Last updated: [DATE] · Draft — not yet reviewed by a lawyer
This is a first draft, written to plainly describe what Agaramiya’s code actually collects and does today — it is not a substitute for a proper legal review against India’s Digital Personal Data Protection Act, 2023 (DPDP Act), which should happen before this app handles real members’ Aadhaar numbers or payments. Anything in [brackets] below still needs a real answer.
This policy covers Agaramiya (“we”), a matrimonial platform for the Tamil community, live at agaramiya.com. It applies to anyone who creates an account.
Only what each feature actually needs to work — nothing is collected “just in case”:
By default, every table in our database is locked down so a member can only ever read or write their own row — this is enforced by the database itself (Postgres row-level security), not just by the app’s screens. Other members only ever see a deliberately narrow, purpose-built slice of your profile: a masked card (first initial, age, location, verification badge) while browsing, and your full name and about-me only after a match becomes mutual — and only if they’ve subscribed to Elite. The one person who runs Agaramiya can see member profiles, verification status, and filed reports for moderation purposes — never private message content, and never gated behind the Elite subscription (that gate exists between members, not between a member and the person operating the platform).
We don’t sell your data. It passes through a small number of service providers, each doing one specific job:
Today, data is kept for as long as your account exists — we don’t yet have an automated retention/deletion schedule. Building one (and a self-serve export/delete flow) before real members’ data is at stake is an explicit, tracked next step — see “What’s next” in the project README. Until it exists, you can request deletion or an export of your data by emailing us (Section 8), and we’ll handle it by hand.
Under the DPDP Act, you (as a “Data Principal”) have the right to access what we hold about you, ask us to correct it, ask us to erase it, and withdraw consent you’ve previously given (for example, for identity verification) — withdrawing consent doesn’t affect anything done before the withdrawal. To exercise any of these, contact us using Section 8 below.
Creating an account means you’ve read and agreed to this policy. Identity verification asks for a separate, explicit consent (a checkbox naming the DPDP Act directly) before your Aadhaar number is ever used, exactly as described in Section 2.
For any question about this policy, to exercise a right under Section 6, or to raise a grievance about how your data has been handled, contact Agaramiya’s Grievance Officer, as required under Section 8 read with Section 13 of the DPDP Act:
Vinothkumar Kannan, Founder & Grievance Officer
Email: support@agaramiya.com
We aim to acknowledge every grievance and respond within 30 days. This is Agaramiya’s general support address — not a personal address — also shown on the Support page. A dedicated grievance-only inbox may be set up separately as the platform grows.
If this policy changes in a way that matters, we’ll update the date at the top and, once Agaramiya has a way to message all members at once, let you know directly.