Privacy Policy

This Policy explains what Namaste Indian collects on the website and mobile apps, why we collect it, how it is used and shared, and how you can control or delete your data — including rights under India’s Digital Personal Data Protection Act, 2023.

Last updated · 24 August 2026

Data Fiduciary: Namaste Indian (“we”, “us”), operating at www.namaste-indian.com. Under the Digital Personal Data Protection Act, 2023, we determine the purpose and means of processing your personal data. This Policy applies to our website, Android and iOS applications, and related services that link here.

1. Who we are

Namaste Indian is a social platform for people in and connected to India. Features may include profiles, posts and feeds, Discover/search, news and Live TV surfaces, Reels, direct messages, voice/video calls, Hub directories (business, creator, community), roommates and schemes listings, notifications, and account settings. Not every feature is available to every user at all times.

2. Scope & Indian law

This Policy covers personal information we process when you create an account, browse while signed out, use our apps, or contact us. It should be read with our Terms of Service, Community Guidelines, and Grievance Officer page. After you sign in, product privacy controls (who can see your profile fields) are in Settings → Privacy.

Our privacy practices are designed for users in India and informed by:

3. Information we collect

We collect information you provide, information created by your use of the service, and limited information from third parties you choose to connect (such as Google Sign-In). We do not sell personal information.

3.1 Account & authentication

  • Registration — username, email address, display name, password (stored only as a one-way hash), and confirmation that you accept our Terms. We may also store invite or referral codes you use at signup.
  • Google Sign-In — if you choose Google, we receive an identifier and basic profile details Google provides (such as email, name, and profile picture) to create or link your account. We do not receive your Google password.
  • Security — optional authenticator-app two-factor authentication (TOTP) and hashed recovery codes; password-reset tokens (hashed); session tokens on your device; login and signup IP and approximate place used for security and based-in features.

3.2 Profile & Hub listings

  • Profile — details you choose to add, such as bio, avatar and banner, city/location label, website and profile links, pronouns, phone, address, date of birth, and gender, plus visibility preferences for those fields.
  • Account type — Personal, Creator, Business, or Community, including review status when you apply for a Hub listing.
  • Business / creator / community profiles — listing content you submit (names, descriptions, categories, contact details, websites, media galleries, hours, and similar fields). Business listings may include map coordinates you provide or that we derive when you set a place.
  • Account based-in — state/country (and related place labels) inferred from your network (IP) at signup or when you use the app, which you can confirm or correct. We do not continuously track your GPS for based-in.

3.3 Content you create

  • Posts & interactions — text, media, polls, hashtags, mentions, likes, bookmarks, reposts, comments, and view counts needed to operate feeds.
  • Media uploads — images, video, audio, or documents you upload (for example avatars, banners, posts, Hub galleries). Files are stored with our media provider (see Sharing).
  • Messages — direct messages are stored on our servers so you can read them on any device you sign in with. We store message text, optional chat photos, and conversation metadata needed to deliver chat. Staff may access messages for safety and abuse review. Disappearing and view-once messages are removed from Namaste after their timer; they are not end-to-end encrypted, and screenshots, notifications, or copies already on a device may remain.
  • Calls — when you place or accept a voice or video call, we process call session and signalling data (such as SDP/ICE needed to connect peers). Call audio/video is carried peer-to-peer over WebRTC where possible; we do not operate a general call-recording product.
  • Reports — when you report a user, post, or message, we store the reason, optional notes, and a content snapshot needed for moderation.
  • Optional interest signals — for example Government ID interest (we do not collect government ID scans for that signal).

3.4 Device, usage & notifications

  • Technical logs — IP address, approximate location derived from IP, user agent / app type, timestamps, and server logs used to operate, secure, and debug the service.
  • Push tokens — if you enable notifications, we store device tokens for Firebase Cloud Messaging (native Android/iOS push) and/or Web Push subscription keys for browsers.
  • Notification preferences — email and push opt-in flags and quiet-hours settings on your account; device-level mute or opt-out flags may also be stored locally.
  • Search — queries you run may be saved to your account search history (which you can clear). We also keep anonymous aggregate search statistics without tying them to your user id.
  • Optional precise location — only when you use a feature that asks for it (for example confirming based-in with device location, or attaching a place to a post). You can deny permission; core browsing still works.

3.5 What we do not collect as product analytics

We do not integrate third-party advertising or product-analytics SDKs such as Google Analytics, Firebase Analytics, Mixpanel, Amplitude, or Crashlytics in the application source reviewed for this Policy. We rely on first-party server logs and product metrics needed to run Namaste Indian. External content partners (for example video catalogues or Live TV sources) may process requests according to their own policies when you use those surfaces.

