Privacy Policy
Last updated: 22 Jul 2026
1. Who we are
Silsila ("we", "us") is operated by [Owner Name], a sole proprietorship registered at [Full postal address], New Delhi, India. We host curated heritage walks, workshops, and cultural events across India and sell tickets to them through this website. For anything in this policy, contact us at baithak@silsila.com.
2. Personal data we collect
| Category | Data items | When collected |
|---|---|---|
| Account | Name, email address, password (stored only as a secure hash) | When you create an account |
| Google sign-in | Name, email address, profile picture from your Google account | When you sign in with Google |
| Two-factor authentication | Authenticator secret, backup codes | When you enable 2FA |
| Security & sessions | IP address, browser/device information (user agent), a device identifier, and approximate location (city/state, derived from your IP) | When you sign in or use the site |
| Bookings | Attendee name, email, phone number; event, ticket, and payment details | When you book a ticket |
| Payments | Razorpay order, payment, and refund identifiers. We never receive or store your card, UPI, or bank details — payment is completed on Razorpay's secure checkout. | When you pay |
| Newsletter | Email address (double opt-in — we only subscribe you after you confirm by email) | When you subscribe |
| Communications | Emails you send us and our replies | When you contact us |
3. Why we use it
Account creation and login security (including alerting you when your account is accessed from a new device); processing and delivering your bookings and tickets; processing payments and refunds; sending transactional emails (booking confirmations, tickets, reminders, cancellation and refund notices); sending the newsletter you opted into; preventing abuse and fraud (rate limiting); complying with law. We do not sell personal data, run advertising, or use analytics trackers.
4. Cookies
We use only functional cookies: a session cookie to keep you signed in and a preference cookie for your theme. No advertising or analytics cookies — which is why we don't show a cookie banner.
5. Who we share data with (service providers)
Razorpay Software Pvt Ltd (payment processing, India); Google (sign-in with Google); Supabase (database hosting); Vercel (website hosting); Resend (email delivery); Upstash (abuse prevention — receives IP addresses); ipinfo.io (converts your IP to an approximate city for login-security alerts); Mapbox (event location maps — your browser requests map imagery directly from Mapbox); Cloudinary (event images — no personal data). Each provider processes data only to provide its service to us. Some providers store data outside India (currently permitted under Indian law except to restricted countries notified by the Government; we will comply with any such restrictions).
6. How long we keep it
Account data: while your account exists. Booking and payment records: retained after the event for accounting and tax compliance. Sessions and device records: until they expire or you revoke them from Settings → Security. Newsletter email: until you unsubscribe (every email has an unsubscribe link).
7. Your rights
You may access and correct your data in your account settings; request a copy or erasure of your data; withdraw consent (e.g. unsubscribe, delete your account) — withdrawal doesn't affect processing already done; nominate a person to exercise your rights if you are unable to. Write to baithak@silsila.com. Under the Digital Personal Data Protection Act, 2023 you may also complain to the Data Protection Board of India if unsatisfied with our response.
8. Grievance redressal
Grievance Officer: [Owner Name], baithak@silsila.com / [+91 XXXXX XXXXX], [Full postal address], New Delhi, India. We acknowledge complaints within 48 hours and resolve them within one month.
9. Children
Our services are intended for users aged 18+. Bookings for minors must be made by a parent or guardian, who is responsible for the minor's attendance.
10. Security
Passwords are hashed, connections are encrypted (HTTPS), payment data never touches our servers, optional two-factor authentication is available, and we alert you to logins from new devices.
11. Changes
We'll update the "Last updated" date and, for material changes, notify account holders by email.