Legal
Privacy Policy
This policy explains what personal data Dayly collects, why, who can see it, how long we keep it, and the rights you have over it.
Last updated: [To confirm: publication date]
Draft — not yet reviewed by a lawyer
This document is a working draft. It has not been legally reviewed and is not yet in effect. Highlighted items need confirmation before publication:
- [To confirm: …] business or legal detail
- [Product decision: …] confirm actual behaviour
- Commonly required disclosure
Who we are
Commonly required disclosure · DPDP Act 2023
Dayly (the “App”) and this website are operated by [To confirm: registered legal entity name], a company incorporated in India with its registered office at [To confirm: registered office address] (“Dayly”, “we”, “us”). For the purposes of the Digital Personal Data Protection Act, 2023 (“DPDP Act”), we are the Data Fiduciary for the personal data described in this policy.
This policy applies to the Dayly mobile apps and to dayly.fashion. It should be read together with our Terms & Conditions and Community Guidelines.
The short version
- You sign in with your mobile number and a one-time password (OTP).
- Dayly is a women-only community, so we verify new profiles using a quick selfie or ID check during sign-up.
- Your outfit posts are visible according to the setting you choose: public, followers-only or private.
- Ratings, likes and comments are used to compute feeds, leaderboards and your style profile.
- You can turn ratings off, block people, report content, deactivate or delete your account.
- You have rights to access, correct and erase your data and to raise a grievance — see Your rights.
Personal data we collect
Commonly required disclosure · DPDP Act 2023, s. 5
Account and sign-in
- Your mobile number, used to create your account and to send and verify one-time passwords.
- Session and authentication tokens stored on your device to keep you signed in. [Product decision: name the SMS/OTP provider and confirm whether OTP codes or delivery logs are retained]
Profile verification
To keep Dayly women-only, we ask new members to verify their profile with a selfie or an image of an identity document. [Product decision: confirm: (1) whether verification is manual review, automated, or uses a third-party vendor; (2) whether any facial analysis or matching is performed; (3) which ID types are accepted; (4) how long selfie and ID images are kept after a decision and whether they are deleted]
Identity documents are sensitive. We use verification images only to decide eligibility and to prevent impersonation and fraud, and we do not show them to other members.
Profile information
- Name, username, profile photo, city and any bio or details you choose to add.
- Information needed to confirm eligibility, such as age. [Product decision: confirm whether date of birth is collected and stored, or only an age confirmation]
Content and activity
- Outfit photos, captions, outfit categories and types, and where you found an outfit, if you add it.
- The visibility setting of each post and whether ratings are allowed on it.
- Ratings you give and receive, likes, comments, follows, and Shelves (public or private collections).
- Leaderboard positions, profile statistics and achievements computed from this activity.
- Reports you make, people you block, and messages you send to our support team.
Device, usage and diagnostics
- Device model, operating system, app version, language and similar technical information.
- IP address and log data generated when the App communicates with our servers.
- Crash reports and performance diagnostics. [Product decision: name the crash/analytics tools used, if any]
- A push-notification token if you allow notifications. You can turn notifications off in your device settings at any time.
- Location: we use the city you select to personalise feeds and leaderboards. [Product decision: confirm whether device GPS/precise location is ever collected; if not, say so explicitly]
This website
This website does not ask you to sign in and does not set advertising cookies. Images on the site are served by a third-party image service (Unsplash), which receives standard request information such as your IP address and browser type when images load. [Product decision: update this if analytics or a cookie banner are added]
How we use personal data
Commonly required disclosure · DPDP Act 2023, s. 5
We use personal data for these specific purposes:
- To create and secure your account, including OTP sign-in.
- To verify eligibility for our women-only community and prevent impersonation.
- To publish your posts to the audience you choose and show you content from people you follow and from your city.
- To collect and display ratings, likes and comments, and to compute leaderboards and style profile statistics.
- To keep Dayly safe: detecting rating manipulation, spam and abuse; reviewing reports; enforcing our rules.
- To provide support and respond to grievances and data requests.
- To send service notifications and, where you allow it, push notifications.
- To understand how the App is used, fix problems and improve features.
- To comply with legal obligations and respond to lawful requests from authorities.
