Legal
Privacy Policy
What personal data we collect, why, how long we keep it, who we share it with, and the rights you have over it.
Mangala United ("we", "us", "the Association") is a Mangaluru-based IT community association. This policy explains what personal data we collect, why we collect it, how long we keep it, who we share it with, and what rights you have over it.
It covers both our public website at mangalaunited.com and this Membership Portal, where members apply, pay, and manage their membership.
It is issued under the Digital Personal Data Protection Act, 2023 (DPDP Act) and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.
1. What we collect #
When you use the website
You can browse mangalaunited.com without giving us any personal data. Our web host records standard server logs (IP address, browser type, pages requested, timestamp) for security and troubleshooting.
When you create a portal account
| Data | Required? |
|---|---|
| Email address | Required — it is your login identity |
| Password, stored only as a bcrypt hash. We never see it | Required, unless you sign in with Google |
| Google account ID and email, if you choose "Continue with Google" | Optional alternative to a password |
When you apply for membership
| Data | Required? |
|---|---|
| Full name | Required |
| Phone number | Required |
| Postal address | Required |
| Photograph | Required — printed on your membership card |
| Organisation name and job designation | Optional |
| LinkedIn or portfolio URL | Optional |
| Areas of interest, willingness to take an active role, reason for joining | Optional |
| Name of the member who referred you, if any | Optional |
If you ask to end your membership
| Data | Required? |
|---|---|
| Reason for leaving, chosen from a fixed list (for example: cannot afford the fee, moving away, no longer working in IT) | Required — so the committee can see why members leave |
| Anything further you choose to write | Optional. The list above exists so that you never have to describe your circumstances in order to leave |
| The subscription position at the time, and any waiver the committee grants, with its reason | Recorded by us, not entered by you |
| The decision, who took it and when | Recorded by us |
2. Why we collect it #
| Purpose | Data used |
|---|---|
| Assessing your membership application | Name, contact details, professional details, reason for joining |
| Maintaining the register of members required of us as an association | Name, contact details, membership category, join date, status |
| Issuing membership cards and payment receipts | Name, photograph, member code, payment details |
| Administering renewals and sending reminders | Email, phone, membership term dates |
| Determining voting eligibility at the Annual General Meeting | Membership status and payment history |
| Organising events and recording attendance | Name, email, RSVP |
| Sending announcements about the Association | Name, email — you may opt out at any time |
| Meeting our legal, tax and audit obligations | Payment and receipt records |
| Keeping the portal secure and investigating misuse | Login records, IP address, activity log |
We process this data on the basis of the consent you give when you submit your membership application, and — for financial and membership records — because we are legally obliged to keep them.
3. Payments #
All online payments are processed by Razorpay Software Private Limited. When you pay, Razorpay collects your name, email, phone number and payment instrument details directly.
Mangala United never sees or stores your full card number, CVV, UPI PIN, or net-banking credentials. What we receive back and store is limited to the payment identifier, amount, currency, payment method type (for example "UPI" or "Card"), status, and timestamp. We use these to issue your receipt and reconcile our accounts.
Razorpay processes your data under its own Privacy Policy, which applies to you when you make a payment.
4. Photographs and membership cards #
The photograph you upload is used to produce your digital membership card. It is stored on our web server and is visible to Association administrators and to anyone you show your card to.
You may replace your photograph at any time from your profile. When your membership record is erased, the photograph is deleted with it.
5. Public verification links #
Every membership card and every payment receipt carries a QR code. Scanning it opens a verification page that confirms the card or receipt is genuine.
If you believe a verification link has been shared without your consent, contact us and we will issue you a new one, invalidating the old link.
6. Member referrals #
Members can invite someone to join by entering that person's email address. We use it once, to send a single invitation naming the member who referred them, and to send at most one reminder.
Every invitation carries a one-click link to decline further contact. If you receive an invitation you did not ask for, that link stops all further email from us and removes your address from our system. We also delete invitations that are never taken up after 90 days.
7. Community leaderboards #
To encourage participation and recognise member contributions, we may display community leaderboards inside the Membership Portal. These may show a member’s name, profile photograph (where one has been provided), membership badge or achievement level, referral count, and community rank.
Leaderboards are visible only to signed-in members of Mangala United. They are not public, not indexed by search engines, and not shared outside the Association.
Where a setting is offered to control whether you appear on a leaderboard, it is described in the portal. If you would rather not appear and no setting is available yet, contact our Grievance Officer and we will remove you.
8. Activity and audit records #
The portal records significant events on your membership — application submitted, approved, held, payment received, details changed, card downloaded — together with who performed the action and when. You can see your own history in the portal.
We keep these records so that decisions about members can be explained and audited. They are necessary for the proper governance of the Association and are retained even after a membership ends.
