Zoadi is committed to protecting your privacy. This Privacy Policy explains what information we collect from you, why we collect it, how we use and share it, and the choices and rights you have regarding your information. This Policy applies to information collected through our mobile applications, website, and related services. By using Zoadi, you consent to the data practices described in this Policy. If you do not agree with any part of this Policy, please do not use our Services.
1. Information We Collect
We collect personal information that you voluntarily provide to us, information generated by your use of our Services, and information from third parties (such as when you use social login). The types of information we collect include:
- Profile and Account Data: When you sign up, we collect information like your name, email address, phone number, date of birth, gender, and location. You will also provide profile details such as photographs, a personal description, preferences for a partner, and possibly information about your family background, culture, and other personal attributes (for example, religion/caste, mother tongue, occupation, education). Because Zoadi is a matrimony-focused service, you have the option to share sensitive personal information on your profile, such as details about your health or lifestyle (e.g., dietary preferences, health conditions), or financial information (e.g., salary range) – however, providing such details is voluntary. We treat any health, financial, religious, or similar sensitive data you choose to provide with heightened care, as many laws consider these categories “sensitive personal information” requiring special protection.
- User Content: Any content you upload or post on the Service is collected. This includes profile photographs and gallery images, descriptions and essays, and chat messages or other communications with other users. Please be aware that content you share with other users (such as in messages or in your public profile) is at your discretion and risk – avoid sharing information you wouldn’t want to be public.
- Third-Party Login Data: If you register or log in via a third-party Single Sign-On (SSO) service (like Microsoft Sign-In, Google Sign-In, Apple Sign-in, or Facebook Login), we receive information from that provider such as your name, email, and profile photo. We only collect the information that your chosen SSO provider shares with us or allows you to share, and we will use it according to this Policy.
- Device and Usage Information: We automatically collect certain information about your device and how you interact with our app/website. This may include:
- Device identifiers and hardware info: such as your device type, operating system version, unique device ID, and app version.
- Log and usage data: such as access times, pages or screens viewed, IP address, location information (if you allow location access, we may collect approximate location data to show you nearby matches or relevant content), and other technical data about your use of the Service.
- Cookies and tracking: Our website (and possibly our app) uses cookies or similar tracking technologies to remember your preferences and analyze usage. For example, we might use cookies to keep you logged in on the website, or to understand which pages are popular. We do not use cookies for third-party advertising without your consent. You can control cookies through your browser settings, but disabling cookies may affect functionality of the site. (See “Tracking & Cookies” below for more detail.)
- Financial and Payment Information: If you purchase a premium membership or other paid feature, we (or our third-party payment processor) will collect payment information. This may include your credit/debit card number or other payment account details and billing address. We do not store full financial account numbers or credit card numbers on our servers; such data is typically handled by secure third-party payment processors compliant with PCI-DSS standards. For example, if you pay via in-app purchase, Apple or Google will process the transaction and we do not receive your card information. We keep a record of your transactions with us (what you purchased and when) for financial and auditing purposes.
- Information from Others: We may receive information about you from other users or third parties. For example: if a family member is involved in your matchmaking process, they might provide information about you or verify information (with your consent). If another user contacts us about you (such as reporting a concern), we will collect whatever information they provide and any subsequent investigation records. Also, if you contact our customer support, we will receive whatever information you choose to share in that communication.
No Collection of Protected Health/Financial Data: We do not collect government-issued identification numbers, social security numbers, or financial account passwords via our app. We also do not intentionally collect any “protected health information” as defined under HIPAA, since we are not a healthcare provider. Any health-related info you share is by your choice and for personal matchmaking context, not for medical purposes.
Information About Others: If you choose to provide us with personal information of others (for example, you invite a parent to help manage your profile, or you provide a reference contact), you must ensure that you have legal authority or their consent to share that information with us. By providing someone else’s personal data, you represent that you have the right to do so and that you’ve informed them of their rights as relevant. We will use such third-party personal data only for the specific reason it was provided (e.g., to contact the person for verification or to allow them access if it’s a feature).
2. How We Use Your Information
We use your personal information for the following purposes, and we rely on certain legal bases for processing (such as your consent, necessity to perform a contract, and our legitimate interests) as appropriate:
- To Provide and Personalize the Service: We process the information you provide (and other data) to operate the Zoadi platform. This includes creating and displaying your profile to other users, recommending potential matches, and enabling communication (e.g., showing you relevant profiles based on your preferences and vice versa). Our matching algorithm and search functions use the data in your profile (age, location, preferences, etc.) to suggest suitable matches, consistent with the purpose for which you provided the data. We may also personalize your experience by highlighting profiles that might interest you or new features that align with your usage. All these uses of your data are fundamentally to fulfill our contract with you in helping you find a compatible match.
