Ponnani Cultural World Foundation (“PCWF”, “we”, “us”) publishes this document to explain what personal data the PCWF Member application and the pcwf.in member administration system collect, why we collect it, how long we keep it, and the choices available to you.

Last updated: 2 October 2026 · Applies to: the PCWF Member Android application (package com.pcwf.member) and the member administration system at pcwf.in/memberadmin.

This document contains two parts. Part 1 is our Privacy Policy. Part 2 is our Terms of Use, which govern your use of the app and our membership services. Both are binding on you when you create an account or submit a membership application.

1. Who We Are

Ponnani Cultural World Foundation is a registered cultural and charitable foundation operating from Ponnani, Malappuram, Kerala, India, with committees and members in India and across the Gulf region, including the United Arab Emirates, the Kingdom of Saudi Arabia, Kuwait, Bahrain, Qatar and Oman.

We are the data controller for the personal data described in this document. We are not a data broker, an advertising network, or a data reseller. We do not sell your personal data and we do not allow third parties to use it for their own advertising purposes.

ItemDetail
Data controllerPonnani Cultural World Foundation
Registered address32/128 Baniyas Tower, Chanthapadi, Ponnani, Malappuram, Kerala, India
Emailinfo@pcwf.in
Telephone+91 75588 33350
Privacy contactinfo@pcwf.in (we route privacy requests to a designated officer)

2. Scope of This Policy

This Privacy Policy applies to personal data that PCWF collects through:

  • the PCWF Member mobile application for Android;
  • the public membership application form on pcwf.in;
  • the member administration portal at pcwf.in/memberadmin;
  • our membership, event and meeting administration, including notification delivery.

It does not apply to third-party websites or services that we merely link to from within the app or this site. Those providers operate their own privacy practices.

3. Information We Collect

We collect only what we need to run memberships, payments, committees, events and meetings. We do not collect your precise or approximate location, your contacts, your messages, your call logs, or your browsing history outside our own apps.

3.1 Information you give us directly

CategorySpecific dataWhen it is collected
IdentityFirst name, last name, usernameMembership application, account profile
ContactEmail address, mobile number, WhatsApp number, emergency contact name and numberMembership application, account profile
AddressPermanent and current address: house details, country, state, postal codeMembership application, account profile
Personal attributesDate of birth, sex, blood group, occupation / jobMembership application, account profile
Government IDGovernment identification number (optional field)Account profile, where voluntarily provided
OrganisationPCWF location, committee, sub-committee assignmentMembership application, administrative assignment
PhotosProfile photograph, event photographs, meeting photographsMembership application, event and meeting creation
Payment evidencePhotograph or file of your membership fee payment receiptMembership application, member record update
AuthenticationPassword (stored only as a one-way salted hash), two-factor secret, two-factor backup codes, biometrics unlock preferenceAccount setup, security settings
Free-text contentMeeting minutes, meeting invitations, notification messages, membership rejection reasonsFeature usage

About blood group. Blood group is requested only as part of the standard membership record, in the same way a physical membership register records it. It is used for welfare and emergency assistance purposes and is available only to authorised committee administrators and office bearers. It is not used for profiling, marketing or automated decision-making.

3.2 Membership and administrative records we create

To operate the membership register we generate and store an internal membership identifier, a membership number, membership start and expiry dates, membership fee status, your role and permissions, your designation history (title, committee, start and end date, responsibilities), and your notification history. Attendance records are created when you check in to a meeting by QR code.

3.3 Device and technical information

DataPurpose
Push notification token (Google Firebase Cloud Messaging device token)Delivering event, meeting and account notifications to your device, and removing that token when you log out
App diagnostic events (timestamps, feature name, outcome)Diagnosing login, biometric unlock and background/resume behaviour. Diagnostics never contain your password, your session tokens or your profile data
Server and application logsSecurity, fraud prevention, and troubleshooting

We do not collect your IP address as a data category in our app records, and we do not build advertising profiles or share your data with advertising networks.

3.4 Permissions you may grant

PermissionWhat we use it forWhat we do not use it for
CameraScanning a QR code on a membership card to check in to a meeting, and scanning a member's QR code for office bearers authorised to do soWe never photograph or record video. The camera is only used while a scan screen is open
Photo library accessSelecting a profile photograph, a payment receipt, or an event or meeting photograph, through the system photo picker. The app receives only the image you chooseWe do not scan or read your library contents
Biometric (fingerprint / face)Unlocking your session on this device and unlocking stored credentials on this deviceFingerprint or face data never leaves your device and is never transmitted to us
NotificationsSending event, meeting and account alerts you have opted into—

If you deny the camera permission, QR scanning is unavailable. The rest of the app continues to work normally.

