Legal

Privacy Policy

Your privacy is fundamental to how we build Saundarya. This policy explains what personal information we collect, why we collect it, how it is stored and shared, and the rights you have over it under the Digital Personal Data Protection Act, 2023 (India) and the EU GDPR.

1. Who we are

Saundarya Technologies Pvt. Ltd. ("Saundarya", "we", "us", "our") is the data fiduciary responsible for the Saundarya mobile and web applications, the partner app, and this website.

Registered address: Saundarya Technologies Pvt. Ltd., 4th Floor, Prestige Atlanta, 80 Feet Road, Koramangala, Bengaluru — 560095, Karnataka, India. Data Protection Officer: privacy@saundarya.app.

2. Information we collect

Account data — name, email, phone number, city, profile photo and password hash (or the OAuth identifier if you sign in with Google or Apple).

Booking & transaction data — services booked, provider chosen, timestamps, amounts, refunds, ratings and reviews.

Biometric inputs for AI features — selfies and short video frames used for skin, hair and try-on analysis. These are processed on-device by default; when server processing is required (e.g. cloud try-on), inputs are deleted within 24 hours and never used to train models without your explicit opt-in.

Device & log data — device model, OS version, IP address, crash reports and diagnostic logs (with PII redacted).

Location data — coarse device location (city-level) for discovery, and precise location only while you are actively using map or booking screens with permission granted.

Cookies and similar technologies on the web — see the Cookie Policy for the full list.

Providing the service — booking, payments, customer support, safety and fraud prevention. Legal basis: contract.

Personalisation — home feed ranking, recommended providers, saved looks. Legal basis: legitimate interest, with opt-out in Settings → Personalisation.

AI features — skin analysis, try-on, style matching. Legal basis: your consent, granted per feature and revocable at any time.

Marketing communications — only after explicit opt-in. You can unsubscribe from every email and disable push notifications per channel.

Legal & compliance — tax, KYC of partners, response to lawful requests. Legal basis: legal obligation.

4. Who we share it with

Service providers you book with, limited to the information they need to fulfil the booking (name, contact, service, time, notes you add).

Payment processors (Razorpay, Stripe) under PCI-DSS contracts.

Infrastructure processors — Neon (managed Postgres, ap-south-1), Cloudflare (Workers + R2), Resend (transactional email), Firebase (auth + push).

Analytics processors — Google Analytics 4 and PostHog, loaded only with your consent and configured with IP anonymisation.

Law enforcement or regulators when compelled by valid legal process, or to protect the rights, property or safety of Saundarya, our users or the public.

We do not sell personal or biometric information and we do not share data with advertising networks.

5. International transfers

Personal data of Indian users is stored primarily in the ap-south-1 (Mumbai) region. Backups may be replicated to eu-central-1 (Frankfurt).

Where processors are located outside India, transfers are protected by Standard Contractual Clauses or equivalent safeguards.

6. Retention

Account data — retained while your account is active, then 30 days after deletion for reversal, and 7 years for financial records as required by Indian tax law.

Biometric inputs — deleted within 24 hours of server processing, unless you save a look to your library.

Server logs — 90 days.

Support tickets — 24 months.

7. Your rights

Access, correction, portability and erasure — request via Settings → Privacy or email privacy@saundarya.app.

Withdraw consent for any optional feature at any time.

Nominate a legal heir under section 14 of the DPDP Act.

Complain to the Data Protection Board of India, or to your local supervisory authority in the EU/EEA/UK.

8. Security

TLS 1.3 in transit, AES-256 at rest, hashed passwords (bcrypt cost 12), key rotation every 90 days, mandatory 2FA for staff with production access, and quarterly third-party penetration tests.

In the event of a personal-data breach affecting your rights, we will notify you and the Data Protection Board of India within 72 hours of becoming aware.

9. Children

Saundarya is not directed to children under 18. We do not knowingly collect data from users under 18. If you believe a minor has provided us data, write to privacy@saundarya.app and we will delete it.

10. Changes & contact

Material changes are notified 30 days in advance via email and an in-app banner.

Contact: privacy@saundarya.app · Saundarya Technologies Pvt. Ltd., 4th Floor, Prestige Atlanta, 80 Feet Road, Koramangala, Bengaluru — 560095, Karnataka, India.

Effective date

10 July 2026. Questions? Email legal@saundarya.app.