- Verification and Security: We use personal data to verify accounts and ensure trust on the platform. For example, we might use your email or phone number to verify your identity or send a one-time password (OTP). We may also use device and log info to detect and prevent fraudulent behavior – for instance, flagging if multiple accounts use the same device or if automated bots try to scrape data. Profile information may be used to authenticate that users are real and meet our eligibility (e.g., ensuring a user is not underage or married). These activities are in our legitimate interest to keep the platform safe and are often also necessary to comply with legal obligations (such as knowing our users to some extent to prevent fraud).
- Facilitating Family Involvement: One aspect that sets Zoadi apart is the ability (if you choose) to involve family members in the matchmaking process. With your permission, we may allow your family member(s) to view or assist with your profile. We might also share certain progress updates or information with them as directed by you. Any such involvement will be under your control and this data use is based on your consent (which you can withdraw by changing settings or notifying us).
- Communication: We will use your contact information (email, phone number) to send you service-related communications. These include: verification codes, notifications about matches or messages, updates about the Service or Terms, and customer service responses. We may also send promotional communications such as newsletters, new feature announcements, or offers, but you will have the opportunity to opt-out of marketing emails or texts. (Transactional service messages, like password resets or match alerts, are necessary for the Service and may not have an opt-out unless you stop using the Service.)
- Payment Processing: If you make purchases, we use your payment information to process those transactions and manage billing. For example, we’ll use and transmit your card data to the payment gateway to charge you, and we’ll use your contact information to send receipts or invoices. We also use purchase history to manage subscriptions (e.g., automatic renewal management) and to apply any applicable taxes.
- Improving and Researching the Service: We may analyze aggregate usage data and feedback to improve Zoadi’s functionality, user experience, and algorithms. For instance, we might review how users navigate the app, or what profile attributes lead to more connections, in order to refine our matchmaking logic. We may also use data for troubleshooting and testing new features. Whenever feasible, we use de-identified or aggregated data for these purposes, which does not identify individuals. In some cases, we may use personal data internally to train our matching models (ensuring we handle it in compliance with consent requirements; e.g., we will not use sensitive data for algorithm training beyond what is necessary for matching without proper legal basis).
- Advertising and Analytics: Currently, Zoadi does not sell your personal data to third-party advertisers. If we display any ads, they will likely be generic or based on non-identifiable criteria (like location or context). We may, however, use third-party analytics tools (like Google Analytics) to understand how users use our Service. These tools may employ cookies or device IDs. We ensure any analytics partners do not receive directly identifying information about you, and any data shared is subject to confidentiality and used only to provide their services to us. If in the future we decide to use your data for targeted advertising or to share data with advertising partners, we will do so only if we have a lawful basis (such as your explicit consent, especially in jurisdictions like India’s DPDPA which require consent for such use). We will update this Policy and provide opt-outs as required in that event.
- Compliance and Legal Obligations: We may process personal data as required to comply with applicable laws, regulations, and legal processes. This includes retaining records as required by tax law, responding to valid requests from government or law enforcement (we will only disclose data to authorities if we believe in good faith we are legally required to do so), and using data to exercise or defend legal claims. For example, if we receive a subpoena or court order, we might need to preserve and share certain data. We also keep data as needed to enforce our Terms of Service, such as investigating violations or banning users who violate rules.
- Protecting Vital Interests or Public Interest: In rare cases, we might use or share information to prevent an emergency involving danger of death or serious physical injury to any person. Additionally, if needed in the public interest (for instance, assisting with a public health mandate or contact tracing in an outbreak, as permitted by law), we would handle data accordingly, though these situations are uncommon and would be done in line with legal allowances.
We make sure that our collection and use of personal data is limited to what is necessary for the purposes we’ve described. We do not use your personal information for completely unrelated purposes without updating you and obtaining appropriate consent. If we plan to process your data for a purpose materially different from what is disclosed here, we will notify you and, if required, seek your consent.
3. How We Share Your Information
We understand that your personal information is sensitive, and we share it only in certain circumstances:
- With Other Users: The very nature of our Service is to share some of your information with other users, because it’s a matchmaking platform. By creating a profile, you consent to share your profile information with other registered users. This includes details like your first name, age, general location (city or country), community background, and other profile attributes. You can control what information is included in your profile. Certain sensitive fields (for example, income or health details) are optional – if you provide them and make them part of your profile, they will be visible to others viewing your profile, so consider carefully what you share. We may also show indicators like “online now” or last active time to other users. Your contact information (email, phone) is never visible to other users unless you explicitly provide it to them in chat. We encourage you to keep communications within our platform for safety and privacy.
