1.Scope and Who We Are
This Privacy Policy explains how Zad Digital (contact: info@zaddigital.com), the operator of the SamajUnnati platform (SamajUnnati, Zad Digital, we, us, or our), handles personal information when you use our website, Android or iOS applications, APIs, family and friend trees, profiles, posts, stories, messaging, notifications, matrimony features, and related services (the Service).
It applies to registered users, people whose limited information is added to a family or friend tree, matrimony profile subjects, website visitors, and people who contact us. Feature-specific notices and device permission prompts may provide additional information.
For privacy inquiries, rights requests, and complaints, contact our designated privacy support channel at info@zaddigital.com.
2.Information We Collect
- Account and authentication: Phone number, OTP request and verification metadata, registration status, authentication tokens, account language, and security events. OTP values are not returned in API responses or intentionally written to application logs.
- Registration and profile information: During account registration and subsequent profile completion, we collect and process the following specific fields so users have full transparency regarding the data requested: (1) Identity & Names: first name, middle name, last name, and display full name; (2) Authentication & Contact: mobile phone number (verified via SMS OTP), optional email address, and optional WhatsApp contact number; (3) Personal & Demographics: profile photo (avatar), date of birth, gender, and blood group; (4) Cultural & Community Details: religion, community, caste, and subcaste; (5) Employment & Education: occupation, professional designation, and education details; (6) Address & Location: residential pincode, area / locality, city, district, state, country, and optional device GPS latitude and longitude (used during registration strictly for area and postal lookup, never persisted for ongoing location tracking); (7) Language Preferences: application interface language and family tree / relation label language; (8) Bio & Media: personal biography and profile banner image; (9) Matrimonial Status: marital status and matrimony profile indicators (if enabled); and (10) Affirmative Legal Consent: server timestamp and version record of your acceptance of the Terms & Conditions and Privacy Policy.
- Relationships and genealogy: Family, friend, and matrimony relationship types; related people; custom names and photos; living/deceased status; approvals, rejections, creator, tree position, visibility, and timestamps.
- Social and media content: Posts, captions, locations, tags, photos, videos, music metadata, likes, comments, replies, shares, stories, mentions, audience selections, views, and deletion or expiry state.
- Communications: Direct and group messages, media and documents, group names and photos, membership, administrator roles, join requests, permissions, read receipts, disappearing-message settings, blocks, and timestamps.
- Matrimony information: Photos, height, complexion, education, occupation, income, lifestyle, languages, religion/community/caste/subcaste, biography, hobbies, interests, preferences, profile manager, verification and claim status, shortlists, interests, matches, blocks, reports, recommendation paths, and compatibility or trust scores.
- Device and notification information: Push token, platform, per-install device identifier, device model/name, application version, notification permission and delivery state, last-seen time, and disabled-token state.
- Location information: Pincode, locality, city, district, state, area, and address. If you choose GPS lookup, precise coordinates are transmitted for geocoding; the resulting area may be stored, while precise registration coordinates are not intended to be persisted as your physical location.
- Operational and security data: Request ID, route and method, query-key names, authenticated user ID, IP address, User-Agent, response status, latency, rate-limit counters, cache activity, errors, abuse indicators, and service health information.
- Consent records: The server date and time when you accepted the Terms and Privacy Policy during registration, together with the versions accepted.
3.Sources of Information
We receive information directly from you; from other users who add you to a family, friend, group, or managed matrimony record; from your device when you grant permission; from your interactions with content and communications; and from service providers that support authentication, messaging, location, media, and notifications.
A relationship record created by another person may exist before you register. If you believe someone submitted your information without authority, contact info@zaddigital.com with enough detail to investigate.
4.How We Use Information
- Create, authenticate, secure, recover, and administer accounts and verified phone-number changes.
- Build and display family and friend trees, relationship requests, profiles, aliases, badges, scores, and connection paths.
- Provide posts, stories, comments, likes, follows, messaging, groups, read state, notifications, and content-sharing features.
- Provide matrimony profiles, preferences, recommendations, interests, matches, shortlists, managed profiles, blocking, and reporting.
- Process selected contacts and location lookups when you request those features.
- Personalize language, layout, feed audiences, connection suggestions, and other user-requested experiences.
- Detect fraud, abuse, unauthorized access, spam, unsafe conduct, policy violations, and technical failures.
- Operate, debug, measure, maintain, and improve performance, reliability, accessibility, and security.
