Brightgoal Legal

Privacy Policy

How Brightgoal handles the information of library owners, staff and students — written plainly, with nothing hidden. We never sell your data, run ads, or track anyone.

Effective 22 July 2026Last updated 27 July 2026brightgoal.in@gmail.com
§ 01

Who we are

Brightgoal is study library management software operated by Harvindar Singh, a sole proprietor trading as Brightgoal, registered under GST in India (GSTIN: [GSTIN]).

We are based in Gonda, Uttar Pradesh, India. Our full registered address is available on written request to the contact below.

Contact for all privacy matters: brightgoal.in@gmail.com

§ 02

The two groups of people in this policy

This is the most important thing to understand about how Brightgoal handles data.

Owners & staffWe are the Data Fiduciary

Library owners and staff create their own Brightgoal accounts. For their data, we are the Data Fiduciary — we decide how it is used, and they can contact us directly about it.

StudentsWe are the Data Processor

Students do not have Brightgoal accounts and never sign up with us. Their details are entered by a library that uses our software. For student data, the library is the Data Fiduciary and Brightgoal is only the Data Processor. We store and process student information solely on that library's instructions. We do not decide what is collected, from whom, or why.

If you are a student, the library you attend is responsible for your information. Contact them first. If they do not respond, you may contact us and we will assist.

§ 03

What we collect

From library owners and staff

  • Name, email address, phone number
  • Password (stored only as a cryptographic hash — we never see it) and multi-factor authentication settings
  • Session cookies that keep you signed in
  • Library details you enter: name, address, location coordinates, contact details, photographs, operating hours, seats, lockers, slots and pricing
  • Subscription and billing records: plan, invoices, payment references, add-ons and SMS credit usage

We do not collect your GST number or any tax identifier from you. We do not receive or store card, UPI or bank details — payments are handled entirely by our payment gateway.

From students (entered by their library)

  • Full name; optionally a photograph and gender
  • Contact number
  • Address, city, state, postal code and country
  • Optionally, a government-issued identity document type and number
  • Enrolment records: slot, seat, locker, start and end dates, attendance window
  • Payment history and billing records for that library

Newsletter subscribers

If you subscribe to our newsletter, we store your email address and confirmation status. Nothing more.

From anyone who contacts us

When you send a message through our contact page, we store the name and email address you give us, the optional library name, the subject you pick, your message, and any files you attach — screenshots, PDFs, screen recordings, or a recorded voice message. Attachments are stored in the same secure file storage as the rest of our data (see section 9).

We also record the IP address and browser identifier the message was sent from. This is solely to prevent abuse of the form and is never used to build a profile of you.

You do not need an account to contact us, and we do not require you to create one.

Automatically

Our hosting providers process IP addresses, browser type and request metadata in server logs for security, abuse prevention and reliability. We do not use these to build profiles.

§ 04

The identity document — what it is and is not

Where a library records a government ID, that field is optional and the library chooses which document to use — Aadhaar in India, or a passport, PAN, voter ID, driving licence, student ID, or the equivalent in any other country.

We store this number for one reason: to identify a student uniquely across Brightgoal, so that a student exists only once in our system. When the same student later joins a different library, that library can enter the number and the student's existing details fill in automatically — so the student does not have to supply the same information repeatedly or carry documents to every library.

You should know all of the following:

We cannot verify these numbers. We do not check them against any government database or authority. We store the value exactly as the library typed it. We make no claim that it is accurate, valid, or belongs to the person named.
It is not used for identity verification, authentication, KYC, or eligibility decisions.
If it is left blank, the student record is still created normally. Only the automatic cross-library fill is unavailable, and that person may be recorded separately at each library.
We never require Aadhaar specifically, and no service depends on providing it.
§ 05

Information shared between libraries

Because student records are shared platform-wide, a library that enters a matching identity document number can see and auto-fill an existing student's stored name, contact and address details.

This is deliberate — it is what makes re-enrolment simple. We are telling you plainly because it means information a student gives to one library can become visible to another library they later approach. Libraries cannot see another library's enrolments, payments, seats or internal records.

§ 06

What we do with the information

  • Operate the software: enrolments, seats, lockers, slots, payments and receipts
  • Show each library owner analytics about their own library only. No owner sees another library's data.
  • Send transactional messages — receipts, reminders and account notices — where the library has enabled them
  • Take subscription payments and issue invoices to library owners
  • Keep the service secure, prevent abuse and fix faults
  • Send our newsletter, if you asked for it

We may also produce aggregated, non-identifying statistics across libraries to help students find suitable libraries and to improve the product. These will never identify an individual student.

§ 07

What we never do

We never sell personal information. Not to anyone, for any price.
We do not run advertising, ad pixels, or targeted marketing.
We use no third-party analytics or tracking — no Google Analytics, no Meta pixel, no session recorders, no behavioural trackers of any kind.
We do not use personal data to train AI models.
We do not profile or track children.
We do not share data between libraries beyond what is described in Section 5.
§ 08

Who else processes data for us

We use a small number of service providers, listed with their purpose on our Sub-processors page. They may only act on our instructions.

