swipetripjoin waitlist

privacy policy

Last updated

the short version

  • We collect what we need to run a safe, verified travel-dating app — nothing for advertising.
  • Your Aadhaar number is never stored. ID photos, the face cut from your Aadhaar and your liveness selfies are deleted as soon as a person has reviewed them.
  • To stop one person holding two accounts, we keep an encrypted face template — only with your separate consent, and deleted with your account.
  • Location is shared only during trips you declare, with people you choose. Never in the background between trips.
  • We never sell your data. You can see, correct or delete it anytime.

1. Who we are and what this covers

SwipeTrip ("SwipeTrip", "we", "us") runs the SwipeTrip mobile app and swipetrip.in, a travel-first dating and travel-buddy service for adults in India. For the personal data described here, we are the Data Fiduciary under India's Digital Personal Data Protection Act, 2023 ("DPDP Act").

This policy explains what we collect, why, who we share it with, how long we keep it, and the rights you have. It applies to the app, the website and the emails and messages we send.

2. What we collect

  • Account: your mobile number and email address (both verified with one-time codes), first name, optional last name, gender, and date of birth. Only your age is ever shown to others — never your date of birth.
  • Verification: photos of the front and back of your Aadhaar card, a few live selfie frames taken in the app (for example, turning your head when asked), the gender and last four digits printed on your Aadhaar as recorded by our reviewer, and an encrypted face template. See "Identity verification" and "Face matching" below.
  • Profile and preferences: the photos, answers, travel style, destinations, availability and matching preferences (for example, who you'd like to travel with) that you choose to add.
  • Trips and safety: trips you plan or declare, check-in responses, SOS events, and the name and mobile number of the emergency contacts you add.
  • Messages: chats with your matches and with our support team.
  • Location: only if you allow it, and only as described in "Location" below.
  • Device and technical: push-notification token, device name and platform, app version, IP address, and basic logs needed to keep the service secure and working.
  • Sign-up and sign-in security log: each time you request or enter a one-time code, sign up or sign in, we log the IP address, an approximate location worked out from it (city, region and country — looked up on our own servers from an offline database, so your IP isn't sent to anyone for this), your device platform and app version, and whether the code was delivered. We use this only for security and fraud prevention (for example spotting mass fake sign-ups or code abuse) and keep it for 12 months (entries linked to your account are deleted with it).

We do not collect your contacts list, and we do not use advertising SDKs or your device's advertising ID. The only third-party analytics in the app is Firebase (see App analytics and performance), used to understand and improve SwipeTrip — never to advertise to you or sell your data.

3. Identity verification (Aadhaar)

Everyone on SwipeTrip is verified before anyone can see them. In the app you photograph your Aadhaar card and take a short live selfie: the camera asks you to do a few simple things (look straight, turn your head, blink) to make sure a real person is present. Gallery photos can't be used for the selfie.

Your phone checks the photos as you take them — whether the card is sharp and fully in frame, finds the photo printed on it, and compares it with your selfie. Our servers then run their own check, and a trained member of our team reviews everything in two steps: first the faces, then the document. A person always makes the final decision.

  • We never store or show your Aadhaar number. You may upload a masked Aadhaar (with the first eight digits hidden), as UIDAI recommends. Our reviewer records only the last four digits and the gender printed on it.
  • To catch duplicate accounts without keeping your Aadhaar number, we store a one-way keyed code made from your name, date of birth, gender and those last four digits. It can't be turned back into your details.
  • We do not perform Aadhaar authentication with UIDAI and do not use your Aadhaar for any other purpose.
  • The Aadhaar photos, the face cut from them and your selfie frames are stored encrypted in private storage and deleted as soon as the review is complete — approved or not.
  • We keep the result ("verified", the date, who reviewed it) and the automated match scores, for as long as your account exists.
  • Automated tools may estimate age and gender from your selfie only to help our reviewer spot a problem (for example, someone who may be under 18). These estimates never decide anything on their own.

4. Face matching (one person, one account)

So that nobody can hold two accounts — or come back after being removed — we create a face template from your verification selfie: a set of numbers describing your face, not a photo. We compare it with the templates of other members to find possible duplicates, which a person then reviews.

  • This is biometric data, so we ask for your separate consent at sign-up and use it only for this purpose.
  • The template is encrypted and stored apart from the rest of your data, with access limited to the verification system.
  • It is created on our servers from your selfie, never shared with other members, advertisers or anyone outside SwipeTrip's service providers.
  • It is deleted when your account is deleted. You can withdraw this consent, but because it's how we keep SwipeTrip one-person-one-account, withdrawing it means closing your account.

5. Location

Location is optional and off unless you turn it on. When you allow it:

  • During a trip you declare: your live location is shared with the trip's participants and the emergency contacts you chose, until the trip ends or you stop sharing. It switches off automatically when the trip ends.
  • For SOS: pressing SOS sends your current location to your emergency contacts and our safety team.
  • For nearby trips: we use your city or general area — never your exact spot — to show trips near you.

