Privacy Policy
Last updated: 20 September 2026
Before publishing: replace every [SQUARE BRACKET] placeholder below with your real details, and have a lawyer review this against India's Digital Personal Data Protection Act, 2023. This is a working draft, not legal advice.
This policy explains what personal data Socco collects, why we collect it, who we share it with, and the choices you have. It covers the Socco mobile app and this website, both operated by [LEGAL ENTITY NAME], [REGISTERED ADDRESS, CITY, INDIA] ("Socco", "we", "us").
Questions, or want to exercise any of your rights? Write to privacy@socco.in.
Who can use Socco
Socco is only for people aged 18 and over who can verify a current employer email address. We do not knowingly collect data from children. If you believe a minor has created an account, write to us and we will remove it.
The short version on your work email
This is the question people ask first, so here it is up front. We ask for your work email once, to confirm you're a working professional. We send a six-digit code to it. Once you enter that code we convert the address into an irreversible keyed hash, store only that hash and your company's domain, and delete the address itself. We never send anything else to your work email — no marketing, no digests, no reminders. And your employer's name is never shown to anyone on Socco.
What we collect
Information you give us
| Data | Why we need it |
|---|---|
| Work email address | To verify you are a working professional. Hashed and deleted after one-time verification |
| Google or Apple account email | To sign you in and to contact you about your account |
| Phone number | To keep Socco to one account per person, and to power the SOS feature. Stored as a hash |
| Name and profile photo | So hosts and attendees know who is joining them |
| Date of birth | To confirm you are 18 or older. We display only an age range, never your exact age or birth date |
| Gender (optional) | To operate women-only plans and show the mix of attendees |
| Interests and preferred areas | To show relevant plans instead of everything |
| Plans you create or join, and messages in plan group chats | To run the core service |
| Photos you upload to a plan | To display them to the people who attended that plan |
| Trusted contacts for SOS | To alert them if you use SOS |
| Reports you submit about other users | To investigate safety issues |
Information collected automatically
- Approximate and precise location. With your permission, to show plans near you and enable location-based notifications. You can refuse or withdraw this at any time in your device settings; the app still works, you just pick an area manually.
- Device and technical data — device model, OS version, app version, language, and a device identifier for push notifications.
- Usage and diagnostic data — screens visited, features used, crashes and errors, used to fix problems and improve the app.
- Attendance records — whether you checked in at plans you joined, which produces the reliability record hosts can see.
Information from verification partners
If you join as a partner or guest of a member, we ask for a phone number and a selfie, and in some cases an identity document checked by a third-party verification provider. We store the provider's result and reference, plus a one-way hash used to prevent banned users returning. We do not store Aadhaar numbers.
Why we use your data
- To create and secure your account, and verify eligibility
- To show you nearby plans and send notifications you've opted into
- To run plan group chats, approvals, waitlists and bill-splitting
- To keep people safe — investigating reports, detecting fake accounts and repeat offenders, responding to SOS alerts
- To maintain reliability records so hosts can decide who to accept
- To fix bugs, measure whether features work, and improve the product
- To comply with law and respond to lawful requests
What other people can see
This matters, so we're specific about it:
- Visible to other members: your first name, profile photo, age range, your role or industry if you provide it, your reliability record, and the plans you host.
- Visible only to people on the same plan: the exact meeting address (after the host accepts you), your messages in that group chat, and photos you add to that plan.
- Never shown to anyone: your email addresses, your employer's name, your exact date of birth, your phone number, your precise location, and any report you file.
Reports are confidential. We never tell the person you reported who reported them.
Who we share data with
We do not sell your personal data, and we do not share it with advertisers. We share it only with:
- Service providers that run parts of Socco for us — cloud hosting and database [e.g. Supabase], realtime messaging [e.g. Google Firebase], transactional email [e.g. Resend], push notifications, crash reporting, identity verification, and payment processing. They may only use the data to provide their service to us.
