Alphameet Innovate Private Limited
> DRAFT NOTE (remove before publishing): This is v1.1, revised to match the code/API as of July 2026. Text that changed from v1.0, and the reason, is listed in the companion file PRIVACY_POLICY_CHANGELOG_v1.1.md. Infrastructure is confirmed as DigitalOcean: compute in Bangalore (BLR1), India; managed database and object storage (Spaces bucket onemeet) in New York (NYC3), USA. Verification-selfie retention is confirmed: kept for the life of the account, deleted on account deletion (Clause 10). No open ⚠️ CONFIRM items remain; the remaining to-dos before publishing are the placeholders and the SOS-feature check noted in the changelog.
Before you use the OneMeet application, please read this Privacy Policy carefully. It explains what personal data we collect, why we collect it, how we use and share it, how long we retain it, and what rights you have.
We do not rely on a single, all-or-nothing consent. Some processing is necessary to provide you the core service you sign up for (for example, creating and securing your account); for this we rely on contractual necessity. Other processing is optional and is carried out only if you separately choose to allow it — for example, sharing your live location for premises-based discovery, undergoing the Verification Check, personalisation, and marketing communications. For each such optional purpose we ask for your specific, purpose-by-purpose consent at the point where the feature is first used, and you may withdraw consent for any one purpose independently without losing access to the rest of the service. The purposes and their legal bases are set out in Clause 6, and the granular consent and withdrawal mechanism is described in Clause 6A. Any consent you give is free, informed, specific, and unambiguous, and may be withdrawn at any time.
A summary of the key information you are entitled to as a Data Principal is as follows:
You may withdraw your consent — in whole, or for any individual purpose — at any time through the mechanisms described in Clauses 6A and 15. Withdrawing consent for one optional purpose does not withdraw it for others and does not affect processing carried out on a legal basis other than consent. Withdrawal of consent does not affect the lawfulness of processing carried out before such withdrawal.
OneMeet is a mobile application owned and operated by Alphameet Innovate Private Limited, a company incorporated under the Companies Act, 2013, having its registered office at C-1407, 14th Floor, Ardente Pine Grove, Rayasandra, Muthanallur, Bangalore South, Karnataka, India – 560099 (hereinafter referred to as 'the Company', 'we', 'us', or 'our').
OneMeet is a professional networking platform that enables verified adult professionals to discover other professionals present within a shared physical location or premises, send and accept in-person meeting requests, and also connect and communicate online through the application — including in-app text and media messaging and one-to-one voice and video calls. The Company is the Data Fiduciary in respect of all personal data collected through the application.
For any questions, concerns, or requests relating to this Privacy Policy or the processing of your personal data, please contact us at: hello@onemeet.co.in
This Privacy Policy applies to all users of the OneMeet mobile application and the associated website (used solely for application information and download redirection). It governs all personal data collected, processed, stored, or disclosed by the Company in connection with your use of our services.
This Policy is to be read in conjunction with our Terms of Use and any other applicable policies or agreements that govern your use of the OneMeet application. This Policy applies to users located in India. Please note that, as described in Clauses 11 and 12, some of your data is stored and processed on servers located outside India (in the United States).
For the purposes of this Policy, the following terms shall have the meanings ascribed to them below:
We collect the following categories of personal data when you register, create a profile, and use the OneMeet application:
Professional certifications, LinkedIn profiles, and other external professional identifiers are not collected. Professional information you provide is visible to other users as described in Clause 8.
Location data is core to the functionality of the OneMeet application. See Clause 9 for full details on how location and presence data are collected, shared, and used, including our limited use of a foreground service to reliably update your presence.
The application requests the following device permissions. Each is requested on your device and may be revoked by you at any time through your device settings; revocation may affect certain features.
The associated website used for app information and download redirection does not independently collect user data.
As part of the Verification Check (Clause 10) you capture a live selfie. This image is processed to confirm that a genuine human face is present and, where enabled, that it is front-facing and centred. Please read Clause 10 for full detail on how this image is used, whether it is retained, and your controls over it.
The following data is expressly not collected by OneMeet at this time:
Users are expressly warned against sharing sensitive financial, health-related, or government identity information through the in-app messaging feature. The Company is not liable for any harm arising from a user's voluntary disclosure of such information through the messaging system.