SwipeTrip never tracks your location in the background between trips. You can withdraw location consent at any time in the app or in your phone's settings; trip safety features that need location will then be unavailable.

6. How we use your data

  • To create and secure your account, verify your identity and age, and keep you signed in.
  • To show you trips and people, explain why you might get along, and run matches, chats and trip planning.
  • To run safety features: check-ins, SOS, alerts to your emergency contacts, reports and blocks.
  • To send you codes, notifications and service emails (you control which notifications you get; safety alerts during a trip can't be turned off).
  • To prevent fraud, spam and abuse, and to enforce our Terms.
  • To meet legal obligations and respond to lawful requests.

We process your data on the basis of your consent, which you give separately for the Terms, this Privacy Policy and location. We may also process data without consent where the DPDP Act allows it, for example to respond to a medical emergency or a threat to someone's safety, or to comply with the law.

We do not sell your personal data, and we do not use it for third-party advertising.

7. App analytics and performance (Firebase)

To understand how the app is used and to find what's slow or broken, the app uses Google Firebase Analytics and Firebase Performance Monitoring.

  • What's collected: app usage events (for example, finishing a sign-up step, swiping, matching, proposing or accepting a plan, starting a call), which screens you open (by screen type, never which person or chat), your device model, operating system and app version, approximate area (city and country, which Google works out from your connection), and performance timings such as app start time, screen rendering and how long our servers take to respond.
  • How you're identified: by your SwipeTrip account ID (a random code) and an app-install ID. We never send your name, phone number, email, photos, messages or exact location to Firebase.
  • No advertising: we do not collect your phone's advertising ID, ad personalisation is switched off, and this data is never sold or used for ads.
  • Who processes it: Google, acting as our processor, only to provide these services to us.
  • How long: event-level analytics data is kept for 14 months, then deleted automatically (our Google Analytics retention setting); only aggregated, non-identifying reports are kept longer.

8. Who we share it with

  • Other members: your profile — first name, age, photos, answers, travel details and verified badge. Never your phone number, email, date of birth, ID, or exact location outside a declared trip.
  • Your emergency contacts: trip details (who, where, when), missed check-ins and SOS alerts with your location, by SMS. They don't need the app.
  • Service providers who work for us: SMS delivery (2Factor), email delivery (Resend), cloud hosting, database and private file storage, and push notifications (Apple and Google), and app analytics and performance monitoring (Google Firebase — see "App analytics and performance"). They may use your data only to provide their service to us.
  • Emergency services: when you press SOS or when we believe someone is in danger.
  • Authorities: when required by Indian law, a court order, or a lawful request from a government agency.

Some providers may process data outside India. When they do, it is only as permitted under the DPDP Act and with safeguards in our contracts.

9. How long we keep it

  • One-time codes: 10 minutes, stored only as a hash.
  • Sign-up and sign-in security log (IP address, approximate location, platform, app version): 12 months, then deleted automatically; entries linked to your account are deleted with your account.
  • ID photos, face crop and selfie frames: deleted once the review is complete.
  • Face template: until you delete your account (or withdraw face-matching consent, which closes it).
  • Your account and profile: until you delete your account.
  • After you delete your account: your profile is hidden at once and everything is permanently deleted after 30 days. Log back in during those 30 days to cancel.
  • Safety reports you're part of: kept for 90 days after deletion, then deleted, so we can protect other members and meet legal duties.
  • Records the law requires us to keep: for the period the law sets.

10. Your rights

Under the DPDP Act you can:

  • get a summary of the personal data we hold about you and how we use it;
  • correct, complete or update it;
  • have it erased (delete your account in the app, or write to us);
  • withdraw any consent you've given, as easily as you gave it — this won't affect what we did before;
  • nominate someone to exercise these rights if you die or become unable to;
  • raise a grievance with us, and then with the Data Protection Board of India if you're not satisfied.

Use the settings in the app, or email privacy@swipetrip.in. We'll confirm your identity and respond within the timelines the law sets.

11. How we protect it

Data is encrypted in transit. Passwords for staff, one-time codes and session tokens are stored only as hashes; ID images sit in private, encrypted storage reachable only through short-lived links. Access is limited to the people who need it, and actions on sensitive data are logged. No system is perfectly secure; if a breach affects you, we will tell you and the Data Protection Board as the law requires.

12. Adults only

SwipeTrip is only for people aged 18 and over. If you tell us you are under 18, we stop the sign-up and don't keep your details. If we learn that an account belongs to someone under 18, we delete it.

13. Changes to this policy

If we change this policy in a way that matters, we'll tell you in the app before the change applies and ask for your consent again where the law requires it. The date at the top shows when it last changed.

14. Contact and Grievance Officer

Questions about your data: privacy@swipetrip.in.

Grievance Officer: you can reach our Grievance Officer at grievance@swipetrip.in. We acknowledge complaints within 24 hours and resolve them within 15 days. If you're not satisfied, you may complain to the Data Protection Board of India.