Privacy Policy
Legistro ("we", "us", "our") is committed to protecting the privacy of advocates, visitors, and anyone who interacts with our platform. This policy explains what data we collect, why we collect it, how we use it, and your rights.
1. Data We Collect
| Category | Examples | Source |
|---|---|---|
| Account information | Name, email, password (hashed) | You provide at registration |
| Advocate profile data | Enrollment number, bar council, photo, bio, practice areas, phone | You provide during profile setup |
| Identity documents | Bar Council ID scan, enrollment certificate | Uploaded voluntarily for verification |
| Usage data | Pages visited, search queries, profile views, session duration | Automatically collected |
| Inquiry data | Name, phone, email, message of persons submitting inquiries | Submitted by visitors |
| Payment data | Transaction ID, subscription plan, amount | Razorpay (we do not store card details) |
| Technical data | IP address, browser type, device type, cookies | Automatically collected |
2. How We Use Your Data
- Providing the service: Creating and displaying advocate profiles, processing inquiries, managing subscriptions.
- Verification: Reviewing uploaded documents to grant the Verified Enrollment badge.
- Communication: Sending inquiry notifications, OTP codes, subscription receipts, and platform updates.
- Analytics: Understanding how advocates and visitors use the platform to improve features.
- Legal compliance: Retaining records as required under Indian law (e.g., IT Act 2000, GST).
3. Sharing of Data
We do not sell your personal data. We share it only with:
- Razorpay — payment processing (governed by Razorpay's Privacy Policy)
- MSG91 / SMS providers — OTP delivery
- Telegram — if you connect Telegram for inquiry alerts
- Cloud hosting providers — server infrastructure (data stored in India)
- Law enforcement — when required by a valid court order or statutory obligation
4. Advocate Profile Visibility
- Profiles marked "approved" are publicly visible in the directory and may be indexed by search engines.
- Your phone number is shown on your profile only if you enable "Show Phone" in your settings.
- Uploaded identity documents are stored privately and are only accessible to Legistro administrators for verification purposes.
5. Cookies
We use essential cookies for session management and authentication. We do not use advertising or third-party tracking cookies. You may disable cookies in your browser, but this will affect your ability to log in.
6. Data Retention
- Account data: retained while your account is active, and for 2 years after deletion.
- Payment records: 7 years (GST compliance).
- Uploaded documents: deleted within 30 days of account deletion upon request.
- Usage logs: 90 days.
7. Your Rights
Under the Information Technology (Amendment) Act 2008 and applicable Indian data protection law, you have the right to:
- Access the personal data we hold about you.
- Correct inaccurate data.
- Request deletion of your account and associated data.
- Withdraw consent for optional data uses (e.g., marketing emails).
To exercise any of these rights, email us at privacy@legistro.com.
8. Security
We use industry-standard measures to protect your data: HTTPS encryption in transit, hashed passwords, private storage for uploaded documents, and role-based access controls. No system is 100% secure; please use a strong, unique password and report any suspected breach to us immediately.
9. Children
Legistro is not directed at children under 18. We do not knowingly collect data from minors.
10. Changes to This Policy
We may update this policy periodically. We will notify you by email and post the updated date above. Continued use constitutes acceptance.
11. Contact
Privacy questions or requests: privacy@legistro.com · Contact page