We process your personal data only for specific, lawful purposes:
| Processing Activity | Legal Basis |
|---|---|
| Account creation, authentication (Google or OTP), and management | Contractual necessity |
| Verification Check (confirming a genuine face is present) | Consent / Legitimate use — platform safety and authenticity |
| Enabling location-based professional discovery within a Premises | Consent — you expressly opt in to location sharing and visibility |
| Facilitating in-person Meeting Requests | Contractual necessity / Consent — core service feature |
| In-app messaging, media sharing, voice/video calling, and online networking | Contractual necessity — communication features of the service |
| Post-meeting ratings | Legitimate use — safety, trust, and moderation |
| Professional profile visibility to connections and co-located users | Consent — you choose what information to include in your profile |
| Push notifications and delivery to your device | Contractual necessity / Consent |
| Customer support, reporting, and grievance redressal | Contractual necessity / Legal obligation |
| Personalisation of content and discovery | Consent |
| Marketing and promotional communications | Consent — you may opt out at any time |
| Analytics and platform performance tracking | Legitimate use |
| Legal and regulatory compliance | Legal obligation |
| Fraud prevention, security, and platform safety | Legitimate use |
| Human moderation of content and user behaviour | Legitimate use |
| Safety escalation and response to reports | Consent / Legitimate use — physical safety of users |
Where the legal basis above is stated as Consent, that processing is optional and is carried out only with your specific, separately-obtained consent for that purpose, as described in Clause 6A. Where it is stated as Contractual necessity, the processing is required to provide the service you have asked for; declining it means we cannot provide that part of the service. Where it is stated as Legitimate use, we rely on the corresponding ground under the DPDPA and do not require separate consent, but you retain the rights set out in Clause 15.
We ask for your consent separately for each optional (consent-based) purpose, rather than as a single bundled agreement. This means:
A summary of the controls available for each optional purpose:
| Optional (consent-based) purpose | How to give / withdraw consent |
|---|---|
| Location sharing for premises discovery | Grant/deny at first use; toggle location or presence off in-app; revoke OS location permission |
| Premise-level visibility (public vs premise-only) | Choose per your preference in-app; change at any time |
| Verification Check (selfie) | Prompted at verification; you may decline; request removal via Grievance Officer |
| Personalisation of content and discovery | Manage in app settings |
| Marketing communications (email/SMS/WhatsApp/push) | Opt in on request; opt out via unsubscribe in any message or app settings |
The OneMeet application is strictly intended for use by individuals who are 18 years of age or older. We do not knowingly collect personal data from individuals under the age of 18.
At the time of registration you are required to confirm that you are 18 years of age or older, and you provide your age as part of profile setup. Because sign-in may be completed via email or mobile OTP (and Google does not supply verified age to us), age is a self-declared field. The Company shall not be liable for any misrepresentation of age made by a user.
If we become aware or have reasonable grounds to believe that a user is under the age of 18, we will suspend and delete the relevant account and all associated personal data. If you become aware of any account held by a minor, please notify us at hello@onemeet.co.in.
Your professional profile — name, professional details, profile photograph, bio, skills, goals, hobbies, and languages — is visible to:
Your profile is not publicly accessible to all users of the application. Where you set your premise visibility to "premise only", users outside your Premises who are not your connections may see limited or restricted profile information only.
When you send a Meeting Request to another user within the same Premises, your profile — name, professional details, and profile photograph — is shared with that user so they can decide whether to accept.
Networking/follow Requests may be sent to users on the platform. Upon acceptance, both users' profiles become mutually visible as connections.
Once you are connected or have an accepted Meeting Request, you may exchange text and media messages and place voice/video calls. Content you send (including images and videos) is shared with the recipient. You are advised not to share sensitive personal or financial information.
After a meeting, you may submit a private 1–5 star rating and an optional note about the other user. Ratings and notes are used for internal safety and moderation purposes only and are never shown to the user who was rated or to any other user.
You are solely responsible for the accuracy and appropriateness of the information you include in your profile and content. The Company does not independently verify professional information you provide.
Location data is the foundational feature of OneMeet. We collect and use your location data only with your specific consent to this purpose, which we request separately (through the OS permission prompt and an in-app explanation) before location is first accessed — not as part of a general acceptance of this Policy. Granting location consent is optional; if you decline it, location-based discovery is disabled but you may continue to use other parts of the application. You may withdraw your consent to location sharing at any time, independently of any other consent, as described in Clauses 6A and 15.
Location data is collected: (a) while the application is open or running in the foreground; and (b) when you check in to a Premises or activate a session.
We request foreground location only — we do not request "allow all the time" background location tracking. To make presence reliable (for example, to check you out of a Premises promptly when you leave or close the app), the application may run a short-lived foreground service. This service is used solely to maintain and correctly end your presence at a Premises; it is not used to track your movements when you are not using the app.
Location sharing is opt-in and requires you to grant location permission. You may grant or deny this permission through your device settings at any time.
Other users within the same Premises can see that you are present at that Premises (subject to your visibility preference), at the level of approximate area and premises-level location. Exact GPS coordinates are used to determine presence but are not directly displayed to other users.
