shabash
Team Recognition AppPrivacy Policy
Last updated: 19 August 2026
Draft pending Indian counsel review. The grievance officer name has not been appointed yet — contact support@digitium.tech until then.
This notice explains how DIGITIUM TECHNOLOGIES LLP ("we", "us") collects and uses personal data when you visit https://shabash.club, sign in to shabash, or use the workplace recognition Service. It is written for the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 (Rule 3 notice). It is independent of our Terms.
1. Who we are
The Service is operated by DIGITIUM TECHNOLOGIES LLP, an Indian Limited Liability Partnership (LLPIN ACQ-1131), with its registered office at No.74, 3rd Floor, Mass Complex, Sarakki Industrial Layout, JP Nagar 3rd Phase, Bengaluru, Karnataka 560078, India. Contact: support@digitium.tech.
2. Who this notice covers
- Website visitors and people who manage cookie consent
- Users — people who sign in (email magic link or Google)
- Members — people synced into a Group's Team (usually via Slack) who give and redeem recognition
- Admins and the Team Manager who configure the program and receive Team emails
- People who submit a founding-customer claim (name, company name, email, phone)
3. Our dual role
For workplace data that belongs to your employer's recognition program (Member profiles, Slack identifiers, recognition messages, dates of birth and joining, gift-card redemptions), the Customer Group is typically the Data Fiduciary and we act as a Data Processor under their instructions. That relationship is described in our Data Processing Addendum.
We are the Data Fiduciary for User login and sessions, Group billing profiles and Razorpay Subscription data, website visitors, cookie consent records, and product analytics when you consent.
4. Personal data we collect and why
You provide
- Sign-in: email (magic link with Cloudflare Turnstile) or Google OAuth name, email, and picture. We also store whether the email is verified, the User role, the linked Group, whether the User is active, and a soft-delete timestamp if the User is removed
- Billing profile on the Group: name, email, street, city, state, country, zipcode, optional GSTIN (synced to Razorpay)
- Member profile fields: name, username, email, avatar URL, bio, date of birth, date of joining, timezone, and currency, plus Slack external id when synced. An Admin or the Member may edit some of these
- Recognition messages and optional Giphy GIF URLs when a Member awards a Shabash
- Founding-customer claim: name, company name, email, phone (stored in Workers KV)
From Slack
When a Group connects Slack, we sync channel Members using Slack OAuth scopes including users:read, users:read.email, users.profile:read, and related chat/command scopes. We store name, email, Slack external id, timezone, profile start_date as date of joining, and whether Slack marks the person as an admin (mapped to our Admin role). Leaving the connected channel soft-deletes the Member and matching User.
From use of the Service
- Points Balance and Allowance, redeemable currency amount, and Shabash transaction history
- Gift-card redemptions: brand, amount, Hubble order ids, and voucher codes and PINs stored in the tenant database and emailed to the Member
- Proforma, Receipt, and Statement PDFs stored on Cloudflare R2
- Super Admins (Shabash operators) can view a Group's tenant data via /admin to support the Customer
Communications
We send transactional messages only — no marketing list. That includes magic-link emails, billing and Subscription emails, monthly Statements to the Manager, Credit-funding reminders, birthday and anniversary Slack messages, and gift-card issued or failed emails (the issued email includes voucher codes and PINs).
We do not
- Ship physical goods or store payment card numbers (Razorpay does)
- Offer Facebook, Instagram, Twitter, or LinkedIn login — only Google and email magic link
- Run a marketing or SMS list — only transactional email via Cloudflare from no-reply@shabash.club
When we place a Hubble gift-card order, the customerDetails fields we send to Hubble are currently dummy values, not the Member's real name, phone, or email.
5. Cookies
We use cookies and similar technologies to run the Service and to understand how it is used. You can instruct your browser to refuse cookies; if you refuse strictly necessary cookies, some parts of the Service may not work.
Strictly necessary cookies are required to provide the Service you ask for — keeping you signed in, protecting sign-in flows from forgery, and remembering choices you explicitly make. These do not require your consent.
Analytics cookies are optional. They are set by PostHog, our product analytics provider, and help us understand how the Service is used so we can improve it. They are only stored or read after you give consent through the cookie banner, and you can withdraw that consent at any time from the "cookie settings" link in the footer or your account menu — withdrawal is as easy as giving consent, and takes effect immediately.
shabash_session
necessary · 14 days · shabash
keeps you signed in
shabash_auth_oauth_state
necessary · 10 minutes · shabash
protects google sign-in from forgery (csrf)
shabash_auth_oauth_code_verifier
necessary · 10 minutes · shabash
protects google sign-in from forgery (pkce)
shabash_magic_auth_state
necessary · 10 minutes · shabash
protects email sign-in from forgery (csrf)
shabash_fc
necessary · 1 year · shabash
remembers your founding customer claim
sidebar_state
necessary · 7 days · shabash
remembers whether the sidebar is open
shabash_consent
necessary · 6 months · shabash
remembers your cookie choice
shabash_super_admin_session
necessary · 8 hours · shabash
keeps a Super Admin signed in to /admin
shabash_super_admin_auth_oauth_state
necessary · 10 minutes · shabash
protects Super Admin google sign-in from forgery (csrf)
shabash_super_admin_auth_oauth_code_verifier
necessary · 10 minutes · shabash
protects Super Admin google sign-in from forgery (pkce)
ph_*
analytics · up to 1 year · PostHog
posthog product analytics — pageviews and usage events that help us improve shabash
When you make or change a choice, we keep a record of it (what you consented to, when, and which version of this notice you saw) so we can demonstrate compliance. If you are signed in, the record is linked to your User. Consent cookies last about six months; the audit record in Workers KV is kept for about 2 years.
