Privacy Policy
Last updated
- You sign in with Google. We get your name, email address and profile photo. We never see your Google password.
- We collect only what is needed to run a book library: who you are, your requests, and, if you share a book, its photos and your phone number.
- Your email and phone number are shown to a borrower only after you accept their request. Nobody else can see them.
- We don't sell your data, run ads or use trackers.
- You can ask us to show, correct or delete your data at any time.
1. Who we are
This policy explains how The Cloud Library Collective (“we”, “us”) handles personal data on this website and in the book-sharing service run through it (the “Library”). We are a community library run by volunteers on a not-for-profit basis. The volunteers we appoint to run it are called “admins”. For the data described here, we decide why and how it is used.
This policy goes with our Terms of Service.
2. What we collect
- From your Google account, when you sign in: your name, email address and profile photo. That is all we ask Google for.
- Your membership: a member ID, your status (for example pending, active or blocked), your credit balance, any black stars, and the record of credit changes (the “ledger”).
- Your activity: book requests you make or receive, your answers to them, hand-over and return confirmations or reports, and their dates.
- If you share a book: its title, author, condition and photos, the loan period you choose, and your phone number.
- Anything you send an admin, for example when you ask about a black star.
- Basic technical data. Our website host, Vercel, and the services we use, such as Google, may log things like your IP address and browser type when you visit. We don't build profiles from this.
We don't ask for your home address, your date of birth, payment details or any government ID.
3. Why we use it
Only to run the Library:
- to check who you are and keep your account secure;
- to approve members, list books and let admins decide what a book is worth from its photos;
- to pass requests between owners and borrowers, and to introduce them once a request is accepted so they can arrange the hand-over;
- to track credits, hand-overs, returns, lost books and black stars, and to apply the rules in our Terms;
- to email you about your requests, hand-overs, returns and account (these emails are about the Library only and don't contain other members' contact details);
- to keep records, fix problems and prevent misuse.
We rely on your consent when you join and sign in, and on what is needed to provide the service you asked for. We don't sell your data, we don't run ads, and we don't use it to profile you.
4. Who can see what
- Admins can see what is needed to run the Library: members' names and emails, requests, deposits with their photos and phone numbers, black stars and credit records.
- A book's owner sees your name and your request. They don't see your email, phone number or credit balance.
- A borrower sees the owner's name, email and phone number only after that owner accepts their request, and only while the hand-over is in progress. Until then, the site shows them as hidden. This is enforced on our server, not just on the page.
- Other members and visitors see the catalog only: title, author, condition, credits and availability. They can't see who owns a book.
- Your black stars and credit history are visible to you and to admins. They aren't shown to other members.
If you receive another member's details, our Terms say you may use them only to arrange that hand-over.
We may share data if the law requires it, or where it's needed to protect someone's safety. Apart from that, we don't share it with anyone else.
5. Sign-in with Google
We use Google Sign-In only to confirm who you are. We request your name, email address and profile photo, and no other Google data. We can't see your Google password, your Gmail, Drive, contacts or anything else in your Google account.
Our use of information we get from Google is limited to providing and improving the Library's own features described here. We don't use it for advertising or sell it.
You can stop the Library using your Google sign-in at any time in your Google account's connections settings. Use “Sign out” on the site to end your session on this device. To have your Library data deleted as well, contact us (section 13).
6. Where your data is kept
- Google Sheets and Google Drive, under the admins' Google account, hold membership records, requests, the ledger and deposit photos. Photos sit in a private folder shared only with the admins who value books.
- Google Apps Script runs our back end and sends notification emails through Google.
- Vercel hosts the website.
- Google Fonts supplies the typefaces on our pages, so your browser contacts Google when a page loads.
These providers may store and process data on servers outside India, and have their own terms and privacy policies. We choose services we think are reasonable for a small volunteer library, but we can't control how they run.
7. Cookies and browser storage
We don't use advertising or analytics cookies. The site stores a little in your browser to work:
- Session storage: your signed-in session, which is cleared when you close the tab.
- Local storage: your light or dark choice, and a marker that lets Google sign you back in quietly if you have signed in before. Signing out removes the marker.
Google may set its own cookies when you use Google Sign-In. Those are governed by Google's policies.
8. How long we keep it
- Your account details, requests and photos are kept while you're a member, and for a while after so we can settle anything unfinished.
- Some records, such as completed hand-overs, black stars, and the credit ledger, may be kept longer where that's needed for safety and fairness, and to stop someone avoiding a block by starting a new account.
- When you ask us to delete your data, we delete or anonymise what we don't need to keep, promptly.
9. Your rights and choices
You can ask us to:
- tell you what data we hold about you and give you a copy;
- correct anything that's wrong or out of date;
- delete your data, or close your account (see the limits in section 8);
- stop using your data for a purpose you no longer agree to. You can withdraw your consent at any time, though we may then be unable to keep your account open;
- name someone to exercise these rights for you if you die or become unable to.
Write to us using the contact in section 13. We may need to check it's really you first, and we'll reply within a reasonable time.
10. Keeping data safe
We take sensible steps for a small volunteer service: your Google sign-in is checked on our server for every request, other members' contact details are never sent to the browser until a request is accepted, the deposit photos folder is private, and only a few admins have access to the records. No system is perfectly secure, so we can't promise absolute security. If a breach affects your data in a way that could harm you, we'll tell you.
11. Children
The Library is for people aged 18 or over and we don't knowingly collect data from anyone younger. If you think a child has joined, tell us and we'll delete the account.
12. Changes to this policy
We may update this policy. We'll change the “last updated” date at the top and, for important changes, say so on the site or by email.
13. Contact and complaints
Questions, data requests, or to raise a concern: an admin (see the contact details on the site). If we don't sort it out, you can also complain to the Data Protection Board of India once it's operating, or to the courts of Bengaluru. This policy is governed by the laws of India.