Privacy Policy

Last updated: April 2026 Effective date: April 1, 2026 Jurisdiction: India (DPDPA 2023)

Summary: Taara collects your name, birth details (date, time, place), and email to generate personalised Vedic astrology reports. We do not sell your data to anyone. You can request deletion of your data at any time by emailing support@mytaare.com. This policy complies with India's Digital Personal Data Protection Act, 2023 (DPDPA) and the Information Technology Act, 2000.

01About This Policy

This Privacy Policy describes how Taara ("we", "our", or "us") collects, uses, stores, and protects your personal data when you use the website mytaare.com and any associated services (collectively, the "Platform"). By accessing or using the Platform, you agree to the practices described in this Policy.

This Policy is governed by and construed in accordance with the laws of India, including the Digital Personal Data Protection Act, 2023 (DPDPA), the Information Technology Act, 2000 (as amended), and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (SPDI Rules).

02Who We Are (Data Fiduciary)

Under the DPDPA 2023, Taara is the Data Fiduciary — the entity that determines the purpose and means of processing your personal data.

Business Name
Taara (mytaare.com)
Country
India
Contact Email
Report Email

03Data We Collect

3.1 Data You Provide Directly

CategorySpecific Data PointsPurposeRequired?
IdentityFull nameReport personalisation, communicationsYes
Birth DataDate of birth, time of birth, place of birthVedic chart calculation (core service)Yes
ContactEmail addressReport delivery, order confirmation, daily guidanceYes
ContactPhone numberSession booking confirmationOptional
PaymentPayment method type (card/UPI/netbanking)Transaction recordsYes (for paid services)
AccountGoogle profile (name, email, photo URL)Authentication via Google OAuthOptional (if using Google sign-in)
InquiryQuestion / topic for session or "Ask Your Kundli"Generating bespoke astrological guidanceService-dependent

3.2 Data Collected Automatically

  • Usage data: Pages visited, time spent, features accessed, click patterns
  • Device data: Browser type and version, operating system, screen resolution
  • Network data: IP address, approximate geographic location (country/city level)
  • Session data: Session duration, referring URL, exit page
  • Cookies: Authentication tokens, preference cookies (see Section 10)

3.3 Sensitive Personal Data

Under the SPDI Rules, 2011, birth data (date of birth, time of birth, place of birth) may be classified as sensitive personal data in certain contexts. We treat this information with the highest level of care, encrypt it at rest and in transit, and use it exclusively to generate your astrological chart. We do not disclose this data to any third party except as set out in Section 6 of this Policy.

04How We Use Your Data

PurposeData UsedLegal Basis
Generate Vedic astrology reportsName, DOB, TOB, POBContract performance / Consent
Process and confirm paymentsName, email, payment tokenContract performance
Send daily guidance emailsName, email, DOB, TOB, POBContract performance / Consent
Confirm session bookingsName, email, phone, session date/timeContract performance
Customer support and dispute resolutionName, email, order detailsLegitimate interest
Platform analytics and improvementUsage data, device data (anonymised)Legitimate interest
Fraud prevention and securityIP address, device fingerprintLegal obligation / Legitimate interest
Legal compliance and record-keepingTransaction records, communicationsLegal obligation
Marketing (with consent)Email, nameConsent (opt-in only)

We do not use your birth details for any purpose other than generating your personalised astrological reading. We do not sell, rent, or trade your personal data to third parties for their marketing purposes.

05Legal Basis for Processing

Under the Digital Personal Data Protection Act, 2023, we process your personal data on the following lawful grounds:

  • Consent (Section 7, DPDPA): When you submit your birth details and email to receive a free forecast, create an account, or subscribe to daily guidance, you provide explicit consent for us to process your data for those specific purposes.
  • Contract Performance: Processing is necessary to fulfil your purchase of a report or session, including payment processing and delivery of the ordered service.
  • Legitimate Interest: We may process data to prevent fraud, ensure platform security, and improve our services — provided these interests are not overridden by your rights.
  • Legal Obligation (Section 8, DPDPA; IT Act 2000): We may retain and disclose data where required by law, court order, or regulatory authority.

06Third-Party Data Processors

We use the following sub-processors who may access your data only to the extent required to provide their contracted service. Each processor is bound by data processing agreements and is required to handle your data securely.

ServiceProviderData SharedPurposePrivacy Policy
AuthenticationSupabase Inc. (USA)Email, name, OAuth tokenUser accounts & loginsupabase.com/privacy →
Database & StorageSupabase Inc. (USA)All user data, reportsData storagesupabase.com/privacy →
Payment ProcessingRazorpay Software Pvt. Ltd. (India)Name, email, amountSecure payment gatewayrazorpay.com →
Report Generation (AI)OpenAI LP (USA)Name, DOB, TOB, POB, chart dataGenerate report content via GPT-4openai.com/privacy →
Transactional EmailBrevo (France)Name, emailReport delivery, daily guidancebrevo.com →
Cloud HostingRailway (USA)Server-side logs, application dataBackend infrastructurerailway.app →
Frontend HostingVercel Inc. (USA)Access logs, IP addressesWebsite deliveryvercel.com →

We note that OpenAI processes birth data in the United States. By using our services, you consent to this cross-border transfer as described in Section 11. OpenAI's API usage policy prohibits using API data for model training on non-opted-in data.

