Legal
Privacy Policy
Last updated: 7 October 2026
Rishta ("Rishta", "we", "our", "us") is committed to protecting your privacy. This policy explains what information we collect, how we use it, and how we keep it safe. It complies with the Australian Privacy Act 1988 (including the Australian Privacy Principles) and the New Zealand Privacy Act 2020.
1. Who we are
Rishta is not yet an incorporated company. It is run from Auckland by its founder, and this policy will be updated with the company details the moment it is registered. Contact: [email protected]. Your data is stored with Cloudflare, in its Oceania region.
2. Information we collect
Your email address and, if you set one, your password, which is how you sign in. Your full name and mobile number, given when you join: other members never see either, because your profile shows your first name only; the Rishta team can see both. To confirm your mobile, we send a code to it by WhatsApp or text message, through Didit. What you put in your profile: first name, age, gender, city and country, religion, community, languages, diet, height, education, work, marital and residency status, family details, what you are looking for and your partner preferences, and any photos you upload. When something breaks, such as a page error or a call that cannot connect, your browser may send us a short technical note: the page name and a few words about the error, never anything you typed. We keep these for 90 days, only to find and fix problems. What you do here: the interests and notes you send, your messages, photo requests, who you have blocked or reported, your settings, and when you were last active. Before your profile goes live, an ID check: Didit handles the photos of your passport or licence and your selfie, and tells us the result, the name, age and gender on the document, whether the same document or face has been used for another Rishta account, and a scrambled fingerprint of the document number. We never receive or keep the photos of your document. If your profile has photos at the time, your main photo is compared once with the face on your ID, and neither image is kept. When a family member makes a profile, they may give us the email address of the person on it, so we can send them the link to check their own ID. Only if you choose to: a phone number for an Icebreaker call (seen only by the matchmaker hosting it and erased when the call is done), and calls, which connect browser to browser and are never recorded. If you pay: the plan, amount, date and your transfer reference; we never see or store card numbers. Your IP address is used only in hashed form, to limit sign-in attempts and stop abuse.
3. How we use your information
To run Rishta: to show your profile to the members your settings allow, and to deliver interests, messages, photo requests and calls. Every member checks their ID before their profile goes live, and a person looks over every new profile, photos included, the same day. Staff can also open a member's file, photos included, to handle a report or help with their account, and every time a file is opened it is recorded against that staff member's name. To send you the emails you need: sign-in codes; emails about your payments and membership (a payment received, a card that did not go through, a cancellation, a refund), which always come because they are part of your membership; and notifications about things that need you, which you can turn off in Settings. Your mobile number is used to confirm that every member is a real person with a real phone, and so the Rishta team can reach you about your account or a report; it is never given to other members and never used for marketing. To keep members safe, through reports, blocks and limits on abuse. To meet our legal obligations. We do not sell your personal information, and we do not use it for advertising.
4. Decisions about you
Most decisions here are made by people. Two are automatic. When your ID check passes and nothing in it needs a closer look, your profile goes live straight away. When something does (a different age or gender on the ID than on the profile, a name that does not fit, the same ID or face on another account, or a main photo that does not look like the face on the ID), it is held until a person has looked. A person also looks over every new profile the same day. Matchmakers are people. Search is ordered by simple rules you can see, such as how complete a profile is or how recently someone was active, not by a hidden score. If you think a decision about you was wrong, email us and a person will look at it.
5. Data storage and security
Your data is stored in Cloudflare D1 and your photos in Cloudflare R2, in Cloudflare's Oceania region. Everything is encrypted in transit. We do not store identity documents or their photos: from your ID check we keep the result, the name, age and gender on the document, and a scrambled fingerprint of the document number, so that one ID cannot run two accounts. If you set a password, we keep only a scrambled version of it (a slow, salted hash) that cannot be turned back into your password. Sign-in codes sent to your email are kept only as a hash, and only for minutes. Photos are served only to people allowed to see them, and an enlarged photo carries the viewer's member ID. Delete your account in Settings and your profile, photos, messages and interests are deleted at once.
6. Who else handles your information
Cloudflare hosts the site, the database and your photos. Resend sends our emails, so it receives your email address and the email we send you. Didit sends the code that confirms your mobile, so it sees your number, and runs the ID check everyone does before going live, so it handles the photos of your document and your selfie, including a face match, which is biometric information. Didit does this outside Australia and New Zealand, under its own privacy policy, and our team never sees your document. It tells us the result and the name, age and gender on the ID. We use the face from your ID once, to compare it with your main photo, and we do not keep it. We delete the name, age and gender from the ID once a person has looked at your profile, and keep only a scrambled fingerprint of the document number, so we can spot the same document on two accounts. Didit keeps the check for the period set in our account with it, which we keep as short as we practically can, and when you delete your account we ask Didit to delete your check too. When your code goes by WhatsApp, WhatsApp (Meta) carries it. If you hire a matchmaker, they see your profile and your file, but never your messages with other members. We share identifiable personal data with nobody else, we do not sell it, and we do not share it for marketing.
7. Your rights
Under Australian and New Zealand privacy law, you have the right to: access the personal information we hold about you; correct it; have it deleted; and object to how it is used. You can delete your account yourself in Settings at any time. For anything else, email [email protected] and we will respond within 30 days.
8. Cookies
We use one essential cookie, to keep you signed in, and two small ones that only apply in some cases: one remembers whether you chose the Australia or New Zealand site, and one remembers the label on a link you arrived through, so we can count how people found us. Preferences such as day or night mode are kept in your browser, not sent to us. We use no advertising or cross-site tracking cookies. We count visits with Cloudflare Web Analytics. It sets no cookies, does not follow you from site to site and builds no profile of you; it tells us how many people opened which page, from which country, in which browser, and how fast the page loaded. See the Cookie Policy.
9. Children
Rishta is not intended for anyone under 18. We do not knowingly collect data from minors. If you believe a minor has created an account, contact us immediately and we will delete it.
10. Changes to this policy
We will email members before making material changes to this policy. Continued use after that constitutes acceptance.
11. Contact
Questions about this policy: [email protected]. For general enquiries: [email protected]. For complaints under the Australian Privacy Act, you may also contact the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au, and in New Zealand the Office of the Privacy Commissioner at privacy.org.nz.
Questions about your privacy?
Email us at [email protected] — we respond within 2 business days.