Location and presence data is retained for the duration of your active account. Location history and past check-in records are retained as part of your account data. Upon account deletion, location data is deleted in accordance with Clause 13.
Your precise location data is not shared with any third party for commercial, advertising, or profiling purposes. Location data is processed by Google Maps SDK solely to enable the Premises-based discovery feature.
To help keep OneMeet authentic and safe, the application asks you to complete a Verification Check: you capture a live selfie using your device camera. This clause explains how that image is handled.
We do not sell, rent, or trade your personal data to any third party. We share your data only in the following circumstances:
As described in Clause 8.
Our infrastructure is operated on DigitalOcean. Specifically:
DigitalOcean processes this data on our behalf as a data processor and is contractually and technically bound to protect it. DigitalOcean's privacy practices are available at https://www.digitalocean.com/legal/privacy-policy. Because parts of our infrastructure are located in the United States, some of your personal data is stored and processed outside India — see Clause 12.
We use Google Authentication for optional user sign-in and Google Maps SDK for location services. Google's data practices are governed by https://policies.google.com/privacy.
We use Fast2SMS to deliver one-time passwords and transactional SMS. Your mobile number is shared with this provider solely for message delivery.
We use SendGrid (a Twilio service) to send one-time passwords and transactional emails. Your email address is shared solely for message delivery.
We use Firebase Cloud Messaging (a Google service) to deliver push notifications. Your push token and associated device identifier are processed for this purpose, subject to Google's Privacy Policy.
Voice and video calls use standard WebRTC connectivity, which relies on public STUN servers (currently operated by Google) to help establish a direct peer-to-peer connection. Call audio/video is not routed through or stored by us; only call metadata (Clause 4.5(c)) is stored.
Our support and human moderation team may access user-generated content, interaction records, reports, ratings, and profile information to enforce community standards, review reports, and respond to safety concerns. When you contact support or file a report from within the app, the app may open your email or WhatsApp client pre-filled with your message and basic diagnostic details (your user ID and username, app version, device brand/model and OS version, and, for a report, the ID of the user, post, or story being reported). Support communications sent this way are delivered to us by email or via WhatsApp.
We may disclose your personal data to government authorities, law enforcement, courts, or regulators where legally required under applicable Indian law. We will, to the extent permitted by law, notify you of any such disclosure.
In the event of a merger, acquisition, restructuring, or sale of assets, your personal data may be transferred to the successor entity, subject to the protections in this Policy. You will be notified.
Some of your personal data is stored and processed outside India. In particular, our managed database and our object storage (images, videos, and verification selfies) are hosted in the United States (DigitalOcean, New York / NYC3 region), while our application compute is located in India (DigitalOcean, Bangalore / BLR1). By using the application and providing your consent, you acknowledge and consent to the transfer, storage, and processing of your personal data in the United States for the purposes described in this Policy. We take reasonable steps to ensure your data continues to be protected in accordance with this Policy and applicable law wherever it is processed.
To the extent that any additional data transfer occurs as a result of our use of Google services (Google Authentication, Google Maps, Firebase Cloud Messaging) or our SMS/email providers, such transfer is governed by those providers' own data-transfer mechanisms and privacy commitments.
We retain your personal data for as long as your account is active and as necessary to fulfil the purposes for which it was collected, or as required by applicable law. Specifically:
Upon deletion of your account, your data is handled per Clause 14.
You may delete your OneMeet account at any time through the account settings section of the application. Upon initiating deletion:
To request deletion outside the in-app process, contact our Grievance Officer (Clause 23).
As a Data Principal under the DPDPA, 2023, you have the following rights:
15.1 Right to Access — via your profile page and account settings. 15.2 Right to Correction — via your profile settings. 15.3 Right to Erasure — via account deletion (Clause 14). 15.4 Right to Withdraw Consent (per purpose) — you may withdraw consent for any individual consent-based purpose, independently of the others, without losing access to the rest of the service (see Clause 6A). You may do so by: (a) using the relevant in-app control (e.g., turning off location or presence visibility, disabling personalisation, or unsubscribing from marketing); (b) deleting data via profile settings; (c) contacting customer care to generate a Service Request Number (SRN); or (d) writing to our Grievance Officer (Clause 23). Withdrawing consent for a purpose disables the feature that depends on it (for example, withdrawing location consent deactivates location-based features) but does not by itself terminate your account. Only where you withdraw consent to — or otherwise object to — processing that is strictly necessary to provide the core service (contractual necessity) may we be unable to continue providing the account. Withdrawal does not affect prior lawful processing. 15.5 Right to Object to Marketing — via the unsubscribe option in marketing communications or by contacting our Grievance Officer. 15.6 Right to Nominate — you may nominate another individual to exercise your rights in the event of death or incapacity; contact our Grievance Officer. 15.7 Right to Approach the Data Protection Board — if unsatisfied with our response.
