Privacy Policy

    Version 3.3

    PIKANDO™ DIGITAL PRIVATE LIMITED

    CIN: U62099KA2025PTC202253 | GSTIN: 29AAPCP7341B1Z8

    #17, 2nd Floor, 7th Main Road, II Stage, Indiranagar, Bengaluru - 560038, Karnataka, India

    PRIVACY POLICY

    For Posters and Seekers

    • Effective Date: 22nd June 2026
    • Version: 3.3
    • Last Updated: 9th July 2026
    • Supersedes: Privacy Policy v2.0 (February 2026), Biometric Data and Consent Policy v1.0 (January 2026)

    1. Introduction

    Pikando Digital Private Limited (“Pikando”, “we”, “us”, or “our”) respects your privacy and is committed to protecting your personal data. This Privacy Policy describes how we collect, use, share, store, and protect your information when you use the Pikando platform (our mobile application on iOS and Android), our websites (including pikando.com and the SOS location-sharing web pages), and any related services (collectively, the “Platform”).

    This Policy explains your rights under Indian law, including the Digital Personal Data Protection Act, 2023 (“DPDP Act”), the Digital Personal Data Protection Rules, 2025 (“DPDP Rules”), the Information Technology Act, 2000, and associated rules, and how you can exercise those rights.

    This Policy applies to all users of Pikando in India, including Posters (task creators) and Seekers (independent service providers). By using Pikando, you agree to the collection and use of your information in accordance with this Privacy Policy and our Terms of Service. If you do not agree, please do not use the Platform.

    This Privacy Policy incorporates and replaces the previously separate Biometric Data and Consent Policy. All biometric data handling is now covered in Sections 4 and 7 of this document.

    2. Information We Collect

    2.1 Information You Provide Directly

    Account Information: When you register on Pikando, we collect your name, mobile number, and email (your mobile number and email are verified via OTP). If you register as a Seeker, you will provide additional details such as your skills, work experience, service categories, availability, and professional certifications where required.

    Identity Verification (KYC) Data: To ensure trust and safety, Seekers undergo identity verification through our authorised verification partner. Verification may include Aadhaar, PAN, DigiLocker records, facial verification, liveness checks, or other government-issued identity documents and verification methods as determined by Pikando or its verification partners. For details on biometric data handling, see Section 4.

    Background Verification Data: Depending on the task category, Seekers may undergo background verification through our partner, which may include police clearance verification (PCC), court record verification (CCRV), and address verification. Verification requirements are category-specific and based on Pikando’s tiered verification framework.

    Task Information: When Posters create task listings, any information input about the task (description, budget, location, milestones) is stored. When Seekers make offers or communicate about a task, the information shared (offer amount, messages) is collected.

    Payment Information: Payment processing is handled through our licensed Payment Aggregator. For Posters, payment instrument details (UPI, debit/credit card, net banking) are collected and processed securely by our payment partner. Pikando does not store full card details. For Seekers, we collect bank account details or UPI ID for transferring earnings. PAN verification status is stored for tax compliance purposes (the actual PAN number is not stored, only a verified/not-verified boolean).

    Communications: Messages exchanged through the in-app chat, support requests, and feedback submitted through the Platform. For in-app voice calls between a matched Poster and Seeker, we process call metadata (participants, timing, and call status) through our calling provider. In-app voice calls are not recorded; no call audio is stored by Pikando or its calling provider.

    2.2 Information We Collect Automatically

    Device and Log Information: Device type, operating system version, unique device identifiers, app version, IP address, time and date of access, and screens viewed.

    Location Data: With your explicit permission, we collect precise geolocation data for task location matching, face verification at task locations, and safety features (SOS). You can control location sharing via your device settings. Disabling location services may limit certain Platform features.

    Usage Analytics: Anonymised and aggregated data about how users interact with the Platform, used to improve features and user experience.

    2.3 Information from Third Parties

    Verification Partners: With your consent, we receive verification results including authentication status, face match results, liveness detection results, and background check outcomes. We receive only verification outcomes and reference tokens, not raw biometric data or identity document numbers.

    Payment Partner: We receive transaction status, payment confirmations, and payout status from our Payment Aggregator, which is licensed and regulated by the Reserve Bank of India.

