Privacy Policy
This Privacy Policy explains what personal data Sangini collects, why we collect it, who can see it, how long we keep it and what you can ask us to do with it. Sangini is a product operated by RoamSaathi.
1. Who we are
Sangini is a women only platform for planning and joining social outings. It is operated by RoamSaathi (referred to in this policy as RoamSaathi, we, us or our).
For the purposes of applicable data protection law, RoamSaathi is the data fiduciary and data controller for personal data processed through Sangini. Our registered entity details and contact addresses are set out in section 16.
2. Scope of this policy
This policy applies to the Sangini web application, its progressive web app, this website and any related communications we send you, such as verification emails and plan updates.
It does not apply to services operated by other companies that you may reach from Sangini. Where a plan moves into a third party group messaging service, the privacy policy of that service applies to the messages you exchange there. Section 8 explains this in more detail.
3. The data we collect
3.1 Data you give us
- Account data. Your mobile phone number, which is required in order to create an account, and optionally an email address.
- Profile data. Your name, date of birth, age, city, gender, a short biography, a profile photo, your interests and your preferred language.
- Emergency contact. The name and phone number of a person you nominate. This is never shown to other members and is used only in the circumstances described in section 4.
- Identity verification data. A selfie and a government issued identity document, such as an Aadhaar card or a driving licence. Section 5 covers this separately because it is treated with the highest level of restriction.
- Plan content. The plans you create, including title, description, category, date, time, city, meeting details, capacity and any cover image you upload.
- Interest and participation data. The plans you show interest in, what you tell a host when you do, whether you were shortlisted, whether the host accepted you, whether you confirmed and whether you attended.
- Ratings and feedback. The ratings, highlight tags and written feedback you give after an outing, and the ratings others give you.
- Reports and safety information. Any report you submit about a member, a plan or a group, including the reason you select and the description you write, and any evidence you choose to attach.
- Support correspondence. Messages you send to our support or safety team, and notes our reviewers make about verification calls or safety cases.
3.2 Data we collect automatically
- Device and connection data. IP address, browser and device type, operating system and referring page, collected in server logs.
- Usage data. Which screens you open, which plans you view and which actions you take, used to operate the service and to investigate abuse.
- City preference. A cookie that records the city you selected in the feed switcher, so that the feed opens on that city next time. See section 7.
- Authentication data. One time passcodes and session tokens, together with the time and result of each sign in attempt. One time passcodes are stored only as an irreversible hash and expire after a short period.
3.3 Data we do not collect
We do not collect your precise device location. We do not read your contacts, your photo library beyond the files you deliberately upload, your calendar or your messages. We do not collect payment card details through Sangini.
4. Why we use your data and on what legal basis
We use your personal data only for the purposes below. Where the law requires a legal basis for processing, the applicable basis is stated alongside each purpose.
- To create and operate your account. Performance of our contract with you.
- To verify that you are a woman and that you are who you say you are. Your consent, and our legitimate interest in keeping a women only community safe. This is the single most important purpose for which we process data, and it is the reason Sangini can exist at all.
- To review plans before they are published, to shortlist interested members and to introduce groups. Performance of our contract with you, and our legitimate interest in member safety.
- To show you plans near the city you have selected. Performance of our contract with you.
- To send you service messages, such as verification outcomes, plan approvals, shortlist notifications and safety notices. Performance of our contract with you.
- To investigate reports, prevent abuse and enforce our Terms. Our legitimate interest in the safety of members, and compliance with legal obligations.
- To contact your nominated emergency contact. Vital interests. We will use this only where we have a reasonable and good faith belief that you are at risk of serious harm, or where a competent authority requires it. We do not use it for marketing, for administrative messages or for any other purpose.
- To comply with law, including responding to lawful requests from public authorities and retaining records we are required to retain. Legal obligation.
We do not sell your personal data. We do not share it with advertisers, data brokers or list resellers, and we do not use your verification documents, your emergency contact or your safety reports for any form of marketing.
5. Identity verification data
Identity verification is a manual human review. When you submit a selfie and a government identity document, the following applies.
- Your documents are stored in a private storage location that is not reachable from the public internet and that does not issue shareable or time limited public links. There is no URL that can be forwarded to view your document.
- Only trained reviewers on our verification and safety teams can open them, through an internal tool, and only for as long as they are assigned to your review.
- Every access to a verification document is recorded in an access log against the individual staff member, the document, the reason and the time. That log is retained independently of the document itself.
- Your documents are never shown to other members, are never attached to your public profile, and are never used to train any automated or machine learning system.
- We record only the outcome of the review and the minimum information needed to support it. We do not retain a copy of your full Aadhaar number or equivalent national identifier beyond what is necessary for the review, and where we are able to redact an identifier while still completing the check, we do.
Verifying your phone number and verifying your identity are two different things. Passing a phone number check never marks an account as verified. Only a human reviewer can do that.
6. What other members can see
Other members of Sangini can see the following about you:
- your name as entered on your profile, your profile photo, your age, your city, your biography and your interests;
- whether your account is verified;
- the plans you host, once those plans are published, and your rating summary.
Other members can never see the following:
- your phone number or email address, unless and until you choose to share it yourself inside a confirmed group;
- your exact date of birth;
- your emergency contact, in any form;
- your identity documents or anything derived from them;
- reports you have submitted, or reports submitted about you;
- the individual ratings or written feedback that any single person left about you.
