Privacy Policy
Table of Contents
Who We Are
This Privacy Policy is published by GameOn Sports Services Private Limited ("GameOn", "we", "us", "our"), a company incorporated under the Companies Act, 2013.
GameOn operates a Platform that allows users in India to discover, book, and pay for sports venues (turfs, courts, grounds, academies, and related facilities), to find and host matches with other players, and to engage with sports communities.
We are the data fiduciary under the Digital Personal Data Protection Act, 2023 ("DPDP Act") and the body corporate under the Information Technology Act, 2000 and the IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 ("SPDI Rules").
This Privacy Policy is published in compliance with:
- The Information Technology Act, 2000 and rules made thereunder, including the SPDI Rules and the IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021
- The Digital Personal Data Protection Act, 2023 (as and when fully notified, including its operative rules)
- The Consumer Protection Act, 2019 and the Consumer Protection (E-Commerce) Rules, 2020
Scope and Acceptance
By visiting the website, installing or using the GameOn app, or otherwise availing of the Platform, you confirm that you have read, understood, and agreed to this Privacy Policy and our Terms of Service. If you do not agree to any part of this Policy, please do not use the Platform.
This Policy applies to:
- Users who register and book venues, host or join matches, or interact with content
- Venue Partners who list facilities on GameOn
- Visitors to the website who do not create an account
- Any other person who provides personal data to us in connection with the Platform
This Policy does not apply to:
- Third-party websites, apps, or services to which we may link
- Data you provide directly to a Venue Partner outside the Platform
- Information that has been irreversibly anonymised or aggregated and cannot reasonably be linked to you
Personal Data We Collect
We collect only the data that is necessary to operate the Platform, to process your bookings, and to comply with applicable law.
3.1Data you give us directly
- Identity data: Full name, date of birth (to confirm you are 18+ or to obtain parental consent if between 13 and 18), gender (optional), profile photo (optional).
- Contact data: Mobile phone number (verified by OTP), email address, postal address (only if you ask us to ship or deliver something to you).
- Account credentials: Encrypted password or social-login token (Google / Apple sign-in); we never store your social provider password.
- Sports & profile data: Sports you play, skill level, preferred timings, preferred venues, teams or groups you create, match history, ratings and reviews.
- Booking and transaction data: Venues booked, sport, date, time slot, party size, amount, mode of payment, invoice details, refunds, and cancellation reasons.
- Communications data: Messages sent through our in-app chat, support tickets, emails, WhatsApp messages, and survey or feedback responses.
- Venue Partner data: Business name, owner / authorised representative name, PAN, GSTIN (where applicable), bank account details for settlement, photos of the venue, pricing, slot inventory, cancellation rules, and KYC documents we are legally required to verify.
3.2Data we collect automatically
- Device data: Device model, OS and version, unique device identifiers (Android Advertising ID, IDFA on iOS, or equivalents), mobile network operator, screen resolution, app version, time-zone, and language.
- Log data: IP address, login timestamps, session duration, screens viewed, taps and clicks, search queries, crash logs, and diagnostic information.
- Approximate and precise location data: With your prior in-app permission, we collect your precise GPS location to show you nearby venues, sort venue results by distance, and improve "venues near me" discovery. You can deny or revoke this permission at any time from device settings.
- Cookies and similar technologies (website only): First-party cookies and local storage to keep you signed in, remember your city, and measure aggregate usage. See Section 12.
3.3Data from phone contacts (optional, with permission)
If — and only if — you choose to invite friends to GameOn through our in-app "Invite friends" feature, we request your permission to read your phone's contact list. We use contacts data solely to:
- Display your contacts inside the invite screen so you can select whom to invite
- Send invitations (SMS / WhatsApp message) to the specific contacts you choose
- Match your contacts (using phone numbers) with existing GameOn users for "people you may know" suggestions
3.4Data we receive from third parties
- Payment gateway (Razorpay): Payment status, masked card or UPI identifier (last 4 digits / VPA prefix), gateway transaction ID, refund status. We never see or store your full card number, CVV, UPI PIN, OTP, or netbanking password.
