PRIVACY POLICY

OneMeet Application
Effective Date: 15/07/2026  |  Version: 1.1

Alphameet Innovate Private Limited

> DRAFT NOTE (remove before publishing): This is v1.1, revised to match the code/API as of July 2026. Text that changed from v1.0, and the reason, is listed in the companion file PRIVACY_POLICY_CHANGELOG_v1.1.md. Infrastructure is confirmed as DigitalOcean: compute in Bangalore (BLR1), India; managed database and object storage (Spaces bucket onemeet) in New York (NYC3), USA. Verification-selfie retention is confirmed: kept for the life of the account, deleted on account deletion (Clause 10). No open ⚠️ CONFIRM items remain; the remaining to-dos before publishing are the placeholders and the SOS-feature check noted in the changelog.

NOTICE UNDER THE DIGITAL PERSONAL DATA PROTECTION ACT, 2023

Before you use the OneMeet application, please read this Privacy Policy carefully. It explains what personal data we collect, why we collect it, how we use and share it, how long we retain it, and what rights you have.

We do not rely on a single, all-or-nothing consent. Some processing is necessary to provide you the core service you sign up for (for example, creating and securing your account); for this we rely on contractual necessity. Other processing is optional and is carried out only if you separately choose to allow it — for example, sharing your live location for premises-based discovery, undergoing the Verification Check, personalisation, and marketing communications. For each such optional purpose we ask for your specific, purpose-by-purpose consent at the point where the feature is first used, and you may withdraw consent for any one purpose independently without losing access to the rest of the service. The purposes and their legal bases are set out in Clause 6, and the granular consent and withdrawal mechanism is described in Clause 6A. Any consent you give is free, informed, specific, and unambiguous, and may be withdrawn at any time.

A summary of the key information you are entitled to as a Data Principal is as follows:

You may withdraw your consent — in whole, or for any individual purpose — at any time through the mechanisms described in Clauses 6A and 15. Withdrawing consent for one optional purpose does not withdraw it for others and does not affect processing carried out on a legal basis other than consent. Withdrawal of consent does not affect the lawfulness of processing carried out before such withdrawal.

1. About Us

OneMeet is a mobile application owned and operated by Alphameet Innovate Private Limited, a company incorporated under the Companies Act, 2013, having its registered office at C-1407, 14th Floor, Ardente Pine Grove, Rayasandra, Muthanallur, Bangalore South, Karnataka, India – 560099 (hereinafter referred to as 'the Company', 'we', 'us', or 'our').

OneMeet is a professional networking platform that enables verified adult professionals to discover other professionals present within a shared physical location or premises, send and accept in-person meeting requests, and also connect and communicate online through the application — including in-app text and media messaging and one-to-one voice and video calls. The Company is the Data Fiduciary in respect of all personal data collected through the application.

For any questions, concerns, or requests relating to this Privacy Policy or the processing of your personal data, please contact us at: hello@onemeet.co.in

2. Scope and Applicability

This Privacy Policy applies to all users of the OneMeet mobile application and the associated website (used solely for application information and download redirection). It governs all personal data collected, processed, stored, or disclosed by the Company in connection with your use of our services.

This Policy is to be read in conjunction with our Terms of Use and any other applicable policies or agreements that govern your use of the OneMeet application. This Policy applies to users located in India. Please note that, as described in Clauses 11 and 12, some of your data is stored and processed on servers located outside India (in the United States).

3. Definitions

For the purposes of this Policy, the following terms shall have the meanings ascribed to them below:

4. Personal Data We Collect

We collect the following categories of personal data when you register, create a profile, and use the OneMeet application:

4.1 Account and Basic Information

Note on age and gender: OneMeet supports two sign-in methods — Google Sign-In and email/mobile OTP. Age and gender are provided by you as part of profile setup; they are not obtained from Google. See Clause 7 for how we apply our 18+ age restriction.

4.2 Professional Information

Professional certifications, LinkedIn profiles, and other external professional identifiers are not collected. Professional information you provide is visible to other users as described in Clause 8.

4.3 Location and Presence Data

Location data is core to the functionality of the OneMeet application. See Clause 9 for full details on how location and presence data are collected, shared, and used, including our limited use of a foreground service to reliably update your presence.

