PairNow

Privacy Policy

Version 1.2 · Last updated 19 August 2026 · Nxtspacelabs Private Limited

How PairNow collects, uses, protects and shares your data — written plainly, and backed by the controls we actually run.


Data at a glance

A one-screen summary for the impatient. The full sections below are the authoritative text.

Data type Do we collect it? Why Who else sees it How long we keep it
Phone number Yes To create your account (OTP) Our OTP / SMS provider Account life + 30 days after deletion
Display name, gender, age, photo Yes To let you match + call Other Users you interact with Account life + 30 days after deletion
KYC (PAN, ID, bank details) — Creators only Yes, for Creators Payout + statutory compliance Our payment partner, our tax filings, statutory authorities 8 years (Income Tax Act) after last payout
Video / voice call content No — we don't record calls
Call metadata (who, when, duration, Butterflies spent) Yes Billing, dispute resolution, safety Both call participants (their side of the record) 12 months
Chat metadata Yes Message delivery + safety Recipient 90 days
Face-gate presence check (video calls) On-device only — no image leaves your phone To pause video when a face isn't visible No one — never transmitted Not retained. Only aggregate counters (paused seconds, face-detected-at-end flag)
Aadhaar (if collected during Creator KYC) Only last-4 digits are readable to us; the rest is masked before storage Statutory KYC only Our payment partner's KYC pipeline Account life + 8 years (PMLA / IT Act)
Financial transactions (Butterflies purchase, gift, withdrawal) Yes Ledger, tax, refund Our payment partner (payment leg), our accountants 8 years (Income Tax Act)
Device model + IP + crash logs Yes Compatibility, security, debugging Our crash-reporting and analytics providers 90 days
Face-gate biometric scan (if a future paid ID-verification is enabled — currently NOT active) Only if you explicitly opt in ID verification On-device or named third-party (would be disclosed) 30 days maximum

Good to know We never sell your data. We never listen to or record your calls. Face-gate lives on your phone, not our servers.


1. Definitions

  • "Personal Data" — data about an individual who is identifiable by or in relation to such data.
  • "Sensitive Personal Data or Information" ("SPDI") — as defined under the SPDI Rules; includes financial information such as bank account, payment instrument and KYC details.
  • "Processing" — any operation performed on Personal Data (collection, storage, use, sharing, disclosure, erasure, destruction).
  • "Data Principal" — the natural person to whom the Personal Data relates.
  • "Data Fiduciary" — the person who, alone or in conjunction with others, determines the purpose and means of processing (that's us).
  • "Company", "we", "us", "our" — Nxtspacelabs Private Limited, a company incorporated under the Companies Act 2013 with its registered office at Hyderabad, Telangana, India.

This Policy describes how the Company collects, uses, stores, shares, transfers and protects the Personal Data of Users and Creators ("you", "your") of the PairNow mobile application and associated services ("Platform", "PairNow", "Services").

Legal basis for this document: electronic record published under the Information Technology Act 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules 2011 ("SPDI Rules"), the IT (Intermediary Guidelines and Digital Media Ethics Code) Rules 2021 ("IT Rules 2021"), and the Digital Personal Data Protection Act 2023 ("DPDP Act"). For the purposes of the DPDP Act, the Company is a Data Fiduciary and you are the Data Principal.

By creating an account, accessing or using PairNow, you acknowledge that you have read and understood this Policy. Where processing is based on consent, your consent is sought separately and expressly as described below.


2. Eligibility — Adults Only

PairNow is strictly for persons aged eighteen (18) years or above. We do not knowingly permit the registration of, or the collection of Personal Data from, any person below 18, whether as a User or a Creator.

Good to know We back this up with more than a checkbox — see Section 12 for the actual controls we run.

Read alongside our Age Restriction & Child Safety Policy.


3. Personal Data We Collect

3.1 Identity and account data

Mobile phone number, name/display name, gender, age and date of birth, profile photograph and profile information you provide.

3.2 Verification data (Creators only)

KYC information including PAN, government-issued identity document, photograph, bank account details, and such other information required for onboarding, payout and statutory compliance. Aadhaar handling: if you provide an Aadhaar-linked ID, we display and store only the last 4 digits for verification-match purposes; the remaining digits are masked before persistence, in line with UIDAI guidelines.

3.3 Financial and transaction data

Records of Butterflies purchased, gifts sent, earnings and withdrawals. Card, UPI, netbanking and other payment-instrument data are collected and processed by our payment partner, not stored by us.

