Comprehensive Privacy & Legal Compliance
This privacy policy complies with Apple App Store and Google Play Store requirements, including the General Data Protection Regulation (GDPR), California Consumer Privacy Act (CCPA), Apple's App Tracking Transparency (ATT) framework, and Google Play's Data Safety guidelines.
Table of Contents
1. Information We Collect
Data you provide directly, automatically collected telemetry, and third-party data.
1.1 Information You Provide Directly
Account Information
- Full name, email address, password (encrypted)
- Date of birth, gender
- Authentication method (Email, Google, Apple Sign-In)
Profile Information
- Profile and selfie photos
- Height, weight, blood type, zodiac sign
- Location (division, district, GPS coordinates)
- Education, profession, job title, company, income category
- Family details (family type, family plan, profile created by)
- Religion and religious practices
- Lifestyle habits (drinking, smoking, workout, dietary preferences, sleeping habits, pets)
- Personality type, communication style, love language
- Relationship goals, pronouns, languages spoken
- Interests, music preferences, movie preferences, book preferences, travel preferences
- Bio and "about me" text
- Profile blur preference settings
Identity Verification
- Front and back images of National ID card (NID)
- Verification status (Pending, Approved, Rejected)
Communication
- Chat messages and file attachments sent through the App
- Reports and feedback submitted to us
1.2 Information Collected Automatically
Device Information
- Device type, operating system
- Unique device identifiers
- Mobile network information
- Browser type & version (web views)
Usage Data
- App features & interactions
- Swipe history (likes, dislikes)
- Profile views & match activity
- Session duration & frequency
- Error logs & crash reports
Location Data
- Approximate IP location
- Precise GPS location (when granted)
- Distance match calculations
1.3 Information from Third Parties
Social Login Providers:
- Google: Name, email address, profile picture (when you sign in with Google).
- Apple: Name, email address (when you sign in with Apple; Apple may relay a private relay email).
2. How We Use Your Information
Purposes of processing and corresponding GDPR legal bases.
We use the information we collect for the following purposes:
| Purpose | Legal Basis (GDPR) |
|---|---|
| Create and manage your account | Contract performance |
| Provide match suggestions based on your preferences | Contract performance / Legitimate interest |
| Enable real-time chat between matched users | Contract performance |
| Verify your identity via NID | Legitimate interest (safety & trust) |
| Send match notifications and interest alerts | Contract performance / Legitimate interest |
| Improve and optimize the App | Legitimate interest |
| Detect and prevent fraud, abuse, and security issues | Legitimate interest |
| Comply with legal obligations | Legal obligation |
| Send transactional emails (OTP, password reset) | Contract performance |
| Personalize your experience and content | Legitimate interest |
3. How We Share Your Information
We do not sell your personal information. How data is shared with users, providers, and legal entities.
3.1 With Other Users
- Your public profile (name, photos, bio, and profile details you choose to share) is visible to other users based on your visibility and privacy settings.
- Your exact location is never shared with other users. Only approximate distance is shown.
- Chat messages are visible only to you and the matched user.
3.2 With Service Providers
We share data with the following third-party service providers who assist in operating the App:
| Service Provider | Purpose | Data Shared | Privacy Policy |
|---|---|---|---|
| Cloudinary | Image hosting and storage | Profile photos, selfie photos, NID images, chat attachments | cloudinary.com/privacy |
| Google OAuth | Social authentication | Authentication tokens | policies.google.com/privacy |
| Apple Sign-In | Social authentication | Authentication tokens | apple.com/privacy |
| Nodemailer/SMTP | Transactional emails | Email address, OTP codes | Depends on your SMTP provider |
| PostgreSQL (hosted) | Database storage | All account and profile data | Depends on hosting provider |
3.3 For Legal Compliance
We may disclose your information if required by law, regulation, legal process, or governmental request.
3.4 Business Transfers
In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction with notice.
3.5 With Your Consent
We may share your information for purposes not described in this policy with your explicit consent.
4. Third-Party Services
Analytics, advertising practices, and user tracking disclosures.
4.1 Analytics and Crash Reporting
We may use device-level analytics to understand App performance and crash logs. This data is anonymized and does not contain personal identifiable information.
4.2 Advertising
Patro Patri does not display third-party advertisements. We do not use advertising SDKs or share data with advertising networks.
