This Privacy Policy describes how ISocial Sports Private Limited ("Nudge", "we", "our", "us"), a company incorporated under the laws of India with its registered office at BVR Ek, Opposite Inder Residency, Ellisbridge, Ahmedabad, Gujarat – 380006, India, collects, uses, stores, shares, transfers and erases your personal data when you use the Nudge mobile application, the website www.justnudge.com, and associated services (together, the "Platform"). This Policy supersedes Version 2.0 and serves as the notice required under section 5 of the Digital Personal Data Protection Act, 2023.
Nudge acts as a Data Fiduciary under the Digital Personal Data Protection Act, 2023 ("DPDP Act") and the Digital Personal Data Protection Rules, 2025 ("DPDP Rules"), and, where applicable to users in the European Union, European Economic Area or United Kingdom, as a Data Controller under Regulation (EU) 2016/679 ("GDPR") and the UK GDPR.
This Policy is designed to be understandable independently of any other document. You may access this notice, and every request for consent we make, in English or in any language specified in the Eighth Schedule to the Constitution of India. To request a copy in another language, use the in-app language selector or write to our Privacy Contact at the details in clause 19.
1. Scope and Applicability
This Policy applies to:
- all users of the Nudge mobile application (Android and iOS) and visitors to www.justnudge.com;
- users who enable Commerce features, including receipt scanning and SMS transaction parsing (Android only);
- users who connect third-party accounts, including Google or Gmail; and
- users located in India (governed primarily by the DPDP Act and DPDP Rules) and users located in the EU, EEA or UK (who have additional rights under the GDPR or UK GDPR, set out in clause 13).
This Policy is drafted to comply with the DPDP Act and DPDP Rules, the GDPR and UK GDPR, the Information Technology Act, 2000 (to the extent applicable to matters not covered by the DPDP Act), the Promotion and Regulation of Online Gaming Act, 2025 and the Promotion and Regulation of Online Gaming Rules, 2026 (which govern the games offered on the Platform), and Google's API Services User Data Policy (for the optional Gmail integration).
2. Key Terms
- Personal Data: any data about an individual who is identifiable by or in relation to such data (section 2(t), DPDP Act).
- Processing: any wholly or partly automated operation performed on digital personal data, including collection, recording, storage, use, sharing, disclosure, erasure or destruction (section 2(x), DPDP Act).
- Data Principal / Data Subject: you, the individual to whom the personal data relates.
- Data Fiduciary / Controller: Nudge, which determines the purpose and means of processing your personal data.
- Data Processor: any person or entity that processes personal data on our behalf under a valid written contract.
- Consent Manager: a person registered with the Data Protection Board of India through whom you may give, manage, review and withdraw consent.
- Child: an individual who has not completed eighteen years of age.
3. Personal Data We Collect, Purposes and Legal Bases
In accordance with section 5(1) of the DPDP Act and Rule 3 of the DPDP Rules, the table below gives an itemised description of each category of personal data we collect, the specific purpose for which it is processed, and the legal basis for that processing under the DPDP Act and the GDPR. We collect and process only such personal data as is necessary for each specified purpose.
| Personal data (itemised) | Specified purpose | Legal basis — DPDP Act | Legal basis — GDPR |
|---|---|---|---|
| Full name; mobile number; email address; age bracket; your confirmation at registration that you meet the minimum age requirement | Account creation and management; recording your age confirmation and applying the age checks in clause 14; login authentication; service communications | Certain legitimate uses — voluntary provision (s.7(a)); consent (s.6) where applicable | Contract performance (Art. 6(1)(b)); consent (Art. 6(1)(a)) |
| Device model, OS and version; device identifier; IP address; approximate (city-level) location; app version; session and crash logs | Platform operation and security, fraud detection, abuse prevention, debugging. This processing is necessary to operate the Platform safely and continues for so long as you hold an account | Certain legitimate uses — voluntary provision for the specified purpose (s.7(a)); consent (s.6) for any use beyond security and operation | Legitimate interests — security and fraud prevention (Art. 6(1)(f)); contract performance (Art. 6(1)(b)) |
| Games played; time spent; scores; tournament participation; leaderboard display name; offers viewed, claimed and redeemed; in-app purchases; engagement metrics | Operating the gaming and rewards platform; leaderboards; internal product improvement | Certain legitimate uses (s.7(a)); consent (s.6) | Contract performance (Art. 6(1)(b)); legitimate interests (Art. 6(1)(f)) |
| Receipt and transaction data: merchant name; transaction date and time; purchase amount; items purchased (where printed); payment method type (never full card details); transaction reference | Purpose 1 — Rewards: detecting, extracting and validating purchase transactions to award Gems, points or rewards; fraud prevention | Consent (s.6) — separate and specific, per clause 4 | Consent (Art. 6(1)(a)); contract performance (Art. 6(1)(b)) |
| Receipt and transaction data (as above) | Purpose 2 — Commercial Analytics: generating aggregated market intelligence, category-level consumer spend reports and brand preference analytics that Nudge licenses or sells to CPG companies, FMCG brands, retailers and advertisers | Separate, specific, opt-in consent (s.6). OPTIONAL — declining does not affect rewards or core features | Consent (Art. 6(1)(a)) — separate opt-in |
| Receipt and transaction data (as above) | Purpose 3 — Brand Partner Sharing: sharing receipt-derived insights with the categories of recipient listed in clause 7 | Separate, specific, opt-in consent (s.6). OPTIONAL | Consent (Art. 6(1)(a)) — separate opt-in |