- Your trusted contacts, when you trigger an SOS alert.
- Law enforcement or regulators, where legally required, or where we believe in good faith that disclosure is necessary to prevent serious harm.
- A successor entity, if Socco is involved in a merger, acquisition or restructuring. We'll notify you if that happens.
Some providers may process or store data outside India. Where that happens, we take steps to ensure comparable protection.
How long we keep it
| Data | Retention |
|---|---|
| Work email address (plaintext) | Deleted immediately after verification. Only an irreversible hash and the company domain remain |
| Account and profile | Until you delete your account |
| Plan group chat messages | Deleted shortly after the plan ends (typically 24 hours; longer for multi-day trips) |
| Plan photos | Up to [30] days, or until removed by the uploader or the person pictured |
| Attendance and reliability records | Kept while your account exists, as they underpin trust between members |
| Safety reports, blocks, and verification hashes | Up to [24] months after the event, so we can detect repeat offenders and enforce bans |
| Diagnostic and crash data | Up to [90] days |
If you delete your account we remove your profile and content. We may retain a minimal safety record — for example a hashed identifier attached to a ban or an unresolved report — where we are permitted or required to. We keep only what is necessary and no longer than needed.
Your legal basis and your consent (DPDP Act)
Under India's Digital Personal Data Protection Act, 2023 we process your personal data on the basis of the consent you give when you create an account and accept these policies, and on the basis of legitimate uses permitted by the Act — including preventing fraud and responding to a threat to someone's safety.
You may withdraw your consent at any time by deleting your account (see Delete your data). Withdrawing consent does not affect processing already carried out, and we may retain the minimal safety records described below where the law permits or requires it.
We do not knowingly process the personal data of anyone under 18. Socco is an 18+ service, and we do not carry out behavioural tracking or targeted advertising directed at children.
Retention required by law (IT Rules 2021)
Socco is an intermediary under India's Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021. Those Rules require us to:
- Retain your registration information for at least 180 days after you delete your account
- Preserve information and records for longer where needed for an investigation, or where directed by a court or authorised government agency
- Remove non-consensual intimate imagery within 24 hours of a complaint, and act on lawful takedown orders within 36 hours
This means a small amount of data may survive account deletion. It is the minimum the law allows, it is not used for any other purpose, and it is deleted once the obligation ends.
If there is a data breach
If a breach affects your personal data we will notify you and the Data Protection Board of India as required by the DPDP Act, and tell you what happened, what data was involved, and what you should do.
Your rights
You can:
- Access the personal data we hold about you
- Correct anything inaccurate, in the app or by writing to us
- Delete your account and associated data — see Delete your data
- Withdraw consent for location, notifications or contacts at any time in your device settings
- Nominate someone to exercise your rights on your behalf if you are unable to, as the DPDP Act allows
- Complain to our Grievance Officer first. If you're not satisfied you may escalate to the Grievance Appellate Committee constituted under the IT Rules 2021 (within 30 days), and to the Data Protection Board of India for data protection matters
We aim to respond to requests within 30 days.
How we protect your data
Data is encrypted in transit. Access to production systems is limited to people who need it. Database access rules restrict every record to the people entitled to see it, and uploaded photos are stored in private storage rather than on the open internet. Work email addresses are hashed with a keyed function whose secret is never stored alongside the data. No system is perfectly secure, but if a breach affects your data we will notify you and the relevant authority as required by law.
Grievance officer
As required under Indian law, you may contact our grievance officer:
[NAME]
Grievance Officer, [LEGAL ENTITY NAME]
hello@socco.in
[FULL PHYSICAL ADDRESS, CITY, STATE, PIN — the IT Rules require this to be published]
We acknowledge complaints within 24 hours and aim to resolve them within 15 days.
Changes to this policy
If we make material changes we'll notify you in the app or by email before they take effect, and update the date at the top of this page.