Privacy Policy
This document explains how Nidhi Arpan and the Registered Trusts on the platform collect, store, share, and protect the personal, financial, and technical data of devotees, donors, sponsors, and organizational users. It also enumerates every browser or device permission we request, mapped to the specific feature that requires it (see Section 12 · Permissions).
Google Play Data-Safety kit
Bulk-upload files auto-generated from this policy. Upload the CSV directly into the Play Console's Data Safety section, or use the Markdown answer-sheet to copy each field by hand. Refreshed on every deploy.
This Privacy Policy outlines how Nidhi Arpan (hereinafter referred to as “Platform”, “we”, “us”, or “our”) collects, processes, stores, shares, and protects personal, financial, and technical data. This policy applies to:
- Organizational Users: Trust administrators, trustees, mandal committee members, treasurers, and authorized counter/field volunteers.
- Devotees & Donors: Individuals making seva contributions, general donations, or purchasing event darshan/entry passes.
- Commercial Sponsors & Vendors: Businesses and advertisers contracting for physical or digital branding.
This Policy complies strictly with:
- The Digital Personal Data Protection Act, 2023 (DPDPA) of India.
- The Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.
- Relevant statutory provisions under the Income Tax Act governing donor reporting, certificate issuance, and statement filing.
- The Registered Trust / Organization (Mandal): Acts as the Data Fiduciary. The Trust determines the specific purpose and necessity for collecting contributions, seva bookings, devotee contact details, and statutory tax identifiers.
- Nidhi Arpan: Acts as the Data Processor and technology intermediary. Nidhi Arpan provides multi-tenant cloud software, Point-of-Sale (POS) synchronization, automated tax compliance formatting, and gate access verification infrastructure.
A. Devotee & Donor Information
- Contact & Identity Data: Full name, mobile phone number, email address, physical address, city, and pin code.
- Statutory Tax Identification: Permanent Account Number (PAN), collected exclusively when a donor requests a tax deduction receipt under Section 133 of the Income-tax Act, 2025 (formerly Section 80G of the 1961 Act).
- Transaction Metadata: Contribution amounts, payment modes (Cash, Online Dynamic UPI QR, Card POS, Net Banking), timestamps, seva/cause allocation, and unique transaction reference identifiers.
- Biometric Verification Media (Facial Photos): Facial photographs captured via native browser or device camera strictly for event ticketing, high-throughput VIP darshan passes, and gate access anti-fraud validation.
B. Organization & Administrator Data
- Legal Entity Details: Legal organization name, entity type (Trust, Society, Mandal, Samiti, Ashram), government registration number, Trust PAN card, Section 332 registration details (formerly Section 12A / 12AB), Section 133 approval certificates (formerly Section 80G), Foreign Contribution Regulation Act (FCRA) registration details (where applicable), and authorized signatory digital signatures.
- Settlement & Banking Information: Bank account numbers, IFSC codes, bank branch names, encrypted payout UPI IDs, and payment aggregator linked sub-account identifiers.
- User Accounts: Trustee and volunteer names, assigned administrative roles, mobile numbers, encrypted credentials, and shift activity logs.
C. Device Telemetry, Hardware & Local Storage Data
- Device Telemetry: Device form-factor classification (
isDesktop,isLaptop,isMobile,isTablet), browser specifications, IP address, and hardware camera interface status. - Push Notification Registration Data: When you tap Enable browser push, we store a Firebase Cloud Messaging (FCM) registration token and your user-agent string against your account so that server-side triggers (e.g., low-quota top-up nudges, sponsor payment confirmations, KYC status changes) can push instant alerts to that specific browser. Tokens are auto-purged on delivery failure and can be revoked at any time from your browser's site settings.
- Local Offline Cache: Encrypted local device storage and IndexedDB queues utilized by our Progressive Web App (PWA) to temporarily store cash records and cache ticket cryptographic payload hashes during cellular network congestion at festival grounds.
We process personal and sensitive data strictly for the following operational and statutory purposes:
- Transaction Processing & Digital Delivery: Recording seva donations, tracking cash collections, and instantly dispatching digital receipts and QR passes via SMS, WhatsApp, and secure web links.
