SheJoins is a women-only service that helps verified women find company for everyday plans in public places, such as a concert, a coffee or a hospital visit. This policy explains what personal data we collect, why, who we share it with, how long we keep it, and your rights.
Who we are. SheJoins is operated by Starbrain Technologies OPC Private Limited. Company details: on the Starbrain website (address to follow). ("SheJoins", "we", "us")
| Role | Contact |
|---|---|
| Data fiduciary (India) / controller (UK, EU) | Starbrain Technologies OPC Private Limited (details: on the Starbrain website, address to follow) |
| Grievance officer (India) | name to be added after incorporation, support@shejoins.com, phone to be added after incorporation |
| Data protection officer | To be added after incorporation; until then, support@shejoins.com |
| UK representative (UK GDPR Art. 27) | To be appointed before SheJoins opens in the UK |
| EU representative (GDPR Art. 27) | To be appointed before SheJoins opens in the EU |
We operate in India (Bengaluru and Mumbai), the United Kingdom (London), France (Paris) and the United States (New York). Wherever you are, this policy applies, together with the extra rights for your region in section 10.
1. Summary
- Women only, verified by people. To join, you show an ID document and record a short video. Our review team checks them by hand.
- ID images and video are deleted 30 days after we decide. After that we keep the decision, the last 4 characters of your ID number, and one-way codes that can't be turned back into your details (section 5).
- Your contact details stay private. Other members never see your phone number, and chats block numbers, links and handles.
- Safety data is used only for safety. Your location is shared only while the app is open during a booking, or when you press SOS. Only our safety team and your trusted contact see it, and we delete it 72 hours after the booking.
- We don't sell your data or use it for advertising.
- Analytics, with limits. We count visits and a few sign-up steps with Google Analytics. We never send your number, your name, your bookings, your chats, your location or anything about safety (section 4, Analytics). You can turn it off.
2. What we collect
| What | Examples | Where it comes from |
|---|---|---|
| Account | Mobile number, country | You |
| Verification | Legal name, date of birth, ID type, photos of your ID (front, back), a 10-second video following an on-screen prompt, a live profile photo | You, through the in-app camera |
| Verification results | Our reviewer's decision and checklist, including only "ID states female: yes" (never what the ID says about sex or gender), the date of birth shown on the ID, the last 4 characters of the ID number, one-way codes of your ID number and of your name with date of birth | Our reviewers |
| Profile | Display name, area, languages, bio, activities and rates, status line, gallery photos and videos, intro video, visibility settings | You |
| Activity | Plans, applications, chat messages, reviews you write and receive, blocks and reports | You and other members |
| Bookings and payments | Bookings, times, venues, amounts, payment status, refunds. For companions, payout details (bank or UPI). | You, and our payment providers. We never see your full card details. |
| VIP membership | Your plan, its renewal and its status | Google Play, RevenueCat, PayPal, UPI |
| Safety | Your trusted contact's name and number, start-code checks, check-in answers, your location during a booking (while the app is open, with your consent), SOS alerts and what our team did | You, your phone, our safety team |
| Moderation | Automatic checks of uploads for nudity and contact details, flags when text tries to share contact details, warnings, suspensions, removals | Our systems, our team |
| Usage (analytics) | Pages viewed, taps on Join and Become a companion, sign-in and sign-up steps, sending verification, installing the app, campaign tags in the link you came from (such as utm_source), browser and device type, approximate location derived from your IP address | Your browser, through Google Analytics |
| Device and security | Push notification token, app-integrity and anti-bot signals (reCAPTCHA Enterprise / App Check), IP address and technical logs | Your device, Google |
Your trusted contact's details. You give us someone else's name and number. Please tell them first. We text them only if you press SOS or stop answering check-ins during a booking.
