For temple-controlled devotee, enquiry, communication and operating records, the temple normally determines the purpose and authorised users; BookMyMandir processes workspace records where applicable. The company separately determines purposes for account, lead, support and security records. The exact data-fiduciary, processor or other statutory role depends on the record, agreement and law.
The primary application data plane is configured in AWS Mumbai. CloudFront is global, and approved email or identity services may process limited data outside Mumbai. This page does not claim that every byte or provider backup stays in India.
Source controls include per-channel consent states, purpose suppression, email withdrawal, bounded form-expiry snapshots and manual privacy-request intake. They are operational evidence, not independent proof that a temple's original notice or consent collection was legally sufficient.
Current application expiries include 365 days for booking enquiries and certain temple workflows, 180 days for company lead/claim/enterprise/support intake, and 30/90/180/365-day snapshots for temple-form responses. Some account, audit, consent and operational records do not yet have a complete automated deletion schedule.
Read the full privacy notice ↗