1. Who we are
This Privacy Policy is issued by MARRYMANTRA SERVICES PRIVATE LIMITED ("MarryMantra", "we", "us", or "our"), brand name MarryMantra, with registered office at Near Sakhala Tent House, C/o Trilok Ram Mali, Ladnun Road, Near New Sankhala Tent House, Sujangarh, Churu, Rajasthan – 331507. GSTIN: 08AATCM5091R1ZB.
We operate a wedding and celebration marketplace connecting customers with service partners listed on the platform in India.
For privacy questions or DPDP grievances, contact privacy@marrymantra.in. General support: support@marrymantra.in.
2. Scope — apps and surfaces covered
This Policy applies to: (a) the MarryMantra User mobile application (com.marrymantra.user); (b) the MarryMantra Partner mobile application (com.marrymantra.partner); (c) the Admin portal used by authorised staff; (d) our website at marrymantra.in including /invite, /qr, and /r deep-link landing pages; and (e) related APIs and backends.
By creating an account, completing KYC, making a booking, scanning a referral QR, or otherwise using our Services, you acknowledge this Policy.
3. Identity and contact data
We collect mobile number, name, email address, city, profile photo, authentication provider (OTP or Google), Firebase user ID where applicable, and mobile verification status.
Partners additionally provide business name, contact person name, bio, languages, partner type(s), and registration city.
4. Authentication and session data
We process one-time passwords (OTPs), JWT access and refresh tokens, login timestamps, and logout events. On logout we may deactivate associated push notification tokens.
OTP login may use MSG91 (including widget mode) or our backend OTP flow. Google Sign-In uses Google / Firebase Authentication credentials (ID tokens).
5. KYC and sensitive personal data
For partner verification we may collect government identity details and documents (PAN, Aadhaar, Passport), GSTIN, firm name, business address and address proof, selfie images, and liveness / face-match scores.
We collect bank payout details: account holder name, account number, IFSC, account type, and related Razorpay contact / fund-account identifiers where used.
Type A KYC is a full verification flow; Type B KYC is a lighter document set for eligible partner types. Treat KYC data as sensitive. Access is limited to authorised operations and compliance review.
6. Booking and event data
Bookings may include first/last name, mobile, cities, address, event dates, guest count, bride/groom side, venue type, package and catering selections, and service preferences.
Partners creating bookings on behalf of clients may store client name and mobile until the client claims the booking. Home-visit requests store visit address, geo-coordinates, geo-selfie, and visit OTP.
7. Location data
With your permission we may collect approximate or precise location for: city auto-detection; home-visit verification; QR scan attribution; and KYC ground-visit coordinates.
You can deny or revoke location permission in device settings; some features (city detect, geo-verified visits, QR attribution) may then be limited.
8. Payments, wallet, and invoices
We process payment amounts, Razorpay order / payment / payment-link IDs, wallet balances and ledger entries (token, advance, program fees, wallet top-ups/withdrawals), vouchers, and GST invoice snapshots (buyer/seller names, addresses, GSTIN).
Card and UPI credentials are handled by Razorpay; we do not store full card numbers on our servers.
9. Photos, video, and media
We store profile images; KYC document images and selfies; partner gallery media; franchise office photos; complaint attachments; chat media; timeline proof videos; and home-visit geo selfies.
KYC and proof media are private and served via short-lived signed URLs where applicable. Certain catalog/gallery assets may be publicly readable for marketplace display.
10. Chat and communications content
In-app chat may store participants, message text, media paths, and sender name snapshots for coordination between users, partners, and home-visit agents.
For home visits, certain personal details may be withheld from an agent until the agent accepts the request.
11. Referrals and QR attribution
We process referral codes, referrer/referee identifiers, reward amounts, program type, and attribution audits. QR scans may record IP address, device information, and latitude/longitude for fraud prevention and commission attribution.
Site landing pages (/invite, /qr, /r) may pass referral parameters into app install / open flows.
12. Notifications and messaging
We store FCM tokens (token, device type, app type) for push notifications. We send transactional SMS (OTP, booking-related templates) via MSG91 and may use SMSHorizon as a fallback. Commercial SMS uses registered DLT templates where required.
Admin tools may send push campaigns to selected audiences. You can disable push in device settings; transactional SMS for security/booking may still be necessary.
13. Reviews, complaints, and franchise
Reviews and ratings, complaint descriptions and categories (service quality, vendor, payment, delay, other), shopping QR complaints, and attachments are stored for quality and enforcement.
Franchise applications may include office address, size, photo URLs, and City Manager notes.
14. Analytics and technical data
We use Firebase Analytics / Google Analytics 4 on the User and Partner mobile apps, on marrymantra.in (including /invite, /qr, and /r), on the Admin portal, and on the Partner website. Where enabled, the backend may also send Measurement Protocol events. Event parameters are designed to avoid direct PII (no phone/name/token in event params). On mobile apps after login we may attach opaque user IDs and city as user properties. Website and Admin analytics do not set a user_id.
