Privacy Policy & Data Protection Charter

VibeNMeet Mobile Application

Ref: VNM-LEGAL-DP-2026-V1.1.2 Effective Date: October 8, 2026 Last Revised: October 8, 2026

PREAMBLE & STATUTORY BASIS

This Privacy Policy and Data Protection Charter (hereinafter referred to as the "Privacy Policy" or "Charter") constitutes a formal, legally binding instrument executed between You (hereinafter referred to as the "Data Principal", "User", or "Subscriber") and VibeNMeet (along with its parent operating entity The Unemployee, collectively referred to as the "Company", "Data Fiduciary", "We", "Us", or "Our").

This Charter is published and enforced in strict compliance with the statutory framework of the Republic of India, specifically:

  1. The Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023) [hereinafter "DPDPA 2023"];
  2. Section 43A, Section 69, Section 72A, and Section 79 of the Information Technology Act, 2000 (Act No. 21 of 2000) [hereinafter "IT Act"];
  3. The Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 [hereinafter "SPDI Rules"];
  4. Rule 3 and Rule 4 of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 [hereinafter "IT Intermediary Rules 2021"];
  5. The Consumer Protection (E-Commerce) Rules, 2020 framed under the Consumer Protection Act, 2019; and
  6. The Indian Contract Act, 1872 (Act No. 9 of 1872).
BY ACCESSING, DOWNLOADING, INSTALLING, REGISTERING WITH, OR UTILIZING THE VIBENMEET APPLICATION (THE "APPLICATION"), THE DATA PRINCIPAL HEREBY CONFIRMS HAVING READ, UNDERSTOOD, AND UNEQUIVOCALLY ACCEDED TO THE TERMS EMBODIED HEREIN. IN THE EVENT THE DATA PRINCIPAL DOES NOT ACCEDE TO THIS CHARTER, ACCESS TO THE APPLICATION MUST BE IMMEDIATELY TERMINATED.

CLAUSE 1: DEFINITIONS & INTERPRETATION

1.1. Definitions: In this Charter, unless the context otherwise requires:

  • "Account" means the unique digital credential, access profile, and cryptographic identifier assigned to the Data Principal within the Application.
  • "Applicable Law" means any Indian statute, law, regulation, ordinance, rule, judgment, order, decree, clearance, directive, or notification enacted or issued by any court, tribunal, regulatory authority, or the Data Protection Board of India.
  • "Biometric Information" means facial geometry, landmarks, and liveness signals collected solely for anti-catfishing and identity verification under Rule 2(1)(b) of the SPDI Rules.
  • "Consent" means any freely given, specific, informed, unconditional, and unambiguous indication of the Data Principal's intent pursuant to Section 6 of the DPDPA 2023.
  • "Data Fiduciary" has the meaning ascribed to it under Section 2(i) of the DPDPA 2023, referring specifically to the Company.
  • "Data Principal" has the meaning ascribed to it under Section 2(j) of the DPDPA 2023, referring to the natural person to whom the personal data relates.
  • "Digital Billing Systems" means the native, sandboxed payment processing frameworks provided exclusively by Apple Inc. (Apple App Store / StoreKit 2) and Google LLC (Google Play Store / Google Play Billing).
  • "New Happenings" means the localized, verified event, cultural gathering, workshop, and business announcement publication directory operated within the Application.
  • "Personal Data" means any data about an individual who is identifiable by or in relation to such data pursuant to Section 2(t) of the DPDPA 2023.
  • "Women Circle" means the gender-gated social connection and discovery environment engineered pursuant to reasonable classification principles under Indian constitutional jurisprudence, where posting and interactive rights are reserved to female and non-binary individuals.

1.2. Interpretation: Headings are for convenience only and do not govern interpretation. The singular includes the plural and vice versa.

CLAUSE 2: CATEGORIES OF PERSONAL DATA PROCESSED

2.1. Data Voluntarily Submitted by the Data Principal:

  • Identity Attributes: Legal first name, self-declared gender, age, profession or occupation, biographical narrative, state and municipal locality (selected via cascading selector covering all 28 Indian States and 8 Union Territories), and primary profile portrait.
  • Authentication Identifiers: Primary mobile number, verified electronic mail address (received via OAuth integrations), Google Account ID, Apple ID identifier, and cryptographic raw SHA-256 authorization nonces.
  • Biometric Identity Data (KYC): Voluntary facial portrait captures and liveness verification metrics processed through FaceVerificationService to prevent fraudulent impersonation and award the verified Trust Score credential.
  • User-Generated Submissions: Real-time text communications, push-to-talk audio voice recordings, shared chat photographs, Local Vibe notices, New Happening submissions, Women Circle posts and threaded comments, Daily Spark responses, message requests, and incident report narratives.

