BondOn Legal

Privacy Policy

This Policy explains how Sanghance handles information across the BondOn customer app, public website, invitation and matrimony-profile links, admin tools, support channels, and connected services.

Effective and last updated: August 10, 2026

1. Who operates BondOn and what this Policy covers

BondOn is operated by Sanghance ("Sanghance", "BondOn", "we", "us", or "our"). This Policy applies when you use the BondOn mobile or web app, bondoncircle.com and compatible legacy BondOn links, community invitation pages, matrimony-profile sharing pages, Firebase backend, notifications, admin or moderation tools, and support or grievance workflows (together, the "Service").

BondOn is currently designed for adults in supported Hindu communities and for Hindu matrimony. This Policy also covers limited information about people who have not yet registered when a member or authorised admin sends them an invitation or creates a represented matrimony profile with permission.

2. Our privacy commitments

  • We do not sell personal data.
  • We do not currently use personal data for third-party behavioural advertising.
  • Contact names are used on your device to help you choose invitees; BondOn sends only phone numbers you select or enter for an invitation.
  • BondOn does not currently request precise device-location permission. Location details in profiles or messages are details you enter or choose to share, along with any compatible legacy location fields already associated with an account.
  • Matrimony photo controls and private-community rules reduce exposure, but no digital control can prevent an authorised viewer or link recipient from taking a screenshot, copying information, or sharing it outside BondOn.

3. Information you provide

  • Account and authentication information: mobile number, OTP verification state, Firebase user ID, display name, username or alias, optional profile photo, account-completion state, registration and login timestamps, and session information. User accounts are phone-first; limited email information may exist for legacy accounts, support, or authorised admin accounts.
  • Profile and community information: language, notification preferences, name or alias, optional gender, birthday or calculated age, city or locality, country, profile and verification status, religion and community selection, membership history, access-request notes, invite association, blocked users, muted chat topics, and last-seen or read activity.
  • Invitations and access requests: invite code, issuer, selected target mobile numbers, hashed and masked versions of invite targets where used for matching or preview, community, issue and expiry state, delivery outcome, use count, nudge history, and an optional access-request note. An access request may also include the authenticated requester's name, profile photo, verified mobile number, and any compatible legacy verified email.
  • Chats and community content: direct, religion, and community messages; system messages; replies; edits; reactions; timestamps; read state; pinned or deleted state; reports; and shared images, videos, audio or voice notes, files, links and link previews, contact details, location text or map content, polls, votes, and other material you choose to submit.
  • Matrimony profile information: information you submit for yourself or a person you are authorised to represent, including name, birthday and calculated age, gender, marital status, profile-for relationship, representative name, contact and email, preferred contact time and meeting type, religion, caste, sub-caste, community, gothra, birth star, raasi, place of birth, native place, current and job location, height, education, profession, company, salary, languages, diet, drinking and smoking preferences, family type and values, parents' professions, sibling details, interests, description, partner expectations and preferences, contact number, primary and gallery photos, draft or publication state, verification notes, report state, connection state, and photo-access choices.
  • Reports, safety, deletion, and support information: report reasons, block reasons, moderation context, submitted evidence, warning or restriction history, deletion reason, support messages, grievance details, and information used to verify account ownership and resolve a request.

4. Information received from other people

Another member may provide your mobile number to invite you. A family member, representative, or authorised admin may provide information to create or manage a matrimony profile for you. Users may mention you in content or submit a report concerning your account, message, invitation, or profile. Community and BondOn admins may add verification, access, warning, moderation, or audit information.

Anyone who provides another person's information must have a lawful basis and the person's permission where required. If you believe your information or profile was provided without authority, contact us so that we can review it.

5. Device permissions and information kept on your device

  • Contacts: if you grant access, BondOn can display names and phone numbers from your address book for selection. The contact list and search remain on the device; selected phone numbers are sent when you issue an invite.
  • Photos, videos, files, camera, and microphone: these permissions may be requested when you select, capture, crop, upload, play, or record profile photos, matrimony photos, chat media, files, videos, or voice notes. A permission is optional, but the related feature may not work without it.
  • Notifications: notification permission allows service, safety, invitation, access, direct-chat, religion-chat, community-chat, and matrimony-related alerts on supported devices.
  • Local app state: BondOn may keep language and onboarding choices, cached Remote Config state, pending invite or profile-share tokens, notification identifiers, last-read cache, version-check state, and normal media or network caches on your device. Removing app data or uninstalling the app may clear this local state but does not itself delete server records or your account.

