Skip to content
saanjha

Privacy Policy

Version 1.0 · Last updated 2026-08-07

1. Who we are

Saanjha is operated by EVANIK NETWORKS PRIVATE LIMITED ("we", "us"), a company registered in India under CIN U74900DL2016PTC290140, with its registered office at D-79, Sector 2, Noida 201301, Uttar Pradesh, India. We are the Data Fiduciary for the personal data described here, as that term is used in the Digital Personal Data Protection Act, 2023 ("DPDP Act").

Contact: privacy@saanjha.ai

2. What Saanjha does, in brief

Saanjha lets neighbours pool their grocery orders. One member travels to a wholesale market and buys on behalf of others in their community. We coordinate the order, hold the payment until goods are handed over, and maintain the trust signals that make this safe between people who are not close friends.

Understanding that helps explain why we collect what we do: almost all of it exists to make a transaction between two neighbours safe.

3. What we collect, and why

3.1 Information you give us

Data Why Legal basis
Mobile number Your identity on Saanjha. Used to sign in and to reach you about an order. Necessary to provide the service
Name and photo So neighbours know who they are handing goods to Necessary to provide the service
Email address Account recovery and statements Necessary to provide the service
Flat or house number To confirm you live in the community you are joining Necessary to provide the service
Government ID reference, via DigiLocker or a licensed verification partner Required before you can host a trip or handle other members' money Consent, plus legal obligation
Bank account (sellers only) To pay you Necessary to provide the service
Photographs you upload Receipts, and evidence when you report a problem with an order Necessary to resolve disputes
Messages you send Coordinating a trip or pickup Necessary to provide the service
Date of birth To confirm you are old enough to use Saanjha and to apply the protections the DPDP Act requires for children Consent
Names, relationship and dates of birth of the people in your household So your family can be recognised at a pickup and so an order can be collected on your behalf Consent

3.2 Information collected automatically

Data Why
Approximate and precise location, only while the app is open To show communities near you, to confirm you are inside a community boundary, and to corroborate a handover at the pickup point
Device identifiers, model, OS version, app version Security, fraud prevention, crash diagnosis
IP address Security and abuse prevention
App usage events To understand which parts of the product work

3.3 Information about other people

If you list the people in your household, you are giving us personal data about someone other than yourself. Please add someone only if you are entitled to — for an adult, that means they know and agree.

Children. Under the DPDP Act, anyone under 18 is a child, and their data may be processed only with the consent of a parent or lawful guardian. If you add a child to your household you are confirming you are that parent or guardian. We do not use children's data for advertising, we do not track them, and we do not build behavioural profiles of them.

You can remove anyone from your household at any time in the app, and doing so deletes their entry.

We do not collect location in the background. The app cannot track you when it is closed. This is enforced technically, not only by policy: the Android build explicitly blocks the background location permission.

3.3 Contacts

If you choose to invite neighbours from your contacts, your device computes a one-way cryptographic hash of each phone number and sends only those hashes. We never receive or store your contact list, your contacts' names, or the numbers of people who are not Saanjha users.

3.4 What we never collect

  • Your Aadhaar number. Verification is done through DigiLocker or a licensed partner, and we retain only a verification reference and the last four digits.
  • Your card details or UPI PIN. Payments happen inside your bank or UPI app.
  • Your face, as a stored image. If you complete biometric verification, the selfie is compared and then deleted; only the result is retained.
  • Anything from your chats, for advertising purposes. Chat content is never used for targeting.

4. How we use it

To operate trips, orders, payments and handovers. To verify identity and residence. To compute trust scores and badges. To prevent fraud, including detecting fake bids, collusion and manipulated evidence. To resolve disputes. To send you notifications about your orders. To meet legal obligations, including tax and financial record-keeping.

Automated decisions. Some decisions are automated: trust tier, exposure limits, badge eligibility, and the automatic approval of small refund claims. Where an automated decision restricts what you can do, we tell you which rule caused it, and you can appeal to a human.

5. Who we share it with

Recipient What Why
Other members of your community Your name, photo, badges, trust tier, flat number, and your order contents where relevant to a shared trip The service does not work otherwise
Our payment partner, an RBI-authorised payment aggregator Payment details To collect and settle payments
Identity verification partner Verification data To verify you
Delivery partner, if you choose delivery Name, phone, address To deliver
Cloud and communications providers Data necessary to run the service Infrastructure
Law enforcement or regulators Where legally required Legal obligation

We do not sell your personal data. We do not share it with advertisers for their own use.

6. Where it is stored

On servers located in India (AWS Asia Pacific, Mumbai and Hyderabad). We do not transfer personal data outside India except where a service provider requires it and a lawful basis exists.

7. How long we keep it

Data Retained
Order, payment and handover records 8 years, for tax and company law
Verification records 5 years after the relationship ends
Consent records For as long as needed to evidence consent
Chat messages 90 to 180 days
Location captured for an invite 90 days after the invite is resolved
Notification and analytics logs 90 days
Dispute evidence 3 years
Selfie images used for verification Deleted immediately after matching

8. Your rights

Under the DPDP Act you may:

  • Access the personal data we hold about you
  • Correct anything inaccurate or incomplete
  • Erase your data, subject to records we must keep by law
  • Nominate someone to exercise these rights if you die or become incapacitated
  • Withdraw consent at any time, as easily as you gave it
  • Complain to us, and then to the Data Protection Board of India

Use Profile → Settings → Privacy in the app, or write to privacy@saanjha.ai. We respond within 30 days.

To delete your account: https://saanjha.ai/account/delete

9. Consent

We ask for consent separately for each purpose. Consent boxes are never pre-ticked. Declining marketing messages does not affect your ability to use Saanjha — you will still receive messages about your own orders, because those are necessary to provide the service you asked for.

You can change any of this in Settings → Notifications.

10. Children

Saanjha is for people aged 18 and over. We do not knowingly collect data from children. If we learn that we have, we will delete it.

11. Security

Data is encrypted in transit and at rest. Access to personal data by our staff requires a documented reason and is logged. Sensitive fields are masked by default. We run regular security testing.

No system is perfectly secure. If a breach affects you, we will notify you and the Data Protection Board as the law requires.

12. Changes

We will tell you in the app before a material change takes effect, and we keep previous versions available.

13. Contact and complaints

Privacy questions: privacy@saanjha.ai Data Protection Officer: Nikhil Sharma, sharmanikhil7011@gmail.com Grievance Officer: see https://saanjha.ai/legal/grievance

If you are not satisfied with our response, you may complain to the Data Protection Board of India.