2.2. Data Collected Automatically via System Telemetry:

  • Foreground Geographic Coordinates: High-precision latitude, longitude, reverse-geocoded locality, and spatial geohash indices (geoPrefix3, geoPrefix4, geoPrefix5) accessed strictly while the Application executes in the foreground. Background location tracking is strictly disabled.
  • Hardware & System Attributes: Manufacturer, brand, commercial model identifier, CPU architecture, screen resolution, operating system version, and system build number.
  • Persistent Security Identifiers: Apple Identifier for Vendors (IDFV), Android Hardware ID, Firebase Cloud Messaging (FCM) registration tokens, and cryptographic hardware attestation tokens generated via Firebase App Check (Google Play Integrity API and Apple DeviceCheck / App Attest).
  • Network Telemetry: Client Internet Protocol (IP) address, mobile network operator, connection type (Wi-Fi, 4G, 5G), and network routing timestamps.

2.3. Direct Messaging Security Architecture & Non-E2EE Disclosure:

Encryption in Transit & at Rest: All direct chat communications, text messages, media URLs, and push-to-talk audio voice snippets are encrypted in transit across public networks utilizing Transport Layer Security (TLS 1.3 / HTTPS) and encrypted at rest on cloud database infrastructure utilizing AES-256 block-level encryption.

Access-Controlled Database Model: Direct communications are stored in access-controlled cloud database records restricted strictly to authenticated conversation participants (participants: [uidA, uidB]) via server-enforced security rules.

Non-E2EE Processing Principle: Direct communications on VibeNMeet do NOT utilize End-to-End Encryption (E2EE) with zero-knowledge asymmetric keys. Communications are processed on secure cloud infrastructure to enable:

  1. Automated Content Moderation: Real-time prevention of spam, illicit solicitation, hate speech, and safety violations via the ContentSafetyValidator;
  2. Abuse & Harassment Incident Adjudication: Granular review of reported message bubbles, quoted evidence snippets, and message request interactions when a Data Principal files a user safety report (reports / admin_reports);
  3. Evidentiary Export: Generation of verifiable chat transcripts when a Data Principal exercises their statutory Right to Access or requires documentation for legal proceedings; and
  4. Statutory Law Enforcement Compliance: Mandatory assistance to authorized government investigative agencies pursuant to Section 69 of the IT Act and Rule 3(1)(h) of the IT Intermediary Rules 2021.

CLAUSE 3: FINANCIAL EXCLUSIONS & IN-APP PURCHASES GOVERNANCE

3.1. Zero Financial Data Storage Principle: The Company enforces an absolute non-storage principle concerning banking credentials. The Data Fiduciary does not collect, process, handle, view, or store: Credit card or debit card PAN, CVV, expiry dates, net banking credentials, or UPI PINs.

3.2. Digital Billing Transactions: All monetary consideration paid for digital goods, memberships, passes, top-up packs, and event listing fees is processed exclusively through Apple StoreKit 2 and Google Play Billing.

3.3. Transaction Ledger: To satisfy statutory auditing requirements under Rule 5 of the Consumer Protection (E-Commerce) Rules, 2020, and ensure idempotent entitlement delivery, non-sensitive purchase metadata is recorded in an immutable collection (purchase_ledger).

3.4. Non-Refundable Covenant (Indian Contract Act, 1872): ALL MONETARY DISBURSEMENTS, IN-APP PURCHASES, CONSUMABLE TOP-UPS, LISTING CHARGES, AND SUBSCRIPTION FEES CONSTITUTE CONSIDERATION FOR IMMEDIATELY PROVISIONED DIGITAL SERVICES AND ARE STRICTLY FINAL AND NON-REFUNDABLE UPON PAYMENT COMPLETION. NO CLAIMS FOR PRO-RATA REIMBURSEMENT, PARTIAL REFUND, OR CASH RESTITUTION SHALL BE ENTERTAINED BY THE COMPANY. DISPUTES GOVERNING STORE-LEVEL BILLING ERRORS REMAIN SUBJECT EXCLUSIVELY TO THE JURISDICTION AND REFUND POLICIES OF APPLE INC. OR GOOGLE LLC.