You can change device permissions in system settings. Your device provider, mobile network, operating system, and any app you choose through the system share sheet handle information under their own terms and privacy practices.

6. Information collected automatically

  • Device and service information such as platform, app version, Firebase project environment, device or operating-system details, IP and network information processed by hosting providers, request timestamps, authentication and security events, and service logs.
  • Notification information such as permission and opt-in state, Firebase or OneSignal subscription token and identifier, BondOn user ID used as an external notification identifier, delivery and click events, community or topic tags, and notification settings.
  • Usage and reliability information such as screens opened, feature actions, authentication and invite outcomes, community and feature identifiers, counts, app environment, error categories, performance data, and crash reports. Firebase Analytics and Crashlytics may be associated with a BondOn user ID or pseudonymous identifier so that we can diagnose account-specific failures. BondOn's analytics layer is designed to remove common direct identifiers such as names, phone numbers, and email addresses from event parameters.
  • Public website and link information such as page requests, link token requests, response state, browser or user-agent information, approximate network data, and security or availability logs processed by Firebase Hosting, Cloud Functions, and related infrastructure.

7. How and why we use information

  • Verify mobile numbers, complete sign-up, maintain sessions, recover intended deep-link actions, and protect accounts.
  • Create and display profiles, determine community eligibility, process open joins, invitations and access requests, maintain membership, and prevent conflicting or duplicate joins.
  • Deliver direct and group conversations, replies, reactions, attachments, voice notes, polls, read state, link previews, and system or admin messages.
  • Create, reserve, upload, save, publish, claim, find, filter, hide, share, pause, rotate, connect through, and moderate matrimony profiles and photo-access requests.
  • Send OTPs, push notifications, WhatsApp or SMS invitations where configured, support replies, safety warnings, access decisions, and other service or administrative communications.
  • Detect abuse, enforce invite limits, process reports and blocks, automatically limit visibility after configured report thresholds, conduct human moderation, prevent fraud and child sexual abuse or exploitation, preserve safety evidence, and comply with lawful requests.
  • Operate, secure, test, analyse, troubleshoot, configure, and improve the Service; diagnose crashes; maintain backups and admin audit trails; and plan or verify releases.

We process personal data with your consent or at your request, to provide and secure the Service you use, to comply with law, and for other lawful uses permitted by applicable data-protection law. Where a feature is optional, withdrawing permission or consent may disable that feature without affecting processing that was already lawful.

8. Community, chat, and admin visibility

Your display name or alias, profile photo, verification state, relevant profile details, and community membership may be visible to eligible community members. Direct-chat content is visible to its participants. Religion and community-chat content is visible to eligible members of that chat. Reactions, replies, read state, and attachments are visible as part of the relevant conversation.

Reports may include a copy of message content, sender information, profile context, and related metadata so that an authorised admin can investigate. Authorised admins and moderators may access relevant account, membership, invite, access-request, message, matrimony, report, deletion-request, moderation, configuration, and audit records for support, safety, operations, and legal compliance. Admins may send system or direct administrative messages and record decisions in audit logs.

9. Invitations and community access

A targeted invite can store the selected mobile number, a secure hash used for matching, a masked version used for safe guidance, issuer and community details, status, expiry, use history, and delivery results. Before OTP, an invitation page may reveal only masked target guidance and may check whether an entered number belongs to the invitation. Successful use associates the invite and issuer with the joined account. Existing members are not charged another invite use, and an account already linked to a different community is not silently moved.

If you request community access, authorised community or BondOn admins can review the requester's profile, verified contact, selected community, note, status, and prior request history. An approval, rejection, cancellation, invite suspension, or invite strike may be recorded and communicated to relevant users. Invitation delivery through WhatsApp, SMS, email for compatible legacy records, or a shared link also involves the relevant telecom, messaging, email, or recipient platform.

