Privacy Policy
Table of Contents
Who We Are
This Privacy Policy is published by GameOn Sports Services Private Limited ("GameOn", "we", "us", "our"), a company incorporated under the Companies Act, 2013.
GameOn operates a Platform that allows users in India to discover, book, and pay for sports venues (turfs, courts, grounds, academies, and related facilities), to find and host matches with other players, and to engage with sports communities.
We are the data fiduciary under the Digital Personal Data Protection Act, 2023 ("DPDP Act") and the body corporate under the Information Technology Act, 2000 and the IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 ("SPDI Rules").
This Privacy Policy is published in compliance with:
- The Information Technology Act, 2000 and rules made thereunder, including the SPDI Rules and the IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021
- The Digital Personal Data Protection Act, 2023 (as and when fully notified, including its operative rules)
- The Consumer Protection Act, 2019 and the Consumer Protection (E-Commerce) Rules, 2020
Scope and Acceptance
By visiting the website, installing or using the GameOn app, or otherwise availing of the Platform, you confirm that you have read, understood, and agreed to this Privacy Policy and our Terms of Service. If you do not agree to any part of this Policy, please do not use the Platform.
This Policy applies to:
- Users who register and book venues, host or join matches, or interact with content
- Venue Partners who list facilities on GameOn
- Visitors to the website who do not create an account
- Any other person who provides personal data to us in connection with the Platform
This Policy does not apply to:
- Third-party websites, apps, or services to which we may link
- Data you provide directly to a Venue Partner outside the Platform
- Information that has been irreversibly anonymised or aggregated and cannot reasonably be linked to you
Personal Data We Collect
We collect only the data that is necessary to operate the Platform, to process your bookings, and to comply with applicable law.
3.1Data you give us directly
- Identity data: Full name, date of birth (to confirm you are 18+ or to obtain parental consent if between 13 and 18), gender (optional), profile photo (optional).
- Contact data: Mobile phone number (verified by OTP), email address, postal address (only if you ask us to ship or deliver something to you).
- Account credentials: Encrypted password or social-login token (Google / Apple sign-in); we never store your social provider password.
- Sports & profile data: Sports you play, skill level, preferred timings, preferred venues, teams or groups you create, match history, ratings and reviews.
- Booking and transaction data: Venues booked, sport, date, time slot, party size, amount, mode of payment, invoice details, refunds, and cancellation reasons.
- Communications data: Messages sent through our in-app chat, support tickets, emails, WhatsApp messages, and survey or feedback responses.
- Venue Partner data: Business name, owner / authorised representative name, PAN, GSTIN (where applicable), bank account details for settlement, photos of the venue, pricing, slot inventory, cancellation rules, and KYC documents we are legally required to verify.
3.2Data we collect automatically
- Device data: Device model, OS and version, unique device identifiers (Android Advertising ID, IDFA on iOS, or equivalents), mobile network operator, screen resolution, app version, time-zone, and language.
- Log data: IP address, login timestamps, session duration, screens viewed, taps and clicks, search queries, crash logs, and diagnostic information.
- Approximate and precise location data: With your prior in-app permission, we collect your precise GPS location to show you nearby venues, sort venue results by distance, and improve "venues near me" discovery. You can deny or revoke this permission at any time from device settings.
- Cookies and similar technologies (website only): First-party cookies and local storage to keep you signed in, remember your city, and measure aggregate usage. See Section 11.
3.3Data from phone contacts (optional, with permission)
If — and only if — you choose to invite friends to GameOn through our in-app "Invite friends" feature, we request your permission to read your phone's contact list. We use contacts data solely to:
- Display your contacts inside the invite screen so you can select whom to invite
- Send invitations (SMS / WhatsApp message) to the specific contacts you choose
- Match your contacts (using phone numbers) with existing GameOn users for "people you may know" suggestions
3.4Data we receive from third parties
- Payment gateway (Razorpay): Payment status, masked card or UPI identifier (last 4 digits / VPA prefix), gateway transaction ID, refund status. We never see or store your full card number, CVV, UPI PIN, OTP, or netbanking password.
- Identity / social sign-in (Google, Apple): Your name, email address, profile picture, and a unique provider ID. We do not receive your password.
- Venue Partners: Booking-related data the Venue Partner records on their end (check-in confirmation, no-show flag, walk-in fees).
- Public sources: Where required for Venue Partner KYC, publicly available registries (MCA, GST portal, PAN verification utilities).
