PRIVACY POLICY
Last updated: September 8, 2026
1. Who Are We?
Tamil-Meet is a mobile dating application designed for the Tamil community, published by: SASU RCM Consulting 13 rue Giuseppe Verdi - 77185 Lognes, FRANCE Contact email: contact@tamil-meet.com In this policy, "we", "our" or "Tamil-Meet" refers to SASU RCM Consulting as data controller within the meaning of the General Data Protection Regulation (GDPR — EU Regulation 2016/679).
2. Who Does This Policy Apply To?
This policy applies to anyone using the Tamil-Meet mobile application, available on iOS (App Store) and Android (Google Play), as well as the tamil-meet.com website and its early access list. The application is restricted to persons aged 18 years or older.
3. What Personal Data Do We Collect?
3.1 Registration Data (mandatory) • Email address: Account creation, authentication, identity verification • Password: Authentication (stored in hashed form using Argon2) • Username: Identification on the platform (visible to other users) • Date of birth: Minimum age verification (18 years) and age display • Gender: Matching with search criteria • Gender sought: Matching with search criteria • Country of origin: Cultural affinities and search criteria 3.2 Profile Data (mandatory at profile creation) • Height: Search criteria and profile display • Build: Search criteria and profile display • City and country of residence: Profile display and geographic search • Profile photos: Visual presentation (see Section 5 on photos) 3.3 Optional Profile Data You may choose to provide the following information to enrich your profile: • Languages spoken • Interests • Personality traits • Values • Relationship status (single, divorced, widowed) • Has children (yes/no) • Wants children (yes/no/maybe) • Smoker (yes/no) • Alcohol consumption (never, occasionally, socially, regularly) • Biography (free text, 500 characters max.) 3.4 Geolocation Data With your explicit consent, we collect your geographic position (GPS coordinates) to enable proximity-based profile search. You can disable geolocation at any time in your device settings. 3.5 Communication Data • Chat messages: Communication between users (text messages) • Photo access requests: Management of mutual consent to view clear photos • Reports: Platform moderation and security 3.6 Technical and Usage Data • Phone number (optional): Additional account verification • Push notification token (Expo Push Token): Sending push notifications to your device • Platform (iOS/Android): Technical adaptation of the service • Date/time of last activity: Online status display • Profile visit history: "Who viewed your profile" notification • Notification preferences: Personalisation of received notifications 3.7 Payment Data Premium subscriptions are managed exclusively by the integrated payment systems of Apple (App Store) and Google (Google Play). We do not collect or store any banking data (card number, IBAN, etc.). We only retain: • The store transaction identifier (Apple/Google) • The subscription type (monthly, quarterly, biannual) • The start, expiry and potential cancellation dates • The purchase platform (iOS/Android)
4. Legal Basis for Processing
In accordance with Article 6 of the GDPR, we process your data on the following bases: • Performance of a contract (Art. 6.1.b): Account creation, profile management, matching, messaging, subscription management • Consent (Art. 6.1.a): Geolocation, push notifications, processing of optional profile data • Legitimate interest (Art. 6.1.f): Content moderation (photos and reports), fraud prevention, platform security, anonymised usage statistics, handling of support contact requests sent through the website • Legal obligation (Art. 6.1.c): Retention of data required by law (e.g. transaction data)
5. Photos: Privacy by Default
Tamil-Meet is built on a fundamental principle of photo privacy: • Your photos are blurred by default for all other users. • Each uploaded photo is stored in two versions: an original (clear) version and a blurred version. • For another user to view your clear photos, they must send you an access request that you can accept or decline. • Access is revocable: you can withdraw access to your clear photos at any time. • In case of refusal, a 7-day cooldown period applies before a new request can be sent. Automatic Photo Moderation Your photos are analysed by an automated moderation system (Amazon Rekognition) to detect inappropriate content (nudity, violence, etc.). This processing is necessary to ensure the security and compliance of the platform. Moderation results (categorisation labels) are retained but no facial recognition or biometric identification is performed.
6. Sub-processors and Data Recipients
We use the following sub-processors to ensure the operation of the service: • Amazon Web Services (AWS) — S3: Photo hosting — EU (eu-west-3, Paris) • Amazon Web Services (AWS) — Rekognition: Automatic photo moderation — EU (eu-west-1, Ireland) • Apple Inc.: In-app purchase management (iOS) and webhook notifications — United States • Google LLC: In-app purchase management (Android) and webhook notifications — United States • Expo: Push notification delivery, and mobile app hot-fix distribution (IP address, platform, runtime version and release channel, sent on each app start; and, when a hot-fix fails to launch, the corresponding technical error message) — United States • Railway: Application and database hosting — United States • Plus Five Five, Inc. (Resend): Transactional email routing and contact-list hosting — United States • Meta Platforms Ireland Limited: Advertising campaign measurement on the tamil-meet.com website, only after consent — Ireland (transfers to the United States are covered by safeguards) • PostHog, Inc.: Audience measurement and session replay on the tamil-meet.com website, only after consent — EU (European cloud, Frankfurt) • Functional Software, Inc. (Sentry): Mobile app crash and backend error detection and diagnostics (account identifier, device model, app version, technical stack trace) — EU (Sentry European region) For data transfers to the United States (Apple, Google, Expo, Resend), these are governed by the EU-U.S. Data Privacy Framework or by Standard Contractual Clauses (SCCs) approved by the European Commission, in accordance with Chapter V of the GDPR.
