Legal
Privacy Policy
Last updated: 25 June 2026
ParcharPay ("we", "us", "our") operates the ParcharPay platform at parcharpay.org (the "Service"), enabling Sangat (donors) to send Bheta (contributions) to verified Parcharaks (recipients) worldwide. This page is maintained by ParcharPay to explain how we collect, use, disclose and protect personal information.
We handle personal information in accordance with the Australian Privacy Principles ("APPs") contained in the Privacy Act 1988 (Cth) and, where applicable, the European Union's General Data Protection Regulation ("GDPR"). This Policy does not create a certification or independent audit; it describes our current practices.
1. Information we collect
- Account data: name, display name, email address, password hash, and authentication identifiers (e.g. Google/Apple OAuth subject IDs).
- Parcharak profile data: Jatha name, biography, avatar/gallery images, mailing address for physical sign fulfilment.
- KYC & payout data (via Stripe): identity verification documents, date of birth, government ID details, banking information, and tax identifiers. This data is collected and stored directly by Stripe under their privacy policy; we receive only verification status and limited metadata.
- Contribution/transaction data: amount, currency, donor name/email (if provided), optional message, Stripe payment IDs, platform fee and net payout amounts.
- Technical data: IP address, user agent, device/browser information, cookies and similar identifiers, plus security/audit logs.
2. How we use information (APP 6 / GDPR Art. 6)
- Provide, operate, and improve the Service and process contributions.
- Verify identity and comply with anti-money-laundering, counter-terrorism financing, sanctions and tax obligations.
- Fulfil physical sign and goods shipping requests where applicable.
- Send transactional emails (receipts, security alerts, fulfilment updates).
- Detect, prevent and respond to fraud, abuse and security incidents.
- Comply with legal obligations and lawful requests from regulators or law enforcement.
Our legal bases under GDPR are (a) performance of a contract, (b) compliance with legal obligations, (c) our legitimate interests in operating and securing the Service, and (d) consent where required.
3. Disclosure to third parties (APP 6, APP 8)
We share personal information only with the following categories of processors:
- Stripe, Inc. — payment processing, Stripe Connect onboarding/KYC, payouts.
- Lovable Cloud (Supabase) — authenticated data storage, file storage and serverless compute.
- Resend — transactional email delivery.
- Google Search Console — search analytics for our marketing pages (no end-user PII).
Some of these providers process data in the United States and the European Union. Where we transfer personal information overseas (APP 8), we take reasonable steps to ensure recipients handle it consistently with the APPs and, for GDPR-protected data, rely on Standard Contractual Clauses or equivalent safeguards.
We do not sell personal information.
4. Data storage & security (APP 11)
Data is stored encrypted at rest and transmitted over TLS. Access to backend systems is restricted via role-based access control, row-level security and audit logging. Sensitive payment credentials never touch our servers — they are tokenised and held by Stripe. We retain personal information only for as long as necessary to provide the Service and to comply with our legal, accounting and reporting obligations (generally up to seven years for financial records under Australian law).
5. Your rights
Subject to the APPs and (where applicable) GDPR, you have the right to:
- Access the personal information we hold about you (APP 12, GDPR Art. 15).
- Request correction of inaccurate information (APP 13, GDPR Art. 16).
- Request deletion or erasure (GDPR Art. 17), subject to legal retention obligations.
- Restrict or object to certain processing (GDPR Arts. 18, 21).
- Receive a copy of your data in a portable format (GDPR Art. 20).
- Withdraw consent at any time where processing is based on consent.
- Lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au, or with your local EU supervisory authority.
To exercise these rights, email us at contact@parcharpay.org. We will respond within 30 days.
6. Cookies & analytics
We use strictly necessary cookies for authentication and session management, and a minimal set of first-party cookies/localStorage entries to remember your preferences (e.g. language, "Keep me logged in"). We do not use advertising trackers. Where required by GDPR, optional analytics cookies will only be set with your consent.
7. Children's privacy
The Service is not directed at children under 16. We do not knowingly collect personal information from children. If you believe a child has provided us with information, please contact us and we will delete it.
8. Data breach notification
In the unlikely event of an eligible data breach, we will notify affected individuals and the OAIC in accordance with the Notifiable Data Breaches scheme under the Privacy Act 1988 (Cth), and EU supervisory authorities within 72 hours as required by GDPR Article 33.
9. Changes to this Policy
We may update this Privacy Policy from time to time. Material changes will be communicated by email or via a notice on the Service. Continued use of the Service after the effective date constitutes acceptance.
10. Contact
Questions or privacy requests: contact@parcharpay.org
