Privacy policy
Effective from 1 October 2026
This notice explains how [Registered company name] ("GoSaathi"), [Registered office address], processes your personal data as a data fiduciary under the Digital Personal Data Protection Act, 2023 and the Information Technology Act, 2000.
What we collect
- Account: name, email, password (stored only as a one-way hash) or Google sign-in details, city and interests.
- Companion profile: display name, age, gender, languages, photos, bio, experiences, prices, availability, and a government ID document for verification.
- Bookings and payments: booking details, amounts, Razorpay order and payment references, refunds and booking credit. We never see or store card, UPI or bank details.
- Communication: messages, reviews, reports and support requests.
- Technical: session cookies, a first-party cookie recording how you found us (kept 30 days), push-notification subscriptions if you turn them on, and security logs such as IP address for rate limiting and fraud prevention.
Why we use it
- To create and secure your account and verify your email.
- To run bookings, payments, refunds and credit, and send booking notifications.
- To verify companions' identity and keep the community safe, including reviewing reported messages and investigating disputes.
- To prevent fraud and abuse and to meet legal, tax and accounting obligations.
- To understand which channels bring visitors, using aggregated counts only.
We process your data on the basis of your consent, given when you sign up, and for legitimate uses permitted by law. You can withdraw consent at any time; this ends your use of the service but does not affect processing already done or data we must keep by law.
Who we share it with
- The other side of your booking: your name, booking details and messages.
- Service providers acting on our instructions: Razorpay (payments), Cloudinary (photo and document storage), our email provider, MongoDB Atlas (database) and Vercel (hosting). Some of these store data outside India under contractual safeguards.
- Authorities, when required by law or to protect someone's safety.
Verification documents are visible only to authorised GoSaathi staff. We do not sell personal data.
How long we keep it
- Account and profile data: while your account is active, and deleted within 90 days of closure unless the law needs longer.
- Identity documents: deleted within 90 days after a companion application is rejected or the account is closed.
- Booking, payment and refund records: 8 years, as required by tax and accounting law.
- Messages and reports: up to 2 years, or longer if part of an open investigation.
Your rights
You can ask to access a summary of your data, correct or update it, erase it, withdraw consent, nominate someone to exercise your rights, and raise a grievance. Write to support@gosaathi.online from your registered email. You can also complain to the Data Protection Board of India.
Children
GoSaathi is only for people aged 18 and above. We do not knowingly process children's data; accounts found to belong to minors are closed.
Security
We use encryption in transit, hashed passwords, access controls, audit logs of staff actions and private storage for identity documents. No system is perfectly secure; we will notify you and the Board of a personal data breach as the law requires.
Cookies
We use only first-party cookies needed to keep you signed in, protect forms, and remember how you found us. We do not use third-party advertising cookies.
Contact and grievances
Grievance Officer
Badal Kumar
Email: grievance@gosaathi.online
[Registered company name], [Registered office address]
We acknowledge complaints within 24 hours and resolve them within 15 days.
Changes
We will post any changes here and tell you about material changes by email. Also see our Terms of use.