Skip to main content

Data Practices

A transparent guide to how your data and external integrations are handled on Sangathan.

Storage & Isolation

Your data is stored in encrypted PostgreSQL database clusters. Every row of data created is tagged with your Organisation ID. Our database engine enforces strict Row-Level Security (RLS), meaning it is technically impossible for a query from Organisation A to return data from Organisation B.

Google API Integrations & Limited Use

Sangathan offers optional integrations with Google Contacts, Sheets, Forms, and Calendar solely to streamline member invitations, survey migration, and meeting coordination.

  • Explicit Consent & On-Demand: We only access Google data when you explicitly trigger an import or calendar sync action.
  • Strict Limited Use: Our use of Google user data adheres strictly to the Google API Services User Data Policy.
  • Zero Advertising & No Data Sales: Google user data is never sold, shared with data brokers, or used for advertising/profiling.
  • 1-Click Revocation: You can disconnect your Google account anytime via Google Account Permissions or Sangathan settings.

Retention & Deletion

We keep your data only as long as your account and collective workspace remain active.

  • Active Workspaces: Data is retained for ongoing operations.
  • Deleted Workspaces: Data enters a "Soft Delete" recovery state for 14 days, allowing accidental deletions to be restored.
  • Permanent Erase: After 14 days, data is permanently wiped from active database storage.

Export Rights & Data Portability

You are never locked in. Admins can export their entire Member Registry, Donation Logs, and Meeting Minutes as CSV or JSON files at any time from the dashboard settings.

Legal Compliance

We comply with the Information Technology Act, 2000. In strict accordance with the law, we may be required to preserve specific records (Legal Hold) if served with a valid court order or investigation notice by Indian authorities.