| Profile, usage and transaction data | Purpose 4 — Personalised Offers: personalising the offers, deals and brand-partner recommendations shown to you within the Platform | Separate, specific, opt-in consent (s.6). OPTIONAL | Consent (Art. 6(1)(a)) |
| Advertising identifier (Google Advertising ID; Identifier for Advertisers on iOS where you permit it); install, session and in-app event data; campaign or referral source; coarse region | Purpose 5 — Advertising and Attribution: measuring the performance of Nudge's own marketing campaigns and attributing installs. Detailed in clause 8 | Separate, specific, opt-in consent (s.6). OPTIONAL | Consent (Art. 6(1)(a)) |
| Crash, diagnostic and stability data | Detecting and fixing faults, and protecting the security and integrity of the Platform. Detailed in clause 8 | Certain legitimate uses — voluntary provision for the specified purpose (s.7(a)) | Legitimate interests — security and service integrity (Art. 6(1)(f)) |
| SMS transaction data (Android only): bank transaction alert content matching RBI-mandated formats — merchant, amount, timestamp, reference | Automated detection of eligible purchases for rewards (Purpose 1 only). Personal SMS, OTPs and non-transactional messages are never read or stored | Separate, specific consent (s.6) via a dedicated in-app disclosure and the Android READ_SMS permission | Consent (Art. 6(1)(a)) |
| Google user data: transactional emails relating to receipts, invoices and purchase confirmations only | Automated receipt detection and validation (Purpose 1 only). Never used for advertising, profiling, resale or any secondary purpose | Separate, specific consent (s.6) via the Google OAuth consent screen | Consent (Art. 6(1)(a)) |
| Grievance and support communications | Responding to requests, complaints and rights exercises; maintaining records of grievance redressal, including as required by Rule 20 of the Online Gaming Rules | Certain legitimate uses (s.7(a)); legal obligation | Legal obligation (Art. 6(1)(c)); legitimate interests (Art. 6(1)(f)) |
3.1 What we do not do
We do not sell personal data in identifiable form. We do not use Google user data for advertising or profiling. We do not operate chat, direct messaging or any user-to-user social graph, so we do not process message content or social graph data. We do not process children's personal data for commercial analytics, brand partner sharing, advertising, attribution, behavioural monitoring, tracking or targeted advertising under any circumstances (clause 14).
3.2 Where consent is withdrawn from a security purpose
Processing of the device, security and fraud prevention data described in the second and ninth rows above is necessary for us to operate the Platform safely and to protect all users. Where you withdraw consent from any purpose, we cease processing for that purpose, but we may continue to retain and process the minimum data necessary for security, fraud prevention and the establishment or defence of legal claims, to the extent permitted by law. If you wish all such processing to stop, you may close your account under clause 11.
3.3 Gems, Rewards and No Monetary Value
Gems, points, badges, leaderboard standings and other in-platform rewards are loyalty and gamification features only. They have no direct monetary value, are not a form of currency, are not transferable to any other user or platform, and cannot be staked, deposited, withdrawn, cashed out, sold or converted into money or money's worth. Gems, points and other in-platform rewards may be earned only through eligible gameplay and commerce activities and may be redeemed only against vouchers or other benefits made available by brand partners through the Platform, in accordance with the applicable programme rules and terms published in-app. The Platform may offer optional in-app purchases of cosmetic or functional virtual items. Such virtual items are licensed for use within the Platform only, have no monetary value outside the Platform, cannot be exchanged for Gems or other in-platform rewards, cannot be staked, and cannot affect any reward outcome. Any such purchase is not an entry fee, stake or consideration for participating in a game or for obtaining a reward. Nothing on the Platform constitutes an "online money game" as defined in the Promotion and Regulation of Online Gaming Act, 2025, and no personal data is processed by us for the purpose of facilitating any such activity. Any reward or Gems left unused for 30 (thirty) days or more shall be auto-deleted.
4. How We Obtain Your Consent
Where consent is our basis for processing, it is obtained in accordance with section 6(1) of the DPDP Act and Articles 4(11) and 7 of the GDPR: it is free, specific, informed, unconditional and unambiguous, and given through a clear affirmative action such as ticking an unticked box or activating a clearly labelled toggle. We never rely on pre-ticked boxes, silence, inactivity, or your mere use of the Platform as consent.
Our consent architecture is granular. At onboarding and in the in-app Privacy Centre, you are presented with separate, individually controllable consents for:
- (a) Rewards Processing — processing your receipt and transaction data to award Gems and rewards (required only if you choose to use Commerce features);
- (b) Commercial Analytics — inclusion of your transaction data in aggregated market-intelligence products (optional; off by default);
- (c) Brand Partner Sharing — sharing of receipt-derived insights with the recipient categories in clause 7 (optional; off by default);
- (d) Personalised Offers — personalisation of offers and recommendations shown within the Platform (optional; off by default);
- (e) Advertising and Attribution — the SDK processing described in clause 8 (optional; off by default);
- (f) SMS Transaction Parsing (Android only); and
- (g) Gmail Integration (when available) — each behind its own dedicated disclosure and permission flow.
