Privacy Policy
Greatminds Retail Private Limited (“GoWith”, “we”, “us”) is committed to protecting the personal data of every User of the GoWith platform (the “Platform”). This Privacy Policy explains what personal data we collect, why we collect it, how we process and share it, and the rights you have under the Digital Personal Data Protection Act, 2023 (“DPDP Act”) and other applicable Indian laws.
This Policy forms part of our Terms of Service. Please read both together.
1. Data Fiduciary Information
For the purposes of the DPDP Act, GoWith is the Data Fiduciary that determines the purpose and means of processing your personal data. You are the Data Principal. Our contact details:
2. Categories of Personal Data We Collect
2.1 Data you provide directly
- Account data: mobile number, full name, display name, date of birth, city, gender.
- Profile data: profile picture, bio, interests, languages spoken.
- KYC data (Companions only): government photo ID (Aadhaar, PAN, driving licence, or passport), a live selfie captured through the app, and bank account or UPI details.
- Booking data: services booked, times, venues, ratings you give and receive, communications with the other party through the Platform.
- Payment data: card token or UPI reference, transaction records, payout history (Companions).
2.2 Data collected automatically
- Device data: device type, operating system, unique device identifier, IP address, app version.
- Usage data: pages viewed, features used, session duration, referral source.
- Location data: precise GPS location during a Meet (for check-in verification only, never continuously in the background).
- Cookies and similar: session cookies for authentication and preference storage. We do not use third-party advertising cookies.
2.3 Data collected from third parties
- KYC providers: verification outcomes and match confidence scores.
- Payment providers: transaction status, payout confirmations.
3. Purposes of Processing
We process your personal data for the following specified purposes:
- To provide the Platform: creating and managing your account, matching Bookers with Companions, processing Bookings, managing payments and Escrow.
- To verify identity: performing KYC checks on Companions, preventing fraud and impersonation.
- To ensure safety: GPS check-in verification, dispute resolution, monitoring for prohibited conduct.
- To communicate with you: transactional notifications (Booking status, payout confirmations), safety alerts, service updates. Marketing communications are sent only with your consent.
- To comply with law: tax reporting (including TDS under Section 194O), responding to lawful requests from authorities, maintaining records required by the IT Act and DPDP Act.
- To improve the Platform: analysing aggregated, anonymised usage patterns.
4. Legal Bases for Processing
Under Section 4 of the DPDP Act, we process your personal data on the following bases:
- Consent: for KYC document collection, marketing communications, and any processing you specifically opt in to.
- Legitimate uses (Section 7): for performing the Platform contract you enter into by signing up; for compliance with legal obligations; for responding to medical or safety emergencies; for the fulfilment of any employment-related obligation to Companions.
5. Sharing of Personal Data
We share your personal data only in the following circumstances:
- With the other party to a Booking: your display name, profile photo, city, and rating are visible to Companions when you book them (and vice versa). Full contact details are never shared.
- With service providers: KYC verification providers, payment processors (RazorpayX), cloud infrastructure (AWS ap-south-1, Mumbai region), SMS and email providers, analytics providers — all bound by contractual data protection obligations.
- With law enforcement: when required by valid legal process, court order, or to prevent imminent harm.
- In a business transfer: in the event of a merger, acquisition, or asset sale, personal data may be transferred subject to appropriate protections and prior notice to Users.
We do not sell your personal data to third parties for advertising or any other purpose.
6. Cross-Border Data Transfer
Personal data is primarily stored on servers located in India (AWS ap-south-1, Mumbai region). Where any processor requires temporary access from outside India, transfers are made only to jurisdictions permitted under the DPDP Act and Central Government notifications, subject to contractual safeguards equivalent to Indian data protection standards.
7. Data Retention
- Active account data: retained while your account is active.
- KYC documents: retained for the duration of Companion status plus five (5) years, in accordance with Prevention of Money Laundering Act record-keeping requirements.
- Booking and transaction records: retained for eight (8) years in accordance with the Income Tax Act and GST record-keeping requirements.
- Support and safety records: retained for three (3) years post resolution.
- Marketing communication logs: retained until consent is withdrawn.
On account closure, personal data not required for legal retention is deleted or anonymised within thirty (30) days.
8. Your Rights as a Data Principal (DPDP Act)
Under Chapter III of the DPDP Act, you have the following rights:
- Right to information: to receive a summary of the personal data being processed and processing activities undertaken.
- Right to correction and erasure: to correct inaccurate or misleading data, complete incomplete data, update data that has become outdated, and request erasure of data that is no longer necessary.
- Right to grievance redressal: to raise a complaint about the processing of your personal data (see Section 11).
- Right to nominate: to nominate any other individual to exercise your rights in the event of your death or incapacity.
- Right to withdraw consent: at any time, subject to lawful consequences (e.g., withdrawing KYC consent as a Companion will end your ability to accept Bookings).
To exercise any right, contact our Data Protection Officer (Section 11) or submit a request through the app under Settings → Privacy.
9. Security of Personal Data
We implement reasonable technical and organisational security measures under Section 8(5) of the DPDP Act, including:
- Encryption of data in transit (TLS 1.2+);
- Encryption at rest for sensitive fields including KYC documents and payment tokens;
- Role-based access controls limiting employee access to personal data on a need-to-know basis;
- Regular security audits and vulnerability testing;
- Incident response procedures with 72-hour breach notification.
In the event of a personal data breach that is likely to result in harm to you, we will notify the Data Protection Board of India and affected Data Principals in accordance with Section 8(6) of the DPDP Act.
10. Children
The Platform is not intended for use by individuals under 18 years of age. We do not knowingly collect personal data of minors. If we become aware that a User is under 18, their account will be terminated and all personal data deleted immediately.
11. Data Protection Officer and Grievance Redressal
You may contact our Data Protection Officer for any query or grievance relating to your personal data:
If you are dissatisfied with our response, you may lodge a complaint with the Data Protection Board of India established under the DPDP Act.
12. Changes to this Policy
We may update this Privacy Policy from time to time. Material changes will be notified via in-app notice or email at least fourteen (14) days prior to taking effect. The “Last updated” date at the top will reflect the latest revision.