Privacy Policy
Last updated: 16 August 2026
This Privacy Policy explains what personal data Midnight Mitra (“Midnight Mitra”, “we”, “us”, “our”) collects, why we collect it, who we share it with, how long we keep it, and the rights you have over it. It covers our website, our customer app, our partner (therapist) app and our support channels. We process the personal data of users in India in accordance with the Digital Personal Data Protection Act, 2023 (the “DPDP Act”), the Information Technology Act, 2000 and the rules made under them. Because we send therapists into people’s homes, we collect some data that ordinary marketplaces do not — identity documents and live location. Those two are explained in full in sections 4 and 5, because you should not have to guess what happens with them.
1. Who this policy applies to
This policy applies to three groups: customers who book sessions, therapists who accept and perform them, and anyone who contacts us through the website without holding an account. Some sections apply only to one group; where that is the case, it says so.
Midnight Mitra operates as an intermediary marketplace. We are the data fiduciary for the data described here. Therapists are independent service partners, not employees, and are separately responsible for how they handle anything you tell them directly during a session.
2. Data we collect from customers
- Identity and contact: first and last name, mobile number, email address if you provide one, gender if you choose to share it, and your preferred language.
- Addresses: the addresses you save for at-home service, including flat or building number, landmark, city, PIN code and, where you allow it, a map pin. Access notes you add for the therapist (gate codes, entry instructions) are stored with the address and shown to the assigned therapist and to our operations team.
- Booking and payment records: which service, when, where, the price breakdown, taxes, any coupon applied, the payment method and status, invoices, refunds and your wallet balance and ledger.
- Safety preferences: whether you have asked to be matched only with female therapists. This is stored on your account and applied to every booking.
- Communications: in-booking chat messages, support tickets and their replies, incident and dispute reports, and the notifications we have sent you.
- Device and technical data: a device identifier generated by the app, platform and app version, and the IP address a request came from. The device identifier is generated randomly by the app itself — it is not a hardware serial, advertising ID or any identifier that follows you across other apps.
- Live location — only in the narrow window described in section 5.
- For a booking between 8 PM and 6 AM: a photo of a government identity document and a live selfie taken through the app's camera at the time of booking, and the document number if you choose to add it. This is a safety record for that booking, kept as described in section 4, and is never shown to the therapist.
- If someone referred you to Midnight Mitra, who that was, and if you refer someone else in turn, who they are and the reward it earns you.
3. Data we collect from therapists
- Everything in section 2 that applies to holding an account, plus the following.
- Verification documents: government identity documents such as Aadhaar or PAN, professional certifications and, where applicable, police-verification records. These are required before an account can accept work; a therapist who has not passed verification cannot go online.
- Payout details: bank account number, IFSC, account holder name and optionally a UPI ID. These are used only to pay you.
- Working data: skills, service areas, weekly availability, duty status, job history, ratings and reviews, earnings and payout records.
- Profile photographs, which are reviewed by a human before they become visible to customers.
- Live location during jobs, and between jobs only if duty-hours tracking is switched on — see section 5.
4. Identity documents and payout details
Identity documents are the most sensitive data we hold, so they are handled differently from everything else. This covers a therapist's KYC documents and a customer's night-booking ID and selfie alike. They are uploaded to private storage that is not reachable from the public internet. The document number and the storage path are encrypted at rest with AES-256. Bank account numbers are encrypted the same way, and once saved we only ever display the last four digits back to you.
Access is restricted to staff whose role carries the relevant permission, it is limited to what that role actually needs to review, and every single view of a document is written to an audit log with the name of the staff member who opened it. Nobody at Midnight Mitra can browse an approved therapist's identity documents, or a customer's night-booking photos, through the ordinary admin screens.
A night-booking photo is a safety record, not an identity check we score or verify against a database — it is kept on file so that, if something goes wrong during that booking, there is a contemporaneous record of who booked it.
We do not sell, rent or share identity documents with any third party for marketing, analytics or profiling. They are disclosed outside the company only where the law compels it.
5. Location data — exactly what is collected and when
Location is the area where marketplaces most often over-collect, so this section states the rule precisely rather than in general terms.
For therapists, position is recorded while a job is in progress — from the point of setting out, through arrival, to the end of the session. Separately, an administrator can enable duty-hours tracking, in which case position is also recorded while the therapist is signed on and online between jobs. That setting is off by default. Therapists can see which mode is active from within the partner app.
For customers, position is recorded only while a booking of yours is actually live — that is, while the therapist is on the way, has arrived, or the session is running. Outside that window the app does not record your position at all. There is no background tracking of customers, ever.
Disclosure is limited in the same way as collection. Our operations staff can look at a customer’s trail only while that customer has a live booking; once the session ends, the trail stops being viewable through our tools. A therapist’s job trail remains available to safety and dispute staff for as long as it is retained, because that is what a later incident investigation depends on. Every time a staff member opens a location trail, the fact of it and how many points were shown is written to the audit log.
You control the underlying permission on your device and can withdraw it at any time in your device settings. Withdrawing it will stop live tracking working, which means we cannot show your therapist’s approach in real time and our safety team has less to work with if something goes wrong during a session.
6. Why we process your data
- To create your account, verify your mobile number, and verify therapist identity and qualifications before anyone is allowed to accept work.
- To price, take and fulfil bookings — including matching you to an eligible therapist, dispatching the job, and running the Service OTP that opens and closes a session.