7. Location data
Sangini works at the level of a city, not a street. We store the city you select or give us at sign up, and we order the feed by the distance between city centres. We do not request or store your device GPS location, and the distance shown against a plan is a distance between cities. It is not a measure of how far you personally are from a venue.
The meeting detail you enter for a plan is free text that you write yourself. It is shown only to members who have been confirmed for that plan.
8. Who we share data with
We share personal data only with the categories of recipient below, and only to the extent needed for the stated purpose. Each processor is bound by a written agreement that limits them to acting on our instructions.
- Cloud hosting and storage providers, who host the application, its database and its file storage.
- Phone number verification providers, who confirm that you control the phone number you signed up with. They receive your phone number and nothing else.
- Identity verification providers, where we use one to help check a government identity document. They receive only the document and the details needed for that check.
- Email and messaging providers, who deliver the transactional messages we send you.
- Group messaging services. When a group is confirmed, we may create a group on a third party messaging service and add confirmed participants using the phone numbers on their accounts. Messages exchanged in that group are governed by that service's own privacy policy and are not stored by us.
- Professional advisers and authorities, where we are legally required to disclose data, or where disclosure is necessary to establish, exercise or defend legal claims, or to prevent serious harm to a person.
If RoamSaathi is involved in a merger, acquisition or transfer of assets, personal data may be transferred as part of that transaction. We will notify you before your data becomes subject to a materially different privacy policy.
9. How long we keep data
- Account and profile data: for as long as your account is open, and for up to 90 days after you delete it, to allow for account recovery and to complete any open safety investigation.
- Verification documents: retained only while needed to complete the review and to demonstrate that the review was properly carried out. Where no legal or safety reason requires otherwise, we delete the underlying document files and retain only the outcome of the decision.
- Verification access logs: retained for a longer period than the documents themselves, because their purpose is to hold us accountable for how the documents were handled.
- Plans, participation records and ratings: retained while your account is open. After deletion they are retained in a form that no longer identifies you, so that other members' records of their own outings remain intact.
- Reports, safety cases and evidence: retained for as long as necessary for the safety of the community and for the defence of legal claims, which may be longer than the life of the account concerned.
- Server logs: typically retained for a short operational period and then deleted or aggregated.
10. How we protect your data
- All traffic between your device and our servers is encrypted in transit.
- Verification documents are held in private storage that is separate from public media and is not directly addressable.
- Access to personal data by our staff is role based, granted on a need to know basis and logged.
- One time passcodes are stored only as hashes, expire quickly and are limited in the number of attempts allowed.
- Sensitive administrative actions are recorded in an append only audit trail.
No system is perfectly secure. If a personal data breach occurs that is likely to result in a risk to you, we will notify you and the relevant supervisory authority within the periods required by applicable law.
11. Your rights and how to use them
Subject to applicable law, you have the right to:
- access the personal data we hold about you, and receive a copy of it;
- correct data that is inaccurate or incomplete, which you can do directly from your profile for most fields;
- erase your data, by deleting your account, subject to the retention rules in section 9;
- withdraw consent where our processing relies on consent, without affecting processing already carried out;
- object to or restrict processing based on our legitimate interests;
- data portability, where the law provides for it;
- nominate another person to exercise your rights in the event of death or incapacity, where the law provides for it;
- complain to your data protection authority.
To exercise any of these rights, write to us at the address in section 16. We will acknowledge your request and respond within the period required by applicable law, and in any event without undue delay. We may ask you to confirm your identity before we act on a request, so that we do not disclose your data to someone else.
Please note that withdrawing consent to identity verification means we can no longer keep you inside a verified community, and your access to plans will end.
12. Children
Sangini is not intended for anyone under 18 years of age. We do not knowingly collect personal data from children. If we learn that an account belongs to a person under 18, we will close it and delete the associated data. If you believe a child has provided us with personal data, contact us using the details in section 16.
13. International transfers
We primarily store and process personal data in India. Some of our service providers may process data in other countries. Where personal data is transferred outside the country in which it was collected, we put in place appropriate safeguards, such as contractual protections requiring a standard of protection equivalent to that of the originating jurisdiction, and we transfer only to jurisdictions not restricted by the applicable government.
14. Cookies and similar technologies
Sangini uses a small number of cookies and local storage entries, all of which are necessary for the service to work:
- Session and authentication tokens, which keep you signed in.
- City preference, which remembers the city you last selected in the feed.
- Security cookies, which protect against cross site request forgery.
We do not use advertising cookies, cross site tracking pixels or third party behavioural profiling. If we introduce optional analytics in future, we will ask for your consent first and update this policy before doing so.
15. Changes to this policy
We may update this policy as the product changes or as the law changes. The version number and effective date at the top of this page will always tell you which version applies. If a change is material, we will notify you in the app or by email before it takes effect, and where the law requires it we will ask for your consent again.
16. Contact and grievance redressal
If you have a question about this policy, wish to exercise a right, or wish to complain about how we have handled your personal data, contact us. We take every message seriously and a person will read it.
Data Protection Officer and Grievance Officer
RoamSaathi
Email: privacy@roamsaathi.com
Safety and urgent concerns:
safety@roamsaathi.com
Postal address: [Registered office address to be inserted before publication]
We will acknowledge a grievance within 24 hours of receipt and aim to resolve it within 15 days, in line with applicable Indian law. If you are not satisfied with our response, you may escalate to the Data Protection Board of India or, where you are located outside India, to your local supervisory authority.