Last updated: 2 July 2026
1. Introduction
Striiva ("Striiva", "we", "us") operates the Striiva mobile app and website (striiva.com) (together, "the Platform"), which lets you discover and book sports venues, join pickup games, and organize or join teams and tournaments in India. This Privacy Policy explains what personal data we collect, why we collect it, who we share it with, how long we keep it, and the choices and rights you have. It is published in accordance with the Digital Personal Data Protection Act, 2023 ("DPDP Act") and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 and the Intermediary Guidelines, 2021.
For the personal data we process about our users, Striiva acts as the Data Fiduciary. By using the Platform, you confirm you have read and understood this policy.
2. Data We Collect
We collect the following categories of personal data:
- Account & profile data — your name, phone number, email address, city, profile photo, bio, date of birth, gender (optional), and sport preferences.
- Authentication data — your verified phone number (via one-time password) and, if you use Google Sign-In, your Google account identifier, name, and email.
- Booking & activity data — venues you view, search queries, bookings, cancellations, pickup games and teams you join, tournament registrations, reviews, and ratings.
- Payment data — records of payments, refunds, and payouts. Card, UPI, and bank credentials used to pay are collected and processed directly by our payment processor (Razorpay); we do not store your full card number or UPI PIN on our servers.
- KYC & bank details (venue owners and organizers only) — PAN, GST details, identity documents, a verification selfie where required, and the bank / payout account details needed to settle payouts to you.
- Photos & content — images you upload (profile photo, venue photos, KYC documents), which are stored on our image storage provider (Cloudflare R2).
- Device & push data — device model, operating system, app version, and push notification tokens (Firebase Cloud Messaging) used to deliver booking and game notifications.
- Location data — approximate or precise location (with your permission) to show venues and games near you. You can disable location access in your device settings; some features that rely on proximity may then be limited.
- Usage & technical data — log data, IP address, and interaction events used for security, debugging, and product analytics.
3. Why We Use Your Data (Purpose & Legal Basis)
Under the DPDP Act we process your personal data on the basis of the consent you give when you create an account and use specific features, and for the legitimate uses permitted by law. We use each category of data for the purpose it was collected:
- Provide the service — create and manage your account, show venues and games, process bookings and registrations (account, booking, and location data).
- Verify your identity — authenticate you by phone OTP or Google Sign-In, and run KYC checks for owners and organizers (authentication and KYC data).
- Process payments and payouts — take booking payments, issue refunds, and settle payouts (payment and bank data).
- Communicate with you — send booking confirmations, reminders, and service messages by push notification, SMS, WhatsApp, or email (contact and device data).
- Safety, fraud prevention, and support — protect the Platform and its users, resolve disputes, and respond to your requests (usage, technical, and activity data).
- Improve the Platform — understand feature usage and fix problems using analytics (usage data).
- Comply with law — meet tax, accounting, and other legal obligations (payment and transaction records).
You may withdraw your consent at any time (see Section 7). Withdrawing consent does not affect processing already carried out, and some processing required by law will continue as described in Section 6.
4. Third-Party Processors We Share Data With
We share the minimum data necessary with trusted service providers (Data Processors) who process it on our instructions to run the Platform. We do not sell your personal data.
- Razorpay — payment gateway. Processes booking payments, refunds, and payouts. Receives payment amount, contact details, and the payment instrument you enter. See Razorpay's own privacy policy for how it handles that data.
- Firebase / Google (Google LLC) — phone-number OTP verification, Google Sign-In, and push notifications (Firebase Cloud Messaging). Receives your phone number, Google account identifier, and device push token.
- Cloudflare R2 — stores images and documents you upload (profile photos, venue photos, KYC documents).
- Analytics & error monitoring — we use product analytics and error-monitoring tools to measure usage and detect crashes. These receive de-identified usage and device data.
- Communication providers — SMS, WhatsApp, and email providers used to deliver OTPs, confirmations, and reminders receive your phone number or email and the message content.
5. When We Disclose Data
Beyond the processors above, we disclose data only in these situations:
- Venue owners and organizers — when you book a venue or register for a tournament, we share the booking or registration details needed to fulfil it (such as your name and contact number).
- Legal and safety — where required by law, court order, or a lawful government request, or to protect the rights, safety, and property of Striiva, our users, or the public.
- Business transfers — in connection with a merger, acquisition, or sale of assets, subject to this policy continuing to apply.
6. How Long We Keep Your Data (Retention)
We keep your personal data only for as long as your account is active or as needed to provide the Platform. When you delete your account (see Section 8), we permanently erase or irreversibly anonymize your personal data, except for a limited set of records we are legally required to retain:
- Financial and transaction records (payments, refunds, payouts, invoices) are retained in de-identified form for the period required under the Income-tax Act, GST law, and anti-money-laundering rules.
- Records tied to an active dispute, chargeback, or legal claim are retained until it is resolved.
Once the applicable retention period ends, these records are deleted as well.
7. Your Rights
Under the DPDP Act, you have the right to:
- Access — obtain a summary of the personal data we hold about you and how it is processed.
- Correction and updating — correct inaccurate or incomplete data; you can edit most profile data directly in the app.
- Erasure — delete your account and personal data (see Section 8).
- Withdraw consent — withdraw consent for processing at any time, as easily as you gave it.
- Grievance redressal — raise a complaint with our Grievance Officer (Section 12).
- Nominate — nominate another individual to exercise your rights in the event of death or incapacity.
To exercise any of these rights, contact us at privacy@striiva.com. We may need to verify your identity before acting on a request.
8. How to Delete Your Data
You can permanently delete your account and personal data at any time — from inside the app (Profile → Privacy & Security → Delete Account) or by request if you no longer have the app installed. Full step-by-step instructions, exactly what is deleted, and what is legally retained are on our Delete Account page.
9. Children's Privacy
The Platform is intended for users aged 18 and above. We do not knowingly collect personal data from children under 18 without verifiable consent from a parent or lawful guardian, as required by the DPDP Act. If you believe a child has provided us personal data, contact us at privacy@striiva.com and we will delete it.
10. Data Security
We use reasonable security safeguards to protect your data, including encryption of data in transit (TLS), access controls and least-privilege access to production systems, secure storage of uploaded files, and tokenized handling of payment credentials by our payment processor. No method of transmission or storage is completely secure; if we become aware of a personal-data breach that affects you, we will notify you and the Data Protection Board as required by law.
11. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date above and, where appropriate, notify you in the app. Continued use of the Platform after an update means you accept the revised policy.
12. Grievance Officer
In accordance with the Information Technology Act, 2000, the Intermediary Guidelines, 2021, and the DPDP Act, the contact details of our Grievance Officer are:
- Name: [TO BE FILLED]
- Designation: Grievance Officer, Striiva
- Email: grievance@striiva.com [TO BE FILLED]
- Address: [TO BE FILLED], Ahmedabad, Gujarat, India
We aim to acknowledge complaints within 24 hours and resolve them within the timelines prescribed by law.