g.
gigora
Terms of UsePrivacy PolicyCommunity GuidelinesGrievance Redressal

Privacy Policy

Last updated: 15 August 2026

In plain terms. We collect the minimum we need to run a campus-only gig platform: your college email, the profile you choose to fill in, the gigs and messages you create. We never sell your data. We never show your phone number to another student unless you share it yourself. You can delete your account, and everything personal in it, from inside the app at any time.

1. Who is responsible for your data

Vayuun Technologies (OPC) Private Limited (CIN: TODO_ADD_CIN), TODO_ADD_REGISTERED_ADDRESS, is the Data Fiduciary under India's Digital Personal Data Protection Act, 2023 (“DPDP Act”) — and the “controller” if the EU/UK GDPR applies to you.

Data protection contact: privacy@vayuuntechnologies.in

2. What we collect

DataWhy we need itLegal basis
College email addressTo verify you are a student of a supported college and to sign you inConsent; performance of our Terms
One-time passwords (stored only as a hash)To confirm it is really you signing inLegitimate interest — account security
Name, year, branch, skills, bio, avatarTo build the profile other students see when you post or applyConsent
Phone number (WhatsApp)Kept private. Only used if you tap “Open in WhatsApp” in a chat you are already part of. It is never displayed on your public profile or in the feed.Consent
Gigs, applications, pitches, reviewsTo run the marketplace and show ratingsPerformance of our Terms
Chat messagesTo deliver messages between the two parties on a gigPerformance of our Terms
Reports, strikes, moderation recordsTo keep the platform safe and to comply with IT Rules 2021Legal obligation; legitimate interest — safety
Student ID card photo (only if you choose to get verified)To confirm you are the student you say you are. Seen only by a moderator, and deleted immediately once the check is done — approved or not. We never keep ID cards. All that survives is a yes/no flag on your profile.Consent — entirely optional
Push notification tokenTo send you alerts about applications and messagesConsent (you can revoke it in your device settings)
Technical logs (IP address, timestamps, error logs)Security, abuse prevention, rate limiting, debuggingLegitimate interest; legal obligation

What we deliberately do not collect

  • No payment details, card numbers, bank accounts, or UPI IDs — money never flows through Gigora
  • No precise location, contacts list, photo library, or microphone access
  • No advertising identifiers, and no third-party advertising or analytics trackers

3. Who can see what

  • Other students at your college see your name, avatar, year, branch, skills, bio, rating, completed-gig count, and any gigs or reviews you post. Students at other colleges see nothing.
  • Only the two people in a chat can read that chat. Our staff do not read private messages except where a message is specifically reported to us, or where we are legally compelled.
  • Your email address is never shown to other students. Your phone number is never shown unless you choose to start a WhatsApp conversation.

4. Who we share data with

We do not sell your personal data, and we do not share it for advertising. We use a small number of processors:

ProcessorPurposeWhere
Neon (serverless Postgres)Database hostingCloud region as configured
Google CloudApplication hostingCloud region as configured
Email provider (SMTP)Delivering one-time passwordsIndia / global
Expo push notification serviceDelivering push notificationsUnited States

We also disclose data where we are legally required to — for example in response to a valid order from a court or an authorised government agency under the IT Act, 2000.

Some processors are outside India. Where personal data is transferred internationally, we rely on appropriate safeguards and transfer only what is necessary for the service to function.

5. How long we keep it

  • Account data — while your account is active.
  • After you delete your account — your personal data is erased or irreversibly anonymised promptly (normally within 30 days).
  • OTP records — short-lived; codes expire in 10 minutes.
  • Student ID photos — deleted the moment a moderator decides, whether you are approved or rejected. They are never archived, never used for anything else, and never shown to another student.
  • Moderation and safety records — where the IT Rules, 2021 require an intermediary to preserve information (including for 180 days after an account is withdrawn or cancelled), we retain the minimum necessary, in a form separated from your active profile.
  • Chat messages — deleted with the conversation when both participants' accounts are gone; a message reported for abuse may be retained for the safety record.

6. Your rights

Under the DPDP Act (and the GDPR where it applies) you can:

  • Access — ask for a copy of the personal data we hold about you
  • Correct — fix anything inaccurate (most of it you can edit yourself in the app)
  • Erase — delete your account and data, from Profile → Delete account
  • Withdraw consent — at any time, as easily as you gave it
  • Grievance redressal — complain to us first, using the process on our Grievance page
  • Nominate — under the DPDP Act, nominate someone to exercise your rights if you die or become incapacitated; write to us to do this
  • Portability and objection — where the GDPR applies to you, you also have rights to data portability and to object to certain processing

To exercise any right, email privacy@vayuuntechnologies.in from your registered college email. We respond within the timelines the law sets.

If you are not satisfied, you may complain to the Data Protection Board of India (or, if the GDPR applies to you, your local supervisory authority).

7. Children

Gigora is for users aged 18 and above. We do not knowingly collect personal data from children. The DPDP Act requires verifiable parental consent before processing a child's data, and we do not undertake such processing. If you believe someone under 18 has registered, tell us at admin@vayuuntechnologies.in and we will remove the account.

8. Security

  • Traffic is encrypted in transit (HTTPS/TLS)
  • One-time passwords are stored only as salted hashes, never in plain text
  • Sessions use signed tokens; queries are scoped to your college at the database layer
  • Access to production data is limited to people who need it to operate the service

No system is perfectly secure. If a personal data breach occurs, we will notify the Data Protection Board of India and affected users as required by law.

9. Cookies

The mobile app does not use advertising cookies. Our website and admin panel use only strictly necessary cookies (for example, to keep an administrator signed in). We do not run third-party analytics or advertising trackers.

10. Changes

We will post any update here and change the “last updated” date. If a change materially affects your rights we will notify you in the app or by email, and we will remind you of this policy at least once a year.

11. Contact

Vayuun Technologies (OPC) Private Limited
TODO_ADD_REGISTERED_ADDRESS
Privacy: admin@vayuuntechnologies.in
Grievance Officer: see Grievance Redressal

Vayuun Technologies (OPC) Private Limited
CIN: TODO_ADD_CIN
Registered office: TODO_ADD_REGISTERED_ADDRESS
Email: admin@vayuuntechnologies.in

Gigora is a product of Vayuun Technologies (OPC) Private Limited. Gigora is an independent platform and is not affiliated with, endorsed by, or sponsored by any college or university.