DATA PRACTICE REVIEW
Personal Data Collection Review
Current-state review of the personal data categories used by the StartupStack platform and the control applied to each category.
Account data
Email, username and credential material are required to operate an account. Passwords are handled by WordPress authentication and are not stored by the StartupStack plugin as plaintext.
Mobile data
Country calling code and 10-digit mobile number are collected for OTP verification. Verification matching uses a hash; a display-safe mobile value may remain in user metadata for account support.
Publisher KYC
Aadhaar is mandatory for Publisher KYC. Raw Aadhaar is never stored by StartupStack; only a salted one-way hash is retained for duplicate-account prevention. Individual Publishers additionally provide Udyam/MSME; Organization Publishers additionally provide GSTIN.
Social proof
LinkedIn OIDC is used for Publisher professional/social proof. The plugin stores a hash of the LinkedIn subject identifier plus limited profile data. LinkedIn is not treated as government identity verification.
Public publishing
Author profiles and published articles are intentionally public. Users are instructed not to place sensitive personal data in public content.
Consent records
Registration and Publisher KYC consent events are versioned and stored with privacy-preserving hashes rather than raw connection identifiers.
Recommended actions
Maintain a vendor inventory, processor agreements, retention schedule, access review, incident-response procedure, data-subject request process and periodic policy review. Confirm the actual processing against the final production configuration before launch.
Implementation note: This page is a platform implementation baseline, not a legal opinion. StartupStack should validate it with Indian privacy/corporate counsel and update it for its actual vendors, retention periods, contracts, security controls and notified obligations before relying on it as a final legal document.