9. Who we share data with #
We do not sell, rent or trade your personal data. We share it only with the service providers we need to run the Association:
| Provider | Purpose | Location |
|---|---|---|
| Razorpay Software Pvt Ltd | Payment processing | India |
| Google LLC | "Sign in with Google", if you choose it | United States |
| MilesWeb | Website and portal hosting, database storage | India |
| Google LLC (Gmail SMTP) | Sending portal email | United States |
We may also disclose data where we are required to by law, a court, or a regulator.
Within the Association, your record is visible to committee members and volunteers holding an administrative role in the portal. Access is controlled by role, and administrative access to member records is logged. Other members see only what a community leaderboard shows (see above) — never your contact details, address or payment history.
A request to end your membership, including the reason you give and anything further you write, is visible to the committee members who handle membership decisions. It is not shared outside the Association.
10. How long we keep it #
| Record | Retained for | Why |
|---|---|---|
| Unsuccessful membership applications | 12 months | To answer queries and prevent duplicate applications |
| Active member records | For the duration of membership | To administer your membership |
| Former member records | Register entry kept indefinitely; other details erased after 3 years | Statutory register, audit and historical record |
| Payment and receipt records | 8 years | Income Tax Act and audit requirements |
| Activity and audit records | 7 years | Governance and accountability |
| Referral invitations not taken up | 90 days | No longer needed |
| Server and security logs | 90 days | Security investigation |
| Resignation requests, including the reason and any waiver | Kept with the membership record | A membership can end, be resumed and end again; each decision has to remain explainable |
11. Cookies #
The public website sets no cookies of its own. The Membership Portal sets only cookies that are strictly necessary for it to work:
| Cookie | Purpose | Expires |
|---|---|---|
| ci_session | Keeps you signed in as you move between pages | 2 hours of inactivity |
| csrf_cookie_name | Protects forms against cross-site request forgery | 2 hours |
| remember_code | Keeps you signed in between visits, only if you choose "remember me" | 24 hours |
We use no advertising, tracking or analytics cookies. Because all of the above are strictly necessary, we do not ask for cookie consent. If we ever add analytics, we will ask first.
12. Security #
We protect your data with:
- HTTPS encryption on the website and portal;
- passwords stored only as bcrypt hashes, never in readable form;
- role-based access, so volunteers see only what their role requires;
- rate limiting and account lockout to resist password-guessing;
- an audit trail of actions taken on your membership record, including actions taken by administrators.
No system is completely secure. We commit to the measures above and to telling you promptly if something goes wrong.
13. Your rights #
Under the DPDP Act you have the right to:
- Access — obtain a copy of the personal data we hold about you;
- Correction — have inaccurate data corrected. Most fields you can edit yourself in the portal;
- Erasure — ask us to delete your data, subject to the retention rules above;
- Withdraw consent — for anything we do on the basis of consent, including announcement emails;
- Nominate — name someone to exercise these rights on your behalf if you die or become incapacitated;
- Complain — to our Grievance Officer, and then to the Data Protection Board of India.
To exercise any of these, email our Grievance Officer below. We will respond within 30 days. There is no charge.
14. Grievance Officer #
In accordance with section 13 of the DPDP Act and Rule 5(9) of the IT Rules, 2011:
| Grievance Officer | General Secretary, Mangala United |
| connect@mangalaunited.com | |
| Postal address | House no. 1-N-34-3123/11, ONYX APT No.303, Opp. Dominic Church Hall, Urva Store, Ashok Nagar, Mangaluru Taluk, Dakshina Kannada – 575006 |
| Response time | Acknowledgement within 48 hours; resolution within 30 days |
If you are not satisfied with our response, you may complain to the Data Protection Board of India.
15. Data breaches #
If a breach affects your personal data, we will notify the Data Protection Board of India and every affected person, without undue delay and within the timeframe the DPDP Act requires. Our notification will describe what happened, what data was involved, what we are doing about it, and what you should do.
16. Children #
Membership is open to adults aged 18 and over. We do not knowingly collect data from children. If we learn that we have, we will delete it.
17. Changes to this policy #
We will publish any change here with a new version number and effective date, and keep previous versions available. Where the law requires us to notify you directly or to ask for fresh consent, we will. Continued use of the portal after the effective date means you accept the updated policy.
18. Contact us #
| Organisation | Mangala United — registration no. DRDK/SOR/76/2025-2026 |
| Address | House no. 1-N-34-3123/11, ONYX APT No.303, Opp. Dominic Church Hall, Urva Store, Ashok Nagar, Mangaluru Taluk, Dakshina Kannada – 575006 |
| connect@mangalaunited.com | |
| Phone | +91 73385 14244 |