Legal Document

Privacy Policy

Effective: 4 May 2026
Updated: 20 May 2026
India

Table of Contents

01

Who We Are

This Privacy Policy is published by GameOn Sports Services Private Limited ("GameOn", "we", "us", "our"), a company incorporated under the Companies Act, 2013.

CINU93290UW2026PTC252581
Date of Incorporation4 May 2026
Registered OfficeKH-126, Bypass Road, Shanti Shivpuri, Ghaziabad, Uttar Pradesh — 201001, India
Emailsupport@gameon-india.com
Phone+91 88961 72818

GameOn operates a Platform that allows users in India to discover, book, and pay for sports venues (turfs, courts, grounds, academies, and related facilities), to find and host matches with other players, and to engage with sports communities.

We are the data fiduciary under the Digital Personal Data Protection Act, 2023 ("DPDP Act") and the body corporate under the Information Technology Act, 2000 and the IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 ("SPDI Rules").

This Privacy Policy is published in compliance with:

  • The Information Technology Act, 2000 and rules made thereunder, including the SPDI Rules and the IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021
  • The Digital Personal Data Protection Act, 2023 (as and when fully notified, including its operative rules)
  • The Consumer Protection Act, 2019 and the Consumer Protection (E-Commerce) Rules, 2020
This document does not require any digital or physical signature and is a legally binding electronic record under the Information Technology Act, 2000.
02

Scope and Acceptance

By visiting the website, installing or using the GameOn app, or otherwise availing of the Platform, you confirm that you have read, understood, and agreed to this Privacy Policy and our Terms of Service. If you do not agree to any part of this Policy, please do not use the Platform.

This Policy applies to:

  • Users who register and book venues, host or join matches, or interact with content
  • Venue Partners who list facilities on GameOn
  • Visitors to the website who do not create an account
  • Any other person who provides personal data to us in connection with the Platform

This Policy does not apply to:

  • Third-party websites, apps, or services to which we may link
  • Data you provide directly to a Venue Partner outside the Platform
  • Information that has been irreversibly anonymised or aggregated and cannot reasonably be linked to you
03

Personal Data We Collect

We collect only the data that is necessary to operate the Platform, to process your bookings, and to comply with applicable law.

3.1Data you give us directly

  • Identity data: Full name, date of birth (to confirm you are 18+ or to obtain parental consent if between 13 and 18), gender (optional), profile photo (optional).
  • Contact data: Mobile phone number (verified by OTP), email address, postal address (only if you ask us to ship or deliver something to you).
  • Account credentials: Encrypted password or social-login token (Google / Apple sign-in); we never store your social provider password.
  • Sports & profile data: Sports you play, skill level, preferred timings, preferred venues, teams or groups you create, match history, ratings and reviews.
  • Booking and transaction data: Venues booked, sport, date, time slot, party size, amount, mode of payment, invoice details, refunds, and cancellation reasons.
  • Communications data: Messages sent through our in-app chat, support tickets, emails, WhatsApp messages, and survey or feedback responses.
  • Venue Partner data: Business name, owner / authorised representative name, PAN, GSTIN (where applicable), bank account details for settlement, photos of the venue, pricing, slot inventory, cancellation rules, and KYC documents we are legally required to verify.

3.2Data we collect automatically

  • Device data: Device model, OS and version, unique device identifiers (Android Advertising ID, IDFA on iOS, or equivalents), mobile network operator, screen resolution, app version, time-zone, and language.
  • Log data: IP address, login timestamps, session duration, screens viewed, taps and clicks, search queries, crash logs, and diagnostic information.
  • Approximate and precise location data: With your prior in-app permission, we collect your precise GPS location to show you nearby venues, sort venue results by distance, and improve "venues near me" discovery. You can deny or revoke this permission at any time from device settings.
  • Cookies and similar technologies (website only): First-party cookies and local storage to keep you signed in, remember your city, and measure aggregate usage. See Section 11.

3.3Data from phone contacts (optional, with permission)

If — and only if — you choose to invite friends to GameOn through our in-app "Invite friends" feature, we request your permission to read your phone's contact list. We use contacts data solely to:

  • Display your contacts inside the invite screen so you can select whom to invite
  • Send invitations (SMS / WhatsApp message) to the specific contacts you choose
  • Match your contacts (using phone numbers) with existing GameOn users for "people you may know" suggestions
We do not upload your full contact list to our servers as a continuous sync, sell contact data, share contact data with advertisers, or use contact data for any purpose other than the invite and "people you may know" features.