We are in the process of rolling out the full in-app Privacy Centre described in this clause 4, with individually controllable, purpose-by-purpose toggles for each item listed above, and expect it to be fully live within FY26. Until each toggle is live, the corresponding consent is captured through an interim in-app flow that remains free, specific, informed and revocable, and we do not process the relevant personal data for a purpose unless the applicable consent has actually been given.
Declining any optional consent will not affect your access to Nudge's core gaming and rewards features. Each consent request is presented in clear and plain language, is available in English or any Eighth Schedule language, and includes the contact details of our Privacy Contact.
4.1 Consent records
We maintain auditable records of every consent given, including what you consented to, when, the version of the notice presented to you, and any subsequent modification or withdrawal. Under section 6(10) of the DPDP Act we are obliged to prove that notice was given and consent obtained, and our records are maintained accordingly.
4.2 Consent Manager
You may also give, manage, review or withdraw your consent through a Consent Manager registered with the Data Protection Board of India, once such Consent Managers are operational. Rule 4 of the DPDP Rules takes effect on 13 November 2026 and we will interoperate with registered Consent Managers as required.
4.3 Fresh consent for new purposes
If we propose to process your personal data for a purpose not covered by your existing consents, we will present you with an updated notice and obtain fresh, affirmative consent before the new processing begins. No new or materially reconfigured software development kit, and no new processing purpose, is released without review under our internal product launch gate. Continued use of the Platform is never treated as consent to a new processing purpose.
5. Withdrawing Your Consent
You may withdraw any consent, in whole or in part, at any time, with comparable ease to the way you gave it (section 6(4), DPDP Act; Article 7(3), GDPR). Each consent listed in clause 4 has its own toggle in the in-app Privacy Centre (Profile → Privacy Centre → My Consents). You may also withdraw consent by writing to our Privacy Contact, or through a registered Consent Manager.
On withdrawal:
- we will, within a reasonable time, cease processing your personal data for the withdrawn purpose, and cause every Data Processor engaged by us to cease such processing (section 6(6), DPDP Act);
- we will erase the relevant personal data in accordance with clause 11, unless retention is required by law or permitted under clause 3.2;
- withdrawal does not affect the lawfulness of processing carried out before withdrawal; and
- the consequences of withdrawal — for example, an inability to earn receipt-based rewards after withdrawing Rewards Processing consent — are borne by you, but withdrawal will never affect features that do not depend on the withdrawn consent.
6. Receipt Scanning and SMS Parsing
6.1 Receipt scanning (Android and iOS)
When you submit a receipt by camera scan or image upload, our systems use optical character recognition to extract the transaction fields itemised in clause 3, validate the transaction against fraud-detection rules before awarding rewards, and store only the extracted data.
6.2 SMS transaction parsing (Android only)
- A dedicated in-app disclosure screen explains exactly what will be read and why, before the Android READ_SMS permission is requested;
- Only messages matching known RBI-mandated bank transaction alert patterns are processed. Personal SMS, OTPs and non-transactional messages are never read, stored or transmitted;
- Parsing occurs locally on your device. Only the extracted transaction fields are transmitted over an encrypted connection. Raw SMS content is never stored on our servers;
- You may revoke the permission at any time via your device settings or the in-app Privacy Centre. Both routes are equally effective; and
- This feature is offered only where permitted by the applicable app store policies, and may be withdrawn or modified if those policies change.
This SMS transaction parsing feature, and the dedicated in-app disclosure flow described above, are being rolled out during FY26. The feature is not enabled on a user's account, and the Android READ_SMS permission is not requested, until the applicable in-app disclosure and consent step has been completed for that user.
6.3 Fraud prevention and Review of Adverse Actions
We use automated and other technical controls to identify duplicate, altered or suspicious receipts and transactions, including anomaly detection, configurable thresholds on spend amounts and submission frequency, and other fraud-prevention measures. These controls may result in a temporary verification hold of up to 72 hours for new users or may flag an account, receipt or transaction for further review. A verification hold is a temporary measure and does not constitute a final determination regarding your eligibility for a reward. No reward will be reversed, and no account will be suspended or terminated, solely on the basis of an automated fraud or anomaly signal. Any proposed reward reversal, suspension, termination or other adverse action based on suspected fraud, abuse or breach will be reviewed and approved by an authorised member of our staff before it takes effect. Where a reward is reversed or an account is suspended or terminated following such review, we will provide you with the reasons for the action, subject to any restriction imposed by applicable law or where disclosure would compromise fraud-prevention, security or legal processes. You may raise a grievance in accordance with clause 16.
7. Commercial Analytics and Data Sharing
Part of Nudge's business is the generation of aggregated market intelligence — such as category-level consumer spend reports, brand preference indices and campaign measurement analytics — which Nudge licenses or sells to third parties. Your transaction data is included in these products only if you have given the separate, opt-in Commercial Analytics consent described in clause 4(b).