3.4 Device and technical data

Device model and identifiers, operating system, IP address, network information, app version, language, crash logs and diagnostic data.

3.5 Interaction and call metadata

The fact, time, duration, participants and Butterflies value of 1:1 video/voice calls and live rooms, gifting activity and in-app chat metadata.

Good to know We do not routinely record or monitor the content of your calls. Where a call, chat or stream is flagged (by automated systems or user reports) for suspected violation of law or our policies, relevant Content, recordings or screenshots may be captured, reviewed and preserved for safety, moderation and legal-compliance purposes only. Content is examined by our human moderation team — not indexed, not used for ads, not shared beyond the immediate safety review.

3.6 On-device presence check (Face-gate) — video calls

When the presence-check feature is enabled for your account, the app uses an on-device face-detection component to check whether a face is visible in your camera preview. This check runs entirely on your phone.

  • What is processed: camera-preview video frames, read directly from your device's camera, examined on-device for the presence of a face and (optionally) low-resolution landmark signals such as whether eyes appear open.
  • What we do NOT do: we do not extract, derive, or store any biometric identifier — the check reports only present or absent.
  • Where it happens: on this phone, in-process. No camera frame, image, or face-detection output is transmitted to PairNow servers, to your call partner, to Google, or to any third party. Nothing is written to persistent storage. The check runs only while a video call is active.
  • What we retain: aggregate, non-identifying counters — how often the gate paused a call, total paused seconds, whether a face was detected at call end. These counters contain no image data, no face data, and no information that could re-identify a specific frame.
  • Your control: on your first video call after this feature is turned on for your account, you will see a notice describing it and can choose Enable or Not now. You may change your choice from Settings → Privacy → Video presence check at any time. Declining does not affect your ability to make video calls; the presence check simply stays off for your account.
  • Legal basis (India — DPDP Act 2023): on-device processing of your camera preview for the sole purpose of the described real-time UX, based on your consent, with no cross-border transfer, no linkage to your identity beyond the call session, and no retention of the raw processed data.

3.7 Usage and analytics data

Features used, session information, preferences and engagement data collected via SDKs and analytics tools (see Section 6 for the named list of processors).

3.8 Support and grievance data

Communications you send to us, reports you file, and correspondence with our Grievance Officer.


4. Purposes of Processing and Lawful Basis

We process your Personal Data for the following purposes. Under the DPDP Act, our primary lawful basis is your consent, obtained at or before the point of collection. Certain processing is also carried out for "certain legitimate uses" permitted under Section 7 of the DPDP Act, and to discharge legal obligations.

  1. To create, verify, operate and secure your account.
  2. To enable real-time 1:1 video/voice calls, live rooms, chats and gifting between Users and Creators.
  3. To process purchase of Butterflies, Creator earnings and withdrawals through our payment partner.
  4. To conduct KYC, age verification, fraud prevention, anti-money-laundering and tax compliance.
  5. To operate content moderation, trust and safety, and to detect, prevent and act on illegal or prohibited conduct including child sexual abuse or exploitation.
  6. To provide customer support and to receive and resolve grievances.
  7. To perform analytics, improve, personalise and secure the Platform, and prevent misuse.
  8. To send service, transactional and, where you consent, promotional communications.
  9. To comply with law and respond to lawful requests from courts, regulators and law-enforcement agencies.

Good to know We only ask for what a specific feature needs. Adding a payment method asks for payment info. Making a call asks for microphone. Enabling face-gate asks for camera. Every ask names why.


  1. Consent is obtained through clear, affirmative action accompanied by an itemised notice describing the Personal Data sought and the purpose, in accordance with Sections 5 and 6 of the DPDP Act, available in English and, on request, in the languages specified in the Eighth Schedule to the Constitution.
  2. You may withdraw your consent at any time, with ease comparable to the manner in which it was given, through in-app settings or by writing to our Grievance Officer/Data Protection Officer. Withdrawal will not affect the lawfulness of prior processing and may limit or end your ability to use some or all Services.
  3. Where you have engaged a Consent Manager registered with the Data Protection Board of India, you may manage consent through such Consent Manager.