- Comply with legal obligations, enforce agreements, resolve disputes, and protect users, the public, and the Service.
5.Legal Bases and Consent
Depending on applicable law, we process information to perform our contract with you, with your consent, for legitimate interests such as security and service improvement, to protect vital interests, and to comply with legal obligations. Where consent is required, you may withdraw it for future processing, but withdrawal does not invalidate earlier lawful processing and may prevent use of a feature.
Registration requires affirmative acceptance of the Terms and Privacy Policy. The server records the acceptance time and policy versions; it does not rely on a timestamp supplied by your device. Device permissions are separate and can be changed in operating-system settings.
6.Profile, Tree, and Content Visibility
Visibility depends on the feature, audience, relationship status, creator, account privacy, and settings. Public-safe profile information may include a name, image, banner, general biography, gender, living status, occupation, education, area, designation, and membership date. Sensitive owner fields such as phone, email, exact address, pincode, WhatsApp number, full birth date, and blood group are not intended to be returned by the generic public-profile endpoint.
Relationship and tree features may expose names, phone numbers, custom labels, photographs, status, and relationship information to participants or people with authorized tree access. Some user-created, unregistered, deceased-person, or managed records may exist without the subject having an account.
A private-profile setting limits certain post visibility but does not make every profile, relationship, notification, message, or matrimony field invisible. Matrimony profiles marked public may be shown to eligible users. Content recipients can copy, screenshot, or redistribute information outside our control.
7.Contacts and Information About Other People
With permission, the mobile app can open a system contact picker or contact list to help you select a person. The selected contact’s name, phone number, and available image may be copied into a relationship form and submitted only when you choose to save it. We do not intend to upload your entire address book automatically.
You must have authority to submit information about another living person. Do not submit unnecessary sensitive details. The person may contact us to request review, correction, restriction, or removal, subject to identity verification and applicable law.
8.Location and Geocoding
You may enter a pincode or grant foreground location permission to identify your locality. Pincode or coordinate queries may be sent to Google Maps Geocoding, India Post or postal-data services, and OpenStreetMap Nominatim. Those providers process the request under their own terms and policies.
We use the result to populate locality, area, city, state, country, or pincode fields. You can skip location during registration or change device permission later. Graph layout coordinates used to draw relationship trees are not intended to represent physical GPS location.
9.OTP, Authentication, and Session Security
OTPs are generated using a cryptographic random-number function, stored temporarily in Redis with an expiry and attempt counter, transmitted through an internal RabbitMQ queue, and sent through the configured SMS provider. The current default validity is ten minutes but may change for security or operational reasons.
OTP values are not returned by HTTP responses, intentionally written to application logs, or sent through in-app socket events. They necessarily exist in temporary authentication infrastructure and the SMS delivery path so that verification can work. Correct verification consumes the OTP; repeated incorrect attempts and excessive requests are limited.
Authentication tokens may remain valid for the configured session period and are stored on your device or browser. Protect your device, sign out of shared devices, and notify us if you suspect compromise.
10.Messages, Stories, Notifications, and Media
Message content and attachments are stored so they can be delivered to conversation members. Read receipts and last-read times may be recorded. Unless expressly stated otherwise, do not assume communications are end-to-end encrypted. Group members and administrators may see content according to membership and permission settings.
Deleted or disappearing messages may have their active database content cleared, but copies can remain in backups, caches, push notifications, recipient devices, screenshots, or object storage for a period. Stories generally stop appearing after expiry, but expiry is not a promise of immediate physical erasure from every system.
Push notifications may show names, activity, or message previews on a lock screen. You can change notification permissions and preview settings through your device. Disabling a device token stops intended future delivery but token records may be retained temporarily for security and delivery diagnostics.
Uploaded media may be stored in object storage and delivered through public or cacheable URLs. Application access controls may govern discovery, but anyone who obtains a public media URL may be able to access or cache it. Avoid uploading highly sensitive content.
11.Matrimony Data and Profiling
Matrimony functionality can involve sensitive personal, community, lifestyle, income, preference, relationship-path, and compatibility information. We use it to display profiles, filter or rank potential profiles, calculate recommendations, facilitate interests and matches, and prevent abuse.
Recommendation, trust, distance, or compatibility scores are automated product indicators based on available data and are not background checks, guarantees, or professional decisions. You should independently verify information. Managed profiles may be created or maintained by another authorized family member and may later be claimed by the subject.
