Privacy Policy

Last updated: March 2026

1. Data We Collect

We collect the following information: (a) Account data — name, email, phone number, profile photo; (b) Event data — event type, date, location, guest count, budget preferences; (c) Payment data — UPI transaction references (UTR numbers), payment amounts; (d) Provider data — bio, categories, pricing tiers, portfolio media, ratings; (e) Usage data — search queries, page views, session cookies.

2. How We Use Your Data

Your data is used to: (a) match you with relevant artists and services; (b) process bookings and payments; (c) send booking confirmations and status updates via email, SMS, and WhatsApp; (d) improve our AI-powered search and recommendations; (e) prevent fraud and ensure platform safety; (f) display provider profiles and reviews to potential clients.

3. Data Sharing

We share your data only as necessary: (a) With booked Providers/Clients — name, contact details, and event information are shared when a booking is confirmed; (b) With service providers — MSG91 (notifications), Supabase (database), Vercel (hosting), Groq (AI); (c) We do not sell your data to third parties.

4. Data Storage & Security

Your data is stored in Supabase (AWS Mumbai region, ap-south-1). All data is encrypted in transit (TLS) and at rest. Row Level Security (RLS) policies ensure users can only access their own data. We use secure authentication via Supabase Auth with support for email, phone OTP, and Google OAuth.

5. Cookies

We use essential cookies for: (a) Supabase authentication session management; (b) maintaining your login state. We do not use third-party tracking cookies or advertising pixels.

6. Data Retention

Account data is retained until you request deletion. Booking history is retained for 3 years for dispute resolution and legal compliance. Anonymized analytics data may be retained indefinitely.

7. Your Rights (DPDP Act 2023)

Under the Digital Personal Data Protection Act 2023, you have the right to: (a) access your personal data; (b) correct inaccurate data; (c) request deletion of your data; (d) withdraw consent for data processing; (e) nominate a person to exercise your rights. To exercise these rights, email privacy@joshoit.com.

8. Children's Privacy

Sohaya is not intended for users under 18. We do not knowingly collect data from minors. If we learn that we have collected data from a child, we will delete it promptly.

9. Changes to This Policy

We may update this policy periodically. Material changes will be communicated via email or in-app notification. Continued use of the platform constitutes acceptance of the updated policy.

10. Contact

Data Protection Officer: privacy@joshoit.com
Sohaya Entertainment Pvt. Ltd., Vasai, Maharashtra, India.