- Statutory Tax Compliance: Compiling annual donor statements (Form 113 of the Income-tax Act, 2025 — formerly Form 10BD of the 1961 Act) and issuing formal tax deduction certificates (Form 114 — formerly Form 10BE) for submission by the Trust to the Income Tax Department of India.
- Event Ticketing & Anti-Fraud Verification: Mathematically verifying cryptographically signed QR tickets at physical gate scanners and performing visual facial matching against the primary ticket holder to eliminate ticket resale and unauthorized entry.
- Shift Auditing & Financial Integrity: Enabling organization treasurers and platform auditors to maintain immutable financial ledgers, blind-count cash reconciliations, and vendor expense approvals.
- Security & Abuse Prevention: Enforcing once-in-a-lifetime free trial quotas, preventing duplicate accounts via destination UPI uniqueness checks, and mitigating Sybil attacks.
Nidhi Arpan does not sell, rent, or trade personal information. Data is shared strictly under the following operational necessities:
- To the Respective Trust / Organization: Devotee details, donation amounts, and PAN records are shared with the specific Trust to which the donation was made.
- Payment Aggregators & Gateways: Transaction metadata and settlement split instructions are transmitted to authorized Reserve Bank of India (RBI) regulated payment aggregators (e.g., Razorpay) to execute digital payments and multi-tenant split settlements.
- Statutory Authorities: Aggregated donation filings containing donor PANs are formatted for submission to the Income Tax Department of India in accordance with statutory mandates.
- Telecommunications & Messaging Infrastructure: Phone numbers and dynamic link identifiers are processed via TRAI-compliant Distributed Ledger Technology (DLT) SMS routes (e.g., MSG91) and Meta Cloud API (WhatsApp) for transactional notices, OTPs, and receipt links.
- Push Notification Infrastructure: Registration tokens (issued by Google's Firebase Cloud Messaging) and short notification payloads (title, body, deep-link) are transmitted to Google's FCM edge to deliver browser push alerts. No donor personal data, PAN, banking details, or transaction amounts are ever placed in a push payload.
- Legal & Law Enforcement: Disclosures will be made when required by applicable law, court order, or authorized government agencies.
- To ensure zero disruption during network outages at crowded festival sites, the Platform utilizes browser-level IndexedDB and Service Workers to temporarily queue cash transactions and cache ticket cryptographic hashes.
- Offline data stored on local volunteer devices is encrypted at rest and automatically synchronized to the central database upon internet restoration.
- Volunteer logout workflows are blocked while unsynchronized records remain pending in local queues, ensuring complete transaction data integrity.
- Encryption Standards: All data in transit is encrypted using TLS 1.3. Sensitive database fields (such as banking records, PANs, and destination UPI IDs) are encrypted at rest using AES-256.
- Access Isolation: Role-Based Access Control (RBAC) and database-level Row-Level Security (RLS) isolate multi-tenant data. Volunteers can only access active shift operational data.
- Cryptographic QR Validation: QR ticket payloads are cryptographically signed using private HMAC/JWT keys, preventing payload forgery or off-platform ticket generation.
- General Account Information: Retained for the duration of the organization's active tenant relationship with Nidhi Arpan.
- Facial Verification Media: Captured photo verification media is retained strictly for the duration of the event lifecycle and necessary audit verification, after which it is archived or deleted.
- Statutory Financial Records (Non-Erasable): Under the Income Tax Act, the Prevention of Money Laundering Act (PMLA), and Indian accounting standards, financial audit ledgers, donation receipts, and donor PAN records must be retained for a mandatory statutory period (minimum 7 to 8 financial years). Requests for account closure or data erasure cannot override this statutory preservation requirement.
Subject to the statutory retention obligations detailed in Section 8, users and devotees may:
- Request an accessible summary of their personal data processed by the Platform.
- Request correction, completion, or updating of inaccurate personal data.
- Access grievance redressal mechanisms regarding data processing.
- Nominate an authorized individual to exercise data privacy rights in the event of death or incapacity.
Nidhi Arpan does not knowingly profile or collect personal data of minors under the age of 18 without parental or legal guardian consent (e.g., when a primary ticket holder acquires passes on behalf of family members).
