Privacy Policy
Last updated: 12 September 2026
This policy explains how Rahul Baghel, sole proprietor, trading as Tugethr ("Tugethr", "we", "us", "our"), with its principal place of business at B-59A, Rajat Vihar, Sector 62, Noida, Uttar Pradesh 201309, India, collects and handles your personal data when you use the Tugethr mobile application, the Tugethr website and the Tugethr merchant portal (together, the "Platform").
Tugethr is a sports community app. It helps adults find players, organise matches, join crews, book venues and message each other. Handling your data carefully matters more here than in most apps, because the Platform knows where you are, who you play with and what you say to them.
Under India's Digital Personal Data Protection Act, 2023 ("DPDP Act") you are the Data Principal and we are the Data Fiduciary for your personal data. We also follow the Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 ("SPDI Rules").
Four things worth knowing up front. Your chat messages are encrypted in transit and at rest, but we hold the key that unwraps your chat key, so message content can be accessed for safety and legal reasons (section 4). A nightly encrypted backup of your own chat history is uploaded to our servers, and it is on by default (section 4.1). Your precise location is stored on our servers so that discovery works, but other users are only ever shown a distance rounded to the nearest 100 metres and your city (section 5). AI help inside chat is off by default, and switching it on sends recent decrypted messages to a third-party AI provider (section 6).
1. The data we collect
1.1 Data you give us
- Account details: your mobile number and/or email address, and for older accounts a password (which we store only as a salted hash, never in readable form).
- Profile details: display name, first and last name, date of birth, gender, bio, profile photograph and up to six additional photographs, answers to profile prompts, your sports with skill level and years played, weekly availability, city, state, country and, if you provide it, address and postal code.
- Discovery settings: whether your profile is public, whether you are discoverable nearby, whether you appear on the map, your search radius, who can message you and whether your online status is shown.
- Verification photograph: if you apply for a verified badge, the selfie you submit, and any identity document if we ask for one. A member of our team reviews it manually. We do not run facial recognition on it.
- Content you create: match listings and descriptions, screening questions and the answers you give when joining a match, crew details, availability pings, post-match photos and captions, peer ratings and kudos you give other players, quiz answers, and feedback.
- Support and reports: the text and any images in support tickets, feedback and reports you file about other users. Where you report a chat message, your device attaches a decrypted copy of the reported message so a moderator can read it.
- Payment details you enter at checkout: the name, email address and phone number you pass to the payment gateway.
- Merchant details (venue partners only): business name, contact name, phone and email, GST number, PAN, and bank account name, number, IFSC and bank name or a UPI ID for payouts.
1.2 Data your device sends us
- Location: your latitude, longitude and the accuracy reading reported by your device, plus the resulting city, state and country. See section 5.
- Device and push data: a push notification token, a device identifier, the platform (Android or iOS), a device label you set for linked devices, and the app version.
- Encryption material: the public half of your account identity key and of each device key, and an encrypted blob holding your account key. See section 4.
- Technical logs: your IP address, user agent, and the time and outcome of sign-in, sign-out and OTP events. We also record the IP address used when a merchant signs a venue agreement.
1.3 Data generated by your use of the Platform
- Chat and call metadata, described in section 4.
- Matches you created, joined, were approved or rejected for, and your participation history; your connections and play requests; crews you belong to.
- Venue bookings: the venue, date, time, sport, amount, platform commission, status and the related payment reference.
- Payment records, described in section 7, and your subscription and add-on history.
- Usage counters we keep to enforce plan limits: how many play requests and matches you have used this month, and how many AI actions you have used today for each feature. These are counters, not copies of what you did.
- Badges, trophies, quiz runs, per-question quiz answers and quiz statistics.
- Records of one-time passwords we sent (the phone number or email they were sent to, the purpose, the outcome and the number of attempts, but never the code itself), and copies of transactional emails we sent you.
- Moderation records: reports filed by or about you, warnings, suspensions and the actions our administrators took.
1.4 What we do not collect
- We do not use any third-party analytics, advertising, attribution or crash-reporting SDK in the app. There is no Firebase Analytics, no Crashlytics, no Sentry, no Amplitude, Mixpanel, PostHog or Segment, and we do not read your advertising identifier.
- We do not read your contacts, your call log, your SMS messages or your photo library. You choose individual photos to share.
- We do not collect location in the background. Location is only read while the app is open.
- We do not collect health, biometric, caste, religious, political or sexual orientation data, and you should not put such data in your profile.
