Privacy Policy
1. Overview
The India Post Dashboard (the "Application") is an internal operations dashboard operated by the Circle Office, Haryana (the "Organization"), a unit of India Post. The Application is intended exclusively for authorized personnel of the Organization and is not offered to the general public.
This Privacy Policy explains what information the Application collects, how it is used and protected, how long it is retained, and how users can access or request the deletion of their data. This policy applies to personal information processed through the Application, including personal information obtained through Google APIs (as defined in Google's Google API Services User Data Policy).
2. Information we collect
The Application collects only the minimum information required for its operational function:
- User identification. The email address used to sign in, which identifies the user, determines their role and permissions, and attributes their actions in the audit trail.
- Account records created by the Organization. User profiles (name, role, department, office, and contact details) are created and maintained by the Organization's administrators inside the Organization-owned spreadsheet. Users do not create these themselves.
- Operational content. Records, submissions, tasks, approvals, notifications, documents attached to records, and audit-log entries that users enter into the Application. This content is stored in Google Sheets and Google Drive resources owned by the Organization.
- Technical logs. Google Apps Script execution logs (exception logging) may record system events for troubleshooting. These logs are accessible only to the Organization's administrators.
The Application does not collect location data, device identifiers, or any data for advertising, profiling, or analytics outside the Organization.
3. How we use the information
Collected information is used solely for the operational purposes of the Organization, including:
- Authenticating users and enforcing role-based access control.
- Reading, updating, and managing the Organization's operational records in the dashboard spreadsheet.
- Attaching documents to records and exporting reports (e.g., XLSX, PDF).
- Maintaining an audit log of actions for accountability and compliance.
4. Google account permissions (scopes)
To provide these functions, the Application requests the following Google account permissions. Access is limited to what the Application needs and nothing more:
- See your primary Google Account email address (
userinfo.email) — to identify the signed-in user and record their actions in the audit trail. - See, edit, create, and delete your spreadsheets in Google Drive (
spreadsheets) — to read and update the Organization-owned dashboard spreadsheet and to generate report workbooks. - See, edit, create, and delete only the specific Google Drive files you use with this app (
drive.file) — to store documents attached to records and temporary report files. This permission is limited to files created or opened by the Application. - Manage the current script's processes and triggers (
script.scriptapp) — to manage the Application's scheduled processes.
5. Limited use of Google user data
In accordance with Google's API Services User Data Policy, the Application's use of information received from Google APIs is limited to the following:
- Providing or improving user-facing features of the Application described in this policy.
- Compliance with applicable law.
- Security and anti-abuse purposes.
The Application does not transfer, sell, or share Google user data with any third party, advertising platform, data broker, or other service. It does not use the data for advertising, cross-device tracking, or to train machine-learning models, except as explicitly permitted by Google's policy.
6. Data retention
Operational data is retained for as long as it is required for the official functions of the Organization, consistent with India Post record-keeping practices and applicable law. Audit-log entries are kept to maintain an accurate history of system use. When information is no longer needed, it is deleted by the Organization's administrators in the ordinary course of administration.
7. Data deletion
Users who believe their personal information should be corrected, removed, or deleted should contact the Organization (see Contact us). Administrators of the Application can also delete operational records, user profiles, and audit entries directly within the Application.
See the Data Deletion page for the steps users and administrators can take to delete data.
8. Sharing and disclosure
Personal information is shared only with authorized personnel of the Organization who require it to operate and maintain the Application. The Organization does not sell, rent, or trade personal information. Information may be disclosed where required by law or legal process, or to protect the rights, property, or safety of the Organization or others.
9. Data security
The Application runs on Google Workspace infrastructure, which provides encryption in transit and at rest. Access to the Application is protected by role-based login, password hashing, session expiry, login throttling, and an audit trail. Only authorized administrators of the Organization can access the underlying spreadsheets and Drive resources.
10. Third-party services
The Application is built on Google Apps Script and stores its data in Google Workspace resources (Google Sheets, Google Drive, Gmail) owned by the Organization. The Application does not integrate with any other third-party services and does not transfer user data to any third party.
11. Changes to this policy
This policy may be updated from time to time. When it changes, the "Last updated" date at the top of this page will be revised. Continued use of the Application after changes take effect constitutes acceptance of the revised policy.
12. Contact us
For questions about this Privacy Policy or to request access to or deletion of your data, contact:
- Email: vcharyanaco@gmail.com
- Organization: Circle Office, Haryana, India Post