Back to Hustl

Privacy Policy

Last updated: August 2026

1. Who we are

Hustl ("Hustl", "we", "us") operates a gig marketplace connecting independent workers ("Hustlers") with businesses ("Partners") for short-term work in India. We are the Data Fiduciary for personal data processed through our website, progressive web apps (PWA), and future native iOS and Android applications.

Registered entity: Hustl (operating at hustl.today). Grievance / privacy contact: privacy@hustl.today. General support: support@hustl.today.

This policy applies only to users who are 18 years or older and who reside in India. Our services are not offered outside India.

2. Personal data we collect (itemised)

Under the Digital Personal Data Protection Act, 2023 (DPDPA) and the Digital Personal Data Protection Rules, 2025 (Rule 3), we provide this itemised description of personal data we collect and why.

2.1 Identity and account

  • Mobile phone number (Firebase Authentication OTP sign-in)
  • Email address (optional, where provided)
  • Display name, profile photo, cover photo, bio
  • Role (Hustler or Partner), language preference (English, Tamil, Hindi)
  • Referral code and referrer reference

Purpose: account creation, authentication, profile display, referrals, customer support, and fraud prevention.

2.2 Identity documents and verification

  • Your Aadhaar number, in full and unmasked, and a photograph of your Aadhaar card. Both are required to complete signup.
  • PAN and other government identity document images, where we ask you for them
  • A selfie photograph, if you choose to attach one when you submit your documents (optional)
  • The review outcome a member of the Hustl team records against each document (pending, verified or rejected) and any reason given for a rejection
  • Partner business GSTIN, FSSAI or trade licence references, and verification documents

Purpose: confirming who you are before your account goes live, platform trust, payout eligibility, and regulatory compliance.

How this check is actually carried out. Verification is manual. A member of the Hustl team looks at the documents you submit and records the outcome. We do not use an external identity-verification provider, Aadhaar eKYC, automated PAN verification, a face-match or liveness check, or a background check. Nothing you submit is sent to a verification vendor. Because there is no eKYC step, your Aadhaar number is stored in full in our restricted internal records rather than as a masked or tokenised reference, and your document images are held in access-controlled storage. If we later connect an external verification provider or introduce automated checks, we will update this policy and give notice before that processing starts.

A Partner business GSTIN is optional. Our software contains an optional lookup of a GSTIN against the public GST registry through MasterGST, but that lookup is not enabled during the public beta: no GSTIN is sent to MasterGST today. A GSTIN a Partner supplies is checked for valid format by our own software and is then reviewed by the Hustl team by hand, along with the other business documents. If we enable the registry lookup, we will say so on this page and list MasterGST in section 5 before any GSTIN is sent to it.

2.3 Financial and payouts

  • Wallet balances, ledger entries, earnings, withdrawals, fees, and penalties
  • UPI ID and/or bank account number and IFSC for payouts
  • Partner beta credit balances and the record of credits granted, spent and refunded
  • TDS-related transaction records where applicable

Purpose: job funding, hustler payouts, reconciliation, tax reporting support, and dispute resolution.

How money actually moves today. No payment gateway is connected to Hustl. Verified Partners post shifts using free beta credits, so we do not collect card, netbanking or other payment-instrument details from Partners in order to take payment from them. Hustler payouts are released manually by the Hustl team to the UPI ID saved on your profile, after you complete a shift and submit your shift rating. If we connect a payment or payout provider in future, we will update this policy and the list in section 5 before any of your data is shared with it.

2.4 Location data

  • GPS coordinates at check-in and check-out
  • Live GPS (latitude, longitude, accuracy, heading, speed) during active checked-in shifts, updated approximately every 10 seconds
  • Job and business addresses
  • SOS alert location when a Hustler triggers emergency assistance
  • Approximate city, region, and country derived from IP address (hashed IP stored separately)

Purpose: attendance records, partner visibility during active jobs, safety, routing/ETA assistance, and dispute evidence. Live location is shared only with authorised parties for the active booking (Partner, support, admin), and only while you are checked in to a shift or during one of three limited windows: a short pre-shift window you have confirmed, a window requested by a Hustl admin on an active booking, and when you trigger SOS. This matches section 3 of our Safety Policy.

2.5 Device, session, and technical data

  • Browser or app user agent, screen resolution, timezone, locale
  • Push notification permission state and FCM device tokens
  • Location permission state (not continuous location until you grant OS permission)
  • PWA install indicator
  • Hashed IP address and hashed user agent in session records
  • App version and platform (web, iOS, Android when launched)

Purpose: security, session management, push delivery, debugging, and fraud detection.

2.6 Behavioural and communications

  • Job bookings, cancellations, check-in/out photos, reviews, strikes
  • In-app chat messages and support conversations
  • Dispute records and evidence
  • Activity events (e.g. login, booking, payment events) without raw IP in default activity payloads
  • Saved jobs and notification preferences (where enabled)

Purpose: operating the marketplace, safety, moderation, and customer support.

