Privacy Policy
Version 2026-08-13 · Effective 13 August 2026
This Privacy Policy explains how Alongo Technologies Pvt. Ltd. (PLACEHOLDER) (“Alongo”, “we”, “us”), the Data Fiduciary, collects, uses, shares, retains and protects your personal data when you use the Alongo apps and website (the “Platform”). We process personal data in accordance with applicable Indian law, including the Digital Personal Data Protection Act, 2023 (“DPDP Act”), the rules made under it as and when they come into force, and the Information Technology Act, 2000.
1. Personal data we collect
- Account & profile: mobile number, name, email (if you use Google sign-in), profile photo(s), city/region, date of birth or age confirmation, and — for Companions — bio, activities offered, availability and rates.
- Identity-verification data (Companions, and where required): government-issued photo ID (front/back), a live selfie used to match your ID, PAN number and PAN image, and questionnaire details (e.g. languages, occupation, emergency contact). See Section 3 for how this is handled.
- Location: with your permission, approximate device location to show nearby companions and set your region. Companion locations are shown to others only at an approximate area, never an exact address.
- Bookings & payments: booking details, amounts, and payment/payout status. Card/UPI/bank details are collected and processed by our RBI-regulated payment partners; we do not store full payment credentials.
- Messages & content: end-to-end encrypted message content (unreadable by us), delivery metadata, and content you submit such as reviews, reports and photos.
- Device & usage: device identifiers, app version, IP address, push-notification tokens, cookies/similar technologies (website), and diagnostic/usage logs used to operate and secure the service.
- Support & safety: information you share when you contact support, file a grievance, appeal an action, or report another user.
2. How and why we use your data (purposes)
- To create and operate your account and provide the marketplace — discovery, chat, bookings, payments and payouts.
- To verify identity and keep the community safe — ID/face verification, fraud prevention, photo screening, moderation of reports, and enforcing our Terms and Community Guidelines.
- To process payments, hold funds until a booking’s conditions are met, and pay Companions.
- To send service communications (e.g. booking updates, security alerts).
- With your separate opt-in: personalised matching, product analytics, location-based suggestions, your personal “social life / companion life” insights, promotional messages, and contribution to anonymous aggregate trends. You control each of these in Data & privacy settings.
- To improve, troubleshoot and secure the service, and to comply with legal obligations and establish/defend legal claims.
3. Identity-verification & facial data (special handling)
Because identity verification is sensitive, we treat it differently from an ordinary profile photo:
- What we collect: your government ID image(s), a live selfie, PAN number and image, and questionnaire answers.
- Why: to confirm you are a real, unique adult and to meet KYC/AML and safety obligations. Providing it is voluntary, but Companions cannot be approved to take Bookings without it.
- Face processing: your uploaded images are processed by an automated image service to detect a face and screen for unsafe content, and your selfie is compared against your ID to check they match. This face comparison is used only to verify identity. We do not build a face-recognition database or use your face to identify you elsewhere.
- Human review: a trained reviewer may check the result before approval. Verification decisions are not fully automated in a way that denies you a service without the ability to raise a grievance.
- Storage & retention: verification images are stored with restricted, least-privilege access via our image processor; ID/PAN records are retained for the period required under KYC/AML and tax law (see Section 8), then deleted or anonymised. If verification fails, related images are retained only as long as needed for fraud-prevention and appeal, then removed.
- Access: your ID/PAN/verification data is never shown to other users.
4. Legal grounds & your consent
We rely on the grounds available under the DPDP Act, matched to the purpose: your consent for optional purposes; the necessity to provide the service you asked for; compliance with legal obligations; and certain legitimate uses permitted by law. Rather than treating simply using the app as blanket consent, we ask for consent where it is required — for example separate in-app prompts for location, photos/camera, notifications, personalisation, analytics, your personal insights, and marketing. You can grant or withdraw each purpose at any time in Data & privacy settings; withdrawing consent won’t affect processing already carried out and may limit certain features. Essential processing needed to run bookings, payments and safety cannot be switched off while you use the Platform.
5. Who we share data with (Data Processors)
We share the limited profile information necessary to arrange a Booking with the other user (e.g. first name, photo, city, verified status) — never your ID/PAN/verification data or contact details. We do not sell your personal data. We use the following categories of service providers, acting on our instructions under contract:
| Provider | Purpose | Data | Outside India? |
|---|---|---|---|
| Google Firebase | Phone & Google sign-in, and push notifications (FCM) | Mobile number, email, authentication identifiers, device push tokens | Yes |
| Razorpay | Collecting booking payments from Explorers (RBI-regulated) | Booking amount, payment-instrument details (handled by Razorpay), contact details | No |
| RazorpayX | Paying out earnings to Companions | Payout bank/UPI/fund-account details, amounts | No |
| Cloudinary | Hosting & processing images, including profile photos and identity-document images | Profile photos; identity-verification document & selfie images | Yes |
| Google Cloud Vision | Automated safety screening & face detection on uploaded images | Uploaded images (processed to return safety/face signals; see the identity-verification section) | Yes |
| Resend | Sending transactional email (e.g. receipts, security alerts) | Email address, message content | Yes |
| Google Maps Platform | Maps and approximate-area display | Coarse location / region | Yes |
| Hosting infrastructure | Running the application server and database | All categories, as controller-held data | No |
We also disclose data where required by law, court order or lawful request, or to protect the rights, property or safety of users, the public or Alongo; and in a merger, acquisition or reorganisation, subject to this Policy.