- To take payment, issue invoices, apply GST where it is chargeable, process refunds and wallet credits, and pay therapists.
- To operate the safety features: SOS, live tracking during a session, incident handling and the moderation of chat and reviews. An SOS alerts our safety team, not emergency services directly — if you need police, ambulance or fire services, call 112 yourself as well. You can follow up on how an incident was handled at support@midnightmitra.com or grievance@midnightmitra.com.
- To send you booking updates, security notices and service messages by push notification, SMS or in-app message.
- To detect and prevent fraud, contact-detail sharing intended to take work off-platform, and breaches of our conduct policy.
- To meet legal obligations — tax records, statutory retention, responses to lawful requests, and the record-keeping the IT Rules require of an intermediary.
7. Consent, and where we do not rely on it
We ask for your explicit consent at registration, and we record when and for what you gave it. You can withdraw consent at any time from the app or by writing to us.
Some processing does not stop when consent is withdrawn, because it does not rest on consent in the first place: keeping tax invoices, retaining safety and incident records, and holding data we are required by law to keep. Withdrawing consent for the processing that is essential to the service means we can no longer provide the service to you, and your account will be closed.
9. Chat, reviews and moderation
Messages sent through in-booking chat are scanned automatically for content that breaks our rules — most commonly phone numbers, messaging-app handles, UPI IDs and attempts to arrange payment outside the platform. A message caught by that check is withheld rather than delivered, is placed in a human moderation queue, and the sender is told it was not delivered.
Reviews go through the same moderation queue and are not published automatically.
This means a member of our moderation team may read messages and reviews that were flagged. They do not have access to the ordinary contents of conversations that were never flagged.
10. Security
No system is perfectly secure. If a breach occurs that is likely to affect you, we will notify you and the Data Protection Board of India as required under the DPDP Act.
- All traffic between your device and our servers is encrypted in transit with TLS.
- Identity document numbers, document storage paths and bank account numbers are encrypted at rest with AES-256.
- Access to the back office is role-based. Staff are given only the permissions their role needs, and an account can be suspended immediately, which also invalidates any session it holds.
- Sensitive administrative actions — viewing a document, opening a location trail, approving a payment, changing tax settings, granting a role — are recorded in an append-only audit log that names the staff member who did it.
- Passwords are stored only as salted hashes. One-time passwords are stored hashed and expire quickly.
11. How long we keep data
- Location points are deleted 180 days after they are recorded. That window is set to outlast the period in which a payment can be charged back or a dispute realistically raised, and no longer.
- Audit logs are kept for eight years, to match the record-retention period for books of account under the Companies Act, 2013 and to cover tax and safety enquiries.
- Invoices, payment records and tax documents are kept for the period Indian tax law requires.
- Booking history, incident reports and safety records are kept while they may still be needed for a dispute, an investigation or a legal claim.
- Account and profile data is kept while your account is open, and thereafter only as set out above.
12. Your rights under the DPDP Act
We do not charge for exercising these rights. We respond within the timelines in section 15.
- Access — you can obtain a copy of the personal data we hold about you. In the customer app this is available immediately from Profile, under “Your data”, and is delivered as a file you can keep.
- Correction — you can correct data that is wrong or out of date, from the app or by writing to us.
- Erasure — you can ask us to delete your account. What that actually does is set out in section 13, in plain terms, because “delete” means different things at different companies.
- Withdrawal of consent — see section 7.
- Grievance redressal — you can complain to our Grievance Officer, and if you are not satisfied, to the Data Protection Board of India.
- Nomination — you may nominate another individual to exercise these rights on your behalf in the event of your death or incapacity.
13. What deleting your account actually does
When you delete your account, we do the following, and we would rather tell you exactly than let the word “delete” imply more than it means.
- Your login is closed immediately and every signed-in session is revoked, so the account cannot be used again.
- Your entire location history is permanently erased. It is not archived and it is not recoverable.
- Your account record is closed and retired rather than erased outright, because bookings, invoices and safety records have to remain attached to an identifiable person for tax and legal reasons. It is no longer visible or usable as an account.
- Bookings, invoices, tax records, incident reports and safety records are retained for the periods in section 11.
- Any remaining wallet balance is closed with the account and is not refunded to a bank account, so withdraw or use it first.
- Your deletion request itself is logged, so that we can show it was made and honoured.
14. Children
Our services are for adults only. You must be 18 or older to hold an account, and you confirm this at registration. We do not knowingly collect data from anyone under 18, and we do not use children’s data for tracking or targeted advertising in any form. If we learn that an account belongs to a minor, we close it and delete the associated data.
15. Grievance Officer and response times
Privacy questions and requests can be sent to privacy@midnightmitra.com. Formal grievances, including anything you wish to escalate, should go to our Grievance Officer at grievance@midnightmitra.com.
In line with the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, we acknowledge a complaint within 24 hours and aim to resolve it within 15 days. Requests to exercise your DPDP rights are actioned within 30 days. If we need longer because a request is complex, we will tell you why and when to expect an answer.
If you remain dissatisfied, you may complain to the Data Protection Board of India.
16. Changes to this policy
We may update this policy as the service changes or the law does. The date at the top always reflects the current version. Where a change materially affects how we handle your data, we will tell you in the app or by email before it takes effect, rather than relying on you to notice.