[Product decision: the pitch materials describe trend insights for brands and advertising. If Dayly will share aggregated or de-identified trend data with brands, show ads, or run sponsored challenges, describe each purpose here (and obtain consent where required) before launch. If not, state that you do not.]
Our legal basis
Commonly required disclosure · DPDP Act 2023, ss. 6–7
We process personal data on the basis of your consent, which you give when you create an account and use specific features, and for certain legitimate uses permitted by the DPDP Act — for example, where you voluntarily provide data for a specified purpose, or where processing is needed to comply with law.
Where we rely on consent you can withdraw it at any time, as easily as you gave it, through in-app settings or by contacting us. Withdrawal does not affect processing that happened before it, and some features (such as sign-in) cannot work without the related data.
[To confirm: whether consent will be managed through a registered Consent Manager, and the in-app consent flow]
Your controls and settings
- Choose public, followers-only or private for each post, and edit or delete posts.
- Turn ratings on or off.
- Make Shelves public or private.
- Block members and report content.
- Turn push notifications off in your device settings.
- Deactivate or delete your account — see Account Deletion.
How long we keep data
Commonly required disclosure · DPDP Act 2023, s. 8(7)
We keep personal data only as long as needed for the purposes above, then erase it, unless the law requires us to keep it longer.
| Data | Retention |
|---|---|
| Account and profile data | While your account is active; then [To confirm: period after deletion] |
| Posts, ratings, comments, Shelves | Until you delete them or your account; then [To confirm: period] |
| Verification images | [To confirm: period after verification decision] |
| Deactivated accounts | [To confirm: how long a deactivated account is kept before deletion, if ever] |
| Logs and security records | [To confirm: period required by law] |
Indian law may require us to retain certain information after an account is deleted — for example, the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 require intermediaries to retain some registration information for a period after an account is cancelled, and the rules under the DPDP Act may require logs to be kept for a minimum period. [To confirm: exact statutory retention periods, as confirmed by counsel]
How we protect data
Commonly required disclosure · DPDP Act 2023, s. 8(5)
We take reasonable security safeguards to prevent personal data breaches, including [To confirm: e.g. encryption in transit (TLS), encryption at rest, access controls, least-privilege staff access, audit logging]. Sign-in tokens are stored in encrypted storage on your device.
No system is perfectly secure. If a personal data breach occurs, we will notify the Data Protection Board of India and affected members as required by law.
Your rights
Commonly required disclosure · DPDP Act 2023, ss. 11–14
Under the DPDP Act, you have the right to:
- Obtain a summary of the personal data we process about you and the processing activities.
- Know the identities of other Data Fiduciaries and Data Processors with whom your data has been shared.
- Correct, complete or update your personal data.
- Erase your personal data, unless retention is required by law.
- Withdraw consent.
- Have your grievances redressed.
- Nominate another person to exercise your rights in the event of death or incapacity.
To exercise these rights, use the in-app settings or contact us at [To confirm: privacy request email]. We will respond within [To confirm: response period]. We may need to verify your identity first.
If you are not satisfied with our response, you may complain to the Data Protection Board of India after using our grievance process.
Children and age eligibility
Commonly required disclosure · DPDP Act 2023, s. 9
Dayly is only for people aged 18 or older. We do not knowingly collect personal data from anyone younger. Under the DPDP Act, anyone under 18 is a child, and processing their data requires verifiable parental consent; Dayly does not offer this, so under-18s may not use the App.
If we learn that someone under 18 has created an account, we will close it and delete their data, subject to legal retention requirements. If you believe a child is using Dayly, please contact us.
Where data is stored
Your data is stored on servers located in [To confirm: country/region of hosting]. If data is transferred outside India, we will do so only as permitted under the DPDP Act and any restrictions notified by the Government of India.
Grievance Officer and contact
Commonly required disclosure · DPDP Act 2023 & IT Rules 2021
For questions, data requests or grievances, contact our Grievance Officer:
- Name: [To confirm: Grievance Officer name]
- Email: [To confirm: Grievance Officer email]
- Address: [To confirm: Grievance Officer postal address]
We acknowledge grievances and resolve them within the timelines required by applicable law. [To confirm: acknowledgement and resolution timelines, as confirmed by counsel]
Changes to this policy
We may update this policy as Dayly evolves or the law changes. We will change the “Last updated” date above and, for material changes, notify you in the App before they take effect.