- We never see your card number, CVV, UPI PIN or net banking password.
- We do not sell your personal data, and we do not share it with data brokers.
2. Why we use your data, and our legal basis
Under the DPDP Act we process your personal data on the basis of the consent you give when you create an account and when you grant a permission such as location or notifications, and for certain legitimate uses permitted by the Act, such as complying with a legal obligation. Payment details, passwords and financial information are treated as sensitive personal data under the SPDI Rules.
- To run your account: registering you, verifying your phone or email by OTP, keeping you signed in and letting you manage your profile.
- To check you are 18 or over: using the date of birth you give us, both in the app and again on our servers.
- To provide discovery and matchmaking: using your location, sports, skill level, availability and activity to show you nearby players, matches, crews and venues, and to show you to them.
- To deliver messages, calls and notifications between you and the people you contact.
- To take payments, activate plans and add-ons, confirm bookings, issue receipts and process refunds.
- To provide optional AI features you have enabled, as described in section 6.
- To keep the Platform safe: investigating reports, detecting fraud and abuse, applying rate limits, blocking spam and enforcing our Terms of Service.
- To support you: answering tickets, emails and feedback.
- To improve the Platform: understanding aggregate usage such as how many people use a feature. This is calculated from our own database, not from any third-party tracker.
- To comply with the law and to respond to lawful requests from courts, regulators and law enforcement.
We do not use your personal data to make any decision that produces a legal effect on you without a human being involved.
3. What other users can see
- Your profile is private by default. It only appears in Discover after you choose to make it public.
- When your profile is public, other users can see your display name, photographs, bio, age, gender, city, sports and skill levels, badges you have chosen to display, whether you are verified, whether you are online and a distance rounded to the nearest 100 metres. We never send your coordinates to another user's device.
- If you turn on "Show me on the map", the app places a marker for you. The marker is drawn from that rounded distance on a bearing derived from your account number, so it sits the right distance away but in the wrong direction. It is never your real position, and the consent flag only takes effect at all if your profile is public and you are discoverable nearby.
- Match organisers see your name, photo, age, gender, city, verified status and the sporting details on the profile you share with them, plus any screening answers you give. This applies even if you use an alias profile.
- Other participants in a match or crew see your profile and anything you post there. Everyone in a group chat sees your messages in that group.
- You control your online status, whether you can be found nearby, whether you appear on the map, who can message you, and you can hide your online status from specific people.
4. Encrypted chat and calls
Messages and chat media are encrypted on the sending device, encrypted in transit, and stored encrypted on our servers. The keys are managed by us (section 4.3), so we are technically able to decrypt message content. We access it to investigate a report, to deal with abuse or fraud, and where the law requires it.
4.1 Your chat backup
Your phone, not our server, is the permanent home of your chat history, so losing the phone would lose the history. To prevent that, the app makes an encrypted backup of your own messages and uploads it to us.
- It is on by default and it runs automatically, once a night, at around midnight local time. The app wakes itself to do it. You can switch it off, or change how it is keyed, in Settings under Chat & devices.
- We keep exactly one backup per account: each upload replaces the previous one. We store the encrypted blob, its size, how many messages it contains and when it was made.
- By default the backup is encrypted with your account key, and we hold the key that unwraps your account key (section 4.3), so we are technically able to read a backup made this way.
- If you instead set your own backup passphrase, that passphrase is never sent to us, we cannot read the resulting backup, and we cannot reset or recover the passphrase if you lose it.
- Deleting your account deletes the backup.
4.2 Message metadata
Delivering a message requires us to know where to send it. We hold, in readable form:
- the conversation, whether it is one to one or a group, and who its participants are;
- the name of a group conversation;
- who sent each message and when;
- a coarse message category, whether an encrypted file is attached, and the size of the encrypted payload;
- delivery and read status, and which message a reply points to;
- that a reaction, an edit, a pin or a delete was sent, and when;
- whether a message has been edited or deleted, and when;
- the storage key of an encrypted media file, so we can delete it later;
- your per-conversation settings, such as which chats you have pinned, muted, archived, locked or hidden, and the names of any lists you create;
- who is online, and the model and platform of the devices linked to your account;
- for calls: who called whom, whether it was audio or video, whether it was answered, missed or declined, when it started and ended, and a short reason it ended. Nothing of what was said.
