How Golden Connects Protects Your Data
At Golden Connects, the foundation of everything we do is trust. You share your business relationships, your professional contacts, and your personal details with us — and we take that responsibility seriously. This article explains what we do to protect your data, what rights you have, and how we stay accountable.
We Follow the Law — Both Indian and International
Golden Connects is built and operated in India, and we comply with the Digital Personal Data Protection (DPDP) Act, 2023 — India's foundational data protection law. For members and chapter admins based in the European Union or the United Kingdom, we apply GDPR (General Data Protection Regulation) standards on top of that. In practice, this means every member — regardless of where they are in the world — gets the same strong protections.
You Must Agree Before We Process Your Data
Before you join Golden Connects — whether through a chapter application form or an invite link — we ask you to explicitly read and agree to our Privacy Policy and Terms of Service. This isn't a buried checkbox. It's a clear, confirmed agreement at the moment of signup.
We record the date and time of your consent. If we update our policies in a meaningful way, we'll ask you to confirm again. You can read the full policies at any time:
- Privacy Policy →
- Terms of Service →
You Control Your Cookies
When you visit goldenconnects.com, we don't load any tracking or analytics tools until you say it's OK.
We use Google Analytics (with Consent Mode v2) to understand how the platform is used. By default, analytics are turned off. When you visit for the first time, you'll see a cookie banner with three clear choices:
- Essential — required for login and session management (always on)
- Analytics — helps us improve the platform (off by default, opt-in)
- Marketing — third-party tags loaded via Google Tag Manager (off by default, opt-in)
You can change your preferences at any time from the Cookie Preferences page. We never use cookies to build advertising profiles or sell your data to third parties.
Your Rights — And How to Use Them
Under both DPDP and GDPR, you have clear rights over your personal data. Here's what they mean in practice, and how to exercise each one inside Golden Connects:
Right to Access
You can download a complete copy of your data — your profile, gives, introduction history, scores, badges, and notification preferences — in a single JSON file. Go to Dashboard → Profile → Privacy & Data → Download my data.
Right to Rectification
You can update your name, business name, designation, phone, city, and profile photo at any time from your profile settings.
Right to Erasure ("Right to be Forgotten")
You can permanently delete your account from Dashboard → Profile → Privacy & Data → Delete my account. When you delete your account:
- Your email, phone, city, and photo are immediately anonymised
- Your password is cleared
- Your notification preferences are deleted
- Your gives and introduction history are de-identified and retained only to preserve chapter records (other members' introductions reference this activity)
- Remaining aggregate data is automatically deleted within 365 days by our data retention system
Right to Restriction
If you believe your data is being processed incorrectly but don't want to delete your account, you can request restriction of processing from the same Privacy & Data page. This pauses all non-essential processing of your data and stops all email communications until you lift the restriction.
Right to Portability
The "Download my data" export is machine-readable JSON — suitable for portability requests.
Right to Object
You can opt out of marketing and digest emails at any time. Every email we send includes a one-click unsubscribe link in the footer, and you can manage all preferences from Dashboard → Profile → Notifications. Transactional emails (like introduction alerts and password resets) are not affected by marketing opt-outs.
Data Minimisation — We Only Collect What We Need
We don't ask for information we don't use. Here's what we collect and why:
| Field | Why we need it |
|---|---|
| Name | To identify you to your chapter members |
| Login + transactional notifications | |
| Business name, designation, industry | So others can understand what you do and who you can introduce |
| Phone (optional) | Contact detail for introductions — visible to approved connections |
| City (optional) | Helps with location-relevant gives |
| Profile photo (optional) | Puts a face to the name in chapter introductions |
We don't collect government IDs, financial information, or special category data.
Automated Data Retention
We don't keep data forever. Our platform runs automated, scheduled data deletion so that old data doesn't silently accumulate:
| Data | Kept for |
|---|---|
| Active member accounts | While subscription is active |
| Anonymised member records after self-deletion | 365 days |
| Rejected applications | 90 days |
| Approved applications | 30 days after approval |
| In-app notifications | 6 months |
| Archived gives | 24 months |
| Access requests (website form) | 12 months |
Password Security — Including Breach Detection
When you create or reset a password, Golden Connects checks it against the HaveIBeenPwned database — a publicly known list of passwords that have appeared in data breaches worldwide. If your chosen password has ever been compromised, we'll ask you to pick a different one. This check happens using a privacy-safe k-anonymity method: we never send your full password to any external service.
Passwords are stored using bcrypt (12-round hashing). We don't store plain-text passwords anywhere.
Authentication Security
Your login session is protected by cryptographic JWT tokens stored in httpOnly cookies — meaning your authentication token is invisible to browser scripts and cannot be stolen via cross-site scripting (XSS). When you log out, both the session cookie and the refresh token are immediately cleared server-side. Login attempts are rate-limited per IP address to prevent brute-force attacks.
Who Can See Your Data
Different roles in Golden Connects have different access levels:
Other chapter members can see your name, business name, designation, industry, profile photo, city, and your active gives. They cannot see your email, phone, login history, or score breakdown unless an introduction is approved.
Your chapter admin can see your full profile, manage your membership, and view chapter-wide activity. They cannot access other chapters' data.
Region owners have read-only access to member directories and health metrics across chapters in their region. They cannot modify your account.
Platform administrators can access all data for account recovery, abuse handling, and billing. All sensitive actions taken by platform administrators are recorded in an immutable audit log.
Our Sub-Processors
We use the following third-party services to operate the platform:
| Provider | Purpose | Location |
|---|---|---|
| MongoDB Atlas | Database hosting | Mumbai (India) |
| Vercel | Application hosting and edge delivery | US/EU |
| Resend | Transactional email delivery | United States |
| Google Analytics | Platform usage analytics (consent-gated) | United States |
| helpguides.app | Knowledge base and help articles | — |
All providers are bound by Data Processing Agreements (DPAs). You can view the full sub-processor list at goldenconnects.com/dpa.
For Chapter Admins — Your Responsibilities
When you run a chapter on Golden Connects, you are the data controller for your members' personal data. Golden Connects is your data processor — we act on your instructions. This means:
- You're responsible for approving members based on legitimate business interest
- You should not share member contact details outside the platform
- If you become aware of a data incident, notify us at
hello@goldenconnects.comwithin 24 hours
You can read the full Data Processing Addendum between chapter admins and Golden Connects at goldenconnects.com/dpa-chapter. Your Privacy & Data page (Admin → Data & Privacy) shows exactly what member data is held, who can see it, and for how long.
Contact Us
For any questions, data requests, or privacy concerns, contact us at hello@goldenconnects.com. We aim to respond within 5 business days. For formal data subject requests (access, erasure, portability), use the self-service tools in your dashboard — or email us if you need help.
If you are in the EU and feel your request was not handled properly, you have the right to lodge a complaint with your national Data Protection Authority.
Last updated: May 2026 · Golden Connects
Created by Mohnish
Last updated: May 29, 2026