7.1 Categories of recipient
Where you have given the applicable consent, receipt-derived insights may be shared with:
- consumer packaged goods (CPG) and fast-moving consumer goods (FMCG) manufacturers and brands;
- retailers, e-commerce platforms and quick-commerce platforms;
- advertising, media and market-research agencies acting for the above; and
- brand partners whose offers are redeemable on the Platform, for campaign measurement.
7.2 Form of sharing, and why we still ask for your consent
Insights shared with these recipients are aggregated and are anonymised to the standard in clause 11.3 before release. We do not share your personal data with these recipients in identifiable form.
We nonetheless ask for your separate consent to this purpose because the inputs to these products are your personal data, and the processing required to build them — selection, enrichment and aggregation of your transaction records — is processing of personal data whatever the form of the output. Treating the purpose as consent-based also means that withdrawing consent removes your data from future products and from the datasets used to build them. If any future product were to involve sharing identifiable personal data, it would require a further separate consent naming the recipient category and purpose.
7.3 Other disclosures
- Service Providers (Data Processors): cloud hosting, OCR and on-device processing, authentication, payment processing, analytics infrastructure, fraud detection, customer support, marketing attribution, voucher and partner-fulfilment services, AI-assisted content moderation and support automation, and communications vendors process personal data on our behalf strictly under written contracts meeting the requirements of section 8(2) of the DPDP Act and Article 28 GDPR — covering scope of processing, confidentiality, security measures, restrictions on onward disclosure, breach notification, audit rights, and erasure obligations including certification of erasure on termination or consent withdrawal.
- Legal Authorities: where required by law, court order, or the direction of a competent authority in India or another applicable jurisdiction, including the Online Gaming Authority of India and the Data Protection Board of India.
- Corporate Transactions: in a merger, acquisition, reconstruction or asset transfer approved by a competent court, tribunal or authority, personal data may be transferred to the successor entity subject to protections at least equivalent to this Policy, and you will be notified of any such transfer.
Where personal data we process is likely to be used to make a decision that affects you, or is disclosed to another Data Fiduciary, we ensure its completeness, accuracy and consistency as required by section 8(3) of the DPDP Act.
7.4 Third-Party Links
The Platform may contain links to third-party services, or offers redeemable on, third-party websites and applications operated by brand partners, merchants or advertisers. Your use of any such third-party service, website or application may be subject to that third party's own terms and privacy policy. This Policy applies only to personal data processed by Nudge or by third parties processing personal data on Nudge's behalf as Data Processors. It does not apply to personal data processed independently by third-party sites. We are not responsible for the privacy practices or content of any third party, and we encourage you to review the privacy policy of any site you visit through the Platform.
8. Software Development Kits, Advertising Identifiers and Mobile Tracking
8.1 What SDKs are
Our mobile applications include software development kits ("SDKs") and embedded third-party services. An SDK is third-party code embedded in our application; depending on its function, it may transmit data about your device and your use of the application — or data you provide directly, for example when you contact support — to the provider of that SDK or service. We use SDKs and embedded third-party services across the following categories: crash and stability reporting; product analytics; marketing attribution and advertising; authentication; payments; customer support; voucher and partner-fulfilment services; AI-assisted content moderation and support automation; and on-device processing of receipts. The current list, organised by category, is set out in clause 8.3.
8.2 Data Processed by Our Analytics, Attribution and Advertising SDKs
This clause 8.2, and clauses 8.4 to 8.7 below, apply specifically to the crash and stability reporting, product analytics, and marketing attribution and advertising SDKs identified as such in clause 8.3. These SDKs may process:
- your advertising identifier — the Google Advertising ID on Android and, only where you permit it under clause 8.5, the Identifier for Advertisers on iOS;
- device model, operating system and version, application version, language and coarse region;
- installation, session, screen-view and in-app event data;
- crash, diagnostic and stability data; and
- the marketing campaign or referral source through which you installed the application.
These SDKs do not receive your name, mobile number, email address, receipt images or receipt contents. Other categories of SDK and embedded third-party service listed in clause 8.3 — for example, those used for authentication, payments, customer support and voucher fulfilment — necessarily process the specific data described against them in that list, on the legal bases set out in clause 3.
8.3 Current SDK and Third-Party Service List
The table below lists the SDKs and embedded third-party services in our applications, organised by category, the provider of each, the purpose it serves and the categories of data it receives. We review and update this list with each application release, and we will publish and keep updated a corresponding list at www.justnudge.com/sdk-disclosures.
