This policy explains what SaathWala collects when you use SaathWala, why we collect it, who can see it and what you can ask us to do with it. It is written to meet the Digital Personal Data Protection Act, 2023.
1. What we collect
- Account details. Name, email address, mobile number, password in hashed form.
- Profile details. Date of birth, gender, the gender you are looking for, city, locality, a short bio, hobbies, the occasions you are interested in, and a profile photograph.
- Identity verification. The last four digits of your Aadhaar number, a one way cryptographic hash of the full number, and the document image you upload. Companions also give a live selfie taken on the device camera.
- Consent records. The exact wording of each statement you agreed to, its version, the date and time and your IP address.
- Payment records. Plan purchased, amount, date, and the payment reference from our gateway. We never see or store your card number, UPI PIN or bank credentials.
- Usage data. Profiles you view, contacts you reveal, profiles you save, searches you run, your IP address and browser type.
- Advertising identifiers. Cookies set by us and by Meta, and click identifiers appended to links when you arrive from an advertisement.
2. How we handle your Aadhaar
We never store your full Aadhaar number. When you submit it, we keep only the last four digits and an irreversible keyed hash used to stop one person opening several accounts. The number itself is discarded.
The document image you upload is encrypted at rest and can be opened only by our verification staff through an internal tool. Every single access is written to an audit log with the staff member's identity and the time. The document is never shown to other members and never leaves our systems.
We are not an authorised Aadhaar e-KYC entity and we do not query UIDAI. Verification is a manual document check by our team. Sharing Aadhaar is voluntary, masked Aadhaar is accepted, and other government ID can be used through support. The document image and selfie are deleted after review; details are in the Identity Verification Policy.
3. Why we use it
- To create and run your account, and to authenticate you.
- To match you with companions by city, locality, shared interests and occasion.
- To verify that members are real, adult and unique, which is the core safety promise of this service.
- To take payment and give you the access you paid for.
- To respond to support requests and to investigate reports of misconduct.
- To measure and improve our advertising, as described in section 6.
- To meet legal obligations and to respond to lawful requests from authorities.
4. Who can see what
- Other members see a companion's display name, age, city, locality, photographs, languages, bio, hobbies and occasions. They never see a full residential address, an email address or an identity document.
- Contact details such as phone number are masked, and revealed only when a member with an active plan and verified identity reveals that specific profile.
- Without a membership, photographs are blurred and names are shown as initials.
- Our staff can see what is needed to verify identity and handle support. Access to identity documents is restricted and audited.
5. Who we share it with
- Razorpay, our payment gateway, to process payments. They receive your name, email, phone and the amount.
- Meta Platforms, for advertising measurement. What we send is described below.
- Google, for website analytics (Google Analytics) after you accept cookies. Google receives page visits and actions such as sign-up or purchase, linked to a one-way code rather than your name, email or phone.
- Hosting and communication providers who run our servers and send our notifications.
- Law enforcement or courts, where we are legally required to respond.
We do not sell your personal data to anybody, and we do not share your contact details with advertisers.
6. Cookies and advertising measurement
We use the Meta pixel and the Meta Conversions API to understand which advertisements bring people to us. When you take an action such as signing up or buying a plan, we send Meta an event describing that action together with identifiers that are cryptographically hashed before they leave our server, such as your email address and phone number. Hashing means Meta can match you to an existing profile they already hold but cannot read the original values from us.
None of this happens until you choose Accept on the cookie banner. Choosing Only essential turns it off and does not affect your membership. Every cookie is listed in the Cookie Policy.
7. How long we keep it
- Account and profile data, for as long as your account exists.
- Identity document images and selfies, deleted within 30 days of review, or 180 days if never reviewed. The last four digits and the one-way code stay with your account.
- Consent records, for as long as your account exists and for the period needed to show we obtained consent.
- Payment and tax records, for eight years, as Indian tax law requires.
- After account closure, remaining personal data is deleted or irreversibly anonymised within ninety days, except records we must keep by law.
8. Your rights
You may ask us to:
- Give you a copy of the personal data we hold about you.
- Correct anything inaccurate or incomplete.
- Delete your account and the personal data attached to it.
- Withdraw a consent you previously gave.
- Nominate somebody to exercise these rights if you die or become incapacitated.
You can download your data and delete your account yourself from your account page. For anything else, write to hi@saathwala.in from your registered email address. We respond within thirty days. Withdrawing consent is as easy as giving it, but we cannot keep running an account without it.
If you are not satisfied with our answer, use the grievance process. After that you may complain to the Data Protection Board of India.
9. Grievance officer
- Email
- hi@saathwala.in
- Response
- Acknowledged within 24 hours, resolved within 15 days
10. Security
Passwords are stored hashed and never in readable form. Identity documents are encrypted at rest. Access to personal data by staff is limited by role and written to an audit log. We use encrypted connections throughout. No system is perfectly secure, and if a breach affects your personal data we will notify you and the Data Protection Board as the law requires.
11. Children
This service is strictly for adults aged 18 and over. We do not knowingly collect data from children. If we discover an account belongs to a minor we delete it immediately.
12. Changes
We will post any change here and update the date at the top. If a change materially affects your rights we will notify you directly.