processes, discloses and protects personal information of users ("you", "User") of the website, mobile-optimised web application and associated services available at korpo.in and its subdomains (collectively, the "Platform"). This Policy is published in accordance with the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 ("SPDI Rules"), the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, and, upon its notification and to the extent applicable, the Digital Personal Data Protection Act, 2023 ("DPDP Act").
This Policy should be read together with our Terms and Conditions. By accessing or using the Platform, you consent to the collection, use, storage, disclosure and processing of your information as described in this Policy. If you do not agree with this Policy, please do not use the Platform.
Korpo is a verified corporate-employee marketplace and community platform. Because access is gated behind corporate-email verification and every module (marketplace, rentals, referrals, carpool, skills, deals, events, learning, concierge and benefits) involves an exchange of some personal information between Users, protecting that information is central to how the Platform is built and operated.
3.1 Information you provide directly:
3.2 Information collected automatically:
3.3 Information from other Users: Other Users may share information about you as part of reviews, ratings, referral posts, or dispute/abuse reports.
We collect information (a) directly from you when you register, verify your email, create a listing, send a message, or otherwise interact with the Platform; (b) automatically through cookies, log files, and similar technologies as you use the Platform; and (c) from third parties, including our email/OTP verification provider and payment gateway, strictly to the extent necessary to operate the relevant feature.
We use the information we collect to:
By registering on and using the Platform, you provide your consent, as contemplated under the SPDI Rules and, once applicable, the DPDP Act, to the collection and Processing of your Personal Data for the purposes described in this Policy. Where required by Applicable Law, we will seek your specific, informed and unambiguous consent before collecting or processing any Sensitive Personal Data or Information, and you may withdraw such consent at any time by writing to us at the contact details in Section 19, subject to the Platform's ability to continue providing the relevant Service.
We do not sell your Personal Data. We may share your information in the following circumstances:
We use cookies, local storage, and similar tracking technologies to keep you signed in, remember your preferences (e.g., selected city), understand how the Platform is used, and improve performance. You can control or disable cookies through your browser settings; however, disabling certain cookies may limit your ability to use some features of the Platform.
Payments for Premium subscriptions and other paid features are processed through RBI-authorised third-party payment gateway(s). Korpo does not collect or store your full card number, CVV, UPI PIN, or net-banking credentials; these are handled directly by the payment gateway in accordance with applicable RBI guidelines and the Payment Card Industry Data Security Standard (PCI-DSS), where applicable. Korpo retains only transaction identifiers, billing name, and payment status necessary for record-keeping, invoicing, and dispute resolution.
We implement reasonable security practices and procedures, commensurate with industry standards, to protect your Personal Data against unauthorised access, alteration, disclosure, or destruction, consistent with the requirements of the SPDI Rules. These measures include encryption of data in transit, access controls, and secure hosting infrastructure. However, no method of transmission over the internet or electronic storage is completely secure, and we cannot guarantee absolute security. You are responsible for keeping your account credentials confidential.
We retain your Personal Data for as long as your account remains active, and thereafter for such period as is reasonably necessary to fulfil the purposes described in this Policy, comply with our legal, accounting, or reporting obligations, resolve disputes, prevent fraud and abuse, and enforce our agreements. When Personal Data is no longer required for these purposes, we will delete it or anonymise it in accordance with Applicable Law.
Subject to Applicable Law, you have the right to:
To exercise any of these rights, please write to us at the contact details in Section 19. We may need to verify your identity before acting on your request, and may decline requests that are manifestly unfounded, excessive, or that we are not permitted to fulfil under Applicable Law.
The Platform is intended solely for use by individuals who are at least 18 years of age and hold a Verified Corporate Email. We do not knowingly collect Personal Data from anyone under 18. If we become aware that we have inadvertently collected Personal Data from a person under 18, we will take steps to delete such information promptly.
The Platform may contain links to, or integrations with, third-party websites, brands, deals, or service providers (including under the Employee Deals, Concierge, and Employee Benefits modules). This Policy does not apply to, and Korpo is not responsible for, the privacy practices of any third party. We encourage you to review the privacy policy of any third-party service before providing your information to it.
We primarily store and process data on servers located in India. Where any of our service providers (such as cloud hosting or analytics providers) process data outside India, we take reasonable steps to ensure such transfers are subject to contractual safeguards and a level of protection consistent with this Policy and Applicable Law, including the SPDI Rules and, where applicable, the DPDP Act.
In the event of a Personal Data breach that is likely to affect you, we will take reasonable steps to notify you and the relevant regulatory authorities in accordance with Applicable Law, including any timelines prescribed under the Information Technology Act, 2000, and, once applicable, the DPDP Act.
In accordance with the Information Technology Act, 2000, the SPDI Rules, and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, the name and contact details of the Grievance Officer for privacy-related concerns are provided below:
The Grievance Officer shall acknowledge complaints within 24 (twenty-four) hours and endeavour to redress the grievance within 15 (fifteen) days from the date of receipt, in accordance with Applicable Law.
We may update this Policy from time to time to reflect changes in our practices, the Platform, or Applicable Law. The revised Policy will be posted on this page with an updated "Last updated" date, and, where the changes are material, we will make reasonable efforts to notify you (such as by email or an in-app notice). Your continued use of the Platform after such changes take effect constitutes your acceptance of the revised Policy.
If you have any questions, concerns, or requests regarding this Privacy Policy or your Personal Data, please contact us at: privacy@korpo.in or hello@korpo.in, or via our Contact page. Korpo is built and operated from Chennai, Tamil Nadu, India.