3. How we use your data

We process personal data only for lawful purposes connected to our platform, including:

  • Providing and improving the Hustl service
  • Matching Hustlers with Partner job postings
  • Processing payments and payouts
  • Sharing limited profile and live location data with the other party during an active job
  • Preventing fraud, GPS spoofing, duplicate accounts, and abuse
  • Resolving disputes using objective evidence (GPS, photos, chat, timestamps)
  • Complying with Indian law, tax, and lawful government requests
  • Sending transactional notifications (booking updates, payout status, security alerts)

4. What we do not do with your data

  • We do not sell your personal data to data brokers or advertisers.
  • We do not use Google Analytics, Meta Pixel, or other cross-site advertising trackers.
  • We do not track you across other companies' apps or websites for advertising.
  • We do not knowingly collect data from anyone under 18.

5. Third parties who process data on our behalf

We use service providers (Data Processors) under contracts requiring reasonable security safeguards:

  • Google Cloud / Firebase, authentication, database, file storage, realtime location channel, push messaging, App Check (reCAPTCHA Enterprise), Maps APIs (India region infrastructure)
  • Sentry, error monitoring (user ID and role only; email and IP stripped before transmission)
  • Vercel, hosting and privacy-friendly page analytics (Web Vitals; no ad profiling)

SMS/OTP for login is delivered through Firebase Phone Authentication (Google). We may add transactional SMS providers (e.g. MSG91) in the future with updated notice.

Disclosed, but not receiving your data today. The following are built into our software but are switched off during the public beta. We list them so you can see what is present in the system, not because they are processing anything. If we enable one, we will move it into the list above and give notice first.

  • MasterGST, optional GSTIN lookup against the public GST registry for Partner businesses. Not enabled; no GSTIN is sent to MasterGST today, and GSTINs are reviewed by the Hustl team by hand.
  • Slack, optional internal operational alerts to the Hustl team. Not enabled; and it would never be used to market to you.

Providers we do not use. No identity-verification provider, no payment gateway and no payout settlement provider receives your personal data from Hustl today. Earlier versions of this policy named Digio for KYC, Razorpay for Partner payments and Cashfree for payouts. None of those integrations is live, none of them processes your data, and they have been removed from the list above. Identity documents are reviewed by the Hustl team, and payouts are released by the Hustl team.

What the manual payout involves. Because payouts are released by hand rather than by a settlement provider, a member of the Hustl team enters the UPI ID saved on your profile, and the amount owed, into the banking or UPI application used to send the transfer. Your UPI ID and the transfer amount are therefore visible to that banking provider and to the UPI network, in the same way as any ordinary UPI payment made to you. No other personal data is passed with the transfer.

6. Cookies and similar technologies

  • Firebase Auth session, required to keep you signed in.
  • reCAPTCHA / App Check, bot and abuse protection.
  • Vercel Analytics, aggregated performance metrics on our web apps; not used for cross-site advertising.
  • Local browser storage, preferences and session navigation on PWA (not sold or shared).

See our Data Compliance and Cookies page for more detail.

7. Data retention

While your account is active, we retain the data needed to operate it, complete shifts and payments, provide support, prevent misuse, and meet specific legal duties. An accepted account-deletion request starts a 30-day recovery period followed by a scheduled purge. We do not apply one blanket retention period to every record: after purge, only scoped records that have a documented tax, accounting, settlement, dispute, fraud-prevention, security, or legal-hold purpose remain. Your rights under section 9 are unaffected.

  • Identity documents, including your Aadhaar number, your Aadhaar card photograph and any PAN, other ID or selfie image: kept while your account exists and during the 30-day recovery period. Verification is a manual review by our team. These records and files are included in the post-deadline purge unless a documented legal or security purpose requires a specific item to remain for longer.
  • Financial and transaction records: retained beyond account purge only to the extent needed for tax, accounting, settlement, dispute, fraud-prevention, or legal obligations. Where GST records apply, the statutory basis is 72 months from the due date of the relevant annual return, extended for an active proceeding when required. Retained records are disconnected from the live account identifier where possible; Hustl does not retain all account data for 72 months by default.
  • Activity logs, chat messages, location records and session or device metadata: kept while your account exists where needed to operate the service. At account purge they are removed or pseudonymized unless a specific legal, resolved-dispute, fraud-prevention, or security obligation requires a scoped record.

How account deletion works. When you or we close an account, normal access is blocked and the account is held in a recoverable state for 30 days. During that period, signing in with the registered phone number opens a restore-only screen. At the deadline, the account becomes eligible for permanent purge: personal account data is removed or pseudonymized, and private document images and unrelated files are deleted. Public profile media, push tokens, sessions, live-location data, and presence are removed or revoked at the appropriate lifecycle step. Only the narrowly required records described above remain. Separately, if you verify a phone number but never finish signing up, and the incomplete account holds no identity number, no completed verification, no bookings and no earnings, it is deleted 7 days after it was created.