3.5. Subscription Lifecycle & Cancellation: Auto-renewable subscriptions renew automatically at monthly intervals unless canceled by the Data Principal at least 24 hours prior to the conclusion of the active billing cycle via Apple App Store or Google Play Store account settings.

3.6. Meetup & Footfall Verification Ledger (meetup_ledger): To ensure accurate footfall accounting for listed commercial venues, prevent duplicate interaction claims, and compile anonymous platform-level geographic demand statistics, confirmed meetups are recorded in a read-restricted administrative collection. Star ratings submitted following an offline meetup evaluate exclusively the listed commercial venue (comfort, ambience, service). The Data Fiduciary strictly does NOT rate, score, evaluate, or profile individual human users.

3.7. Non-Applicability to Social Credit Scoring: The Data Fiduciary does not deploy any social credit scoring, behavioral classification, or personality grading systems. The verified connection counter and "Trust Score" reflect solely an objective, voluntary numerical count of mutual in-person meetups and biometric selfie liveness verifications designed exclusively to prevent synthetic bots and catfishing.

CLAUSE 4: NEW HAPPENINGS: EDITORIAL GOVERNANCE & 72-HOUR STATUTORY COVENANT

4.1. Pre-Publication Administrative Moderation: Every New Happening submission enters a mandatory administrative review queue (status: 'submitted'). The Company exercises strict editorial discretion to verify public safety, truthfulness, and community guideline compliance.

4.2. Covenant of Live Visibility: The Data Fiduciary covenants and guarantees the following operational standards:

  • Trigger Precondition: Published strictly upon formal administrative approval (status: 'approved_pending_payment') AND payment of the ₹199 listing fee (com.vibenmeet.app.happening.publish_fee) or valid Free Launch Post quota redemption.
  • Strict 72-Hour Live Window: Guaranteed to remain active, searchable, and discoverable in the public local directory for EXACTLY SEVENTY-TWO (72) CONSECUTIVE HOURS (3 CALENDAR DAYS) from publication.
  • Automated Expiration: Upon lapse of 72 hours (expiresAt = publishedAt + 72 hours), an automated backend sweep transitions the post to expired status (status: 'expired'), permanently removing it from the public feed.

4.3. Free Launch Quota: Each registered event organizer account is allocated an initial quota of two (2) approved New Happening publications free of charge.

4.4. Editorial Reservation of Pinned Placement: Pinned placement is an exclusive editorial instrument exercised solely by platform administrators. Organizers and commercial entities cannot purchase or bid for pinned placement.

CLAUSE 5: WOMEN CIRCLE: REASONABLE CLASSIFICATION & ACCESS GATING

5.1. Constitutional Classification: Engineered pursuant to Article 15(3) of the Constitution of India as a protected digital sanctuary:

  • Self-Declared Gender Immutability: Gender is declared during initial onboarding and is rendered strictly immutable. Client-side modifications are blocked by server-side rules.
  • Differential Rights: Write access (creating posts, posting comments, sending Hearts, liking comments, initiating author message requests, and reporting) is reserved exclusively to users whose self-declared gender is "Female" or Non-binary ("Other"). Users whose self-declared gender is "Male" possess strictly read-only discovery privileges.

5.2. Threading & Moderation: Nested comments capture parent author attribution (replyToOwnerName). Post authors maintain the unilateral prerogative to remove third-party comments from their posts (deletedByPostAuthor).

5.3. Familiar Faces Signal: Bidirectional in-app soft indicators surface between pairs who cross 3 mutual platform interactions. The signal is strictly in-app and is never transmitted via push notifications.

CLAUSE 6: HARDWARE SENSORS & SYSTEM PERMISSIONS (APPLE GUIDELINE 5.1.1 COMPLIANCE)

6.1. Camera Permission (CAMERA / NSCameraUsageDescription): Invoked exclusively for capturing user profile avatars, sending photos and visual media in direct chats, capturing Happening promotional flyers, conducting facial liveness KYC verification (FaceVerificationService), and optical scanning of VibePass QR codes for mutual in-person verification. Video feeds during QR scanning execute in volatile RAM on-device and are never recorded, photographed, stored, or transmitted to any server.

