This policy explains what Rangmel collects, why, who sees it and what you can do about it. It is written to India's Digital Personal Data Protection Act, 2023.
The short version. Your gender identity, pronouns and orientation are the most sensitive things you give us, and we treat them that way: they are shown only to the people you chose to be shown to, they are never sent to advertising networks in any form, and you can hide or delete them at any time without losing your account.
1. What we collect
What you give us
- Account: email address, mobile number, password (stored only as a one-way hash).
- Profile: the name you chose, date of birth, gender identity, pronouns, orientation, relationship intentions, city, optional area, photographs, bio, prompt answers, interests, height.
- Preferences: who you want to meet, age range, and your privacy settings.
- Optional, and only if you ask for a badge: a government photo ID (passport, driving licence, voter ID or PAN) and a live selfie.
- Content: messages, reports you file, and support conversations.
What we record as you use it
- Swipes, matches, blocks, profile views and last-active time.
- IP address, device and browser information, and approximate city.
- Payment records: amount, date, plan, and the payment gateway's reference. We never see or store your card number.
2. Special category data, and the promise attached to it
Under the DPDP Act and comparable laws elsewhere, your gender identity, gender history and sexual orientation are sensitive personal data. We collect them because the app cannot function without them — a dating app that does not know who you are or who you want to meet is not a dating app — and we collect them only with your explicit, itemised consent, recorded with the exact wording you agreed to, the timestamp and the IP address.
Specifically, we commit that:
- These fields are never shared with advertising or analytics networks — not in plain text, not hashed, not bucketed, not inferred through a proxy field. Hashing is exactly how ad networks match identities, so a hashed gender marker is not anonymisation.
- They are never sold, and never shared with data brokers.
- They are visible only to signed-in members you have chosen to be visible to, according to your own privacy setting.
- You can hide your orientation from your profile, or change any of these fields, at any time, from Privacy settings.
3. Photographs
You choose who sees your photographs: everyone signed in, only people you match with, or one person at a time. When they are hidden, we do not merely blur them in the browser. We generate a separate, permanently blurred file under its own random filename, and that is the only file a viewer who is not entitled to the original ever receives. The original is never sent to their device, so it cannot be recovered from the network tab or by guessing a URL.
No membership tier can see past another member's photo privacy setting.
4. Identity documents
Verification is optional. If you submit a document:
- The number is not stored. We keep only the last four characters and a one-way keyed hash, used to stop the same document being used on two accounts.
- The document image is encrypted at rest (AES-GCM) and is streamed only to a reviewer, through an audited route. It is never shown on your profile and never visible to another member.
- Verified documents are deleted after the retention period set in Admin (30 days by default). Documents from rejected or abandoned checks are deleted after 180 days.
- We do not accept Aadhaar, and the form refuses it. A private company has no lawful basis to collect it here, and the risk to you if it leaked is not worth the convenience.
5. Who sees what
- Other members: what your privacy settings allow, and nothing else. Your email address, phone number, date of birth, exact location and identity documents are never shown to another member.
- Our team: a small number of trained staff, for moderation, verification and support. Every access to a document is written to an audit log.
- The open web: nothing, unless you explicitly chose "anyone, including the open web" as your visibility. That setting is off by default.
- Processors: our hosting provider, our payment gateway (Razorpay), and our email provider. They act on our instructions and cannot use your data for their own purposes.
6. Advertising and analytics
We measure how people find the app, using Meta's Conversions API and Google Analytics. What we send is limited to an email address, a phone number, an account identifier and a city, all hashed where the platform supports it, plus the name of the action taken (for example "signed up").
What is never sent: your gender identity, your pronouns, your orientation, your date of birth, your photographs, your messages, who you matched with, or anything derived from them. Event names are generic on purpose: an advertising network is told that an account was created, never what kind of person created it.
You can opt out of analytics in your browser, and blocking them does not restrict any part of the app.
7. How long we keep things
- Profile and messages: while your account is open.
- Identity documents: as set out in section 4.
- Payment records: eight years, as required by Indian tax law. These records contain no identity fields.
- After deletion: photographs and documents are removed from disk immediately; identifying profile fields are erased; the account row is anonymised and retained only so that blocks and payment records remain valid. Leftover rows are swept 90 days later.
8. Your rights
- Access: download everything we hold about you as JSON from your account.
- Correction: edit any profile field yourself, at any time.
- Erasure: delete your account from your settings. If you want a break rather than an ending, pause instead — it hides you from every deck and deletes nothing.
- Withdraw consent: hide or clear any identity field without losing your account.
- Grievance: our officer is named on the Grievance Redressal page and replies within the statutory period.
9. Security
Traffic is encrypted in transit. Documents are encrypted at rest. Passwords are hashed, never stored or recoverable. Sessions are regenerated on sign-in and on password change. Admin access is role-restricted and every administrative action is logged with the actor, the entity and the time.
We cannot promise a breach will never happen. If one does and it affects you, we will tell you and the Data Protection Board, as the DPDP Act requires.
10. Requests from the authorities
How we handle law enforcement requests, and what we will not do, is set out separately on the Law Enforcement & Transparency page.
11. Changes
If we change how we use your data, we ask for your consent again rather than assuming it. Material changes are shown in the app before they take effect.