10. Matrimony profiles, claiming, and Safe Reveal

A matrimony profile is shown within its eligible community context and may contain detailed personal, family, lifestyle, professional, contact, and preference information. A profile can be created for the account holder or for a family member or represented person with permission. Photos may be visible immediately or protected by photo-on-request controls. Photo requests, approvals, profile connections, direct-chat state, reports, and blocks are recorded to operate those controls.

An authorised admin may create a profile using a supplied mobile number and publication consent. While that profile is unclaimed, its selected self or representative contact number is intentionally available in the profile as the contact action. BondOn stores a hash of the mobile number in a restricted claim record so that an eligible matching Firebase phone account can claim the profile after completing sign-up. The raw mobile number is not stored in the claim registry, but it remains in the profile where it was supplied as the intended contact. A claimant already linked to another community is not automatically moved.

Safe Reveal and community controls restrict access inside BondOn; they do not verify a viewer's identity beyond BondOn's available checks and cannot stop screenshots, downloads, photography of a screen, or later off-platform sharing by an authorised viewer.

11. Public matrimony-profile sharing

A profile owner can create a random public link, pause or resume it, or rotate it to a new link. Anyone who possesses an enabled link can view its short public preview without signing in. The public page is marked for search engines not to index or archive, but that signal is not an access control and cannot make a shared link secret.

The public preview can show the display name and a limited approved set of fields selected by BondOn's validated presentation settings: age, gender, marital status, education, profession, height, and languages known. The current default selection is age, education, and profession. It may show the approved primary photo unless the profile uses photo-on-request or the safe placeholder is required. It does not expose the complete profile, profile path, birthday, contact details, community identity, private description, location, or Storage URL on the public page.

The share message prepared for the owner may include additional profile details selected by the configured message template, such as age, gender, location, education, profession, religion, caste, community, partner expectations, description, or a note. The owner chooses whether and where to send that message through the device share sheet and should review it before sharing. The receiving app and recipients can copy or redistribute it.

Opening the complete profile in BondOn requires authentication, a current enabled link, active owner and viewer accounts, matching eligible community membership, a shareable profile, and no mutual block. Pausing stops public and in-app resolution until resumed. Rotating retires the old token, but previously captured preview information or messages cannot be recalled from recipients.

12. Notifications and message previews

BondOn uses OneSignal, Firebase, platform notification services, user and community identifiers, subscription tokens, membership tags, and notification preferences to target eligible alerts and avoid sending a user's own message back to them. Depending on your settings and the content type, a notification may include a sender or community name, message text, or a label such as image, video, file, or audio message. Turning off message previews replaces content with a generic notice where supported by BondOn's delivery path.

Device lock-screen settings, operating-system behaviour, connected wearables, and notification extensions can still display notification information to anyone with access to the device. You can manage preview and community or religion notification settings in BondOn, and system-level permission in device settings. Some essential account, safety, legal, or administrative messages may still be sent through the app or another reasonable channel.

13. Service providers and other sharing

We disclose information only as needed to provide, secure, support, and improve BondOn; at your direction; or as permitted or required by law. Provider access is limited to the role each provider performs.

  • Google Firebase and Google Cloud services, including Authentication, Firestore, Cloud Functions, Cloud Storage, Cloud Messaging, Hosting, Analytics, Crashlytics, Remote Config, Scheduler, and related security and infrastructure services.
  • OneSignal for push-subscription management, notification targeting, delivery, and interaction reporting.
  • MSG91 and configured WhatsApp, SMS, or email delivery services; compatible legacy email delivery may use a configured provider or Firebase email extension.
  • Apple App Store, Google Play, Apple and Android notification services, operating-system link handling, and app-distribution or integrity services.
  • Support, professional, security, legal, or infrastructure providers who need limited information to assist us under appropriate duties.
  • A buyer, successor, adviser, or authority in connection with a lawful business transaction, legal request, emergency, safety investigation, Terms enforcement, or protection of users and the public, subject to applicable law.

External links, telephone calls, WhatsApp, SMS, email, app stores, and apps selected through your device are controlled by third parties and have separate privacy practices.