6. Sharing and Disclosure of Personal Data

We do not sell your Personal Data. We share it only as follows:

6.1 Third-party processors (by category)

Each of the following processes Personal Data on our behalf under a written data-processing contract that limits use to our instructions and to the purposes named here. We disclose processors by category, as the DPDP Act requires:

Processor category Purpose Data categories
Payment partner Purchases, payouts, KYC, reconciliation, refund Name, PAN, bank account, UPI VPA, card/UPI transactions, KYC documents
Cloud hosting provider Encrypted storage of profile, chat metadata, call ledger, wallet balances All Personal Data listed in Section 3 except call content and face-gate frames
Real-time calling provider Real-time voice/video call transport Ephemeral RTC session tokens, call transport signals (no call content stored)
OTP / SMS provider OTP delivery for phone verification Phone number, OTP
Analytics provider Product analytics (feature usage, funnels) Device identifiers, session events, no direct identifiers
Crash-reporting provider Crash and error reporting Stack traces, device model, app version — no PII by policy
Push-notification provider Push notifications Device push token, notification payload

6.2 Other Users / Creators

Limited profile information necessary to enable calls, rooms and gifting is shown to the person you interact with.

6.3 Law enforcement and authorities

Where required by law, court order or lawful direction, or to protect safety, prevent crime (including child sexual abuse and exploitation), and enforce our terms.

6.4 Corporate transactions

With acquirers or successors in a merger, reorganisation or transfer of business, subject to this Policy.

Good to know No processor listed above has permission to reuse your data for their own marketing. Our payment partner may retain payment records for statutory reasons; every other processor operates strictly on our instructions.


7. Cross-Border Transfer

Your Personal Data is primarily stored and processed in India. Where processors or infrastructure are located outside India, we may transfer Personal Data abroad subject to: - appropriate contractual safeguards (standard data-processing terms, security representations), and - only to countries not restricted by the Central Government under Section 16 of the DPDP Act.

Current out-of-India processing (subject to change; see Section 6 for the processor categories): - Our crash / error-reporting provider may route error events via EU infrastructure. - Our product-analytics provider's primary region is the United States. - Our push-notification provider operates from its global infrastructure.


8. Data Retention and Deletion — Specific Timelines

We retain Personal Data only for as long as necessary for the purposes for which it was collected, to provide the Services, and to comply with legal, tax, accounting, safety and dispute-resolution obligations.

Data category Retention period
Account profile (nickname, photo, gender, DOB) Account life + 30 days grace after deletion
Phone number Retained after deletion only to prevent a deleted or banned account from re-registering, and for any legally-required period
Call metadata (participants, duration, Butterflies) 12 months rolling
Chat metadata 90 days rolling
Financial transaction records 8 years (Income Tax Act, PMLA)
KYC documents (Creator) Account life + 8 years after last payout (PMLA / IT Act)
Face-gate raw frames Not retained. Aggregate call-counters only, 12 months.
Support tickets 3 years from ticket close
Grievance Officer records 3 years (IT Rules 2021 Section 3(2))
Crash logs / device diagnostics 90 days
Records relating to suspected or actual child sexual abuse/exploitation Preserved for the periods required by the IT Rules 2021 and criminal law, notwithstanding any deletion request

On expiry of the retention period, on account closure, or on withdrawal of consent where no other lawful basis applies, we delete or anonymise your Personal Data in accordance with Section 8(7) of the DPDP Act.

Good to know When you delete your account, your PairNow profile (name, photo and other profile details) is removed promptly. We keep a minimal record afterwards — including your phone number — so the account cannot be re-registered and so we can meet legal, tax and safety retention duties (e.g. 8-year financial records). Deletion is not reversible, so please export anything you want to keep beforehand.


9. Data Security

We implement reasonable security practices and procedures as required under Section 8 of the DPDP Act and the SPDI Rules, which may include, without limitation, encryption of data in transit and at rest, access controls on a need-to-know basis with audit logs, secure handling of KYC and financial data through our payment partners' pipelines, network and application security controls, periodic review of our security posture, and staff confidentiality obligations, in each case as we consider commercially appropriate and as our security posture evolves over time.

No method of transmission or storage is fully secure; in the event of a breach, we will act as set out in Section 13.


10. Your Rights as a Data Principal

Subject to the DPDP Act, you have the following rights:

Right What it means for you
Access (Section 11(1)(a) DPDP) Ask us for a summary of your Personal Data and how it's processed.
Correction, completion, updating (Section 12(1) DPDP) Fix anything wrong or incomplete in your profile or records.
Erasure (Section 12(3) DPDP) Ask us to delete your data (except where retention is required by law — see Section 8).
Data portability (implicit under Section 11(1)(a) DPDP with Section 12 completion right) Request an export of your Personal Data in a machine-readable format.
Restrict or object to processing (implicit under Section 6(4) DPDP withdrawal right, applied to specific purposes) Turn off specific processing categories (e.g. analytics, marketing) while keeping your core account.
Grievance redressal (Section 13 DPDP) Complain to our Grievance Officer; escalate to the Data Protection Board of India if unsatisfied.
Nominate (Section 14 DPDP) Nominate another individual to exercise your rights on your death or incapacity.
Withdraw consent (Section 6(4) DPDP) Withdraw consent at any time — as easy to withdraw as it was to give.