- With Your Family (if applicable): If you choose to involve family members or nominate a family elder/representative in the process (a feature we may offer), some of your information may be shared with them. For instance, you might authorize a parent to have limited access to your account or to receive copies of match suggestions. Such sharing will only occur with your explicit consent and configuration.
- Our Service Providers: We use trusted third-party companies to perform certain business-related functions. These include, for example:
- Hosting and Infrastructure: Zoadi is built on secure cloud services (such as Amazon Web Services). Thus, your data is stored and processed on cloud servers that we lease. We ensure that these providers implement robust security measures. In fact, AWS maintains compliance with high security standards (including certifications like ISO 27018 for cloud privacy and PCI-DSS for financial data security). They act under our instructions and do not access or use your data except as needed to maintain the service.
- Analytics and Crash Reporting: We may use analytics tools (e.g., Google Analytics or Fabric/Firebase Crashlytics) which may process usage data and device identifiers to help us understand app performance and stability. These providers are prohibited from using personal data for any purpose other than providing services to us.
- Payment Processors: When you make payments, third-party processors (such as Stripe, Apple, Google, or other payment gateways) will receive your payment data to process transactions. They are PCI-DSS compliant and are authorized to use your data only as necessary to process payments. We do not receive or store your full credit card info from the app stores; we may receive limited info like the last four digits of a card or a transaction ID.
- Communications Providers: We may use services to send communications to you (for example, an SMS provider for sending verification codes to your phone, or an email service like SendGrid for emails). These providers will have access to your phone number or email only for the purpose of sending the messages and not for their own use.
- Verification Services: If we employ third-party verification (such as identity verification or background checks in the future), we would share necessary data (like your name or ID documents) with those vendors to perform the verification. This will be done only with your knowledge (e.g., asking you to submit to an ID check). All these service providers are bound by contractual obligations to keep your information confidential and to use it only for the services they provide us. We conduct diligence to ensure they have strong data protection practices.
- With Legal Authorities or When Required by Law: We may disclose personal information if we genuinely believe that such action is necessary to: (a) comply with a legal obligation or valid legal process (e.g., subpoenas, warrants, or court orders); (b) enforce our Terms of Service or other agreements, and investigate potential violations; (c) detect, prevent, or address fraud, security, or technical issues; or (d) protect the rights, property, or safety of Zoadi, our users, or the public. For example, if we are mandated by law enforcement with a lawful request for user data relating to a criminal investigation, we may be compelled to provide it. We will challenge overbroad or unlawful requests as appropriate. In jurisdictions with data protection laws, we will ensure any disclosure aligns with those laws (for instance, under India’s laws, disclosures will be made only per lawful request; under U.S. law, we may have to comply with certain government requests, etc.).
- Business Transfers: If Zoadi is involved in a merger, acquisition, financing due diligence, reorganization, bankruptcy, receivership, sale of company assets, or transition of service to another provider, your information may be transferred as part of such a transaction. We would ensure the new owner or successor continues to handle your information in line with this Privacy Policy (or you’ll be given notice and a chance to opt-out or delete your data, as applicable). For example, if another company acquires Zoadi, your information would likely be one of the assets transferred, but the new company would be bound to this Policy’s commitments until it’s updated and you’re notified.
- Aggregated or De-Identified Data: We may share information that has been aggregated or anonymized, so it no longer can identify you, for research, marketing, or other business purposes. For instance, we might publish statistics like “Zoadi has 10,000 users in 2025” or “30% of our users are in Canada” or share insights on diaspora matchmaking trends. Such information will not contain personal data and is not subject to usage restrictions because it cannot be traced back to any individual.
We do NOT sell your personal information to third parties for monetary consideration. We also do not share personal information with third parties for their own direct marketing uses without your explicit consent. In the context of certain privacy laws like the California Consumer Privacy Act (CCPA/CPRA), “selling” or “sharing” has broad definitions, and Zoadi’s policy is to refrain from any practice that would be deemed selling under those laws (for example, we do not exchange user data for money with data brokers). If that ever changes, we will provide required notices and opt-out rights.
If we ever need to share your data in any manner not covered above, we will do so only with your consent or after providing you with notice and a clear opportunity to opt out.
4. International Data Transfers
Zoadi is initially focused on users in the United States, Canada, and India, but we aim to serve users globally. Consequently, your information may be transferred to and stored on servers in multiple countries, including the United States. Specifically, our primary servers are on AWS data centers which might be in the U.S. or another region we select. Also, our core team and support staff may operate from the U.S. (and possibly other countries) to service the platform. This means your personal information could be processed outside of your home country.
