Legal

Privacy Policy

Effective 19 May 2026

1. Who We Are

Aggarwal Heritage (aggarwalheritage.com) is operated by Amit Singla, New Delhi, India (“we”, “us”, “our”). We are the data controller for personal information collected through this service.

Contact: hello@aggarwalheritage.com

2. Data We Collect

Account information

Your name, email address, and password (stored as a secure hash) when you sign up.

Family data

Names, birth dates, death dates, relationship details, hometown, gotra, and other genealogical information you add about family members. You choose what to add.

Photos & audio recordings

Profile photos and oral history audio recordings you upload for family members.

Usage data

Basic server logs (IP address, browser type, pages visited) retained by our hosting provider (Vercel) for security and debugging.

Payment data

If you subscribe or donate, Stripe collects your payment information directly. We receive only a confirmation token — we never see or store your card number.

3. How We Use Your Data

  • Providing the service — displaying your family tree, rituals, and heritage content to you and invited family members.
  • Sending reminders — birthday, anniversary, and other reminders you set up. You can unsubscribe at any time.
  • Transactional emails — account confirmation, access approval notifications, and family invitations.
  • AI-assisted features — content you submit to ritual structuring or image import features is sent to Anthropic Claude for processing and then discarded. We do not retain it for training.
  • Security & fraud prevention — detecting and responding to abuse or unauthorised access.
  • Legal compliance — meeting our obligations under applicable law.

We do not sell your data, use it for targeted advertising, or share it with third parties for their own marketing.

4. Data Sharing & Third Parties

We use the following service providers to operate the platform. Each is bound by its own privacy policy and data processing agreement:

ProviderPurposeData shared
SupabaseDatabase, authentication, file storageAll app data, including account and family records
VercelWeb hosting & CDNServer request logs, IP addresses
ResendTransactional email deliveryYour email address and email content
StripePayment processingPayment details (processed directly by Stripe — we receive only a token)
AnthropicAI ritual structuring & image importContent you explicitly submit to those features — not background data

We may disclose data if required by law, court order, or to protect safety.

5. Cookies & Local Storage

We use session cookies set by Supabase to keep you logged in. These are strictly necessary for the service to function — no consent banner is required. We do not use advertising or tracking cookies. We do not use Google Analytics or similar tools.

6. Data Retention

  • Account and family data is kept for as long as your account is active.
  • When you request account deletion, we delete your personal data within 30 days.
  • Anonymised usage statistics and server logs may be retained for up to 12 months.
  • Payment records are retained for 7 years as required by financial regulations.

7. Your Rights

Depending on where you live, you may have the following rights. Email us at hello@aggarwalheritage.com to exercise any of them:

  • Access — request a copy of the personal data we hold about you.
  • Correction — ask us to fix inaccurate data.
  • Erasure — request deletion of your account and personal data.
  • Portability — receive your data in a machine-readable format.
  • Objection — object to us processing your data for any purpose.
  • Unsubscribe — opt out of reminder emails via the link in any reminder email, or by emailing us.

India — Digital Personal Data Protection Act 2023

If you are an Indian resident, you have the rights above as “Data Principals” under the DPDPA 2023. We process your data on the basis of your consent (given at account creation). You may withdraw consent at any time by deleting your account.

European Union — GDPR

If you are in the EU/EEA, your lawful basis for processing is contract performance (operating your account) and legitimate interests (security, anti-fraud). You have the right to lodge a complaint with your local data protection authority.

8. Children's Privacy

This service is not directed at children under 13. We do not knowingly collect personal data from children under 13. If you believe a child under 13 has provided data, please contact us and we will delete it promptly.

Family members of any age may be recorded in the family tree by an adult account holder — this is genealogical data, not an independent child account.

9. Security

We use industry-standard protections: encrypted connections (HTTPS), Supabase Row Level Security to isolate family data, and hashed passwords. No system is 100% secure. If you believe your account has been compromised, contact us immediately.

10. Changes to This Policy

We will update this Policy when our practices change. Material changes will be notified by email to registered users. The effective date at the top of this page will be updated.

11. Contact & Complaints

For any privacy question or to exercise your rights:

Amit Singla

Aggarwal Heritage

New Delhi, India

Email: hello@aggarwalheritage.com

We will respond within 30 days. If you are unsatisfied with our response, you have the right to escalate to the relevant data protection regulator in your country.