4.4 Device Permissions and Media

The application requests the following device permissions. Each is requested on your device and may be revoked by you at any time through your device settings; revocation may affect certain features.

4.5 Interaction and Activity Data

4.6 Technical and Device Data

The associated website used for app information and download redirection does not independently collect user data.

4.7 User-Generated Content

4.8 Verification Selfie (Biometric-Adjacent Data)

As part of the Verification Check (Clause 10) you capture a live selfie. This image is processed to confirm that a genuine human face is present and, where enabled, that it is front-facing and centred. Please read Clause 10 for full detail on how this image is used, whether it is retained, and your controls over it.

4.9 Data NOT Collected

The following data is expressly not collected by OneMeet at this time:

Users are expressly warned against sharing sensitive financial, health-related, or government identity information through the in-app messaging feature. The Company is not liable for any harm arising from a user's voluntary disclosure of such information through the messaging system.

5. How We Collect Personal Data

6. Purpose of Data Collection and Legal Basis

We process your personal data only for specific, lawful purposes:

Processing ActivityLegal Basis
Account creation, authentication (Google or OTP), and managementContractual necessity
Verification Check (confirming a genuine face is present)Consent / Legitimate use — platform safety and authenticity
Enabling location-based professional discovery within a PremisesConsent — you expressly opt in to location sharing and visibility
Facilitating in-person Meeting RequestsContractual necessity / Consent — core service feature
In-app messaging, media sharing, voice/video calling, and online networkingContractual necessity — communication features of the service
Post-meeting ratingsLegitimate use — safety, trust, and moderation
Professional profile visibility to connections and co-located usersConsent — you choose what information to include in your profile
Push notifications and delivery to your deviceContractual necessity / Consent
Customer support, reporting, and grievance redressalContractual necessity / Legal obligation
Personalisation of content and discoveryConsent
Marketing and promotional communicationsConsent — you may opt out at any time
Analytics and platform performance trackingLegitimate use
Legal and regulatory complianceLegal obligation
Fraud prevention, security, and platform safetyLegitimate use
Human moderation of content and user behaviourLegitimate use
Safety escalation and response to reportsConsent / Legitimate use — physical safety of users

Where the legal basis above is stated as Consent, that processing is optional and is carried out only with your specific, separately-obtained consent for that purpose, as described in Clause 6A. Where it is stated as Contractual necessity, the processing is required to provide the service you have asked for; declining it means we cannot provide that part of the service. Where it is stated as Legitimate use, we rely on the corresponding ground under the DPDPA and do not require separate consent, but you retain the rights set out in Clause 15.

6A. Granular Consent and How to Manage It

We ask for your consent separately for each optional (consent-based) purpose, rather than as a single bundled agreement. This means:

A summary of the controls available for each optional purpose:

Optional (consent-based) purposeHow to give / withdraw consent
Location sharing for premises discoveryGrant/deny at first use; toggle location or presence off in-app; revoke OS location permission
Premise-level visibility (public vs premise-only)Choose per your preference in-app; change at any time
Verification Check (selfie)Prompted at verification; you may decline; request removal via Grievance Officer
Personalisation of content and discoveryManage in app settings
Marketing communications (email/SMS/WhatsApp/push)Opt in on request; opt out via unsubscribe in any message or app settings

7. Age Restriction and Protection of Minors

The OneMeet application is strictly intended for use by individuals who are 18 years of age or older. We do not knowingly collect personal data from individuals under the age of 18.

At the time of registration you are required to confirm that you are 18 years of age or older, and you provide your age as part of profile setup. Because sign-in may be completed via email or mobile OTP (and Google does not supply verified age to us), age is a self-declared field. The Company shall not be liable for any misrepresentation of age made by a user.

If we become aware or have reasonable grounds to believe that a user is under the age of 18, we will suspend and delete the relevant account and all associated personal data. If you become aware of any account held by a minor, please notify us at hello@onemeet.co.in.

8. Profile Visibility and Data Shared with Other Users

8.1 General Profile Visibility

Your professional profile — name, professional details, profile photograph, bio, skills, goals, hobbies, and languages — is visible to:

Your profile is not publicly accessible to all users of the application. Where you set your premise visibility to "premise only", users outside your Premises who are not your connections may see limited or restricted profile information only.