Protection for Cross-Border Data: When we transfer personal data internationally, we take steps to protect it:
- If you are in Canada or the European Economic Area (EEA) or the UK, and your data is transferred to a country that does not have an adequacy decision or similar level of data protection, we will implement appropriate safeguards. These may include using standard contractual clauses approved by regulators, or other lawful mechanisms, to ensure your data is afforded a high level of protection in the destination country. You can contact us for more information on the safeguards for cross-border transfers.
- Users in India should be aware that your data may be transferred out of India. Under the upcoming Digital Personal Data Protection Act, 2023 (DPDPA), transfers will be permitted subject to certain conditions and government notifications. We will ensure compliance with any localization or transfer requirements that become law. At present, by using Zoadi and providing your data, you consent to the transfer of your data outside India for processing. We will only transfer to jurisdictions or entities that we believe have robust data protection measures in place.
- Regardless of where your data is stored, we will apply the same protections described in this Privacy Policy. Our service providers are contractually obligated to protect your data to standards commensurate with the laws of your home country, where applicable. For example, our cloud provider (AWS) allows us to control where data is stored and has stringent security and privacy controls.
- That said, different countries have different laws and the data in transit may be subject to lawful access by courts, law enforcement and national security authorities in the destination jurisdictions. We strive to only disclose data under strict legal procedures (as noted in “How We Share…”).
By using our Service, you understand that your information will be transferred to the United States and possibly other jurisdictions, which may have data protection rules that are different or less stringent than those of your country. However, we value your privacy and will take all necessary measures to ensure your data is treated securely and in accordance with this Policy.
5. Data Security
We employ a variety of administrative, technical, and physical security measures to protect your personal information. These measures are designed considering the sensitivity of the data we collect (for instance, we recognize that some personal data such as health or financial info is highly sensitive and requires strong protection). Our security practices include:
- Encryption: We use industry-standard encryption protocols (such as HTTPS/TLS) to encrypt data in transit between your device and our servers. Sensitive personal data and passwords are encrypted at rest in our databases.
- Access Controls: Access to personal data is restricted to authorized personnel who need it to operate, develop or support our Services. Zoadi team members are bound by confidentiality obligations. We also implement access logs and audits; any third-party service providers who might have incidental access (such as cloud platform staff) are similarly bound by strict obligations and technological barriers.
- Security Certifications: Our infrastructure partners (like AWS) maintain high-level security certifications and compliance (including ISO 27001, SOC 2, PCI-DSS for handling payment data, and adherence to GDPR requirements). We inherit many of these security controls from our providers and layer our own controls on top. AWS data centers are highly secure, employing measures like biometric access, 24/7 monitoring, and built-in firewalls.
- Testing and Updates: We regularly update our application and backend systems to apply security patches and improvements. We conduct periodic security assessments and may engage third-party security auditors or use bug bounty programs to identify vulnerabilities. Our code and systems are monitored for unusual activity.
- Payment Security: Any payment information entered in our app is transmitted securely to the payment gateway. We comply with Payment Card Industry Data Security Standard (PCI-DSS) when handling credit card data (mainly by using certified payment processors so that we do not directly store sensitive card numbers).
- Anonymization: Where possible, we anonymize or pseudonymize data. For instance, if we use production data for testing, we remove identifying details. When creating analytical reports, we use aggregated data.
- Employee Training: We train our team about the importance of privacy and security. We have internal policies governing how confidential information is handled.
Despite all these measures, it’s important to note that no method of transmission over the Internet or electronic storage is 100% secure. We strive to protect your data, but we cannot guarantee absolute security. You also play a role in security: please choose a strong password, do not share it, and notify us immediately of any unauthorized account access.
Data Breach Procedures: In the event of a data breach that affects your personal information, we will act promptly to contain and investigate the breach. We will notify affected users and the relevant authorities as required by law. For example, under Canadian law, we must inform the Privacy Commissioner and individuals of certain breaches. Similarly, many jurisdictions (like states in the U.S., EU’s GDPR, and India’s forthcoming law) require breach notification. We will comply with these obligations, providing you information about what happened, what data was involved, and recommendations for your protection, in a timely manner.
6. Data Retention
We retain your personal information only for as long as necessary to fulfill the purposes for which we collected it, including for the purposes of satisfying any legal, accounting, or reporting requirements. The criteria used to determine our retention periods include: the length of time you have an account with us, the nature and sensitivity of the information, and the potential risk of harm from unauthorized use or disclosure of the information.
- Active Accounts: For as long as you maintain an account on Zoadi, we will keep the information you have provided and data generated by your use. This is necessary to operate the Service (for example, your profile needs to exist to show it to others, your chat messages need to be stored so you and your recipients can access them, etc.).