- Identity / social sign-in (Google, Apple): Your name, email address, profile picture, and a unique provider ID. We do not receive your password.
- Venue Partners: Booking-related data the Venue Partner records on their end (check-in confirmation, no-show flag, walk-in fees).
- Public sources: Where required for Venue Partner KYC, publicly available registries (MCA, GST portal, PAN verification utilities).
3.5Sensitive personal data (SPDI)
Under the SPDI Rules, the following categories are "sensitive personal data or information" and we collect them only with your explicit consent and only where necessary:
- Passwords (stored only as a salted hash)
- Financial information such as bank account, card, or UPI details (handled by the payment gateway; we receive only masked tokens)
- Physical, physiological, or mental-health information — we do not collect this
- Sexual orientation — we do not collect this
- Biometric information — we do not collect this
How We Use Your Data
We will not use your personal data for any new purpose materially different from those listed below without first notifying you and, where required, obtaining your fresh consent.
| Purpose | Examples | Legal Basis |
|---|---|---|
| Account creation & authentication | Registering you, OTP login, password reset | Performance of contract; consent |
| Operating the Platform | Showing venues, processing bookings, sending confirmations, in-app chat | Performance of contract |
| Payments and refunds | Processing payments via Razorpay, refunds, invoices | Performance of contract; tax law compliance |
| Discovery & personalisation | "Venues near you", recommended slots, matches you may want to join | Legitimate interests; consent (precise location) |
| Communications | Booking confirmations, reminders, OTPs, customer support, transactional SMS / WhatsApp / push | Performance of contract; consent (for promotional messages) |
| Marketing | Newsletters, promotional offers, contests, referrals | Opt-in consent only — you can opt out any time |
| Safety, fraud prevention, security | Detecting payment fraud, spam, abusive behaviour, fake listings | Legitimate interests; compliance with law |
| Analytics & product improvement | Crash reports, feature usage, A/B tests (pseudonymised where possible) | Legitimate interests |
| Legal & regulatory compliance | Tax records, lawful government requests, dispute resolution | Compliance with law |
Push Notifications, SMS, and WhatsApp Messages
By creating an account, you consent to receive transactional communications necessary to operate the service:
- Booking confirmations, reminders, cancellation, and refund notifications
- One-time passwords (OTPs) for login and payment verification
- Match invites and chat messages from other users you have interacted with
- Account-security alerts
Promotional communications are sent only if you opt in during onboarding or in app settings. You can withdraw this consent at any time by:
- Toggling off "Promotional notifications" in Settings → Notifications
- Replying STOP to a promotional SMS
- Clicking "Unsubscribe" in any marketing email
- Sending DND requests through the in-app channel selector for WhatsApp
We comply with the TRAI Telecom Commercial Communications Customer Preference Regulations, 2018 (TCCCPR).
Cash-at-Venue, Booking Cancellation, and Refund Data
Where you choose Cash at Venue as a payment mode, we collect your booking commitment details (name, mobile, venue, slot) but do not process the payment through GameOn — the transaction settles directly with the Venue Partner.
For prepaid bookings, refund timelines and policies are governed by our Terms of Service and the Venue Partner's published cancellation policy. Refund-related data is retained for the statutory period required under the Income Tax Act, 1961 and the GST Act, 2017 — typically 8 years from the end of the financial year.
Where Your Data Is Stored, and Cross-Border Transfers
We store and process your personal data on cloud infrastructure located in India (AWS Mumbai / Hyderabad regions or equivalent India-region providers).
Some service providers (e.g., Google Firebase for crash reporting, our customer-support and email tooling) may process limited operational data on servers outside India. Where such transfer occurs, we ensure that:
- It is necessary for the contract or for legitimate business operations
- The receiving party is bound by a written agreement that provides at least the same level of data protection as required under Indian law
- The receiving country is not restricted under Section 16 of the DPDP Act
Data Retention
| Category of Data | Retention Period |
|---|---|
| Active account data (profile, bookings, communications) | Throughout the life of your account |
| Inactive accounts (no login for 24 consecutive months) | Reminder sent; if no login within 30 days, deactivated. Data retained only for legally required durations. |
| Transaction and tax records (invoices, refunds, GST data) | 8 years from end of financial year (Section 36, CGST Act) |
| KYC documents of Venue Partners | 8 years from end of business relationship (PMLA) |
| Marketing-consent records and consent withdrawals | 3 years after withdrawal |
| Server logs and crash diagnostics | 90 days, rolling |
| Customer-support tickets | 3 years after closure |
After the applicable retention period, we delete or irreversibly anonymise your personal data, except where retention is required under a legal hold, an ongoing dispute, or a request from a regulator.
