Version 2.0 · Effective Date: 19 September 2026 · Last Updated: 19 September 2026
PlusOne Technologies Pvt. Ltd. ("PlusOne", "we", "us", or "our") operates the PlusOne mobile application, website, and related services (collectively, the "Platform").
PlusOne is a human connection and companionship platform that enables users to discover, communicate with, and book companions for legitimate social, recreational, professional, cultural, travel, entertainment, and other real-world activities.
This Privacy Policy is our notice to you under the Digital Personal Data Protection Act, 2023 ("DPDP Act") and the DPDP Rules, 2025. It explains, in plain language, what personal data we collect, why we collect it, who we share it with, how long we keep it, and how you can exercise your rights. PlusOne is the "Data Fiduciary" for the personal data described here.
When you create an account we collect:
You may add:
To keep the Platform safe, accounts are identity-verified. Verification is carried out by Digio, an India-based identity-verification and eSign provider, through a hosted flow inside the app:
What we store: only the Digio reference id for the request, the last four digits of your Aadhaar number, an Aadhaar reference id, your verified name and date of birth, the face-match score and the liveness result, and the verification status. For eSign we store the signed PDF, its fingerprint and the Digio document id.
What we do not store: your full Aadhaar number, your Aadhaar card image, or the selfie image. These are processed by Digio and are not saved on PlusOne servers.
Sharing identity data with Digio is a separate consent purpose (aadhaar_digio, see Section 12). If Digio-based verification is not available in your region or environment, a manual document-upload review may be used; in that case the document and selfie you upload are stored privately until reviewed and are deleted 90 days after a rejected or withdrawn attempt.
With your device permission we collect:
Location is never shared with your emergency contacts unless you have switched on the sos_location_share purpose (Section 12). You can turn off location access in your device settings; features that depend on it will stop working.
When you make or accept a booking we record the activity, date, start and end time, duration, meeting location, price, the other participant, booking status, cancellation or decline reasons, and payment references.
Booking chat messages, images, shared locations and call records are processed to deliver them to the other party, to keep the Platform safe, to investigate reports, and to comply with law. Chat is available only while a booking is paid and active. Uploaded images and videos are automatically scanned for prohibited content (Section 13.2).
Payments are processed by Razorpay. PlusOne receives the transaction id, order id, payment status, amount, payment method type, refund and settlement information. We do not receive or store your full card number, CVV, UPI PIN or banking password.
For companion payouts we store the account holder name, IFSC or UPI id, the last four digits of the bank account number and the Razorpay fund-account reference. The full account number is held by Razorpay, not by PlusOne.
For companions and eligible members we keep a ledger of booking earnings, platform commission, refunds, wallet balance, withdrawals, referral rewards, promotional credits and invoices. These records are financial and tax records and are retained as described in Section 14 even after account deletion.
Ratings and reviews you write are shown to other users with your name and profile photo. Companions may also rate members after a booking. Do not include another person's private or sensitive information in a review.
We automatically collect device type, operating system, app version, IP address, push-notification token, crash reports, login timestamps, language and timezone, and how you use the Platform. This is used for security, troubleshooting, fraud prevention and to keep the app working.
The website and app use local storage, session tokens, cookies and SDKs for authentication, security, preferences and crash reporting. We do not use third-party advertising cookies.
PlusOne offers optional AI features: personalised companion and activity picks, a concierge chat, and booking-plan suggestions. These are off until you switch on the ai_personalisation purpose (Section 12). Every AI endpoint is blocked server-side until that consent is recorded.
When enabled, the following is processed:
Your interests, your typed request and the shortlisted companion listings are sent to our AI processing partner listed in Section 13.2 to generate the natural-language reply. Your phone number, email, Aadhaar data, payment data, chat history and exact coordinates are not sent to the AI partner. AI output is a suggestion only and never a guarantee about another person.