4.3 Tracking
We do not track users across apps or websites for advertising purposes. We do not use the Facebook SDK, Google AdMob, or similar tracking technologies. If this changes in the future, we will update this policy and request appropriate consent as required by Apple's App Tracking Transparency framework.
5. Data Retention
How long we retain various data categories before secure deletion.
| Data Type | Retention Period |
|---|---|
| Account data (name, email, profile) | Retained while your account is active; deleted within 30 days of account deletion |
| Profile photos | Retained while your account is active; deleted from Cloudinary within 30 days of account deletion |
| NID verification images | Retained for 90 days after verification decision, then permanently deleted |
| Chat messages | Retained for 12 months after the last message in a conversation |
| Swipe and usage data | Retained for 24 months, then anonymized |
| Crash logs | Retained for 12 months |
| Email OTP codes | Deleted after 10 minutes |
When data is no longer needed, it is securely deleted or anonymized so that it can no longer be associated with you.
6. Data Security
Technical and organizational security safeguards implemented.
We implement appropriate technical and organizational security measures to protect your personal information, including:
7. Your Rights and Choices
Account management, GDPR user rights, CCPA rights, and privacy settings.
7.1 Account Management
Access and Update: You can access and update your profile information at any time through the App settings.
Delete Account:
You can request account deletion through the App settings or by contacting us. Upon deletion:
- Your account will be deactivated immediately
- Your data will be permanently deleted within 30 days
- Your profile will no longer be visible to other users
- Matched conversations may be retained in anonymized form for the other user
7.2 Data Rights (GDPR - EU/EEA Users)
If you are located in the European Union or European Economic Area, you have the following rights:
| Right | Description |
|---|---|
| Access | Request a copy of the personal data we hold about you |
| Rectification | Request correction of inaccurate personal data |
| Erasure | Request deletion of your personal data ("right to be forgotten") |
| Restriction | Request restriction of processing of your personal data |
| Portability | Request transfer of your personal data to another controller |
| Objection | Object to processing of your personal data based on legitimate interests |
| Withdraw Consent | Withdraw consent at any time where processing is based on consent |
To exercise any of these rights, please contact us at mrfahim31@gmail.com. We will respond to your request within 30 days.
7.3 California Privacy Rights (CCPA - US Users)
If you are a California resident, you have the right to:
- Know what personal information we collect, use, disclose, and sell
- Delete your personal information
- Opt-out of the sale of your personal information (we do not sell personal information)
- Non-discrimination for exercising your privacy rights
To exercise these rights, contact us at mrfahim31@gmail.com or call +44 7404 671042.
7.4 Location Data
- Enable/disable location in device settings
- Revoke location permission anytime in App settings
- Disabling location may limit distance match features
7.5 Notifications
- Manage push notifications in device settings
- Opt out of non-transactional email updates
7.6 Data Portability
Request a copy of your data in a machine-readable JSON format by emailing mrfahim31@gmail.com.
8. Children's Privacy
Strict 18+ age restriction policy.
Patro Patri is not intended for users under the age of 18. We do not knowingly collect personal information from children under 18. If we become aware that we have collected personal information from a child under 18, we will take steps to delete such information promptly.
If you are a parent or guardian and believe your child has provided us with personal information, please contact us at mrfahim31@gmail.com.
9. International Data Transfers
Cross-border processing and global protection safeguards.
Your information may be transferred to and processed in countries other than your country of residence. These countries may have data protection laws that differ from the laws of your country.
We ensure that appropriate safeguards are in place for international transfers, including:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Adequacy decisions where applicable
- Data processing agreements with our service providers
10. Changes to This Privacy Policy
Updates and notification procedures for policy revisions.
We may update this Privacy Policy from time to time. We will notify you of any material changes by:
- Posting the new Privacy Policy on this page
- Updating the "Last Updated" date at the top of this page
- Sending an in-app notification for significant changes
We encourage you to review this Privacy Policy periodically for any changes. Your continued use of the App after any modifications constitutes your acceptance of the updated Privacy Policy.
11. Contact Us
Official contact details for privacy inquiries.
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Patro Patri
Patropatri and Equity Ally Technologies Limited
12. Apple App Store Compliance
Specific disclosures required by Apple Store guidelines & ATT framework.
This section addresses specific requirements mandated by Apple's App Store Review Guidelines and privacy policies.
12.1 App Tracking Transparency (ATT)
- We do not track users across apps and websites owned by other companies.