7. Data Retention Periods
• User account and profile: Retained as long as the account is active. Deleted within 30 days after account deletion request. • Chat messages: Retained as long as the conversation exists. Deleted with the account. • Photos: Deleted from our servers (S3) within 30 days after deletion by the user or account deletion. • Transaction data (subscriptions): Retained for 6 years in accordance with French accounting and tax obligations. • Reports: Retained for 1 year after resolution to combat repeat offenders. • Email verification codes: Automatically deleted after 15 minutes (expiry). • Webhook logs: Retained for 1 year for debugging and auditing purposes. • Support contact requests: Retained in the support inbox for 3 years from the last exchange, then deleted. No copy is recorded in any database; if a technical incident occurs while the request is being processed, only a technical error report is transmitted to our error monitoring provider, and that report does not contain the request (see section 14). • Early access signups: Retained for 3 years from the last contact, then deleted. • Unsubscribed signups: The row is retained as proof of consent withdrawal (email address, status, acquisition channel, language and timestamps), and no longer receives any emails.
8. Your Rights
In accordance with the GDPR, you have the following rights: • Right of access (Art. 15): obtain a copy of your personal data. • Right to rectification (Art. 16): correct your inaccurate or incomplete data. • Right to erasure (Art. 17): request the deletion of your account and data. • Right to restriction (Art. 18): request restriction of processing in certain cases. • Right to data portability (Art. 20): receive your data in a structured, machine-readable format. • Right to object (Art. 21): object to processing based on legitimate interest. • Right to withdraw your consent at any time for processing based on consent (geolocation, push notifications). How to Exercise Your Rights Send your request to contact@tamil-meet.com specifying the email address associated with your account. We will respond within 30 days. In case of dispute, you may file a complaint with the CNIL (Commission Nationale de l'Informatique et des Libertés): • Website: www.cnil.fr • Address: 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07
9. Data Security
We implement the following technical and organisational measures to protect your data: • Password encryption using the Argon2 algorithm (recommended by OWASP). • JWT token authentication with automatic rotation and limited lifetime (15 min for access, 7 days for refresh). • Encryption in transit (HTTPS/TLS) for all communications between the application and our servers. • Secure storage of authentication tokens on the device via Expo SecureStore. • Rate limiting on sensitive endpoints (registration, login, reporting). • Notification tokens stored securely and deleted upon logout.
10. Security and Moderation Features
• User blocking: you can block a user at any time. Blocked profiles become mutually invisible. • Reporting: you can report inappropriate behaviour (inappropriate photos, harassment, fake profile, spam). Each report is reviewed by our moderation team. • Automatic photo moderation: photos are analysed before publication to detect content that does not comply with our terms of use. • Profile visibility: you can hide your profile at any time via the application settings.
11. Notifications
Tamil-Meet may send you push notifications to inform you of: • New messages received • Photo access requests received • Photo access requests accepted • Profile visits • Photo moderation results You can customise or disable each notification type in the application settings (Notifications section).
12. Minors
Tamil-Meet is strictly reserved for persons aged 18 and over. We do not knowingly collect personal data from minors. If we learn that a minor has created an account, it will be immediately deleted.
13. Changes to This Policy
We reserve the right to modify this privacy policy. In case of a substantial change, you will be notified by notification in the application or by email. The date of last update is shown at the top of this document. Continued use of Tamil-Meet after notification of a change constitutes acceptance of the updated policy.
14. Website, Early Access List and Contact Requests
For the tamil-meet.com website and early access list, SASU RCM Consulting is the data controller. We collect your email address, acquisition source, display language and, where applicable, optional gender and age range. This data is used to manage your signup, send you launch information and measure acquisition. The legal basis is your consent (GDPR Art. 6.1.a), collected through the checkbox and then confirmed by double opt-in. Active signups are retained for 3 years from the last contact; after unsubscribing, the row is retained as proof of withdrawal. You may withdraw consent at any time through the unsubscribe link or by contacting us. You have the rights described in section 8 and may lodge a complaint with the CNIL. Support contact requests The contact form on the tamil-meet.com website lets you send a request to our support team. We then process the category of your request (technical issue, my account, subscription and billing, reporting content or behaviour, privacy and personal data, or other request), the subject, your email address, the free-text message you write and the display language of the website at the time of sending. As the message is a free-text field, we invite you to include only the information needed to handle your request. This data is not recorded in any database: the form creates no account, no ticket and no application record, and the content you type is not logged. Your request is sent by email to our support inbox (contact@tamil-meet.com), routed by our sub-processor Resend (see section 6). Your email address is set as the Reply-To of that message, so that our answer reaches you directly. If a technical incident occurs while your request is being processed, a technical error report is transmitted to our error monitoring provider Sentry (see section 6), for diagnostic purposes; that report contains neither the subject, nor your message, nor your email address, nor your IP address. Your request lives on in that support inbox, and not in our application systems. The legal basis is our legitimate interest (GDPR Art. 6.1.f) in receiving and handling the requests addressed to us. Where your request concerns the exercise of your rights (section 8), our answer also falls under our legal obligation under Article 12 of the GDPR. Messages received are retained in the support inbox for 3 years from the last exchange, then deleted. You have the rights described in section 8 over this data and may in particular ask us to delete an exchange early. If you do not have a Tamil-Meet account, write to us from the email address used in your request: that address is what lets us identify the exchange concerned, as the section 8 procedure otherwise asks for the address linked to your account.
15. Contact
For any questions regarding this privacy policy or your personal data: SASU RCM Consulting 13 rue Giuseppe Verdi - 77185 Lognes, FRANCE Email: contact@tamil-meet.com This privacy policy is drafted in accordance with the General Data Protection Regulation (GDPR — EU Regulation 2016/679) and the French Data Protection Act of 6 January 1978, as amended.