Legal · v1.0

Privacy Policy

How MarryMantra collects, uses, shares, and protects personal data across our User App, Partner App, Admin tools, and website.

Effective 30 July 2026 · Last updated 8 September 2026

1. Who we are

This Privacy Policy is issued by MARRYMANTRA SERVICES PRIVATE LIMITED ("MarryMantra", "we", "us", or "our"), brand name MarryMantra, with registered office at Near Sakhala Tent House, C/o Trilok Ram Mali, Ladnun Road, Near New Sankhala Tent House, Sujangarh, Churu, Rajasthan – 331507. GSTIN: 08AATCM5091R1ZB.

We operate a wedding and celebration marketplace connecting customers with service partners listed on the platform in India.

For privacy questions or DPDP grievances, contact privacy@marrymantra.in. General support: support@marrymantra.in.

2. Scope — apps and surfaces covered

This Policy applies to: (a) the MarryMantra User mobile application (com.marrymantra.user); (b) the MarryMantra Partner mobile application (com.marrymantra.partner); (c) the Admin portal used by authorised staff; (d) our website at marrymantra.in including /invite, /qr, and /r deep-link landing pages; and (e) related APIs and backends.

By creating an account, completing KYC, making a booking, scanning a referral QR, or otherwise using our Services, you acknowledge this Policy.

3. Identity and contact data

We collect mobile number, name, email address, city, profile photo, authentication provider (OTP or Google), Firebase user ID where applicable, and mobile verification status.

Partners additionally provide business name, contact person name, bio, languages, partner type(s), and registration city.

4. Authentication and session data

We process one-time passwords (OTPs), JWT access and refresh tokens, login timestamps, and logout events. On logout we may deactivate associated push notification tokens.

OTP login may use MSG91 (including widget mode) or our backend OTP flow. Google Sign-In uses Google / Firebase Authentication credentials (ID tokens).

5. KYC and sensitive personal data

For partner verification we may collect government identity details and documents (PAN, Aadhaar, Passport), GSTIN, firm name, business address and address proof, selfie images, and liveness / face-match scores.

We collect bank payout details: account holder name, account number, IFSC, account type, and related Razorpay contact / fund-account identifiers where used.

Type A KYC is a full verification flow; Type B KYC is a lighter document set for eligible partner types. Treat KYC data as sensitive. Access is limited to authorised operations and compliance review.

6. Booking and event data

Bookings may include first/last name, mobile, cities, address, event dates, guest count, bride/groom side, venue type, package and catering selections, and service preferences.

Partners creating bookings on behalf of clients may store client name and mobile until the client claims the booking. Home-visit requests store visit address, geo-coordinates, geo-selfie, and visit OTP.

7. Location data

With your permission we may collect approximate or precise location for: city auto-detection; home-visit verification; QR scan attribution; and KYC ground-visit coordinates.

You can deny or revoke location permission in device settings; some features (city detect, geo-verified visits, QR attribution) may then be limited.

8. Payments, wallet, and invoices

We process payment amounts, Razorpay order / payment / payment-link IDs, wallet balances and ledger entries (token, advance, program fees, wallet top-ups/withdrawals), vouchers, and GST invoice snapshots (buyer/seller names, addresses, GSTIN).

Card and UPI credentials are handled by Razorpay; we do not store full card numbers on our servers.

9. Photos, video, and media

We store profile images; KYC document images and selfies; partner gallery media; franchise office photos; complaint attachments; chat media; timeline proof videos; and home-visit geo selfies.

KYC and proof media are private and served via short-lived signed URLs where applicable. Certain catalog/gallery assets may be publicly readable for marketplace display.

10. Chat and communications content

In-app chat may store participants, message text, media paths, and sender name snapshots for coordination between users, partners, and home-visit agents.

For home visits, certain personal details may be withheld from an agent until the agent accepts the request.

11. Referrals and QR attribution

We process referral codes, referrer/referee identifiers, reward amounts, program type, and attribution audits. QR scans may record IP address, device information, and latitude/longitude for fraud prevention and commission attribution.

Site landing pages (/invite, /qr, /r) may pass referral parameters into app install / open flows.

12. Notifications and messaging

We store FCM tokens (token, device type, app type) for push notifications. We send transactional SMS (OTP, booking-related templates) via MSG91 and may use SMSHorizon as a fallback. Commercial SMS uses registered DLT templates where required.

Admin tools may send push campaigns to selected audiences. You can disable push in device settings; transactional SMS for security/booking may still be necessary.

13. Reviews, complaints, and franchise

Reviews and ratings, complaint descriptions and categories (service quality, vendor, payment, delay, other), shopping QR complaints, and attachments are stored for quality and enforcement.

Franchise applications may include office address, size, photo URLs, and City Manager notes.

14. Analytics and technical data

We use Firebase Analytics / Google Analytics 4 on the User and Partner mobile apps, on marrymantra.in (including /invite, /qr, and /r), on the Admin portal, and on the Partner website. Where enabled, the backend may also send Measurement Protocol events. Event parameters are designed to avoid direct PII (no phone/name/token in event params). On mobile apps after login we may attach opaque user IDs and city as user properties. Website and Admin analytics do not set a user_id.

