ShalaERP

Privacy Policy

ShalaERP holds children's records and a school's salary bill, so this page is written to be read rather than to be technically compliant. It says what the software collects, who else touches it, where it lives, and what you can ask us to do about it.

Last updated 27 July 2026

Who we are

This website and the ShalaERP software are operated by ShalaERP, a sole proprietorship run by Ankur Singhal and based in Jaipur, Rajasthan, India. You can reach us at sales@shalaerp.com or +91 94606 50122.

Because ShalaERP is a sole proprietorship rather than a company, Ankur Singhal is personally the individual accountable for how data is handled, and is the person your grievance reaches.

Two different relationships — this matters

Almost every question about a school ERP and privacy comes down to who decides what data is collected. There are two separate situations here, and we are in a different role in each.

When you browse this website or send us a demo enquiry, we decide what to collect and why. In the language of India's Digital Personal Data Protection Act, 2023, we are the Data Fiduciary for that information.

When your school uses ShalaERP, your school decides which student and staff records are entered, which optional fields are filled, and who on its staff may see them. The school is the Data Fiduciary. We are a Data Processor, handling that data only to provide the service the school has asked for, and only on the school's instructions. We do not decide what goes into your students' records, and we do not use those records for our own purposes.

What we collect from website visitors

  • Demo enquiries: the school name, your name, your phone number, an approximate student count, and any note you add. This reaches us by email so we can reply — nothing more.
  • Aggregate website analytics through Vercel Analytics, which counts page views and performance without cookies and without building a profile of you.
  • Your light/dark theme choice, stored in your own browser's local storage. It never leaves your device and never reaches us.
  • We do not run advertising or third-party tracking scripts on this site, and we do not use cookies to follow you between sites.

What the software stores on a school's behalf

This is the honest, complete picture of the categories a school can put into the system. Most fields are optional — a school chooses how much to fill in, and many schools leave the sensitive ones blank.

  • Students: name, date of birth, photograph, address, class, section, roll and admission numbers, blood group, category, and Aadhaar number where a school chooses to record it.
  • Guardians: father's and mother's names, guardian phone number and email address.
  • Student activity: daily attendance, fee liability and payments, receipts, concessions, exam marks and report cards, and certificates issued such as transfer and bonafide certificates.
  • Staff: name, contact details, date of birth, photograph, addresses, emergency contact, blood group, Aadhaar number, PAN, and bank account number, IFSC and branch where payroll is used.
  • Staff activity: attendance, leave applications, approvals and balances, salary structures, monthly payroll runs and payslips.
  • Uploaded documents: whatever a school attaches to a record — commonly birth certificates, transfer certificates, Aadhaar copies, caste certificates, medical records, staff documents and leave attachments.
  • Device tokens: if a staff member installs the Android app, an anonymous push-notification token for their device, so notices and leave decisions can reach their phone.
  • An audit log of which user changed which record and when, which exists precisely so a school can answer that question later.

Children's data

Most records in a school ERP are about children, and we treat that as the most sensitive thing the system holds.

Under the DPDP Act, processing a child's personal data requires verifiable consent from a parent or guardian. That consent is obtained and held by the school, as the Data Fiduciary and the party with the actual relationship with the family. We process children's data only to provide the software to the school.

We never use children's data for advertising, profiling, tracking, or behavioural monitoring of any kind. ShalaERP also has no parent or student login at all — only school staff can sign in, which keeps the number of people who can reach a child's record as small as the school decides.

What we never do with school data

  • We never sell, rent or trade school, student or staff data. There is no circumstance in which this changes.
  • We never use it for advertising, and we run no ad networks in the software.
  • We never use a school's data to train artificial-intelligence or machine-learning models, our own or anyone else's.
  • We never share one school's data with another. Isolation is enforced in the database itself, not just in the interface.
  • We do not read school records out of curiosity. Staff access happens only when a school asks us for support, or when we must investigate a fault.

Who else handles the data

We do not run our own data centres. A small number of infrastructure providers process data on our behalf, each under their own security commitments:

  • Supabase — the database, sign-in system and file storage that hold every school record and uploaded document.
  • Vercel — hosting for the web application and this website, which means it handles the network requests between your browser and the software.
  • Google Firebase Cloud Messaging — delivers push notifications to the Android app. It receives only the device token and the text of the notification, never your student or financial records.
  • Vercel Analytics and Speed Insights — aggregate, cookieless usage and performance figures.
  • Google Firebase Crashlytics — receives a report when the Android app stops unexpectedly, so the fault can be found and fixed. What a report contains, and what it is scrubbed of first, is described under “The Android app on your phone”.
  • Website demo enquiries are additionally sent to us by email through Resend, and reach our own mailbox.