4. How we use information

  • Create and secure accounts, including Google Sign-In and 2FA.
  • Provide feeds, profiles, Hub listings, search, news, Live TV, Reels, chat, calls, and settings you use.
  • Send transactional email (password reset, security alerts, and similar service messages) and optional activity email if you keep email notifications on.
  • Deliver push notifications you allow; respect quiet hours and opt-outs where implemented.
  • Moderate reports, enforce Terms and Community Guidelines, prevent abuse, and comply with applicable Indian law.
  • Personalise local context (such as based-in) and improve reliability and performance of the service.

5. Lawful use & consent (DPDP)

Under the DPDP Act, 2023, we process personal data for a lawful purpose either with your consent or for certain legitimate uses recognised by law (for example, employment is not our primary basis; more relevant examples include responding to medical emergencies we do not operate, or complying with law / court / government orders). For Namaste Indian, the primary bases are:

  • Consent — when you create an account, accept Terms / Privacy, enable optional permissions (notifications, precise location, camera/mic for calls), or connect Google / Apple Sign-In.
  • Service delivery — processing needed to provide the features you request (feeds, chat, Hub listings, security).
  • Legal compliance & safety — fraud prevention, moderation of unlawful content, responding to valid legal process, and protecting children and the public.

You may withdraw consent for optional processing (for example turn off push notifications or revoke device permissions) without losing core account access, except where that processing is necessary to provide a feature you continue to use. Withdrawal does not affect processing already completed lawfully.

6. Sharing & service providers

We do not sell your personal information. We share data only as needed to run Namaste Indian:

  • Other users — content and profile fields you make public or share in posts, Hub listings, or messages.
  • Infrastructure — database hosting (MongoDB Atlas) and application/web hosting providers that process data under our instructions.
  • Media — Cloudinary stores and delivers uploaded media.
  • Email — transactional email via Brevo and/or Resend.
  • Sign-in — Google for Google Sign-In token verification.
  • Push — Firebase Cloud Messaging for native push; browser push services for Web Push.
  • Calls — public STUN servers may assist WebRTC connectivity; we do not currently operate a private TURN relay as a product feature.
  • Maps & place lookup — IP/geo and reverse-geocode providers (such as IP lookup and OpenStreetMap Nominatim) when we resolve places you request.
  • Content partners — when you use Live TV, requests may go to catalogue providers such as YouTube under their terms.
  • Optional schemes data — government/scheme search partners when that Hub feature is enabled.
  • Authorities — when required by applicable Indian law or to protect people and the platform.

7. Cookies & device storage

Namaste Indian primarily uses local device storage (such as browser localStorage / sessionStorage and equivalent Capacitor storage on Android) rather than advertising cookies. Examples include session tokens, theme and language preferences, multi-account switcher data, push opt-out flags, and short-lived UI caches. Older app versions may still have unused encrypted chat-key backups in IndexedDB from a former scheme.

Clearing site or app data signs you out. Some features will not work until you sign in again.

8. Android / iOS app permissions

Our mobile apps may request permissions so features you choose can work. You can deny optional permissions in system settings; core browsing may still work with reduced functionality.

  • Internet / network state — load the app and sync with our servers.
  • Notifications — deliver push alerts when you enable them.
  • Photos / videos / storage (as applicable by Android version) — let you pick images or videos for posts, avatars, banners, and Hub media.
  • Location (approximate or precise) — optional based-in confirmation, place attachment on posts, or map-related Hub fields. Not used for continuous background tracking of based-in.
  • Vibrate — haptic feedback for certain interactions (for example pull-to-refresh).
  • Camera and microphone — requested at runtime when you start or accept a voice or video call (WebRTC). We do not use these for silent recording.

We do not ask to read your contacts address book for Namaste Indian features described in this Policy.

9. Security

  • In transit — production traffic is served over HTTPS; the Android app is configured to disallow cleartext HTTP.
  • Passwords — stored with a modern one-way hash (BCrypt); we never store plaintext passwords.
  • Sessions — authenticated API access uses tokens (JWT) that can be invalidated when you change security settings or we bump session versions.
  • Chat — direct messages are stored on our servers and delivered over HTTPS; they are not end-to-end encrypted. Disappearing messages vanish from Namaste after the timer, not from screenshots or devices that already received them.
  • Access — staff moderation and admin tools are restricted to authorised roles; abuse of access is prohibited.
  • Your responsibilities — use a strong unique password, enable 2FA when available, keep your devices updated, and be careful with links and shared devices. No online service is perfectly secure.

We do not claim that every database field is encrypted at rest beyond what our infrastructure providers offer under their standard controls.