We reserve the right to amend this Privacy Policy to reflect legal, regulatory, or technical changes. Material modifications will be notified through the platform dashboard or official communication channels.
Nidhi Arpan is delivered as a Progressive Web App (PWA) that runs inside your browser. We follow the principle of minimum-necessary access: no permission is requested speculatively, each prompt is fired strictly in response to a specific action you tap, and every permission can be revoked at any time from your browser or operating-system settings. The mapping below is the complete, exhaustive list of prompts the Platform can trigger.
A. Permissions we DO request (feature-by-feature mapping)
- Camera (
navigator.mediaDevices.getUserMedia) — Prompted only when a volunteer taps Capture Photo on the POS Entry-Passes panel, or when a devotee opens their self-serve entry-pass link. Used to attach a single facial photograph to the pass for gate-scan anti-fraud verification. We do not record video, we do not keep the camera stream open beyond the single capture, and no image is uploaded until you tap Confirm. - Notifications (Web Push / Firebase Cloud Messaging) — Prompted only when you tap Enable browser push on the
/notificationspage. Used to deliver operational alerts (receipt-quota top-up nudges, sponsor payment confirmations, KYC status changes, maker-checker approvals). We never use push for marketing or promotional content. - File Picker & Photo Storage (
<input type="file">) — Prompted when an admin taps Upload Logo on/settings/branding, Attach Bill Photo on/expenses, or Add Screenshot on/feedback. Used only to attach the single image you explicitly pick to the specific record you are editing. We do not browse or index your device's file system. - Biometric Sensor / Passkey (Web Authentication API — Fingerprint, Face ID, Windows Hello, Android biometrics) — Prompted only during passkey enrolment on
/settingsand later on the Fingerprint icon on/login. The biometric template itself never leaves your device— it is protected by your operating system's Secure Enclave / TEE. Only a device-bound public key (base64url) is stored on our server so we can verify future sign-ins. - Clipboard Write (
navigator.clipboard.writeText) — Fired when you tap a Copybutton (referral link, TOTPotpauth://URI, transaction reference, invoice ID). We only ever write the exact string shown on-screen; we never read your clipboard. - Bluetooth (
navigator.bluetooth.requestDevice, optional) — Prompted only when you tap Pair Printer in/settingsto connect a thermal-receipt printer over Bluetooth Low Energy. Skipping the pairing does not affect any core function of the Platform. - Service Worker & IndexedDB — Registered silently on first visit as part of PWA installation. Used for offline queueing of cash receipts at festival venues with no cellular signal, and for caching static assets for instant reload. No cache contents are uploaded off-device.
- Cookies & Local Storage — Set on first sign-in to maintain your Supabase authentication session (
sb-*cookies), your language / sidebar preferences, and offline-queue markers. We do not use ad-network cookies or third-party analytical trackers.
B. Permissions we do NOT request (for the avoidance of doubt)
- SMS Read / Receive (
RECEIVE_SMS,READ_SMS): OTPs are sent to your registered mobile and you type them in manually. We never auto-read incoming SMS. - Precise or Background Location (
ACCESS_FINE_LOCATION,ACCESS_BACKGROUND_LOCATION): We do not track device geolocation for any purpose. - Foreground Service (Android
FOREGROUND_SERVICE): The PWA does not run outside its browser tab. All offline sync happens through the Service Worker's own background lifecycle, not a persistent foreground service. - Microphone — no voice or audio capture, anywhere in the product.
- Contacts / Address Book — donor phone numbers are typed by the volunteer or the donor. We never read your device contacts.
- Calendar, Physical Activity, Health / Sensors, Nearby Devices, Call Log, Phone State — none of these are used or requested.
Every browser-native permission prompt is triggered on-tap and can be revoked at any time from your browser or OS settings. Revoking a permission only disables the corresponding feature; your account, receipts, and other data remain unaffected.
In accordance with the Information Technology Act, 2000 and the Digital Personal Data Protection Act, 2023, the details for the designated Grievance Officer are:
© 2026 Nidhi Arpan · Donations Simplified · Compliant with DPDP Act 2023 & IT Rules 2011

