Skip to content

Legal

Privacy Policy

How Ratnagiri District Athletics Association collects, uses, stores, and protects personal information across this website.

Effective date: 9 September 2026

On this page

1. Who operates this website

This website is operated by Ratnagiri District Athletics Association (“RDAA”, “we”, “us”), affiliated to the Maharashtra Athletics Association, for the administration of district athletics events across the nine talukas of Ratnagiri, Maharashtra.

Legal status: a society registered under the Societies Registration Act, 1860, registration no. MH-3286/Ratnagiri (registered as "Ratnagiri District Amateur Athletics Association"). Address: 3467, Parvati Sadan, Miryabandar Road, Ratnagiri, Maharashtra 415612.

This policy is written to reflect what this website actually does, in plain language, consistent with the Digital Personal Data Protection Act, 2023 (“DPDP Act”) and the Digital Personal Data Protection Rules, 2025. It does not by itself make the website “certified” or “fully compliant” with any law — it is a good-faith description of our actual practices, kept up to date as those practices change.

2. Scope

This policy covers personal information collected through ratnagiriathletics.in and any successor domain — the public marketing pages, the event-application (“Apply”) flow, the application-status lookup, and the photo gallery. It does not cover third-party websites we link to (see “Third-party links” in our Disclaimer).

3. Personal data we collect

Information you provide when registering an athlete for an event (the /apply form — the only place the public site asks for personal information):

  • Full name of the athlete
  • Date of birth (used to calculate the correct age-group category)
  • Gender
  • WhatsApp number
  • Email address
  • Taluka (sub-district, within Ratnagiri district)
  • Selected event and competition events (e.g. 100m, Long Jump)
  • Optionally, a screenshot of your UPI/bank payment as proof of payment (see “Payment processing” below)

We do not ask for a government-issued ID number, full postal address, bank account/card numbers, or a profile photo of the applicant anywhere on this site.

Information collected automatically: standard web server/hosting logs (e.g. IP address, browser/device information) generated by our hosting provider (Vercel) and database provider (Google Firebase) as part of ordinarily operating the website — we do not run any separate analytics, advertising, or tracking script of our own. See our Cookie Policy for the full list of storage mechanisms this site actually uses.

4. Information about minors

RDAA administers age-group athletics categories that include participants under 18 (currently Under 14, Under 16, and Under 18 brackets), so the /apply form will, in the ordinary course of event registration, collect the name, date of birth, and other details listed above for children.

Under the DPDP Act, processing a child’s (under-18) personal data requires verifiable consent from a parent or lawful guardian. The /apply form requires whoever submits the registration to confirm they are either the athlete (if 18 or older) or the athlete’s parent/guardian submitting and consenting on the athlete’s behalf — see the consent statement directly above the submit button on the form. We do not currently run a separate identity-verification step for that confirmation (e.g. verifying the submitter’s own ID), which is a limitation of a self-service, no-login public registration form; RDAA relies on the accuracy of what is submitted, the same way it does for every other field on the form.

We do not knowingly use a minor’s data for any purpose beyond event administration, age-group placement, results publication, and communicating about the specific event registered for.

5. Why we collect this information

  • Event/tournament registration — to register an athlete for a specific RDAA event and the correct competition events within it.
  • Age-group placement — date of birth is used only to calculate which age-group category (e.g. Under 16) an athlete competes in.
  • Communication — to send a registration-confirmation email and, where necessary, to contact an applicant about their registration via the email or WhatsApp number provided.
  • Payment verification — to match a UPI/bank transfer to the correct application (see “Payment processing” below).
  • Duplicate-registration prevention — email and WhatsApp number are used (in hashed form — see below) to detect if the same person has already registered for the same event.
  • Event administration — taluka, gender, and age group help RDAA plan heats, categories, and logistics.
  • Results and rankings — event results are published as PDF documents; see “Publicly displayed information” below.
  • Security and fraud prevention — see “Cookies and similar technology” regarding optional bot-protection.