We use your personal data to:
Using the Platform for the core service (account, bookings, payments, chat, safety) is covered by your acceptance of the Terms and this Policy. Some processing needs a separate, specific consent. All four purposes below are OFF by default:
| Purpose key | What it allows | What happens if you do not consent |
|---|---|---|
aadhaar_digio | Sharing your name and contact with Digio and completing Aadhaar verification, face match and eSign through Digio. | Identity verification cannot be completed. Companion features and bookings that require a verified account stay unavailable. |
ai_personalisation | Processing your interests, approximate location and typed requests for AI recommendations, concierge and planner (Section 10). | AI features stay switched off. All other features work normally. |
marketing | Sending offers, promotions and product updates by push, SMS or email. | You receive only service notifications (bookings, payments, safety, security). |
sos_location_share | Including your live location link in the SOS SMS sent to your emergency contacts. | Your emergency contacts are still alerted by SMS, but the message says "location not shared". |
Withdrawing consent is as easy as giving it. Change any of these choices at any time from Settings → Privacy in the app, or through the account API (PUT /api/v1/me/consents/purposes with {"purpose": "...", "granted": false}). Withdrawal takes effect immediately for future processing; it does not affect processing already done. Each grant or withdrawal is recorded with the date, the policy version and your IP address, and appears in your data export.
PlusOne does not sell personal data.
Other users can see your name, profile photo, age, interests, languages, general location or distance, availability, ratings and reviews, and companion listing details. Your phone number, email, date of birth, Aadhaar details and payment details are never shown on your profile.
When you trigger SOS, your emergency contacts receive an SMS with your name, the nearest police station, and — only with the sos_location_share consent — a map link to your location.
We use the following processors, each bound by contract to act only on our instructions:
| Processor | Purpose | Data shared | Processing region |
|---|---|---|---|
| Digio | Aadhaar verification, selfie face match, Aadhaar eSign | Name, mobile/email identifier; Aadhaar and selfie are shared by you directly with Digio | India |
| Razorpay (incl. RazorpayX) | Payment collection, escrow, refunds, companion payouts | Name, contact, payment amount, bank/UPI details for payouts | India |
| MSG91 | SMS one-time passwords and SOS alerts | Mobile number, OTP, SOS message text | India |
| Firebase Cloud Messaging (Google) | Push notifications | Device push token, notification text | Global (Google infrastructure; may be outside India) |
| Firebase Crashlytics (Google) | Crash reporting | Device model, OS, app version, crash traces | Global (may be outside India) |
| Google Maps Platform (Places API) | Place search, address suggestions, nearest police station for SOS | Search text and approximate coordinates | Global (may be outside India) |
| Sightengine | Automated moderation of uploaded photos and videos | The uploaded image or video | Outside India (European Union) |
| Microsoft Azure | Application hosting, database and media storage | All Platform data | India / Asia region |
| Azure OpenAI Service (Microsoft) | AI processing partner for recommendations, concierge and planner (Section 10) | Interests, typed request, companion listing summary — only with ai_personalisation consent | As configured for our deployment; may be outside India |
| Email service (SMTP) | Email one-time passwords and service email | Email address, message text | As configured for our deployment |
Where a processor is located outside India (Google, Sightengine, and potentially Azure OpenAI), personal data is transferred outside India for that purpose only. Such transfers are made only to countries not restricted by the Central Government under Section 16 of the DPDP Act and under contracts that require the processor to protect the data.
We disclose personal data to courts, police or regulators when required by Indian law, to respond to lawful requests, to prevent imminent harm, or to investigate fraud or unlawful activity.
If PlusOne is merged, acquired or restructured, personal data may be transferred to the successor, who must honour this Policy.
We keep personal data only as long as needed for the purpose it was collected, and then delete it automatically. A retention job runs every 24 hours and applies the following periods:
| Data | Retention period |
|---|---|
| Booking location shares (static and live) | Deleted 30 days after the share expires |
| Booking chat messages and chat media | Deleted 365 days after the booking ended (completed, cancelled or expired) |
| One-time passwords (OTP) | Deleted 7 days after expiry |
| Search history | Deleted after 180 days |
| Rejected or withdrawn KYC attempts (including any manually uploaded document or selfie) | Deleted 90 days after rejection or withdrawal |
| Last known location | Kept only as the single current value; deleted immediately on account deletion |
| Approved identity verification record (Digio reference, Aadhaar last 4, verified name and DOB, face-match result) | Kept while the account is active; deleted immediately on account deletion |
| Signed eSign agreements (member terms, companion agreement) | Kept for 8 years from signing as legal evidence, then eligible for deletion |
| Bookings, payments, invoices, wallet ledger, payouts, subscriptions | Kept for at least 8 years as financial and tax records under Indian company and tax law, linked to an anonymised user id after account deletion |
| Support tickets, safety reports, consent records and audit logs | Kept while the account exists and for as long as needed to demonstrate compliance, linked to an anonymised user id after account deletion |
If you stop using the Platform without deleting your account, your account data stays until you delete it or until we are required by law to erase it.