Some pages load third-party services that are not analytics: Cloudflare Turnstile (bot protection on forms) and Razorpay (payment checkout). These run only where needed and may set their own strictly necessary cookies while you use those features. The browser may also request a Gravatar image using a hash of the Member's email when no avatar URL is set.
6. Processors
We use the following processors / sub-processors. The same list appears in the DPA.
Cloudflare
- Purpose
- Hosts the Service (Workers), stores consent, founding-claim records, and Hubble cache (KV), bot protection (Turnstile), PDF storage (R2), PDF rendering (Browser Rendering), and transactional email (Email Sending)
- Data
- Request data, session cookies, consent records, Hubble brand cache and API tokens, billing PDFs, form submissions protected by Turnstile, recipient email and message content (magic links, billing, Statements, gift-card details)
- Region
- Global edge; US and EU data centers depending on request path
Turso / libSQL
- Purpose
- Main database (Users, Groups, billing) and per-Group tenant databases
- Data
- User accounts, Group and billing profile data, Member profiles, recognition, redemptions, Credit ledgers
- Region
- Configured Turso region (typically US or EU)
Slack
- Purpose
- Workspace integration for Member sync, recognition posts, and occasion messages
- Data
- Slack user ids, names, emails, profile start dates, channel membership, messages we post
- Region
- United States / Slack global infrastructure
Google
- Purpose
- OAuth sign-in for Users and Super Admins
- Data
- Name, email, and profile picture provided by Google during sign-in
- Region
- United States / Google global infrastructure
Razorpay
- Purpose
- Subscription billing and payment processing
- Data
- Billing profile (name, email, address, GSTIN), Subscription status, payment events — card numbers stay with Razorpay
- Region
- India
Hubble
- Purpose
- Gift card catalogue and order fulfillment
- Data
- Order amounts, brand ids, voucher codes returned to us; API customerDetails currently use dummy values
- Region
- India
PostHog
- Purpose
- Product analytics (only after cookie consent)
- Data
- Pageviews, usage events, device and browser metadata
- Region
- United States (us.i.posthog.com)
OpenRouter
- Purpose
- Optional AI polish of recognition notes and Member bios when a Member clicks generate
- Data
- Prompt text the Member submits for generation
- Region
- United States / OpenRouter model providers
Upstash QStash
- Purpose
- Scheduled jobs (Slack sync, birthdays, anniversaries, Statements, Credit reminders, season reset, Hubble brand sync, subscription sync)
- Data
- Job payloads referencing Group and Member identifiers
- Region
- Configured Upstash region
Giphy
- Purpose
- Optional GIF search for recognition messages
- Data
- Search queries; selected GIF URLs stored with the Shabash
- Region
- United States
Gravatar
- Purpose
- Avatar fallback in the browser when a Member has no uploaded avatar
- Data
- Email hash requested by the browser
- Region
- United States
7. Cross-border processing
Some processors are located outside India (for example PostHog in the United States, and other vendors with US or EU infrastructure). We take reasonable contractual and security steps appropriate to the Service. By using the Service, you understand that personal data may be processed in those regions as described above.
8. Retention
We keep personal data while the Group or User remains active. Soft deletion marks Member, User, and Group records when they are removed; billing and tax records are kept as required by law. Consent audit records in Workers KV expire after about 2 years. If a Hubble gift-card order fails or is cancelled, we restore the Group's Credit and the Member's points.
9. Your rights
Under the DPDP Act, you may request access, correction, erasure, withdrawal of consent (where processing is consent-based), grievance redressal, and nomination of another person to exercise rights in the event of death or incapacity, subject to the Act and applicable exemptions. Email support@digitium.tech. Cookie analytics consent can be changed from cookie settings. Admins can deactivate Members in the product today; we do not yet offer a self-serve "download my data" or erase button.
10. Complaints to the Data Protection Board of India
If you are not satisfied with our response, you may complain to the Data Protection Board of India as provided under the DPDP Act.
11. Children
The Service is a workplace product for adults. You must be 18 or older. We do not knowingly offer the Service to children as defined under the DPDP Act.
12. Security
We use commercially reasonable technical and organisational measures to protect personal data. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. Gift-card voucher codes and PINs are sensitive credentials — treat emails that contain them carefully.
13. Changes
We may update this notice from time to time. We will change the "Last updated" date above. Material changes will be called out on this page. Continued use of the Service after an update means you have read the revised notice.
14. Grievance Officer
A named grievance officer will be published here after appointment. Until then, write to support@digitium.tech with the subject line "Grievance — privacy".
DIGITIUM TECHNOLOGIES LLP · LLPIN ACQ-1131 · No.74, 3rd Floor, Mass Complex, Sarakki Industrial Layout, JP Nagar 3rd Phase, Bengaluru, Karnataka 560078, India · support@digitium.tech