3.5Sensitive personal data (SPDI)
Under the SPDI Rules, the following categories are "sensitive personal data or information" and we collect them only with your explicit consent and only where necessary:
- Passwords (stored only as a salted hash)
- Financial information such as bank account, card, or UPI details (handled by the payment gateway; we receive only masked tokens)
- Physical, physiological, or mental-health information — we do not collect this
- Sexual orientation — we do not collect this
- Biometric information — we do not collect this
How We Use Your Data
We will not use your personal data for any new purpose materially different from those listed below without first notifying you and, where required, obtaining your fresh consent.
| Purpose | Examples | Legal Basis |
|---|---|---|
| Account creation & authentication | Registering you, OTP login, password reset | Performance of contract; consent |
| Operating the Platform | Showing venues, processing bookings, sending confirmations, in-app chat | Performance of contract |
| Payments and refunds | Processing payments via Razorpay, refunds, invoices | Performance of contract; tax law compliance |
| Discovery & personalisation | "Venues near you", recommended slots, matches you may want to join | Legitimate interests; consent (precise location) |
| Communications | Booking confirmations, reminders, OTPs, customer support, transactional SMS / WhatsApp / push | Performance of contract; consent (for promotional messages) |
| Marketing | Newsletters, promotional offers, contests, referrals | Opt-in consent only — you can opt out any time |
| Safety, fraud prevention, security | Detecting payment fraud, spam, abusive behaviour, fake listings | Legitimate interests; compliance with law |
| Analytics & product improvement | Crash reports, feature usage, A/B tests (pseudonymised where possible) | Legitimate interests |
| Legal & regulatory compliance | Tax records, lawful government requests, dispute resolution | Compliance with law |
Push Notifications, SMS, and WhatsApp Messages
By creating an account, you consent to receive transactional communications necessary to operate the service:
- Booking confirmations, reminders, cancellation, and refund notifications
- One-time passwords (OTPs) for login and payment verification
- Match invites and chat messages from other users you have interacted with
- Account-security alerts
Promotional communications are sent only if you opt in during onboarding or in app settings. You can withdraw this consent at any time by:
- Toggling off "Promotional notifications" in Settings → Notifications
- Replying STOP to a promotional SMS
- Clicking "Unsubscribe" in any marketing email
- Sending DND requests through the in-app channel selector for WhatsApp
We comply with the TRAI Telecom Commercial Communications Customer Preference Regulations, 2018 (TCCCPR).
Cash-at-Venue, Booking Cancellation, and Refund Data
Where you choose Cash at Venue as a payment mode, we collect your booking commitment details (name, mobile, venue, slot) but do not process the payment through GameOn — the transaction settles directly with the Venue Partner.
For prepaid bookings, refund timelines and policies are governed by our Terms of Service and the Venue Partner's published cancellation policy. Refund-related data is retained for the statutory period required under the Income Tax Act, 1961 and the GST Act, 2017 — typically 8 years from the end of the financial year.
Where Your Data Is Stored, and Cross-Border Transfers
We store and process your personal data on cloud infrastructure located in India (AWS Mumbai / Hyderabad regions or equivalent India-region providers).
Some service providers (e.g., Google Firebase for crash reporting, our customer-support and email tooling) may process limited operational data on servers outside India. Where such transfer occurs, we ensure that:
- It is necessary for the contract or for legitimate business operations
- The receiving party is bound by a written agreement that provides at least the same level of data protection as required under Indian law
- The receiving country is not restricted under Section 16 of the DPDP Act
Data Retention
| Category of Data | Retention Period |
|---|---|
| Active account data (profile, bookings, communications) | Throughout the life of your account |
| Inactive accounts (no login for 24 consecutive months) | Reminder sent; if no login within 30 days, deactivated. Data retained only for legally required durations. |
| Transaction and tax records (invoices, refunds, GST data) | 8 years from end of financial year (Section 36, CGST Act) |
| KYC documents of Venue Partners | 8 years from end of business relationship (PMLA) |
| Marketing-consent records and consent withdrawals | 3 years after withdrawal |
| Server logs and crash diagnostics | 90 days, rolling |
| Customer-support tickets | 3 years after closure |
After the applicable retention period, we delete or irreversibly anonymise your personal data, except where retention is required under a legal hold, an ongoing dispute, or a request from a regulator.
Your Rights
As a Data Principal under the DPDP Act and the SPDI Rules, you have the following rights, exercisable free of charge by writing to support@gameon-india.com:
We respond to requests within 30 days of receipt (or sooner if required by law). To protect your data, we may need to verify your identity (typically by OTP) before acting on certain requests.
