DATA PROTECTION

Privacy Policy

Last Updated: August 2026

At Shadi Krao, privacy is our cornerstone. We are committed to safeguarding your personal data, identity, and matrimonial search with absolute integrity and bank-grade security.

1. Information We Collect & How It Is Used

To provide a highly secure and verifiable matrimonial sanctuary, we collect:

  • Profile & Generational Demographics: Name, age, gender, city/overseas country, career, education, living preferences (joint vs separate portion), and sectarian practices.
  • Identity & Qualification Proof: CNIC/NICOP scans, International Passports, payment receipts, and educational degree certificates strictly accessible to our authorized safety compliance administrators during Stage 1 and Stage 2 verification audits.
  • Guardian & Wali Details: Guardian contact number and relationship for family chaperone coordination.
  • Google User Data: Email address, full name, and Google ID when utilizing Google OAuth 2.0.

2. Pardah Photo Vault & Anti-Screenshot Protection

We recognize the sacred sensitivity of matrimonial photo sharing. Shadi Krao employs our proprietary Pardah Photo Vault:

  • Default Modesty Blur: Profile pictures remain blurred and protected by default.
  • Protected Image Watermarking: Images are served with client-side deterrents and viewer-specific watermarking to prevent off-screen photography and unauthorized downloading.
  • Mutual Consent Unlocks: Full high-resolution photos and phone numbers are only disclosed when both candidates (and their respective family guardians) approve a mutual reveal request.

3. Encrypted Communication & Session Storage

All sensitive system sessions, authentication tokens, and WhatsApp integration credentials are encrypted at rest using AES-256-GCM cryptographic standards. Web traffic is secured end-to-end via TLS 1.3, ensuring system sessions and private verification states remain protected against unauthorized access.

4. Google OAuth 2.0 User Data Policy

Shadi Krao's use and transfer of information received from Google APIs adheres strictly to the Google API Services User Data Policy, including the Limited Use Requirements:

  • Authentication Only: Google account data is exclusively used to securely log you in and map your account.
  • No Third-Party Sale: We never sell, trade, or rent your data to advertisers or data brokers.
  • No AI Model Training: Your private data is strictly insulated and never utilized to train LLMs or AI datasets.

5. Data Retention & Account Erasure

You retain ultimate control over your digital footprint. You may delete your account at any time through your Dashboard settings. Upon deletion, your profile, chat history, uploaded CNIC/degree verification documents, and Google OAuth tokens are permanently and irreversibly purged from our active databases.