10. Retention

We keep account, content, and operational data while your account is active and as needed for security, abuse prevention, disputes, backups, and legal obligations. After deletion or purge, residual copies may remain in encrypted backups or logs for a limited period before they age out. Moderated reports and safety records may be retained longer when needed to protect the community or comply with law. Disappearing and view-once chat messages are scrubbed from active chat storage after their timer; backups, logs, or safety review copies may still exist for a limited period.

11. Your rights under the DPDP Act, 2023

As a Data Principal, you may exercise rights available under the Digital Personal Data Protection Act, 2023, including:

  • Right to access information — about the personal data we process about you and the processing activities (where applicable).
  • Right to correction and erasure — correct inaccurate or incomplete personal data, and request erasure when the data is no longer necessary for the purpose, consent is withdrawn, or erasure is otherwise required — subject to retention needed for security, disputes, and law.
  • Right of grievance redressal — raise a concern with us (see Grievance Officer below); you may escalate to the Data Protection Board of India once that mechanism is fully operational under the Act and rules.
  • Right to nominate — nominate another individual to exercise your rights in the event of death or incapacity, as provided under the Act (contact us to record a nomination).

In product, you can already:

  • Access & edit — view and update most profile and privacy fields in Settings and Edit profile.
  • Visibility — control many public fields under Settings → Privacy.
  • Notifications — turn email/push preferences off in Settings; also use device notification settings and email unsubscribe links where provided.
  • Search history — clear history from Discover/search tools where available.
  • Content — delete posts and other content you control. Disappearing chat messages are removed from Namaste after the timer; recipients may still have screenshots or copies already on their devices.
  • Requests — email namasteindia.ap@gmail.com with “Privacy / DPDP” in the subject for access, correction, erasure, or nomination requests we cannot complete fully in-app.

12. Account & data deletion

You can delete your account after signing in: open Settings → Security and follow the delete-account flow (username confirmation; password and/or 2FA when those protections are enabled). Deletion removes or disassociates account data we control according to our purge process (including profile content, posts you own, chat messages we store for you, device push tokens, and related records), subject to backups, legal holds, and information needed for safety or compliance.

If you cannot access your account, contact namasteindia.ap@gmail.com with proof of ownership so we can help.

13. Children

Under the DPDP Act, 2023, a child is an individual under 18 years. We do not knowingly process children’s personal data for tracking, behavioural advertising, or other purposes barred for children. Account creation requires acceptance of Terms; users under 18 need consent of a parent or lawful guardian for use of the service and related processing. We also apply a practical minimum age of 13 (when date of birth is set) consistent with common app-store expectations.

If you believe a child is using Namaste Indian without required consent, or that we hold a child’s data inappropriately, contact us so we can take appropriate action. Our Child Safety Standards explain how we prevent and report child sexual abuse and exploitation under POCSO and related law.

14. Where data is processed

We operate with a focus on India. Servers, databases, media, email, and push providers may process data in India and other countries where those providers maintain infrastructure. By using Namaste Indian you understand that your information may be transferred to and processed in those locations subject to appropriate safeguards offered by those providers and applicable law, including the DPDP Act’s rules on cross-border transfers as notified by the Central Government from time to time.

15. Grievance Officer

For privacy complaints, DPDP rights requests, or intermediary grievances related to personal data or content, contact:

We aim to acknowledge grievances within 24 hours and resolve them within 15 days, as expected under the IT Rules, 2021.

16. App Store & Google Play

This Privacy Policy is the public policy linked from our Google Play and Apple App Store listings. It is available at a stable, publicly accessible URL without a login wall:

Google Play. Play Console requires this policy in the Privacy Policy field and the Data safety form. In-app, the same policy is linked from Settings → Policies and from account registration. Account deletion removes or disassociates data we control (not a mere freeze), as described in Account & data deletion above. Disclosures in Data safety must match this Policy (account info, messages, media, location when you allow it, device identifiers / push tokens, and the processors listed under Sharing).

Apple App Store. App Store Connect requires a Privacy Policy URL for the app. Reviewers must reach Privacy Policy and Terms of Use without signing in — both are public on this site. Optional User Privacy Choices may point to the rights section above. App Privacy “nutrition labels” in App Store Connect must match the data practices described here.

For store reviewers: the developer / app name is Namaste Indian (package / bundle com.namasteindia.app). Privacy contact: namasteindia.ap@gmail.com.

17. Changes to this Policy

We may update this Policy to reflect product, legal, or operational changes. The “Last updated” date at the top of this page will change when we do. Material changes may also be communicated in-product or by email when appropriate. Continued use after an update means you acknowledge the revised Policy.

18. Contact

Privacy questions, data requests, or deletion help:

For Google Play and App Store reviewers: this Policy is publicly available at https://www.namaste-indian.com/privacy. Terms of Use: https://www.namaste-indian.com/terms. Child Safety: https://www.namaste-indian.com/child-safety.