6.2. Photo Library Permission (READ_MEDIA_IMAGES / NSPhotoLibraryUsageDescription & NSPhotoLibraryAddUsageDescription): Invoked exclusively for selecting and uploading profile portraits from the device gallery, selecting and sharing images in direct chats, uploading promotional flyers for New Happenings, and saving shared media files upon explicit user request.

6.3. Microphone Permission (RECORD_AUDIO / NSMicrophoneUsageDescription): Invoked strictly while the Data Principal holds the push-to-talk recording trigger in direct chats to record audio voice notes. Background microphone listening is strictly barred.

6.4. Location Permission (Foreground Only / NSLocationWhenInUseUsageDescription): High-accuracy location access is requested solely while the Application is actively displayed to discover nearby local vibes, cafes, and happening venues. Background location tracking is neither implemented nor requested.

6.5. Clipboard Access: Invoked strictly when the user initiates manual copy actions (e.g. copying support emails, event hyperlinks, or payment identifiers).

CLAUSE 7: ENFORCEMENT, SUSPENSIONS, BANS & ANTI-CIRCUMVENTION

7.1. Account Sanctions (accountFlags): Upon identification of statutory violations or harassment, the Data Fiduciary may impose isBanned (permanent platform termination), isSuspended (temporary suspension until suspendedUntil), or womenCircleBanned (revocation of write privileges).

7.2. Due Process & Ban Appeals: Sanctioned users are restricted to the BanScreen with an administrative appeal channel (appealReason) adjudicated under principles of natural justice.

7.3. Anti-Circumvention Ledger: To prevent recidivism by banned bad actors, an irreversible cryptographic hash of the offender's unique hardware identifier, phone number, and IP block is maintained in an internal banned_identifiers ledger. Subsequent account creation attempts utilizing identical credentials are automatically rejected.

CLAUSE 8: DATA RETENTION, ARCHIVAL, DEACTIVATION & ERASURE (APPLE GUIDELINE 5.1.1(v) & IT RULES 2021)

8.1. Operational Retention: Active profile data is maintained for the account lifecycle. Ephemeral Local Vibe posts expire after 24 hours. New Happenings expire after 72 hours.

8.2. Temporary Account Deactivation: Data Principals may choose Settings → Deactivate Account to temporarily hide their profile, feeds, and active chats. An account remains dormant and invisible until the user logs in and taps "Reactivate Account" on the authentication gate.

8.3. Dual-Path Account Deletion (Apple Guideline 5.1.1(v)): In compliance with Apple App Store Review Guideline 5.1.1(v), VibeNMeet provides an easily discoverable in-app account deletion mechanism under Settings → Delete Account, offering two explicit options:

  • Option A: Schedule Deletion (30-Day Cooling-Off Window): The account enters a thirty (30) day cooling-off period during which it is rendered invisible to public discovery and chat listings. Logging back in within 30 days provides a one-tap cancellation gate to restore the account. Following 30 days, active profile records and communications are permanently purged.
  • Option B: Delete Immediately (Permanent Erasure): The Data Principal may elect to execute immediate, irreversible account erasure. Protected by an uppercase confirmation phrase, this immediately triggers a secure backend Cloud Function (deleteUserAccount) utilizing the Firebase Admin SDK. The function permanently wipes the user's Firebase Authentication record via getAuth().deleteUser(uid), expunges user media from Cloud Storage buckets, marks active chats, and deletes the Firestore user document with zero delay.
8.4. Mandatory 180-Day Statutory Record Retention (Rule 3(1)(h) IT Rules 2021): Notwithstanding account deactivation or deletion requests, the Data Fiduciary preserves authentication logs, transaction ledgers (purchase_ledger), report files, and exit identity snapshots (incorporating verified Google email address auth.getUser(uid).email, declared phone number, geographic coordinates, reverse-geocoded address, gender, age, and associated chat identifiers at the moment of deletion) in an isolated, encrypted collection (/user_identity_snapshots) for a mandatory statutory period of ONE HUNDRED AND EIGHTY (180) DAYS to assist competent law enforcement authorities in cyber-incident investigations. Access is strictly quarantined and restricted to administrative compliance roles upon formal judicial summons.