3.4Data we receive from third parties

  • Payment gateway (Razorpay): Payment status, masked card or UPI identifier (last 4 digits / VPA prefix), gateway transaction ID, refund status. We never see or store your full card number, CVV, UPI PIN, OTP, or netbanking password.
  • Identity / social sign-in (Google, Apple): Your name, email address, profile picture, and a unique provider ID. We do not receive your password.
  • Venue Partners: Booking-related data the Venue Partner records on their end (check-in confirmation, no-show flag, walk-in fees).
  • Public sources: Where required for Venue Partner KYC, publicly available registries (MCA, GST portal, PAN verification utilities).

3.5Sensitive personal data (SPDI)

Under the SPDI Rules, the following categories are "sensitive personal data or information" and we collect them only with your explicit consent and only where necessary:

  • Passwords (stored only as a salted hash)
  • Financial information such as bank account, card, or UPI details (handled by the payment gateway; we receive only masked tokens)
  • Physical, physiological, or mental-health information — we do not collect this
  • Sexual orientation — we do not collect this
  • Biometric information — we do not collect this
04

How We Use Your Data

We will not use your personal data for any new purpose materially different from those listed below without first notifying you and, where required, obtaining your fresh consent.

PurposeExamplesLegal Basis
Account creation & authenticationRegistering you, OTP login, password resetPerformance of contract; consent
Operating the PlatformShowing venues, processing bookings, sending confirmations, in-app chatPerformance of contract
Payments and refundsProcessing payments via Razorpay, refunds, invoicesPerformance of contract; tax law compliance
Discovery & personalisation"Venues near you", recommended slots, matches you may want to joinLegitimate interests; consent (precise location)
CommunicationsBooking confirmations, reminders, OTPs, customer support, transactional SMS / WhatsApp / pushPerformance of contract; consent (for promotional messages)
MarketingNewsletters, promotional offers, contests, referralsOpt-in consent only — you can opt out any time
Safety, fraud prevention, securityDetecting payment fraud, spam, abusive behaviour, fake listingsLegitimate interests; compliance with law
Analytics & product improvementCrash reports, feature usage, A/B tests (pseudonymised where possible)Legitimate interests
Legal & regulatory complianceTax records, lawful government requests, dispute resolutionCompliance with law
05

Push Notifications, SMS, and WhatsApp Messages

By creating an account, you consent to receive transactional communications necessary to operate the service:

  • Booking confirmations, reminders, cancellation, and refund notifications
  • One-time passwords (OTPs) for login and payment verification
  • Match invites and chat messages from other users you have interacted with
  • Account-security alerts
Transactional communications are part of the service and cannot be turned off entirely without deactivating your account.

Promotional communications are sent only if you opt in during onboarding or in app settings. You can withdraw this consent at any time by:

  • Toggling off "Promotional notifications" in Settings → Notifications
  • Replying STOP to a promotional SMS
  • Clicking "Unsubscribe" in any marketing email
  • Sending DND requests through the in-app channel selector for WhatsApp

We comply with the TRAI Telecom Commercial Communications Customer Preference Regulations, 2018 (TCCCPR).

06

Cash-at-Venue, Booking Cancellation, and Refund Data

Where you choose Cash at Venue as a payment mode, we collect your booking commitment details (name, mobile, venue, slot) but do not process the payment through GameOn — the transaction settles directly with the Venue Partner.

For prepaid bookings, refund timelines and policies are governed by our Terms of Service and the Venue Partner's published cancellation policy. Refund-related data is retained for the statutory period required under the Income Tax Act, 1961 and the GST Act, 2017 — typically 8 years from the end of the financial year.