| Category | Provider | Purpose | Data received |
|---|---|---|---|
| Analytics & Crash Reporting | Google Firebase (Analytics, Crashlytics, Cloud Messaging) | Understand app usage, diagnose crashes, send push notifications | Device identifiers, device information, usage data |
| Attribution | Singular | Measure marketing campaign performance | User ID, a subset of usage events, and purchase data; the SDK also automatically collects your advertising ID, device fingerprint and IP address |
| Advertising | AppLovin MAX and its demand-network partners (see table below) | Serve advertising within the Platform | No personal information is passed to these services; their SDKs independently collect your advertising ID, device information and IP address |
| Authentication | Truecaller | Phone-based sign-in | Only an authorisation code is received by the app; your profile data is exchanged securely on our servers |
| Payments | Google Play Billing; Apple StoreKit | Process in-app purchases | Product and transaction identifiers required to complete your purchase |
| Customer Support | Freshchat (Freshworks) | In-app customer support | Your name, email address and phone number, when you contact support |
| Partner Services | Hubble | Voucher generation and delivery | Your phone number, user ID and account balances |
| AI & Data Processing | Anthropic (Claude) | Content moderation, support automation and internal data processing, as our sub-processor | Limited user data such as support queries or anonymised usage data, subject to our data processing agreement; Anthropic does not use your data to train its models |
| On-Device Processing | Google ML Kit; TensorFlow Lite | Receipt scanning (optical character recognition) | Your receipt images and extracted text are processed entirely on your device and are never shared with any third party |
Advertising Network Partners
Where you have given Advertising and Attribution consent under clause 4(e), AppLovin MAX may serve advertising through the following demand-network partners. We do not pass personal information to these partners; their SDKs may independently collect your advertising identifier, device information and IP address.
| Partner | Privacy Policy |
|---|---|
| AppLovin | applovin.com/privacy |
| Google AdMob / Ad Manager | policies.google.com/privacy |
| BigoAds | bigoads.com/privacy-policy |
| Digital Turbine (Fyber) | digitalturbine.com/privacy-policy |
| InMobi | inmobi.com/privacy-policy |
| ironSource / Unity Ads | unity.com/legal/privacy-policy |
| Liftoff (Vungle) | liftoff.io/privacy-policy |
| Mintegral | mintegral.com/en/privacy |
| Moloco | moloco.com/privacy-policy |
| Pangle (ByteDance) | pangleglobal.com/privacy/enduser-en |
8.4 Consent and sequencing
We treat SDKs in two categories. This clause 8.4 governs product analytics, and marketing attribution and advertising SDKs only. Authentication, payment processing, customer support, voucher and partner-fulfilment services, AI-assisted processing, and on-device processing described in clause 8.3 operate on the legal bases already itemised in the table at clause 3, as necessary to provide the specific feature you are using, and are not subject to a separate consent toggle under this clause.
- Strictly necessary: crash and stability reporting, and SDKs required for security and fraud prevention. These operate on the basis of clause 3 and are not subject to a consent toggle, because without them we cannot keep the application working safely.
- Optional: product analytics, and marketing attribution and advertising SDKs. These are initialised only after the relevant consent under clause 4(e) has been presented to you and given, and are suppressed if you decline or later withdraw. On withdrawal, we stop sending further data about you to the relevant provider from the application, and we take reasonable steps, consistent with our contracts with those providers and as required by section 8(2) of the DPDP Act, to have data already collected about you deleted from their systems. We are strengthening our automated tooling during FY26 to make this deletion step fully systematic across every optional SDK.
8.5 iOS App Tracking Transparency
On iOS, we request permission through Apple's App Tracking Transparency framework before accessing the Identifier for Advertisers. If you decline, we do not access that identifier, and attribution operates on a privacy-preserving basis only. You may change this choice at any time in your iOS settings.
8.6 Android advertising identifier
You may reset your Google Advertising ID, or opt out of personalised advertising, at any time in your Android device settings. Where you delete the identifier, we do not attempt to reconstruct it or to use any alternative persistent identifier in its place.
8.7 Limits on advertising use
Where we use marketing attribution or advertising SDKs, they operate only to measure and attribute Nudge's own marketing campaigns. We do not sell your personal data. We do not permit these SDKs to build cross-application profiles of you, and we do not use them to serve you advertising outside the Platform. We do not enable any advertising or attribution SDK for any account identified as belonging to a child.
8.8 Governance of SDK changes
No SDK is added, removed or materially reconfigured without review under our internal product launch gate, which assesses privacy, child safety, monetisation and security implications. We retain records of each such review.
8.9 Website tracking
Tracking on our website is dealt with separately in clause 15.
9. International Data Transfers
Your personal data is primarily hosted and processed on cloud infrastructure located in India (on Google Cloud Platform's Indian region). Certain technology partners, SDK providers and other vendors identified in clause 8.3 may process data outside India in the course of providing their services to us.
Your personal data may be stored, accessed, processed or transferred within or outside India, including through third-party service providers, technology partners, SDK providers, cloud service providers and other vendors engaged by the Platform from time to time, depending on the nature of the services and features used.
Where personal data is stored, accessed, processed or transferred across jurisdictions, such activities may be subject to the applicable data protection, privacy, data transfer and other regulatory requirements of the relevant jurisdiction. The Platform and its relevant service providers shall process personal data in accordance with the laws and regulatory requirements applicable to them and to the relevant processing activity, as may be applicable from time to time.
The Platform may use service providers located in or operating from different jurisdictions for hosting, storage, analytics, communications, security, payments, customer support and other operational purposes. The specific location from which a service provider operates or processes data may vary from time to time based on the services provided and the applicable arrangements.
Where required under applicable law, appropriate contractual, technical or organisational measures may be implemented in relation to the processing or transfer of personal data. Nothing in this Privacy Policy shall be construed as creating any representation or warranty regarding the specific location of storage or processing by any third-party service provider, except as expressly required under applicable law.
Where personal data is transferred outside India, such transfer complies with section 16 of the DPDP Act and with any Central Government notification restricting transfers to specified countries or territories.
