shabash

Team Recognition App

Privacy Policy

Last updated: 19 August 2026

Draft pending Indian counsel review. The grievance officer name has not been appointed yet — contact support@digitium.tech until then.

This notice explains how DIGITIUM TECHNOLOGIES LLP ("we", "us") collects and uses personal data when you visit https://shabash.club, sign in to shabash, or use the workplace recognition Service. It is written for the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 (Rule 3 notice). It is independent of our Terms.

1. Who we are

The Service is operated by DIGITIUM TECHNOLOGIES LLP, an Indian Limited Liability Partnership (LLPIN ACQ-1131), with its registered office at No.74, 3rd Floor, Mass Complex, Sarakki Industrial Layout, JP Nagar 3rd Phase, Bengaluru, Karnataka 560078, India. Contact: support@digitium.tech.

2. Who this notice covers

  • Website visitors and people who manage cookie consent
  • Users — people who sign in (email magic link or Google)
  • Members — people synced into a Group's Team (usually via Slack) who give and redeem recognition
  • Admins and the Team Manager who configure the program and receive Team emails
  • People who submit a founding-customer claim (name, company name, email, phone)

3. Our dual role

For workplace data that belongs to your employer's recognition program (Member profiles, Slack identifiers, recognition messages, dates of birth and joining, gift-card redemptions), the Customer Group is typically the Data Fiduciary and we act as a Data Processor under their instructions. That relationship is described in our Data Processing Addendum.

We are the Data Fiduciary for User login and sessions, Group billing profiles and Razorpay Subscription data, website visitors, cookie consent records, and product analytics when you consent.

4. Personal data we collect and why

You provide

  • Sign-in: email (magic link with Cloudflare Turnstile) or Google OAuth name, email, and picture. We also store whether the email is verified, the User role, the linked Group, whether the User is active, and a soft-delete timestamp if the User is removed
  • Billing profile on the Group: name, email, street, city, state, country, zipcode, optional GSTIN (synced to Razorpay)
  • Member profile fields: name, username, email, avatar URL, bio, date of birth, date of joining, timezone, and currency, plus Slack external id when synced. An Admin or the Member may edit some of these
  • Recognition messages and optional Giphy GIF URLs when a Member awards a Shabash
  • Founding-customer claim: name, company name, email, phone (stored in Workers KV)

From Slack

When a Group connects Slack, we sync channel Members using Slack OAuth scopes including users:read, users:read.email, users.profile:read, and related chat/command scopes. We store name, email, Slack external id, timezone, profile start_date as date of joining, and whether Slack marks the person as an admin (mapped to our Admin role). Leaving the connected channel soft-deletes the Member and matching User.

From use of the Service

  • Points Balance and Allowance, redeemable currency amount, and Shabash transaction history
  • Gift-card redemptions: brand, amount, Hubble order ids, and voucher codes and PINs stored in the tenant database and emailed to the Member
  • Proforma, Receipt, and Statement PDFs stored on Cloudflare R2
  • Super Admins (Shabash operators) can view a Group's tenant data via /admin to support the Customer

Communications

We send transactional messages only — no marketing list. That includes magic-link emails, billing and Subscription emails, monthly Statements to the Manager, Credit-funding reminders, birthday and anniversary Slack messages, and gift-card issued or failed emails (the issued email includes voucher codes and PINs).

We do not

  • Ship physical goods or store payment card numbers (Razorpay does)
  • Offer Facebook, Instagram, Twitter, or LinkedIn login — only Google and email magic link
  • Run a marketing or SMS list — only transactional email via Cloudflare from no-reply@shabash.club

When we place a Hubble gift-card order, the customerDetails fields we send to Hubble are currently dummy values, not the Member's real name, phone, or email.

5. Cookies

We use cookies and similar technologies to run the Service and to understand how it is used. You can instruct your browser to refuse cookies; if you refuse strictly necessary cookies, some parts of the Service may not work.

Strictly necessary cookies are required to provide the Service you ask for — keeping you signed in, protecting sign-in flows from forgery, and remembering choices you explicitly make. These do not require your consent.

Analytics cookies are optional. They are set by PostHog, our product analytics provider, and help us understand how the Service is used so we can improve it. They are only stored or read after you give consent through the cookie banner, and you can withdraw that consent at any time from the "cookie settings" link in the footer or your account menu — withdrawal is as easy as giving consent, and takes effect immediately.

  • shabash_session

    necessary · 14 days · shabash

    keeps you signed in

  • shabash_auth_oauth_state

    necessary · 10 minutes · shabash

    protects google sign-in from forgery (csrf)

  • shabash_auth_oauth_code_verifier

    necessary · 10 minutes · shabash

    protects google sign-in from forgery (pkce)

  • shabash_magic_auth_state

    necessary · 10 minutes · shabash

    protects email sign-in from forgery (csrf)

  • shabash_fc

    necessary · 1 year · shabash

    remembers your founding customer claim

  • sidebar_state

    necessary · 7 days · shabash

    remembers whether the sidebar is open

  • shabash_consent

    necessary · 6 months · shabash

    remembers your cookie choice

  • shabash_super_admin_session

    necessary · 8 hours · shabash

    keeps a Super Admin signed in to /admin

  • shabash_super_admin_auth_oauth_state

    necessary · 10 minutes · shabash

    protects Super Admin google sign-in from forgery (csrf)

  • shabash_super_admin_auth_oauth_code_verifier

    necessary · 10 minutes · shabash

    protects Super Admin google sign-in from forgery (pkce)

  • ph_*

    analytics · up to 1 year · PostHog

    posthog product analytics — pageviews and usage events that help us improve shabash

When you make or change a choice, we keep a record of it (what you consented to, when, and which version of this notice you saw) so we can demonstrate compliance. If you are signed in, the record is linked to your User. Consent cookies last about six months; the audit record in Workers KV is kept for about 2 years.

