Our Core Privacy Principles
These four principles guide every product decision we make about data.
Minimal Data Collection
We only collect data you choose to share. We do not track, infer, or buy data about you from third parties.
You Control Visibility
Every piece of information you share has a visibility setting. You decide who sees it — just family, just community, or public.
Data Stored in India
All your data is stored on servers physically located in India, compliant with DPDP Act 2023 and IT Act 2000 requirements.
No Selling of Data
We have never sold user data and never will. Your community membership information is sacred. We treat it that way.
What Data We Collect and Why
We collect only what is needed. Here is a clear breakdown of every category of data we hold, and the legal basis for holding it.
Account Information
Contractual necessity- Name, mobile number, email
- Profile photo (optional)
- Community identifiers (surname, gotra, native village)
Purpose: To create and maintain your account on the platform.
Matrimony Data
Explicit consent (opt-in only)- Horoscope, education, income range (optional)
- Family background
- Partner preferences
Purpose: To match you with compatible matrimonial profiles in the community.
Professional & Business Data
Explicit consent (opt-in only)- Employment history, skills, resume
- Business name, address, services
Purpose: To help you find jobs or display your business to community members.
Usage & Activity Data
Legitimate interest (anonymised analytics)- Pages visited, features used
- Search queries within the platform
- Notification preferences
Purpose: To improve platform performance and personalise your experience.
Payment Data
Contractual necessity- Donation transaction records
- UPI ID or card type (not full card number)
- Payment status
Purpose: To process your donations and provide 80G receipts.
Your Rights Under DPDP Act 2023
The Digital Personal Data Protection Act 2023 gives you strong rights over your personal data. We honour all of them.
Right to Access
You can request a full copy of all data we hold about you at any time. We will provide it within 30 days, free of charge.
How to exercise: Go to Settings → Privacy → Download My Data
Right to Correction
If any information we hold is incorrect, you have the right to correct it immediately through your profile settings.
How to exercise: Profile → Edit Profile → Update any field
Right to Deletion (Right to Be Forgotten)
You can request complete deletion of your account and all associated data. We will process this within 30 days.
How to exercise: Settings → Account → Delete Account → Confirm
Right to Withdraw Consent
You can withdraw consent for any specific use of your data (e.g., matrimony visibility, business directory listing) without deleting your account.
How to exercise: Settings → Privacy → Manage Consents
Right to Grievance
If you believe your privacy rights have been violated, you can file a complaint with our Data Protection Officer or directly with the MEITY grievance portal.
How to exercise: Email: dpo@dhor.in | Response within 7 working days
Right to Nominate
Under DPDP Act 2023, you may nominate another person to exercise your data rights in case of death or incapacity.
How to exercise: Settings → Privacy → Nominate a Representative
Third-Party Services
We use a limited number of third-party services, each bound by their own privacy policies and our data processing agreements:
- Razorpay — Payment processing for donations. Razorpay is PCI-DSS compliant. We never see or store your full card number.
- MSG91 / Twilio — OTP and notification SMS delivery. Your mobile number is shared only for delivery purposes.
- AWS India (Mumbai Region) — Cloud infrastructure. All data stays in the ap-south-1 (Mumbai) region.
We do not share your data with advertisers, data brokers, political organisations, or any other third parties beyond those listed above.
How We Protect Your Data
AES-256 Encryption
All data at rest is encrypted using AES-256.
TLS 1.3 in Transit
All data in transit is encrypted using TLS 1.3.
Zero-Trust Architecture
Internal systems require explicit authorisation. No implicit trust.
Regular Security Audits
Independent pen-testing every 6 months. Vulnerability disclosure policy active.
If you discover a security vulnerability, please report it responsibly to security@dhor.in. We will acknowledge within 24 hours and resolve critical issues within 72 hours.
Children's Privacy
Dhor.in is intended for users aged 18 and above. We do not knowingly collect personal data from children under 18.
If you are a parent or guardian and believe your child under 18 has registered on our platform, please contact us immediately at privacy@dhor.in. We will delete the account within 72 hours.
Youth platform features (for ages 18–25) are open to verified adults only, with additional parental consent options available for users aged 18–19.
Contact Our Data Protection Officer
Data Protection Officer
For privacy complaints, data requests, or DPDP Act grievances, contact our DPO directly. All requests are handled confidentially and within statutory timelines.
You may also file a complaint with the Data Protection Board of India (once constituted under DPDP Act 2023) or MEITY's IT grievance portal at pgportal.gov.in.