This policy explains what Parda collects, why, who sees it, how long we keep it and what you can demand of us. It is written under India’s Digital Personal Data Protection Act, 2023.
The short version. We do not show your real name to anybody. We hold as little as we can get away with. Your photos are masked on our server and the clear file is never sent to a browser you have not given a key to. Deletion is real deletion. And a court order can still reach whatever we hold, which is the honest reason we hold so little — see Law Enforcement Requests.
1. Who is responsible
Parda is the Data Fiduciary for your personal data. Our Grievance Officer is named on the Grievance Redressal page and is the person to contact about anything in this policy.
2. What we collect
a. Account data
Email address, a password (stored only as a bcrypt hash, never in readable form), and a display name you choose. We do not ask for your real name for your profile.
b. Profile data
Age, gender, city and general locality, relationship status, what you are looking for, availability, interests and anything you write about yourself. You choose all of it and you can change or remove any of it.
c. Identity verification data
To list a profile you submit a government photo identity document (passport, driving licence, voter ID or PAN) and a live camera selfie. We do not use Aadhaar. A private platform cannot require it, following K.S. Puttaswamy v. Union of India (2018), which struck down Section 57 of the Aadhaar Act.
- The document image is encrypted with AES-GCM at rest and is never shown to another member.
- Only the last four characters of the number and a one-way hash are kept, so we can spot duplicates without storing the number.
- The document and selfie images are deleted after review — see retention below.
- Every admin who opens a document is logged, with who, when and why.
d. Photographs
For every photo you upload we generate a masked copy on our server. The image is reduced to 40 pixels wide, enlarged in interpolating steps and passed through twelve gaussian passes, so the detail that identifies a face is destroyed rather than hidden. The masked copy gets its own random filename. The clear file is never sent to a browser that has not been given a key by you. This matters: a blur applied with CSS can be removed by anybody who opens a developer console, and many platforms in this category do exactly that.
e. Messages
Message content, so conversations work. Phone numbers, email addresses and social handles are stripped out of message bodies automatically before delivery. Messages are not end-to-end encrypted — we can read them if a report or a lawful order requires it, and we would rather say so than imply otherwise.
f. Payment data
Handled by our payment gateway. We never see or store your card number. We keep the transaction reference, amount, date and status, because tax law requires it.
g. Technical data
IP address, device and browser type, and timestamps, for security, fraud prevention and abuse investigation. Kept for the minimum period in section 5.
h. Measurement
Only with your consent from the cookie banner. See the Cookie Policy.
3. Why we process it, and on what basis
| Purpose | Basis under the DPDP Act |
|---|---|
| Creating and running your account | Your consent, given at registration |
| Verifying age and identity | Your consent, and our legitimate need to keep minors off an adult platform |
| Showing your profile to other members | Your consent, withdrawable by hiding or deleting your profile |
| Safety, moderation and fraud prevention | Legitimate use, and our obligations as an intermediary |
| Payments and tax records | Legal obligation |
| Measurement and advertising | Your consent, withdrawable at any time |
4. Who sees what
- Other members see your display name, age, gender, city, general locality, relationship status, interests and your masked photos. They see your clear photos only if you have given them a private key. They never see your real name, your exact address, your email, your phone number or your identity document.
- Our team sees what is needed for the job at hand. Identity documents are visible only to the small verification team, and every view is logged.
- Our processors: a payment gateway, an email provider, and hosting. Each is bound by contract and receives only what it needs.
- Advertising platforms, only with your consent, and only as hashed values — never your messages, photographs or profile content.
- Nobody else. We do not sell personal data, we do not share it with data brokers, and we do not trade it.
5. How long we keep things
- Identity documents and selfies: deleted 30 days after a successful review; rejected or stale submissions after 180 days. Only the last four characters and the one-way hash remain.
- Messages: until you delete them, or until your account is deleted. Deletion is immediate and permanent.
- Profile and photos: until you delete them.
- Technical and security logs: 90 days.
- Payment records: 8 years, as required by Indian tax law, with your name removed where possible.
- Deleted accounts: purged within 30 days. See Account & Data Deletion.
6. Your rights under the DPDP Act
- Access — a summary of what we hold about you. Download it yourself from your account screen, instantly.
- Correction and completion — edit your profile, or write to the Grievance Officer.
- Erasure — delete your account and content. One click, no retention period, no waiting.
- Withdraw consent — as easily as you gave it. Withdrawing consent to processing means the account closes.
- Grievance redressal — the process on the grievance page, with statutory timelines.
- Nominate — appoint somebody to exercise your rights if you die or become incapacitated. Write to the Grievance Officer.
- Complain to the Board — you may escalate to the Data Protection Board of India if we do not resolve your grievance.
7. Security
- HTTPS everywhere; passwords hashed with bcrypt and never recoverable.
- Identity documents encrypted at rest with AES-GCM, served only through an audited, authenticated admin route.
- Masked photo copies generated server-side, with the clear original never sent to an unauthorised browser.
- Role-based admin access; every administrative action written to an audit log.
- Rate limiting and lockout on authentication.
No system is perfectly secure. The 2015 Ashley Madison breach is the reference case for this entire category, and the lesson we took from it is architectural rather than cosmetic: the only data that cannot leak is data we never collected. That is why your real name is not in our database.
If a breach occurs that is likely to affect you, we will notify you and the Data Protection Board of India as the DPDP Act requires.
8. Children
This service is for adults only. We do not knowingly process the data of anyone under 18, and every listing is age-checked against a government photo ID by a person. If you believe a minor has an account, report it immediately and we will act the same day.
9. Where your data is
Data is stored on servers located in India. Where a processor operates outside India, transfers are made only to jurisdictions permitted under the DPDP Act and under contractual safeguards.
10. Changes
Material changes to this policy are announced here and by email at least 7 days before they take effect.
Last updated: 25 September 2026.