Privacy Policy
Last updated: August 9, 2026Effective date: August 9, 2026
This Privacy Policy explains how KashmirLocal collects, uses, and protects information when you visit https://kashmirlocal.com and use our services. It applies to the website, the public business directory, and the administrator area.
1. Who we are
KashmirLocal is a local business directory that helps people find shops, restaurants, services, healthcare providers, hotels, and education providers across Jammu & Kashmir. We are the data controller for the information described in this policy.
Contact / Grievance Officer
You can contact our privacy team or grievance officer at:
Email: contact.kashmirlocal@gmail.com
Postal address: KashmirLocal, Jammu & Kashmir, India.
2. Information we collect
Business / listing information
When a business listing is added or updated (by an authorised administrator on your behalf or on their own behalf), we collect and store the following information: business name, category, description, phone number, address, Google Maps link, and an optional image URL or external link. This information is displayed publicly in the directory.
Administrator account information
To manage listings, an administrator signs in with an email address and password. We authenticate administrators through Supabase Auth. We do not store your password or its hash on our own servers; Supabase creates and verifies password hashes for us. After successful authentication, only users whose identifier appears in the server-side administrator allow-list receive a signed admin-session cookie. That cookie, together with a per-request CSRF token, is what authorises access to the admin area. Ordinary authenticated users do not receive an admin session.
Account / visitor information you provide
KashmirLocal does not provide public registration, comment forms, or a newsletter sign-up for general visitors. If you contact us directly (for example by email), we keep your message and contact details only so that we can reply to you.
Information your device sends automatically
When you visit the site, our servers automatically record certain information about your request: your IP address, browser type, device type, operating system, the date and time of your visit, and the pages you view. We use this only to operate and protect the website, to enforce rate limits, and to diagnose problems. We do not use it to profile or identify individual visitors.
3. How we use your information
- Display business listings in the public directory.
- Authenticate administrators and control access to the admin area.
- Keep the website secure, detect misuse, and prevent abuse or spam.
- Respond to your privacy, correction, or deletion requests.
- CACHE business data on the server so the directory loads quickly.
We do not sell, rent, or trade your personal information, and we do not use it for behavioural advertising or marketing.
4. Business / listing information
Listing details such as phone numbers and addresses are published in the public directory so that visitors can find and contact businesses. By providing this information, the submitting administrator represents that they have the right to share it and that it is accurate. If you believe a listing is inaccurate or should be removed, please contact us (see section 9).
5. Cookies and similar technologies
We use cookies only where strictly necessary for the website to work. We do not use advertising, tracking, or social-media cookies, and we do not use localStorage or session storage to store user identifiers.
The cookies below are set only for administrators who sign in to the admin area. Ordinary visitors who do not sign in are not given any cookies by KashmirLocal.
Authentication cookies are marked HttpOnlyand SameSite=Lax, and they are set with the Secure flag when the site is served over HTTPS. Cookies are cleared when you log out.
6. Third-party services
We use the following services to operate the site. We are not responsible for the privacy practices of these providers.
- Supabase. Supabase hosts our database (where business listings and administrator emails are stored) and authenticates administrators via email and password. Data is stored by Supabase on servers that may be located outside India, under the privacy and security terms Supabase provides.
- Google Fonts. We load fonts (Geist and Inter) through the Next.js built-in font optimisation, which retrieves font files from Google. Google receives a request for the font files when the page loads.
- Outbound links. The directory links to Google Maps and WhatsApp so visitors can call, navigate, or message a business. Selecting one of these links takes you to another site owned by that provider, which has its own privacy policy.
- Images and links from external sources. Business photos are loaded directly from the URLs provided by administrators. The host that serves the image receives your IP address and browser information in the same way as any normal web request.
7. Data retention
- Business listings are kept for as long as they are part of the directory. You may ask us to remove a listing at any time (see section 9).
- Administrator account data (email address) is retained for as long as the account exists.
- Session and CSRF cookies expire automatically (8 hours for the session/access tokens, 30 days for the refresh token) and are cleared when you log out.
- Server log information is kept for a short period to support security and debugging, then deleted.
We may keep information for longer if the law requires us to.
8. Security
We take reasonable steps to protect the information in our care:
- Administrator sessions are signed with a server-held secret key using HMAC-SHA256 and stored in
HttpOnlycookies. Passwords are never handled by our own code. - The database service key and authentication secret live only on the server. Browsers never receive the privileged database key; public listing data is read using a separate anonymous key, and admin writes happen server-side behind authentication.
- All form input is validated and sanitised on the server, and every state-changing administrator request must carry a valid CSRF token.
- Authentication and admin endpoints are rate-limited.
- The site is served over HTTPS in production, and session cookies are marked
Securethere. - Supabase provides password storage and database access security for us.
No method of transmitting information over the internet is completely secure. Please use a strong, unique password for your administrator account, and sign out when you finish a session on a shared device.
9. Your rights and correction / deletion requests
You have the right to know what personal information we hold about you, to ask that inaccurate information be corrected, and to request that your data be deleted. Because we do not provide self-service account tools, please send your request to:
Email: contact.kashmirlocal@gmail.com
Please include enough information to identify you (for example, the email address associated with your administrator account, or the name of the business listing concerned). We will verify your identity where appropriate and respond within a reasonable time, and usually within 30 days.
Business owners may also ask that their listing be corrected or removed by writing to the above address with the business name and a description of the change.
10. Privacy and children
KashmirLocal is not intended for children under 18 years of age. We do not knowingly collect personal information from children. If you believe we have collected personal information from a child, please contact us and we will remove it.
11. Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will update the date shown at the top of this page. For any material change we will post a notice on this page so you can review the updated policy before it takes effect.
12. Contact / Grievance
Email: contact.kashmirlocal@gmail.com
KashmirLocal, Jammu & Kashmir, India.
Website: https://kashmirlocal.com