3. Why we use it, and on what basis
| Purpose | Data | Basis (UK and EU GDPR) | India (DPDP) |
|---|---|---|---|
| Create and run your account; show your profile to verified members | Account, profile, activity | Contract | Consent |
| Check that every member is a real, adult woman who is who she says she is | Verification | Legitimate interests (a women-only service that is safe to use); for ID images and video, also your explicit consent | Consent |
| Keep removed members out (section 5) | Verification results, removed-member record | Legitimate interests (protecting members) | Legitimate use: preventing fraud and harm, with notice |
| Bookings, payments, refunds and payouts | Bookings and payments | Contract; legal obligation (tax and accounting) | Consent; legal obligation |
| Safety: start codes, check-ins, SOS, texts to your trusted contact and our responders | Safety | Contract and legitimate interests; vital interests in an emergency; location only with your consent | Consent; medical or safety emergency (DPDP s.7) |
| Moderation: scanning uploads and text; acting on reports | Moderation, activity | Legitimate interests (safety, our rules) | Consent; legitimate uses |
| Notifications | Device | Consent (you can turn each kind off; safety ones can't be turned off during a booking) | Consent |
| Security, anti-fraud and anti-bot | Device and security | Legitimate interests | Legitimate uses |
| Understand how people find and use SheJoins, and fix where sign-up gets stuck | Usage (analytics) | Legitimate interests; consent where the law requires it (we don't run analytics in the UK or EU until we offer that choice) | Consent |
| Legal claims, law enforcement requests | As needed | Legal obligation; legitimate interests | Legal obligation |
Automated decisions. No decision about you is made by a computer alone. Automatic scans only hold an upload or text for a person to check. A reviewer decides every verification, report and strike. When you photograph your ID, an automatic check (Google Cloud Vision) looks for document text, and for a large face that would mean a selfie instead of an ID, so you can retake the photo straight away. We don't keep what it reads, and it decides nothing about your account.
4. Who we share it with
Other members see only what's on your profile, your plans and applications, your chats with them, and published reviews (without the reviewer's name). They never see your phone number, ID, legal name or date of birth.
Your trusted contact gets a text with your first name, the venue, the emergency number and a private link to your last location. The link stops working when that location data is deleted.
Service providers. They process data only on our instructions:
| Provider | What for | Where |
|---|---|---|
| Google Cloud and Firebase (Google) | Hosting, database, storage, sign-in, push notifications, App Check and reCAPTCHA Enterprise, image and video scanning | Data stored in Mumbai, India (asia-south1); some global services (sign-in, push, reCAPTCHA) |
| MSG91 (once set up) | Safety texts in India | India |
| Twilio (once set up) | Safety texts in the UK, France and the US | United States and others |
| PayPal | Payments and subscriptions outside India | Varies |
| Google Pay for Business (UPI) | Payments in India | India |
| Google Play and RevenueCat | VIP subscriptions in the Android app | United States and others |
| Google Analytics (Google, through Firebase) | Usage statistics (section 4, Analytics) | United States and others |
Authorities. We share data with police or other authorities when the law requires it, or when someone's life or safety is at risk (for example, during an SOS).
We don't sell personal data, and we don't share it for advertising.
Analytics
What we measure. On shejoins.com and in the SheJoins web app we use Google Analytics, through Firebase, to count visits and a few steps:
- pages viewed
- taps on Join and Become a companion
- starting sign-in, a code being sent, and finishing sign-up
- sending your verification
- the app's install prompt being shown, and the app being installed
With each, Google receives the campaign tags in the link you came from (such as utm_source), your browser and device type, and an approximate location it works out from your IP address.
What we never send. Your phone number, your name, your ID, photos or videos, other members' details, plans or bookings, chats, your location, or anything about check-ins or SOS. We don't set a user ID. Links that carry a chat or a booking, and the page your trusted contact opens, are never measured.
Why. To see which pages help women find SheJoins, and where joining gets stuck, so we can fix it.
Settings. Google signals and ad personalisation are switched off. We don't use analytics for advertising, and it isn't used to show you ads.
When it's off. Analytics doesn't run:
- if your browser sends Global Privacy Control or Do Not Track
- if your device's time zone is in the UK or Europe, until we offer a consent choice there
- in our admin tools, ever
Turning it off. Use the switch at the end of this page to turn analytics off on this device, or install Google's opt-out add-on for your browser (tools.google.com/dlpage/gaoptout).
How long. Google keeps event-level analytics data for 2 months. After that we see only totals.
5. Keeping removed members out
If an account is removed for serious or repeated breaches of our rules, we keep:
- the legal name and date of birth
- the ID type and the last 4 characters of the ID number
- one-way codes of the ID number, and of the name with date of birth
- the account's profile photo (the one other members already saw)
We keep this so the same person can't simply verify again under a new number. When someone new applies, our reviewers compare them with this record by hand. Only our verification reviewers can see the photo, and every time they open it is logged.
