Shashandoot
Privacy policy
What the current Shashandoot application handles, and what remains to be confirmed before launch.
Operated by Madhuban LLP
info@shashandoot.comDraft updated: 23 September 2026
Preview draft. Service providers and retention arrangements must be confirmed before these policies are finalised.
Scope of this draft
This draft describes the current application features. It is not a statement that all launch privacy arrangements are complete. Service providers, retention periods and the purpose of collecting precise location still need confirmation.
Information entered during registration
- Contact details: email address and phone number. Email is used to send one-time login codes; the current application checks phone format but does not verify phone ownership.
- Profile details: first and last name, professional role, an optional firm name and a role description when “Other” is selected.
- Location: latitude, longitude and a consent timestamp. The current registration flow requests browser location permission and requires location to complete registration. Public pages can be browsed without completing registration.
Login, session and search information
The application keeps login-code verification records, expiry times and attempt counts to support authentication and limit abuse. Account information and points activity support the account pages.
Session cookies support sign-in, language selection and form security. Depending on deployment settings, session and server records can include IP addresses, browser information and request details. Search terms and filters appear in the URL and may be retained in browser history or server logs; avoid entering sensitive personal details.
How information is used
Contact form names, subjects and messages are processed to handle enquiries and passed to the configured email service. During local preview, the log mailer records messages locally instead of delivering email.
Contact and profile information supports account registration and display. Email supports login-code delivery. Session and authentication information supports access control, preferences and misuse prevention.
The current application stores precise coordinates with the profile. The operational purpose and retention of this location data must be explained and confirmed before public launch.
Service providers and external links
Hosting, database and email delivery services may process information needed to operate the service. The actual providers and processing locations must be confirmed for the public deployment.
When you follow a link to a government portal or another external site, that site’s own privacy practices apply. This draft does not promise how those sites handle data.
Retention and security
Data should be kept only for defined operational or legal needs. Specific retention periods, deletion procedures and backup handling remain to be finalised.
The application hashes login codes and restricts account pages to signed-in users. Production security depends on deployment configuration and ongoing maintenance; no system can guarantee absolute security.
Your choices and privacy requests
You can browse public pages without creating an account. You can control browser location permissions and cookies, although disabling required permissions or cookies may prevent registration or sign-in. Revoking a permission does not automatically delete information already stored.
Access, correction, deletion, consent withdrawal and grievance requests should be directed to info@shashandoot.com. The current preview has no self-service account deletion.
Policy updates
This page will be updated as the service and its data practices are finalised. Any additional uses of information should be explained before those uses begin.