- Inactive Accounts: If you do not log in or use your account for an extended period, we may flag the account as inactive. We may contact you before deleting an inactive account. Generally, core profile information might be retained for a certain period (for example, 1-2 years) in case you return, unless you delete your account. We will either delete or anonymize data from inactive accounts after that period, unless we have legal reasons to keep it longer.
- Account Deletion: If you choose to delete your account, we will initiate deletion of personal information associated with your account from our production systems. We aim to do this promptly (within 30 days in many cases, subject to technical feasibility). However, some information may be retained in backups or logs for a short period until those are cycled out. Also, we may retain certain information even after account deletion if we have a legitimate reason: e.g., records of transactions for financial reporting, information needed for dispute resolution or legal defense, or data we’re required to keep by law. When we retain data for such reasons, we limit access to it and only use it for that purpose.
- Chat and Communications: Messages you send to other users may persist on the Service (in the recipient’s inbox) even after you delete your account or the message on your side. We generally do not purge chat histories unless both users have deleted the conversation or closed their accounts. If you want a specific chat removed, you can request that we delete it for both parties, but we will need both users’ agreement or some verification to do so.
- Backup & Archival: Our system may keep backup copies of data (for reliability) which are retained for a limited time with strict access controls. After the retention period, backups are destroyed or overwritten.
- Legal Hold: If we are involved in litigation or receive a legal request relevant to your data, we may retain your information as needed to comply with our legal obligations or to establish or defend claims, until such issues are resolved – even if that extends beyond our standard retention timeline.
- Anonymized Data: In some cases, rather than deleting your data, we may anonymize it so it can no longer be associated with you, and use it for statistical purposes. For example, after you delete your account, we might keep aggregated statistics that include data from your usage (like number of matches made) but not in a way that identifies you.
In summary, we endeavor not to keep personal data longer than necessary. When data is no longer needed, we will ensure it is either securely deleted or irreversibly anonymized.
7. Your Rights and Choices
Depending on your jurisdiction and subject to applicable law, you may have certain rights regarding your personal information. We are committed to honoring the rights of users as required by law and, in many cases, even if not legally required, we strive to provide you with control over your information.
Access and Correction: You have the right to access the personal information we hold about you and to request correction of any inaccuracies. Much of your basic information is accessible and editable directly through your profile settings (for example, you can log in and edit your profile details, preferences, photos, etc. at any time). If you need assistance or wish to get a full copy of your data, you can contact us (see Contact section below). We will provide you with a summary of the data we have about you and, if you find any of it to be incorrect or outdated, you may request an amendment. We may ask for verification of identity before releasing data to ensure we don’t send your personal data to an impostor.
Deletion (Right to Erasure): You can delete your account through the app’s settings. This will remove your profile from being seen by others. As noted in Data Retention, we will then delete or anonymize personal data in accordance with our retention practices. In certain jurisdictions (such as under California law or EU GDPR), you have the right to request deletion of your personal data. We honor such requests unless we have a lawful reason to retain specific data (for instance, if we must keep certain records for legal compliance or if an exception under law applies). If you just want to take a break, you might choose to “deactivate” your profile (if we offer such a feature) rather than deletion; a deactivated profile is hidden from others but retains your data for when you return.
Withdrawal of Consent: In cases where we process your information based on your consent, you have the right to withdraw your consent at any time. For example, if you consented to us using your sensitive personal information (like health or religious data) on your profile and you change your mind, you can remove that data from your profile (withdrawing consent to process that piece of data) or request we delete it. Similarly, if you consented to receive promotional emails or optional features, you can opt out. Note that withdrawal of consent does not affect the lawfulness of processing before the withdrawal. If you withdraw consent for essential data (like you no longer want us to process any of your personal data), we might have to close your account, as we cannot provide the service without processing that data.
Object or Restrict Processing: In certain jurisdictions (e.g., EU/UK), you have the right to object to our processing of your personal data, or ask us to restrict processing. For example, you can object to processing done on legitimate interests grounds if you believe your rights outweigh our interests. You can also request restriction if you contest the accuracy of data or have certain other disputes with processing. We will consider such requests and comply if required by law. For instance, if you object to direct marketing, we will stop using your data for that purpose (which you can also achieve simply by unsubscribing from marketing emails).
Data Portability: To the extent applicable (e.g., under GDPR or the new Canadian Consumer Privacy Protection Act if it comes into force), you may have the right to obtain your personal data in a structured, commonly used, and machine-readable format, and to have that data transmitted to another service provider where technically feasible. If you need such an export, we can provide your profile and basic data in a JSON or CSV format upon request.
