Privacy Policy
Last updated: February 2026 · Governed by the Digital Personal Data Protection Act, 2023 (India)
1. Introduction
Sahasamstapaka Private Limited (“Company”, “we”, “us”, or “our”) operates FoundrForge (“Platform”), a subscription-based co-founder matching platform designed to help solo founders in India find compatible co-founders for their ventures. This Privacy Policy (“Policy”) explains how we collect, use, store, disclose, and protect personal data when you access or use the Platform, including our web and app-based services, matchmaking features, and in-app chat.
The Platform enables users to create a profile, get matched with prospective co-founders based on skills, role, and location preferences, and communicate with matches once mutual interest and, where relevant, intellectual- property-related consent has been established. We do not mediate, guarantee, or take part in any deals, agreements, or arrangements reached between users.
This Policy is designed around the Digital Personal Data Protection Act, 2023 (“DPDP Act”) and the Information Technology Act, 2000 read with the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 (“IT Rules, 2021”), as applicable to us as a platform operating solely in India. By creating an account or otherwise using the Platform, you confirm that you have read, understood, and consented to the practices described in this Policy.
2. Types of Data Collected
2.1 Profile and Identity Information
- Full Name
- Email Address
- Profile Photo (retrieved via Google sign-in)
- City
- Role Type, Skills, and Elevator Pitch (as entered by you)
- LinkedIn Profile URL and related professional details (only if you choose to connect LinkedIn)
2.2 Communication Data
- In-app chat messages exchanged with matches
- Consent timestamps (e.g., when you accept a match request or provide IP-related consent before chatting)
2.3 Technical and Transactional Data
- IP address recorded at the moment consent is given
- Payment gateway reference IDs for subscription payments (we do not collect or store card numbers or other card details)
2.4 Data We Do Not Collect
We do not intentionally collect health data, financial account details beyond payment gateway references, race, religion, or other sensitive personal data as may be understood under applicable law.
3. Purpose and Legal Basis of Processing
We process personal data solely for the purpose of co-founder matchmaking. We do not use personal data for advertising, resale, or any profiling activity beyond matching.
3.1 Purposes
- To create and manage your profile on the Platform
- To match you with prospective co-founders using our algorithmic matching process
- To enable communication (chat) between matched users, subject to consent safeguards described in Clause 5
- To process subscription payments
- To calculate and display a response-rate indicator based on how quickly you respond to match requests
- To comply with applicable law
3.2 Legal Basis under the DPDP Act, 2023
Our processing is based on your explicit, granular, and freely given consent, obtained at the relevant stage (account creation, LinkedIn connection, and prior to unlocking chat with a match). Consent is not bundled, and you may withdraw it at any time by deleting your account, as described in Clause 6.
4. How We Use Your Data
- Matching only: your profile data (skills, role, city, elevator pitch) is used exclusively to generate and rank potential co-founder matches.
- Automated matching (profiling): the Platform uses automated algorithmic processing of your skills, experience, and location filters to suggest relevant co-founders. This is limited to matchmaking and does not extend to advertising or unrelated profiling.
- AI-assisted “Smart Matches”: certain matching recommendations are generated with the assistance of a third-party large language model (Claude, by Anthropic), accessed through the Emergent platform, strictly for reasoning support in generating match suggestions.
We do not use your personal data for marketing or advertising purposes.
5. Special Consent Mechanisms
Because FoundrForge facilitates early-stage discussions between founders, certain features are designed to protect your identity and ideas until a genuine mutual match is established.
5.1 Blurred Profile Details
When you send or receive a match request, your name and LinkedIn details (if connected) remain blurred to the other party until the request is accepted.
5.2 Optional LinkedIn Verification
Connecting your LinkedIn profile is optional. If you choose to do so, your profile displays a LinkedIn-verified badge. We access only the minimum information necessary (such as your name and email) to confirm the match, and we do not write or post anything back to your LinkedIn account.
5.3 Consent Prior to Chat Access
Once a match is mutually accepted, both users are shown a “5 Ground Rules” screen before the chat unlocks. This screen is shown fresh on every new match and covers:
- Not sharing raw intellectual property (source code, proprietary designs, secret formulas, or investor materials) before signing an independent non-disclosure agreement (NDA); FoundrForge is not a party to any such NDA.
- A reminder that merely discussing an idea does not, by itself, protect it under Indian IP law, and that users should keep a dated record of specific expressions of their idea.
- A warning against ever paying another user upfront for funding, investment access, registration, or escrow, since this is a common scam pattern; users are encouraged to report and block anyone who asks.
- Links to independent, external, lawyer-drafted mutual-NDA templates for users who wish to sign an NDA before sharing IP. FoundrForge does not host, review, endorse, or process these documents, and any signing is entirely between the two users.
- A reminder that FoundrForge does not broker deals: term sheets, equity splits, and disputes are matters between the users, not the Platform.
Before the “I understand – Enter chat” action becomes available, users must check boxes confirming: (a) their understanding of their rights to erasure, correction, and portability of their data; (b) their agreement to the Terms of Service, including its IP-protection clauses (that FoundrForge is a networking platform only, that users share ideas at their own risk, that the Company is released from user-to-user IP disputes, and that no partnership or agency is created by use of the app); and (c) that they have read and understood the 5 rules above, take sole responsibility for the IP and information they share in chat, will not pay anyone upfront for funding or investment access, will report anyone who asks, and have reviewed the Terms of Service and this Privacy Policy. Users may instead choose to decline and exit.
