Skip to main content

Privacy Policy

How we collect, use, and protect your personal information when you visit www.thirupathicanda.org.

Last updated: 5 May 2026

This Privacy Policy explains, in plain language, what personal information we collect when you visit www.thirupathicanda.org (the “site”), why we collect it, who we share it with, and the choices and rights you have. We have written this policy to be compliant with Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy laws.

Who we are

The site is operated by an independent volunteer based in Canada (the “operator”, “we”, “us”, or “our”). It is a non-commercial devotional resource on the worship and teachings of Lord Sri Venkateswara, the Lord of the Seven Hills.

If you have questions about this Privacy Policy or about how your personal information is handled, you can email privacy@thirupathicanda.org or use our contact form.

Scope of this policy

This policy describes how we collect, use, share, and safeguard personal information when you visit www.thirupathicanda.org or interact with the site — for example, when you subscribe to our newsletter or send us a message through the contact form.

We comply with PIPEDA and, where applicable, the Personal Information Protection Act of British Columbia, the Personal Information Protection Act of Alberta, and the Quebec Act respecting the protection of personal information in the private sector (“Law 25”).

Information we collect

We collect only the information needed to operate the site responsibly. Specifically:

  • Newsletter subscriptions — your email address, optional first and last name, the language you are reading the site in, the IP address and browser user-agent string at the moment of subscribing, and an approximate location derived from that IP address (country, province or state, city, latitude and longitude, time zone, internet service provider, and autonomous-system network).
  • Contact-form submissions — your name, email address, optional subject, your message, and the language you were reading the site in.
  • Submissions blocked by anti-spam protection — when our anti-spam system rejects a contact-form submission, we keep the submitted payload, IP address, browser user-agent string, and language so that an administrator can review and tune the protection.
  • Administrator accounts — if you administer the site, your email address and a salted password hash are managed for us by Supabase Auth.
  • Server access logs — like every web service, our hosting provider records standard request logs (IP address, request time, page requested, and response status) for security and reliability purposes; we do not access these for marketing.

We do not knowingly collect any sensitive personal information (such as financial information, health information, or government identifiers), and we do not run advertising trackers, behavioural-advertising pixels, or social-media share-trackers on the site.

Why we collect this information

We use your information only for the purposes for which it was collected:

  • To send you the devotional newsletter you subscribed to, in the language you were reading the site in.
  • To respond to enquiries, suggestions, and corrections you submit through the contact form.
  • To detect and reduce spam, fraud, and abuse of our forms.
  • To improve the accuracy of translations and the regional relevance of the newsletter (for example, timing festival reminders to your area).
  • To secure the site and the administrator backend, including login session management and audit.

We do not sell your personal information, and we do not use it for advertising or to build behavioural profiles.

Service providers we share information with

We do not share your personal information with anyone for their own purposes. We do, however, rely on a small number of carefully selected service providers (“data processors”) who handle data on our behalf and only on our written instructions:

  • Supabase Inc. — provides our database and authentication services. Subscriber details, contact-form submissions, blocked-spam logs, and administrator accounts are stored in a Supabase project.
  • Vercel Inc. — provides our hosting, edge network, and product analytics. Server logs and aggregate cookieless usage analytics are processed by Vercel.
  • geoip.archangelfs.ca — a self-operated geolocation lookup used to convert IP addresses into approximate location at the moment of subscription. Only the IP address is sent to this service; no name or email is shared with it.

We may also disclose personal information when we are legally required to (for example, in response to a lawful court order issued in Canada), or when necessary to protect the safety, rights, or property of the operator, our users, or the public.

Storage outside Canada

Some of our service providers store and process data on servers outside Canada (primarily in the United States). When personal information is transferred outside Canada it remains subject to the laws of the country in which it is held, and may be accessible to the law-enforcement and national-security authorities of that country.

We use providers who offer industry-standard contractual and technical safeguards. By using the site you acknowledge this cross-border processing. If you would prefer that your data not be transferred outside Canada, please do not subscribe to the newsletter and do not submit the contact form.

Cookies and similar technologies

The site uses a small number of strictly functional cookies and stored values:

  • A locale preference cookie set by next-intl that remembers which language version of the site you last viewed (en, ta, or te).
  • Authentication cookies set by Supabase Auth, used only when an administrator signs in to the backend; these are not set for ordinary visitors.

We do not set advertising cookies, third-party tracking cookies, or social-media pixels. Vercel Analytics is configured to operate without cookies.

How long we keep your information

We keep newsletter subscriber records for as long as you remain subscribed. If you unsubscribe, we keep a minimal suppression record (your email address marked as unsubscribed) so that we do not accidentally re-send messages to you.

Contact-form submissions are kept for up to twenty-four months after the last related correspondence, after which they are deleted unless we have a legitimate reason to retain them longer (for example, an ongoing matter).

Spam and blocked-submission logs are kept for up to ninety days for tuning the anti-spam protection, then deleted.

Administrator accounts are kept for as long as you remain an administrator. When you cease to be an administrator, your account is removed.

How we protect your information

We use industry-standard safeguards appropriate to the sensitivity of the data:

  • All connections to the site are encrypted in transit using TLS.
  • Personal information at rest is held inside a Supabase project with row-level security policies that allow public submissions but restrict reads and updates to authenticated administrators.
  • Administrator passwords are hashed and salted by Supabase Auth — the operator never sees your raw password.
  • Anti-spam protection on the contact form uses one-time tokens, randomized field names, multiple honeypots, and timing checks to deter automated abuse.

No system can guarantee absolute security. If we ever become aware of a breach affecting your personal information, we will notify the Office of the Privacy Commissioner of Canada and the affected individuals as required by PIPEDA.

Your rights

Under PIPEDA and applicable provincial law you have the right to:

  • Access — request a copy of the personal information we hold about you.
  • Correction — ask us to correct any personal information that is inaccurate or incomplete.
  • Withdrawal of consent — withdraw your consent to our use of your personal information at any time, subject to legal or contractual restrictions and reasonable notice.
  • Deletion — request deletion of your personal information when it is no longer required for the purposes for which it was collected.
  • Portability (Quebec residents under Law 25) — request that we provide your computerized personal information in a structured, commonly used technological format.

To exercise any of these rights, email privacy@thirupathicanda.org from the address on file. We will respond within thirty days. There is no charge for reasonable requests.

Children

The site is not directed at children under the age of thirteen, and we do not knowingly collect personal information from children. If you believe a child has submitted information through the site, please contact us and we will delete it promptly.

Changes to this policy

We may update this Privacy Policy from time to time. The “Last updated” date at the top of this page reflects the most recent change. If we make a material change that affects how we use your personal information, we will notify subscribers by email before the change takes effect.

How to make a complaint

If you have a concern about how we have handled your personal information, please email privacy@thirupathicanda.org first so that we have an opportunity to address it. If you are not satisfied with our response, you have the right to lodge a complaint with the Office of the Privacy Commissioner of Canada (priv.gc.ca) or with the privacy regulator in your province.

Contact

Questions, requests, or concerns regarding this Privacy Policy can be sent to privacy@thirupathicanda.org or submitted through our contact form.