Privacy Policy & Data Security
We understand that matrimonial biodatas contain deeply personal, familial, and astrological information. Here is our transparent, legally binding commitment to how your data is collected, stored, shielded, and kept private.
Our Core Privacy Principles at a Glance
Blocked from Google
All profile links are protected with noindex and strict robots.txt blocks so your biodata never appears in public web searches.
PIN-Protected Details
Contact numbers, emails, and home addresses can be locked behind a 4-digit PIN verified securely on the server.
Zero Data Selling
We never sell, rent, or trade matrimonial biodatas to advertisers, insurance telemarketers, loan brokers, or third parties.
1-Click Full Erasure
You retain complete ownership. You can pause, mark married, or permanently wipe your profile and photos at any time.
1Identity & Scope of this Policy
This Privacy Policy applies to the web application and services provided by My Shadi Profile (accessible via https://myshadiprofile.in, hereinafter referred to as “the Platform”, “we”, “us”, or “our”).
We operate as a Data Fiduciary / Service Provider under the Digital Personal Data Protection Act, 2023 (DPDP Act) and the Information Technology Act, 2000 (along with its reasonable security practices and sensitive personal data rules). This policy explains how personal and matrimonial data is collected, stored, accessed, and safeguarded when you create, edit, or share a marriage biodata link or download a printable PDF.
2Information We Collect & Why
We collect information that you voluntarily provide when creating or editing your matrimonial profile. Because marriage biodatas in India serve as cultural introductions between families, this information includes:
A. Personal & Demographic Data
Full name, gender, date of birth, time of birth, place of birth, height, weight, marital status, diet preferences, mother tongue, native place, and blood group.
B. Cultural & Horoscope / Astrological Data
Religion, caste, sub-caste, gothram, rasi (moon sign), nakshatram, lagnam, and manglik status. These details are provided voluntarily for traditional matching purposes.
C. Education & Career Background
Highest educational qualification, college/university name, profession/designation, employer company name, annual income range, and work location.
D. Family Background
Father's name and occupation, mother's name and occupation, siblings count/status, family type (Joint/Nuclear), and family values.
E. Sensitive Contact Information (Maskable)PIN Protected
Contact person name, primary phone number, WhatsApp contact number, residential address, and email address. When PIN protection is enabled, these details are never sent to the client browser without entering the correct PIN.
F. Photographs & Media
Primary portrait photograph and optional family/gallery photographs that you upload and crop using our platform tools.
G. Authentication & Technical Telemetry
Mobile number for OTP verification, session security tokens, anonymous IP access logs for DDOS defense, and profile views counter.
3Lawful Purpose & Legal Basis for Processing
Under Section 4 and Section 6 of the DPDP Act 2023, we process your data based on your explicit affirmative consent given when you create an account, submit your biodata, or choose to publish your profile link.
We process your information solely for the following purposes:
- To generate your customized mobile biodata web link (e.g.,
myshadiprofile.in/p/your-slug). - To generate print-ready, publication-grade vector A4 PDF documents.
- To verify your account identity via secure SMS One-Time Passwords (OTP).
- To facilitate 1-click bilingual translation into Indian regional languages when selected by you or profile viewers.
- To prevent fraud, automated scraping, account takeover, or platform misuse.
4Where & How Your Data is Stored
We utilize world-class, ISO 27001 and SOC 2 certified cloud infrastructure provided by Google Cloud Platform & Firebase:
- Database Storage: Profile records are stored in Google Cloud Firestore databases located in secured multi-region data centers with automated failover and daily encrypted backups.
- Encryption at Rest: All data stored in our databases and cloud buckets is encrypted using 256-bit Advanced Encryption Standard (AES-256).
- Encryption in Transit: All communications between your device, our Next.js edge servers, and our databases use Transport Layer Security (TLS 1.3 / HTTPS) with strict HSTS headers.
- Granular Security Rules: Database read/write rules enforce that only verified user session tokens can modify, update, or delete account biodata.
