Privacy Policy

Shree Samast Bargam Samaj Unjha
Website: https://bargamsamajunjha.com
Last updated: 8 June 2026  ·  Effective date: 8 June 2026

1. Who we are

Shree Bar Gam Samaj, a registered trust ("Samaj", "we", "us", "our"), operates a non-commercial, community-run membership platform for the Bargam KP Samaj community under the name Shree Samast Bargam Samaj Unjha. The platform maintains a member directory and provides related community services through our website at https://bargamsamajunjha.com and our Android application.

  • Legal entity: Shree Bar Gam Samaj, a registered trust. The platform operates publicly under the name "Shree Samast Bargam Samaj Unjha".
  • Registered / operating address: 3rd Floor, Shoolin Square, Visnagar Road, Unjha, Mehsana – 384170, Gujarat, India
  • Email: [email protected]
  • Phone: +91 63593 24365

For the purposes of the Digital Personal Data Protection Act, 2023 ("DPDP Act") and the Digital Personal Data Protection Rules, 2025 ("DPDP Rules"), the Samaj is the Data Fiduciary that decides why and how your personal data is processed. Where this policy refers to "you" or a "Data Principal", it means the individual whose personal data we process.

This platform is intended only for members of the Bargam KP Samaj community. It is not a public social network or a commercial service.

2. Scope of this policy

This policy explains what personal data we collect, why, who can see it, how long we keep it, the third parties who help us run the service, and the rights you have. It applies to the website, the member portal, the admin panel, and the Android application (a wrapped version of the same website).

It does not cover any external website you reach via a link from our platform, or the independent practices of the third-party service providers listed in Section 9 (each of whom has its own privacy policy).

3. The personal data we collect

We collect the following categories of personal data. Many fields are optional; the data you provide depends on how complete you choose to make your profile.

Identity and personal details: name (first, middle, last), gender, date of birth, blood group, complexion, height, weight, marital status, native place within the community, hobbies, goals, and (where culturally relevant) post-marriage family-name details.

Contact details: mobile number, alternate mobile number, email address.

Address details: home and work address, area, city, district, taluka, state, country, PIN code, and landline/fax where provided.

Education and profession: qualification, education details, school and college/university names, medium of instruction, profession, and profession details.

Family information: the relationship links between a head-of-family member and the family members (spouse, children, parents, siblings) recorded under that account, and which community branch you belong to.

Photographs: a profile photo and up to ten additional gallery ("portfolio") photos. These typically show the member's face. We do not perform facial recognition or any biometric inference on these images.

Account and authentication data: your username (usually your mobile or email), a securely hashed password, verification status, and login timestamps.

Welfare-scheme data: when you apply for a community welfare scheme, the information in your application and any supporting documents you upload (which may include income, education, or identity documents). See Section 13.

Activity and technical data: a history of changes made to your record (what changed, when, and by whom), search queries you run in the directory, suggestions/feedback you submit, OTP and message delivery logs, and standard server/security logs (IP address, timestamps, and partial request information).

Children's data. A head-of-family member may register family members who are minors (under 18), including their name, date of birth, community, and relationship. By registering a minor, the head-of-family member confirms they are the minor's parent or lawful guardian and consents on the minor's behalf. We do not direct any tracking or advertising at children.

4. Sensitive personal data

Some of the data above may be treated as sensitive or as carrying special significance, including:

  • Photographs showing identifiable faces.
  • Community / sub-community association — the very existence of an account on this platform indicates membership of a specific community.
  • Health-related fields such as blood group, height, weight, and complexion.
  • Marital and family status.

We collect these only with your participation, use them solely for the community-directory and matchmaking purposes described in Section 5, and apply the access controls described in Section 8.

5. Why we process your data (purposes)

We process personal data only for the following purposes:

  1. Account creation and authentication, including OTP-based identity verification.
  2. Maintaining the community member directory, so approved members can find one another across the communities on the platform.
  3. Facilitating matchmaking, by surfacing unmarried members against filters such as community, native place, age, gender, and marital status.
  4. Managing family relationships recorded under a head-of-family member's account.
  5. Community administration, so branch admins can keep their roster accurate.
  6. Accountability and dispute resolution, by keeping an audit history of changes to each record.
  7. Processing welfare-scheme applications.
  8. Sending transactional communications (Section 7).
  9. Maintaining security and operational logs.

We rely on your consent (given at registration and when you provide optional data or upload documents) and, where applicable, on the legitimate uses permitted under the DPDP Act for running a member-requested community service. You may withdraw consent as described in Section 11.

We do not: display third-party advertising; sell, rent, or lend your data; use your data for marketing or profiling against external services; or perform facial recognition or other biometric inference.

6. How you become a member, and consent

You join either by self-registering (you enter a mobile/email, verify an OTP, complete your profile, and an admin approves it) or by being added directly by a community admin. A head-of-family member can add family members, who do not log in themselves.

At registration you will be asked to confirm that you have read and agree to this Privacy Policy and our Terms and Conditions. By submitting another member's information (for example, a family member's), you confirm you are authorised to do so and, in the case of a minor, that you are their parent or lawful guardian.

7. Communications we send you

All messages we send are transactional — tied to an action by you or an admin. We do not run a marketing newsletter or send promotional messages.

  • SMS / WhatsApp: one-time passwords for registration, login, and password reset (delivered via MSG91; WhatsApp delivery is an option you choose).
  • Email: OTPs, password-reset links, account approval/rejection notices, and welfare-scheme application confirmations.

WhatsApp is offered only as an alternative OTP channel that you actively select.