For users in the EU, EEA or UK, any transfer of personal data outside the EEA or UK is made only: (a) to jurisdictions covered by an adequacy decision of the European Commission or the UK equivalent; or (b) subject to appropriate safeguards under Article 46 GDPR, such as Standard Contractual Clauses, together with supplementary measures where necessary. You may obtain a copy of the relevant safeguards by contacting our Privacy Contact.
Separately, where the Online Gaming Authority of India issues a direction under section 8(3) of the Promotion and Regulation of Online Gaming Act, 2025 requiring traffic data or metadata to be retained on computer resources located in India, we comply with that direction.
10. Security and Breach Notification
- Personal data is encrypted at rest (AES-256), and all data is encrypted in transit (TLS 1.2 or higher). We are extending at-rest encryption coverage to further categories of data during FY26. Access is restricted to authorised personnel on a need-to-know basis and is subject to periodic review. Administrative and privileged access requires multi-factor authentication. OAuth tokens and other secrets are stored securely and are never exposed in logs;
- We implement appropriate technical and organisational measures under section 8(4) of the DPDP Act, take reasonable security safeguards to prevent a personal data breach under section 8(5), and comply with Article 32 GDPR. We maintain application and infrastructure logging with alert triage, documented incident playbooks, and tested backups; and
- In the event of a personal data breach, we will intimate each affected Data Principal without delay, and the Data Protection Board of India without delay, followed by a detailed report within 72 hours, in the form and manner prescribed by Rule 7 of the DPDP Rules (section 8(6), DPDP Act). For users in the EU, EEA or UK, we will notify the competent supervisory authority within 72 hours and affected data subjects where required by Articles 33 and 34 GDPR.
10.1 Security Incidents and Adverse Actions
Where our security, fraud-prevention or monitoring systems identify activity that may compromise the security or integrity of the Platform, or indicate suspected fraudulent or abusive activity, we may take proportionate temporary measures, including restricting access to relevant features or placing a temporary hold on rewards, while the matter is investigated. No reward reversal, account suspension or termination, or other adverse action with a material effect on your access to the Platform or your rewards, will be based solely on automated processing. Any such proposed action will be subject to review by an authorised member of our staff before it takes effect. Any personal data breach will be handled in accordance with the breach notification and response requirements set out in this clause and applicable law.
11. Data Retention and Erasure
The retention periods and erasure process described in this clause 11 are the standard we apply to personal data processed on and after the Effective Date of this Policy. We continue to invest in automated data-lifecycle tooling to operationalise this schedule without manual intervention across every system in which personal data is held.
11.1 Retention schedule
| Data category | Retention period | Trigger for erasure |
|---|---|---|
| Account data | Duration of active account, plus up to 90 days after deletion (recovery window) | Account deletion request; consent withdrawal; the inactivity rule in clause 11.2 |
| Receipt and transaction data | Up to 24 months from submission, unless a shorter period applies | Purpose fulfilment; consent withdrawal; account deletion |
| SMS-parsed transaction data | Same as receipt data | Same as receipt data. Revocation of the SMS permission stops new collection immediately |
| SDK, advertising identifier and attribution data | Up to 14 months from collection | Withdrawal of Advertising and Attribution consent; account deletion; deletion or reset of your advertising identifier |
| Crash and diagnostic data | Up to 12 months | Expiry of the period; account deletion |
| Google user data (when the integration is live) | Only while the integration is active | Deleted within 30 days of disconnection or account deletion |
| Grievance and consent records | As required to demonstrate compliance and by applicable law, including Rule 8(3) of the DPDP Rules | Expiry of statutory limitation periods |
| Irreversibly anonymised aggregate data | May be retained — no longer personal data (clause 11.3) | Not applicable |
11.2 Erasure, inactivity and the deletion process
On your withdrawal of consent, your erasure request, or when the specified purpose is no longer being served (whichever is earliest), we will, unless retention is required by law or permitted under clause 3.2:
- erase your personal data from our production systems, analytics platforms and reporting pipelines;
- remove it from archived and cohort datasets;
- exclude it from any further model training immediately, and remove it from model-training datasets at the next scheduled retraining cycle;
- erase it from backups on the next scheduled backup rotation; and
- cause every Data Processor to erase the personal data we made available to it, and obtain certification of erasure (section 8(7), DPDP Act; Article 17 GDPR).
Inactivity. Where you do not approach us for the specified purpose, or do not exercise any of your rights, for a continuous period of three years, the specified purpose is treated as no longer being served and your personal data is erased, in the manner and to the extent required by Rule 8 of the DPDP Rules. We will notify you at least 48 hours before such erasure so that you may retain your account if you wish. This does not apply to data required to give you access to your account or to any accrued Gems or in-platform currency balance.
11.3 Anonymisation standard
Data is treated as anonymised — and therefore outside the scope of this Policy — only where it has been irreversibly transformed such that you can no longer be identified, directly or indirectly, by any means reasonably likely to be used. Pseudonymised data, and aggregated outputs from which individual-level data remains recoverable, remain personal data and are erased as part of the process in clause 11.2. We assess our anonymisation methods against this standard periodically and retain a record of each assessment.
