Introduction
Welcome to Drifty, operated by Drifty Technologies Private Limited ("Drifty", "we", "us", or "our"), a company incorporated under the Companies Act, 2013, with its registered office in India.
This Privacy Policy describes how we collect, use, process, disclose, store, and protect information about you when you use our mobile application, website, and related services (collectively, the "Platform").
๐ Plain English: This document tells you exactly what data we collect, why we collect it, and how we keep it safe. We are fully compliant with India's Digital Personal Data Protection (DPDP) Act, 2023.
By downloading, installing, or using Drifty, you acknowledge that you have read and understood this Privacy Policy and consent to the practices described herein. If you do not agree, please discontinue use of the Platform immediately.
Data We Collect
We collect information in three ways: information you provide directly, information collected automatically, and information from third parties.
A. Information You Provide
- Account Information: Full name, date of birth, gender, phone number, and email address during registration.
- Vibe Profile: Music preferences, personality traits, hobbies, lifestyle choices, and answers to our 12-question vibe quiz.
- Photos & Media: Profile photos and any media you voluntarily upload to the Platform.
- Voice Notes: Audio recordings sent through our vibe-starter chat feature, stored temporarily for message delivery.
- Verification Data: Aadhaar-linked selfie data used solely for identity verification; the raw Aadhaar number is never stored on our servers.
- Communications: Messages, reports, and support communications you send to us.
- Payment Information: For Drifty Premium subscribers โ billing details processed via our PCI-DSS compliant payment partners. We do not store card numbers.
B. Information Collected Automatically
- Device Information: Device model, OS version, unique device identifiers, and mobile network information.
- Usage Data: Features used, time spent, swipe patterns (aggregated), and interaction logs.
- Location Data: Approximate city-level location (GPS-precise location is only used during SOS emergencies with your explicit consent).
- Log Data: IP address, browser type, pages visited, and crash reports.
C. Information from Third Parties
- Spotify Integration: If you connect your Spotify account, we access your top artists, genres, and listening patterns to power Music DNA Matching. We do not access your Spotify credentials or payment data.
- Social Login: If you sign in via Google or Apple, we receive your name and email as shared by those services.
What We Never Collect
Your Aadhaar number, financial account details, or private messages between matched users.
Minimal by Design
We follow data minimization principles โ we only collect what's necessary for the service to work.
How We Use Your Data
We use the information collected for the following specific, lawful purposes:
- Matching Algorithm: To generate vibe-based matches using personality traits, music preferences, energy patterns, and behavioral signals.
- Platform Operations: To provide, maintain, and improve the Drifty Platform, including processing transactions and sending service-related notifications.
- Safety & Security: To detect, investigate, and prevent fraud, abuse, harassment, and violations of our Community Guidelines.
- Identity Verification: To confirm user authenticity and maintain a fake-profile-free environment.
- Personalization: To recommend local events, cafรฉs, and experiences that match your and your match's shared vibe profile.
- Customer Support: To respond to your queries, resolve disputes, and provide technical assistance.
- Legal Compliance: To comply with applicable Indian laws, including the DPDP Act, 2023, IT Act, 2000, and any court orders or regulatory requirements.
- Analytics: To understand platform usage trends using anonymized, aggregated data. Individual user behavior is never sold or shared for advertising.
We do not use your data for: targeted advertising, selling to third parties, profiling for political purposes, or any purpose not listed above.
Data Sharing & Disclosure
Your data is not for sale. Period. We may share data only in these limited circumstances:
- With Your Consent: When you explicitly authorise sharing, such as when your profile is shown to potential matches.
- Service Providers: Trusted vendors under strict data processing agreements that prohibit further sharing.
- Safety Emergencies: When you activate the SOS feature, your location is shared with your designated emergency contacts only.
- Legal Obligations: When required by law, court order, or government authority under applicable Indian legislation.
- Business Transfers: In the event of a merger, acquisition, or asset sale, your data may be transferred. You will be notified with the option to delete your account before transfer.
Our Key Service Providers Include:
- Amazon Web Services (AWS) โ Cloud hosting, India region data centres
- Razorpay / Stripe โ Payment processing
- Firebase / Google Cloud โ Push notifications, analytics
- DigiLocker API โ Aadhaar-based verification
- Spotify API โ Music preference data
Data Storage & Security
We store all personal data on servers located in India, in compliance with data localisation requirements under Indian law.
Encryption at Rest
All stored data is encrypted using AES-256 encryption.
Encryption in Transit
All data transmissions use TLS 1.3 protocols.
Regular Audits
We conduct quarterly security audits and annual penetration testing.
Access Controls
Strict employee access controls with role-based permissions and audit logs.
Data Retention
- Active Accounts: Data retained for the duration of your account's existence.
- Deleted Accounts: Personal data deleted within 30 days of account deletion request.
- Voice Notes: Automatically deleted from servers 7 days after delivery.
- Chat Messages: Deleted from servers 90 days after account deletion.
Your Rights Under DPDP Act, 2023
As a data principal under the Digital Personal Data Protection Act, 2023, you have the following rights:
- Right to Access: Request a copy of all personal data we hold about you.
- Right to Correction: Request correction of inaccurate or incomplete personal data.
- Right to Erasure: Request deletion of your personal data. See our Account Deletion page.
- Right to Withdraw Consent: Withdraw your consent for data processing at any time.
- Right to Grievance Redressal: Lodge a complaint with our Grievance Officer or the Data Protection Board of India.
- Right to Nominate: Nominate another individual to exercise your rights in the event of your death or incapacity.
To exercise any right: Email our Data Protection Officer at driftysupportapp@gmail.com or visit Settings โ Privacy โ Data Rights in the app. We will respond within 30 days.
Cookies & Tracking Technologies
Our website uses cookies and similar tracking technologies.
- Essential Cookies: Required for basic platform functionality. Cannot be disabled.
- Analytics Cookies: Help us understand how users interact with the Platform using anonymized data. You may opt out via the cookie consent banner.
- Preference Cookies: Remember your settings and preferences.
We do not use third-party advertising cookies or cross-site tracking technologies.
Children's Privacy
Drifty is strictly intended for individuals who are 18 years of age or older. We do not knowingly collect personal data from minors.
Our Aadhaar-linked verification process is specifically designed to prevent minors from creating accounts. If we discover that a user is under 18, we will immediately suspend the account and permanently delete all associated data without notice.
If you believe a minor has created an account on our Platform, please report it immediately at driftysupportapp@gmail.com.
Third-Party Links & Integrations
The Platform may contain links to third-party websites, services, or integrations. These third parties have their own privacy policies, and we are not responsible for their practices.
When you connect Spotify, you are also subject to Spotify's Privacy Policy. You can disconnect Spotify at any time from Settings โ Connections.
Policy Updates
We may update this Privacy Policy periodically. When we make material changes, we will post the updated policy with a revised "Last Updated" date and send an in-app notification and/or email to registered users.
Your continued use of the Platform after 7 days of notification constitutes acceptance of the updated policy.
Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact our Grievance Officer:
Data Protection Officer / Grievance Officer
Drifty Technologies Private Limited
India
Response time: Within 30 days of receipt