8. Who can see your data

Visibility is controlled by role:

  • Public visitors (no login): can see community totals (no individual data), the public trustees list, public events, scheme descriptions, and a small homepage preview of recently-updated unmarried members showing first name, last name, community, and photo — limited to males aged 21+ and females aged 18+. Minors are never shown in this preview.
  • Logged-in (approved) members: can view their own full profile and family members, and can browse other approved members across all communities on the platform, including the contact details on those profiles. Unapproved, rejected, and deleted profiles are not shown.
  • Community Admins: can manage members of their own community branch only.
  • Super Admin: has full access across all communities for administration.

9. Third parties who process data for us

We use the following service providers ("Data Processors"), each bound to process data only on our instructions:

  • Amazon Web Services (AWS) — hosting of the application, database, and a private storage bucket for photos and documents. Region: Mumbai, India (ap-south-1).
  • Cloudflare — security, DDoS protection, and request proxying at the network edge.
  • MSG91 — delivery of SMS, WhatsApp, and email one-time passwords (India-based).
  • Hostinger — outbound transactional email delivery.

A legacy database from our previous system is being read one-way into the current platform during a transition period and will be decommissioned; no data flows back to it.

10. Where your data is stored, and cross-border transfers

Your data is stored primarily in India — the database, photos, and uploaded documents all reside in AWS's Mumbai (ap-south-1) region, and OTPs are sent via an India-based provider.

Some routine routing may cross borders:

  • Cloudflare processes requests at the network edge location nearest the visitor before forwarding them to our India-based servers; only static assets (such as images and stylesheets) are cached at the edge, and no personal data is stored there.
  • Email may transit our email provider's globally distributed infrastructure in transit.
  • WhatsApp OTPs are delivered through the WhatsApp Business platform operated by Meta, which may route messages through infrastructure outside India.

11. Your rights

Subject to the DPDP Act, you have the right to:

  • Access the personal data we hold about you.
  • Correct, complete, or update your data.
  • Erase your data where it is no longer needed for the purpose it was collected.
  • Withdraw consent you previously gave.
  • Nominate another individual to exercise your rights in the event of death or incapacity. To register a nomination, please contact our Grievance Officer (Section 16).
  • Grievance redressal — raise a complaint and receive a response within a reasonable, defined time.

You can already do much of this yourself in the member portal: view your profile, edit most fields, add or remove family members, delete your profile and gallery photos, change your password, view your activity history, and withdraw a pending scheme application.

For anything not yet available as a self-service feature — including obtaining a downloadable copy of all your data, or permanent deletion of your entire account — please contact our grievance officer (Section 16). We will action verified requests within 15 days of receiving them.

12. How long we keep your data

  • Active accounts: retained while your account remains active.
  • Deactivated/deleted accounts: when an account is removed, it is hidden from all views and can no longer log in, and the associated profile and gallery photos are deleted from storage immediately. The underlying record is then retained for 3 years, after which it is permanently deleted. (Limited audit-history entries may be retained beyond this period for accountability, as described below.)
  • Audit history (the log of changes to a record): retained for accountability and dispute-resolution purposes, including after an account is deactivated.
  • One-time passwords: held briefly in session and expire within about 10 minutes; not stored long-term.
  • Server and sync logs: rotated and retained for roughly 14 days.
  • Welfare-scheme applications and documents: rejected applications and their uploaded documents are permanently deleted 1 year after the decision. Approved applications and their documents are retained for as long as the member's account is active, and are permanently deleted when the member's account is purged (3 years after deactivation).

13. Welfare schemes

When you apply for a community welfare scheme, we collect your application details and any supporting documents you upload (which may include income certificates, marksheets, or identity documents). These are stored in our private India-based storage and are reviewed only by the Super Admin for approval. You can withdraw a pending application yourself. Rejected applications and their documents are deleted one year after the decision; approved applications and their documents are retained for as long as the member's account is active, and are permanently deleted when the member's account is purged (see Section 12).

14. Cookies and similar technologies

We use only strictly-necessary and functional cookies and storage — for security (CSRF protection, Cloudflare bot management), to keep you logged in, to remember your login identifier if you choose "Remember me", and to detect whether you are using the mobile app or the website. We do not use third-party tracking or analytics cookies, and we do not run any third-party analytics or advertising trackers.

15. How we protect your data

We apply reasonable security safeguards, including: encrypted connections (HTTPS) enforced across the site; a private, access-controlled storage bucket with time-limited links for reading photos and documents; password hashing using bcrypt — passwords are stored only in hashed form and cannot be read in plain text by anyone, including administrators; role-based access control with per-request re-verification; strict scoping of community admins to their own branch; rate limiting on logins, OTPs, uploads, and searches; a network firewall and intrusion-prevention on our servers; and a web application firewall and DDoS protection at the edge.

No system is perfectly secure, and we cannot guarantee absolute security; however, we work to protect your data and to address any vulnerability promptly. In the event of a personal data breach, we will notify the Data Protection Board of India and affected individuals as required by the DPDP Rules.

16. Grievance officer / contact

If you have a question, request, or complaint about your personal data, contact:

  • Grievance Officer: Bhadresh Patel
  • Email: [email protected]
  • Phone: +91 99253 99100
  • Address: 3rd Floor, Shoolin Square, Visnagar Road, Unjha, Mehsana – 384170, Gujarat, India

If you are not satisfied with our response, you may escalate to the Data Protection Board of India.

17. Changes to this policy

We may update this policy from time to time. The "Last updated" date at the top reflects the latest version, and material changes will be communicated to members through the platform.


See also our Terms and Conditions.