5.4 Response Rate
If a user does not respond to a match request within 72 hours, their displayed response rate decreases, which may lower the visibility of their profile in future matches. FoundrForge does not mediate, verify, or participate in any discussions, negotiations, or agreements between matched users.
6. Data Storage, Retention, and Deletion
6.1 Consent at Sign-Up (DPDP Consent Screen)
Before any personal data is saved, new users are shown a dedicated consent screen at sign-up, referencing the Digital Personal Data Protection Act, 2023, and are asked to explicitly consent to two matters:
- Storage of personal data: that the user’s profile, matches, and chat messages will be stored with FoundrForge’s cloud database provider, and will never be sold, licensed, or shared with advertisers.
- Processing for matchmaking only: that the user’s data will be processed strictly for the purpose of surfacing potential co-founder matches, and will not be sold, licensed, or shared with advertisers.
This screen also confirms that the user retains the absolute right to wipe their data at any time via Settings → Privacy & Security, and that such deletion is immediate and irreversible.
6.2 Storage
Personal data is stored on MongoDB Atlas, hosted in the Mumbai (ap-south-1) region.
6.3 Retention
While your account remains active, your data is retained to enable the Platform’s core matching and chat functions. Upon account erasure, your personal data is immediately and permanently deleted (hard delete). Payment transaction records are retained for 7 years to comply with applicable tax law, and are de-linked from your profile once your account is deleted.
6.4 Deletion
You may delete your account and personal data at any time through your account settings. Deletion is immediate, other than the de-linked payment records described above.
7. Data Security
All data in transit is protected using HTTPS. Session cookies are configured with httpOnly, secure, and SameSite=None attributes. Access to chat is restricted through server-side authorization checks limiting participation to the two matched users. Multi-factor authentication is enabled on our database administration account. Security headers, including X-Content-Type-Options, X-Frame-Options, HSTS, and Content-Security-Policy, have been implemented. Authentication endpoints are protected with rate limiting to reduce the risk of automated abuse. We are in the process of formalising a written data breach response plan; this Policy will be updated once that process is complete.
8. Data Sharing and Third Parties
We share limited personal data with the following third parties, each scoped to the minimum data necessary for their function:
- Google — receives no data from us; we act as a “relying party” on Google’s OAuth authentication, meaning Google verifies your identity and returns your email, full name, and profile picture to our authentication processor (see below) at your instruction when you click “Sign in with Google.”
- Emergent Labs Pte. Ltd. (“Emergent”) — our authentication and AI-services platform, acting as a Data Processor on our instructions. Emergent brokers the Google OAuth handshake between Google and FoundrForge, and in doing so momentarily receives your Google email address, full name, and profile picture solely to authenticate you into your FoundrForge Account. Emergent does not retain this data beyond the authentication event, does not use it for its own marketing or analytics, and does not share it with any further party. Emergent also operates the secure API relay through which we access Anthropic Claude for the Smart Matches feature described in §7; no personal data other than your public profile role, skills, city, and elevator pitch is transmitted through this relay for that purpose.
- LinkedIn — for optional profile verification (OAuth), limited to reading name and email to confirm the match; no data is written back to LinkedIn.
- Razorpay — for processing subscription payments.
- Anthropic (Claude), accessed via the Emergent platform for AI-assisted match reasoning only, as described above.
We do not sell, rent, or trade your personal data to any third party. We currently do not transfer personal data outside India, except where our processors listed above operate their services from data centres located in permitted jurisdictions in accordance with §16(2) of the DPDP Act, 2023.
9. Cookies and Tracking Technologies
We use only essential cookies necessary for authentication and secure session management. We do not use analytics, marketing, or advertising cookies.
10. User Rights
You retain the following rights over your personal data, consistent with the rights confirmation shown to you at sign-up and before entering chat with a match:
- Erasure: you retain the absolute right to wipe all of your data at any time via Settings → Privacy & Security. Deletion is immediate and irreversible, as described in Clause 6.
- Correction: you may review and update your profile information at any time through Settings.
- Portability: you may request your data in a structured format by contacting our Data Protection Officer.
- Consent withdrawal: since our processing is consent-based, deleting your account withdraws your consent and stops all further processing of your personal data, other than legally mandated retention of de-linked payment records.
To exercise any of these rights or raise a concern, you may contact our Data Protection Officer at the details in Clause 12.
11. Compliance and Grievance Redressal
This Policy is built around the requirements of the DPDP Act, 2023. A grievance redressal mechanism is provided for under our Terms of Service.
- Name: Harish S E
- Designation: Founder and Grievance Officer
- Email: harish.se@foundrforge.in
We will communicate any material changes to this Policy at least 7 days in advance through an in-app banner and email notification before such changes take effect.
12. Contact Information
For any questions, requests, or concerns relating to this Privacy Policy or your personal data, you may contact our Data Protection Officer:
- Data Protection Officer (DPO): Abinaya Balas
- Email: support@foundrforge.in
- Registered office: No. 11 (Old No. 76), Situated at Diagonal Road, 3rd Block, Jayanagar, Ward No. 167 (Old No. 59), Bangalore, Karnataka – 560011
- GSTIN: 29ABUCS6856L1Z3
13. Amendments to this Policy
We may update this Policy from time to time. Updates will be notified via the App and will take effect on the date specified. Continued use of the Services after changes constitutes acceptance of the revised Policy.