Your Rights
As a Data Principal under the DPDP Act and the SPDI Rules, you have the following rights, exercisable free of charge by writing to support@gameon-india.com:
We respond to requests within 30 days of receipt (or sooner if required by law). To protect your data, we may need to verify your identity (typically by OTP) before acting on certain requests.
Account Deletion
You have the right to delete your GameOn account at any time. This section describes — in compliance with the Google Play Store and Apple App Store policies on account deletion — exactly how to request deletion, what data we delete, what data we are legally required to retain, and on what timeline.
11.1 How to request account deletion
You may request account deletion through any of the following channels:
| Channel | How |
|---|---|
| In-app | Open the GameOn app → Profile → Settings → Account → Delete Account → confirm. |
| Web | Visit www.gameon-india.com/delete-account — submit the form using your registered mobile number → confirm the OTP. |
| Email support@gameon-india.com from your registered email address with the subject line "Delete my account". We will respond with an OTP-based verification step. |
The web URL above is publicly accessible without logging in, in compliance with the Google Play Store Account Deletion requirements.
11.2 Verification
Before processing any deletion request, we will verify that you are the legitimate account owner — typically by sending a one-time password (OTP) to your registered mobile number or email address. This protects your account against unauthorised deletion by another person who may have temporary access to your device. Verification is normally completed within 24 hours of your request.
11.3 What we delete
Upon verification, we permanently delete the following categories of your personal data, from active production systems within 7 days, and from all rolling backups within 30 days:
- Profile data — your name, date of birth, gender, profile photograph, sports of interest, skill level, preferred timings, preferred venues, captain badges, and any saved-favourites lists.
- Contact data — your mobile number, email address, postal address (if any), and saved emergency-contact details.
- Account credentials — your password (stored only as a salted hash), Google / Apple social-login tokens, and authentication session tokens.
- Communications data — your in-app chat messages, customer-support tickets, in-app feedback, and survey responses, except where a ticket is the subject of a legal hold or an ongoing dispute.
- Device data — push-notification tokens, device identifiers, IDFA / Android Advertising ID associated with your account.
- Behavioural data — in-app search history, browse history, recommendation signals, A/B-test bucketing.
- Phone contacts data (if previously granted) — any matched contacts cached against your account.
- Location data — precise GPS coordinates and city/locality stored against your account.
11.4 What we anonymise (rather than delete)
The following are anonymised — your personally identifying information is removed, but the underlying record is preserved with no link to you:
- Reviews and ratings you have posted about venues. The review content stays attached to the venue (so future players continue to benefit from the feedback) but with the author identifier removed and replaced with "Former GameOn user." This is standard practice across rating platforms and is consistent with venue owners' contractual right to keep aggregated feedback on their listings.
- Aggregated and de-identified analytics that have already been irreversibly aggregated before your deletion request (for example, "300 bookings in Saket on Saturday evening") — these cannot be reversed and remain in our reporting.