14. Automated processing and moderation

BondOn uses rules and automated checks to validate OTP and invite ownership, detect duplicate or conflicting membership, filter unsafe or malformed input, target notifications, rate-limit activity, protect uploads, and hide messages or matrimony profiles after configured report thresholds. These actions can affect visibility or feature access. Authorised admins can review reports, restore or remove content, warn users, restrict chat or invitation privileges, suspend or ban accounts, and record the reason.

BondOn does not perform a comprehensive criminal, financial, employment, education, identity, family, or matrimonial background check and does not make a guarantee about compatibility, profile truth, or marriage outcomes.

15. Retention, deletion, and backups

We keep information for as long as reasonably needed for the purpose described in this Policy: to maintain an active account, community, conversation, invitation, profile, share link, support request, or safety record; to secure the Service; and to meet legal, audit, dispute, and enforcement needs. Retention depends on the data and the context rather than one period for every record.

  • Unfinished admin-created matrimony reservations normally expire after 24 hours and are scheduled for removal with their staged images, subject to operational completion and retained audit or error records.
  • Active matrimony-share records and prepared previews are kept while needed to operate the link. Paused, rotated, unavailable, legacy, and terminal records may be retained in restricted form for link integrity, migration, abuse prevention, and audit. Rotation does not delete copies already made by recipients.
  • Reports, moderation records, invite strikes, blocks, bans, deletion-request records, and admin audit logs may be retained as needed to protect users, prevent repeat abuse, document decisions, and resolve disputes or legal requests.

You can initiate deletion in the app or through the Delete Account page. After identity verification and review, standard requests are generally processed within 7 days. We delete or de-identify account data where reasonably and legally possible. Messages or community records may remain in deleted, de-identified, or limited form where removal would affect other users' conversation context, safety evidence, audit integrity, fraud or ban prevention, legal duties, or disputes. Backups, caches, provider records, and logs may remain until they expire or are overwritten through normal cycles.

16. Security

We use safeguards designed for the nature of the Service, including encrypted network transport, Firebase-managed infrastructure, authenticated and role-based access, Firestore and Storage security rules, restricted server-only lifecycle records, file type and size validation, random public-link tokens, admin custom claims, audit logs, retry and idempotency controls, and limited operational access. No internet service is completely secure. Keep your device, mobile number, OTPs, profile links, and account sessions safe, and report suspected unauthorised access promptly.

17. Your choices and rights

  • Review and update available profile, language, community, notification, and matrimony information in the app.
  • Choose whether to grant device permissions, issue an invite, publish a matrimony profile, allow photos on request, approve photo access, create or send a public profile link, or contact another member.
  • Pause, resume, or rotate a matrimony-share link; mute available chat topics; turn supported notification previews on or off; block users; report content; disconnect direct chat; cancel eligible access requests; leave a community; or request account deletion.
  • Ask us for information about your personal data, correction, completion, updating, erasure, consent withdrawal where applicable, grievance redressal, nomination, or another right available under applicable law.

We may ask for information needed to verify identity, authority, and account ownership. A request may be limited or refused where the law permits or requires us to preserve information, protect another person's rights, maintain safety evidence, or prevent fraud. We will explain the applicable reason where required.

18. International processing

BondOn is operated for users in India and may be used elsewhere. Our cloud, notification, analytics, messaging, app-store, and support providers may process information in India and other countries where they or their subprocessors operate. We use applicable legal grounds and provider, contractual, technical, and organisational safeguards for cross-border processing, subject to any restriction imposed by applicable law.

19. Adults only

BondOn is intended only for people aged 18 or above. We do not knowingly permit a minor to create an account or matrimony profile. If we learn that a minor's information has been submitted, we may restrict the account, remove the profile, and delete or preserve information as appropriate for the child's safety and applicable law. Please report such a concern immediately.

20. Changes to this Policy

We may update this Policy when features, providers, practices, or law change. We will update the date above and may provide additional notice in the app, on the website, or through another reasonable channel for a material change. Where law requires new consent, we will request it before the relevant processing. Earlier versions may continue to apply to an issue arising while they were in effect.

21. Contact and grievance redressal

For privacy questions, access or correction requests, deletion support, unauthorised-profile concerns, safety escalations, grievances, or legal notices, email support@sanghance.com. Please include enough information to identify the account or issue, but do not send OTPs, passwords, unnecessary identity documents, or unrelated sensitive information. We may verify your request before taking action.