← Back to Fondue

Legal

Privacy Policy

Effective 17 September 2026 — first draft, pending legal review (see note below).

A note on this document. This policy was drafted to accurately reflect what Fondue actually collects and does, and to follow the Digital Personal Data Protection Act, 2023 and its 2025 Rules. It has not yet been reviewed by an India-qualified lawyer, and a few specific details (marked “PLACEHOLDER”) are still open. Please get it reviewed before treating it as final, especially given Fondue handles biometric verification and payments.

1. Who this policy covers

This Privacy Policy explains how Fondue Collective Private Limited (“Fondue,” “we,” “us”) collects, uses, shares, and protects personal data when you use the Fondue app and website (app.thefondue.in and any successor domain, together the “Service”). Fondue is an invitation-led, IRL-first connection platform for people in India, built around a deliberately different safety model from typical dating or social apps — this policy explains that model in plain terms, not just the legal minimum.

By applying to or using Fondue, you agree to the collection and use of information as described here. If you don’t agree, please don’t use the Service.

2. What we collect

Account & contact. Email address, phone number (verified by one-time code), and your Google account identifier if you sign in with Google.

Application & profile. Name, date of birth, gender, orientation, city, occupation, relationship status, what you’re looking for, free-text answers about how dating has felt for you, your values and non-negotiables, what you’re proud of, three words that describe you, the “circles”/interest scenes you pick, an optional referral (“vouched by”), and your stated faith if you choose to share it (never used to filter or match you).

Anti-discrimination confirmation. We ask every applicant to affirm they won’t use Fondue to match on caste, community, or religion. We record that you agreed, not a caste category — Fondue does not collect, store, or use caste data for matching, full stop.

Identity verification (biometric). To confirm you’re a real person, we run a live liveness check and a face-match against your own application photo at signup, using third-party verification services. This is verify-then-discard: the biometric scan itself is used only for that one verification and is not retained by Fondue afterward — see “How long we keep it” below for the exact window.

Photos. Your application photo (never shown to anyone else on Fondue) and a separate discovery photo (shown to a candidate only under the asymmetric-reveal rules described in Section 5).

Social accounts. If you choose to connect LinkedIn, Spotify, X, Instagram, or Substack, we use that connection to help confirm you’re a real person and as part of how we vet applications — we don’t post on your behalf, and none of it is shown to another member before you both agree to meet. You can disconnect any single account at any time from Settings, with one condition disclosed upfront: an active profile needs at least one connected account, so you can’t disconnect your last one without first connecting another (this keeps every active profile behind a real, verifiable person). Disconnecting clears that account’s stored handle, not just its status.

Location. Coarse, city-area-level location, captured only when you actively turn on “Open to meet nearby,” and only for as long as you leave that on. Your precise location is never stored, never shown to anyone, and never reconstructable from what we do store — see Section 5.

Payment information. When you confirm a plan, a small token fee is processed through Razorpay, our payment partner. Fondue never sees or stores your card, UPI, or bank details — Razorpay handles that directly under its own PCI-compliant systems; we only receive confirmation that a payment succeeded.

Safety reports. If you report that “something felt off,” we record what you tell us, who it’s about, and the outcome, so we can act on it and, where needed, involve the people responsible for your safety on our team.

Usage & device data. Push-notification tokens (if you opt in), basic app-usage logs, and standard device/browser information collected automatically for security and reliability.

3. Why we collect it (and your consent)

Under the Digital Personal Data Protection Act, 2023, we only process your personal data on the basis of your consent, which must be free, specific, informed, unconditional, and given through a clear affirmative action — not assumed from silence or a pre-ticked box. We ask for that consent at each relevant step (for example, separately for location, for identity verification, and for notifications), and we tell you what it’s for when we ask.

We use your data only for the purposes it was collected for: running your application and vetting, operating discovery and the handshake, processing payments for confirmed plans, keeping the community safe, and communicating with you about your account and plans. We do not use your data for advertising, and we do not sell it.

Withdrawing consent. You can withdraw consent for a specific use (for example, turning location off, or disconnecting a social account) at any time in the app. Withdrawing consent doesn’t affect anything we did with your data before you withdrew it, and may mean some parts of the Service stop working for you until you consent again.