8.2 Meeting Requests (In-Person)

When you send a Meeting Request to another user within the same Premises, your profile — name, professional details, and profile photograph — is shared with that user so they can decide whether to accept.

8.3 Networking / Follow Requests (Online)

Networking/follow Requests may be sent to users on the platform. Upon acceptance, both users' profiles become mutually visible as connections.

8.4 Messaging and Calling

Once you are connected or have an accepted Meeting Request, you may exchange text and media messages and place voice/video calls. Content you send (including images and videos) is shared with the recipient. You are advised not to share sensitive personal or financial information.

8.5 Post-Meeting Ratings

After a meeting, you may submit a private 1–5 star rating and an optional note about the other user. Ratings and notes are used for internal safety and moderation purposes only and are never shown to the user who was rated or to any other user.

8.6 User Responsibility

You are solely responsible for the accuracy and appropriateness of the information you include in your profile and content. The Company does not independently verify professional information you provide.

9. Location and Presence Data — Detailed Disclosure

Location data is the foundational feature of OneMeet. We collect and use your location data only with your specific consent to this purpose, which we request separately (through the OS permission prompt and an in-app explanation) before location is first accessed — not as part of a general acceptance of this Policy. Granting location consent is optional; if you decline it, location-based discovery is disabled but you may continue to use other parts of the application. You may withdraw your consent to location sharing at any time, independently of any other consent, as described in Clauses 6A and 15.

9.1 How Location is Collected

Location data is collected: (a) while the application is open or running in the foreground; and (b) when you check in to a Premises or activate a session.

We request foreground location only — we do not request "allow all the time" background location tracking. To make presence reliable (for example, to check you out of a Premises promptly when you leave or close the app), the application may run a short-lived foreground service. This service is used solely to maintain and correctly end your presence at a Premises; it is not used to track your movements when you are not using the app.

9.2 Location Sharing — Opt-In

Location sharing is opt-in and requires you to grant location permission. You may grant or deny this permission through your device settings at any time.

9.3 What Other Users Can See

Other users within the same Premises can see that you are present at that Premises (subject to your visibility preference), at the level of approximate area and premises-level location. Exact GPS coordinates are used to determine presence but are not directly displayed to other users.

9.4 User Controls Over Location Visibility

9.5 Retention of Location Data

Location and presence data is retained for the duration of your active account. Location history and past check-in records are retained as part of your account data. Upon account deletion, location data is deleted in accordance with Clause 13.

9.6 Location Data and Third Parties

Your precise location data is not shared with any third party for commercial, advertising, or profiling purposes. Location data is processed by Google Maps SDK solely to enable the Premises-based discovery feature.

10. Verification Check and the Verification Selfie

To help keep OneMeet authentic and safe, the application asks you to complete a Verification Check: you capture a live selfie using your device camera. This clause explains how that image is handled.

11. Data Sharing and Disclosure

We do not sell, rent, or trade your personal data to any third party. We share your data only in the following circumstances:

11.1 With Other Users of the Platform

As described in Clause 8.

11.2 With Cloud and Storage Providers

Our infrastructure is operated on DigitalOcean. Specifically:

DigitalOcean processes this data on our behalf as a data processor and is contractually and technically bound to protect it. DigitalOcean's privacy practices are available at https://www.digitalocean.com/legal/privacy-policy. Because parts of our infrastructure are located in the United States, some of your personal data is stored and processed outside India — see Clause 12.

11.3 With Google (Sign-In and Maps)

We use Google Authentication for optional user sign-in and Google Maps SDK for location services. Google's data practices are governed by https://policies.google.com/privacy.

11.4 With Our SMS Provider

We use Fast2SMS to deliver one-time passwords and transactional SMS. Your mobile number is shared with this provider solely for message delivery.

11.5 With Our Email Provider

We use SendGrid (a Twilio service) to send one-time passwords and transactional emails. Your email address is shared solely for message delivery.

11.6 With Google / Firebase Cloud Messaging

We use Firebase Cloud Messaging (a Google service) to deliver push notifications. Your push token and associated device identifier are processed for this purpose, subject to Google's Privacy Policy.