Matrimony services are for adults. Report underage profiles, impersonation, coercion, fraud, or unauthorized managed profiles promptly.
13.Service Providers and External Platforms
Providers visible in the current technical design include PostgreSQL and Prisma-related database infrastructure; Redis; RabbitMQ; Cloudflare R2; BulkSMSIndia; Google Maps and YouTube services; India Post or postal lookup services; OpenStreetMap Nominatim; Firebase Cloud Messaging; Apple or iTunes media preview services; Expo/EAS; mobile app stores; and network or hosting providers. Actual production vendors, accounts, regions, and subprocessors may change.
Third-party websites and services control their own privacy practices. We encourage you to review their notices. We do not send OTP values to analytics providers; OTP values are handled only through the authentication and SMS-delivery path described above.
15.Retention
We retain information for as long as reasonably necessary to provide the Service, maintain relationships and content requested by users, secure accounts, resolve disputes, enforce agreements, comply with law, and protect legitimate interests. Retention varies by data type and cannot always be tied to one fixed period.
OTPs expire after a short configured period. Stories stop appearing after their expiry time. Posts, comments, users, relationships, and messages may use soft deletion or content clearing before later cleanup. Media, backups, immutable caches, delivery records, security logs, disabled push tokens, fraud records, and content shared with other users may remain longer.
When retention is no longer justified, we will delete, anonymize, or restrict information using reasonable processes. A finalized production retention schedule should be approved by the operator and counsel.
16.Security
We use administrative, technical, and organizational safeguards intended to reduce unauthorized access, alteration, disclosure, or loss. Current controls include access-limited APIs, authentication tokens, rate limits, OTP expiry and attempt limits, server-side validation, scoped profile responses, content-type checks, structured logging with redaction, and provider access controls.
No security method is perfect. We do not claim that every database field is individually encrypted or that transmission, storage, devices, or third-party services are risk-free. You should use a secured device, protect OTPs and sessions, and avoid placing highly sensitive information in public profiles, messages, trees, or media.
17.Your Choices and Rights
Submit privacy requests to info@zaddigital.com. We may need to verify your identity and authority, especially for phone numbers, minors, managed profiles, relationship records, or requests submitted on behalf of another person. Some requests may be limited by law, safety, fraud prevention, other users’ rights, or technical and backup constraints.
- Access and update many profile details through the Service.
- Choose profile privacy, content audiences, follows, relationship actions, blocks, notifications, and device permissions where available.
- Request access, correction, deletion, restriction, objection, withdrawal of consent, or a copy of information where applicable law provides those rights.
- Request review of information another user submitted about you.
- Unregister a push token by signing out where supported and manage operating-system permissions directly.
18.Account and Data Deletion
You may request account closure or deletion by emailing info@zaddigital.com. Include the phone number associated with the account only when requested through a secure verification process; never send an OTP. We will explain verification steps and the expected handling of active profile data.
Deletion may not remove another user’s independent relationship record, messages or media retained by recipients, legally required records, fraud-prevention information, aggregate or anonymized data, backups awaiting rotation, or cached media immediately. Where complete deletion is not available, we may restrict, de-identify, or detach information as permitted by law.
19.Children and Young People
The general Service can contain family-tree information about children submitted by parents or lawful guardians. Children should not independently register or submit personal information unless permitted by applicable law and appropriately authorized. Matrimony functionality is strictly for adults.
If you believe a child’s information was submitted without authorization or is excessive, contact us. We may remove, restrict, or request verification from the responsible adult.
20.International Processing and Data Location
The Service and its providers may process or store information in locations different from yours. Data-protection standards may vary. Where required, we use appropriate contractual, organizational, or legal safeguards. You may contact us for information about the safeguards applicable to your information.
21.Changes to This Policy
We may update this Policy when features, vendors, laws, or practices change. We will update the effective date and version. Material changes may be announced through the Service and may require renewed acceptance. Earlier consent records remain associated with the document versions accepted at that time.
22.Contact, Complaints, and Grievances
For privacy questions, rights requests, complaints, unauthorized profiles, safety concerns, or deletion requests, contact info@zaddigital.com. Provide a clear description and relevant account or content identifiers, but do not email OTPs, passwords, financial information, or unnecessary sensitive documents.
Service: SamajUnnati Platform. Operated by: Zad Digital. Privacy and grievance contact: info@zaddigital.com.