11.4 Gems and Reward Balances on Erasure
Because Gems and other in-platform rewards have no monetary value (clause 3.3), they are not "personal data" in themselves, but any unredeemed balance is tied to your account. On account deletion, or on erasure following the inactivity rule in clause 11.2, any unredeemed Gems or reward balance is forfeited and cannot be recovered, transferred or compensated in cash. We will give you reasonable notice of this consequence, consistent with clause 11.2, before erasure takes place.
12. Your Rights (All Users — DPDP Act)
- Right to Access (s.11): obtain a summary of your personal data being processed, the processing activities undertaken, and the identities of all Data Fiduciaries and Data Processors with whom it has been shared, with a description of the data shared.
- Right to Correction, Completion, Updating and Erasure (s.12): have inaccurate or misleading data corrected, incomplete data completed, data updated, and personal data erased unless retention is necessary for the specified purpose or required by law.
- Right of Grievance Redressal (s.13): readily available means of grievance redressal, as set out in clause 16.
- Right to Nominate (s.14): nominate another individual to exercise your rights in the event of your death or incapacity, via Privacy Centre → Nominee or by writing to our Privacy Contact.
- Right to Withdraw Consent (s.6(4)): as set out in clause 5.
12.1 How to make a request, and what happens next
Make any request through Privacy Centre → My Data, or by writing to our Privacy Contact at the details in clause 19. So that we do not disclose your data to anyone else, we verify your identity before acting on a request: normally by confirming control of the registered mobile number or email address on the account. We do not require you to provide any identity document.
We acknowledge every request within 48 hours and complete it within 30 days. Where a request is complex, we will tell you within those 30 days and complete it as soon as possible thereafter. There is no charge for exercising any right. If we decline a request, in whole or in part, we will tell you why and how to raise a grievance under clause 16.
12.2 Duties of a Data Principal
In exercising your rights under this clause 12 and section 15 of the DPDP Act, we ask that you: do not impersonate another person when providing personal data; do not suppress material information when providing personal data for any document, proof of identity, proof of address or account registration; do not register a false or frivolous grievance or complaint with us, a Consent Manager or the Data Protection Board of India; and furnish only information that is verifiably authentic when exercising the right to correction or updating under clause 12(b). These duties do not affect the rights available to you elsewhere in this Policy.
13. Additional Rights for EU, EEA and UK Users (GDPR)
If you are located in the EU, EEA or the UK you additionally have the following rights, exercisable free of charge, to which we will respond within one month (extendable by two further months for complex requests, with notice):
- Access (Art. 15), Rectification (Art. 16), Erasure or the "right to be forgotten" (Art. 17), and Restriction of processing (Art. 18);
- Data Portability (Art. 20): receive the personal data you provided to us in a structured, commonly used, machine-readable format, and have it transmitted to another controller where technically feasible;
- Right to Object (Art. 21): object at any time to processing based on legitimate interests, and to direct marketing, in which case we will stop;
- Automated Decision-Making (Art. 22): we do not make decisions based solely on automated processing that produce legal or similarly significant effects concerning you. Automated fraud detection may place a temporary hold of up to 72 hours on a reward pending verification; a hold is not a final decision, and no reward reversal, account suspension or other adverse outcome takes effect without review by an authorised member of our staff. You may contest any such decision, obtain an explanation of it, and raise a grievance under clause 16; and
- Complaint to a Supervisory Authority (Art. 77): lodge a complaint with the supervisory authority of your habitual residence, place of work, or the place of the alleged infringement.
14. Children's Data
Nudge is intended only for individuals aged 18 and above. The Platform is neither designed for nor offered to children.
14.1 How we check age
At registration, you must tick an unticked checkbox confirming that you have read and agree to our Terms of Use, which require you to be at least 18 years of age. We do not currently collect a verified date of birth, and we do not verify your age against an identity document or a third-party age-verification service. We describe our measures accurately here rather than claim a stronger control than we operate. We apply proportionate measures to detect obvious circumvention, including duplicate-account and device-level checks and the review of credible reports from any source. Where we have reasonable grounds to believe an account holder is under 18, we immediately restrict that account from all reward-bearing and commerce features.
14.2 Strengthening these measures
We keep these measures under review and are strengthening them. As an interim step, we will introduce a separate, unticked age-confirmation step at registration and the capture of your date of birth, so that age confirmation is not bundled with acceptance of our Terms of Use. We will thereafter adopt a verification route contemplated by Rule 10 of the DPDP Rules — such as a virtual token mapped to verified identity and age details issued by an authorised entity, including a Digital Locker service provider — in advance of section 9 of the DPDP Act and Rule 10 taking effect on 13 May 2027. Our current and planned measures are disclosed as "user safety features" for the purposes of Rule 23(g) of the Online Gaming Rules.
14.3 No child profiling — absolute
We do not, under any circumstances, undertake tracking or behavioural monitoring of children, or targeted advertising directed at children (section 9(3), DPDP Act). Children's data is never included in commercial analytics, brand-partner products, advertising or attribution. We do not undertake any processing likely to cause a detrimental effect on the well-being of a child (section 9(2), DPDP Act).
