Legal

Privacy Policy

Last updated: 29 April 2026 · DPDP Act, 2023 compliant

1. In short

Plain English: We collect what's needed to match your listings to buyers — name, email, phone, city, role, and the listings/requirements you post. We never sell your data, never run third-party ad tracking, and your phone is hidden by default. You can export or delete your data anytime.

2. Data we collect

You give us directly

Collected automatically

3. Why we collect it

PurposeLawful basis (DPDP)
Run the matching engine and show you relevant listings/requirementsConsent & legitimate use
Verify your identity and RERA status to maintain trustLegitimate use
Send transactional emails (signup confirmation, password reset, match alerts)Performance of contract
Detect fraud, abuse, and policy violationsLegitimate use
Comply with legal obligations (IT Rules, RERA, tax law)Legal compliance
Send product updates and marketing emailsConsent (opt-out anytime)

4. How we share data

We do not sell your personal data. Limited sharing happens only as below:

5. Storage & security

Personal data is stored on Supabase Postgres (project region: ap-south-1, Mumbai) with row-level security ensuring you can only edit your own records. Passwords are hashed using bcrypt; sessions use signed JWTs with rotation. Data in transit is protected with TLS 1.2+.

Despite reasonable safeguards, no system is fully impenetrable. If we detect a personal-data breach affecting you, we will notify you and the Data Protection Board within the timelines required by the DPDP Act.

6. Cookies & analytics

We use a small number of first-party cookies and localStorage entries strictly for:

We do not run Google Analytics, Meta Pixel, or any third-party advertising/retargeting trackers. We may add privacy-respecting product analytics (PostHog or self-hosted) in future and will update this Policy if so.

7. Your rights under the DPDP Act, 2023

As a Data Principal, you have the right to:

We respond to verified requests within 30 days.

8. Data retention

We retain personal data for as long as your account is active, plus the periods below:

9. Children

Matchnclose is not directed at users under 18 years of age. If we discover that we have collected data from a minor without verifiable parental consent, we will delete it promptly.

10. Changes to this Policy

Material changes will be communicated by email or in-app notice at least 14 days before they take effect. The "Last updated" date at the top of this page reflects the most recent revision.

11. Contact us