Praav

Privacy Policy

Last updated: 8 April 2025  ·  Effective date: 8 April 2025

1. Who We Are

Praav ("Praav", "we", "us", "our") is a relationship-discovery platform operated by Praav Technologies Private Limited, a company incorporated under the Companies Act, 2013, with its registered office in Kerala, India.

This Privacy Policy explains how we collect, use, store, share, and protect your personal data when you use the Praav mobile and web application ("Platform"). It is prepared in compliance with the Digital Personal Data Protection Act, 2023 ("DPDP Act"), the Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 ("SPDI Rules").

By creating an account or using the Platform you acknowledge that you have read, understood, and consent to the practices described in this policy.

2. Personal Data We Collect

2.1 Data you provide directly

  • Account data: mobile number, email address, password (hashed).
  • Profile data: display name, age, city/district, gender, sexual orientation, relationship intent, religion, biography, and profile photographs.
  • Communication data: messages exchanged between matched users on the Platform.
  • Payment data: transaction identifiers, order IDs, and payment status processed via Razorpay. We do not store card numbers, CVV, UPI PINs, or bank credentials.
  • Support data: information you share when contacting our Grievance Officer or support team.

2.2 Data collected automatically

  • Usage data: pages visited, features used, swipe actions, timestamps.
  • Device data: IP address, browser type, operating system, device identifiers.
  • Log data: error logs, server request logs retained for security and debugging.

2.3 Sensitive Personal Data (SPDI)

Under the SPDI Rules, sexual orientation and certain health-related information are classified as sensitive. We collect your sexual orientation solely for the purpose of enabling compatible matching. This data is not disclosed to third parties except as described in Section 5, and only with your explicit consent given at the time of profile creation.

3. How We Use Your Data

We process your personal data for the following purposes:

PurposeLegal basis under DPDP Act
Account creation and authenticationConsent / Contractual necessity
Profile display in the discovery feedConsent (you choose to publish)
Matching and messaging between usersConsent / Contractual necessity
Processing payments for premium featuresContractual necessity
Sending transactional notifications (OTP, match alerts)Consent / Legitimate use
Safety — detecting fake profiles, spam, harassmentLegitimate use (safety)
Complying with legal obligationsLegal obligation
Improving the Platform through aggregated analyticsLegitimate use (anonymised)

We do not use your data for targeted advertising or sell it to third parties.

4. Consent and Withdrawal

Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal. You can:

  • Unpublish your profile at any time from Settings.
  • Delete your account (and all associated data) from Settings → Delete Account.
  • Contact our Grievance Officer to request erasure of specific data.

Withdrawal of consent to publish your profile will result in it being hidden from the discovery feed immediately. Withdrawal of consent to process your account data will require account deletion.

5. How We Share Your Data

5.1 Service providers (Data Processors)

We share data with the following processors who act under our instruction:

  • Supabase Inc. — cloud database and storage hosting. Data stored on servers in Singapore (ap-southeast-1). Supabase complies with SOC 2 Type II.
  • Razorpay Software Pvt. Ltd. — payment processing. Razorpay is a PCI-DSS compliant processor regulated by the Reserve Bank of India.
  • Resend Inc. — transactional email delivery (OTPs, notifications).

5.2 Other users

When you publish your profile, other users can see your display name, age, city, photos, bio, orientation, intent, and interests. Your email, phone number, and exact location are never shown to other users unless you explicitly purchase and use the Contact Reveal feature.

5.3 Legal disclosures

We may disclose your data to government authorities, law enforcement, or courts when required by Indian law, a court order, or to protect the safety of users or the public.

We do not sell, rent, or trade your personal data to any third party for commercial purposes.

6. Cross-Border Data Transfers

Your data is stored on Supabase infrastructure hosted in Singapore. By using the Platform you consent to this transfer. Supabase maintains appropriate safeguards for international data transfers consistent with applicable data protection laws.

We will comply with any data localisation requirements notified by the Government of India under the DPDP Act as and when they come into force.

7. Data Retention

Data typeRetention period
Profile and account dataUntil account deletion, then 30 days for recovery, then permanently deleted
MessagesUntil either party deletes their account, maximum 2 years
Payment transaction records7 years (as required by the Income Tax Act, 1961)
Server and security logs90 days rolling
Support correspondence2 years from last interaction

8. Your Rights under the DPDP Act, 2023

As a Data Principal, you have the right to:

  • Access: obtain a summary of personal data we hold about you and how it is processed.
  • Correction: correct inaccurate or outdated personal data.
  • Erasure: request deletion of your personal data, subject to legal retention obligations.
  • Grievance redressal: file a complaint with our Grievance Officer (see Section 11).
  • Nominate: nominate another individual to exercise your rights in the event of your death or incapacity.

To exercise any of these rights, email our Grievance Officer at privacy@joinpraav.com. We will respond within 30 days of receipt of a verifiable request.

9. Security

We implement reasonable technical and organisational security measures including:

  • TLS 1.2+ encryption for all data in transit.
  • AES-256 encryption at rest for database storage.
  • Row-level security policies on all database tables.
  • Service-role keys stored exclusively on server-side infrastructure, never exposed to browsers.
  • Multi-factor authentication enforced for all administrative access.

No system is completely secure. In the event of a data breach that is likely to result in high risk to your rights, we will notify affected users and the relevant authority as required by applicable law.

10. Children

The Platform is strictly for persons aged 18 years and above. We do not knowingly collect personal data of minors. If you believe a minor has created an account, please report it immediately to our Grievance Officer and we will take prompt action to delete the account.

11. Grievance Officer

In accordance with the Information Technology Act, 2000 and the DPDP Act, 2023, we have appointed a Grievance Officer:

Name: [Grievance Officer Name]

Designation: Grievance Officer

Email: grievance@joinpraav.com

Address: Praav Technologies Private Limited, Kerala, India

Response time: Acknowledgement within 24 hours; resolution within 30 days

If you are not satisfied with the resolution, you may escalate the matter to the Data Protection Board of India once constituted under the DPDP Act, or approach a competent court of jurisdiction.

12. Cookies

We use only essential cookies required for authentication (session tokens) and security (CSRF protection). We do not use tracking, advertising, or analytics cookies. You can disable cookies in your browser settings; however, this will prevent you from logging in to the Platform.

13. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you via email or an in-app notice at least 7 days before the changes take effect. Continued use of the Platform after the effective date constitutes acceptance of the revised policy.

If you do not agree with any changes, you may delete your account before the effective date.

14. Contact Us

For privacy-related queries not covered above, write to us at privacy@joinpraav.com.

Terms of ServiceGrievance PolicyBack to Praav