14.4 Where a child is identified after registration
We immediately suspend all processing of that account's personal data and exclude it from every analytics and attribution pipeline. We then erase all associated personal data, including from Data Processor systems, and terminate the account. We do not seek parental or guardian consent in order to allow a child's account to continue, because the Platform is not offered to children; accordingly, the only outcome is erasure and termination. Where a parent or lawful guardian contacts us about a child's account, we will act on that request and confirm completion.
14.5 Reporting
If you believe a child has created an account, contact us at dpo@justnudge.com, and we will act within 72 hours.
14.6 Note on the EU/UK Age of Consent
This clause 14 defines "child" as an individual under 18, consistent with the DPDP Act. We record, for clarity to EU, EEA and UK users, that Article 8 GDPR and the UK GDPR permit a younger individual (as low as 13, depending on member state law) to consent to certain information-society services in their own right. This distinction does not affect Nudge's own eligibility requirement: the Platform remains restricted to users aged 18 and above under clause 14, regardless of the age at which a user could otherwise independently consent under the GDPR or UK GDPR.
15. Cookies and Website Tracking
Our website uses cookies for session management and authentication (strictly necessary), and — only with your consent given through the cookie banner — analytics and preference cookies. Non-essential cookies are off by default. You may change your choices at any time via the cookie settings link in the website footer, or through your browser settings. Declining non-essential cookies does not affect core functionality. Tracking within our mobile applications is dealt with in clause 8.
16. Grievance Redressal and Complaints
16.1 Step 1 — contact us
Raise any grievance about our obligations or your rights through Privacy Centre → Raise a Grievance, or by writing to our Grievance Officer or Privacy Contact at the details in clause 19. We will acknowledge within 48 hours and respond within 30 days. Rule 14(3) of the DPDP Rules permits a period of up to 90 days; 30 days is our own commitment to you, and we will tell you if a matter is exceptionally complex.
16.2 Step 2 — Data Protection Board of India
If you are not satisfied with our response, or in the case of a personal data breach, you may complain to the Data Protection Board of India in the manner prescribed under the DPDP Act and DPDP Rules, through the Board's digital portal (details are published by the Board and linked in our Privacy Centre). Under section 13(3) of the DPDP Act you must first exhaust the grievance redressal opportunity with us before approaching the Board.
16.3 Step 2 — Online Gaming Authority of India
Where your grievance concerns a game offered on the Platform rather than your personal data, and is not resolved by us, you may approach the Online Gaming Authority of India within 30 days under Rule 20 of the Online Gaming Rules, with a further appeal to the Appellate Authority under Rule 7 of those Rules.
16.4 EU, EEA and UK users
You may additionally complain to your supervisory authority, as described in clause 13(e).
17. Indemnity and Limitation of Liability
To the maximum extent permitted by law, Nudge is not liable for indirect, incidental, special or consequential damages arising from your use of the Platform. Our aggregate liability for direct damages is limited to the amount paid by you to Nudge in the twelve months preceding the claim, or INR 10,000, whichever is higher. This limitation does not apply to liability arising under the Digital Personal Data Protection Act, 2023, liability under the Consumer Protection Act, 2019, liability for gross negligence or wilful misconduct, or any liability that cannot be limited under applicable law. You agree to indemnify Nudge against claims, losses and expenses (including reasonable legal fees) arising from your breach of this Privacy Policy, your submission of fraudulent receipts, or your breach of applicable law, except to the extent caused by our own breach of this Policy or of applicable data protection law.
18. Platform Availability
The Platform may, from time to time, be unavailable, interrupted, delayed or affected due to technical issues, maintenance, upgrades, system failures, connectivity issues, third-party service failures, force majeure events or other circumstances beyond the reasonable control of the Platform. While we will use reasonable efforts to maintain the availability and proper functioning of the Platform and to restore any interruption at the earliest reasonably practicable opportunity, we do not guarantee that the Platform will be continuously, uninterruptedly or error-free available at all times.
To the extent permitted under applicable law, the Platform shall not be responsible for any loss, inconvenience or inability to access or use the Platform arising from such circumstances.
19. Privacy Contact
We have voluntarily designated a Privacy Contact, based in India, who is the point of contact for all questions, rights requests and grievances under this Policy. Nudge has not been notified as a Significant Data Fiduciary under section 10 of the DPDP Act; if it is so notified, we will appoint a Data Protection Officer meeting the requirements of section 10(2)(a) and update this Policy.
| Role | Contact |
|---|---|
| Privacy Contact | Vani Balachandran; dpo@justnudge.com |
| Grievance Officer | Vani Balachandran; grievance@justnudge.com |
| Rights requests and grievances | dpo@justnudge.com |
| Legal notices | legal@justnudge.com |
| Address | ISocial Sports Private Limited, BVR Ek, Opposite Inder Residency, Ellisbridge, Ahmedabad, Gujarat – 380006, India |
The business contact information above is published on our website in accordance with section 8(9) of the DPDP Act and Rule 9 of the DPDP Rules.
20. Changes to This Policy
We may update this Policy to reflect changes in our features, legal requirements or practices. For material changes, we will give you at least 15 days' advance notice by in-app notification and email, update the version number and "Last Updated" date, and — where a change involves a new or expanded processing purpose — obtain your fresh, affirmative consent before that processing begins. We will never treat your continued use of the Platform as consent to a new processing purpose.