Who we are
Brightgoal is study library management software operated by Harvindar Singh, a sole proprietor trading as Brightgoal, registered under GST in India (GSTIN: [GSTIN]).
We are based in Gonda, Uttar Pradesh, India. Our full registered address is available on written request to the contact below.
Contact for all privacy matters: brightgoal.in@gmail.com
The two groups of people in this policy
This is the most important thing to understand about how Brightgoal handles data.
Library owners and staff create their own Brightgoal accounts. For their data, we are the Data Fiduciary — we decide how it is used, and they can contact us directly about it.
Students do not have Brightgoal accounts and never sign up with us. Their details are entered by a library that uses our software. For student data, the library is the Data Fiduciary and Brightgoal is only the Data Processor. We store and process student information solely on that library's instructions. We do not decide what is collected, from whom, or why.
If you are a student, the library you attend is responsible for your information. Contact them first. If they do not respond, you may contact us and we will assist.
What we collect
From library owners and staff
- Name, email address, phone number
- Password (stored only as a cryptographic hash — we never see it) and multi-factor authentication settings
- Session cookies that keep you signed in
- Library details you enter: name, address, location coordinates, contact details, photographs, operating hours, seats, lockers, slots and pricing
- Subscription and billing records: plan, invoices, payment references, add-ons and SMS credit usage
We do not collect your GST number or any tax identifier from you. We do not receive or store card, UPI or bank details — payments are handled entirely by our payment gateway.
From students (entered by their library)
- Full name; optionally a photograph and gender
- Contact number
- Address, city, state, postal code and country
- Optionally, a government-issued identity document type and number
- Enrolment records: slot, seat, locker, start and end dates, attendance window
- Payment history and billing records for that library
Newsletter subscribers
If you subscribe to our newsletter, we store your email address and confirmation status. Nothing more.
From anyone who contacts us
When you send a message through our contact page, we store the name and email address you give us, the optional library name, the subject you pick, your message, and any files you attach — screenshots, PDFs, screen recordings, or a recorded voice message. Attachments are stored in the same secure file storage as the rest of our data (see section 9).
We also record the IP address and browser identifier the message was sent from. This is solely to prevent abuse of the form and is never used to build a profile of you.
You do not need an account to contact us, and we do not require you to create one.
Automatically
Our hosting providers process IP addresses, browser type and request metadata in server logs for security, abuse prevention and reliability. We do not use these to build profiles.
The identity document — what it is and is not
Where a library records a government ID, that field is optional and the library chooses which document to use — Aadhaar in India, or a passport, PAN, voter ID, driving licence, student ID, or the equivalent in any other country.
We store this number for one reason: to identify a student uniquely across Brightgoal, so that a student exists only once in our system. When the same student later joins a different library, that library can enter the number and the student's existing details fill in automatically — so the student does not have to supply the same information repeatedly or carry documents to every library.
You should know all of the following:
What we do with the information
- Operate the software: enrolments, seats, lockers, slots, payments and receipts
- Show each library owner analytics about their own library only. No owner sees another library's data.
- Send transactional messages — receipts, reminders and account notices — where the library has enabled them
- Take subscription payments and issue invoices to library owners
- Keep the service secure, prevent abuse and fix faults
- Send our newsletter, if you asked for it
We may also produce aggregated, non-identifying statistics across libraries to help students find suitable libraries and to improve the product. These will never identify an individual student.
What we never do
Who else processes data for us
We use a small number of service providers, listed with their purpose on our Sub-processors page. They may only act on our instructions.
| Provider | Purpose |
|---|---|
| Appwrite Cloud | Database, authentication and file storage |
| Vercel | Application hosting |
| Cashfree | Subscription payment processing |
| Resend | Transactional and newsletter email |
| MSG91 | SMS delivery (where enabled) |
| WhatsApp Business Platform (Meta) | WhatsApp reminders (where enabled) |
Where data is stored
Our database and files are hosted on Appwrite Cloud in Frankfurt, Germany. Application hosting is provided by Vercel. This means personal information — including that of students in India and elsewhere — is stored on servers in the European Union, a jurisdiction with strong data-protection standards.
Payment processing is performed by Cashfree in India.
Public information
Every library may claim a public web address at brightgoal.in/username. This is off by default and only becomes visible once the owner claims a username and enables it. The owner controls what appears: library name, photographs, location, hours, facilities, slots and pricing.
Enabled libraries may also appear on our public map with their location.
No student information ever appears on a public library website or on the map.
Visitors to a public site may check seat availability and see an estimated fee. These enquiries are not stored — nothing typed into that estimator is recorded or retained by us.
How long we keep information
When a library owner deletes a library, that library's data — enrolments, seats, lockers, slots, payment records and settings — is deleted immediately.
Generated PDF documents (bills, receipts, reports) are marked for deletion at the same moment and are permanently removed from storage by an automated cleanup process shortly afterwards. This is because a library may hold thousands of files; the deletion runs in batches rather than all at once.
Student and identity records are retained. They are shared across the platform and are not owned by any single library — the same student may attend another library now or in future, and deleting them would break their records elsewhere. A student who wants their record removed entirely may contact us using Section 14, and we will remove it where no lawful reason requires us to keep it.
Dormant accounts. If a subscription has been expired or an account unused for more than 12 months, we may delete that account and its remaining data. We will email the account holder at least 30 days beforehand so they can resubscribe or ask us for a copy of their records. We are not obliged to delete dormant data, and we will not delete anything belonging to an account with an active subscription.
Contact messages. Messages sent through our contact page, and any files attached to them, are kept until we delete them manually — there is no automatic expiry. Deleting a message also permanently deletes every file attached to it. You may ask us to delete a message you sent using Section 14.
We keep invoices and payment records for as long as tax and accounting law requires.
Children
Brightgoal is sold to library businesses, not to students, and we do not knowingly deal with children directly.
Some students may be under 18. The library that enters a student's information is responsible for obtaining verifiable parental or guardian consent where required, and confirms it has done so under our Terms of Service. We have no way to determine a student's age from the information supplied.
We do not profile, track, monitor the behaviour of, or advertise to any student, of any age.
If you believe a child's information has been entered without proper consent, contact us and we will act.
Your rights
You may ask us to:
- Access the personal information we hold about you
- Correct anything inaccurate
- Delete your information, where no legal obligation requires us to keep it
- Explain how your information has been used
- Withdraw newsletter consent — every email has a one-click unsubscribe link
Students: contact your library first, as they control your record. If they do not help, write to us and we will assist.
Library owners and staff: contact us directly.
Deleting your account. Brightgoal does not currently offer a self-service way to delete your account. You can delete any library you own from within the software, but the account itself must be closed by us. Write to us and we will delete your account and its associated data, subject to records we are required by law to keep. We intend to add self-service account deletion in future, and will tell users when it becomes available.
Write to brightgoal.in@gmail.com. We respond within 30 days.
Security
Passwords are hashed and never stored or visible in readable form. Multi-factor authentication is available. All traffic is encrypted in transit. Staff access is limited by a granular permission system enforced on both the interface and the server, so a staff member can only reach what the owner has allowed.
No system is perfectly secure. If a breach affects your personal information, we will notify you and the relevant authority as the law requires.
Changes to this policy
We will update this page when our practices change and revise the date at the top. Significant changes affecting library owners will be notified by email.
Grievances
For any concern about how your information is handled, contact Harvindar Singh at brightgoal.in@gmail.com. We will acknowledge and respond within 30 days.
This policy is governed by the laws of India.
Questions about your data?
We answer every privacy request within 30 days.
