Here is every kind of personal data SocioStory keeps. You’ll only have some of it: most people never use every part of SocioStory.
Your account
- What
- Your name, email address and password (kept only as a secure hash we can't read), how you're here (for example as a volunteer, an NGO or a CSR team), and your organisation and city if you add them. If you sign in with Google, we receive your name, email address and profile photo link from Google. If you arrived through an invitation link, we note which campaign it was.
- Why
- To run your account, show you the right tools, and put your name on the stories you write and the certificates you earn.
- Who sees it
- You. Your name also appears on your stories and certificates, and to the organisations you work with.
- How long
- While your account exists.
Sign-in and security
- What
- When you sign in, the browser and device you used and its IP address. Password-reset links we send you. If you switch on two-step sign-in, its secret and backup codes.
- Why
- To keep you signed in, and to spot and stop misuse of your account.
- Who sees it
- Only us.
- How long
- Each sign-in is deleted once it ends, 30 days after your last visit. Reset links expire within an hour.
Your volunteer profile
- What
- Your date of birth, mobile number, city, state and PIN code, the causes you care about, your skills and languages, when you're free, how far you'll travel, a short bio, and whether your public profile is on.
- Why
- Your date of birth lets us check you're 18 or over on the day of each drive, because volunteering is for adults. Your phone number is used only if you choose to share it with a drive's coordinator. The rest helps you find drives that suit you.
- Who sees it
- It's private. Organisers never see your date of birth. Your public profile is off unless you switch it on; when it's on it shows your name, city, causes, hours, badges and certificates, never your date of birth, phone number or email.
- How long
- While your account exists.
Drives, attendance and hours
- What
- Each drive you sign up for and the consent you gave, whether your seat came through your college Centre, when you checked in and out (by scanning the drive's QR code, or as marked by its coordinator), the hours credited, and the organiser's sign-off. The website never reads your location.
- Why
- To run the drive, record your hours in the hour ledger, and issue your certificate.
- Who sees it
- The drive's organiser sees your name, college and status, and your phone number only if you shared it. Your Centre's leaders see their members' places. Nobody can search or browse volunteers.
- How long
- For the life of the platform: hours can't be changed once recorded. If you erase your account, they stay without your name.
Certificates
- What
- Your name, what the certificate is for (a course and your score, or a drive with its date, hours and organiser) and our digital signature.
- Why
- So that you, a college or an employer can check the certificate is genuine.
- Who sees it
- Anyone who has the certificate's link or ID can open its page. Certificates aren't listed in search engines.
- How long
- For the life of the platform. If you erase your account, the certificate stays, re-signed in the name “Former volunteer” or “Former learner”.
Stories
- What
- What you write, the photos you add, the three consent statements you confirm when you send a story for review, and our editors' notes to you. We re-encode every photo, which removes camera and location data.
- Why
- So our editors can review, edit and publish your story.
- Who sees it
- Our editors read every story. Once published, it’s public, with your name as the author. If you’re in someone else’s story and want it removed, ask us to take it down.
- How long
- While it's published, or until you delete a draft. If you erase your account, drafts are deleted and published stories carry the byline “Former contributor”.
The Academy
- What
- The lessons you complete, your quiz scores and your answers in final assessments.
- Why
- To track your progress and issue course certificates.
- Who sees it
- You and our Academy team.
- How long
- While your account exists.
Jobs and CVs
- What
- Your career profile (headline, experience, skills, phone number and LinkedIn), the CVs you upload, the jobs you save, and each application you send with its cover letter.
- Why
- So you can apply for jobs, and employers can consider your application.
- Who sees it
- An employer sees an application, and the CV with it, only when you send it to them. CVs are private files: they're never public, and we open them only for you, the employers you applied to and our editors.
- How long
- While your account exists. If you erase it, your CVs are deleted and employers see “Former applicant”.
Organisations, messages and updates
- What
- Your role in an organisation's workspace or a college Centre, the messages you send between NGOs and CSR teams, and the updates, blog posts and drives you write for an organisation. An organisation's registration numbers and verification documents belong to the organisation and are never published.
- Why
- To let organisations work together on SocioStory.
- Who sees it
- The other members of your organisations, and both organisations in a conversation. Updates and blog posts are public, under the organisation's name.
- How long
- While the organisation or conversation exists.
Payments
- What
- When an organisation pays for a plan: the plan, the amount, whether it was paid, and who started the payment. Card and bank details go straight to our payment provider, Razorpay; we never see them.
- Why
- To switch plans on, and to keep the accounts the law requires.
- Who sees it
- The organisation's owners and admins, and our finance team.
- How long
- 8 years, as tax law requires (to be confirmed with our chartered accountant).
Messages to an NGO through its website
- What
- If you write to an NGO through the website it builds on SocioStory: your name, email address, phone number if you give it, and your message. We also keep a salted fingerprint of your IP address, never the address itself.
- Why
- To pass your message to the NGO, and to stop spam.
- Who sees it
- That NGO's team. We don't use your message for anything else.
- How long
- Until the NGO deletes it. The NGO is responsible for how it uses your message.
The weekly mailer
- What
- Your email address, where you signed up, and when you confirmed or left.
- Why
- To send you the weekly mailer, which you asked for.
- Who sees it
- Only us, and the service that sends the mailer for us.
- How long
- Until you unsubscribe: one click in any mailer, or from Privacy & data.
Notifications, emails and messages we send you
- What
- What we tell you in your dashboard and by email, SMS or WhatsApp, and how you want to hear from us.
- Why
- To tell you what's happening with your drives, stories, applications and requests.
- Who sees it
- Only you, and us when we check a message was delivered.
- How long
- Notifications you've read are deleted after a year. The text of emails and messages is removed after 180 days; a short delivery record stays.
Consents, requests and reports
- What
- Every consent you give or withdraw, with the version of this notice you saw; requests you make under this notice; and any dispute about your hours or concern you report.
- Why
- To prove what you agreed to, and to deal with your requests, disputes and reports.
- Who sees it
- You, and the members of our team who handle them.
- How long
- Consent records for as long as your account exists (then without your name); requests for 3 years after we close them; safeguarding reports for 7 years.
Server logs and error reports
- What
- The IP address, time and page of each visit, and details of errors. Error reports never include passwords or sign-in cookies.
- Why
- To keep SocioStory secure and working, and because India's cyber-security rules require logs.
- Who sees it
- Our technical team, and the service that collects error reports for us.
- How long
- 13 months, in India.