Where the data is stored

School data is stored on servers in Singapore, which means it is transferred out of India and processed there. We are telling you this plainly because the DPDP Act expects cross-border transfer to be disclosed, and because some schools have a policy about it — if that is your school, raise it with us before you buy rather than after.

Singapore is the region closest to India offered by our database provider, which is why it was chosen: it keeps the software responsive for Indian schools. India has not restricted transfers to Singapore, and we will move the data if that ever changes.

Data is encrypted in transit using HTTPS everywhere, including from the Android app.

The Android app on your phone

The staff app keeps a little data on the device itself, and sends two things you did not type. Both are listed here because Google Play requires them to be declared, and a declaration that does not match this page is worth nothing.

  • A push-notification token, so the server knows which device to send a notice or a leave decision to. It identifies a device, not a person, and it is removed when you sign out.
  • A crash report, in released versions, when the app stops unexpectedly. Reports are deliberately built not to identify anyone: they carry your role, your school's identifier and which kind of screen you were on — enough to reproduce a fault, not enough to name you. No user ID, no email address and no name is attached, and the screen is recorded as a pattern rather than the actual record you were looking at. Before a report leaves the phone it is scrubbed of any Aadhaar number, email address, phone number, web address or sign-in credential that a technical error message happened to contain.
  • Your sign-in session, stored on the phone encrypted with a key held in the device's hardware-backed keystore.
  • Attendance you have taken but not yet submitted, so a register taken in a classroom with no signal is not lost. It is sent when the device reconnects and removed once accepted. Marks and money are never held this way.
  • A small cache of class lists, so those screens open quickly.
  • Automatic cloud backup is switched off for the app, so none of the above is copied into your personal Google account. Signing out clears the session and removes the device's notification registration.

What the app asks permission for

The Android app asks for one permission: notifications. It asks after you have signed in rather than on first launch, so you are deciding about something you have seen, and declining costs you nothing but the notifications.

It does not request location, contacts, camera, microphone, photos, SMS or call logs. There is no advertising and no analytics or tracking software in the app — nothing you do in it is profiled. ShalaERP has no sign-up, no password reset and no self-registration: your school issues your credentials, so an account can neither be created nor deleted from inside the app. Ask your school's administrator to revoke it and access ends immediately.

How long we keep it

While a school's subscription is active, its records are kept for as long as the school wants them — school records need to be retrievable years later, so we do not quietly expire them.

When a subscription ends, the school has 30 days to export whatever it needs, after which the data is deleted. Encrypted nightly backups are retained for about 30 days and are then overwritten, so deleted data disappears from backups within roughly that window too.

Demo enquiries from this website are kept only as long as the conversation is live. Ask us and we will delete yours.

How the data is protected

These are the specific measures in place, described so you can check them rather than take an adjective on trust:

  • Each school's records are isolated at the database level through row-level security, so the boundary holds even if application code has a bug.
  • What each role may see and do is decided on the server on every page and every change, not merely hidden in the interface.
  • Passwords are handled by the sign-in system and never stored by us in a readable form.
  • Fee collection, marks import and payroll runs are committed as single transactions, so an interrupted save cannot leave a half-written financial record.
  • An audit log records who changed what, and deleted records go to a recycle bin with undo rather than vanishing.
  • Encrypted per-school backups run nightly and can be restored.
  • We hold no third-party security certification such as ISO 27001 or SOC 2, and we will not imply otherwise. If a certification is a requirement for your school, tell us and we will be straight with you about where we stand.

Your rights over your data

You can ask to see the data held about you, have it corrected, or have it erased. How to do that depends on which relationship you are in.

If you are a parent, guardian, student or staff member of a school that uses this software, please approach the school first. The school controls those records and can correct them directly — we cannot change a school's records on a third party's instruction, and it would be wrong of us to try. Where the school needs our help to fulfil your request, we help.

If you sent us an enquiry through this website, write to sales@shalaerp.com and we will delete it.

To request deletion of data held about you in a school's ShalaERP records, write to ankursinghal060@gmail.com with "Deletion request" in the subject. We will route it to your school, which holds the decision, and support them in acting on it. We cannot erase a school's records on our own initiative — that is what the two relationships above mean in practice.

The Android app has no sign-up and no account deletion, because it creates no accounts: your school issues and revokes them. There is therefore nothing to delete from inside the app, and asking your school's administrator to revoke your login ends your access immediately.

Complaints

If something about how we handle data concerns you, write to Ankur Singhal at sales@shalaerp.com with "Privacy" in the subject. We aim to reply within 30 days.

If you are not satisfied with our response, you may escalate to the Data Protection Board of India under the DPDP Act, 2023.

Changes to this policy

We will update the date at the top of this page whenever this policy changes. If a change materially affects how school data is handled, we will email the admins of every school using ShalaERP rather than rely on you noticing the page.