Privacy Policy

DRAFT — this document has not been reviewed by a licensed Indian lawyer and must not be treated as final, legally binding policy until that review happens. It is a structurally complete starting point reflecting how Snehito's systems actually work today, written to be replaced or corrected by counsel before launch — not launch-ready legal copy.

This Privacy Policy explains what personal data Snehito collects through its website and apps, why, how it is used, who can see it, and the choices and rights you have. It applies to customers, the family members who manage a customer's account on their behalf, Snehito Companions, and Franchisees (referral partners).

1. Who we are

Snehito is a Kerala-based ageing-life platform operated in India, connecting older adults and their families abroad with verified Companions, health tracking tools, and related services. For the purposes of India's data protection law, Snehito acts as the "Data Fiduciary" for the personal data described in this policy, and you (or the older adult on whose behalf a family member registers) are the "Data Principal."

2. Information we collect

Account and identity information: full name, date of birth, gender, phone number (verified by OTP), email (optional), photo, address, and — where you choose to sign in with Google — the name, email, and profile photo Google shares with us.

Family/beneficiary information: where a family member registers on behalf of an older relative, we collect the relative's (beneficiary's) name, date of birth, address, and relationship to the registrant, along with emergency contact details for both.

Health information: anything you choose to add to the Health Passport — blood group, allergies, conditions, medication, doctors, preferred hospital, insurance details, and uploaded medical documents (prescriptions, lab reports, discharge summaries). This is entirely optional and is described in full in our separate Health Privacy Policy, which governs Health Passport data specifically alongside this policy.

Payment information: Snehito does not store your card, UPI, or bank details. Payments are processed by our payment gateway partner (Razorpay), and we retain only the resulting transaction records (amount, status, order/payment reference).

Location information: (a) the address you provide for a booking, geocoded to a map coordinate so a Companion can be matched and can navigate to you; (b) an optional one-time location pin you may choose to share at the moment you make a booking, if you are physically at the service address; and (c) while a booking is actively in progress, a Companion's live location may be shared with you for safety and coordination — this live-tracking session ends automatically when the booking ends. We do not track anyone's location outside of these specific, purpose-limited contexts.

Companion and Franchisee information: if you register as a Snehito Companion or Franchisee, we additionally collect the identity, address, background-verification, and (for Companions) service-area and availability information described during that registration flow.

Communications: messages sent through Snehito's in-app chat, support inquiries, and reviews you submit.

Technical information: device type, browser, IP address, and basic usage analytics (see "Cookies and analytics" below).

3. Why we process your information, and on what legal basis

We process personal data to: provide Companion bookings and matching; process payments and subscriptions; verify Companion and Franchisee identity; operate the Health Passport at your direction; provide customer support; send service-related notifications; and meet our legal and regulatory obligations (including tax, audit, and grievance-redressal record-keeping).

Where Indian law requires a specific legal basis for processing (including the Digital Personal Data Protection Act, 2023 once its consent and notice provisions come into force), we rely on your consent, or on processing that is necessary to perform the service you have asked for. We do not sell personal data to third parties, and we do not use health information for advertising.

4. Who can see your information

Access is role- and consent-gated, not open by default:

  • A Snehito Companion sees only the booking details and the specific Health Passport fields you have authorized, and only for the duration of an active booking with them — not your full profile or history.
  • Family members on a shared account see what your subscription tier and your explicit consent allow.
  • Franchisees (referral partners) never see your personal or health information — a Franchisee's dashboard shows only aggregate referral and commission figures, never an individual customer's data.
  • Snehito staff access is permission-gated by role and every access to sensitive records is logged in an audit trail.
  • We may disclose information where required by law, to enforce our Terms of Service, or to protect the safety of a user in an emergency.

Phone numbers are never shown to other members in any context. All member-to-member contact happens inside Snehito through in-app chat, voice, or video.

5. Data retention

We retain personal data for as long as your account is active, plus a further retention period for financial, tax, and audit records as required by applicable law. Live-location data from an active booking is discarded automatically once that booking's location session ends. If you delete your account, we will delete or anonymize your personal data within a reasonable period, except where we are legally required to retain it (for example, payment and tax records).

6. Your rights

Subject to applicable law, you have the right to: access the personal data we hold about you; request correction of inaccurate data; request erasure of your data (subject to our legal retention obligations); withdraw consent for optional processing (such as an optional Google Drive backup); and nominate another individual to exercise these rights on your behalf in the event of your death or incapacity, as contemplated under the Digital Personal Data Protection Act, 2023. To exercise any of these rights, contact us using the details in Section 11 below.

7. Cookies and analytics

We use essential cookies/local storage to keep you signed in and to remember your session. Where configured, we also use Google Analytics to understand aggregate usage of the site (pages visited, general traffic patterns) — this does not include your Health Passport contents or booking details, and you can decline analytics cookies where a consent banner is presented.

8. Security

We use encryption in transit (HTTPS) and access-controlled, permission-gated systems, with audit logging of access to sensitive records. Health documents and payment credentials are never stored in plain text. No system is perfectly secure, and we encourage you to use a strong, unique password-equivalent (your registered phone number's own security) and to report any suspected unauthorized access immediately.

9. Where accounts are managed by a family member

Many Snehito accounts are set up and managed by a family member on behalf of an older relative who receives the care. Where this is the case, the registering family member is responsible for having the appropriate authority and, where relevant, the consent of the person receiving care, to share their information with Snehito.

10. Applicable law

This policy is intended to reflect Snehito's obligations under India's Information Technology Act, 2000 (including the reasonable security practices required by Section 43A) and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, which specifically classify physical, physiological, and mental health information as "sensitive personal data or information." It is also intended to reflect the Digital Personal Data Protection Act, 2023 and its Rules, which are being phased in and will govern personal data processing more comprehensively as their provisions come into effect. Exactly how these frameworks apply to Snehito's specific data flows — and any additional steps needed for compliance — requires review by a licensed Indian lawyer, which has not yet happened; see the notice at the top of this page.

11. Grievance Officer and contact

For privacy questions, to exercise your rights under Section 6, or to raise a grievance about how your data has been handled, please use our Contact page. A named Grievance Officer, as contemplated under Indian IT Rules, will be designated and published here once this policy has been through legal review.

12. Changes to this policy

We will notify registered users of material changes to this Privacy Policy.

Privacy Policy | Snehito