- We do not use the IDFA (Identifier for Advertisers) or any other device-level tracking identifiers for advertising purposes.
- No ATT prompt is required at this time because we do not perform tracking as defined by Apple.
- If we introduce tracking features in the future, we will implement the ATT framework and request user consent before tracking.
12.2 Privacy Nutrition Labels
Our App Store privacy nutrition labels accurately reflect the data practices described in this policy. We disclose:
- Data Used to Track You: None
- Data Linked to You: Contact Info, Identifiers, Usage Data, Diagnostics
- Data Collected for Account Creation: Contact Info, Health & Fitness (blood type), Financial Info (income category), Location, Sensitive Info (NID for verification), User Content, Usage Data, Diagnostics
12.3 Data Deletion
Users can delete their account and associated data through:
- In-app settings → Account → Delete Account
- Email request to mrfahim31@gmail.com
Account deletion removes personal identifiers within 30 days. We provide confirmation of deletion upon request.
12.4 Sign in with Apple
- We offer Sign in with Apple as a login option alongside Email and Google Sign-In.
- Users may choose to share their email or use Apple's Private Relay email.
- We respect Apple's requirement that Sign in with Apple must be offered if any third-party social login is available.
12.5 Purpose Strings
All permission requests in the App include clear purpose strings explaining why each permission is needed:
| Permission | Purpose String |
|---|---|
| Camera | "Patro Patri needs camera access to take profile photos and selfies for identity verification." |
| Photo Library | "Patro Patri needs photo library access to select profile photos from your device." |
| Location | "Patro Patri needs your location to show nearby matches and calculate distance." |
| Notifications | "Patro Patri needs notification permission to alert you about new matches and messages." |
12.6 Required Reason APIs
We only access APIs that fall within Apple's approved use cases. We do not access:
- User's contacts
- Health data beyond blood type (user-provided)
- Financial data beyond income category (user-provided)
13. Google Play Store Compliance
Data Safety Section, Developer Policy & Android Permission declarations.
This section addresses specific requirements mandated by Google Play Store policies and the Data Safety section.
13.1 Data Safety Declaration
Our Google Play Data Safety section accurately declares:
- Personal info (name, email, date of birth, gender)
- Photos and videos (profile photos, selfies, NID images)
- Messages (chat messages between matched users)
- Location (precise GPS, approximate location)
- Device and other IDs (device identifiers for security)
Data shared: None (we do not share data with third parties for their own purposes)
Data is encrypted in transit: Yes
Data can be deleted: Yes, users can request deletion
13.2 Google Play Developer Policy Compliance
- Family Policy: We do not target children under 13. Our age gate requires users to be 18+.
- Sensitive Data: We obtain explicit consent before collecting sensitive data (location, NID images).
- Data Security: We use industry-standard encryption and security practices.
- Deletion: Users can delete their account and data at any time.
13.3 Permissions
We request only the minimum permissions necessary for App functionality:
| Permission | Justification |
|---|---|
| ACCESS_FINE_LOCATION | To calculate distance for nearby match suggestions |
| ACCESS_COARSE_LOCATION | Fallback for approximate location when fine location is unavailable |
| CAMERA | To take profile photos and selfie for verification |
| READ_EXTERNAL_STORAGE / READ_MEDIA_IMAGES | To select photos from device for profile |
| WRITE_EXTERNAL_STORAGE | To save downloaded images (Android < 13) |
| INTERNET | Required for all network communication |
| ACCESS_NETWORK_STATE | To check connectivity status |
| RECEIVE_BOOT_COMPLETED | To restore notifications after device restart |
| VIBRATE | For notification vibration |
13.4 Google Play Data Deletion
In compliance with Google Play's data deletion requirements:
- Users can delete their account via Settings → Account → Delete Account in the App.
- Upon account deletion:
- All personal data is permanently deleted within 30 days
- Profile is immediately deactivated and hidden from other users
- Chat history may be retained in anonymized form for the other matched user
- Users can also request data deletion by emailing mrfahim31@gmail.com with the subject line "Data Deletion Request" and including their registered email address.
- We will confirm deletion within 7 business days.
13.5 Prominent Disclosure
- During onboarding, users are informed of all data types collected
- Permission requests include clear explanations
- Full Privacy Policy accessible from settings and during registration
13.6 Consent
- Explicit consent for location, camera, and photo library access
- Opt-in consent for NID verification images
- Users can withdraw consent at any time via settings