We believe privacy is a right, not a feature. Here's exactly how we handle your data.
Last updated: June 15, 2026
🔒 The short version: We collect only what we need to make CafeConnects work. We never sell your data. Your location is never stored permanently. You can delete everything, anytime.
When you create an account, we collect: your name, email address, phone number, age, gender pronouns, bio, interests, and profile photo (only displayed after mutual poke). We also collect your ID verification data (processed by our third-party provider Onfido; we do not store raw document images).
We collect data about your interactions on the platform: pokes sent and received, match status, chat session metadata (not content of ephemeral chats), and any reports or blocks you submit.
We collect basic device identifiers, OS version, and app version for security and debugging purposes. We do not collect persistent advertising identifiers without explicit consent.
We use your data solely to:
We do not use your data for advertising targeting. We do not sell your data to third parties. We do not build behavioural profiles for marketing purposes.
📍 This is our most important privacy commitment: We never store your precise location permanently. Location data exists only in real-time cache (Redis) while your app is open, and is deleted automatically when you close it.
Here is the full lifecycle of your location data:
At the time of a match, we record only which café (by café ID, not precise coordinates) the match occurred at. This café-level record is stored to power repeat-visit analytics for café partners. It contains no precise location data.
We share your data only in the following circumstances:
We do not sell, rent, or trade personal data. Period.
Under applicable Indian data protection law (DPDP Act 2023) and GDPR principles, you have the right to:
To exercise any right, email privacy@cafeconnects.in. We respond within 30 days.
We implement industry-standard security measures: encryption in transit (HTTPS/TLS), encryption at rest for sensitive fields, access controls, and regular security audits. Contact info shared after the 3rd poke is encrypted with a user-specific key.
No system is perfectly secure. If you discover a vulnerability, please report it responsibly to security@cafeconnects.in.
Our website uses minimal cookies: session cookies for authentication, and anonymised analytics cookies (you can opt out). We do not use cross-site tracking or advertising cookies.
For privacy questions, requests, or concerns:
If you're not satisfied with our response, you may lodge a complaint with the relevant data protection authority.