Automated Decision-Making: Zoadi’s matchmaking algorithm may be considered a form of automated processing that affects which profiles you see. You have the right not to be subject to a decision based solely on automated processing that significantly affects you, unless it’s necessary for entering or performing a contract with you or based on your explicit consent, etc. Our matching suggestions are a core part of the service you signed up for (performance of contract) and do not produce legal effects on you, but we understand you might want insight. While we cannot disclose proprietary algorithm details, we can assure you that we do not use algorithms to discriminate or make prohibited decisions. If you have specific concerns about an automated decision (like if you believe our system is unfairly limiting your visibility), you can contact us and we will review the situation with human intervention as needed.
California Privacy Rights: If you are a California resident, in addition to the rights above, you have rights under the CCPA/CPRA including:
- The right to know what personal information we have collected about you, including categories of information, sources, purposes, and third parties with whom we share it. Much of this is outlined in this Privacy Policy. You can also request that we provide the specific pieces of personal data we have about you.
- The right to delete personal information (subject to exceptions).
- The right to correct inaccurate personal information.
- The right to opt out of “selling” or “sharing” personal information. (As stated, we do not sell your data in the traditional sense, but if any sharing were to be considered a “sale” or “share” under CPRA, you can opt out. For example, if we ever introduce personalized advertising using your data, we will provide a “Do Not Sell or Share My Personal Information” link as required.)
- The right to not be discriminated against for exercising your CCPA rights. We will not deny you our services or provide a different level of service just because you exercised your privacy rights. (However, note that deleting certain data or opting out of some uses may affect our ability to provide the Service – e.g., if you don’t allow us to use your profile data, we can’t match you – which is a logical consequence but not discrimination under the law.) If you are a California resident and want to exercise these rights, you can contact us as described below. We may need to verify your identity (for example, by confirming some information we have on file) before fulfilling requests. You may also designate an authorized agent to make requests on your behalf by providing the agent with written permission; we will still take steps to verify that the request is valid.
Canadian Users: If you are in Canada, you have similar rights under PIPEDA: you can request access to your personal information and challenge its accuracy and completeness. We will respond to such requests within a reasonable time (generally within 30 days as required by PIPEDA, unless an extension is permitted). If you are not satisfied with our response, you may have the right to file a complaint with the Office of the Privacy Commissioner of Canada. Our designated Privacy Officer will assist with any concerns (see Contact section).
Indian Users: Under the currently applicable IT Act rules (and forthcoming DPDPA, 2023), you have rights such as the ability to access and review information you provided, and withdraw consent. You may also contact our Grievance Officer for any complaints regarding data handling. Once the DPDPA is in effect, you will have rights like the right to correction and erasure, the right to seek grievance redressal via the Data Protection Board of India, etc. We will update our practices to align with the new law and facilitate those rights. For now, if you’re in India and have a question or request regarding your data, please reach out to our Grievance Officer (contact below), and we’ll address it in accordance with Indian law.
Opting Out of Communications:
- Emails and SMS: You can unsubscribe from marketing emails at any time by clicking the “unsubscribe” link in the email. For SMS messages, you can reply “STOP” to opt out (if applicable). Note that you will still receive transactional messages necessary for Service (e.g., match notifications, account alerts).
- Push Notifications: With your consent, we may send push notifications or alerts to your mobile device. You can disable these by changing the notification settings on your device for our app.
- Profile Visibility: If at any time you wish to not be visible to other users (say you want to pause without deleting), check if we offer a “hide profile” or “pause” feature. Otherwise, you can simply delete your account and come back later if you choose.
We are committed to transparency and user control. If you have any questions about your privacy rights or how to exercise them, please contact us. We will not charge you for making a request (unless it’s excessive or unfounded, in which case we might charge a reasonable fee or refuse, per law). We will do our best to honor your requests in a timely manner and within any deadlines set by applicable laws (e.g., within 30-45 days). If we cannot fulfill your request, we will explain why (for example, if fulfilling it would infringe on another person’s rights or if we are legally prevented from doing so).
8. Cookies and Tracking Technologies
Our website and app use cookies and similar tracking technologies to improve user experience and analyze usage. This section explains how we use these tools:
What are Cookies? Cookies are small text files placed on your device (computer or mobile) when you visit a website. They allow the website to recognize your device and store information about your preferences or past actions. Other similar technologies include web beacons (clear GIFs), local storage (for apps), and SDKs for mobile apps that perform a similar function.
Types of Cookies We Use:
- Essential Cookies: These are necessary for the website to function. For example, they help authenticate users and prevent fraudulent use of user accounts. Without these cookies, some services cannot be provided. (If our site has a login, an essential cookie keeps you logged in during your session.)