Children's Privacy
The Platform is intended for users aged 18 and above. We do not knowingly collect personal data from children under 18 without verifiable parental consent.
If you are between 13 and 18, you may use the Platform only with the consent and supervision of a parent or legal guardian, who must register the account on your behalf and accept this Policy. Under the DPDP Act, we are required to obtain verifiable parental consent before processing data of a person under 18 and do not engage in behavioural tracking or targeted advertising directed at such persons.
If you believe a child under 18 has provided us personal data without verifiable parental consent, please contact us at support@gameon-india.com and we will delete such data promptly.
Security
We follow industry-accepted security practices, including:
In the event of a personal data breach likely to result in significant harm, we will notify the Data Protection Board (when constituted) and affected Data Principals as required under Section 8(6) of the DPDP Act, within the prescribed timelines.
No method of transmission or electronic storage is 100% secure. We commit to commercially reasonable measures.
Grievance Officer
In accordance with the Information Technology Act, 2000, the SPDI Rules, the Intermediary Guidelines, 2021, and the Consumer Protection (E-Commerce) Rules, 2020:
The Grievance Officer will acknowledge your complaint within 48 hours of receipt and resolve it within 15 days (or 1 month for sensitive personal data grievances, per the SPDI Rules).
Changes to This Privacy Policy
The "Last Updated" date at the top of this page always shows when this Policy was last revised. For material changes (new categories of data collected, new purposes, new third parties), we notify you via:
- An in-app notification on your next sign-in
- An email to your registered email address
- A prominent notice on the website homepage for at least 14 days
Your continued use of the Platform after such notice constitutes acceptance of the revised Policy.
Governing Law and Jurisdiction
This Privacy Policy is governed by the laws of India. Any dispute arising out of or in connection with this Policy is subject to the exclusive jurisdiction of the competent courts at Ghaziabad, Uttar Pradesh, India, without prejudice to any rights you may have under applicable consumer-protection laws.
Appendices
Appendix A — Play Store Data Safety Disclosure
| Data Type | Collected? | Shared with Third Parties? | Purpose | Optional / Required |
|---|---|---|---|---|
| Name | Yes | Shared with Venue Partner for confirmed bookings | Account management; booking fulfilment | Required |
| Email address | Yes | No | Account management; communications | Required |
| Phone number | Yes | Shared with Venue Partner for confirmed bookings | OTP verification; booking fulfilment | Required |
| User IDs (account ID) | Yes | No | Account functionality | Required |
| Address | Yes (optional) | No | Communications, where you request | Optional |
| Approximate location | Yes | No | App functionality (city detection) | Optional |
| Precise location | Yes (with permission) | No | App functionality ("venues near me") | Optional |
| Phone contacts | Yes (with permission, for invites) | No (only contacts you choose to invite receive a message) | App functionality (Invite friends; "people you may know") | Optional |
| Photos (profile picture) | Yes (optional upload) | No | Personalisation | Optional |
| App interactions | Yes | No | Analytics; app functionality | Required |
| In-app search history | Yes | No | App functionality | Required |
| Crash logs | Yes | Processed by Google Firebase (processor only) | App stability | Required |
| Diagnostics | Yes | Processed by Google Firebase (processor only) | App stability | Required |
| Payment info (masked tokens only) | Yes | Processed by Razorpay (processor only) | Payment processing | Required for prepaid bookings |
| Purchase history | Yes | No | Account management | Required |
| Other financial info (full card / CVV / UPI PIN) | No — never collected | — | — | — |
| Health & fitness data | No | — | — | — |
| Sensitive personal info (race, religion, political opinion, sexual orientation, biometric, genetic) | No | — | — | — |
Security practices declared for Play Store:
- Data is encrypted in transit (HTTPS / TLS 1.2+).
- You can request that data be deleted (in-app + via support@gameon-india.com).
- Data collection and security practices follow Google Play's Families Policy where applicable.
Appendix B — Apple App Store Privacy Nutrition Label
- Data Used to Track You:None. GameOn does not track users across other companies' apps and websites.
- Data Linked to You:Name, Email, Phone Number, User ID, Address (optional), Precise Location (optional), Coarse Location, Contacts (with permission, invite flow only), Photos (profile, optional), Purchase History, Payment Info (masked tokens only), App Interactions, Search History, Customer Support communications, Crash Data, Performance Data, Diagnostics.
- Data Not Linked to You:None at launch.