Privacy Policy
Effective 22 September 2026 · Version 2026-09-22.2-bf96acfc-3680-464e-875b-6b7f46393b75 · Operator details updated 22 September 2026
Humsafar Tech operates Amdavad Drop. This policy explains what we collect through our directory website and apps, why we use it, who can see it and how to make a request. The service is for adults aged 18 and older. We do not knowingly create accounts for children; contact us if a child’s information has been submitted.
1. Information we collect
- Account: name, email address, verification status and a hashed password if you use email sign-in. Google sign-in provides a Google account identifier, name and verified email. We do not request access to Gmail, Drive, contacts or your Google password, and do not retain Google access or refresh tokens.
- Posts: titles, descriptions, categories, neighbourhoods, service details, pricing, availability, portfolio links, photos and the WhatsApp contact number you choose to supply.
- Member activity: saved posts, blocked-member preferences, reports, moderation decisions and contact-button activity. A contact attempt records the member, post and time; it does not record a conversation or prove that work occurred.
- Consent and support: accepted policy version, acceptance time and method, operator details at acceptance, and information you send when requesting help or exercising rights.
- Technical data: essential session cookies, app authentication tokens, network address and limited server/security logs needed to deliver, troubleshoot and protect the service. We do not collect device location; neighbourhood information is entered by you.
2. Why we use it
We use this information to create and secure accounts, verify email addresses, publish and moderate posts, save items, enable relevant introductions, handle complaints, prevent abuse, record agreement and meet applicable legal obligations. Account processing is necessary to provide the member features you request. Posting contact information is a deliberate choice to make yourself reachable for the purpose described below. We do not use Google data for advertising, sell personal information, or send marketing simply because you joined.
3. What is public and who receives it
Approved listing and needs-board content, including uploaded photos and portfolio links, is public and may be indexed by search engines. Your account email is not shown on public listings. Your stored WhatsApp number is encrypted in our database and disclosed through the contact feature to signed-in, verified members who have accepted our policies. A recipient can retain or forward a number after disclosure; encryption does not prevent that. Only publish contact details you are authorised and willing to share for enquiries.
Authorised administrators can access account, contact, moderation and support records as needed to run the service. Hostinger provides hosting and database infrastructure. Our configured email delivery provider processes transactional emails such as verification and password recovery. Google handles Google sign-in, and WhatsApp receives information when you open its service. Those providers may process data in countries other than India under their own privacy practices and contractual safeguards. We limit data supplied to what the feature requires.
We may disclose relevant information when reasonably necessary to comply with a valid legal request, protect rights or investigate abuse, consistent with applicable law. We do not give members access to other members’ saved lists or internal reports.
4. Cookies and app storage
The website uses essential cookies for sessions, sign-in, request security and interface operation. The app stores its authentication token using device secure storage and caches directory metadata locally. The current directory does not use advertising trackers or optional behavioural analytics. Blocking essential cookies can prevent sign-in. Your browser and device settings let you clear stored data; sign-out also revokes the current app token.
5. Retention and deletion
We keep account data, agreement records, saved items and posts while needed for your account and the features you request. Closed or unpublished posts remain available to you and moderators until deletion. App sign-in tokens expire after 30 days; website sessions normally expire after 2 hours of inactivity.
Deleting your account removes its active database record, posts, saved items, policy acceptance records and uploaded photos, and revokes active sessions and app tokens. References to you in retained contact statistics and reports are unlinked; report text or support correspondence may still contain information you supplied. Relevant complaint, security and legal records may be retained for as long as reasonably needed to resolve an issue or meet a legal obligation, with access restricted. We review deletion requests for those records individually.
Deleted data may persist temporarily in restricted disaster-recovery backups until those backups are replaced or expire under the hosting or backup retention cycle. It is not used for ordinary operations. If a backup is restored, outstanding deletion requests must be reapplied. Copies independently saved by recipients or search engines are outside our control; contact us for help identifying the relevant party.
6. Your choices and requests
You can edit or close your posts, change saved items, manage blocked members, sign out and delete your account in My space. Google-only members can use the password-reset email to set a password and securely confirm account deletion, or request deletion by email. You can withdraw consent by closing or deleting posts, deleting your account, or contacting us. Withdrawal does not undo earlier lawful processing and may mean we cannot continue providing the affected feature.
For access, correction, deletion, a copy of your information, withdrawal, concerns about contact misuse or other rights available under applicable law, email the contact below from your registered address. We may request proportionate information to verify your identity; do not send identity documents unless specifically requested through an appropriate channel. You may nominate someone to act where applicable law provides that right. We aim to acknowledge requests within 3 working days and respond within 30 days, or within any shorter applicable legal deadline. We will explain material limits or lawful reasons for retaining information and how to challenge our response. You may also use any complaint mechanism available under applicable law.
7. Security and changes
We use HTTPS in production, hashed passwords, encrypted stored WhatsApp numbers, restricted administration and checks on access to member features. No service can promise absolute security. Avoid putting sensitive information in public posts and report suspected misuse promptly. We will assess security incidents and notify affected people or authorities when required by applicable law.
We publish policy changes with a new version and require renewed agreement for member features. Changes to the operator’s public contact details are reflected here. Questions, privacy requests and grievances should be addressed to:
Humsafar Tech12/A Prerna Kutir Bunglows, behind Sarthi Hotel, Vastrapur, Ahmedabad, Gujarat 380054, India
Support, privacy, grievance and legal contact: maxsinner@gmail.com