    3. How We Use Your Information

    3.1 To Provide and Operate the Platform

    • Account creation, authentication, and identity verification
    • Matching Seekers with relevant tasks and displaying profiles
    • Processing payments, holding funds, and transferring earnings
    • Enabling in-app communication between Posters and Seekers
    • Sending transactional notifications (task confirmations, payment updates, safety alerts)

    3.2 To Ensure Trust, Safety, and Verification

    • Verifying Seeker identity at onboarding and at task locations
    • Processing category-specific background verification (PCC, CCRV)
    • Monitoring for fraud, abuse, and policy violations
    • Operating the SOS and emergency assistance feature
    • Algorithmic ranking, matching, and display of Seekers and tasks based on verification status, ratings, proximity, and other relevance signals

    3.3 To Improve and Personalise Services

    • Analytics and research to improve Platform features and user experience
    • Recommending relevant tasks to Seekers and suitable Seekers to Posters
    • We do not currently send marketing communications. If marketing communications are introduced in the future, they will be sent only with your consent and with easy opt-out options.

    3.4 Legal Compliance

    • Complying with applicable Indian laws including the DPDP Act, IT Act, Income Tax Act 2025, CGST Act, and RBI regulations
    • Responding to lawful requests from government authorities, courts, or the Data Protection Board of India
    • Tax deductions (TDS) and tax collection (TCS) as required by law
    • Enforcing our Terms of Service and protecting our legal rights
    • Preserving evidence for dispute resolution, fraud prevention, and law enforcement purposes

    4. Biometric and Facial Data

    This section specifically addresses how we handle biometric and facial data in compliance with the DPDP Act 2023, DPDP Rules 2025, and UIDAI guidelines.

    4.1 Types of Facial Data Processed

    Onboarding Verification: A live photograph is captured during identity verification for face match and liveness detection. This photograph is securely stored as your verification reference image and is used as the reference for subsequent identity checks. With your separate, explicit consent, the same photograph may also be set as your initial profile picture on the Platform. Your verification reference image and your profile picture are distinct images, each governed by its own consent; changing your profile picture does not change your verification reference image.

    Location-Based Verification: When a Seeker arrives at a task location for in-person tasks, a real-time facial image is captured and compared against your verification reference image (the photograph captured during onboarding verification). The arrival verification image is deleted immediately after matching.

    Profile Picture Updates: If a verified Seeker changes their profile picture, the new photograph is compared against the verification reference image through our authorised verification partner to confirm that it shows the verified account holder and to prevent impersonation. Repeated failed matches may temporarily restrict further profile picture changes.

    4.2 What We Store

    • Verification status (verified / not verified)
    • Tokenized verification reference (not your actual Aadhaar number)
    • Demographic details (name, date of birth, address: without Aadhaar number mapping)
    • Your verification reference image (the photograph captured during onboarding verification, used for subsequent identity checks)
    • Your profile photograph (stored with your explicit consent; you can change it at any time)
    • Verification timestamps and transaction references for audit purposes

    4.3 What We Do NOT Store

    • Actual Aadhaar numbers (only a tokenized verification reference)
    • Core biometric information (fingerprints, iris scans)
    • Arrival verification images (deleted immediately after face match)
    • OTPs or authentication credentials beyond the session

    4.4 Consent for Biometric Processing

    We obtain explicit, informed consent before any biometric or facial data processing. Consent is obtained separately for onboarding verification (identity verification when registering as a Seeker), use of your verification photograph as your profile picture, and location-based face verification at task locations.

    You may withdraw consent at any time. However, withdrawing consent for mandatory verification will result in suspension of your Seeker account. Your biometric-related data will be deleted within 48 hours of processing your withdrawal request, except where retention is required by law. Any earnings or balances in your account will remain accessible and can be withdrawn.

    5. Legal Basis for Processing

    Under the DPDP Act 2023, we process your personal data on the following legal bases:

    • Consent (Section 6, DPDP Act): Biometric data, location data, profile photo (Identity verification, location-based verification, personalised recommendations)
    • Legitimate Use (Section 7, DPDP Act): Account data, task data, communications, payment data (Platform operations, transaction processing, safety, legal compliance)
    • Legal Obligation: PAN verification, earnings data, transaction records (Tax compliance (TDS/TCS under Income Tax Act 2025, GST obligations))
    • Contractual Necessity: Account data, verification status, payment details (Performance of the agreement between you and Pikando)

    6. Data Sharing and Disclosure

    Pikando does not sell your personal data. We share your information only in the following circumstances:

    6.1 With Other Users

    To facilitate the marketplace: Seeker profiles (name, profile photo, skills, ratings, verification badges) are visible to Posters. Once a task is assigned, limited contact information may be exchanged to facilitate service delivery. Task details and locations are shared with assigned Seekers.

