Privacy Policy
Draft — not yet finalised. This policy is a working document. Contact us at [email protected] with any questions.
Operated by: Mazhali, India
1. Who we are and our role
Mazhali provides a kindergarten/pre-school management application that schools use to record attendance, share daily reports and photos, post to a class feed, message guardians, and send announcements.
- The school that subscribes to Mazhali controls what data is collected about children, staff, and guardians, and is responsible for obtaining valid consent.
- Mazhali processes personal data only on the instructions of the school, under a written contract.
- You (a guardian, staff member, or — through a guardian — a child) are the person whose data is handled.
If you are a parent/guardian with a question about your child’s data, your first point of contact is your child’s school. You may also contact us at [email protected].
2. What personal data Mazhali handles
About children
- Full name, date of birth, gender, profile photograph
- Class and enrolment information
- Attendance records
- Daily reports: mood, meals, nap, activities, and staff notes
- Photographs in daily reports and the class feed
About guardians and staff
- Name, email address, phone number, profile photo
- Account role and relationship to the child
- Private 1-to-1 message content between guardians and staff
- Push-notification device tokens and notification history
- Invitation records
About fees and payments
- Fee schedules and invoices raised against a child (title, amount, due date, status)
- Payment references and timestamps (e.g. Razorpay payment/payment-link IDs, UPI transaction references, refund references) needed to reconcile whether an invoice was paid
- A school’s own payment-gateway configuration (e.g. Razorpay key ID, UPI VPA and payee name); gateway API secrets are stored encrypted and are never shown back to the school after entry
- Guardian-submitted payment claims (self-reported UPI/manual payments) awaiting admin verification
Technical data
- Authentication identifiers and session tokens
- Basic operational logs needed to run and secure the service
We do not store card, netbanking, or wallet details of guardians — card entry happens directly with the payment gateway (e.g. Razorpay), which returns only a payment reference to Mazhali. We also do not store government IDs or health records beyond optional notes a school chooses to enter.
3. Why we process this data
We process the above solely to provide the Mazhali service to the school:
- Record and display attendance, daily reports, feed posts, announcements, and calendar events
- Enable messaging between guardians and staff
- Deliver push notifications
- Raise and track fee invoices, and process payments a guardian chooses to make through the school’s configured payment gateway
- Authenticate users and enforce access controls
- Secure, back up, debug, and maintain the service
We do not use children’s data for advertising, profiling, or behavioural tracking.
4. Who we share data with
Mazhali does not sell personal data. We use the following sub-processors strictly to operate the service:
| Sub-processor | Purpose |
|---|---|
| Supabase | Authentication and photo storage |
| Google Firebase Cloud Messaging | Push notification delivery |
| Razorpay | Payment processing and payment links, where a school chooses Razorpay as its payment gateway |
| Hosting provider | Application hosting and database |
A school may instead choose to collect fees via UPI or manual (offline) payment, in which case no third-party payment processor is involved and Mazhali records only the payment reference the guardian or school enters.
5. How long we keep data
We retain data for as long as a school has an active subscription. When a school ends its subscription, we provide a data export and then delete or anonymise all data within a reasonable period, except where required by law.
6. How we protect data
- Encryption of data in transit (HTTPS/TLS)
- Role-based access control — users see only their own school’s data
- Multi-tenant isolation — no school can access another school’s data
- Restricted internal access on a need-to-know basis
- Regular backups
7. Your rights
You have the right to access, correct, or request erasure of your personal data. Because the school controls the data, most requests are handled through your school. There is no in-app self-service deletion — to request erasure, contact your school directly, or email us at [email protected] with your full name, registered email address, and school name; we will confirm receipt within 2 business days and complete the deletion within 30 days.
8. Changes to this policy
We may update this policy and will notify subscribing schools of material changes.
9. Contact
Email: [email protected]
Location: India