6. International transfers
Some processors above (marked “Yes”) may process data outside India — for example authentication, notifications, image hosting/processing and email. Where we transfer personal data internationally, we do so only as permitted by applicable law and the DPDP framework as it comes into force, under contractual safeguards that require the recipient to protect the data consistent with this Policy. We maintain an internal data-flow map identifying, for each transfer, the data category, purpose, processor, country and safeguard.
7. Cookies & similar technologies (website)
Our website uses strictly necessary cookies to function and may use limited analytics to understand usage. You can control cookies through your browser settings. The mobile apps use device storage and identifiers for equivalent purposes.
8. Data retention
We keep personal data only as long as needed for the purpose, or as required by law. Indicatively:
| Data | Retention |
|---|---|
| Account & profile data | While your account is active; deleted or irreversibly anonymised within 30 days of account deletion, subject to the exceptions below |
| Profile & identity-document images | Until you remove them or delete your account; verification images may be retained longer where KYC/AML law requires † |
| Identity-verification records (result, PAN, document metadata) | For the period required under applicable KYC/AML and tax law (indicatively up to 8 years) † |
| Payment, payout & invoice records | As required under tax and payment-provider rules (indicatively up to 8 years) † |
| Booking records | Up to 5 years for dispute resolution, tax and safety purposes † |
| Reviews & ratings | Until account deletion, subject to operational/legal retention |
| Chat message ciphertext (unreadable by us) | While the conversation exists; removed on account deletion, subject to a report / legal-hold exception |
| Chat delivery metadata | Up to 90 days for delivery, security and abuse-prevention |
| Safety, fraud & moderation records | Up to 3 years to protect the community and establish/defend legal claims † |
| Security & access logs | Up to 180 days |
| Support & grievance records | Up to 2 years † |
Periods marked “†” are indicative and being confirmed with counsel/CA against KYC/AML, tax and payment-provider requirements. When data is no longer required, we delete or irreversibly anonymise it.
9. Deleting your account & the legal-preservation exception
You can delete your account at any time in-app (Profile → Settings → Delete Account) or at /delete-account. Deletion removes or anonymises your profile and personal data within the timelines above. Certain records may be retained where necessary for: legal or regulatory obligations (including KYC/AML and tax); fraud prevention and platform security; financial reconciliation and chargebacks; resolving an open dispute; or establishing, exercising or defending legal claims and responding to lawful requests. Retained records are minimised and access-restricted, and deleted once the obligation ends.
10. Your rights as a Data Principal
Under the DPDP Act you have the right to:
- access and obtain a summary of the personal data we process and how; you can also export your own data in-app (Data & privacy → Export my data);
- correct, complete or update inaccurate or incomplete data;
- request erasure of your data and account (subject to Section 9);
- withdraw consent as easily as it was given;
- nominate another individual to exercise your rights in the event of death or incapacity; and
- readily raise grievances (Section 12).
To exercise any right, use the in-app controls or email privacy@companion.app. We respond within the timelines set by law. If you are not satisfied, you may complain to the Data Protection Board of India.
11. Security & breach notification
We use technical and organisational safeguards including TLS encryption in transit, end-to-end encryption for messages, least-privilege access to verification data, and access controls. We maintain an internal incident-response procedure (detection → containment → investigation → notification → remediation). No system is perfectly secure. In the event of a personal-data breach, we will notify the Data Protection Board of India and affected users as required by law.
12. Children
The Platform is strictly for adults aged 18 and over. We do not knowingly process the personal data of anyone under 18; if we learn that we have, we will delete it promptly.
13. Grievances & our Grievance Officer
For privacy questions, to exercise your rights, or to raise a complaint, contact our Grievance Officer: Grievance Officer, Companion (PLACEHOLDER — named individual), grievance@companion.app. We acknowledge grievances within 24 hours and aim to resolve them within 15 days, in line with applicable rules. See Contact & Grievance. You may also complain to the Data Protection Board of India.
14. Changes & contact
We may update this Policy; material changes will be notified in-app or by other reasonable means, and the version/effective date above will change. Data Fiduciary: Alongo Technologies Pvt. Ltd. (PLACEHOLDER), Bengaluru, Karnataka, India (PLACEHOLDER — registered office). Privacy: privacy@companion.app · Grievance: grievance@companion.app.