You can delete your account at any time from Settings → Delete account in the app, from the web deletion page, or through the account API (DELETE /api/v1/me). Deletion takes effect immediately — there is no waiting period:
The following are kept in anonymised form (linked only to a numeric id, not to your name or contact) for the period in Section 14: bookings, payments, invoices, wallet ledger, payouts, subscriptions, support tickets, safety reports, signed eSign agreements, consent records and audit logs. This is required for tax, accounting, dispute and safety-investigation purposes.
We protect personal data with:
No system is perfectly secure. Keep your OTPs private and sign out on shared devices.
If a personal-data breach affects you, we will notify you through the app, and by SMS or email where available, without undue delay and in the form required by the DPDP Rules. We will also notify the Data Protection Board of India within the statutory 72-hour window. Each notice describes what happened, which data was involved, what we are doing, and what you should do. The notice is linked from the message and is also published as a public security-notice page (/api/v1/legal/breach/{id}).
PlusOne is for adults only. You must be 18 years or older. Your date of birth is checked on our servers when you set up your profile, again against your Aadhaar date of birth when you complete identity verification through Digio, and again before every booking. If we learn that a person under 18 has created an account, we delete it. We do not knowingly process children's data and we do not use tracking or targeted advertising directed at children.
We process identity verification results, reports, blocks, SOS events, booking history and moderation results to keep the Platform safe. Uploaded photos and videos are automatically checked for nudity and prohibited content. Repeated violations lead to account restrictions.
Service notifications — booking updates, payment receipts, safety alerts, security alerts (new sign-in, account changes) and legally required notices — are part of the service and do not need consent, although you can control push, SMS and email channels in Settings.
Marketing and promotional messages — offers, promotions and product news — are sent only if you have switched on the marketing purpose (Section 12). Promotional sends are filtered server-side so users without this consent never receive them. Switch it off at any time.
Links or integrations to third-party services (for example Google Maps or Razorpay checkout) are governed by those providers' own privacy policies.
Under the DPDP Act you have the following rights. There is no charge for exercising them.
Download a complete copy of your personal data from Settings → Download my data in the app or via GET /api/v1/me/export. One export per day is allowed. The JSON file includes: your account details, member profile, companion listing, bookings (the other party is identified by name only), reviews written and received, payments, wallet totals and transactions, legal consents, purpose consents, emergency contacts, saved addresses, interests, settings, the number of registered devices, and your audit log. Every export is itself recorded in the audit log.
Edit your name, photo, bio, interests, addresses, emergency contacts and preferences directly in the app. For anything you cannot change yourself (for example, a verified name), contact the Grievance Officer or raise a support ticket.
See Section 15.
See Section 12.
See Section 23.
You may nominate another person to exercise these rights on your behalf in the event of your death or incapacity. Send the nominee's name and contact details to the Grievance Officer from your registered email or phone; we will record the nomination against your account.
We may ask you to verify your identity before acting on a request.
For any question, complaint or request about your personal data, contact our Grievance Officer (also our Data Protection contact):
Grievance Officer
Name: Manikanta
Email: manisbk0@gmail.com
Phone: +91 84317 55621
Address: PlusOne Technologies Pvt. Ltd., HSR Layout, Bengaluru, Karnataka, India
You can also raise a ticket in the app under Help & Support and choose the "Privacy" or "Grievance" topic; these tickets are tracked with a statutory due date.
We respond to and resolve grievances within 45 days of receipt, as required by Section 13 of the DPDP Act. If you are not satisfied with our response, or we do not respond within 45 days, you may complain to the Data Protection Board of India.
Current officer details are also published in the app and at GET /api/v1/legal/documents.
PlusOne is hosted on Microsoft Azure in the India / Asia region. Some processors listed in Section 13.2 (Google Firebase, Google Maps Platform, Sightengine, and potentially Azure OpenAI) process data outside India. We transfer only the minimum data each needs and only to countries not restricted by the Central Government under Section 16 of the DPDP Act.
We may update this Policy. Material changes will be announced in the app and by email or push notification, and you may be asked to accept the new version. The version number and "Last Updated" date at the top will change. Consents you give are recorded against the policy version in force at the time.
PlusOne Technologies Pvt. Ltd.
HSR Layout, Bengaluru, Karnataka, India
Privacy: privacy@plusoneapp.in
Grievance Officer: manisbk0@gmail.com