Last Updated: March 14, 2026
Introduction
Shri Brahman Swarnkar Samaj (Raj.) Mumbai ("we," "us," or "our") operates the Soni Community mobile application (the "App"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our App.
Registration Number: F-27022
Please read this Privacy Policy carefully. By using the App, you agree to the collection and use of information in accordance with this policy.
1.1 Personal Information You Provide
When you register and use the App, we collect the following personal information:
Required Information (Mandatory):
- Full Name
- Mobile Number (10-digit)
- Registration Number
- Gender
Optional Information:
- Marital Status
- Date of Birth
- Email Address
- Profile Photo
- Father's Name, Mother's Name, Spouse Name
- Children's Details (Name, Date of Birth, Gender)
- Current Address, Locality, City, State, Pincode
- Native Place
- Gotra (family lineage)
- Occupation, Education
- Birth Place, Height, Weight
- Zodiac Sign, Manglik Status
1.2 Automatically Collected Information
- Usage Data: App usage patterns, features accessed, time spent
- Device Information: Device type, operating system, unique device identifiers
- Login Activity: Last login timestamp, online/offline status
- Location Data: City and locality information (manually entered, not GPS-based)
1.3 User-Generated Content
- Posts (text, images, videos, audio)
- Comments on posts
- Reactions to posts
- Event registrations and attendance
- Payment transaction screenshots (for event payments)
- Family tree information
1.4 Payment Information (For Paid Events Only)
What we collect:
- โ
Payment confirmation screenshots (UPI transaction receipts)
- โ
Transaction reference numbers
- โ
Payment amount and date
What we DO NOT collect:
- โ Credit/Debit card numbers
- โ Card CVV codes
- โ Bank account credentials
- โ UPI PINs or passwords
Storage: Payment screenshots are stored securely on our servers and deleted after 6 months or upon account deletion.
2. How We Use Your Information
2.1 Core Functionality
- Account creation and authentication
- Profile management
- Community member directory
- Event management and registration
- Payment details management
- Family tree visualization
- Communication within the community
2.2 Community Features
- Displaying member profiles to other authenticated users
- Facilitating connections between community members
- Family relationships and relatives management
- Event announcements and notifications
- Panel member communications
- Biodata search
2.3 Administrative Purposes
- Verifying new member registrations
- Managing event payments (Offline/Cash Mode)
- Moderating user-generated content
- Maintaining data accuracy
- Providing customer support on best effort basis
2.4 Analytics and Improvements
- Improving app features and user experience
- Generating community statistics (demographics, localities, gotras)
3. Data Sharing and Disclosure
3.1 Within the Community
Visible to All Authenticated Members:
- Full Name
- Profile Photo
- Mobile Number
- Gender
- Marital Status
- City/Locality
- Occupation
- Education
- Gotra
Limited Visibility:
- Date of Birth (age calculated and displayed)
- Family details (only in family tree context)
- Children information (only for married members)
3.2 We DO NOT Share Your Data With:
- โ Third-party advertisers
- โ Marketing companies
- โ Data brokers
- โ Social media platforms
- โ Any external commercial entities
3.3 Legal Requirements
We may disclose your information if required by law, court order, or governmental authority, or to protect our legal rights. We will only produce data available in the application and cannot provide any information beyond the app's data store.
4. Device Storage and Session Management
๐ Critical Disclosure - Please Read Carefully
4.1 Authentication Tokens (Mobile App Storage)
We store an encrypted authentication token using React Native's AsyncStorage (secure device storage) to keep you logged in between app sessions.
What this means:
- An encrypted token is saved locally on YOUR device only using AsyncStorage
- This token allows you to stay logged in without re-entering credentials
- AsyncStorage is the secure, industry-standard storage for React Native apps
- The token is NOT accessible to other apps on your device
- The token is encrypted and cannot be read by anyone else
When is it deleted:
- Automatically when you log out of the app
- Automatically when you request account deletion
- Automatically after 7 days for security (you'll need to log in again)
- Manually if you clear app data from device settings
Why we need it: This is a standard security practice for mobile apps. Without this token, you would need to enter your mobile number and password every single time you open the app.
4.2 Session Tracking and Auto-Logout
We monitor your app activity to automatically log you out after 30 minutes of inactivity for security purposes.
