Privacy Policy
Effective 13 August 2026 · Version 1.0
1.Introduction and scope
1.1This Privacy Policy (“Policy”) describes the manner in which Freezy (“Freezy”, “we”, “us” or “our”) collects, uses, stores, discloses, transfers, retains and otherwise processes Personal Data of users (“you”, “your” or “User”) in connection with the Freezy mobile application, the website at planfreezy.com, and all related services (collectively, the “Services”).
1.2This Policy is published in accordance with the Digital Personal Data Protection Act, 2023 and the rules made thereunder, the Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, each as amended from time to time (collectively, “Applicable Law”).
1.3By creating an account, accessing or using the Services, you acknowledge that you have read and understood this Policy and consent to the processing of your Personal Data in accordance with it. If you do not agree, you must not use the Services.
1.4This Policy forms part of, and should be read together with, our Terms of Service.
2.Definitions
In this Policy, unless the context requires otherwise:
- (a)“Personal Data” means any data about an individual who is identifiable by or in relation to such data;
- (b)“Processing” means any operation performed on Personal Data, including collection, recording, storage, use, disclosure, transfer, erasure or destruction;
- (c)“Data Principal” means the individual to whom the Personal Data relates;
- (d)“Data Fiduciary” means the person who alone or in conjunction with others determines the purpose and means of Processing;
- (e)“Data Processor” means any person who processes Personal Data on behalf of a Data Fiduciary;
- (f)“Account” means the registered user account created by you to access the Services.
3.Data Fiduciary
3.1Freezy is the Data Fiduciary in respect of the Personal Data described in this Policy and determines the purposes and means of its Processing.
3.2All correspondence in relation to this Policy may be addressed to hello@planfreezy.com.
4.Personal data we collect
4.1Information you provide directly. When you register for and use the Services, we collect the categories of Personal Data set out below.
| Category | Particulars |
|---|---|
| Identity and contact data | Name, email address and, where you choose to provide it, mobile number. |
| Authentication data | Your password, stored solely as a one-way cryptographic hash. We do not retain, and cannot recover, your password in plain text. |
| Preference data | Persona, locality, city, indicative weekend budget, energy level, interests, hobbies, dietary and other stated preferences. |
| Weekly inputs | Availability, budget or energy adjustments and free-text notes you submit for a given week. |
| Communications | Messages you send through the in-app assistant and any requests derived from them. |
| Feedback data | Ratings, selections and reactions in respect of plans delivered to you. |
| Transaction data | Subscription tier, amount, currency, date, period of validity and payment reference identifiers issued by our payment processor. |
4.2Information collected automatically. We collect a device push-notification token where you enable notifications, and technical logs generated in the ordinary course of operating the Services, including timestamps of account activity and diagnostic information relating to errors.
4.3Location data.Where you expressly grant permission, we obtain a single reading of your device's approximate position for the purpose set out in clause 5.1(c). The following limitations apply and are implemented in the Services:
- (a)the reading is taken once, at the time permission is granted, and is not repeated;
- (b)no background or continuous location collection is performed at any time;
- (c)the coordinates are truncated prior to storage to approximately 110 metres of precision, such that they identify a locality and not a residential address;
- (d)the grant of permission is optional and the Services remain functional without it; and
- (e)you may erase the stored coordinates at any time within the application, and such erasure takes effect immediately.
4.4Payment instrument data. We do not collect, receive or store card numbers, unified payments interface identifiers, bank account details or any other payment instrument credentials. Such data is submitted by you directly to our payment processor and does not transit our systems.
4.5Sensitive Personal Data. We do not knowingly collect financial information constituting payment credentials, biometric data, health data, or data relating to religious or political beliefs, caste, or sexual orientation. You should not submit such information through the in-app assistant or any free-text field.
