Security & Acceptable Use Policy

Effective Date: June 2025

1. Scope

This policy covers the Nidhi Arpan platform: the donor checkout, the organisation dashboard and point-of-collection tools, the collaborator and sponsor portals, and the internal staff console. It sits alongside our Terms of Use and Privacy Policy — where a security matter is also a privacy matter, the Privacy Policy governs how personal data is handled.

2. How your money moves

Donations and subscription payments are processed by our payment gateway partner. Card numbers, UPI credentials, CVVs and bank passwords are entered on the gateway, never on our servers, and we do not store them at any point.

  • Every online payment is confirmed against a signed gateway webhook before a receipt is issued — a receipt cannot be minted by a browser alone.
  • Cash collections are recorded against a named collector, reconciled at shift close, and require an admin sign-off PIN to settle.
  • Platform fees, GST and settlement splits are computed server-side from a single configured registry, never from values sent by the browser.
3. Access control

Access is role-based and enforced on the server for every request, not merely hidden in the interface.

  • Organisation accounts sign in with a mobile number and PIN; sensitive resets require a one-time password.
  • Within an organisation, owners, admins, volunteers and gate scanners each see and do only what their role allows.
  • Internal staff accounts require a second factor (TOTP) and are additionally restricted per module; the most destructive operations are reserved for a single root account.
  • Support staff cannot browse a tenant as themselves — assisted access is time-limited and written to an audit trail.
4. Audit trail and data integrity
  • Receipts are immutable once issued. A mistake is corrected by a recorded void or refund, never by silently editing history.
  • Administrative actions on tenant data — suspensions, verification decisions, configuration changes, assisted access — are logged with the actor and a before/after snapshot.
  • Donation and expense records are retained for the statutory period required by Indian tax law even after an account closes.
5. Data protection
  • All traffic is served over HTTPS. Data at rest sits in a managed Postgres service with row-level isolation between organisations.
  • Anti-fraud selfies and similar short-lived evidence are deleted automatically once their retention window expires.
  • Message content sent over WhatsApp or SMS is redacted in our internal logs, and phone numbers are masked in staff-facing tooling.
  • You may request export or deletion of your organisation’s data — see the Privacy Policy for the process and the statutory records we must keep.
6. Acceptable use

You agree not to use the platform to do any of the following. We may suspend an account immediately, without notice, where we reasonably believe one of these is happening.

  • Collect money for a cause, entity or purpose other than the one declared during registration and verification.
  • Issue tax-exemption receipts that the organisation is not legally entitled to issue.
  • Upload another party’s trademark, logo or likeness without permission, or content that is unlawful, hateful or obscene.
  • Probe, scan, load-test or attempt to bypass any authentication, rate limit or authorisation control.
  • Scrape donor records, resell platform data, or send unsolicited bulk messages to contacts you did not collect yourself.
  • Share staff or owner credentials, or use an automated agent to operate an account on your behalf.
7. Your responsibilities
  • Keep your PIN and one-time passwords private; we will never ask for either over a call, chat or email.
  • Remove team members promptly when they leave, and give each person their own login rather than a shared one.
  • Verify your organisation’s registration details and bank account before requesting settlement.
  • Tell us immediately if you suspect an account has been compromised.
8. Reporting a vulnerability

We welcome responsible disclosure. Email support@nidhiarpan.com with the affected URL, the steps to reproduce, and what an attacker could achieve. Please give us a reasonable window to fix the issue before disclosing it publicly, and do not access, alter or exfiltrate any data that is not your own while testing. We will acknowledge your report and keep you updated until it is resolved.

9. Incidents

If an incident affects your organisation’s data, we will notify the registered owner with what happened, what data was involved, what we have done, and what you should do — and we will notify the authorities where the law requires it.

10. Changes to this policy

We may update this policy as the platform changes. Material changes will be announced in-product to organisation owners. Continued use after an update means you accept the revised policy. Questions: support@nidhiarpan.com.