Privacy Policy
Last updated: March 2026
1. Data We Collect
We collect the following information: (a) Account data — name, email, phone number, profile photo; (b) Event data — event type, date, location, guest count, budget preferences; (c) Payment data — UPI transaction references (UTR numbers), payment amounts; (d) Provider data — bio, categories, pricing tiers, portfolio media, ratings; (e) Usage data — search queries, page views, session cookies.
2. How We Use Your Data
Your data is used to: (a) match you with relevant artists and services; (b) process bookings and payments; (c) send booking confirmations and status updates via email, SMS, and WhatsApp; (d) improve our AI-powered search and recommendations; (e) prevent fraud and ensure platform safety; (f) display provider profiles and reviews to potential clients.
3. Data Sharing
We share your data only as necessary: (a) With booked Providers/Clients — name, contact details, and event information are shared when a booking is confirmed; (b) With service providers — MSG91 (notifications), Supabase (database), Vercel (hosting), Groq (AI); (c) We do not sell your data to third parties.
4. Data Storage & Security
Your data is stored in Supabase (AWS Mumbai region, ap-south-1). All data is encrypted in transit (TLS) and at rest. Row Level Security (RLS) policies ensure users can only access their own data. We use secure authentication via Supabase Auth with support for email, phone OTP, and Google OAuth.
5. Cookies
We use essential cookies for: (a) Supabase authentication session management; (b) maintaining your login state. We do not use third-party tracking cookies or advertising pixels.
6. Data Retention
Account data is retained until you request deletion. Booking history is retained for 3 years for dispute resolution and legal compliance. Anonymized analytics data may be retained indefinitely.
7. Your Rights (DPDP Act 2023)
Under the Digital Personal Data Protection Act 2023, you have the right to: (a) access your personal data; (b) correct inaccurate data; (c) request deletion of your data; (d) withdraw consent for data processing; (e) nominate a person to exercise your rights. To exercise these rights, email privacy@joshoit.com.
8. Children's Privacy
Sohaya is not intended for users under 18. We do not knowingly collect data from minors. If we learn that we have collected data from a child, we will delete it promptly.
9. Changes to This Policy
We may update this policy periodically. Material changes will be communicated via email or in-app notification. Continued use of the platform constitutes acceptance of the updated policy.
10. Contact
Data Protection Officer: privacy@joshoit.com
Sohaya Entertainment Pvt. Ltd., Vasai, Maharashtra, India.