4. How We Use Your Information

We use your personal data for the following purposes and no others:

  • processing and deciding your membership application, which is reviewed by a human administrator and never by an automated scoring system;
  • creating and maintaining your membership record, membership number and card;
  • processing membership fees, recording payment receipt evidence and tracking fee status;
  • managing committees, office-bearer designations, scope of administrative permissions and location-based access control;
  • publishing and delivering event and meeting information, including invitations and QR-based attendance;
  • sending you notifications about your membership, events and meetings that concern you;
  • verifying your identity when you log in, change sensitive settings, or request account deletion;
  • protecting the security and integrity of our services, preventing fraud and abuse, and diagnosing faults;
  • complying with our legal, tax and regulatory obligations.

Where we rely on consent, you may withdraw that consent at any time by contacting us or by requesting deletion of your account.

5. How We Share Your Information

We do not sell your personal data, and we do not share it for cross-context behavioural advertising.

We share personal data only in these limited circumstances:

  • Service providers acting on our instructions — Google Firebase for push delivery, Google reCAPTCHA for abuse prevention on public forms, and our email delivery provider. These providers process data only to perform services for us and are contractually bound to our instructions.
  • Within PCWF's own administration. — Committee administrators and authorised office bearers can view member records within the geographic and organisational scope assigned to them. Access is logged.
  • At a member's request. — Where you have consented to it, for example where you submit a payment receipt or event photo, or where another member is authorised to scan your membership QR code for check-in or verification.
  • Legal compliance. — Where disclosure is required by Indian law, a court order, or a competent authority. We will notify you unless legally prohibited from doing so.
  • Corporate reorganisation. — If PCWF is merged, restructured or wound up, your data may transfer to a successor entity, which will be bound by this policy.

6. Third-Party Services

We use the following third-party services, each under a separate agreement with us:

ProviderServiceData involved
Google Firebase Cloud MessagingPush notification deliveryYour device push token and notification trigger data. No personal profile fields are sent with a push message.
Google reCAPTCHAAbuse and bot prevention on public membership formsRequest metadata captured by reCAPTCHA at the moment you submit a public form.
Our email delivery providerTransactional emailYour email address and the content of membership and administrative messages.
Our web hosting providerHosting and TLS termination for pcwf.inHosting logs, including network metadata.
Android / Google PlayDistribution of the app, in-app updates, and notification displayStandard platform identifiers handled by Google Play.

These providers may process data in their own infrastructure and may have their own privacy terms, which we do not control. We do not embed advertising or analytics advertising SDKs in the app.

7. Data Retention

We keep personal data for as long as your membership is active, because the membership register is the legal and organisational record of the foundation.

  • Active members. — Membership records are retained for the duration of the membership and for as long afterwards as required to satisfy legal, tax and audit obligations.
  • Withdrawn, dormant and rejected applicants. — Records are retained while the application is under consideration or the appeal window is open, then retained in a restricted state as described in the Data Deletion section.
  • Uploaded files. — Profile photographs and payment receipts are retained while the member record exists.
  • Push notification tokens. — Retained while you use the app. Tokens are deleted when you log out and when your account is deactivated.
  • App diagnostics. — Retained for a short period for troubleshooting, then purged.

8. Account and Data Deletion

You have a self-service right to request deletion of your account and your personal data. Two deletion paths are provided:

  1. In the app. Open the hamburger menu, tap Settings, then tap Request Account Deletion and confirm with your password. You may cancel a pending request at any time before it is approved.
  2. On the web. Visit pcwf.in/account-deletion.php for the full procedure, including exactly which data is deleted, which is retained in anonymised form, and how the grace period works.

When you submit a request you are logged out immediately. An administrator reviews the request. Once approved, a 30-day grace period begins, during which your account is deactivated but your data is still recoverable by contacting us. At the end of the grace period the data is permanently and irreversibly deleted.

A minimal anonymised audit record is retained to preserve the integrity of the membership register: your internal user code, an anonymised email placeholder, your original registration date, and the date your deletion was completed. That record contains no information that can be linked back to you as a person.

9. Your Rights

Subject to applicable law, you may:

  • Access your personal data — visible in the app on your Profile and Member Card screens.
  • Correct it — edit your profile in the app. For security-sensitive fields such as your name, email, mobile number or Government ID, an edit is raised as a change request and takes effect only after administrator approval, so that membership records stay trustworthy.
  • Request deletion — as described in section 8.
  • Withdraw consent for optional processing by contacting us.
  • Object to or restrict processing, and receive a copy of your data in a portable form, by writing to info@pcwf.in.
  • Lodge a complaint with your local data protection authority. We would ask that you contact us first so we can try to resolve the concern.