11.7 Voice/Video Call Connectivity

Voice and video calls use standard WebRTC connectivity, which relies on public STUN servers (currently operated by Google) to help establish a direct peer-to-peer connection. Call audio/video is not routed through or stored by us; only call metadata (Clause 4.5(c)) is stored.

11.8 With Human Moderators and Support

Our support and human moderation team may access user-generated content, interaction records, reports, ratings, and profile information to enforce community standards, review reports, and respond to safety concerns. When you contact support or file a report from within the app, the app may open your email or WhatsApp client pre-filled with your message and basic diagnostic details (your user ID and username, app version, device brand/model and OS version, and, for a report, the ID of the user, post, or story being reported). Support communications sent this way are delivered to us by email or via WhatsApp.

11.9 With Law Enforcement and Legal Authorities

We may disclose your personal data to government authorities, law enforcement, courts, or regulators where legally required under applicable Indian law. We will, to the extent permitted by law, notify you of any such disclosure.

11.10 Business Transfers

In the event of a merger, acquisition, restructuring, or sale of assets, your personal data may be transferred to the successor entity, subject to the protections in this Policy. You will be notified.

12. Cross-Border Data Transfer

Some of your personal data is stored and processed outside India. In particular, our managed database and our object storage (images, videos, and verification selfies) are hosted in the United States (DigitalOcean, New York / NYC3 region), while our application compute is located in India (DigitalOcean, Bangalore / BLR1). By using the application and providing your consent, you acknowledge and consent to the transfer, storage, and processing of your personal data in the United States for the purposes described in this Policy. We take reasonable steps to ensure your data continues to be protected in accordance with this Policy and applicable law wherever it is processed.

To the extent that any additional data transfer occurs as a result of our use of Google services (Google Authentication, Google Maps, Firebase Cloud Messaging) or our SMS/email providers, such transfer is governed by those providers' own data-transfer mechanisms and privacy commitments.

13. Data Retention

We retain your personal data for as long as your account is active and as necessary to fulfil the purposes for which it was collected, or as required by applicable law. Specifically:

Upon deletion of your account, your data is handled per Clause 14.

14. Account Deletion and Data Purge

You may delete your OneMeet account at any time through the account settings section of the application. Upon initiating deletion:

To request deletion outside the in-app process, contact our Grievance Officer (Clause 23).

15. Your Rights and Withdrawal of Consent

As a Data Principal under the DPDPA, 2023, you have the following rights:

15.1 Right to Access — via your profile page and account settings. 15.2 Right to Correction — via your profile settings. 15.3 Right to Erasure — via account deletion (Clause 14). 15.4 Right to Withdraw Consent (per purpose) — you may withdraw consent for any individual consent-based purpose, independently of the others, without losing access to the rest of the service (see Clause 6A). You may do so by: (a) using the relevant in-app control (e.g., turning off location or presence visibility, disabling personalisation, or unsubscribing from marketing); (b) deleting data via profile settings; (c) contacting customer care to generate a Service Request Number (SRN); or (d) writing to our Grievance Officer (Clause 23). Withdrawing consent for a purpose disables the feature that depends on it (for example, withdrawing location consent deactivates location-based features) but does not by itself terminate your account. Only where you withdraw consent to — or otherwise object to — processing that is strictly necessary to provide the core service (contractual necessity) may we be unable to continue providing the account. Withdrawal does not affect prior lawful processing. 15.5 Right to Object to Marketing — via the unsubscribe option in marketing communications or by contacting our Grievance Officer. 15.6 Right to Nominate — you may nominate another individual to exercise your rights in the event of death or incapacity; contact our Grievance Officer. 15.7 Right to Approach the Data Protection Board — if unsatisfied with our response.

16. Safety, Reporting, and Escalation

Given the real-world meeting-facilitation nature of OneMeet, we provide:

If you encounter a safety concern outside the in-app mechanisms, contact us at hello@onemeet.co.in or on our support channels.

17. Security Measures

We implement technical and organisational measures to protect your data, including:

Our infrastructure is hosted on DigitalOcean (compute in Bangalore, India; managed database and object storage in New York, USA), which provides encryption of data at rest for its managed database and Spaces object storage.

