1 Who we are
PaidSheet (“we”, “us”, the “app”) is operated by the PaidSheet team. Access is limited to members of the Delhi Technological University community who sign in with a @dtu.ac.in email address. If you have any questions about this policy, contact us using the details in section 11.
2 Information we collect
We only collect what the app needs to work. We do not collect your device location, contacts, or advertising identifiers, and we do not use third-party advertising.
| Data | What it is | Why we collect it |
|---|---|---|
| Email address | Your @dtu.ac.in address | Account creation and passwordless one-time-code (OTP) sign-in |
| Profile details | Name, year, branch, and optional bio | To identify you to other students in tasks and chats |
| Profile photo | Avatar image you choose to upload | Optional — shown on your profile and messages |
| Payment QR image | A UPI/payment QR you optionally upload | So counterparties can pay you for completed tasks |
| Tasks & bids | Content you post and bids you place | Core marketplace function |
| Messages | Chat text and images between users | To let you coordinate tasks |
| Ratings & reports | Feedback and safety reports you submit | Trust, safety, and moderation |
| Push token | Firebase Cloud Messaging (FCM) device token | To send you notifications (only if you allow them) |
| Technical data | IP address and basic request info | Security and rate-limiting to prevent abuse |
3 How we use your information
- To create and secure your account and sign you in via one-time codes.
- To operate the marketplace — posting tasks, placing and accepting bids, and chatting.
- To send notifications you have opted into (e.g. a new bid or message).
- To keep the service safe: moderating content, handling reports, and blocking abuse.
- To maintain, debug, and improve the app.
We do not sell your personal data, and we do not use it for third-party advertising or profiling.
4 How information is shared
Some information is visible to other users by design: your name, year, branch, avatar, tasks, bids, ratings, and any messages or payment QR you send to a counterparty. Beyond that, we share data only with the service providers that run the app for us:
- Supabase — database, file storage, and realtime messaging.
- Vercel — hosts our secure API endpoints.
- Google Firebase Cloud Messaging — delivers push notifications.
- Our email provider — sends your one-time sign-in codes.
These providers process data only on our instructions. We may also disclose information if required by law or to protect the safety of our users.
5 Data retention
We keep your account and content while your account is active. One-time codes expire within minutes and are deleted shortly after use. When you delete your account, we remove your profile, tasks, bids, messages, and uploaded images, except where we must retain limited records to comply with the law or resolve disputes.
6 Your choices and rights
- Access & correction — view and edit your profile in the app at any time.
- Notifications — turn push notifications on or off in your device settings.
- Account deletion — request deletion of your account and associated data (see section 7).
7 Deleting your account
To delete your account and all associated data, email us from your @dtu.ac.in address at the contact below with the subject “Delete my account”. We will process the request and confirm within 30 days.
8 Security
We protect your data with encrypted connections (HTTPS), passwordless one-time-code sign-in, database row-level security so users can only reach their own data, and rate-limiting against abuse. No system is perfectly secure, but we work to keep your information safe.
9 Children
PaidSheet is intended for university students and is not directed at children under 13. We do not knowingly collect data from children under 13. If you believe a child has provided us data, contact us and we will delete it.
10 Changes to this policy
We may update this policy as the app evolves. We will revise the “Last updated” date above and, for significant changes, notify you in the app. Continued use after an update means you accept the revised policy.
11 Contact us
Questions, requests, or concerns about this policy or your data:
Email: paidsheetapp@gmail.com