What we track:
- Last interaction timestamp (when you last tapped the screen)
- Active session identifier (a temporary ID for your current session)
- Login/logout events (when you start and end sessions)
Why we track this:
- Security: If you leave the app open and forget about it, we automatically log you out to prevent unauthorized access
- Privacy: If someone else picks up your unlocked phone, they cannot access your community data after 30 minutes
- Best Practice: This is required by data security standards for apps handling personal information
What happens to this data:
- Session timestamps are stored temporarily on our server
- All session data is automatically deleted when you log out
- Session data is permanently deleted when you delete your account
- We do NOT use this data for analytics or profiling
4.3 Family Tree Change Requests
When you submit a request to add or modify family relationships, we retain these requests permanently for audit trail purposes.
What we store:
- Your request to add a family member
- Your request to modify relationships
- Admin approval/rejection decisions
- Timestamps of all changes
Why we store this permanently:
- Data Integrity: To maintain accurate family tree history
- Dispute Resolution: To resolve conflicts if two people claim different relationships
- Audit Trail: To track who made what changes and when
- Compliance: To meet data governance requirements
Important Note: Even if you delete your account, family tree change requests are retained to preserve the integrity of other users' family trees. However, your personal profile data will still be deleted.
5. Data Security
We implement industry-standard security measures to protect your personal information:
Encryption: All data transmission uses HTTPS/TLS encryption
Authentication: Secure login with mobile number and password
Session Management: Automatic logout after 30 minutes of inactivity
Server Security: Data stored on secure servers with access controls
Password Protection: Passwords are stored securely (never in plain text)
Payment Security: We do not store payment card information
Device Security: Authentication tokens encrypted on your device using AsyncStorage
Note: While we strive to protect your information, no method of electronic storage is 100% secure. You are responsible for maintaining the confidentiality of your login credentials.
6. Data Retention
6.1 Active Accounts
Your data is retained as long as your account is active.
6.2 Automatic Deletion
- Posts: User posts are automatically deleted after 30 days
- Session Tokens: Deleted after 30 minutes of inactivity or on logout
- Event QR Codes: Expire after event end date
- Authentication Tokens: Deleted on logout or after 7 days
- Payment Screenshots: Deleted after 6 months or upon account deletion
6.3 Account Deletion
Upon request, we will delete your account and associated data within 30 days.
Account Deletion Timeline:
- Request submission: Immediate
- Admin review: Within 7 business days
- Data deletion: Within 30 days maximum
- Confirmation: Via SMS/Email to registered mobile
What gets deleted:
- โ
Your profile information and photos
- โ
Your posts, comments, and reactions
- โ
Your event registrations
- โ
Your uploaded media files
- โ
Your device authentication tokens
- โ
Your session data
- โ
Your payment screenshots
6.4 โ ๏ธ IMPORTANT: Data Retained After Account Deletion
Even after deleting your account, the following data is permanently retained:
1. Family Tree Change Requests - Required to:
- Maintain accuracy of other users' family trees
- Resolve future relationship disputes
- Provide audit trail for data governance
2. Event Historical Records - Required for:
- Community event archives
- Financial record-keeping
- Legal compliance
3. Audit Logs - Required for:
- Administrative actions tracking
- Security purposes
- Legal compliance records (as required by law)
Note: Your personal profile (name, photo, contact information) will still be deleted from the member directory and will not be visible to other users.
7. Your Rights and Choices
7.1 Access and Update
- You can view and update your profile information at any time through the App
- Access your family tree and manage family connections
- View your event registrations and payments
7.2 Data Deletion
- You can delete your posts at any time (subject to 7-day auto-deletion)
- Request account deletion by contacting: sonicommunitymumbai@gmail.com
- Note: Deleting your account removes your data from the member directory
7.3 Communication Preferences
- You control what information you share in your profile
- You can choose to participate in community posts and events
- Panel communications appear in the "Panel Post" section
7.4 Limitations
- Registration number and mobile number can only be modified by Panel/Admin members
- Some information may be retained for legal or administrative purposes even after account deletion
8. Children's Privacy & CSAE Prevention UPDATED
The App is intended for community members aged 18 and above. We do not knowingly collect personal information from individuals under 18. We maintain an absolute zero-tolerance policy toward Child Sexual Abuse and Exploitation (CSAE) and Child Sexual Abuse Material (CSAM) in all forms.
