Privacy Policy
What we collect, why, how long we keep it, and your rights under India’s Digital Personal Data Protection Act, 2023.
Draft v0.1 · 7 October 2026
Placeholder draft for the PullUp proof of concept. Not legal advice and not yet reviewed by a lawyer. It must be reviewed and replaced before launch.
The short version
- We collect what we need to sell you tickets safely and get you through the door.
- We never sell your data.
- Contact numbers are hashed on your phone; the raw numbers never leave it.
- From DigiLocker we keep only your verified name, date of birth and a masked document number.
- You can see, correct and delete your data from the app.
What we collect
- Account: name, username, phone number, email, date of birth, gender (optional), profile photo (optional), and your self-declaration that you meet the platform’s minimum age.
- Bookings: orders, tickets, the names of people on group and table bookings, check-in times, refunds and reviews.
- Payments: handled by our payment partner. We receive the payment status, method type and the last digits of a card or UPI ID. We never see or store full card numbers, CVVs or UPI PINs.
- Identity (only when you buy a cover-charge ticket or a table that needs it): your verified name, date of birth, gender and a masked document number (like XXXX-XXXX-1234) from DigiLocker. We don’t receive or store your Aadhaar number or a copy of the document. A verification is reused for 365 days, then expires.
- Location: only while the app is open and only if you allow it, to show events near you. We don’t track your location in the background or store a location history.
- Contacts (optional, "Find friends"): numbers are normalised and turned into one-way SHA-256 hashes on your phone. Only hashes are sent, they are compared and then discarded, and only people who turned on "Find me by phone number" can be matched.
- Device: push notification token, app version, device model and error reports, to deliver notifications and fix crashes.
Hosts
If you run a host profile we also collect KYC details for payouts: legal name, PAN (stored masked), business name and GSTIN if any, and bank account (stored masked) with IFSC, verified through a penny-drop check by our payment partner.
Why we use it
- To create your account and verify your phone and email.
- To issue, secure and check tickets, including offline guest lists on the host’s door device, which are wiped automatically 12 hours after the event.
- To enforce age rules, prevent fraud, double entry and abuse.
- To process payments, refunds and host payouts, and to keep the records tax law requires.
- To show your friends which public events you’re going to, only if you leave "Squad visibility" on.
- To send you booking updates, and promotional notifications you can switch off any time.
Who we share it with
- The host of an event you book: your name, ticket type, check-in status and, for ID-checked tickets, that you are verified (not your document details).
- Service providers who run parts of PullUp for us: hosting and database, payments, SMS and email, identity verification and push notifications, under contracts that limit their use of your data.
- Authorities, when the law requires it.
How long we keep it
Account data is kept while your account exists. When you delete your account we remove your profile, photo, friends, follows and identity verification. Booking and payment records are kept, anonymised, for as long as tax and accounting law requires (typically 8 years), because hosts and refunds rely on them.
Deleting your account
- In the app: Profile → Delete account, then type DELETE. It takes effect immediately.
- Can’t open the app? Email operations@pullupnow.in from the email on your account, or include your phone number, with the subject "Delete my account". We confirm within 7 days.
- Accounts with upcoming tickets can be deleted once those events have passed or been refunded.
Your rights
Under the DPDP Act you can access, correct and erase your personal data, withdraw consent, nominate someone to exercise your rights, and complain to us and then to the Data Protection Board of India. Most of this is self-serve in Profile; anything else, email us.
Security
Data is encrypted in transit and at rest. Ticket secrets are encrypted with keys held only on our servers, every database table is protected by row-level access rules, and staff access is audited.
Children
PullUp is not for anyone under 16. If we learn an account belongs to someone younger, we delete it.
Contact and grievances
Questions, complaints or requests about this document: operations@pullupnow.in. Include the reference code from any error message so we can find your case quickly.
Grievance Officer (IT Rules 2021 and DPDP Act 2023): [name, designation and address to be added before launch]. We acknowledge complaints within 24 hours and resolve them within 15 days.