Last updated: August 2026
Hustl ("Hustl", "we", "us") operates a gig marketplace connecting independent workers ("Hustlers") with businesses ("Partners") for short-term work in India. We are the Data Fiduciary for personal data processed through our website, progressive web apps (PWA), and future native iOS and Android applications.
Registered entity: Hustl (operating at hustl.today). Grievance / privacy contact: privacy@hustl.today. General support: support@hustl.today.
This policy applies only to users who are 18 years or older and who reside in India. Our services are not offered outside India.
Under the Digital Personal Data Protection Act, 2023 (DPDPA) and the Digital Personal Data Protection Rules, 2025 (Rule 3), we provide this itemised description of personal data we collect and why.
Purpose: account creation, authentication, profile display, referrals, customer support, and fraud prevention.
Purpose: confirming who you are before your account goes live, platform trust, payout eligibility, and regulatory compliance.
How this check is actually carried out. Verification is manual. A member of the Hustl team looks at the documents you submit and records the outcome. We do not use an external identity-verification provider, Aadhaar eKYC, automated PAN verification, a face-match or liveness check, or a background check. Nothing you submit is sent to a verification vendor. Because there is no eKYC step, your Aadhaar number is stored in full in our restricted internal records rather than as a masked or tokenised reference, and your document images are held in access-controlled storage. If we later connect an external verification provider or introduce automated checks, we will update this policy and give notice before that processing starts.
A Partner business GSTIN is optional. Our software contains an optional lookup of a GSTIN against the public GST registry through MasterGST, but that lookup is not enabled during the public beta: no GSTIN is sent to MasterGST today. A GSTIN a Partner supplies is checked for valid format by our own software and is then reviewed by the Hustl team by hand, along with the other business documents. If we enable the registry lookup, we will say so on this page and list MasterGST in section 5 before any GSTIN is sent to it.
Purpose: job funding, hustler payouts, reconciliation, tax reporting support, and dispute resolution.
How money actually moves today. No payment gateway is connected to Hustl. Verified Partners post shifts using free beta credits, so we do not collect card, netbanking or other payment-instrument details from Partners in order to take payment from them. Hustler payouts are released manually by the Hustl team to the UPI ID saved on your profile, after you complete a shift and submit your shift rating. If we connect a payment or payout provider in future, we will update this policy and the list in section 5 before any of your data is shared with it.
Purpose: attendance records, partner visibility during active jobs, safety, routing/ETA assistance, and dispute evidence. Live location is shared only with authorised parties for the active booking (Partner, support, admin), and only while you are checked in to a shift or during one of three limited windows: a short pre-shift window you have confirmed, a window requested by a Hustl admin on an active booking, and when you trigger SOS. This matches section 3 of our Safety Policy.
Purpose: security, session management, push delivery, debugging, and fraud detection.
Purpose: operating the marketplace, safety, moderation, and customer support.
We process personal data only for lawful purposes connected to our platform, including:
We use service providers (Data Processors) under contracts requiring reasonable security safeguards:
SMS/OTP for login is delivered through Firebase Phone Authentication (Google). We may add transactional SMS providers (e.g. MSG91) in the future with updated notice.
Disclosed, but not receiving your data today. The following are built into our software but are switched off during the public beta. We list them so you can see what is present in the system, not because they are processing anything. If we enable one, we will move it into the list above and give notice first.
Providers we do not use. No identity-verification provider, no payment gateway and no payout settlement provider receives your personal data from Hustl today. Earlier versions of this policy named Digio for KYC, Razorpay for Partner payments and Cashfree for payouts. None of those integrations is live, none of them processes your data, and they have been removed from the list above. Identity documents are reviewed by the Hustl team, and payouts are released by the Hustl team.
What the manual payout involves. Because payouts are released by hand rather than by a settlement provider, a member of the Hustl team enters the UPI ID saved on your profile, and the amount owed, into the banking or UPI application used to send the transfer. Your UPI ID and the transfer amount are therefore visible to that banking provider and to the UPI network, in the same way as any ordinary UPI payment made to you. No other personal data is passed with the transfer.
See our Data Compliance and Cookies page for more detail.
While your account is active, we retain the data needed to operate it, complete shifts and payments, provide support, prevent misuse, and meet specific legal duties. An accepted account-deletion request starts a 30-day recovery period followed by a scheduled purge. We do not apply one blanket retention period to every record: after purge, only scoped records that have a documented tax, accounting, settlement, dispute, fraud-prevention, security, or legal-hold purpose remain. Your rights under section 9 are unaffected.
How account deletion works. When you or we close an account, normal access is blocked and the account is held in a recoverable state for 30 days. During that period, signing in with the registered phone number opens a restore-only screen. At the deadline, the account becomes eligible for permanent purge: personal account data is removed or pseudonymized, and private document images and unrelated files are deleted. Public profile media, push tokens, sessions, live-location data, and presence are removed or revoked at the appropriate lifecycle step. Only the narrowly required records described above remain. Separately, if you verify a phone number but never finish signing up, and the incomplete account holds no identity number, no completed verification, no bookings and no earnings, it is deleted 7 days after it was created.
Corrections to earlier versions of this policy. Earlier versions said that raw Aadhaar document images would be deleted within 30 days of successful verification, that KYC documents would be kept for up to 5 years after account closure, and that we did not store full Aadhaar numbers after verification. Those statements did not describe the earlier system. We store the Aadhaar number and card photograph unmasked while an account is active; the account deletion lifecycle now removes them after the 30-day recovery period unless the scoped exception above applies. This correction does not remove your right to ask us to erase data under section 9.
This will change when identity verification changes. Hustl is in public beta and verification is done by our own team. If we later introduce an external identity verification provider, what we collect, what that provider holds instead of us, and how long any of it is kept will all change. We will update this section and notify you as described in section 1 before that happens.
Almost all personal data is stored in India, on Google Cloud Platform in the asia-south1 (Mumbai) region. That includes your account record, identity documents, wallet and transaction records, bookings, chat and support history.
There is one exception, and we want to be plain about it rather than claim a blanket India-only guarantee. The live-location channel runs on Firebase Realtime Database in the asia-southeast1 (Singapore) region, because that product is not offered in an Indian region. So while you are checked in to a shift, or during one of the limited windows described in section 2.4, the live coordinates carried on that channel are processed outside India. No other category of personal data is sent there. Apart from this channel, we do not intentionally transfer personal data outside India for processing. If we move this channel into an Indian region, we will update this section.
As a Data Principal, you may:
To exercise rights, email privacy@hustl.today from your registered phone or email. We will verify your identity before fulfilling requests. We aim to respond within 30 days. You can also use the in-app deletion flow or the signed-out account-deletion page.
We may introduce the following with updated notice in-app and on this page:
Hustl has no listing on the Apple App Store or Google Play. This section is not a description of a published app. It is the data disclosure we have prepared ahead of a future native iOS and Android release, published here in advance so that it can be compared with what we actually collect. If and when we submit those apps, we expect to declare the following categories to Apple and Google:
Hustl does not use your data to track you across other companies' apps or websites.
If a personal data breach is likely to affect your rights, we will notify the Data Protection Board of India and affected users as required under the DPDPA, including steps taken to mitigate harm.
We may update this policy. Material changes will be communicated via the app, email, or website. Continued use after the effective date constitutes acceptance. Previous versions are available on request.
Terms of Service · Data Compliance · Intellectual Property and Takedown · Safety Policy · Account Deletion