Privacy Policy
Last updated: 27 August 2026
Raninagar-Atrai Online Seba app and website are operated by ALISHA SOFT IT. This policy explains what information the app and related website collect, use, store, share and delete. Please read it before using the app or submitting information.
1. Information we collect
The information required depends on the feature you use. You do not need to provide every type of information to use every feature.
- Account and authentication: name, email, Firebase UID, login provider (Email/Password or Google Sign-In), and any profile phone number or photo you choose to add. We do not store passwords in plaintext in the database.
- Blood donor information: name, blood group, phone, age, thana, address, last donation date, donation count, photo/image URL, user ID, approval/status and timestamp.
- Blood requests and health-related information: patient name, blood group, required date, number of bags, haemoglobin/Hb, age, hospital, thana, phone and free-text details. This is collected to provide an emergency community service.
- Marriage biodata: name, marital status, birth year, height, weight, complexion, blood group, permanent and present address, upbringing location, education, phone, details, biodata number, approval/status and timestamp.
- Complaints, suggestions, comments and reports: name (which may be blank in anonymous mode), phone, upazila, union, category, title, message, comments, support/report activity, user ID, status and timestamp.
- Images and media: secure URLs for images that you submit with a complaint or other submission. Images may be sent to Cloudinary's upload service.
- Education, jobs, shops, rentals and directory listings: depending on the listing, name, phone, address/location, education/job details, price/salary, gender, image, social link and description. Information you voluntarily publish may become a public listing.
- Orders and delivery: if you use shopping features, name, phone, delivery address/village/union, user-provided location, cart items, delivery charge, total, order status and timestamp.
- Notifications and device/app information: Firebase Cloud Messaging token, notification title/body, optional image URL, read/last-seen state, app version, device model and Firebase Analytics usage events when those features are enabled.
- Advertising information: Android Advertising ID and advertising-related information if AdMob is enabled. This processing does not apply when advertising is disabled.
2. How we use information
- To create accounts, sign users in, update profiles and protect accounts.
- To provide blood donor/request, hospital, ambulance, education, job, shop, transport, directory, biodata and other community services.
- To receive, moderate and manage complaints, suggestions, comments, support and reports.
- To show a public listing or request when you choose to publish it.
- To send important notifications and service updates.
- To understand feature usage, reliability and technical problems when Firebase Analytics is enabled.
- To show and measure ads when AdMob is enabled.
- To prevent abuse, spam, fraud and security incidents and to meet legal obligations.
3. Public content and sensitive information
Information submitted as a public listing may be visible to other users. Think carefully before adding phone numbers, addresses, health-related details, photos or family/personal details to a blood listing/request, biodata, complaint, tuition, shop, rental or directory entry. Make sure you have the right and consent to submit another person's information.
An anonymous option may still leave an account UID, timestamp or technical metadata in the system. Do not submit passwords, national ID numbers, bank/card information or unnecessary sensitive information in public content.
4. Who we share information with
- Google Firebase: Authentication, Realtime Database, Cloud Messaging, Analytics and related hosting/services.
- Google Sign-In: for authentication when you choose Google login.
- Cloudinary: to store and deliver user-uploaded complaint or media images.
- AdMob/Google Mobile Ads: for advertising and measurement when ads are enabled.
- Notification/account backend: authenticated requests may be sent to `notification-server-steel.vercel.app` to process notifications and account-deletion requests. The server is intended to verify the Firebase ID token before the deletion workflow.
- Legal or safety reasons: valid government requests, court orders, fraud/security investigations or protection of rights.
We do not sell personal information. Third-party providers may process data under their own privacy policies and service terms.
5. Data security
We aim to use HTTPS/TLS-secured connections for data in transit and use Firebase Security Rules and authenticated access where applicable. Internet services, devices, public listings and third-party providers are not completely risk-free, and we cannot guarantee the privacy of information you intentionally publish publicly.
6. Data retention
Information may be retained for as long as needed to operate the account and services, moderate content, resolve disputes, protect security and meet legal requirements. When account deletion is completed, the deletion workflow is used to remove relevant Firebase records. Cloudinary images, notification/backend logs and provider-side backups or logs may follow the provider's systems and legal retention periods.
7. Account and data deletion
You may use Profile → Delete Account in the app or submit a request through the website's Account Deletion page. Re-authentication may be required. The successful deletion workflow is intended to remove the Firebase Authentication account, user profile and in-scope records associated with your UID, including donor/request, complaint, comment, support/report, biodata, tuition and order records. Public or third-party copies, legal records, security logs or references held in another user's separate record may not be removed immediately or completely where retention is required.
8. Children
The app is not directed to children. We do not knowingly seek to collect account or personal information from children under 13.
9. Permissions and device access
Notification permission and user-selected photo/media access may be needed for particular features. Where the app does not have GPS location permission, it does not collect the device's precise location itself; locations in listings and orders are generally entered or linked by the user.
10. Your rights and contact
You may request correction or deletion of your profile or listing and may raise privacy questions through the website's Contact page. Do not send passwords, national ID, bank information or unnecessary sensitive data through the contact form.
11. Changes to this policy
We may update this policy when features, providers or legal requirements change. The updated version and date will be published on this page.