DATA PRACTICE REVIEW

Personal Data Collection Review

Current-state review of the personal data categories used by the StartupStack platform and the control applied to each category.

Account data

Email, username and credential material are required to operate an account. Passwords are handled by WordPress authentication and are not stored by the StartupStack plugin as plaintext.

Mobile data

Country calling code and 10-digit mobile number are collected for OTP verification. Verification matching uses a hash; a display-safe mobile value may remain in user metadata for account support.

Publisher KYC

Aadhaar is mandatory for Publisher KYC. Raw Aadhaar is never stored by StartupStack; only a salted one-way hash is retained for duplicate-account prevention. Individual Publishers additionally provide Udyam/MSME; Organization Publishers additionally provide GSTIN.

Social proof

LinkedIn OIDC is used for Publisher professional/social proof. The plugin stores a hash of the LinkedIn subject identifier plus limited profile data. LinkedIn is not treated as government identity verification.

Public publishing

Author profiles and published articles are intentionally public. Users are instructed not to place sensitive personal data in public content.

Consent records

Registration and Publisher KYC consent events are versioned and stored with privacy-preserving hashes rather than raw connection identifiers.

Recommended actions

Maintain a vendor inventory, processor agreements, retention schedule, access review, incident-response procedure, data-subject request process and periodic policy review. Confirm the actual processing against the final production configuration before launch.