11.5 What we are legally required to retain
Indian tax and regulatory law requires us to retain certain transaction-related records even after you delete your account. We retain only the minimum necessary records, with personally identifying fields redacted where possible:
| Category of retained data | Retention period | Legal basis | Why |
|---|---|---|---|
| Booking & transaction records (invoices, refunds, GST data, payment-gateway IDs) | 8 years from the end of the financial year in which the transaction occurred | Section 36, Central Goods and Services Tax Act, 2017; Income Tax Act, 1961 | Required for tax audit and GST reconciliation. |
| KYC documents (only if you are a Venue Partner) | 8 years from the end of the partner relationship | Prevention of Money Laundering Act, 2002 | Required AML/KYC retention. |
| Records subject to a legal hold, court order, or law-enforcement request | Until the legal matter is resolved | Mandatory compliance with lawful authority. Code of Criminal Procedure / IT Act, 2000 / court order | Mandatory compliance with lawful authority. |
| Records of marketing-consent grants and withdrawals | 3 years from withdrawal | Demonstrating consent under DPDP Act, 2023 | To prove we honoured opt-out requests. |
Within the retained records, your name, contact details and identifiers are redacted to the minimum extent permitted by law — typically your bookings become linked to a system identifier rather than your name and mobile.
11.6 What you cannot delete or recover after the request
- Past bookings - once you initiate account deletion, you cannot retrieve booking history, refund status, or invoice copies through your account. We recommend you download your data via Settings → Privacy → Download my data before initiating deletion, if you may need these records in the future.
- Active bookings - please cancel any upcoming bookings before requesting deletion. Pending bookings will be cancelled automatically (refunds will be processed per our standard cancellation policy), but you will not be able to attend bookings you had paid for.
- Pending refunds, credits or wallet balances - these are forfeited on account deletion unless you request them to be paid out to your registered bank account before deletion. We will not initiate refunds to a closed account.
- Reviews you posted - anonymised, not deleted (see §11.4).
11.7 Deactivation vs deletion
There is an important distinction:
| Feature | Deactivation | Deletion |
|---|---|---|
| What it does | Hides your profile and bookings from the public. You can log back in any time within 30 days and resume your account. | Permanently removes your personal data per §11.3. Cannot be reversed. |
| Reversible? | Yes, within 30 days. | No. |
| Default choice in the app? | Yes — when you tap "Delete Account" the first prompt offers Deactivation. You must explicitly tap "Permanently delete" to proceed to deletion. | No confirmation required. |
If you want a short break from GameOn, deactivation is the right choice. If you are sure you no longer want a GameOn account, choose deletion.
11.8 Timeline summary
| Step | Time from request |
|---|---|
| Acknowledgement email | Within 24 hours |
| Identity verification (OTP) | Within 24 hours |
| Active-data deletion from production | Within 7 days of verified request |
| Deletion from rolling backups | Within 30 days |
| Final confirmation email | On completion (within 30 days) |
Total maximum elapsed time, from request to full deletion: 30 days, in line with Section 12 of the DPDP Act, 2023.
11.9 Special situations
- Venue Partners. If you are a Venue Partner, your venue listing, booking history attached to the venue, and tax records remain (linked to your business entity rather than you personally). Your partner-personal data — name, contact, authorised-representative photo — is deleted on the same timeline. Detailed Partner-side terms are in the Partner Terms & Conditions.
- Users under 18. Deletion requests for accounts of users under 18 must be initiated by a parent or legal guardian. Contact support@gameon-india.com with proof of guardianship.
- Users with an active dispute, chargeback, or complaint. Deletion is deferred until the matter is resolved, and only the minimum data needed to resolve the dispute is retained for that period.
- Users with a legal hold. If a court, tribunal or law-enforcement agency has issued a hold on your records, we will inform you (unless legally prohibited) and defer deletion until the hold is lifted.
11.10 Re-registering after deletion
You may create a fresh GameOn account at any time using a different (or the same) mobile number. A new account starts with no history — you will not see your previously-completed bookings, captain badges, reviews you authored, or accumulated GameOn credits. The old account cannot be recovered or merged into the new one.
11.11 Questions
Any question about account deletion can be addressed to support@gameon-india.com or to our Grievance Officer (see Section 15). We do not charge a fee for account deletion under any circumstances.
Children's Privacy
The Platform is intended for users aged 18 and above. We do not knowingly collect personal data from children under 18 without verifiable parental consent.
If you are between 13 and 18, you may use the Platform only with the consent and supervision of a parent or legal guardian, who must register the account on your behalf and accept this Policy. Under the DPDP Act, we are required to obtain verifiable parental consent before processing data of a person under 18 and do not engage in behavioural tracking or targeted advertising directed at such persons.