    With your emergency contacts: If you trigger the SOS feature, your live location (updated periodically for the duration of the SOS session) and relevant task details are shared with the emergency contacts you have designated in the app and with Pikando’s safety team, including via a web link viewable by those contacts.

    6.2 With Service Providers and Partners

    • Verification Partner (Identity): Aadhaar/PAN/face verification, liveness detection (Identity details for verification (processed, not stored by Pikando))
    • Verification Partner (Background): Police clearance, court record verification (Identity details for background checks)
    • Payment Aggregator (RBI-licensed): Payment processing, fund holding, payouts (Payment details, bank account information)
    • Cloud Infrastructure Provider: Hosting and data storage (India region) (All platform data (encrypted at rest))
    • Notification and Chat Services: Push notifications, real-time chat (Device tokens, messages)
    • Voice Calling Provider: In-app voice calls between matched Posters and Seekers (User ID, first name, device push tokens, call signalling metadata (calls are not recorded; no call audio))
    • Mapping Services Provider: Address search, autocomplete, and geocoding for task locations (Location search text and coordinates)
    • Customer Support & Live Chat Provider: In-app/web support chat and ticketing (Name, contact details, support conversation content)

    All third-party service providers are bound by data processing agreements requiring them to maintain confidentiality, implement appropriate security measures, and process data only for the specified purposes in accordance with applicable laws.

    6.3 For Legal and Compliance Reasons

    We may preserve, disclose, or share your information if required by law, court order, or government directive, or where Pikando reasonably believes disclosure is necessary for the prevention, detection, or investigation of offences, protection of user safety, fraud prevention, compliance with tax obligations, or response to lawful requests from government authorities including the Data Protection Board of India.

    6.4 Business Transfers

    In the event of a merger, acquisition, or sale of assets, user information may be transferred to the successor entity. We will notify you of any such change and ensure the successor honours this Privacy Policy or obtains fresh consent.

    7. Data Storage, Security, and Retention

    7.1 Data Location

    Your personal data is stored on servers located in India. We comply with data localisation requirements under Indian law. Any cross-border data transfer, if required, will be done only in compliance with the DPDP Act’s provisions on permitted jurisdictions as notified by the Central Government.

    7.2 Security Measures

    • Encryption: All communications encrypted via HTTPS/TLS. Sensitive data encrypted at rest.
    • Access Controls: Role-based access control (RBAC) limits data access to authorised personnel only.
    • Security Standards: We implement reasonable security practices as required under the IT Act and align with industry standards.
    • Data Breach Response: Documented incident response procedures with notification to the Data Protection Board of India and affected users as required by the DPDP Act and DPDP Rules.

    7.3 Retention Periods

    • Account Data: Duration of active account + 3 years after deletion (Contractual + legal compliance)
    • Transaction and Payment Data: 8 years from transaction date (Income Tax Act 2025, GST regulations)
    • Verification Records (KYC): 5 years after account closure (KYC/AML requirements)
    • Verification Reference Image: Duration of active account; deleted within 48 hours of verification-consent withdrawal or account deletion (Consent)
    • Profile Photograph: Duration of active account; deleted within 48 hours of consent withdrawal or account deletion (Consent)
    • Arrival Verification Images: Not retained; deleted immediately after face match (N/A)
    • In-App Chat / Communications: Duration of active account + 180 days after task completion (IT Intermediary Rules, dispute resolution)
    • Dispute Evidence: 3 years from dispute resolution (Legal compliance, audit)
    • Device and Usage Logs: 12 months (Security, analytics)
    • SOS Session Data (location trail, alerts): 180 days, or until resolution of any linked incident, report, or legal hold (Safety, evidence preservation (aligned with IT Rules retention windows))
    • Marketing Consent Records (if marketing is introduced): Duration of consent + 1 year (DPDP Act compliance)

    Upon account deletion or consent withdrawal, we will delete your data within the timeframes specified above, except where retention is required by law. Data that must be retained for legal purposes will be archived securely and will not be used for any other purpose.

    8. Your Rights as a Data Principal

    Under the DPDP Act, 2023 and DPDP Rules, 2025, you have the following rights:

    • Right to Access: You have the right to know what personal data we hold about you and to obtain a summary. You can request this through the app or by contacting us.
    • Right to Correction: You can request correction of inaccurate or outdated personal data. Many fields can be edited directly in the app.
    • Right to Erasure: You may request deletion of your personal data, subject to legal retention requirements. You can use the ‘Delete Account’ option in the app or contact support@pikando.com.
    • Right to Withdraw Consent: Where we rely on consent (biometric processing, location data), you can withdraw it at any time. Withdrawal will not affect processing done before withdrawal but may affect your ability to use certain Platform features.
    • Right to Grievance Redressal: You can escalate concerns to our Grievance Officer, and if unresolved, to the Data Protection Board of India through its online portal.
    • Right to Nominate: You may nominate another individual to exercise your rights in case of your death or incapacity, as provided under the DPDP Act.