5.Purposes of processing
5.1Personal Data is processed only for the following specified purposes:
- (a)to create, authenticate, administer and secure your Account;
- (b)to generate personalised weekend recommendations, being the core function of the Services;
- (c)to exclude venues situated in close proximity to your stated home locality, so that recommendations constitute an outing rather than a local venue;
- (d)to process subscription payments and maintain records of transactions;
- (e)to deliver service communications, including account, password-reset, subscription and weekly plan notifications;
- (f)to respond to your enquiries, requests and grievances;
- (g)to monitor, diagnose and rectify faults, and to maintain the security and integrity of the Services;
- (h)to prevent, detect and investigate fraud, abuse or unauthorised access; and
- (i)to comply with Applicable Law and lawful requests of governmental or judicial authorities.
5.2We do not sell Personal Data. We do not process Personal Data for third-party advertising, behavioural profiling for advertising, or any purpose incompatible with those stated in clause 5.1.
6.Lawful basis and consent
6.1Processing is undertaken on the basis of the consent you provide at the time of registration and, in respect of location and notifications, at the time you grant the relevant device permission.
6.2Certain Processing is undertaken for legitimate uses permitted under Applicable Law, including the performance of the subscription contract, compliance with statutory obligations, and the security of the Services.
6.3Withdrawal of consent. You may withdraw your consent at any time, with effect for the future, by the means described in clause 12. Withdrawal does not affect the lawfulness of Processing carried out prior to withdrawal. Where consent is withdrawn in respect of data necessary for the provision of the Services, we may be unable to continue providing the Services to you.
7.Automated processing
7.1Weekend recommendations are generated by automated means using a third-party large language model. The inputs supplied for this purpose comprise your preference data, weekly inputs, feedback data and, where you use the assistant, recent messages.
7.2Your name, email address, mobile number, authentication data, transaction data and precise coordinates are not supplied to the model.
7.3Our model provider processes such inputs solely on our instructions and does not use them to train its models.
7.4Such automated Processing produces recommendations only. It does not result in any decision producing legal effects concerning you or similarly significantly affecting you. Recommendations may be inaccurate or unsuitable, and you exercise independent judgement in acting upon them.
8.Disclosure to third parties
8.1We engage the following categories of Data Processors, each of which processes Personal Data only on our documented instructions and under obligations of confidentiality and security:
| Category | Data disclosed | Purpose |
|---|---|---|
| Payment processing | Name, email, mobile number, transaction particulars | Collection of subscription fees and settlement |
| Artificial intelligence services | Preference data, weekly inputs, assistant messages | Generation of recommendations |
| Email delivery | Name, email address | Transmission of service communications |
| Cloud hosting and database services | All stored Personal Data | Operation and storage |
| Push notification services | Device push token | Delivery of notifications |
| Error monitoring | Technical diagnostic data | Fault detection and rectification |
8.2We may disclose Personal Data where required to do so under Applicable Law, or pursuant to a lawful order, summons, direction or requirement of a court, tribunal, regulator or law enforcement authority of competent jurisdiction.
8.3In the event of a merger, acquisition, restructuring or transfer of all or part of our business, Personal Data may be transferred to the successor entity, subject to that entity being bound by obligations no less protective than those in this Policy. You will be notified of any such transfer.
9.Cross-border transfers
9.1Certain Data Processors engaged by us are situated, or maintain infrastructure, outside India. Accordingly, Personal Data may be transferred to and processed in jurisdictions other than India.
9.2Such transfers are effected in accordance with section 16 of the Digital Personal Data Protection Act, 2023 and are not made to any territory in respect of which transfer has been restricted by the Central Government by notification.
9.3We require each such Data Processor to maintain security safeguards and confidentiality obligations no less protective than those set out in this Policy.
10.Retention
10.1Personal Data is retained only for so long as is necessary for the purposes set out in clause 5, or for such longer period as is required under Applicable Law.
| Category | Retention period |
|---|---|
| Account, preference, location, communications and feedback data | For the subsistence of the Account; erased within thirty (30) days of a valid erasure request or Account closure. |
| Transaction records | Retained for such period as is prescribed under applicable taxation and companies legislation, notwithstanding Account closure, in minimal form comprising amount, date and reference identifier. |
| Technical and diagnostic logs | Retained for a limited operational period and thereafter erased or aggregated such that you are no longer identifiable. |
| Password reset tokens | Erased or rendered invalid upon use or upon expiry, whichever is earlier. |
10.2Upon expiry of the applicable retention period, Personal Data is erased or irreversibly anonymised.