Technical data may include IP, device info, app version, and signed URL access patterns for security and delivery.
15. Purposes of processing
We process data to: create and secure accounts; verify partners (KYC); facilitate bookings and home visits; collect and reconcile payments; calculate commissions and referrals; operate wallets and vouchers; provide chat and support; send transactional communications; prevent fraud; improve products via analytics; comply with tax, telecom, and legal obligations; and enforce our Terms and Partner Agreement.
16. Legal bases (DPDP framing)
Depending on the activity, we rely on: consent (e.g., optional permissions, marketing where applicable); performance of a contract (bookings, KYC, payouts); legitimate uses consistent with Indian law for security and fraud prevention; and legal obligations (tax records, DLT, dispute evidence).
Where consent is required, you may withdraw it as described in this Policy, subject to residual legal retention needs.
18. Third-party processors
AWS S3 (ap-south-1): storage of KYC docs, media, and proofs with signed upload/download URLs.
Razorpay: payment collection, webhooks, IFSC validation, and payout-related account identifiers where enabled.
MSG91 and SMSHorizon: SMS OTP and transactional messaging; Jio DLT / telecom PE registration for commercial SMS compliance.
Google / Firebase: Authentication (Google Sign-In path), Cloud Messaging (FCM), Analytics, and Hosting for the website.
Infrastructure: AWS EC2 and Secrets Manager for hosting and secrets management.
19. Cross-border processing
Primary object storage is in AWS ap-south-1 (India). Google and Firebase services may process data in other regions as part of their global infrastructure. By using Google Sign-In or Firebase-powered features, you acknowledge such processing may occur outside India subject to those providers' terms and applicable law.
20. Retention
OTPs and similar short-lived credentials expire after use or timeout. KYC, bank, booking, payment, and invoice records are retained as needed for service delivery, disputes, tax, and legal compliance.
Referral attribution records may be deactivated on a scheduled basis (approximately 12 months for certain referral touch data). Chat and media are retained while needed for the booking relationship and dispute window unless deletion is requested and legally permissible.
After account closure we anonymise login identifiers; KYC, booking, payment, and invoice records may still be retained as described above.
21. Your rights under DPDP
Subject to applicable law, you may request: access to personal data we hold about you; correction of inaccurate data; erasure or anonymisation where legally available; withdrawal of consent for consent-based processing; and grievance redressal.
Account closure is in-app (see Section 22). Use the privacy email below for access, correction, or DPDP grievances — not as the only way to delete an account.
Submit those requests to privacy@marrymantra.in with your registered mobile number and a description of the request. We may verify identity before acting. We aim to respond within timelines required by applicable law.
Privacy requests: privacy@marrymantra.in (Grievance Officer appointment pending).
22. Account deletion requests
In the MarryMantra User or Partner app, open Profile and tap Delete Account. Confirm as prompted. This is the primary deletion path.
Deletion is blocked until you finish active bookings, resolve open complaints or disputes, withdraw any partner wallet / held balance, and wait for pending payouts.
If you cannot use the in-app button, email support@marrymantra.in from your registered contact with subject "Account deletion request". Full instructions: /delete-account.
Payment and KYC records may be retained in restricted form as required by law even after account closure.
23. Device permissions
Location (when in use): city detection, home visits, QR attribution. Camera: KYC, proof video, QR scan, complaints. Microphone: video proof recording. Photos/gallery: uploads and complaints. Notifications: push alerts.
Denying a permission limits the related feature; core account login via OTP may still work without location or camera.
24. Children
The Services are intended for users aged 18 years or older. We do not knowingly collect personal data from children under 18. If you believe a minor has provided data, contact us for deletion.
25. Security
We use industry-standard measures including HTTPS, JWT-based API auth, access-controlled admin tools, and short-lived signed URLs for private media. No method of transmission or storage is 100% secure; we do not claim absolute security or that all fields (including KYC/bank data in operational databases) are encrypted at rest with customer-managed keys.
26. Data breach notification
If we become aware of a personal data breach likely to cause harm, we will take reasonable steps to contain the incident and notify affected users and authorities as required by applicable Indian law.
28. Changes to this Policy
We may update this Policy and publish a new version with an updated effective date at marrymantra.in/privacy. Material changes may also be notified in-app or by SMS/email where appropriate. Continued use after the effective date constitutes acceptance of the updated Policy.
29. Governing law
This Policy is governed by the laws of India. Subject to mandatory consumer protections, courts at Rajasthan, India shall have jurisdiction over disputes arising from this Policy.
30. Contact
MARRYMANTRA SERVICES PRIVATE LIMITED, Near Sakhala Tent House, C/o Trilok Ram Mali, Ladnun Road, Near New Sankhala Tent House, Sujangarh, Churu, Rajasthan – 331507. Privacy: privacy@marrymantra.in. Support: support@marrymantra.in. Website: https://marrymantra.in.