Skip to main content

VerifyShaadi policies

Privacy Policy

We handle two kinds of people’s data: yours, as the person who orders a report, and the candidate’s, as the person being verified. This page explains what we collect about each, what we do with it, how long we keep it, and how to make us stop.

Last updated 27 July 2026

1. Who we are

VerifyShaadi is a matrimonial background verification service operated in India by DDverse Initiatives. For the purposes of the Digital Personal Data Protection Act, 2023 (“DPDP Act”) we are the Data Fiduciary for the personal data described below. You, and the candidate being verified, are Data Principals.

You can reach our grievance contact at verifyshaadi@ddverse.in. We aim to acknowledge every privacy request within 3 working days and to resolve it within 30 days.

2. The consent model, in plain terms

There are two ways an order can run, and the difference decides what we are able to check. You choose when you place the order.

Notified, the candidate is asked

We contact the candidate on the phone number or email you provide, tell them who has requested a verification and exactly which checks are proposed, and ask them to consent.

  • If they consent, we run the checks you paid for and nothing beyond them.
  • If they decline, or do not respond within 48 hours, the order is cancelled, no checks are run, and your payment is refunded. See our Refund Policy.
  • The candidate may withdraw consent at any time before delivery. If they do, we stop, we do not deliver partial findings, and we refund you.

Confidential, the candidate is not contacted

In confidential mode we do not approach the candidate. You instead sign a declaration that you have a legitimate reason for the enquiry. In exchange, the report is narrower: checks that legally require the candidate’s own consent cannot be run at all. That includes Aadhaar and PAN-based identity confirmation, EPFO employment history, DigiLocker documents and NAD education records. Your declaration is not a substitute for someone else’s consent, and our systems will not let it be used as one. Confidential reports rely on publicly accessible records only, and they say plainly on the face of the report which checks were unavailable.

3. What we collect

From you, the customer

  • Your mobile number, which is how you sign in (verified by one-time password).
  • Your name, email address and preferred language, if you give them.
  • Details of the order: which product you chose, the candidate’s details you supplied, and the status and timestamps of the work.
  • Payment records: the amount, the order reference, the time, and the result. Card and UPI details are handled by our payment processor and never reach our systems (section 6).
  • Basic technical data, device type, approximate region, and error logs, used to keep the service working.

About the candidate

  • Identifying details you provide: name, date of birth, phone, address, photograph.
  • Government identifier numbers where a check requires one, submitted by the candidate during consent rather than by you wherever possible.
  • The findings of the checks themselves: identity confirmation, address, criminal and court record searches, education and employment history, previous marriage records, and publicly visible social media presence.
  • For NRI and Family Background products, the equivalent overseas or family-level records described on the pricing page.

Some of this is sensitive by any ordinary reading, court records in particular. We treat all of it as confidential and disclose it only to you, the person who ordered the report.

4. What we do not do

  • We do not sell, rent or share personal data with advertisers or data brokers.
  • We do not buy leaked or scraped databases, and we do not use them as sources.
  • We do not access private messages, dating app accounts, call records, bank statements or anything else that requires breaking into an account.
  • We do not follow, photograph or physically surveil anyone.
  • We do not use your report data, or the candidate’s, to train models or to build profiles for any purpose other than producing your report.

5. Why we are allowed to hold it

Our basis under the DPDP Act is consent: yours when you place the order, and the candidate’s when they agree to be verified. Both consents are recorded with a timestamp. Where we retain records after that, for tax, accounting or a legal dispute, we do so because Indian law requires or permits it, which the DPDP Act treats as a legitimate use.

6. Payments

Payments are processed by PayU Payments Private Limited. When you pay, you are handed to PayU’s hosted checkout. Your card number, UPI PIN, CVV, net-banking credentials and any other payment secret are entered there and are never seen by, transmitted to, or stored on VerifyShaadi systems. We receive only a payment reference, an amount, a status and a timestamp. The amount charged is always decided on our server from the order, never sent from your browser or phone.

PayU processes your data under its own privacy policy and as a payment aggregator regulated by the Reserve Bank of India.

7. Who else sees the data

  • Our analysts. A named human analyst reviews every report. Access is limited to the analysts assigned to your order.
  • Verification sources. To run a check we must query the relevant official source or record-holder, a court records database, a university registrar, a former employer’s HR desk. We disclose only the minimum needed for that specific check.
  • Infrastructure providers. Hosting, database, authentication and notification providers process data on our instructions as Data Processors. Our primary hosting and database are configured in Indian or nearest-region data centres.
  • Nobody else, unless a court, regulator or law-enforcement authority makes a lawful, written demand. Where we are legally permitted to tell the affected person that this has happened, we will.

8. Cross-border transfer

For NRI verifications we necessarily interact with record-holders outside India, and we transfer the minimum data required to complete the check you ordered. Some of our infrastructure providers are companies incorporated outside India. Transfers are made only to jurisdictions not restricted by the Central Government under section 16 of the DPDP Act.

9. How long we keep things

  • The completed report and its underlying findings: 12 months from delivery, so you can download it again and so we can answer a dispute about it. Then deleted.
  • Supporting documents supplied by the candidate: 90 days after the report is delivered. Then deleted.
  • Cancelled or refunded orders: 30 days, retaining only what is needed to evidence the refund. Any candidate data already collected is deleted.
  • Consent records and payment/tax records: up to 8 years, because Indian tax and accounting law requires it. These hold the fact and time of consent and payment, not the report contents.
  • Your account until you ask us to close it, plus the periods above.

10. Your rights as a Data Principal

Under the DPDP Act you may ask us to:

  • Confirm and access, tell you what personal data of yours we hold, what we have done with it, and who we shared it with.
  • Correct, complete or update, fix anything inaccurate or out of date.
  • Erase, delete your data where we no longer need it for the purpose it was collected for and no law requires us to keep it.
  • Withdraw consent, as easily as you gave it. Withdrawal is not retrospective: it does not undo processing already lawfully done, and if you withdraw mid-order we cannot complete the report.
  • Nominate, name someone to exercise these rights on your behalf in the event of your death or incapacity.
  • Grievance redressal, complain to us first, and, if we do not resolve it, to the Data Protection Board of India.

A candidate who has been verified has these same rights over their own data, including the right to know that a verification was run, who requested it, and what was found. Write to verifyshaadi@ddverse.in from the number or email used during consent and we will verify your identity before acting.

11. Children

The service is for adults. We do not knowingly accept an order from anyone under 18, and we do not verify a candidate under 18. See our child safety policy for how we handle child sexual abuse and exploitation concerns.

12. Security

Access to report data is restricted to assigned analysts and logged. Sign-in is by one-time password to a verified mobile number, so there is no password of yours to leak. Data is encrypted in transit and at rest by our infrastructure providers. No system is perfect; if a breach affects your data we will notify you and the Data Protection Board as the DPDP Act requires.

13. Cookies and tracking

The public pages of this website set no advertising or analytics cookies. Signing in sets a session cookie, which is strictly necessary for the service to work. We do not run third-party trackers on the marketing pages.

14. Changes

We will update the date at the top of this page when this policy changes, and we will tell you by email or in-app if the change materially affects how we use your data.


Related: Terms of Service · Refund Policy · CSAE Policy