11.Security safeguards
11.1We implement reasonable security practices and procedures commensurate with the nature of the Personal Data processed, including:
- (a)storage of authentication credentials using a one-way adaptive hashing function, such that plain-text passwords are neither stored nor recoverable;
- (b)transmission of data over encrypted channels;
- (c)single-use password reset tokens of limited validity, stored only in hashed form;
- (d)invalidation of all existing sessions upon a change of password, so that any concurrent unauthorised session is terminated;
- (e)rate limiting and throttling of authentication and payment endpoints;
- (f)segregation of administrative and user access credentials; and
- (g)verification of the cryptographic signature of all payment confirmations prior to any entitlement being granted.
11.2Notwithstanding the foregoing, no method of transmission or storage is entirely secure, and we do not warrant absolute security.
11.3In the event of a personal data breach, we shall notify the Data Protection Board of India and each affected Data Principal in the manner and within the timelines prescribed under Applicable Law.
12.Your rights
12.1Subject to Applicable Law, you have the following rights in respect of your Personal Data:
- (a)Right to access — to obtain a summary of the Personal Data processed and the Processing activities undertaken;
- (b)Right to correction — to have inaccurate or misleading Personal Data corrected, and incomplete Personal Data completed;
- (c)Right to erasure — to have your Personal Data erased, save where retention is required under Applicable Law;
- (d)Right to withdraw consent — as set out in clause 6.3, including erasure of stored location data alone without closure of your Account;
- (e)Right to grievance redressal — as set out in clause 13;
- (f)Right to nominate — to nominate another individual to exercise these rights in the event of your death or incapacity.
12.2Requests may be made to hello@planfreezy.com. We shall respond within thirty (30) days of receipt of a valid request. We may require verification of your identity before giving effect to a request.
12.3You are responsible for ensuring that the information furnished by you is accurate and complete, and for not impersonating any other person or furnishing false particulars when exercising the above rights.
13.Grievance redressal
13.1In accordance with the Digital Personal Data Protection Act, 2023 and the Information Technology Act, 2000, the particulars of the Grievance Officer are set out below:
13.2Grievances shall be acknowledged within seventy-two (72) hours of receipt and disposed of within thirty (30) days.
13.3Where you are not satisfied with the resolution provided, you may prefer a complaint to the Data Protection Board of India in accordance with the procedure prescribed under Applicable Law.
14.Children
14.1The Services are not directed at, and are not intended for use by, individuals below eighteen (18) years of age. We do not knowingly process the Personal Data of children.
14.2We do not undertake tracking, behavioural monitoring or targeted advertising directed at children.
14.3If we become aware that Personal Data of a child has been collected without verifiable consent of a parent or lawful guardian, we shall erase such data forthwith. Any parent or guardian who believes such data has been furnished may write to the address in clause 13.
15.Cookies and similar technologies
15.1The mobile application does not employ advertising cookies or third-party tracking technologies. Authentication credentials are held in the secure storage facility provided by your device's operating system.
15.2The website employs only such storage as is strictly necessary for its operation and security. We do not deploy advertising or cross-site tracking technologies.
16.Third-party links
16.1The Services may reference venues, events or resources operated by third parties. We do not control, and are not responsible for, the privacy practices or content of such third parties, and this Policy does not apply to them. You should review their respective policies before furnishing any Personal Data to them.
17.Amendments
17.1We may amend this Policy from time to time. The version and effective date at the head of this Policy shall be updated upon any amendment.
17.2Where an amendment is material, we shall notify you by email to the address associated with your Account, or by prominent notice within the Services, prior to the amendment taking effect.
17.3Continued use of the Services following the effective date of an amendment constitutes acceptance of the amended Policy.
18.Governing law and jurisdiction
18.1This Policy shall be governed by and construed in accordance with the laws of India.
18.2Subject to clause 13.3, the courts at Bengaluru, Karnataka shall have exclusive jurisdiction in respect of any dispute arising out of or in connection with this Policy.
19.Contact
19.1Any question in relation to this Policy, and any grievance under clause 13, may be addressed to hello@planfreezy.com.