Some pages load third-party services that are not analytics: Cloudflare Turnstile (bot protection on forms) and Razorpay (payment checkout). These run only where needed and may set their own strictly necessary cookies while you use those features. The browser may also request a Gravatar image using a hash of the Member's email when no avatar URL is set.

6. Processors

We use the following processors / sub-processors. The same list appears in the DPA.

  • Cloudflare

    Purpose
    Hosts the Service (Workers), stores consent, founding-claim records, and Hubble cache (KV), bot protection (Turnstile), PDF storage (R2), PDF rendering (Browser Rendering), and transactional email (Email Sending)
    Data
    Request data, session cookies, consent records, Hubble brand cache and API tokens, billing PDFs, form submissions protected by Turnstile, recipient email and message content (magic links, billing, Statements, gift-card details)
    Region
    Global edge; US and EU data centers depending on request path
  • Turso / libSQL

    Purpose
    Main database (Users, Groups, billing) and per-Group tenant databases
    Data
    User accounts, Group and billing profile data, Member profiles, recognition, redemptions, Credit ledgers
    Region
    Configured Turso region (typically US or EU)
  • Slack

    Purpose
    Workspace integration for Member sync, recognition posts, and occasion messages
    Data
    Slack user ids, names, emails, profile start dates, channel membership, messages we post
    Region
    United States / Slack global infrastructure
  • Google

    Purpose
    OAuth sign-in for Users and Super Admins
    Data
    Name, email, and profile picture provided by Google during sign-in
    Region
    United States / Google global infrastructure
  • Razorpay

    Purpose
    Subscription billing and payment processing
    Data
    Billing profile (name, email, address, GSTIN), Subscription status, payment events — card numbers stay with Razorpay
    Region
    India
  • Hubble

    Purpose
    Gift card catalogue and order fulfillment
    Data
    Order amounts, brand ids, voucher codes returned to us; API customerDetails currently use dummy values
    Region
    India
  • PostHog

    Purpose
    Product analytics (only after cookie consent)
    Data
    Pageviews, usage events, device and browser metadata
    Region
    United States (us.i.posthog.com)
  • OpenRouter

    Purpose
    Optional AI polish of recognition notes and Member bios when a Member clicks generate
    Data
    Prompt text the Member submits for generation
    Region
    United States / OpenRouter model providers
  • Upstash QStash

    Purpose
    Scheduled jobs (Slack sync, birthdays, anniversaries, Statements, Credit reminders, season reset, Hubble brand sync, subscription sync)
    Data
    Job payloads referencing Group and Member identifiers
    Region
    Configured Upstash region
  • Giphy

    Purpose
    Optional GIF search for recognition messages
    Data
    Search queries; selected GIF URLs stored with the Shabash
    Region
    United States
  • Gravatar

    Purpose
    Avatar fallback in the browser when a Member has no uploaded avatar
    Data
    Email hash requested by the browser
    Region
    United States

7. Cross-border processing

Some processors are located outside India (for example PostHog in the United States, and other vendors with US or EU infrastructure). We take reasonable contractual and security steps appropriate to the Service. By using the Service, you understand that personal data may be processed in those regions as described above.

8. Retention

We keep personal data while the Group or User remains active. Soft deletion marks Member, User, and Group records when they are removed; billing and tax records are kept as required by law. Consent audit records in Workers KV expire after about 2 years. If a Hubble gift-card order fails or is cancelled, we restore the Group's Credit and the Member's points.

9. Your rights

Under the DPDP Act, you may request access, correction, erasure, withdrawal of consent (where processing is consent-based), grievance redressal, and nomination of another person to exercise rights in the event of death or incapacity, subject to the Act and applicable exemptions. Email support@digitium.tech. Cookie analytics consent can be changed from cookie settings. Admins can deactivate Members in the product today; we do not yet offer a self-serve "download my data" or erase button.

10. Complaints to the Data Protection Board of India

If you are not satisfied with our response, you may complain to the Data Protection Board of India as provided under the DPDP Act.

11. Children

The Service is a workplace product for adults. You must be 18 or older. We do not knowingly offer the Service to children as defined under the DPDP Act.

12. Security

We use commercially reasonable technical and organisational measures to protect personal data. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. Gift-card voucher codes and PINs are sensitive credentials — treat emails that contain them carefully.

13. Changes

We may update this notice from time to time. We will change the "Last updated" date above. Material changes will be called out on this page. Continued use of the Service after an update means you have read the revised notice.

14. Grievance Officer

A named grievance officer will be published here after appointment. Until then, write to support@digitium.tech with the subject line "Grievance — privacy".


DIGITIUM TECHNOLOGIES LLP · LLPIN ACQ-1131 · No.74, 3rd Floor, Mass Complex, Sarakki Industrial Layout, JP Nagar 3rd Phase, Bengaluru, Karnataka 560078, India · support@digitium.tech