- Preference Cookies: These remember your settings and choices to provide a more personalized experience (e.g., language preference, or if you log in from a certain region we might show matches accordingly).
- Analytics Cookies: We use these to collect information about how users use our website, such as which pages are visited and any errors encountered. This data helps us improve the platform. We might use Google Analytics or similar, which uses cookies to report on your interactions with our site. The information collected is aggregated and not used to identify individuals. Google Analytics may also set its own cookies; you can opt out by using a browser add-on if you wish.
- Advertising Cookies: Currently, we do not host third-party ads on our platform that would plant advertising cookies. If this changes, these cookies would be used to deliver relevant ads to you and measure their effectiveness, possibly based on your activity on our site and other sites. We will update this Policy and obtain necessary consents if we start using advertising cookies or SDKs.
- Mobile App SDKs: In our mobile application, instead of cookies, we might use SDKs and device identifiers. These function similarly – for example, an analytics SDK might collect usage events, or a push notification token might be stored to send notifications. We treat the data from these as we do cookie data.
Your Choices:
- Browser Controls: For web cookies, you can set your browser to refuse all or some cookies, or to alert you when cookies are being set. Each browser is different, so check the “help” menu of your browser to learn how to change your cookie preferences. Note that if you disable or refuse cookies, some parts of the website might become inaccessible or not function properly (for example, you might not stay logged in).
- Device Settings: For mobile apps, you can typically control tracking via your device settings (for example, you can reset or limit ad tracking via your phone’s privacy settings, which would limit what data can be collected by any advertising networks). Also, you can usually control push notifications and location sharing in your app permissions.
- Do Not Track: Some browsers offer a “Do Not Track” (DNT) feature. There is currently no uniform standard for DNT signals, so our website does not respond to them. We instead provide the cookie management options described here.
- Analytics Opt-Out: If we use Google Analytics on the web, Google provides an opt-out mechanism (a browser add-on) which you can use to prevent your data from being used by Google Analytics on websites.
- Consent Banners: Where required by law (such as in the EU or certain U.S. states), we will present a cookie consent banner when you first visit our site, giving you the option to accept or reject non-essential cookies. You can manage your preferences through that interface.
We strive to respect your privacy and provide you control over tracking. We do not use cookies to collect personally identifying information without consent. Cookies are mainly to ensure the site runs smoothly and to help us understand usage patterns to improve our service.
9. Children’s Privacy
Zoadi is not intended for children under the age of 18. We do not knowingly solicit or collect personal information from anyone under 18 years of age. If you are under 18, please do not use our Service or provide any information to us. Accounts are only to be created and used by adults seeking marriage partners (or by parents on behalf of their adult children with consent, as discussed earlier, but not for minors).
If we learn that we have inadvertently collected personal data from a child under 18, we will take prompt steps to delete such information from our records. For example, if a 16-year-old registers pretending to be 18, and we later discover the truth (through age verification or report), we will terminate the account and remove the data.
Parents or guardians: If you believe that a child under 18 may have provided us personal information, please contact us immediately. We will investigate and, if confirmed, delete the information. Note that in some jurisdictions, the age threshold for “child” may be higher (for instance, under 21). Our requirement is that all users be of legal adult age for entering into a marriage, which is typically 18 in most countries (with some variations).
We comply with applicable laws such as the U.S. Children’s Online Privacy Protection Act (COPPA) which prohibits collecting personal info from children under 13 without parental consent, but as stated, our Service is 18+ only, so COPPA normally does not apply. Similarly, any content inappropriate for minors (if any) is not allowed on the Service per our Terms.
10. Privacy Practices for Different Regions
We strive to comply with global data privacy laws. Here are some region-specific disclosures:
- United States: Zoadi complies with applicable U.S. federal and state privacy laws. If we become subject to any sector-specific law (for example, if we were to handle health records or credit data, which we do not in our regular course, we would comply with HIPAA or FCRA respectively). As a consumer app, our main considerations are state laws like California’s CPRA, which we discussed above. We also adhere to the principles of notice and consent to avoid “unfair or deceptive practices,” as enforced by the FTC. We will take reasonable measures to secure personal information to avoid enforcement actions for inadequate security.