Children Under 18:
- Should be added to their parent's account only
- Should NOT create individual login accounts
- Their information is managed by their parent/guardian
- Profile data managed by parent/guardian
- No direct contact information collected
- Data deleted when parent account is deleted
8.1 Prohibited Content (CSAE/CSAM)
The following are strictly and explicitly prohibited on our platform:
- ๐ซ Child Sexual Abuse Material (CSAM) in any form
- ๐ซ Any content that sexually exploits or abuses children (CSAE)
- ๐ซ Grooming, sextortion, or any behaviour endangering minors
- ๐ซ Sharing, distributing, or soliciting exploitative content involving minors
- ๐ซ Any post, image, audio, or video that sexualises or harms children
- ๐ซ Facilitating trafficking or exploitation of minors
Violations result in immediate account suspension, permanent ban, and mandatory reporting to NCMEC and Indian law enforcement under the POCSO Act, 2012.
8.2 In-App Child Safety Reporting Mechanism NEW
Users can report any post or content that violates our Child Safety Standards directly within the app:
- Tap the ๐ก๏ธ Shield icon that appears on any other user's post in the Posts screen
- Select the violation category (e.g., "Child Safety Violation") and optionally add a description
- Submit โ our moderation team reviews all reports within 24โ48 hours
- Admins resolve reports via the dedicated Child Safety Reports queue in the Admin panel
Alternative: You may also report directly by emailing sonicommunitymumbai@gmail.com with the subject line "Child Safety Report". All reports are handled with strict confidentiality.
8.3 Full Child Safety Standards
Our complete Child Safety Standards โ including prohibited content, enforcement actions, CSAM handling declaration, and legal compliance โ are published at:
๐ Child Safety Standards URL:
https://srv1274900.hstgr.cloud/download/child-safety-standards.html
This document is publicly accessible, references Child Sexual Abuse and Exploitation (CSAE), and identifies this app (Soni Community App (Mumbai)) and its developer (Praveen M Soni), in compliance with Google Play's Child Safety Standards policy.
Compliance: COPPA-compliant (no direct collection from children under 13) ยท POCSO Act, 2012 ยท IT Act, 2000 ยท Google Play Child Safety Standards Policy
9. Third-Party Services
9.1 File Storage
- Provider: Hostinger (srv1274900.hstgr.cloud)
- Purpose: Profile photos, event media, payment screenshots
- Location: India
9.2 No Third-Party Analytics
We do NOT integrate with:
- โ Social media platforms
- โ Google Analytics
- โ Facebook SDK
- โ Advertising networks
- โ Data brokers
- โ Marketing platforms
All analytics are generated internally from our own database.
10. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by:
- Posting the new Privacy Policy in the App
- Updating the "Last Updated" date
- Sending a notification to all registered members (for significant changes)
Your continued use of the App after changes constitutes acceptance of the updated Privacy Policy.
12. Child Safety Standards Reference
Our full published Child Safety Standards โ explicitly prohibiting CSAE/CSAM as required by Google Play's Child Safety Standards policy โ are available at:
๐ https://srv1274900.hstgr.cloud/download/child-safety-standards.html
This document identifies our app (Soni Community App (Mumbai)), developer (Praveen M Soni), our in-app reporting mechanism, enforcement actions, CSAM handling declaration, and all applicable legal compliance measures.
13. Summary of Key Privacy Protections
Data Encryption: All data encrypted during transmission (HTTPS/TLS)
No Third-Party Sharing: Your data stays within the community
Auto-Delete: Posts automatically deleted after 30 days
Secure Storage: Encrypted tokens on your device using AsyncStorage
Auto-Logout: Automatic logout after 30 min inactivity
Account Deletion: Full deletion available within 30 days
No Ads: We never sell your data to advertisers
Community Only: Data visible only to authenticated members
Payment Security: No credit card or bank details stored
Child Safety Reporting: In-app ๐ก๏ธ shield button on posts for reporting CSAE/child safety violations โ reviewed by admins within 24โ48 hours
Zero Tolerance CSAE: Absolute prohibition on CSAM/CSAE โ violations reported to NCMEC and Indian authorities under POCSO Act