    Response Timeline: We will acknowledge your request within 24 hours and respond within 30 days. We may need to verify your identity before processing certain requests. If a request is complex or requires coordination with third-party processors, we will inform you of any expected delay.

    9. Children’s Privacy

    The Platform is not intended for use by individuals under the age of 18. We do not knowingly collect personal data from children. If you are under 18, you should not create an account or use our services. If we become aware that we have collected personal data from a minor, we will take immediate steps to delete such information. If a minor is the beneficiary of a service (e.g., tutoring arranged by a parent), the account must be held by the parent or guardian, who is responsible for providing verifiable consent as required under the DPDP Act.

    10. Automated Decision-Making and Profiling

    Pikando uses automated systems for content moderation (detecting prohibited listings and policy violations), fraud detection (identifying suspicious transaction patterns and account behaviour), algorithmic ranking and matching (determining task visibility, Seeker display order, and search results), and trust scoring (considering ratings, complaints, dispute history, and cancellation patterns for enforcement decisions).

    These automated processes may affect your experience on the Platform, including account restrictions or content removal. You may request human review of any automated decision by contacting us via in-app support chat or by contacting us by email at support@pikando.com.

    11. Cross-Border Data Transfers

    Your personal data is primarily stored and processed within India. If cross-border transfer becomes necessary (for example, if a third-party service provider processes data outside India), such transfer will only occur to jurisdictions permitted by the Central Government under the DPDP Act, or where the transfer is necessary for the performance of a contract or compliance with legal obligations. We will ensure that appropriate safeguards are in place to protect your data during any such transfer.

    12. Data Breach Notification

    In the event of a personal data breach, Pikando will notify the Data Protection Board of India as required under the DPDP Act and DPDP Rules, notify affected Data Principals (users) whose personal data may have been compromised, and provide details including the nature of the breach, likely consequences, and measures taken to mitigate the impact. We maintain documented incident response procedures to minimise impact and prevent recurrence.

    13. Updates to This Policy

    We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. Material changes will be notified through the app or via SMS at least 15 days before taking effect. The ‘Effective Date’ at the top indicates when the current Policy came into effect. Continued use of Pikando after an update constitutes your acceptance of the changes. Where required by law, we will obtain fresh consent for any new or expanded data processing.

    14. Language

    This Privacy Policy is provided in English, Hindi (हिन्दी), and Kannada (ಕನ್ನಡ). The English version is the authoritative reference version. We have taken care to ensure the Hindi and Kannada versions convey the same meaning; if you notice any discrepancy, or if anything about how we handle your data is unclear in your language, contact us at privacy@pikando.com before you proceed. In the event of a conflict in interpretation, the English version prevails, except where applicable law requires the version in your chosen language to govern.

    15. Contact Information and Grievance Officer

    • General Support: support@pikando.com
    • Grievance Officer: Nithyananda Kotian, nithyananda.kotian@pikando.com
    • Data Protection Queries: privacy@pikando.com
    • Registered Office: #17, 2nd Floor, 7th Main Road, II Stage, Indiranagar, Bengaluru - 560038, Karnataka
    • CIN: U62099KA2025PTC202253
    • GSTIN: 29AAPCP7341B1Z8

    Grievance Officer response time: Acknowledgment within 24 hours; resolution within 15 days (or 30 days for DPDP Act data requests). If you are not satisfied with the resolution, you may escalate to the Data Protection Board of India.

    16. Applicable Legal Framework

    • Digital Personal Data Protection Act, 2023
    • Digital Personal Data Protection Rules, 2025
    • Information Technology Act, 2000
    • Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011
    • Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021
    • Consumer Protection Act, 2019
    • Consumer Protection (E-Commerce) Rules, 2020
    • Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act, 2016
    • Income Tax Act, 2025 (applicable TDS/TCS provisions)
    • Central Goods and Services Tax Act, 2017
    • RBI Master Direction on Regulation of Payment Aggregators

    By using the Pikando Platform, you acknowledge that you have read and understood this Privacy Policy.

    © 2026 Pikando Digital Private Limited. All rights reserved.