4. How long we keep it

We keep personal data only as long as we need it for the purpose it was collected, or as required by law. As a first-draft schedule — PLACEHOLDER, pending a real data-retention policy decision:

  • Liveness/face-match biometric scans: discarded immediately after the one-time verification completes, not retained.
  • Live location: never stored — only used in the moment to compute your coarse area, then discarded.
  • Application data for declined or withdrawn applicants: retained for a limited period to handle re-applications and prevent abuse, then deleted.
  • Active member profile & activity data: retained while your account is active, plus a limited period after deletion to handle disputes, safety follow-ups, and legal obligations.
  • Payment confirmations: retained as required under Indian financial record-keeping law.
  • Safety reports and blocks: retained indefinitely where needed to keep a repeat offender from re-entering the platform.

5. Fondue’s safety model, and what this means for your data

This is the part that makes Fondue different from most dating and social apps, and it’s a real, enforced part of how the Service works, not just a policy statement:

  • Your exact location is never shared with another member, ever — not a match, not a candidate, not anyone you could ever be connected to through discovery or the handshake. What’s shared when you open up to someone is a public venue you chose, a time, and an optional short note — never your position.
  • Visibility is asymmetric by design in our proximity-based (Hyperlocal) mode: women see who’s open nearby and choose; men see nothing about a specific woman until she reaches out. This is enforced at the database level, not just hidden in the app.
  • No in-app messaging. Contact happens through a structured handshake only — an optional short note, a yes/no, then a mutually agreed public venue and time. Free-form chat doesn’t exist on Fondue, so there’s no message history to protect or leak.
  • Photos are asymmetric. A candidate’s photo is visible to you when you’re considering them; your own photo is revealed to them only once you choose to reach out.
  • Rejections are absorbed silently. If someone says no, you are never shown that — you simply move on.
  • You can report and block at any time. A safety report triggers a review by our team and can result in a permanent block between the two people involved.

6. Who we share your data with

We never sell your personal data, and we never share it with advertisers. We share it only with:

  • Other members, strictly within the limits described in Section 5 above — never your location, never more than the structured handshake permits.
  • Service providers who process data on our behalf under contract, including our database and hosting infrastructure (Supabase, Vercel), email delivery (Resend), payment processing (Razorpay), identity/liveness verification providers, phone verification (Twilio), and, if you connect it, Strava.
  • Law enforcement or regulators, only where we’re legally required to, or to protect the safety of our members.
  • Your Safety Circle — but only if this feature is live and only for peers you’ve explicitly and mutually added, and only the specific plan details you choose to share with them per date. Your Safety Circle can never see your dating activity, and can never be reached through, or reach you through, dating discovery or the handshake.

7. Where your data is processed

Some of our service providers process data outside India. Under the DPDP Act, cross-border transfer of personal data is generally permitted except to countries the Indian government restricts by notification. We only work with providers who maintain appropriate security safeguards, and we’ll update this section if that list of restricted countries affects any provider we use.

8. Your rights

Under the DPDP Act, you have the right to:

  • Access a summary of the personal data we hold about you and how it’s being processed.
  • Correct or update inaccurate or incomplete data.
  • Request erasure of your personal data, subject to what we’re legally required to keep (see Section 4).
  • Withdraw consent at any time (see Section 3).
  • Nominate another individual to exercise these rights on your behalf in the event of your death or incapacity.
  • Register a complaint with us first, and if unresolved, escalate to the Data Protection Board of India.

To exercise any of these, contact us using the details in Section 11.

9. Children

Fondue is strictly for people 18 years and older. We do not knowingly collect personal data from anyone under 18. If we learn that we have, we’ll delete it promptly.

10. Security

We use industry-standard technical and organizational safeguards — encryption in transit, access controls, and database-level permission rules that restrict who can see what, enforced on our servers rather than left to the app alone. No system is perfectly secure, and if a data breach occurs that affects you, we’ll notify you and the Data Protection Board of India as required by law.

11. Grievance Officer & contact

Under the Information Technology (Intermediary Guidelines) Rules, 2021 and the DPDP Act, we’ve appointed a Grievance Officer you can reach with any privacy question, complaint, or data-rights request:

Kavya Narukurti (Founder — PLACEHOLDER: formal Grievance Officer designation pending)
Email: kavyanarukurti@thefondue.in
Fondue Collective Private Limited
PLACEHOLDER: registered office address

We’ll acknowledge your complaint within 24 hours and aim to resolve it within 15 days, per the IT Rules.

12. Changes to this policy

We may update this policy as Fondue evolves. We’ll post the updated version here with a new effective date, and where a change is material, we’ll let you know directly.