4.3 Your account key
Your account identity key is what unlocks your message history on a device. It is held on our servers in wrapped form and released to devices signed in to your account, so signing in on a new device restores your history. Because we hold the wrapping key, we can unwrap your account key, and any backup encrypted with it. A backup passphrase you set yourself is separate: we do not hold it, and if you lose it we cannot reset or recover it.
4.4 Push notifications for messages
When a message arrives while your app is closed, we send a push through Firebase Cloud Messaging. The visible text of that push is only the sender's name and the words "New message". For short text messages we also attach the encrypted copy addressed to your own device, and your device decrypts it locally to replace the notification with a preview. This means Google receives the sender's display name, the conversation and message identifiers and the encrypted payload, which Google cannot read. Longer messages and media stay as "New message".
4.5 The limits of encryption
- Encryption does not protect you from the person you are talking to. They can screenshot, copy, record or forward anything you send.
- If someone reports one of your messages, their device sends us a decrypted copy of it as evidence. Our moderators read that copy, and we keep it with the moderation record.
- If a message is decrypted on your device, it is stored on that device, and anyone with access to your unlocked phone can read it.
- Voice and video calls travel directly between the two devices, encrypted with WebRTC's DTLS-SRTP. We do not record calls, we do not store any audio or video, and we cannot listen in. Where a home or mobile network blocks a direct connection, the encrypted media is relayed through our own coturn server, which forwards the packets without holding a key to them. Setting up a call also contacts Google's public STUN server, which sees your device's network address.
- The setup information that lets two devices find each other does pass through our servers in readable form and contains network addresses for both devices. We hold the caller's connection offer only while the call is ringing and discard it when the call ends.
5. Location data
- Discovery is geographic, so the Platform needs your location to be useful. With your permission, the app reads your device location and sends the latitude, longitude and accuracy to our servers.
- We store your coordinates on our servers, both in our main database and in a geospatial index used for radius searches. We also store the derived city, state and country.
- We do not keep a location history. Each update overwrites the previous one, so we hold one current position per account and no trail.
- Location is read only while the app is open. The app does not request background location permission.
- We use it to rank and filter nearby players, matches, drop-in pings and venues within your chosen radius, and to fill in your city.
- Other users never receive your coordinates. They receive a distance rounded to the nearest 100 metres and your city.
- If you use "use my current location" in the city picker, your coordinates are sent to Mapbox by our server, so Mapbox sees the coordinates but not your device or IP address. If you open the in-app map, your device contacts Mapbox directly for map tiles, so Mapbox sees your IP address and the area you are viewing. We have turned Mapbox telemetry off.
- If you post a drop-in "free to play" ping, its coordinates are stored with the ping until it expires.
- You can turn location off in your device settings at any time. Discovery, nearby matches and nearby venues will stop working.
6. AI features
Some features use artificial intelligence. To provide them we send the relevant input from our servers to a third-party AI model provider over an encrypted connection. The text provider is selected in our admin console from a small registry and can be changed without a release; today it is Microsoft Azure AI Foundry, and the registry also supports OpenAI and Anthropic. Image generation, image editing and speech-to-text run on Azure AI Foundry in every configuration.
6.1 What is sent, feature by feature
- AI help inside chat (writing assistant and icebreakers): up to the last twenty messages of that conversation in decrypted form, each truncated, together with a short summary of your profile and the other person's profile (name, age, sport, city and up to two prompt answers) and the instruction you type. Icebreaker suggestions send up to the last eight messages.
- Discovery openers: the other person's sports, city, approximate distance, age and a short extract of their bio, plus your sports.
- "Best for you" ranking: a short summary of up to twenty-five candidate profiles (sports, skill, approximate distance, age and a short bio extract) with their internal account identifiers, plus your sports.
- AI search, AI match creation and the AI profile builder: the text you type. If you use voice input, the audio recording itself is uploaded and transcribed by a speech-to-text model, and the transcript is then processed by the text model.
- AI image and GIF generation: the prompt you type.
- AI image editing: the photograph you choose, resized and sent to the provider.
6.2 Your control over AI in chat
- AI help in chat is off by default. The first time you try to use it, the app explains what will be shared and asks you to turn it on. Nothing is sent before you agree.
- Your answer is stored on that device, not on our servers, so turning AI help on does not turn it on for your other phones.
- You can turn it off again at any time in Settings, and you can exclude an individual conversation from AI entirely.
- Settings → AI also has a master switch covering every AI feature on the account, including search, match creation and images. That one is on unless you turn it off, but it cannot override the chat opt-in above: both have to be on before a message leaves your device.
