Sihimoge

Privacy Policy

Last updated: [operator to set date]. Data fiduciary: [operator legal name], [India address]. Data grievance contact: privacy@sihimoge.com.

This notice explains what personal data Sihimoge collects, why, and your rights under the Digital Personal Data Protection Act, 2023.

1. What we collect

  • Account: your email address (stored encrypted; a one-way hash is used for lookup and de-duplication), your chosen username and display name, an optional bio and profile picture, and the date you accepted these terms.
  • Ads: the content you post, an optional phone number (stored encrypted, shown only if you choose), and a map location. You may choose "approximate area only", which blurs the public pin to about 500 metres; the exact point is used only to build a directions link.
  • Photos: we strip all embedded metadata, including GPS, from every uploaded image.
  • Messages and comments: what you send through the site.
  • Usage: lightweight analytics events (an ad was seen, opened, a phone number revealed, and so on), your device type, referring site, and a per-browser session identifier. Your IP address is stored only as a salted hash, except in a short-retention security log kept to answer lawful requests (see retention).

2. Why we use it (lawful basis)

  • To run the service you signed up for - based on your consent, given at signup.
  • To keep the platform safe: prevent spam and abuse, moderate content, and respond to reports and legal orders.
  • To show posters aggregate statistics about their own ads.
  • We do not sell your data. We do not run third-party advertising or trackers.

3. Who we share it with

  • Other users: your public profile, your non-anonymous ads, and any contact details you chose to display.
  • Infrastructure: Cloudflare (content delivery, the "I am not a robot" check, DNS) and our email provider for account emails. The application and database run on hardware we control.
  • Authorities: where required by a valid legal process.

4. Retention

  • Raw analytics events: deleted after 90 days. Aggregate counts are kept.
  • When you delete your account, your content is hidden immediately and erased after 30 days, except a minimal identifying record and security log kept for up to 180 days where the IT Rules require it, after which it is erased.
  • Content removed by a moderator or under a legal order is retained for 180 days for investigation, then erased.

5. Your rights

  • Access and portability: download your data from Settings, or ask us.
  • Correction: edit your profile and ads, or ask us.
  • Erasure: delete your account from Settings.
  • Grievance: contact privacy@sihimoge.com. If unresolved, you may approach the Data Protection Board of India.

6. Children

Sihimoge is for adults (18+). We do not knowingly process the data of anyone under 18. If you believe a minor is using the service, tell us and we will act.

7. Security

Passwords are hashed with argon2id. Email and phone numbers are encrypted at rest. Sessions use signed, http-only cookies with refresh-token rotation. Staff accounts require two-factor authentication. Despite reasonable safeguards, no system is perfectly secure. If a breach affecting your data occurs, we will notify the Data Protection Board and affected users as the law requires.

8. Changes

Material changes to this policy will be announced on the site.