07Data Retention

Data CategoryRetention PeriodReason
Account & profile dataUntil account deletion or 3 years of inactivityAccount management
Order & payment records7 years from transaction dateGST / Income Tax compliance (India)
Generated reports (PDFs)2 years from generationRe-download facility
Daily guidance subscription dataDuration of subscription + 1 yearService delivery and dispute resolution
Support ticket communications3 years from resolutionQuality assurance and legal record
Free forecast leads1 year from last useRate limiting and analytics
Server access logs90 daysSecurity monitoring
Analytics data (anonymised)Indefinite (no PII)Platform improvement

After the applicable retention period, your data is securely deleted or anonymised so that it can no longer be linked to you.

08Data Security

We implement industry-standard technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction:

  • Encryption in transit: All data transmitted between your browser and our servers uses TLS 1.2+ (256-bit SSL encryption).
  • Encryption at rest: Sensitive fields in our database (birth details, personal information) are stored with AES-256 encryption via Supabase Row Level Security (RLS).
  • Access controls: Production database access is restricted to authorised backend services only. No direct public database access is permitted.
  • Payment security: Card details are processed exclusively by Razorpay — we never receive, store, or log full card numbers. Razorpay is PCI-DSS Level 1 certified.
  • Authentication tokens: JWT tokens are short-lived (7 days) and signed with a secret known only to our servers.
  • Vulnerability management: We conduct regular dependency audits and apply security patches promptly.

While we maintain comprehensive security measures, no system connected to the internet is completely immune to security risks. In the event of a data breach affecting your rights, we will notify affected users and the appropriate regulatory authority in accordance with applicable law.

09Your Rights as a Data Principal

Under the Digital Personal Data Protection Act, 2023, you have the following rights as a Data Principal (the individual whose data is being processed):

  • Right to Access (Section 11, DPDPA): You may request a summary of the personal data we hold about you and how it is being processed. We will respond within 30 days.
  • Right to Correction (Section 12, DPDPA): You may request that we correct inaccurate or incomplete personal data.
  • Right to Erasure (Section 12, DPDPA): You may request deletion of your personal data. We will fulfil deletion requests within 30 days, except where retention is required by law.
  • Right to Grievance Redressal (Section 13, DPDPA): You may file a grievance with our Grievance Officer (see Section 13). If unresolved, you may escalate to the Data Protection Board of India.
  • Right to Withdraw Consent: You may withdraw your consent to marketing communications at any time using the unsubscribe link in any email or by contacting us directly. Withdrawal of consent will not affect lawfulness of prior processing.
  • Right to Data Portability: You may request your personal data in a machine-readable format (CSV/JSON) for portability to another service.
  • Right to Nominate: Under DPDPA, you may nominate another individual to exercise these rights on your behalf in case of your incapacity or death.

To exercise any of these rights, email support@mytaare.com with the subject line "Data Rights Request — [Your Full Name]" and we will respond within 30 days.

10Cookies & Tracking Technologies

10.1 Cookies We Use

Cookie NameTypePurposeDuration
taara_tokenStrictly NecessaryAuthentication — keeps you logged in7 days
taara_userStrictly NecessaryStores your display name and email locallySession
sb-* (Supabase)Strictly NecessaryOAuth session management (Google sign-in)1 hour

We do not use third-party advertising cookies, tracking pixels, or behavioural profiling technologies. We do not share cookie data with advertisers. Strictly necessary cookies cannot be disabled as they are essential for the Platform to function.

10.2 Local Storage

We use your browser's Local Storage to store your authentication token and user preferences. This data is stored on your device and is never automatically transmitted to any third party.

11Cross-Border Data Transfers

Some of our third-party processors (Supabase, OpenAI, Railway, Vercel, Brevo) are headquartered or operate servers outside India. By using our services and accepting this Policy, you expressly consent to the transfer of your personal data to these processors in countries including the United States of America and the European Union, where data protection laws may differ from those in India.

We take the following safeguards to protect cross-border transfers:

  • All processors are bound by data processing agreements that require them to implement adequate security measures.
  • OpenAI, Supabase, Vercel, and Brevo are GDPR-compliant and maintain Standard Contractual Clauses (SCCs) for EU data transfers, providing a comparable protection standard.
  • Birth data sent to OpenAI is used solely to generate your report and is not retained by OpenAI for model training under its API data handling policy.

12Children's Privacy

Our Platform is intended for users aged 18 and above. We do not knowingly collect personal data from individuals under 18 years of age. Under Section 9 of the DPDPA 2023, we are required to obtain verifiable parental consent before processing any data of a child.

If you are a parent or guardian and believe that a minor has provided us with personal data without your consent, please contact us immediately at support@mytaare.com. We will promptly delete such data upon verification.

13Grievance Officer

In accordance with the Information Technology Act, 2000, the SPDI Rules, 2011, and the DPDPA 2023, we have designated a Grievance Officer to address complaints and concerns about our data handling practices:

Role
Grievance Officer / Data Protection Officer
Organisation
Taara (mytaare.com)
Response Time
Within 30 days of receiving complaint

If your grievance is not resolved within 30 days, or if you are dissatisfied with the resolution, you may escalate your complaint to the Data Protection Board of India once it is constituted under the DPDPA 2023.

14Changes to This Policy

We may update this Privacy Policy periodically to reflect changes in our practices, technology, or applicable law. When we make material changes, we will:

  • Update the "Last Updated" date at the top of this page
  • Send an email notification to registered users at least 7 days before the change takes effect
  • Display a prominent notice on our Platform for 30 days following any material change

Your continued use of the Platform after the effective date of any changes constitutes your acceptance of the updated Policy. If you do not agree to the changes, you must discontinue use of our services and request deletion of your account.