We aim to respond to a written request within 30 days. We may need to verify your identity before we can act on it.

10. Security

We protect your personal data with a combination of administrative, technical and physical safeguards, including:

  • encryption of all data in transit over TLS, with certificate pinning in the mobile app so that the app refuses to talk to an impersonated server;
  • encryption of session credentials and cached profile data on your device, restricted to this device and unlocked by your device credentials or biometrics;
  • one-way salted password hashing, short-lived access tokens, refresh tokens that are revocable at any time, and forced logout on status change or password change;
  • role-based and location-scoped access control in the administration portal, with administrative actions written to an audit trail;
  • redaction of secret fields such as password hashes and two-factor secrets so that they can never be returned to a client;
  • encrypted database storage at rest, and encrypted off-site backups.

No system is perfectly secure. If you believe your account has been compromised, change your password immediately and contact us at info@pcwf.in.

11. International Data Transfers

PCWF operates in India and the Gulf region, and some service providers may process data on infrastructure located in other countries. Where personal data is transferred outside India, we rely on appropriate safeguards such as standard contractual clauses with our service providers. You may contact us for further information about the safeguards applied.

12. Children

PCWF membership is open to individuals who are at least 18 years old. Our app and membership process are not directed at children, and we do not knowingly collect personal data from anyone under 18. Membership applications from a person under 18 are rejected during review. If you believe a child has provided us with personal data, contact us and we will delete it.

13. Changes to This Policy

We may update this policy from time to time, for example to reflect new features, new law, or changes in how we use data. The “Last updated” date at the top of this page always reflects the current version. Where a change is material, we will make it clear on this page and, where appropriate, notify members through the app or by email. You may request a copy of any earlier version by writing to info@pcwf.in.


Part 2 — Terms of Use

These Terms of Use govern your access to and use of the PCWF Member application, the pcwf.in membership forms, and the member administration system, together with the membership services PCWF provides.

By creating an account, submitting a membership application, or using the app, you agree to these Terms and to our Privacy Policy. If you do not agree, please do not use the services.

1. Membership Eligibility

Membership is open to individuals of 18 years or older who support the objectives of the foundation. Every application — whether submitted in the app, on the public web form, or by an administrator on your behalf — is reviewed by a human administrator and must be approved before an account becomes active. Submitting an application does not create a membership.

You must provide accurate and current information. Knowingly providing false information, or information belonging to another person, is grounds for rejection and, for an existing member, for suspension.

We may decide not to admit an applicant. Where we do, we will record a reason. Nothing in these Terms obliges the foundation to admit any applicant.

2. Your Account

  • You are responsible for everything done under your account, including sharing your device with someone else.
  • Keep your password confidential. Tell us promptly if you believe it has been compromised.
  • You may sign in with either your username or the mobile number registered to your membership, provided the number is one you control.
  • Two-factor authentication may be made mandatory for your account. You must not attempt to bypass, disable or interfere with it.
  • Biometric unlock is a convenience feature. It protects stored credentials on a single device and is not a substitute for your password.
  • Accounts are for named individuals. Automated access, credential sharing, and bulk scripted interaction with the services are prohibited.

3. Acceptable Use

You agree not to:

  • upload, post or share any content that is unlawful, defamatory, discriminatory, sexually explicit, hateful, or that infringes someone else's rights;
  • upload another person's photograph, personal data, or documents without their consent;
  • misuse your membership privileges — for example scanning a member's QR code, or editing a member record, without the authority your role grants you;
  • attempt to gain access to accounts, records or committees outside the scope assigned to you, including through ID manipulation, shared credentials, or exploiting any vulnerability;
  • circumvent, disable or interfere with security controls, access restrictions, certificate pinning, or rate limits;
  • probe, scan or test the vulnerability of our systems without our prior written authorisation;
  • scrape, harvest or bulk-extract member data;
  • use the services for any unlawful purpose, or in a way that damages the foundation's reputation or disrupts other members' use of the services.

We may restrict or suspend an account that breaches this section, without notice where the breach is severe or ongoing.

4. Membership Cards and QR Codes

  • Your membership number, the barcode and the QR code printed on your membership card and in the app are for your identification only. They are not a payment instrument and carry no monetary value.
  • Do not share your membership card or its QR code. Photograph it only if you need it for identification, and be aware that a screenshot may expose your membership number.
  • A QR scan records that the scan happened, by whom, and when. Scanning is limited to office bearers who are authorised for the relevant purpose.
  • We may invalidate or reissue a card at any time, for example on reissue of a membership number or on request.