Given the real-world meeting-facilitation nature of OneMeet, we provide:
If you encounter a safety concern outside the in-app mechanisms, contact us at hello@onemeet.co.in or on our support channels.
We implement technical and organisational measures to protect your data, including:
Our infrastructure is hosted on DigitalOcean (compute in Bangalore, India; managed database and object storage in New York, USA), which provides encryption of data at rest for its managed database and Spaces object storage.
No system of data transmission or storage can be guaranteed completely secure. You use the application at your own risk and are encouraged not to share sensitive information through the messaging system.
The OneMeet mobile application does not use cookies. Within the application, certain technical data (usage analytics and crash reports) is collected automatically through application telemetry, not through cookies or browser tracking.
Marketing is a separate, optional purpose. We send you promotional communications via email, SMS, WhatsApp, push notifications, or in-app notifications only if you have given consent for marketing specifically, and your access to the service is not conditioned on giving that consent (Clause 6A). All marketing communications include an opt-out mechanism, and you may withdraw marketing consent at any time — independently of any other consent — via the unsubscribe option in any message or in app settings. Opting out of marketing does not affect transactional or service-related communications (account notifications, OTPs, security alerts, meeting/call notifications) that are necessary to provide the service.
| Service | Purpose | Privacy Policy Reference |
|---|---|---|
| Google Authentication | Optional user sign-in | https://policies.google.com/privacy |
| Google Maps SDK | Location and Premises-based discovery | https://policies.google.com/privacy |
| Firebase Cloud Messaging (Google) | Push notification delivery | https://policies.google.com/privacy |
| Google STUN servers | Voice/video call connectivity (WebRTC) | https://policies.google.com/privacy |
| DigitalOcean (compute BLR1 India; managed DB + Spaces object storage NYC3 USA) | Cloud hosting and data storage | https://www.digitalocean.com/legal/privacy-policy |
| Fast2SMS | SMS / OTP delivery | https://www.fast2sms.com/privacy-policy |
| SendGrid (Twilio) | Email / OTP delivery | https://www.twilio.com/en-us/legal/privacy |
| WhatsApp (Meta) | Optional support/report channel (opened on your device) | https://www.whatsapp.com/legal/privacy-policy |
We are not responsible for the privacy practices of these third-party services. We encourage you to review their privacy policies.
In the event of a personal data breach likely to result in harm to your rights and interests, the Company will notify the Data Protection Board of India (once constituted and operational) as prescribed under the DPDPA, 2023, and notify affected users in a clear and transparent manner via email, in-app notification, push notification, or a prominent notice on the application.
OneMeet does not use automated algorithms or artificial intelligence to rank or match users for discovery — discovery within a Premises is based on the user's own choices.
The Verification Check may apply an automated facial-presence detection step (Clause 10) to confirm a genuine face is present before a profile is marked verified; where this could affect access, it is subject to human review, and it does not perform biometric identity matching between users. No account suspension or access restriction is applied without human review. No user data is used to train artificial intelligence or machine-learning models.
In accordance with the Information Technology Act, 2000, the SPDI Rules, 2011, and the DPDPA, 2023, the Company has appointed a Grievance Officer.
| Name | Mr. Kodavalli Anudeep Joshua Joel |
| Designation | Operations Manager / Grievance Officer |
| Email Address | Support@onemeet.co.in |
| Correspondence Address | C-1407, 14th Floor, Ardente Pine Grove, Rayasandra, Muthanallur, Bangalore South, Karnataka, India – 560099 |
The Grievance Officer shall acknowledge your complaint within 24 hours and endeavour to resolve it within 30 days. If dissatisfied, you may approach the Data Protection Board of India (Clause 15.7).
We may update this Privacy Policy from time to time. When we make material changes, we will notify you via email, in-app notice, push notification, and/or a pop-up upon your next login. The updated Policy will indicate the revised effective date. Continued use after notification constitutes acceptance; if you do not agree, you must discontinue use and may delete your account.
This Privacy Policy is governed by the laws of India, including the Information Technology Act, 2000, the SPDI Rules, 2011, and the DPDPA, 2023. Disputes are subject to the exclusive jurisdiction of the competent courts in Bangalore, Karnataka, India.
Alphameet Innovate Private Limited C-1407, 14th Floor, Ardente Pine Grove, Rayasandra, Muthanallur, Bangalore South, Karnataka, India – 560099 Email: hello@onemeet.co.in Grievance Officer Email: Support@onemeet.co.in