If you believe a child under 18 has provided us personal data without verifiable parental consent, please contact us at support@gameon-india.com and we will delete such data promptly.
Security
We follow industry-accepted security practices, including:
In the event of a personal data breach likely to result in significant harm, we will notify the Data Protection Board (when constituted) and affected Data Principals as required under Section 8(6) of the DPDP Act, within the prescribed timelines.
No method of transmission or electronic storage is 100% secure. We commit to commercially reasonable measures.
Grievance Officer
In accordance with the Information Technology Act, 2000, the SPDI Rules, the Intermediary Guidelines, 2021, and the Consumer Protection (E-Commerce) Rules, 2020:
The Grievance Officer will acknowledge your complaint within 48 hours of receipt and resolve it within 15 days (or 1 month for sensitive personal data grievances, per the SPDI Rules).
Changes to This Privacy Policy
The "Last Updated" date at the top of this page always shows when this Policy was last revised. For material changes (new categories of data collected, new purposes, new third parties), we notify you via:
- An in-app notification on your next sign-in
- An email to your registered email address
- A prominent notice on the website homepage for at least 14 days
Your continued use of the Platform after such notice constitutes acceptance of the revised Policy.
Governing Law and Jurisdiction
This Privacy Policy is governed by the laws of India. Any dispute arising out of or in connection with this Policy is subject to the exclusive jurisdiction of the competent courts at Ghaziabad, Uttar Pradesh, India, without prejudice to any rights you may have under applicable consumer-protection laws.
Contact Us
Website: www.gameon-india.com
Appendices
Appendix A — Play Store Data Safety Disclosure
| Data Type | Collected? | Shared with Third Parties? | Purpose | Optional / Required |
|---|---|---|---|---|
| Name | Yes | Shared with Venue Partner for confirmed bookings | Account management; booking fulfilment | Required |
| Email address | Yes | No | Account management; communications | Required |
| Phone number | Yes | Shared with Venue Partner for confirmed bookings | OTP verification; booking fulfilment | Required |
| User IDs (account ID) | Yes | No | Account functionality | Required |
| Address | Yes (optional) | No | Communications, where you request | Optional |
| Approximate location | Yes | No | App functionality (city detection) | Optional |
| Precise location | Yes (with permission) | No | App functionality ("venues near me") | Optional |
| Phone contacts | Yes (with permission, for invites) | No (only contacts you choose to invite receive a message) | App functionality (Invite friends; "people you may know") | Optional |
| Photos (profile picture) | Yes (optional upload) | No | Personalisation | Optional |
| App interactions | Yes | No | Analytics; app functionality | Required |
| In-app search history | Yes | No | App functionality | Required |
| Crash logs | Yes | Processed by Google Firebase (processor only) | App stability | Required |
| Diagnostics | Yes | Processed by Google Firebase (processor only) | App stability | Required |
| Payment info (masked tokens only) | Yes | Processed by Razorpay (processor only) | Payment processing | Required for prepaid bookings |
| Purchase history | Yes | No | Account management | Required |
| Other financial info (full card / CVV / UPI PIN) | No — never collected | — | — | — |
| Health & fitness data | No | — | — | — |
| Sensitive personal info (race, religion, political opinion, sexual orientation, biometric, genetic) | No | — | — | — |
Security practices declared for Play Store:
- Data is encrypted in transit (HTTPS / TLS 1.2+).
- You can request that data be deleted (in-app + via support@gameon-india.com).
- Data collection and security practices follow Google Play's Families Policy where applicable.
Appendix B — Apple App Store Privacy Nutrition Label
- Data Used to Track You:None. GameOn does not track users across other companies' apps and websites.
- Data Linked to You:Name, Email, Phone Number, User ID, Address (optional), Precise Location (optional), Coarse Location, Contacts (with permission, invite flow only), Photos (profile, optional), Purchase History, Payment Info (masked tokens only), App Interactions, Search History, Customer Support communications, Crash Data, Performance Data, Diagnostics.
- Data Not Linked to You:None at launch.