8.5. Government Inquiries & Law Enforcement Assistance Protocol: In strict accordance with Section 69 and Section 69B of the IT Act, Rule 3(1)(h) and Rule 3(1)(j) of the IT Intermediary Rules 2021, and Section 94 BNSS 2023 (Section 91 CrPC), user data is furnished strictly upon receipt of a verified written notice, summons, or court order issued by an authorized law enforcement authority.

CLAUSE 9: STATUTORY RIGHTS OF THE DATA PRINCIPAL (DPDPA 2023)

9.1. Enumerated Statutory Rights: Pursuant to Chapter III of the DPDPA 2023, You possess enforceable rights to:

  1. Right to Access: Summary of personal data processed, processing activities, and entities with whom data is shared (Section 11).
  2. Right to Correction & Erasure: Correction of inaccurate data and erasure of obsolete data (Section 12).
  3. Right to Grievance Redressal: Grievance resolution within prescribed statutory timelines (Section 13).
  4. Right to Nominate: Designation of a representative in the event of death or incapacity (Section 14).
  5. Right to Approach the Board: Statutory right to lodge a complaint before the Data Protection Board of India.

9.2. Chat Transcripts & Electronic Evidence: Users may request electronic exports under Right to Portability. Sealed incident conversation audit logs serve as admissible electronic evidence pursuant to Section 63 of the Bharatiya Sakshya Adhiniyam, 2023 (BSA 2023 / Section 65B Indian Evidence Act).

CLAUSE 10: PROHIBITION OF MINOR USAGE (STRICT 18+ MANDATE)

10.1. Absolute Age Gate: The Application is restricted strictly and exclusively to consenting adults aged eighteen (18) years and above.

10.2. Compliance with Section 9 DPDPA 2023: The Data Fiduciary does not knowingly process, track, or profile personal data of children. Any account ascertained to belong to an individual under 18 years shall be summarily deleted within forty-eight (48) hours.

CLAUSE 11: STATUTORY GRIEVANCE REDRESSAL & SAFETY CONTACT

In strict adherence to Rule 3(2) of the IT Intermediary Rules 2021 and Section 8(9) of the DPDPA 2023, the designated Grievance Redressal Officer is:

  • Designation: Grievance Redressal Officer, Legal & Compliance
  • Entity: VibeNMeet / The Unemployee
  • Compliance Email: support@vibenmeet.social
  • Direct Safety & Moderation Escalation: safety@vibenmeet.com
  • Subject Syntax: [STATUTORY GRIEVANCE] - UID: <Your UID>
  • Statutory Timelines: Formal acknowledgment within 24 hours; final redressal and disposal within 15 calendar days.

CLAUSE 12: GOVERNING LAW & JURISDICTION

This Charter shall be governed by, construed, and enforced in accordance with the substantive and procedural Laws of the Republic of India. Subject to the statutory jurisdiction of the Data Protection Board of India, competent courts having territorial jurisdiction over Hyderabad, Telangana, India possess exclusive jurisdiction.

CLAUSE 13: PRIVACY CHARTER FOR LISTED CAFÉS & VENUES

This section details the processing of data relating to café owners, representatives, and venues listed on the VibeNMeet platform:

13.1. Business Data Collection: When a user or venue owner requests to list a café on VibeNMeet, we collect necessary business metadata including venue name, public geographic coordinates, commercial address, public contact/enquiry number, operational hours, price baseline, and venue imagery.

13.2. Purpose & Processing: Such business details are processed and displayed within the application to provide users with transparent location information for meetups. Administrative contact details are used solely by VibeNMeet representatives for administrative onboarding and verification.

13.3. No On-Premise Surveillance or Financial Data Access: VibeNMeet / VIBENMEET LLP does not collect, record, access, or store any on-premise CCTV surveillance footage, point-of-sale customer billing transactions, or commercial financial records from listed venues.

13.4. Non-Disclosure & Security: Contact details submitted for administrative onboarding are protected under industry-standard encryption protocols and will not be sold, rented, or distributed to third-party marketing entities.

Executed by Order of the Management & Legal Directorate
VibeNMeet / VIBENMEET LLP
General Inquiries: support@vibenmeet.social • Safety & Moderation: safety@vibenmeet.com