DPDPA / PRIVACYLinkedIn
Privacy Policy
How StartupStack collects, uses, protects, retains and enables control over personal data.
Who we are
StartupStack operates a publishing and discovery platform for readers, publishers and organizations. For privacy requests, contact neotia.hiten@gmail.com.
Personal data we collect
- Account data: name/display name, email address, username and password credential material.
- Contact verification data: country calling code and mobile number used for account contact and manual verification.
- Publisher KYC data: Aadhaar submitted for publisher KYC, processed only for verification and duplicate-account prevention; raw Aadhaar is never stored by StartupStack. Organization publishers provide GSTIN or Udyam/MSME evidence as applicable.
- Professional/social proof data: the LinkedIn profile URL supplied by the applicant for manual administrator review.
- Publishing/profile data: biography, expertise, organization, job title, country, articles, media and public profile information.
- Technical data: security logs, consent records, cookie preferences and operational metadata.
Purpose and lawful basis
We process personal data for specified platform purposes such as account creation, email confirmation, administrator verification review, fraud/security controls, publishing, support, compliance, analytics and service communications. The DPDPA requires lawful processing and, where consent is the basis, a notice describing the personal data and purpose and mechanisms for rights/grievances.
Aadhaar and KYC minimization
StartupStack never stores the raw Aadhaar number. The 12-digit value is used during registration for identity review and duplicate-account protection. Only a protected HMAC hash is retained for uniqueness checking. No Aadhaar verification API is used. No Aadhaar last-four value is retained.
LinkedIn is collected only as professional/social proof. The applicant supplies a public LinkedIn profile URL at account creation and an administrator manually reviews it. LinkedIn is not identity verification and is not an alternative login.
Sharing and processors
We may use service providers for hosting, email delivery, security and analytics. No external Aadhaar, GST, MSME or SMS verification provider is used in this baseline. Contracts and processor instructions should limit processing to the documented purpose and appropriate safeguards.
Retention
StartupStack should maintain a documented retention schedule by data category. Account, publication and compliance records may need to be retained for operational, contractual or legal reasons; unnecessary KYC material should not be retained indefinitely. The final schedule must be approved for the actual business model.
Your controls
Subject to applicable law and the platform’s legal obligations, provide mechanisms to access information, correct inaccuracies, request erasure where permitted, withdraw consent where consent is the basis, and raise grievances. The DPDPA expressly provides rights and requires mechanisms for complaints and consent management.
Security
Use least privilege, HTTPS, secure secrets, hashed verification tokens/OTPs, audit logging, access controls, backups and incident response. The final security controls should be documented and tested.
Policy updates
The policy version and effective date should be updated whenever material processing changes. The current implementation records a policy version of 14 September 2026.
Implementation note: This page is a platform implementation baseline, not a legal opinion. StartupStack should validate it with Indian privacy/corporate counsel and update it for its actual vendors, retention periods, contracts, security controls and notified obligations before relying on it as a final legal document.