Privacy Policy
Last updated: August 24, 2026
This Privacy Policy describes how SangiNepal Pvt. Ltd. (“SangiNepal”, “we”, “us”) collects, uses, discloses, and safeguards your personal data in connection with the SangiNepal platform. This policy is issued in compliance with the Privacy Act 2075 (2018) of Nepal, the Electronic Transactions Act 2063, and applicable international best practices.
1. Data Controller & Data Residency
SangiNepal Pvt. Ltd., with its registered office in Kathmandu, Nepal, is the Data Controller of personal data collected through this platform. In compliance with the Privacy Act 2075, personal data of Nepali citizens and residents is stored and processed primarily within Nepal. Where cross-border processing is necessary (e.g., Cloudinary image hosting, AWS Rekognition for face matching), we ensure that recipients are bound by contractual data protection obligations consistent with Nepali law.
The Department of Information Technology under the Ministry of Communication and Information Technology may be contacted regarding data protection concerns at the Government of Nepal’s designated contact points.
2. Personal Data We Collect
2.1 Data You Provide
- Account data: full name, email, phone number, date of birth, password hash.
- Profile data: display name, bio, city, languages, hourly rate, profile photos, cover photos, gallery photos.
- Identity documents: citizenship/passport/NID (front and back), live selfie. These are uploaded as private authenticated documents and auto-deleted after verification approval.
- Booking data: purpose of booking, date, time, hours, notes, payment method, payment reference.
- Chat data: text messages, images, audio, and reactions exchanged within bookings.
- Call data: call logs (caller, callee, type, duration) — we do not record audio or video of in-app calls.
2.2 Data Collected Automatically
- Device & usage data: IP address, browser type, operating system, page views, click events, session duration.
- Location data: only when you actively trigger SOS — your live GPS coordinates are shared with your designated emergency contacts and SangiNepal admin for the duration of the booking.
- Push notification tokens: for delivering booking reminders and chat notifications.
- Cookies: session cookies for authentication. We do not use third-party advertising cookies.
2.3 AI-Processed Data
During identity verification, we use AI to extract the following from your uploaded ID: full name, date of birth, ID number, document type, and a face-match score comparing your selfie to the ID photo. This data is stored on the verification record and shown to the admin reviewer. After approval, the raw ID document and selfie images are deleted; the extracted text data is retained for audit purposes for 7 years per Nepali tax law.
3. Legal Basis for Processing
Under the Privacy Act 2075, we process your personal data on the following legal bases:
- Consent: you provide express consent at registration by accepting these Terms and this Privacy Policy.
- Contractual necessity: processing is required to fulfill our contractual obligations to you (booking, payment, verification).
- Legal obligation: we are required by Nepali tax law, anti-money-laundering regulations, and law-enforcement requests to retain certain records.
- Legitimate interest: fraud prevention, platform security, and abuse detection.
- Vital interest: SOS alerts and emergency response to protect your physical safety.
4. How We Use Your Data
- To create and manage your account and authenticate your identity.
- To match clients with companions and facilitate bookings.
- To process payments and issue invoices (including VAT-compliant invoices where applicable).
- To enable real-time chat and audio/video calls between client and companion.
- To send booking confirmations, reminders, and critical safety notifications via email, SMS (Sparrow SMS), and web push.
- To verify identity and prevent fraud, fake accounts, and prohibited content.
- To investigate incidents, abuse reports, and disputes.
- To comply with legal obligations under Nepali law.
- To improve our services through aggregated, anonymized analytics.
5. Data Sharing & Disclosure
We do not sell your personal data. We share data only with:
- Service providers: Cloudinary (image storage), Sparrow SMS (SMS delivery), eSewa/Khalti (payment processing). All providers are bound by data protection agreements.
- Your booking counterparty: your companion or client sees your display name, profile photo, and (during a confirmed booking) your chat messages and call audio/video.
- Your emergency contacts: only when you trigger SOS — they receive your live location.
- Nepali law enforcement: in response to lawful requests under the Electronic Transactions Act 2063 or where required for criminal investigation.
- Successors in business: in the event of merger, acquisition, or asset sale, data may transfer to the successor entity under the same protections.
6. Data Retention
| Data type | Retention period |
|---|---|
| Account data (after deletion) | 30 days (soft delete), then permanently erased |
| ID documents (after verification) | Immediately deleted from storage; extracted text kept 7 years |
| Chat messages | 2 years after booking ends |
| Call logs (no audio/video) | 2 years |
| Payment & invoice records | 7 years (Nepal Income Tax Act requirement) |
| SMS logs | 1 year |
| Audit logs | 3 years |
7. Your Rights Under the Privacy Act 2075
You have the following rights regarding your personal data:
- Right of access: request a copy of all personal data we hold about you.
- Right to rectification: correct inaccurate or incomplete data.
- Right to erasure: request deletion of your account and associated data (subject to legal retention requirements).
- Right to data portability: receive your data in a machine-readable format.
- Right to object: object to processing based on legitimate interests.
- Right to withdraw consent: at any time, without affecting lawfulness of prior processing.
- Right to lodge a complaint: with the Department of Information Technology, Government of Nepal.
To exercise any of these rights, email privacy@sanginepal.np. We respond within 30 days.
8. Security Measures
We implement industry-standard technical and organizational measures:
- Encryption: all data in transit uses TLS 1.3; passwords are hashed with bcrypt (12 rounds).
- Access control: role-based access (CLIENT/COMPANION/ADMIN), session tokens, rate limiting on 25+ sensitive endpoints.
- Private storage: ID documents and selfies are stored as Cloudinary “authenticated” resources — not accessible by public URL. Signed URLs expire in 60 seconds.
- Content moderation: profanity filter + suspicious pattern detection on chat messages.
- Audit trail: all admin actions (verification review, refund approval, config changes) are logged.
- Regular review: security audits conducted before major releases.
Despite these measures, no system is 100% secure. In the event of a data breach affecting your rights under the Privacy Act 2075, we will notify you and the Department of Information Technology within 72 hours of becoming aware of the breach.
9. International Transfers
Where personal data is transferred outside Nepal (e.g., to Cloudinary’s global CDN, AWS Rekognition for face matching), we ensure such transfers are protected by:
- Standard contractual clauses with the recipient.
- Data minimization — only the strictly necessary fields are transferred.
- Encryption in transit and at rest.
- Right to recall data on request.
10. Children’s Privacy
SangiNepal is not directed at children under 18. We do not knowingly collect personal data from anyone under 18. AI-assisted age verification is performed at registration and during ID verification. If you believe a minor has registered, please report it to safety@sanginepal.np and we will investigate and remove the account within 24 hours.
11. Cookies & Tracking Technologies
We use only essential cookies for authentication and session management. We do not use third-party advertising or tracking cookies. Web push notifications require your explicit opt-in and can be revoked at any time from your browser settings or the dashboard.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be notified via email and in-app notification at least 14 days before they take effect. Continued use of SangiNepal after the effective date constitutes acceptance of the revised policy.
13. Contact
For any privacy-related questions, requests, or complaints, contact our Data Protection Officer:
Data Protection Officer
SangiNepal Pvt. Ltd.
Kathmandu, Nepal
Email: privacy@sanginepal.np
Phone: +977-1-XXXXXXX (during business hours, NST)
You may also lodge a complaint with:
Department of Information Technology
Ministry of Communication and Information Technology
Government of Nepal, Singha Durbar, Kathmandu