Skip to main content
HarHarMahadev

Legal

Privacy Policy

Last updated · May 18, 2026

HarHarMahadev is built so pilgrims can plan a yatra without giving up control of their personal information. This notice explains what we collect, why, and the rights you can exercise under India's Digital Personal Data Protection Act, 2023 (DPDP).

1. What we collect

  • Account data: email or phone, password hash, sign-in history, and the consent timestamp recorded when you accept this policy.
  • Pilgrim profile: name, home city / state, preferred deity, dietary notes, spiritual lineage, and travel style — all optional and editable on /me/preferences.
  • Activity data: temples you save, recently view, trips you generate, bookings you complete, and chat transcripts.
  • Spiritual memories: facts the AI chatbot extracts from your conversations (e.g. "I prefer Saivite temples"). You can review and delete these at any time.
  • Operational telemetry: request IDs, IP addresses, and user-agent strings. We retain these for 30 days for security and fraud investigation only.

2. Why we use it

  1. Authenticating your account and securing your sessions.
  2. Personalising recommendations on the Home page and temple detail pages.
  3. Fulfilling bookings — sharing pilgrim name + count + slot with the relevant temple management partner.
  4. Sending transactional SMS / email (booking confirmations, OTPs). We do not market through these channels.

3. Your rights under the DPDP Act

  • Access & portability (§11): Download all your data as a JSON bundle.
  • Correction: Edit profile fields directly on /me.
  • Erasure (§12): Delete your account. We anonymise the profile and cascade-delete dependent rows; booking records may be retained for the period required by Indian tax / consumer-protection law.
  • Withdrawal of consent: Withdraw memory consent at any time via the “Forget everything” control on /me/preferences.
  • Grievance redressal: Email privacy@harharmahadev.com and we will respond within 30 days.

4. Who we share data with

We share the minimum required data with: Razorpay (payment processing), Twilio + SendGrid (transactional notifications), Google Maps Distance Matrix (travel-time estimates), and OpenAI / Gemini (LLM inference on the messages you submit to the chatbot). We never sell your data and we do not run ad networks on this platform.

5. Where data is stored

Primary storage lives in AWS RDS PostgreSQL (Mumbai region) and MongoDB Atlas (Mumbai region). LLM inference happens on the provider's region of choice (typically US); we do not send personally-identifying fields to the LLM beyond what is required to answer your message.

6. Changes to this policy

When we change this policy in a material way, we will surface the change in-app at next sign-in and require explicit re-acceptance. The change log lives in our repo at docs/legal/privacy-changelog.md.