5PIN Protection & Sensitive Field Masking
To protect candidates from unwanted calls or unsolicited inquiries, our platform incorporates a server-side PIN Privacy feature:
- When Privacy Protection (PIN Mode) is enabled, sensitive fields (contact number, WhatsApp number, email, and address) are stripped on the server before transmitting public profile data.
- The visitor must request the 4-digit PIN directly from the candidate or family.
- PIN verification occurs strictly on our backend API endpoint (
/api/profile/verify-pin). The private PIN is never exposed to the client browser source code.
6Google Search Blocking & Anti-Scraping Policy
Unlike public social networks or classified sites, we deliberately block search engine indexers from listing user profiles:
- Robots Exclusion: Our root
robots.txtfile explicitly disallows Googlebot, Bingbot, and all automated crawlers from accessing/p/and/p/*. - No-Index Meta Headers: Every individual profile page serves HTTP and HTML headers:
<meta name="robots" content="noindex, nofollow, nocache" />. - Sitemap Exclusion: User profile URLs are never submitted in
sitemap.xml. - Legal Prohibition of AI Scraping: As articulated in our
/llms.txtpolicy, automated scraping, data harvesting, and model training on personal records hosted on this platform is strictly forbidden and constitutes a violation of the DPDP Act 2023 and the IT Act 2000.
7Third-Party Processors & Data Disclosure
We only share minimal necessary data with vetted infrastructure providers under strict data processing agreements:
- Cloud & Database Hosting: Google Cloud Platform & Firebase (USA / India server clusters).
- SMS OTP Gateways: Telecommunications partners solely for sending authentication codes to your mobile device.
- Translation APIs: When bilingual translation is triggered, non-confidential textual snippets (e.g. occupation terms, education titles) are securely passed to translation endpoints. Private contact numbers and addresses are strictly excluded from translation payloads.
- Legal Compliance: We will only disclose personal records if strictly compelled by a verified court order or statutory Indian law enforcement warrant under the Code of Criminal Procedure, 1973.
8Lifecycle: Married, Paused & Deactivated Profiles
We recognize that marriage profiles are temporary and should be retired once a marriage is finalized:
- Married Status: When you mark your profile as “Married” in the dashboard, the public link immediately ceases displaying your biodata, photos, horoscope, or contact details. Instead, visitors see a celebratory celebratory badge honoring the union.
- Non-Active / Paused Status: If you wish to take a break from matchmaking, setting status to “Non-active” replaces the live link with a private paused notice.
9Data Retention & Right to Permanent Deletion
Under the DPDP Act 2023, you have an unqualified Right to Erasure (Right to be Forgotten):
- You can delete individual photos, bio text, or your entire account directly from your Dashboard settings.
- Alternatively, you can email privacy@myshadiprofile.in with your registered mobile number, and our team will permanently purge your data within 72 hours.
- Once deleted, profile data and associated photo files are permanently purged from active databases and cannot be restored.
10Your Statutory Rights as a Data Principal
As a citizen and user under Indian and global data privacy legislation, you possess the following rights:
11Cookies & Local Storage
We do not use invasive third-party tracking cookies or advertising beacons. We strictly use essential first-party browser local storage (localStorage) to maintain your login session token, profile drafting state, and preferred interface language.
12Grievance Officer & Statutory Contact Details
In compliance with Section 13 of the Digital Personal Data Protection Act, 2023, and Rule 5(9) of the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, the contact details of our Grievance Officer are:
Platform: My Shadi Profile (myshadiprofile.in)
Attention: Grievance Officer – Privacy & Data Protection
Official Email: privacy@myshadiprofile.in
Support Desk: support@myshadiprofile.in
⏱ We acknowledge all complaints within 24 hours and resolve any valid request or data deletion ticket within 15 working days as stipulated by Indian law.
© 2026 myshadiprofile.in • All Rights Reserved.