- The messages sent for AI help include messages the other person wrote. They are not asked separately, so please think about that before you use AI help in a private conversation. If you would rather a particular chat never reached AI, switch it off for that conversation.
6.3 How AI data is handled
- We do not store the prompts you send to AI features or the responses that come back. Our AI service keeps no request log and deliberately omits provider response bodies from its error logs.
- We keep only counters of how many AI actions you have used, so we can enforce your plan's limits.
- Images and GIFs you generate are stored in our file storage so they can be displayed, and are served from the public content URLs described in section 12.
- We use AI providers only under business terms that do not permit them to train their models on your content. We cannot control what a provider does in breach of its own terms.
- AI providers process data outside India. See section 13.
- AI output can be inaccurate. Please review it before you send or rely on it.
7. Payments
- Payments are processed by Razorpay Software Private Limited. Card, UPI, net banking and wallet credentials are entered inside Razorpay's own checkout. They never reach our servers and we never store them.
- We send Razorpay the amount, currency, a receipt reference, internal notes identifying the plan or booking and your account, and the name, email and phone number you supply at checkout.
- We store our own order reference, the Razorpay order and payment identifiers, the payment signature, the amount, currency, status, the payment method category (for example card, UPI, net banking or wallet), a description, the customer name, email and phone supplied at checkout, any error message, and the timestamps.
- We also store the confirmation record Razorpay sends us for each payment. That record can include partial payment instrument details such as the last four digits of a card, the card network and issuing bank, the bank used for net banking, or a UPI virtual payment address, along with the email and phone you gave the gateway. We do not use these fields, but they are retained with the payment record.
- Financial information is sensitive personal data under the SPDI Rules and is handled accordingly.
- Merchant partners additionally provide bank account or UPI details, PAN and GST number for payouts, which we store to settle bookings and to meet tax reporting obligations.
8. Communications and notifications
- Push notifications are delivered by Firebase Cloud Messaging (Google). You can turn off individual categories in Settings and all of them in your device settings. Turning a category off stops us from sending it.
- SMS one-time passwords are sent through Twilio Verify. Your phone number is shared with Twilio for that purpose, and Twilio, not us, generates and checks the code. We never hold the code itself.
- Email (one-time passwords, payment receipts and service notices) is sent through Brevo's SMTP relay. We keep a copy of the emails we send you.
- Marketing messages are off by default. We will only send them if you opt in, and every marketing message will let you opt out.
- We will always send you essential service messages about security, payments, bookings and changes to these policies. You cannot opt out of those while you have an account.
9. Cookies, storage and identifiers
- The mobile app does not use cookies. It stores your session tokens, your encryption keys, your device-local chat history, your settings and cached media in the app's private storage on your device. Clearing app data or uninstalling the app removes them.
- The website stores your session token, your profile summary and a generated browser identifier in your browser's local storage so you stay signed in. We do not set advertising or analytics cookies.
- Device identifiers. Firebase Cloud Messaging generates an installation identifier and sends basic device information to Google in order to issue a push token. This is required for push notifications to work.
10. Who we share your data with
We do not sell your personal data. We share it only as set out below.
10.1 Other users
As described in section 3, and with anyone you choose to message.
10.2 Service providers who process data on our behalf
This is the complete list. There are no others.
- Google Cloud, Mumbai (asia-south1): the servers the Platform runs on. Our main database, our cache, our message bus, our file storage and our call relay all run on machines we operate in that region, not as managed products of a third party.
- MongoDB Atlas: the geospatial database used for nearby search.
- Razorpay: payments, refunds and merchant payouts.
- Twilio: SMS one-time passwords.
- Brevo: transactional email.
- Google (Firebase Cloud Messaging): push notification delivery.
- Mapbox: geocoding for the city picker, and map tiles for the in-app map.
- Microsoft Azure AI Foundry, with OpenAI and Anthropic as configurable alternatives: AI features, as described in section 6.
- Giphy: the in-chat GIF picker. Your device contacts Giphy directly, so Giphy receives your search terms and your IP address. GIF content is restricted to the G rating. When you send a GIF, the recipient's device also loads it from Giphy.
- Google's public STUN server: contacted while a call is being set up, so it sees your device's network address. No call media passes through it.
These providers may only use your data to provide their service to us, under contract.
10.3 Venue partners
When you book a slot, we share the booking details and the contact details needed for the venue to honour it.