Automated decisions (Section 11 rights around profiling): our platform runs automated systems for spam detection, fraud detection on payments and gifts, content-moderation flags, and matching signals. You have the right to request a manual review by writing to our Grievance Officer if you believe an automated decision has affected you unfairly. See Section 11 below.

You may exercise these rights through in-app settings or by contacting our Grievance Officer/Data Protection Officer; we may verify your identity first. You have a corresponding duty under Section 15 of the DPDP Act not to furnish false particulars or file frivolous complaints. If unsatisfied, you may complain to the Data Protection Board of India.

Good to know For most rights, the fastest path is in-app: Profile → Privacy → the specific action. Grievance Officer is for anything the app doesn't offer directly.


11. Automated Decision-Making and Profiling

The following operations run in whole or in part without human review:

Operation What it does Human-review path
Payment fraud detection Flags unusual purchase patterns; can block a suspicious transaction Contact Grievance Officer; we review + release the block if legitimate
Gift-abuse detection Detects abuse patterns in the Butterflies gifting economy Same as above
Content moderation flags Automated flags on flagged text/image/audio for policy violation Every flag before enforcement action goes to human moderation queue
Age/liveness signals Behavioural + optional face-gate signals to detect under-18 accounts Contact support with ID; we manually verify
Match ranking Weighted ordering of profiles based on your and their signals You can adjust preferences in Settings; no manual "re-rank" service

You have the right to know when an automated decision has been made about you, to receive a plain-English explanation of the main factors, and to request a manual review. Write to our Grievance Officer.


12. Children's Data

PairNow is not intended for and is not available to persons under 18. We deploy reasonable measures, which may include self-declaration, date-of-birth capture, KYC for Creators, and behavioural or AI signals, to seek to prevent registration and use by minors, and we do not knowingly process any child's Personal Data or undertake tracking or targeted advertising directed at children. No warranty is given that these measures will detect or prevent every attempt to circumvent them. If we learn that a minor has provided data or is using the Platform, we will terminate the account and delete the data, subject to legal-preservation requirements.

Read alongside our Age Restriction & Child Safety Policy (CSAE).


13. Breach Notification; Cookies/SDKs

13.1 Breach notification

In the event of a personal data breach, we will notify the Data Protection Board of India and each affected Data Principal in the manner and within the timelines prescribed under the DPDP Act and its rules, and comply with applicable CERT-In directions under the IT Act 2000 (currently: within six hours for CERT-In reportable events; within the timelines specified by the DPDP rules for DPB notification).

13.2 Cookies / SDKs

The Platform uses SDKs, device identifiers and analytics tools to operate calls and streaming, remember preferences, measure performance, prevent fraud and improve the Services. Where required, we obtain consent for non-essential SDKs and analytics (our product-analytics and crash-reporting tools).


14. Grievance Officer and Data Protection Officer

Grievance Officer: Mr. G. Uday Sai Nath — grievance.officer@pairnow.in Data Protection Officer: Mr. G. Uday Sai Nath — grievance.officer@pairnow.in General support / help: support@pairnow.in

Registered office: Nxtspacelabs Private Limited (CIN: U62011TS2026PTC218876), H No. 1-60/8/A & B, 3rd Floor, KNR Square, Gachibowli, Hyderabad, Rangareddy, Telangana – 500032, India

The Grievance Officer will acknowledge complaints within 24 hours and resolve them within 15 days as prescribed under IT Rules 2021 Section 3(2). This Policy is governed by the laws of India, with exclusive jurisdiction at the courts of Hyderabad, Telangana, subject to the statutory forums under the DPDP Act.

Read alongside our Grievance Redressal Policy for the full escalation ladder.


15. Changes to This Policy

We may update this Policy from time to time; continued use after the effective date constitutes acceptance, save where fresh consent is required by law.

© 2026 Nxtspacelabs Private Limited Home Safety Center Terms of Use Refund Policy Community Guidelines support@pairnow.in