7. Payment processing

RDAA does not use an integrated online payment gateway. Registration fees are paid directly by the applicant via UPI, to a QR code RDAA displays on the payment step of the /apply flow — that transaction happens entirely within the applicant’s own UPI/banking app and is between the applicant and their bank/UPI provider, not through this website. We never see or store your bank account number, UPI PIN, or card details.

Applicants may optionally upload a screenshot of that payment as proof. That image is stored so an RDAA administrator can manually verify payment against the correct application; it is not publicly visible (see “Who can access applicant data internally” below).

8. Third-party service providers

We use the following service providers to operate this website. Each processes data on our behalf, under their own terms, and none of them are used by us for advertising:

  • Google Firebase (Firestore database, Cloud Storage, Authentication) — stores all application, event, and admin-account data described in this policy.
  • Vercel — hosts and serves this website.
  • Resend — sends the registration-confirmation email (name, email address, and registration details are shared with Resend solely to deliver that email).
  • Google reCAPTCHA (App Check) — where enabled, used only to distinguish real applicants from automated bot traffic on the /apply form; see our Cookie Policy.

We do not sell personal data, and we do not share applicant data with any third party for their own marketing purposes.

9. Publicly displayed information

Event results: RDAA publishes results and rankings for its events as downloadable PDF documents on the public /results pages. Those documents, prepared and uploaded by RDAA administrators, typically include participant names alongside their placings/times — this is standard practice for publishing sporting results and is necessary for the legitimate administration and transparency of a competitive event.

Application status: the /status page shows an application’s details (name, event, payment status) only to someone who already has the exact, system-generated reference number for that application — it is not browsable or searchable, and reference numbers are not published anywhere.

Photo gallery: the public photo gallery currently uses licensed stock photography, not photos of individual RDAA participants.

10. Who can access applicant data internally

Authorised RDAA staff can access applicant data, including payment-proof screenshots, to administer events and verify registrations and payments.

11. Where your data is stored

Our database, storage, and hosting providers (Google Firebase, Vercel) operate global infrastructure, and the specific data-center region for this project depends on how our Firebase project is configured. Where personal data is processed or stored outside India, our providers’ own safeguards apply; RDAA does not separately transfer applicant data to any other third party outside these named service providers.

12. Data retention

We retain application data for as long as reasonably necessary to administer the event registered for, maintain accurate event records and results, and meet any legal or accounting obligations that apply to RDAA. RDAA has not yet fixed a specific retention period or automatic deletion schedule for application records; if you would like your data deleted sooner, see “Your rights” below. Deleting an application record from our admin panel does not automatically delete an associated payment-proof screenshot, if one was uploaded — this is a known limitation, not an intended retention of your data.

13. Security safeguards

Application and payment-proof data can only be browsed or listed by an authenticated RDAA account — the public site can only ever look up one application at a time, and only by its own unique reference number. Registration writes are validated server-side against tampering (for example, an applicant cannot mark their own payment as verified). No system is completely secure, and we cannot guarantee absolute security of information transmitted over the internet.

14. Your rights

Subject to applicable law, you may ask us to:

  • confirm what personal data of yours we hold and access a copy of it;
  • correct or update inaccurate or incomplete data;
  • delete your data, where we are not required to keep it for a legitimate purpose (such as event records already published);
  • withdraw consent for future processing (this does not affect an event registration already completed, or its results record);
  • raise a grievance about how your data has been handled.

To exercise any of these, see our Privacy Rights & Grievance page, or contact us directly (see “Contact” below).

15. Changes to this policy

We may update this policy as the website’s features or our practices change. The “Effective date” at the top of this page reflects the last substantive update.

16. Contact

Privacy questions or requests: registration@ratnagiriathletics.in. General enquiries: registration@ratnagiriathletics.in. For our formal grievance-redressal process, see Privacy Rights & Grievance.