10.4 Legal and corporate
- Where we are required to by law, or in response to a valid order from a court, regulator or law enforcement agency.
- Where we reasonably believe disclosure is necessary to prevent serious harm, fraud, or a threat to someone's safety.
- To our professional advisers, auditors and insurers under a duty of confidentiality.
- To a buyer or successor if we are involved in a merger, acquisition or sale of assets, subject to this policy continuing to apply.
10.5 Sponsored content
If we show sponsored or featured placements, we select them ourselves using signals such as your city, sport, age range and gender. We do not use third-party advertising networks, we do not track you across other apps or websites, and we do not send your personal data to advertisers.
11. How long we keep your data, and account deletion
11.1 While your account is open
- Your profile, sports, settings and photographs are kept until you change or remove them.
- Your location is a single current value, overwritten on each update.
- Encrypted chat messages are kept on our servers indefinitely, until they are deleted.They are not wiped on a timer. We built a sweep that drops delivered ciphertext after a week, and we turned it off: it was destroying the only surviving copy of messages that had reached a phone but never been opened. We would rather tell you the ciphertext is still there than claim a deletion schedule we do not run.
- "Delete for everyone" removes the message from the participants' devices, not from our servers. It works by telling each device to hide the message, so the encrypted copy stays in our database. Using "Clear chat" does delete the message records from our servers, for every participant in that conversation, and account deletion removes the messages you sent, as set out in section 11.3.
- Encrypted media files are deleted from our storage once every recipient device has downloaded them, and a nightly sweep removes any that are still sitting there 30 days after they were sent. Your device keeps its own decrypted copy until you clear it.
- Encrypted messages queued to sync to a device you have just linked are deleted once that device collects them, and in any case after 7 days.
- Your encrypted chat backup is a single record that each nightly upload replaces, so we hold one, never a history of them.
- Payment and booking records are kept for as long as required by tax, accounting and audit law — for our books, at least six years from the end of the financial year the payment falls in.
- Verification photographs are kept while the verification is valid.
- Sign-in and OTP records, moderation records and administrator action logs are kept for security and audit purposes.
11.2 Taking a break instead
Settings → Deactivate account hides your profile, matches and crews from everyone without deleting anything. Signing in again restores the account exactly as it was. If you are unsure, this is the reversible option.
11.3 When you delete your account
There are three ways to delete, and they do not behave the same way:
- In the app (Settings → Delete account): you are signed out at once and your profile disappears immediately, but the data is held for 30 days and erased after that. Signing in during those 30 days cancels the deletion.
- On the website (Settings → Delete account): the purge runs the moment you confirm. There is no grace period and nothing to sign back into.
- By email to support@tugethr.com, if you have lost access to the number or address you signed up with. We verify the account is yours first, and complete it within 15 days.
Full details of each route are on the delete your account page.
We permanently delete:
- your profile photographs, your avatar and the underlying image files;
- your verification photograph and any identity document, and the underlying files;
- your stored location, in both databases;
- your profile prompt answers, sports, skill levels, availability and badges;
- your push notification tokens and linked-device records;
- your sign-in identifiers, so your number or email stops resolving to an account;
- the people you passed on in Discover, and the records of who found you by handle;
- your chat account identity key and device keys, which is what makes any surviving ciphertext unreadable;
- your encrypted chat backup and any pending device-sync data;
- the messages you sent, your conversation memberships and your chat settings;
- your call records.
We anonymise your account record itself: your email, phone number, username, password, name, bio, date of birth, gender, addresses and device identifiers are erased and the account is marked as deleted. We keep the empty record so that financial and moderation references do not break.
We keep:
- payment, subscription and booking records, including the gateway confirmation record described in section 7, for as long as tax and accounting law requires;
- reports filed by you or about you, including any message evidence attached to them, and the related moderation decisions;
- administrator action logs and sign-in event logs, which include IP addresses;
- a one-way hashed record that the account existed: an HMAC-SHA256 digest of your phone number and email under a server-side secret, the date of deletion, and whether the account was suspended at the time. It cannot be turned back into your number or address. It exists so that a user we have banned cannot delete the account and sign up again with a clean record, which on an app where adults meet strangers in person is a safety measure we are not willing to give up;
- messages other people sent you, because those also belong to the other participant's history;
- content you posted into shared spaces, such as match listings you organised and messages in group conversations, which may remain visible to other participants;
- anything we are required to retain by law or need to keep to establish, exercise or defend a legal claim.
