Privacy Policy
How we collect, use, protect, and manage your information.
Introduction
Karighar India ("we," "us," "our," or "the platform") connects customers with skilled karighars (tradespeople and service providers) across India. This Privacy Policy explains what personal information we collect when you use our website and app, why we collect it, how we use and protect it, and the choices and rights you have over it.
This policy applies to everyone who uses Karighar India — customers looking to hire, karighars offering their services, and visitors browsing the site. By using the platform, you agree to the practices described here.
Information We Collect
We collect information in two ways today: what you give us directly when you create an account (like your name and email), and what your role adds on top of that (a karighar, company, or student profile). We do not yet run any analytics, advertising, or tracking scripts, so — unlike many sites — we currently collect very little automatically. That will be called out clearly here if it changes.
- Information you provide: name, email, mobile number, a password, and role-specific profile details (listed below for each role).
- Automatically collected: standard web server logs (IP address, browser, and page requested) generated by our hosting and database provider as a byproduct of serving the site. We do not currently run analytics, advertising, or behavioural-tracking tools of our own.
- From third parties: none at this time. We do not currently offer "Sign in with Google" or similar, and we do not run automated identity-verification checks — see Photos & Documents You Upload below for how manual verification currently works.
How We Use Information
We use your information to operate, secure, and improve the marketplace — never to sell it. Specifically, we use it to:
- Create and manage your account, and confirm it's really you via a confirmation link sent to your email.
- Match customers with relevant karighars, and display profiles, ratings, and search results.
- Send account-related emails, such as sign-up confirmation and password reset.
- Investigate reports, prevent fraud, and enforce our Trust & Safety guidelines.
- Understand how the platform is used, so we can fix problems and build better features.
- Meet legal and regulatory obligations applicable in India.
Account Information
When you create an account, we collect your full name, email, a password, and — for karighars, companies, and students — a mobile number (mobile number is optional for customers). Accounts and sign-in are handled by our authentication provider, Supabase; your password is never stored by us in plain, readable text — it is salted and hashed by Supabase using industry-standard methods before it ever reaches our database. Your role (customer, karighar, company, or student) determines what additional information we collect, described below.
Vendor (Karighar) Information
Karighars additionally provide: business name, category, years of experience, base location, service areas, languages spoken, the services they offer, and a GST or trade licence number. This information is stored in our database and is used to build your public profile and to help customers find you.
Company Information
Companies registering on the platform additionally provide: company name, industry, company size, headquarters location, GSTIN, and, optionally, a DUNS number, website URL, and a short company description. GSTIN is required; the DUNS number is optional and only requested where a company already has one.
Student Information
Students additionally provide: institution name, year of study, base location, availability, skills, and an optional profile description, to build a discoverable profile for part-time or project work.
Customer Information
Customers provide their name, email, and optionally a mobile number and location when they create an account. During sign-up we also offer to collect event preferences (event type, date, budget range, categories needed) to help personalize recommendations — this preference information is not currently saved to our database; it exists only in your browser for that session and is discarded when you close or refresh the page. We'll update this policy once that preference data is actually stored server-side.
Photos & Documents You Upload
Our sign-up flow lets karighars, companies, and students attach a profile photo or logo, portfolio images, a government ID, and — for companies — a registration or incorporation certificate, as part of a "verification" step. These files are uploaded to and stored in Supabase Storage (hosted in the same Mumbai/ap-south-1 region as our database), in a folder tied to your account that only you can write to.
Profile photos, logos, and portfolio images are stored in a public bucket, since they're shown on your public profile by design. Government ID documents and company registration certificates are stored in a separate, private bucket that is not publicly accessible — only you, and staff whose account has been explicitly granted an admin role for verification purposes, can read them. Clicking "Submit for verification" marks your profile as pending manual review; we do not yet run any automated identity-verification checks.
Communication Data
The platform does not currently have an in-app messaging system. Where the site shows a "WhatsApp" button or link, tapping it opens a conversation directly in WhatsApp between you and the other party — that conversation happens on WhatsApp's own platform, under WhatsApp's privacy policy, and we do not log or store its contents. If you contact our support team directly (for example, by email), we keep that correspondence so we can assist you and refer back to it later.
Cookies and Local Storage
We do not currently use cookies or scripts for analytics, advertising, or cross-site tracking. To keep you signed in, our authentication provider (Supabase) stores your session token in your browser's local storage — this is essential to how sign-in works and isn't used to track you elsewhere. You can clear this at any time via your browser settings, which will sign you out.
Third-Party Services
We currently rely on a small number of infrastructure providers to run the platform:
- Supabase — our database, authentication, and file-storage provider. Your account credentials, profile data, and any photos or documents you upload are stored on Supabase infrastructure in the Mumbai (ap-south-1) region, and access to that data is restricted by security rules so that, in general, you can only read and write your own information.
- Google Fonts — used to load the typefaces on this site; loading a font may share your IP address with Google's font servers.
- jsDelivr — a content-delivery network we use to load the Supabase client library that powers sign-in on this site.
These providers only receive what's needed to perform their specific function. We do not sell your personal information to advertisers or data brokers, and we do not currently use any SMS, OTP, or identity-verification vendors.
Data Security
We use industry-standard measures to protect your data, including encrypted connections (HTTPS/SSL) across the platform, password hashing handled by our authentication provider, and Row Level Security rules at the database level that restrict each account to its own data — including preventing users from granting themselves administrator access. The same approach applies to file storage: security rules on our Storage buckets restrict each account to uploading and reading only its own folder, and verification documents (IDs, registration certificates) sit in a private bucket readable only by you and admin-role staff — never publicly accessible. No system is 100% immune to risk, but we work continuously to keep your information secure.
Data Retention
We retain your account and profile information for as long as your account is active, and for a reasonable period afterward to meet legal, accounting, or dispute-resolution requirements — typically [X months/years — to be confirmed with legal counsel]. If your account is deleted, its associated profile data is removed from our database as part of that deletion (our database is configured so role-specific profile records are automatically removed when the underlying account is).
User Rights
You have the right to access the personal information we hold about you, correct inaccurate details, request a copy of your data, and withdraw consent for optional data uses. To exercise any of these rights, contact us using the details below.
Account Deletion
Self-serve account deletion isn't available in the product yet. You can request account deletion at any time by contacting privacy@karigharindia.com, and we will manually delete your account and associated profile data within a reasonable period, except where we are required to retain certain records by law (for example, transaction records for tax purposes).
Changes to This Privacy Policy
We may update this policy as the platform evolves or as Indian data protection law changes. We'll update the "Last updated" date above, and for significant changes, we'll make a reasonable effort to notify you directly (for example, via email or an in-app notice).
Contact Information
Questions about this policy or how your data is handled can be sent to privacy@karigharindia.com, or through our Contact page. Our registered business details: [Legal entity name, registered address, CIN/registration number — placeholder].