Draft. This document is a working draft pending review by legal counsel and will be finalized before launch.
Privacy Policy
Last updated: 20 July 2026
1. Principles
- We collect the minimum needed for safety and service delivery.
- Verification data is used only for verification — never shown to other users, never sold, never used for advertising.
- Consent is explicit, purpose-bound, and withdrawable (DPDP Act, 2023).
- Data is stored in India (AWS ap-south-1, Mumbai region).
2. What we collect
- Account: name, phone, email, date of birth, password (hashed).
- Verification: government-ID images and a live selfie, encrypted at rest with restricted, audit-logged access.
- Bookings: activity, venue, times, payments (processed by licensed payment aggregators — we never store full card numbers).
- Safety: booking-scoped chat (screened for policy violations), meeting confirmations, reports, and — only if you enable it — live location during an active booking.
- Waitlist: contact details and marketing-attribution tags you arrive with.
3. Retention
- Live-location traces: purged within 72 hours unless attached to a reported incident.
- Chat: retained 180 days for safety and dispute purposes, then deleted.
- Verification images: retained while your account is active, per the schedule finalized with counsel; deletion available via support on account closure, subject to legal holds.
4. Sharing
We share data only with: payment aggregators (to process payments), verification providers (to verify you), your emergency contact (only when you trigger SOS), and authorities when the law requires it. We do not sell personal data. Ever.
5. Your rights
Access, correction, deletion, consent withdrawal, and grievance escalation per the DPDP Act — via in-app support or the Grievance Officer listed in the Terms.