ProviderPurpose
Appwrite CloudDatabase, authentication and file storage
VercelApplication hosting
CashfreeSubscription payment processing
ResendTransactional and newsletter email
MSG91SMS delivery (where enabled)
WhatsApp Business Platform (Meta)WhatsApp reminders (where enabled)
§ 09

Where data is stored

Our database and files are hosted on Appwrite Cloud in Frankfurt, Germany. Application hosting is provided by Vercel. This means personal information — including that of students in India and elsewhere — is stored on servers in the European Union, a jurisdiction with strong data-protection standards.

Payment processing is performed by Cashfree in India.

§ 10

Public information

Every library may claim a public web address at brightgoal.in/username. This is off by default and only becomes visible once the owner claims a username and enables it. The owner controls what appears: library name, photographs, location, hours, facilities, slots and pricing.

Enabled libraries may also appear on our public map with their location.

No student information ever appears on a public library website or on the map.

Visitors to a public site may check seat availability and see an estimated fee. These enquiries are not stored — nothing typed into that estimator is recorded or retained by us.

§ 11

Cookies and local storage

We use no advertising or tracking cookies.

  • Session cookies — strictly necessary, HTTP-only and secure, to keep you signed in
  • Local storage — kept on your own device: your theme, language and selected library; interface state such as tabs, filters and saved map libraries; briefly cached lists so screens open instantly; and unsaved form drafts, which can include details you have begun typing about a student. On a shared computer, sign out and clear site data when you finish.
  • Location — only if you allow it on the public map, stored on your device to sort libraries by distance. Refusing does not break the map.

Our Cookie Policy explains all of this in full.

§ 12

How long we keep information

When a library owner deletes a library, that library's data — enrolments, seats, lockers, slots, payment records and settings — is deleted immediately.

Generated PDF documents (bills, receipts, reports) are marked for deletion at the same moment and are permanently removed from storage by an automated cleanup process shortly afterwards. This is because a library may hold thousands of files; the deletion runs in batches rather than all at once.

Student and identity records are retained. They are shared across the platform and are not owned by any single library — the same student may attend another library now or in future, and deleting them would break their records elsewhere. A student who wants their record removed entirely may contact us using Section 14, and we will remove it where no lawful reason requires us to keep it.

Dormant accounts. If a subscription has been expired or an account unused for more than 12 months, we may delete that account and its remaining data. We will email the account holder at least 30 days beforehand so they can resubscribe or ask us for a copy of their records. We are not obliged to delete dormant data, and we will not delete anything belonging to an account with an active subscription.

Contact messages. Messages sent through our contact page, and any files attached to them, are kept until we delete them manually — there is no automatic expiry. Deleting a message also permanently deletes every file attached to it. You may ask us to delete a message you sent using Section 14.

We keep invoices and payment records for as long as tax and accounting law requires.

§ 13

Children

Brightgoal is sold to library businesses, not to students, and we do not knowingly deal with children directly.

Some students may be under 18. The library that enters a student's information is responsible for obtaining verifiable parental or guardian consent where required, and confirms it has done so under our Terms of Service. We have no way to determine a student's age from the information supplied.

We do not profile, track, monitor the behaviour of, or advertise to any student, of any age.

If you believe a child's information has been entered without proper consent, contact us and we will act.

§ 14

Your rights

You may ask us to:

  • Access the personal information we hold about you
  • Correct anything inaccurate
  • Delete your information, where no legal obligation requires us to keep it
  • Explain how your information has been used
  • Withdraw newsletter consent — every email has a one-click unsubscribe link

Students: contact your library first, as they control your record. If they do not help, write to us and we will assist.

Library owners and staff: contact us directly.

Deleting your account. Brightgoal does not currently offer a self-service way to delete your account. You can delete any library you own from within the software, but the account itself must be closed by us. Write to us and we will delete your account and its associated data, subject to records we are required by law to keep. We intend to add self-service account deletion in future, and will tell users when it becomes available.

Write to brightgoal.in@gmail.com. We respond within 30 days.

§ 15

Security

Passwords are hashed and never stored or visible in readable form. Multi-factor authentication is available. All traffic is encrypted in transit. Staff access is limited by a granular permission system enforced on both the interface and the server, so a staff member can only reach what the owner has allowed.

No system is perfectly secure. If a breach affects your personal information, we will notify you and the relevant authority as the law requires.

§ 16

Changes to this policy

We will update this page when our practices change and revise the date at the top. Significant changes affecting library owners will be notified by email.

§ 17

Grievances

For any concern about how your information is handled, contact Harvindar Singh at brightgoal.in@gmail.com. We will acknowledge and respond within 30 days.

This policy is governed by the laws of India.

Questions about your data?

We answer every privacy request within 30 days.

brightgoal.in@gmail.com
Privacy Policy — Brightgoal