Legal Document

Privacy Policy

Effective date: 1 July 2026 · Compliant with DPDPA 2023 (India) · Operated by Bishnu Dev Changkakoti · insiderOne Technologies FZE LLC / Aurist Private Limited

1. Who We Are

TISH Protocol is operated by Bishnu Dev Changkakoti (insiderOne Technologies FZE LLC / Aurist Private Limited) ("we", "us", "operator"). We operate tishlabs.com and provide the TISH loyalty point infrastructure to connected platforms.

Data Protection Contact: tishlabs@insiderone.in

2. Data We Collect

What you give us directly: Email address (waitlist and account registration), name (optional), communications you send us.

What we collect automatically: TISH earn and spend events (pseudonymous, stored as user ID not email), platform actions that trigger TISH, device type, browser, IP address (used for fraud detection, not profiling), timestamps.

What we do not collect: Payment information (we do not process payments), sensitive personal data (caste, religion, health, biometrics), data from minors under 18.

3. Why We Collect It: Legal Basis

Contract performance: To operate your TISH account, maintain your balance, calculate your tier, and deliver benefits you signed up for.

Legal compliance: To comply with Indian IT Act, DPDPA 2023, anti-fraud obligations, and any applicable financial regulation.

Legitimate interest: Fraud prevention, abuse detection, platform security, and product improvement.

Consent (where required): Marketing communications. You may withdraw consent at any time by emailing tishlabs@insiderone.in.

4. How We Use Your Data

We use your data to: operate and maintain your TISH account; calculate earn rates, tiers, and rebates; prevent fraud and abuse; communicate service updates; comply with legal obligations; and improve the platform.

We do not sell your data to third parties. We do not use your data for advertising profiling. We do not share your data with any party except as described below.

5. Data Sharing

Connected platforms: When you earn TISH on a connected platform (e.g., Career OS, Ricorda), that platform shares a pseudonymous user ID and action type with TISH Protocol. We do not receive your name or email from platforms.

Service providers: We use Supabase (database infrastructure). Supabase processes data under our instructions and is bound by data processing agreements.

Legal requirements: We may disclose data if required by Indian law, court order, or competent authority. We will notify you where legally permitted.

6. Data Retention

Account data is retained for the duration of your account plus 3 years after closure (required for legal compliance under Indian law).

TISH ledger records (earn/spend history) are retained indefinitely as they form part of the public audit trail described in the TISH Constitution. These records are pseudonymous.

Waitlist emails that do not convert to accounts are deleted after 24 months.

7. Your Rights under DPDPA 2023 (India)

You have the right to: access the personal data we hold about you; correct inaccurate data; erase your personal data (subject to legal retention requirements); withdraw consent where processing is based on consent; nominate a person to exercise rights on your behalf.

To exercise any of these rights, email: tishlabs@insiderone.in. We will respond within 30 days.

8. Your Rights under GDPR (EU/UK)

If you are in the EU or UK, you additionally have the right to data portability and the right to lodge a complaint with your local supervisory authority. We are not established in the EU; our representative for GDPR purposes is insiderOne Technologies FZE LLC.

9. Cookies and Analytics

We use Google Analytics 4 (GA4) to understand how visitors use this site. GA4 collects anonymised usage data including pages visited, time on site, and approximate location (country/city level). This data is processed by Google LLC under their privacy policy. GA4 sets cookies in your browser to distinguish visits. We do not use advertising or remarketing cookies. No other third-party tracking scripts are loaded on this site.

You may opt out of GA4 data collection by installing the Google Analytics Opt-out Browser Add-on or by enabling “Do Not Track” in your browser settings.

10. Children's Privacy

TISH is not directed at users under 18. We do not knowingly collect data from minors. If you believe a minor has registered, email tishlabs@insiderone.in and we will delete the account immediately.

11. Data Security

We implement industry-standard security measures including encryption in transit (TLS), encryption at rest, access controls, and regular security reviews. No system is 100% secure. In the event of a breach affecting your rights, we will notify you within 72 hours as required by applicable law.

12. Changes to This Policy

We will notify you of material changes via email at least 30 days before they take effect. Continued use constitutes acceptance.

13. Contact

Privacy queries: tishlabs@insiderone.in
Grievance Officer: tishlabs@insiderone.in
Postal: TISH Labs, c/o Aurist Private Limited, India

Last updated: 1 July 2026. Compliant with Digital Personal Data Protection Act, 2023 (India).