We never keep the ID images or the verification video for this. The one-way codes are made with a secret key, so they can't be reversed into the original details.
How long:
- The photo is deleted 3 years after the removal. If the same person tries to join again during that time, it's kept for 3 years from that attempt.
- The rest of the record (name, date of birth, ID type, last 4 characters and one-way codes) is kept while the removal stands.
- Everything is deleted if a removal is overturned on review.
6. How long we keep it
| Data | How long |
|---|---|
| ID images and verification video | Deleted 30 days after the decision (straight away if an unmasked Aadhaar is sent) |
| Verification decision, last 4 ID characters, one-way codes | While your account exists; if you're removed, as in section 5 |
| A removed account's profile photo | 3 years after removal, or 3 years after the last attempt to rejoin |
| Profile, photos, videos | Until you delete them or your account |
| Chat messages | While your account exists; after you delete your account, 90 days, then deleted |
| Location during a booking | Only the latest point; deleted 72 hours after the booking ends |
| Bookings and payment records | As tax and accounting law requires (up to 8 years in India) |
| SOS alerts, reports, warnings, suspensions, removals, audit log | 3 years, longer if needed for a legal claim |
| Backups of our database | Up to 14 weeks, then overwritten |
| Analytics events (Google Analytics) | 2 months, then only totals |
7. Security
- Data is encrypted in transit and at rest.
- ID images sit in a separate storage area no app can reach. Only our reviewers can open them, through a logged screen.
- Staff sign in with Google accounts protected by two-step verification. Each role sees only what it needs, and sensitive views are logged.
- We test our access rules automatically.
If a breach puts you at risk, we'll tell you and the authorities as the law requires: within 72 hours to the ICO or CNIL, as DPDP requires to the Data Protection Board, and as the NY SHIELD Act requires.
8. International transfers
Our main database is in India. If you're in the UK or EU, your data is transferred to India, which has no adequacy decision. We use the European Commission's Standard Contractual Clauses, and for the UK the International Data Transfer Addendum, with the safeguards they require. Some providers also process data in the United States under their own transfer mechanisms. Ask us for a copy of the safeguards.
9. Your choices and rights (everyone)
You can:
- see and correct most of your data in the app
- hide your profile, pause bookings, and choose who sees your videos
- turn notifications off (except safety ones during a booking)
- turn analytics off on your device (section 4, Analytics)
- delete your account in the app (My profile → Delete my account) or at shejoins.com/delete-account
For anything else, write to support@shejoins.com. We reply within 30 days (one month in the UK and EU), and sooner where the law requires.
10. Extra rights by region
India (Digital Personal Data Protection Act, 2023).
- Your rights: to get a summary of your data and who we've shared it with; to have it corrected, completed, updated or erased; to withdraw consent at any time (this doesn't affect what we did before); to nominate someone to act for you if you die or can't act.
- Complaints: contact our grievance officer first (name to be added after incorporation, support@shejoins.com). We acknowledge within 24 hours and resolve within 15 days. If you're not satisfied, you can complain to the Data Protection Board of India.
United Kingdom (UK GDPR, Data Protection Act 2018) and the European Union, including France (GDPR, Loi Informatique et Libertés).
- Your rights: access, rectification, erasure, restriction, portability, and objection (including to processing based on legitimate interests). You can withdraw consent at any time.
- Complaints: to the ICO (ico.org.uk) in the UK, or the CNIL (cnil.fr) in France.
- In France: you can also give instructions about what happens to your data after your death.
United States (New York). New York has no general consumer privacy law today. We apply the rights in section 9 to everyone. We protect data as the NY SHIELD Act requires, and we'll notify you of a breach as it requires.
11. Age
SheJoins is only for women aged 21 and over. We don't knowingly collect data from anyone younger. Verification checks age against the ID.
12. Changes
We'll tell you in the app before an important change takes effect. The date at the top shows the last update.
13. Contact
SheJoins is operated by Starbrain Technologies OPC Private Limited. Company details: on the Starbrain website (address to follow).
support@shejoins.com · Grievance officer: name to be added after incorporation, support@shejoins.com