- Canada: For Canadian users, Zoadi operates in accordance with PIPEDA and comparable provincial laws where applicable. We follow the 10 Fair Information Principles under PIPEDA, which include accountability, identifying purposes, consent, limiting collection, use, disclosure, and retention, accuracy, safeguards, openness, individual access, and challenging compliance. We have appointed a Privacy Officer (contact info below) responsible for our compliance. Personal information will not be used or disclosed for purposes other than those for which it was collected, except with consent or as required by law. We keep personal information only as long as necessary for those purposes. We protect personal information with appropriate security safeguards relative to the sensitivity of the information. You have the right to access your personal information and request corrections if needed. If you have a question or concern about our handling of your data, you may contact our Privacy Officer. If after contacting us your issue is not resolved, you have the right to bring it to the Office of the Privacy Commissioner of Canada.
- India: We comply with the applicable provisions of the Information Technology Act, 2000 and the related Privacy Rules (2011) regarding sensitive personal data. Under those rules, we have a published Privacy Policy (this document) and will not collect sensitive personal data (like passwords, financial info, health data, etc.) without your consent and knowledge of purpose. You have the right to withdraw consent and we provide a way to do so (deletion of data/account). We also will appoint a Grievance Officer as required, to address user grievances within the specified timeframe. The contact for our Grievance Officer is listed below. With the enactment of the Digital Personal Data Protection Act, 2023 (if in force), we will ensure compliance by: obtaining your free, specific, informed consent before processing personal data; processing only for purposes you consented to; providing you with itemized notice of categories of personal data being collected and the purpose; enabling you to exercise rights such as information about processing, correction and erasure, grievance redressal, and nomination of a successor for your data, as applicable. We shall also address personal data breach reporting to the Data Protection Board and affected principals as required by the new law.
- European Union/UK: While our initial user base is not EU-focused, if we do handle personal data of individuals in the EU or UK, we will comply with the General Data Protection Regulation (GDPR) and UK GDPR respectively. This includes having a lawful basis for all processing (our primary bases are consent and contract necessity, and sometimes legitimate interests for security, etc.), honoring rights like access, rectification, erasure, restriction, portability, and objection, and applying GDPR’s stringent security and cross-border transfer requirements. If our user base extends significantly into Europe, we may update this Policy with more specifics and provide an EU representative contact as needed by Article 27 GDPR. For now, EU users can still contact us with any requests and we will cater to them earnestly.
- Other Regions: As we expand, we will monitor and comply with new privacy laws (for example, new U.S. state laws, Brazil’s LGPD, etc.). This Policy will be updated to reflect material changes in compliance.
11. Updates to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. If we make material changes, we will provide notice in a manner reasonably designed to reach you – for example, by emailing the address associated with your account, or by prominently posting a notice in the app or on our website. The notice will state when the Privacy Policy will take effect and highlight the key changes. In some cases, if required by law, we may seek your explicit consent to significant changes (for instance, if we were to start collecting new types of sensitive data or using your data for a new purpose not previously disclosed, we would obtain consent as required).
We encourage you to periodically review this Privacy Policy for the latest information on our privacy practices. The “Last Updated” date at the top indicates when the latest changes were made. By continuing to use Zoadi after a revised Policy takes effect, you are deemed to have accepted the changes. If you do not agree to any updated terms, you should stop using the Services and delete your account before the changes take effect, or contact us to express your concerns (we may be able to accommodate certain requests on a case-by-case basis).
12. Contact Us
If you have any questions, concerns, or requests regarding this Terms of Service or Privacy Policy, you can contact us at:
- Email: admin@zoadi.com
- Mailing Address: Zoadi, LLC – 4667 231st PL SE Sammamish WA USA 98075
- Phone: +1 (919) 475 0312 (available during business hours for urgent privacy/security issues)
Privacy Officer (Canada): Chief Privacy Officer, reachable at the above contact details (admin@zoadi.com). This individual is responsible for overseeing our compliance with PIPEDA and other privacy regulations in Canada.
Grievance Officer (India): Grievance Officer for Zoadi as per Rule 5(9) of the IT Rules, 2011. Contact: admin@zoadi.com. The Grievance Officer is available to address any user grievances relating to personal data or other concerns. We will acknowledge queries within 24 hours and resolve them within the timeframe prescribed by law (currently one month under the IT Rules). With the introduction of the DPDPA, if you are not satisfied with the resolution of your complaint by our Grievance Officer, you may have the right to file a complaint with the Data Protection Board of India.
We are dedicated to protecting your information and rights. Please do not hesitate to reach out to us – whether it’s to exercise your rights, ask a question about something you didn’t understand here, or provide feedback about our privacy practices. Your trust is vital to us, and we will do our utmost to ensure your data is handled securely and lawfully, respecting your privacy at every step.
Thank you for reading our Terms of Service and Privacy Policy. We hope this transparency assures you that we take legal compliance and your privacy seriously. Using Zoadi signifies your agreement to these terms and policies, and we look forward to helping you find meaningful, lasting connections in a safe and respectful way.
Zoadi