Technical data may include IP, device info, app version, and signed URL access patterns for security and delivery.

15. Purposes of processing

We process data to: create and secure accounts; verify partners (KYC); facilitate bookings and home visits; collect and reconcile payments; calculate commissions and referrals; operate wallets and vouchers; provide chat and support; send transactional communications; prevent fraud; improve products via analytics; comply with tax, telecom, and legal obligations; and enforce our Terms and Partner Agreement.

17. Sharing with humans and roles

Assigned partners and City Managers receive booking/event details needed to deliver or oversee services. Home-visit agents receive address and identity details after acceptance. Admins may search users/partners and review KYC, complaints, and payments as part of operations.

We do not sell personal data. We share with processors listed below to run the Services.

18. Third-party processors

AWS S3 (ap-south-1): storage of KYC docs, media, and proofs with signed upload/download URLs.

Razorpay: payment collection, webhooks, IFSC validation, and payout-related account identifiers where enabled.

MSG91 and SMSHorizon: SMS OTP and transactional messaging; Jio DLT / telecom PE registration for commercial SMS compliance.

Google / Firebase: Authentication (Google Sign-In path), Cloud Messaging (FCM), Analytics, and Hosting for the website.

Infrastructure: AWS EC2 and Secrets Manager for hosting and secrets management.

19. Cross-border processing

Primary object storage is in AWS ap-south-1 (India). Google and Firebase services may process data in other regions as part of their global infrastructure. By using Google Sign-In or Firebase-powered features, you acknowledge such processing may occur outside India subject to those providers' terms and applicable law.

20. Retention

OTPs and similar short-lived credentials expire after use or timeout. KYC, bank, booking, payment, and invoice records are retained as needed for service delivery, disputes, tax, and legal compliance.

Referral attribution records may be deactivated on a scheduled basis (approximately 12 months for certain referral touch data). Chat and media are retained while needed for the booking relationship and dispute window unless deletion is requested and legally permissible.

After account closure we anonymise login identifiers; KYC, booking, payment, and invoice records may still be retained as described above.

21. Your rights under DPDP

Subject to applicable law, you may request: access to personal data we hold about you; correction of inaccurate data; erasure or anonymisation where legally available; withdrawal of consent for consent-based processing; and grievance redressal.

Account closure is in-app (see Section 22). Use the privacy email below for access, correction, or DPDP grievances — not as the only way to delete an account.

Submit those requests to privacy@marrymantra.in with your registered mobile number and a description of the request. We may verify identity before acting. We aim to respond within timelines required by applicable law.

Privacy requests: privacy@marrymantra.in (Grievance Officer appointment pending).

22. Account deletion requests

In the MarryMantra User or Partner app, open Profile and tap Delete Account. Confirm as prompted. This is the primary deletion path.

Deletion is blocked until you finish active bookings, resolve open complaints or disputes, withdraw any partner wallet / held balance, and wait for pending payouts.

If you cannot use the in-app button, email support@marrymantra.in from your registered contact with subject "Account deletion request". Full instructions: /delete-account.

Payment and KYC records may be retained in restricted form as required by law even after account closure.

23. Device permissions

Location (when in use): city detection, home visits, QR attribution. Camera: KYC, proof video, QR scan, complaints. Microphone: video proof recording. Photos/gallery: uploads and complaints. Notifications: push alerts.

Denying a permission limits the related feature; core account login via OTP may still work without location or camera.

24. Children

The Services are intended for users aged 18 years or older. We do not knowingly collect personal data from children under 18. If you believe a minor has provided data, contact us for deletion.

25. Security

We use industry-standard measures including HTTPS, JWT-based API auth, access-controlled admin tools, and short-lived signed URLs for private media. No method of transmission or storage is 100% secure; we do not claim absolute security or that all fields (including KYC/bank data in operational databases) are encrypted at rest with customer-managed keys.

26. Data breach notification

If we become aware of a personal data breach likely to cause harm, we will take reasonable steps to contain the incident and notify affected users and authorities as required by applicable Indian law.

27. Cookies and similar technologies

Our website may use cookies or similar technologies for hosting, analytics, and essential site function. See our Cookies Notice at /cookies for details.

28. Changes to this Policy

We may update this Policy and publish a new version with an updated effective date at marrymantra.in/privacy. Material changes may also be notified in-app or by SMS/email where appropriate. Continued use after the effective date constitutes acceptance of the updated Policy.

29. Governing law

This Policy is governed by the laws of India. Subject to mandatory consumer protections, courts at Rajasthan, India shall have jurisdiction over disputes arising from this Policy.

30. Contact

MARRYMANTRA SERVICES PRIVATE LIMITED, Near Sakhala Tent House, C/o Trilok Ram Mali, Ladnun Road, Near New Sankhala Tent House, Sujangarh, Churu, Rajasthan – 331507. Privacy: privacy@marrymantra.in. Support: support@marrymantra.in. Website: https://marrymantra.in.