Privacy Policy
Drafted to align with the Digital Personal Data Protection Act, 2023 (“DPDP Act”) and the DPDP Rules. Pending final review by counsel before public launch.
1. Who this policy covers
This policy applies to anyone who creates a JodiVibes account or otherwise submits personal data to us — Customers, Companions, and anyone who files a grievance or contacts support without an account. UrbanMove Services Pvt Ltd (CIN U49224UP2025PTC229800) is the Data Fiduciary for the purposes of the DPDP Act.
2. What we collect
- Account: full name, phone number, email, date of birth, city, gender.
- Companion verification: a government-ID photograph, a live-captured selfie, and background-check consent and outcome.
- Booking: venue, date and time, duration, occasion, notes to the other party, and payment metadata (never full card/bank details, which the payment aggregator holds).
- Location: collected only during an active, checked-in booking, and only if you choose to share it when raising an SOS alert. Never collected in the background or outside a checked-in booking.
- Communications: in-app messages between a Customer and Companion, and anything you send to support or the Grievance Officer.
- Device and usage data: the minimum needed to operate and secure the service — session identifiers, approximate device/browser type, and basic error/audit logs.
3. Itemised, purpose-specific consent
We ask for separate, explicit consent for each sensitive processing purpose — government-ID processing, background-verification consent, and location-sharing during a booking — never a single blanket checkbox covering all of them. Each consent can be reviewed and withdrawn independently from Profile → Data & Privacy. Withdrawing consent for verification data removes the stored document reference; it does not retroactively undo a verification decision already relied on for bookings that took place.
4. How we use your data
- Operating the marketplace: matching, booking, messaging, and payment processing.
- Identity and safety verification of Companions.
- Safety response: SOS handling, moderation, and investigating reports.
- Dispute resolution between Customers and Companions.
- Legal and regulatory record-keeping (financial records, grievance records).
- Fraud prevention and platform security.
We do not sell personal data, and we do not use it to serve third-party advertising.
5. Who we share it with
- The licensed payment aggregator that processes booking payments and escrow.
- The other party to a booking, limited to what they reasonably need (name, photo, booking details) — a Companion never sees a Customer’s ID document, and vice versa.
- Law enforcement or regulators, where legally required.
- Service providers who process data on our behalf under contract (for example, cloud hosting and database infrastructure), bound to use it only for the purpose we specify.
6. Retention
We keep each category of data only as long as its purpose requires:
- One-time verification codes and rate-limit records: deleted after 24 hours.
- Signed-out or expired sessions: purged after 30 days. An active session is never purged while in use.
- Read in-app notifications: purged after 90 days. Unread notifications are kept until read.
- Bookings, payments and ledger entries: kept indefinitely as statutory financial and tax records (this is required regardless of account deletion — see Section 7).
- Government-ID and selfie images: kept only as long as needed for verification and any mandatory record-keeping period, then deleted; the reference to a document is also cleared immediately if you delete your account (see Section 7).
- An internal audit trail of account and moderation actions: kept indefinitely for accountability. It records what happened and when, not the content of your personal data.
7. Deleting your account
You can request account deletion from Profile → Data & Privacy at any time your account has no open booking. On deletion:
- Your name, phone number, email, date of birth and gender are permanently scrubbed and replaced with non-identifying placeholders.
- Your sessions, one-time codes, favorites and notifications are permanently deleted.
- Verification document references are cleared (the tier/approval outcome is kept, so a removed account cannot quietly re-verify under a new identity).
- Message text you sent is replaced with a removal notice; the other party’s copy of the conversation is preserved for their own record.
- Review star ratings are kept as part of another user’s aggregate score; review text you wrote is removed.
- Bookings, payments, ledger entries and the audit trail are retained, as required by law — the audit trail itself contains no personal data.
8. Your rights
Under the DPDP Act, and available today from Profile → Data & Privacy:
- Access — download a copy of the personal data we hold about you. Identity documents are excluded from this export (they live in a separate encrypted store) — request them via the Grievance Officer.
- Correction — fix inaccurate account information.
- Erasure — delete your account as described in Section 7.
- Withdraw consent — for any itemised consent given, at any time.
- Grievance redressal — raise a concern about how your data is handled with our Grievance Officer; see the Grievance Redressal page.
See also Data Protection & Your Rights for the DPDP-specific detail.
9. Security
Sensitive documents (government ID, selfie) are encrypted at rest and stored in a store separate from our main application database, with access restricted to the verification workflow and authorised administrators. Passwords are never stored in plain text. Sessions can be reviewed and revoked from Profile → Settings.
10. Cross-border data transfer
Our infrastructure providers may process data outside India as part of standard cloud hosting operations. Where this occurs, it is subject to contractual safeguards with those providers. [Confirm current DPDP cross-border transfer requirements with counsel, as rules continue to roll out through 2026.]
11. Children
JodiVibes is for users 18 and older only. We do not knowingly collect data from anyone under 18.
12. Breach notification
In the event of a personal data breach, we will notify the Data Protection Board of India and affected users as required under the DPDP Act and Rules. [Process to be finalised with counsel to match final DPDP Rules notification timelines.]
13. Consent Manager
If a Consent Manager framework is mandated for our Data Fiduciary category under the DPDP Rules, integration details will be published here before it takes effect.
14. Contact
Data Fiduciary: UrbanMove Services Pvt Ltd. Contact: privacy@jodivibes.in.
Last drafted: 14 September 2026. Not yet reviewed by counsel.