Policies / Last updated 3 October 2026
Privacy Policy
What personal data Namestead collects, why, who else sees it, how long we keep it and how you can control it.
Who is responsible
Sushil Kumar (“we”) decides why and how your personal data is used, which makes us the Data Fiduciary under India’s Digital Personal Data Protection Act, 2023 and its Rules. Namestead is an independently operated project owned and maintained by Sushil Kumar. It is not a registered nonprofit, NGO, charitable trust, society or Section 8 company.
The Act’s main duties start to apply on 13 May 2027. We already follow them: this policy is our notice to you under the Act and under Rule 3(1)(a) of the IT Intermediary Rules, 2021.
What we collect
- Account: your name, email address, profile picture and the id and login from GitHub or Google (whichever you sign in with). From GitHub we also read public figures such as account age, public repositories and followers, to set your Trust Points.
- Sign-in records: the time, your IP address, your browser and device type, and a rough place (country, city and network) worked out from an IP data file that lives on our own server.
- Your names and settings: the names you claim, their targets, DNS records and origins you add, and your notification choices.
- Activity inside Namestead: requests, votes, abuse reports, Trust Points and achievements, and the audit trail of actions on your account.
- Contributions: the name and email you give when you contribute, the amount, and the payment and order ids Razorpay returns. We never see your card number, UPI PIN or bank login; Razorpay collects those.
- Visitors to your names: for each visit we count a one-way hashed visitor code (made from the visitor’s IP address, browser and your name with a salt that changes daily and is never stored), the site that referred them (host name only) and the response status. We do not store visitor IP addresses and we put no scripts on your site.
- Messages: the emails we send you and whether they were delivered or bounced; reports and appeals you send us.
Why we use it
Only for the purposes you can see in the list above, and only with your consent or for another purpose the Act allows:
- to run your account and your names, and to show your uptime and visits;
- to keep Namestead safe: abuse and phishing checks, limits on claims, spotting fake accounts and chargebacks;
- to take, record and reconcile contributions and to keep a public ledger;
- to email you about your names, your account, requests you are involved in and, only if you choose it, updates and a weekly digest;
- to meet the law, answer court orders and government notices, and keep the records the law requires.
We do not sell your data and we do not show advertisements.
What is public
- The names you serve are public, because that is how a name works.
- A supporter’s name and the contribution appear in the public ledger and credits unless they chose “anonymous”. Anonymous hides the name in public only; we always keep it for our records.
- We never publish your email address, payment ids, bank details, card or UPI information.
- Your tier frame and badges appear next to your name where you already appear, such as a request you made.
How long we keep it
- Sessions last 30 days and renew while you use them; signing out or deleting your account ends them.
- When you delete your account we remove your provider links, tokens and sessions, release your names and remove your achievements. Your votes stay counted but are no longer linked to you.
- Records the law or our accounts require, such as contributions, the ledger, refunds and abuse evidence, are kept for as long as that is needed and are no longer linked to your profile.
- Visitor hashes and visit counts are rolled up and old detail is deleted on a schedule.
Your rights
Under the Act you can ask to see what we hold about you, to have it corrected or erased, to withdraw consent, to have a grievance heard, and to nominate someone to act for you if you die or cannot act. You can download your data and delete your account yourself in Settings. For anything else write to the grievance contact below.
We acknowledge a complaint within 24 hours and aim to resolve it within 15 days. If you are not satisfied you can complain to the Data Protection Board of India once it is operating, after using our process first.
Keeping it safe
Connections use TLS. Sign-in link tokens are stored hashed. Access to the admin tools is limited to named staff and logged. If a data breach affects you we will tell you and the Data Protection Board as the law requires.
Children
Namestead is for people aged 18 and over. We do not knowingly process the data of anyone under 18. If you think a child has signed up, tell us and we will remove the account.
Contact and changes
Questions about your data and complaints go to the address on the Contact page. We will tell you about material changes to this policy before they apply, and the date at the top of the page says when it last changed.