5. Events and Meetings

  • Event and meeting details, including venue, date, and any photograph, are provided by committee administrators and may change.
  • Attendance at a meeting is recorded when you check in by QR code, or manually by an organiser. A duplicate scan is recorded once and does not create a second attendance record.
  • Meeting minutes are recorded by the organiser and are an administrative record of the meeting, not a public document.
  • Where an event or meeting has a restricted audience, attendance is limited to those invited, to members of the relevant location, or to members of the relevant committee as set out in the event or meeting details.

6. Fees and Payments

  • Membership fees, their amount, and their due dates are set by the foundation and communicated to members.
  • Where a payment receipt is submitted, you confirm that the receipt is genuine, belongs to you, and accurately reflects the payment made. Submitting a false or altered receipt is a serious breach of these Terms.
  • Fee status is recorded by administrators. A dispute about a payment must be raised promptly, in writing, with the receipt details and any bank reference.
  • We are not a payment gateway. Card or transfer details are never entered into the app; you pay through the method notified to you and submit evidence of it.

7. Communications and Notifications

We send you notifications about your membership, events and meetings through the app, and by email or SMS where you have provided contact details for that purpose. These include account and security alerts, membership decisions, event notices, meeting invitations, and check-in confirmations.

Push notifications are shown on your device lock screen, so we keep the content of a push message brief and direct you to open the app for detail. You can turn notifications off in your device settings; doing so may mean you miss time-sensitive membership information.

8. Suspension, Dormancy and Termination

An account may be made dormant, suspended or terminated when:

  • you request deletion, as described in Part 1 section 8;
  • membership fees remain outstanding, or your membership expires;
  • you breach section 3 (Acceptable Use) or any other part of these Terms;
  • we are required to act by law, a court order, or a competent authority.

When your account is suspended or set dormant, you cannot sign in, and your sessions and push tokens are revoked. Where a suspension is a measure we initiated and is capable of remedy, we will tell you why and what you can do to have it lifted.

9. Intellectual Property

The foundation owns or licenses the PCWF name, logo, crest, emblems, website content, app, software, database design, and all membership records and administrative data. Membership confers no ownership of any of it.

You retain ownership of the photographs you upload. By uploading a photograph you grant the foundation a non-exclusive, royalty-free, worldwide licence to store it, reproduce it, resize it, and display it within the membership system, on your membership card, and in committee or event contexts where it is appropriate — for example in an event gallery. You may ask us to remove your photograph by contacting us or by editing your profile where that control is available.

PCWF names, marks and logos may not be used without prior written permission.

10. Disclaimers and Limitation of Liability

The services are provided on an “as is” and “as available” basis. To the maximum extent permitted by law, the foundation disclaims all warranties, express or implied, including implied warranties of merchantability, fitness for a particular purpose, accuracy and non-infringement.

Event, meeting and activity information is supplied in good faith by committee administrators and may be subject to change or cancellation. We do not warrant attendance, suitability or outcomes.

To the maximum extent permitted by law, the foundation is not liable for indirect, incidental, special, consequential or exemplary loss, or for loss of profit, revenue, data or goodwill, arising from your use of the services. Where liability cannot be excluded, it is limited to the amount you paid for the services in the twelve months preceding the claim, which for a free membership application is nil.

11. Indemnity

You agree to indemnify the foundation, its office bearers, committee members and volunteers against claims, damages, costs and reasonable expenses arising from your breach of these Terms, your unlawful use of the services, your infringement of someone else's rights, or your misrepresentation of your identity, age or payment.

12. Governing Law and Jurisdiction

These Terms and the Privacy Policy are governed by the laws of India, and you submit to the exclusive jurisdiction of the courts at Malappuram, Kerala, India. Nothing in these Terms limits any right or remedy you may have under the consumer or data protection law of your country of residence, or any right you may have under mandatory local law.

13. Changes to These Terms

We may revise these Terms. The “Last updated” date at the top of this page reflects the current version. Where a change materially affects your rights or obligations we will give notice through the app or by email before it takes effect. Continuing to use the services after a change takes effect means you accept the revised Terms.


Contact Us

Questions about this policy, about these terms, or about your data:

ChannelDetails
Emailinfo@pcwf.in
Telephone+91 75588 33350
Contact formpcwf.in/contact.php
In the appSettings → Request Account Deletion, or Contact Us
Postal address32/128 Baniyas Tower, Chanthapadi, Ponnani, Malappuram, Kerala, India

Published by Ponnani Cultural World Foundation. This document is maintained at pcwf.in/privacy_policy.php.