Chat data lives in a different service from your account, so the purge makes a second, separate call to erase it. If that call fails it is retried by hand rather than skipped. If you want us to confirm what remains after your deletion, or to remove something specific, contact the Grievance Officer in section 15.
An active paid plan ends when you delete and is not refunded. Cancel it first if you want the unused part of the term back (see the Terms of Service, section 11.3).
12. Security
- All traffic between your device and our servers uses TLS.
- Chat messages and chat media are encrypted in transit and at rest, as described in section 4.
- Passwords are stored only as salted hashes. Sign-in uses short-lived access tokens with rotating refresh tokens, and tokens are invalidated on sign-out.
- Access to production data is restricted to authorised personnel, and administrator actions are recorded in an audit log.
- We apply rate limiting and abuse detection to sign-in, OTP, payment and upload endpoints.
- One limitation you should know about. Profile photographs, match images, venue images and AI-generated images are served from public content URLs. The addresses are long and effectively unguessable, but they are not access-controlled, so anyone who has the exact link can open the file without signing in. Chat media is not affected, because it is encrypted before upload. Do not put anything in a profile or match photo that you would not want a person with the link to see.
- None of this makes a stolen, unlocked phone safe. Your decrypted chat history sits on the device, so a screen lock is the control we cannot apply for you.
- If a personal data breach occurs, we will notify the Data Protection Board of India and affected users as required by the DPDP Act.
13. Transfers outside India
The Platform itself runs in Mumbai. Your profile, your location, your messages, your bookings and your payment records all sit on servers in Google Cloud's asia-south1 region. The geospatial index used for nearby search runs on MongoDB Atlas and holds your account number, your coordinates and their accuracy, your city, state and country, whether you are online and when you were last active. Nothing else.
Six of the providers in section 10 process data outside India: Microsoft Azure AI Foundry for AI features, Firebase Cloud Messaging for push, Twilio for SMS one-time passwords, Brevo for email, and Mapbox and Giphy, which your device contacts directly. Where data is transferred outside India we do so under contractual protections and in accordance with the DPDP Act and any restrictions notified by the Central Government.
14. Your rights
Subject to the DPDP Act and the SPDI Rules, you can:
- Access your data and ask for a summary of the personal data we hold about you and who we have shared it with.
- Correct or update inaccurate or incomplete data. Most of it you can edit directly in the app.
- Delete your data by deleting your account, as described in section 11 and on the delete your account page.
- Obtain a copy of your data in a portable form. There is no self-service export yet, so write to us and we will prepare one.
- Withdraw consent at any time, for example by turning off location, notifications or AI, or by deleting your account. Withdrawing consent does not affect processing already carried out, and some features will stop working.
- Nominate another person to exercise your rights in the event of your death or incapacity.
- Complain to us first, and then to the Data Protection Board of India if you are not satisfied.
To exercise a right, write to support@tugethr.com or to the Grievance Officer in section 15 from the email address or phone number registered to your account. We may ask you to verify your identity. We will respond within the time allowed by law, and normally within 30 days.
15. Grievance redressal
If you have a question, a complaint, or a request about your personal data, contact our Grievance Officer, appointed under the Information Technology Act, 2000, the rules made under it, and the DPDP Act:
- Name: Rahul Baghel
- Designation: Grievance Officer, Rahul Baghel, sole proprietor, trading as Tugethr
- Email: grievance@tugethr.com, or support@tugethr.com
- Phone: +91 88106 13554
- Address: B-59A, Rajat Vihar, Sector 62, Noida, Uttar Pradesh 201309, India
We will acknowledge your complaint within 24 hours and resolve it within 15 days of receipt. If you are not satisfied with our response, you may escalate to the Data Protection Board of India.
16. Children
Tugethr is for adults aged 18 and over. We do not knowingly collect personal data from anyone under 18, and we do not offer a version of the Platform for children. If you believe a person under 18 has created an account, tell us at support@tugethr.com or through the Grievance Officer and we will suspend the account and delete the data.
17. Changes to this policy
We may update this policy as the Platform changes or as the law changes. We will revise the "Last updated" date above, and for material changes we will notify you in the app or by email before the change takes effect.
18. Contact us
Rahul Baghel, sole proprietor, trading as Tugethr, B-59A, Rajat Vihar, Sector 62, Noida, Uttar Pradesh 201309, India.
General enquiries and data requests: support@tugethr.com.