Corrections to earlier versions of this policy. Earlier versions said that raw Aadhaar document images would be deleted within 30 days of successful verification, that KYC documents would be kept for up to 5 years after account closure, and that we did not store full Aadhaar numbers after verification. Those statements did not describe the earlier system. We store the Aadhaar number and card photograph unmasked while an account is active; the account deletion lifecycle now removes them after the 30-day recovery period unless the scoped exception above applies. This correction does not remove your right to ask us to erase data under section 9.

This will change when identity verification changes. Hustl is in public beta and verification is done by our own team. If we later introduce an external identity verification provider, what we collect, what that provider holds instead of us, and how long any of it is kept will all change. We will update this section and notify you as described in section 1 before that happens.

8. Data storage and security

Almost all personal data is stored in India, on Google Cloud Platform in the asia-south1 (Mumbai) region. That includes your account record, identity documents, wallet and transaction records, bookings, chat and support history.

There is one exception, and we want to be plain about it rather than claim a blanket India-only guarantee. The live-location channel runs on Firebase Realtime Database in the asia-southeast1 (Singapore) region, because that product is not offered in an Indian region. So while you are checked in to a shift, or during one of the limited windows described in section 2.4, the live coordinates carried on that channel are processed outside India. No other category of personal data is sent there. Apart from this channel, we do not intentionally transfer personal data outside India for processing. If we move this channel into an Indian region, we will update this section.

  • Encryption in transit (TLS 1.2+)
  • Encryption at rest on cloud infrastructure
  • Role-based access controls and Firestore security rules
  • Server-side-only money and verification-status mutations
  • Rate limiting, App Check, admin MFA for internal tools
  • PII minimisation in logs and error reports

9. Your rights under the DPDPA

As a Data Principal, you may:

  • Access a summary of personal data we hold about you
  • Correct inaccurate data
  • Erase data when no longer required (subject to legal retention)
  • Withdraw consent for consent-based processing (with comparable ease to giving consent)
  • Nominate another individual to exercise rights on your behalf in case of death or incapacity
  • Grievance redressal through our Grievance Officer
  • Complaint to the Data Protection Board of India if not satisfied with our response

To exercise rights, email privacy@hustl.today from your registered phone or email. We will verify your identity before fulfilling requests. We aim to respond within 30 days. You can also use the in-app deletion flow or the signed-out account-deletion page.

10. Planned features (transparent disclosure)

We may introduce the following with updated notice in-app and on this page:

  • Automated identity verification through an external provider, which could include document checks, a face match against a photograph you submit, or periodic re-verification before selected shifts. No such provider is engaged today, and none receives your data. We would name the provider in section 5 and give notice before any of your data reached it.
  • A payment gateway or payout settlement provider, replacing the manual credit and manual UPI release described in sections 2.3 and 5. We would name the provider in section 5 and give notice before any of your data reached it.
  • Native iOS and Android applications, published on the Apple App Store and Google Play. Neither listing exists today; the current Hustl apps are the web apps at app.hustl.today and partner.hustl.today.
  • Device integrity signals for fraud prevention (not used for advertising)
  • Biometric unlock on your device only (stored locally on your phone; not uploaded to Hustl servers)
  • Marketing SMS, WhatsApp, or email only with separate opt-in consent
  • Partner subscription plans with billing disclosures per Consumer Protection (E-Commerce) Rules

11. Disclosures prepared in advance for a future app store submission

Hustl has no listing on the Apple App Store or Google Play. This section is not a description of a published app. It is the data disclosure we have prepared ahead of a future native iOS and Android release, published here in advance so that it can be compared with what we actually collect. If and when we submit those apps, we expect to declare the following categories to Apple and Google:

  • Contact info: phone, email, linked to identity, not used for tracking
  • Financial info: payment and payout metadata, linked to identity, not used for tracking
  • Location: precise location during active jobs, linked to identity, not used for tracking across apps
  • Photos/Videos: profile, identity documents, check-in evidence, linked to identity
  • Identifiers: user ID, device tokens for push, linked to identity, not used for third-party advertising
  • Usage/Diagnostics: crash and performance data via Sentry and Vercel Analytics, not sold

Hustl does not use your data to track you across other companies' apps or websites.

12. Data breach notification

If a personal data breach is likely to affect your rights, we will notify the Data Protection Board of India and affected users as required under the DPDPA, including steps taken to mitigate harm.

13. Changes to this policy

We may update this policy. Material changes will be communicated via the app, email, or website. Continued use after the effective date constitutes acceptance. Previous versions are available on request.

14. Related policies

Terms of Service · Data Compliance · Intellectual Property and Takedown · Safety Policy · Account Deletion