Privacy Policy
Your privacy — especially around mental health — matters deeply to us. This policy explains what we collect, why, and the rights you have.
Last updated: 23 July 2026
Details still shown in square brackets, e.g. [CIN] or [Registered Office Address], are to be completed by Min Talks Private Limited. This template should be reviewed by a qualified Indian legal professional before it is relied upon.
This Privacy Policy describes how MinTalks (“MinTalks”, “we”, “us” or “our”), a brand operated by Min Talks Private Limited, a company incorporated under the laws of India (CIN: [CIN]), collects, uses, stores, discloses and protects your information when you use our website, applications and services (collectively, the “Platform”).
MinTalks operates as an aggregator / intermediary that connects individuals seeking psychological support (“Users”) with independent, licensed mental-health professionals (“Practitioners”). We are committed to handling your data in accordance with the Digital Personal Data Protection Act, 2023 (“DPDP Act”), the Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (“SPDI Rules”), and other applicable Indian laws.
By using the Platform, you consent to the practices described in this policy. If you do not agree, please do not use the Platform.
1. Who we are (Data Fiduciary)
For the purposes of the DPDP Act, MinTalks is the Data Fiduciary that determines the purpose and means of processing your personal data. Our contact details and Grievance Officer are set out at the end of this policy.
2. Information we collect
2.1 Information you provide
- Identity & contact data: name, email address, phone number, date of birth, gender, city/location.
- Account data: login credentials, profile preferences.
- Health & wellbeing data (sensitive personal data): information you share about your mental health, concerns, history, goals, intake questionnaire responses and session-related notes.
- Booking & communication data: appointments, messages with our care team, and feedback.
- Payment data: transaction amount, plan, and payment status. Card, UPI, netbanking and wallet details are collected and processed directly by our payment gateway (Razorpay) — see Section 6. We do not store your full card or banking credentials.
2.2 Information collected automatically
- Device and usage data — IP address, browser type, device identifiers, pages visited, and interaction data, collected via cookies and similar technologies (see Section 9).
2.3 Information from Practitioners
Practitioners may record limited session outcomes or scheduling information necessary to provide continuity of care.
3. How we use your information (Purposes)
- To create and manage your account and verify your identity.
- To match you with a suitable Practitioner and facilitate bookings and sessions.
- To process payments, invoices and refunds.
- To provide customer support and respond to your queries and grievances.
- To improve, personalise and secure the Platform, and to prevent fraud and misuse.
- To send service communications and, where you have consented, wellbeing tips and offers (you may opt out at any time).
- To comply with legal, regulatory and tax obligations.
4. Legal basis & consent
We process your personal data on the basis of your consent and, where applicable, for legitimate uses permitted under the DPDP Act. For sensitive personal data (including mental-health information), we rely on your explicit, informed consent obtained at the point of collection. You may withdraw your consent at any time (see Section 8); withdrawal will not affect processing carried out before withdrawal, and may limit our ability to provide certain services.
5. How we share your information
We do not sell your personal data. We share it only as follows:
- With your matched Practitioner, to enable assessment and therapy.
- With Razorpay, our payment gateway, to process transactions (see Section 6).
- With service providers / Data Processors (e.g. cloud hosting, communication, analytics) engaged under contractual confidentiality and security obligations.
- With legal and regulatory authorities, where required by law, court order, or to protect the rights, safety and security of Users, Practitioners or the public.
- On a business transfer (merger, acquisition), subject to this policy and applicable law.
6. Payments & Razorpay
Online payments on the Platform are processed by Razorpay Software Private Limited (“Razorpay”), a third-party payment aggregator authorised by the Reserve Bank of India. When you make a payment, your payment-instrument details (card, UPI, netbanking or wallet) are collected and handled directly by Razorpay over encrypted, PCI-DSS compliant infrastructure. MinTalks does not receive or store your full card number, CVV or banking passwords.
Your use of Razorpay is additionally governed by Razorpay’s own terms and privacy policy, available at razorpay.com/privacy. We recommend you review them.
7. Data security & retention
We implement reasonable security practices and procedures as required under the IT Act and SPDI Rules, including encryption in transit, access controls, and confidentiality obligations on staff and Practitioners. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.
We retain personal data only for as long as necessary to fulfil the purposes described here, or as required by law (for example, tax and accounting records). When no longer required, data is securely deleted or anonymised.
8. Your rights (Data Principal rights)
Subject to applicable law, you have the right to:
- Access a summary of the personal data we hold about you;
- Request correction, completion or updating of your data;
- Request erasure of your personal data;
- Withdraw consent previously given;
- Nominate another individual to exercise your rights in the event of death or incapacity;
- Grievance redressal (see below).
To exercise any of these rights, contact our Grievance Officer. We may need to verify your identity before acting on a request.
9. Cookies
We use essential cookies to operate the Platform and, with your consent, analytics cookies to understand usage. You can control cookies through your browser settings; disabling some cookies may affect functionality.
10. Children
The Platform is intended for individuals 18 years and older. We do not knowingly collect the data of children without verifiable parental/guardian consent as required under the DPDP Act. If you believe a minor has provided us data without such consent, please contact us for deletion.
11. Cross-border transfers
Where data is processed or stored outside India (e.g. by cloud providers), we take steps to ensure protection consistent with this policy and transfer only to the extent permitted under the DPDP Act and applicable Government notifications.
12. Confidentiality of mental-health information
Information shared during therapy is treated as confidential by Practitioners in line with professional ethics, and is disclosed only with your consent or where disclosure is required by law or necessary to prevent serious harm.
13. Changes to this policy
We may update this policy from time to time. Material changes will be notified on the Platform and, where appropriate, by email. Continued use after changes constitutes acceptance.
14. Grievance Officer & contact
In accordance with the DPDP Act and the Information Technology Act, 2000 (and rules thereunder), the contact details of our Grievance Officer / Data Protection point of contact are:
Grievance Officer / Data Protection Contact
- Name: [Grievance Officer Name]
- MinTalks, operated by Min Talks Private Limited
- [Registered Office Address, City, State, PIN], India
- Email: grievance@mintalks.in
- Phone: +91 91991 81881 · +91 94939 45432
- Hours: Monday–Friday, 10:00–18:00 IST
We aim to acknowledge grievances within 48 hours and resolve them within the timelines prescribed under applicable law.