Privacy Policy
Last updated 4 August 2026 · List Maro
1. Who we are
[LEGAL ENTITY NAME] (“we”, “us”, or “our”) operates List Maro at listmaro.com. For the purposes of India’s Digital Personal Data Protection Act, 2023 (“DPDP Act”), we are the Data Fiduciary for personal data processed through the Service.
Contact: hello@listmaro.com. Grievance Officer details appear in section 14.
2. What we collect
From Google sign-in. When you sign in with Google, we receive and store your name, email address, profile image, Google account identifier, and OAuth access/refresh/id tokens associated with that sign-in. Google is the only sign-in method; we do not offer password accounts.
From content you create. Listings (name, tagline, description, website URL, logo, screenshots), comments, votes, and ownership claims (work email and optional note).
From your session. When you are signed in, the session record stores your IP address and user agent in the clear, together with the session token and expiry. That is the place we retain a raw IP address.
From first-party measurement. Listing views and outbound clicks. We store a salted daily visitor digest (not raw IP), an optional referrer truncated to 500 characters, the listing, the event kind, and the day. See section 4.
From Google Analytics (optional). If you accept analytics cookies, Google Analytics 4 may process device/browser information, approximate location, pages and events on the Service, and a client identifier. We configure Consent Mode so analytics storage stays denied until you accept. See section 4 and the Cookie Policy.
Theme preference. Your light/dark theme choice is stored in the browser’s localStorage under the key theme. It is not sent to our servers as part of analytics.
3. What we do not collect
- Passwords — email-and-password sign-in is disabled; we store none
- Payment card or billing details — paid placement billing is not enabled yet; when it is, this policy will be updated
- Raw IP addresses or user agents in our first-party measurement tables — only a one-way daily digest is stored for deduplication
- Advertising pixels or third-party ad cookies — we do not sell ads or run ad networks on the Service
4. How measurement works
First-party listing events. We record views and outbound clicks per listing so we can show basic interest signals and operate the directory. No cookie is required for this measurement.
For each first-party event we compute a digest roughly of the form sha256(secret | UTC date | IP | user agent), truncated for storage. The secret is our application secret. Including the UTC date means yesterday’s digest cannot be joined to today’s. We keep at most one event per visitor digest, per listing, per kind, per UTC day (duplicates from refreshes are dropped).
Google Analytics 4. When analytics consent is granted, we load Google’s gtag script for property measurement ID G-G8GB9CM54F. Events include page views, searches, listing views, outbound clicks, sign-in clicks, and listing submissions. IP anonymisation is enabled in our tag config. You can reject analytics in the banner; first-party listing measurement continues either way.
5. Purposes and legal bases
We process personal data to:
- Provide the Service, authenticate you, and maintain your session (performance of a contract / legitimate use to operate the account you request)
- Moderate listings and comments, enforce our Terms, and handle ownership claims (legitimate interests in a safe, useful directory)
- Send transactional email — welcome on account creation, and listing approval or change-request notices after review (performance of a contract / legitimate interests in operating the Service you use)
- Measure listing views and clicks with the daily digest described above (legitimate interests in operating and improving the Service)
- Understand aggregate product and marketing patterns via Google Analytics when you consent (consent)
- Optionally pre-fill a listing form from a public URL using an AI extraction step you initiate (your request / contract to provide the feature)
- Comply with law, respond to lawful requests, and protect rights (legal obligation / legitimate interests)
Where consent is required for a specific processing activity, we will ask for it. You may withdraw analytics consent by clearing site data for listmaro.com and rejecting the banner again, or by contacting us.
6. Sharing
Personal data may reach the following categories:
- Google — authentication, and — if you accept analytics cookies — Google Analytics measurement. Google processes that data under its own terms and privacy policy
- OpenAI — only when you use the optional URL-assisted listing pre-fill. We send fetched public page content of the site URL you submit to
gpt-4o-mini. Without an API key configured, the wizard still works without this step - Resend — delivers transactional email (welcome, listing approved, listing changes requested). We send your name, email address, and the relevant listing title and review note to Resend solely to deliver those messages
- Object storage — logos and screenshots are uploaded to S3-compatible storage via a short-lived presigned URL from your browser. Stored media is publicly readable by design so listing pages can display it
- Hosting and database providers — infrastructure that runs the application and stores data
We do not sell personal information. We do not share data with advertisers for cross-context behavioural advertising.
7. International transfers
Some of our processors (for example cloud hosting, object storage, Google, or OpenAI) may process data outside India, including in the United States or other countries. Where we transfer personal data internationally, we do so as permitted under applicable law and with appropriate safeguards for the context of a small SaaS directory service.
8. Retention and deletion
We retain account data while your account is active and as needed to operate the Service, resolve disputes, and meet legal obligations. Session records expire according to session lifetime. Measurement digests are retained as operational analytics for the directory.
If you ask us to delete your account, we will delete or anonymise account identifiers and private data we control, subject to legal holds. Content you published that others rely on (for example a comment already visible in a public thread, or a listing description that remains editorially useful) may remain in public form or be attributed generically after account removal. Media already copied by third parties is outside our control.
9. Your rights under the DPDP Act, 2023
Subject to the DPDP Act and applicable rules, you may have the right to:
- Access a summary of personal data we process about you
- Correct inaccurate or incomplete personal data
- Erase personal data when it is no longer needed for the stated purpose or when consent is withdrawn (where consent was the basis)
- Nominate another individual to exercise rights in the event of your death or incapacity, once nomination mechanisms apply
- Seek grievance redressal as described in section 14
To exercise these rights, email hello@listmaro.com. We may need to verify your identity before acting.
10. Additional rights for EU/UK and California visitors
EU/UK (GDPR / UK GDPR). If you are in the EEA or UK, you may also have rights to access, rectification, erasure, restriction, portability, and objection, and the right to lodge a complaint with a supervisory authority. Where we rely on legitimate interests, you may object to processing on that basis. Contact us using the address above.
California (CCPA/CPRA). We do not sell personal information or share it for cross-context behavioural advertising. California residents may request access, deletion, and correction of personal information we hold, subject to exceptions. Contact hello@listmaro.com. We will not discriminate against you for exercising these rights.
11. Children
The Service is not directed to anyone under 18. We do not knowingly collect personal data from children. If you believe a child has provided data, contact us and we will take appropriate steps to delete it.
12. Security and breach notification
We use reasonable technical and organisational measures appropriate to a service of this scale, including HTTPS, session cookies scoped for security, server-side role checks, and hashed digests for measurement. No method of transmission or storage is perfectly secure.
If a personal data breach occurs that requires notification under applicable law, we will notify affected individuals and authorities as required.
13. Changes
We may update this Privacy Policy from time to time. The “Last updated” date at the top will change when we do. Material changes will be announced on the Service or by email where appropriate.
14. Contact and Grievance Officer
Questions about privacy: hello@listmaro.com.
Grievance Officer (IT Rules, 2021):
- Name: [GRIEVANCE OFFICER NAME]
- Address: [REGISTERED ADDRESS]
- Email: hello@listmaro.com
Grievances will be acknowledged within twenty-four (24) hours and disposed of within fifteen (15) days of receipt. For cookies and browser storage, see our Cookie Policy.