07

Sharing of Personal Data

We do not sell your personal data to anyone, ever.
  • 1
    With Venue PartnersYour name, mobile number, sport, party size, and slot details for confirmed bookings. Venue Partners are contractually bound to use this data solely for the booking.
  • 2
    With payment gatewaysRazorpay processes payments and shares transaction outcomes with us.
  • 3
    With service providers (processors)Cloud hosting (Amazon Web Services or equivalent India-region servers), analytics and crash reporting (Google Firebase), customer support tooling, transactional SMS and WhatsApp providers, and email delivery providers. All processors are bound by written contracts requiring confidentiality, purpose-limitation, and security controls.
  • 4
    With law-enforcement and regulatorsWhere required by order of a court, tribunal, or competent government authority under applicable law.
  • 5
    In a corporate transactionIn a merger, acquisition, financing, restructuring, or sale of assets, your data may be transferred to the successor entity subject to the same protections of this Policy. You will be notified of any such change.
  • 6
    With your explicit consentAny sharing not listed above will be undertaken only after we obtain your specific consent.

We do not share your personal data with advertising networks for cross-site behavioural advertising. We do not run third-party ad SDKs (e.g., Meta Audience Network, Google AdMob) inside the GameOn app at this time.

08

Where Your Data Is Stored, and Cross-Border Transfers

We store and process your personal data on cloud infrastructure located in India (AWS Mumbai / Hyderabad regions or equivalent India-region providers).

Some service providers (e.g., Google Firebase for crash reporting, our customer-support and email tooling) may process limited operational data on servers outside India. Where such transfer occurs, we ensure that:

  • It is necessary for the contract or for legitimate business operations
  • The receiving party is bound by a written agreement that provides at least the same level of data protection as required under Indian law
  • The receiving country is not restricted under Section 16 of the DPDP Act
09

Data Retention

Category of DataRetention Period
Active account data (profile, bookings, communications)Throughout the life of your account
Inactive accounts (no login for 24 consecutive months)Reminder sent; if no login within 30 days, deactivated. Data retained only for legally required durations.
Transaction and tax records (invoices, refunds, GST data)8 years from end of financial year (Section 36, CGST Act)
KYC documents of Venue Partners8 years from end of business relationship (PMLA)
Marketing-consent records and consent withdrawals3 years after withdrawal
Server logs and crash diagnostics90 days, rolling
Customer-support tickets3 years after closure

After the applicable retention period, we delete or irreversibly anonymise your personal data, except where retention is required under a legal hold, an ongoing dispute, or a request from a regulator.

10

Your Rights

As a Data Principal under the DPDP Act and the SPDI Rules, you have the following rights, exercisable free of charge by writing to support@gameon-india.com:

Right to accessObtain a summary of the personal data we hold about you and how we process it.
Right to correctionHave inaccurate or incomplete personal data corrected.
Right to erasureRequest deletion of your personal data where no longer necessary, subject to our retention obligations.
Right to withdraw consentWithdraw any consent at any time. Does not affect lawful processing carried out before withdrawal.
Right to nominateNominate another individual to exercise these rights on your behalf in the event of death or incapacity.
Right to grievance redressalLodge a complaint with our Grievance Officer and subsequently with the Data Protection Board.

We respond to requests within 30 days of receipt (or sooner if required by law). To protect your data, we may need to verify your identity (typically by OTP) before acting on certain requests.

11

Cookies and Similar Technologies (Website)

Our website uses:

  • Strictly necessary cookies: to keep you signed in, maintain booking state, and remember your city. These cannot be turned off.
  • Analytics cookies: Google Analytics to count visits and measure traffic (aggregated, non-identifying).
  • Preference cookies: to remember language, time-zone, and consent choices.

We do not use third-party advertising cookies, retargeting pixels, or cross-site tracking cookies on the website at this time. You can clear cookies from your browser settings at any time; some site features may not work as expected if you do.

12

Children's Privacy

The Platform is intended for users aged 18 and above. We do not knowingly collect personal data from children under 18 without verifiable parental consent.

If you are between 13 and 18, you may use the Platform only with the consent and supervision of a parent or legal guardian, who must register the account on your behalf and accept this Policy. Under the DPDP Act, we are required to obtain verifiable parental consent before processing data of a person under 18 and do not engage in behavioural tracking or targeted advertising directed at such persons.

If you believe a child under 18 has provided us personal data without verifiable parental consent, please contact us at support@gameon-india.com and we will delete such data promptly.

