Privacy Policy

Last updated: 20 September 2026

Before publishing: replace every [SQUARE BRACKET] placeholder below with your real details, and have a lawyer review this against India's Digital Personal Data Protection Act, 2023. This is a working draft, not legal advice.

This policy explains what personal data Socco collects, why we collect it, who we share it with, and the choices you have. It covers the Socco mobile app and this website, both operated by [LEGAL ENTITY NAME], [REGISTERED ADDRESS, CITY, INDIA] ("Socco", "we", "us").

Questions, or want to exercise any of your rights? Write to privacy@socco.in.

Who can use Socco

Socco is only for people aged 18 and over who can verify a current employer email address. We do not knowingly collect data from children. If you believe a minor has created an account, write to us and we will remove it.

The short version on your work email

This is the question people ask first, so here it is up front. We ask for your work email once, to confirm you're a working professional. We send a six-digit code to it. Once you enter that code we convert the address into an irreversible keyed hash, store only that hash and your company's domain, and delete the address itself. We never send anything else to your work email — no marketing, no digests, no reminders. And your employer's name is never shown to anyone on Socco.

What we collect

Information you give us

DataWhy we need it
Work email addressTo verify you are a working professional. Hashed and deleted after one-time verification
Google or Apple account emailTo sign you in and to contact you about your account
Phone numberTo keep Socco to one account per person, and to power the SOS feature. Stored as a hash
Name and profile photoSo hosts and attendees know who is joining them
Date of birthTo confirm you are 18 or older. We display only an age range, never your exact age or birth date
Gender (optional)To operate women-only plans and show the mix of attendees
Interests and preferred areasTo show relevant plans instead of everything
Plans you create or join, and messages in plan group chatsTo run the core service
Photos you upload to a planTo display them to the people who attended that plan
Trusted contacts for SOSTo alert them if you use SOS
Reports you submit about other usersTo investigate safety issues

Information collected automatically

Information from verification partners

If you join as a partner or guest of a member, we ask for a phone number and a selfie, and in some cases an identity document checked by a third-party verification provider. We store the provider's result and reference, plus a one-way hash used to prevent banned users returning. We do not store Aadhaar numbers.

Why we use your data

What other people can see

This matters, so we're specific about it:

Reports are confidential. We never tell the person you reported who reported them.

Who we share data with

We do not sell your personal data, and we do not share it with advertisers. We share it only with:

Some providers may process or store data outside India. Where that happens, we take steps to ensure comparable protection.

How long we keep it

DataRetention
Work email address (plaintext)Deleted immediately after verification. Only an irreversible hash and the company domain remain
Account and profileUntil you delete your account
Plan group chat messagesDeleted shortly after the plan ends (typically 24 hours; longer for multi-day trips)
Plan photosUp to [30] days, or until removed by the uploader or the person pictured
Attendance and reliability recordsKept while your account exists, as they underpin trust between members
Safety reports, blocks, and verification hashesUp to [24] months after the event, so we can detect repeat offenders and enforce bans
Diagnostic and crash dataUp to [90] days

If you delete your account we remove your profile and content. We may retain a minimal safety record — for example a hashed identifier attached to a ban or an unresolved report — where we are permitted or required to. We keep only what is necessary and no longer than needed.

Your legal basis and your consent (DPDP Act)

Under India's Digital Personal Data Protection Act, 2023 we process your personal data on the basis of the consent you give when you create an account and accept these policies, and on the basis of legitimate uses permitted by the Act — including preventing fraud and responding to a threat to someone's safety.

You may withdraw your consent at any time by deleting your account (see Delete your data). Withdrawing consent does not affect processing already carried out, and we may retain the minimal safety records described below where the law permits or requires it.

We do not knowingly process the personal data of anyone under 18. Socco is an 18+ service, and we do not carry out behavioural tracking or targeted advertising directed at children.

Retention required by law (IT Rules 2021)

Socco is an intermediary under India's Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021. Those Rules require us to:

This means a small amount of data may survive account deletion. It is the minimum the law allows, it is not used for any other purpose, and it is deleted once the obligation ends.

If there is a data breach

If a breach affects your personal data we will notify you and the Data Protection Board of India as required by the DPDP Act, and tell you what happened, what data was involved, and what you should do.

Your rights

You can:

We aim to respond to requests within 30 days.

How we protect your data

Data is encrypted in transit. Access to production systems is limited to people who need it. Database access rules restrict every record to the people entitled to see it, and uploaded photos are stored in private storage rather than on the open internet. Work email addresses are hashed with a keyed function whose secret is never stored alongside the data. No system is perfectly secure, but if a breach affects your data we will notify you and the relevant authority as required by law.

Grievance officer

As required under Indian law, you may contact our grievance officer:

[NAME]
Grievance Officer, [LEGAL ENTITY NAME]
hello@socco.in
[FULL PHYSICAL ADDRESS, CITY, STATE, PIN — the IT Rules require this to be published]

We acknowledge complaints within 24 hours and aim to resolve them within 15 days.

Changes to this policy

If we make material changes we'll notify you in the app or by email before they take effect, and update the date at the top of this page.