No system of data transmission or storage can be guaranteed completely secure. You use the application at your own risk and are encouraged not to share sensitive information through the messaging system.

18. Cookies and Tracking Technologies

The OneMeet mobile application does not use cookies. Within the application, certain technical data (usage analytics and crash reports) is collected automatically through application telemetry, not through cookies or browser tracking.

19. Marketing and Communications

Marketing is a separate, optional purpose. We send you promotional communications via email, SMS, WhatsApp, push notifications, or in-app notifications only if you have given consent for marketing specifically, and your access to the service is not conditioned on giving that consent (Clause 6A). All marketing communications include an opt-out mechanism, and you may withdraw marketing consent at any time — independently of any other consent — via the unsubscribe option in any message or in app settings. Opting out of marketing does not affect transactional or service-related communications (account notifications, OTPs, security alerts, meeting/call notifications) that are necessary to provide the service.

20. Third-Party Services and Integrations

ServicePurposePrivacy Policy Reference
Google AuthenticationOptional user sign-inhttps://policies.google.com/privacy
Google Maps SDKLocation and Premises-based discoveryhttps://policies.google.com/privacy
Firebase Cloud Messaging (Google)Push notification deliveryhttps://policies.google.com/privacy
Google STUN serversVoice/video call connectivity (WebRTC)https://policies.google.com/privacy
DigitalOcean (compute BLR1 India; managed DB + Spaces object storage NYC3 USA)Cloud hosting and data storagehttps://www.digitalocean.com/legal/privacy-policy
Fast2SMSSMS / OTP deliveryhttps://www.fast2sms.com/privacy-policy
SendGrid (Twilio)Email / OTP deliveryhttps://www.twilio.com/en-us/legal/privacy
WhatsApp (Meta)Optional support/report channel (opened on your device)https://www.whatsapp.com/legal/privacy-policy

We are not responsible for the privacy practices of these third-party services. We encourage you to review their privacy policies.

21. Personal Data Breach Notification

In the event of a personal data breach likely to result in harm to your rights and interests, the Company will notify the Data Protection Board of India (once constituted and operational) as prescribed under the DPDPA, 2023, and notify affected users in a clear and transparent manner via email, in-app notification, push notification, or a prominent notice on the application.

22. Automated Decision-Making

OneMeet does not use automated algorithms or artificial intelligence to rank or match users for discovery — discovery within a Premises is based on the user's own choices.

The Verification Check may apply an automated facial-presence detection step (Clause 10) to confirm a genuine face is present before a profile is marked verified; where this could affect access, it is subject to human review, and it does not perform biometric identity matching between users. No account suspension or access restriction is applied without human review. No user data is used to train artificial intelligence or machine-learning models.

23. Grievance Officer and Redressal Mechanism

In accordance with the Information Technology Act, 2000, the SPDI Rules, 2011, and the DPDPA, 2023, the Company has appointed a Grievance Officer.

NameMr. Kodavalli Anudeep Joshua Joel
DesignationOperations Manager / Grievance Officer
Email AddressSupport@onemeet.co.in
Correspondence AddressC-1407, 14th Floor, Ardente Pine Grove, Rayasandra, Muthanallur, Bangalore South, Karnataka, India – 560099

The Grievance Officer shall acknowledge your complaint within 24 hours and endeavour to resolve it within 30 days. If dissatisfied, you may approach the Data Protection Board of India (Clause 15.7).

24. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you via email, in-app notice, push notification, and/or a pop-up upon your next login. The updated Policy will indicate the revised effective date. Continued use after notification constitutes acceptance; if you do not agree, you must discontinue use and may delete your account.

25. Governing Law and Jurisdiction

This Privacy Policy is governed by the laws of India, including the Information Technology Act, 2000, the SPDI Rules, 2011, and the DPDPA, 2023. Disputes are subject to the exclusive jurisdiction of the competent courts in Bangalore, Karnataka, India.

26. Contact Us

Alphameet Innovate Private Limited C-1407, 14th Floor, Ardente Pine Grove, Rayasandra, Muthanallur, Bangalore South, Karnataka, India – 560099 Email: hello@onemeet.co.in Grievance Officer Email: Support@onemeet.co.in