13

Security

We follow industry-accepted security practices, including:

HTTPS / TLS 1.2+ encryption of all data in transit
Encryption at rest of sensitive fields (passwords, financial tokens)
Role-based access controls and the principle of least privilege
Annual security reviews and periodic vulnerability scans
Logging and monitoring of access to production systems
Reasonable Security Practices and Procedures as required under Section 8 of the SPDI Rules

In the event of a personal data breach likely to result in significant harm, we will notify the Data Protection Board (when constituted) and affected Data Principals as required under Section 8(6) of the DPDP Act, within the prescribed timelines.

No method of transmission or electronic storage is 100% secure. We commit to commercially reasonable measures.

14

Grievance Officer

In accordance with the Information Technology Act, 2000, the SPDI Rules, the Intermediary Guidelines, 2021, and the Consumer Protection (E-Commerce) Rules, 2020:

NameShivam Tiwari
DesignationFounder & Chief Executive Officer, Grievance Officer
AddressKH-126, Bypass Road, Shanti Shivpuri, Ghaziabad, Uttar Pradesh — 201001
Emailsupport@gameon-india.com
Phone+91 88961 72818
HoursMonday to Friday, 10:00 AM – 6:00 PM IST (excluding public holidays)

The Grievance Officer will acknowledge your complaint within 48 hours of receipt and resolve it within 15 days (or 1 month for sensitive personal data grievances, per the SPDI Rules).

15

Changes to This Privacy Policy

The "Last Updated" date at the top of this page always shows when this Policy was last revised. For material changes (new categories of data collected, new purposes, new third parties), we notify you via:

  • An in-app notification on your next sign-in
  • An email to your registered email address
  • A prominent notice on the website homepage for at least 14 days

Your continued use of the Platform after such notice constitutes acceptance of the revised Policy.

16

Governing Law and Jurisdiction

This Privacy Policy is governed by the laws of India. Any dispute arising out of or in connection with this Policy is subject to the exclusive jurisdiction of the competent courts at Ghaziabad, Uttar Pradesh, India, without prejudice to any rights you may have under applicable consumer-protection laws.

Appendices

Appendix A — Play Store Data Safety Disclosure

Data TypeCollected?Shared with Third Parties?PurposeOptional / Required
NameYesShared with Venue Partner for confirmed bookingsAccount management; booking fulfilmentRequired
Email addressYesNoAccount management; communicationsRequired
Phone numberYesShared with Venue Partner for confirmed bookingsOTP verification; booking fulfilmentRequired
User IDs (account ID)YesNoAccount functionalityRequired
AddressYes (optional)NoCommunications, where you requestOptional
Approximate locationYesNoApp functionality (city detection)Optional
Precise locationYes (with permission)NoApp functionality ("venues near me")Optional
Phone contactsYes (with permission, for invites)No (only contacts you choose to invite receive a message)App functionality (Invite friends; "people you may know")Optional
Photos (profile picture)Yes (optional upload)NoPersonalisationOptional
App interactionsYesNoAnalytics; app functionalityRequired
In-app search historyYesNoApp functionalityRequired
Crash logsYesProcessed by Google Firebase (processor only)App stabilityRequired
DiagnosticsYesProcessed by Google Firebase (processor only)App stabilityRequired
Payment info (masked tokens only)YesProcessed by Razorpay (processor only)Payment processingRequired for prepaid bookings
Purchase historyYesNoAccount managementRequired
Other financial info (full card / CVV / UPI PIN)No — never collected
Health & fitness dataNo
Sensitive personal info (race, religion, political opinion, sexual orientation, biometric, genetic)No

Security practices declared for Play Store:

  • Data is encrypted in transit (HTTPS / TLS 1.2+).
  • You can request that data be deleted (in-app + via support@gameon-india.com).
  • Data collection and security practices follow Google Play's Families Policy where applicable.

Appendix B — Apple App Store Privacy Nutrition Label

  • Data Used to Track You:None. GameOn does not track users across other companies' apps and websites.
  • Data Linked to You:Name, Email, Phone Number, User ID, Address (optional), Precise Location (optional), Coarse Location, Contacts (with permission, invite flow only), Photos (profile, optional), Purchase History, Payment Info (masked tokens only), App Interactions, Search History, Customer Support communications, Crash Data, Performance Data, Diagnostics.
  • Data Not Linked to You:None at launch.