Privacy Policy

Effective Date: May 22, 2026
Last Updated: September 4, 2026

Welcome to ShalaPro (“ShalaPro,” “we,” “our,” or “us”). We are committed to protecting the privacy and security of schools, staff members, students and other users.

This Privacy Policy explains how information is collected, accessed, processed, stored, transmitted and protected when you use:

  • The ShalaPro website at shalapro.com
  • The ShalaPro Windows desktop application
  • The ShalaPro Browser Assistant Chrome extension
  • ShalaPro account, subscription, backup and support services

In this policy, “handle” includes accessing, reading, using, processing, storing or transmitting information. Information may therefore be handled locally on the user’s device without being received or stored by ShalaPro servers.

By using ShalaPro services, you acknowledge the practices described in this Privacy Policy.

1. Information collected by ShalaPro

1.1 Account and school information

When a user creates an account, registers a school, purchases a plan or requests support, we may collect:

  • School name
  • Principal or administrator name
  • Mobile number
  • Email address
  • School address
  • UDISE code
  • School or account identification number
  • Account authentication information
  • Account, profile and subscription status
  • Date and time when the profile was created or updated
  • Communications sent to ShalaPro support

Passwords are not stored as readable plain text. ShalaPro uses protected authentication credentials and session tokens to authenticate accounts.

1.2 Device and technical information

To authenticate the ShalaPro application and Browser Assistant, manage access and protect the service, we may process:

  • Device or installation identifier
  • Device or machine name
  • Operating-system information
  • ShalaPro application version
  • Browser Assistant extension version
  • Protocol and configuration versions
  • Extension origin
  • IP address
  • Browser or application user-agent information
  • Session issue, expiry and revocation times
  • Feature entitlement and access decisions
  • Operational status and error codes

This information is used for security, licensing, school-level access control, version compatibility, service reliability and technical support.

1.3 Operational analytics and diagnostics

Where operational logging or analytics is enabled, ShalaPro may receive limited diagnostic information such as:

  • Feature or module name
  • Supported education portal
  • Success, failure or error status
  • Configuration version
  • Application or extension version
  • Date and time of an operation
  • Non-identifying technical metadata

Operational telemetry is designed to reject student names, student NIC IDs, marks, passwords and other student-identifying fields.

We do not use operational information to create advertising profiles or monitor users’ general browsing activity.

2. Payment information

ShalaPro uses Razorpay as its payment gateway.

ShalaPro does not directly collect or store complete credit-card numbers, debit-card numbers, CVV values, UPI PINs or banking passwords. Razorpay processes payment credentials according to its own privacy and security practices.

ShalaPro may receive and retain payment-related records such as:

  • Transaction or payment identifier
  • Order identifier
  • Payment amount
  • Payment status
  • Payment method category
  • Subscription or plan information
  • Payment date and time

These records are used to confirm payments, activate plans, prevent fraud, provide support and meet accounting or legal requirements.

3. Student and school operational data in the desktop application

ShalaPro is an offline-first Windows application. School operational information entered into the desktop application is primarily stored on the school’s computer.

This information may include:

  • Student names and identification numbers
  • Student contact and family information
  • Class, section and admission information
  • Subject selections
  • Attendance
  • Examination results and marks
  • Fee and ledger information
  • Photographs
  • Staff and school records

This information is controlled by the school and is used only to provide the features requested by the school.

Local ShalaPro data is normally stored within the Windows application data location on the school’s computer.

4. Encrypted cloud backups

When cloud backup is enabled, ShalaPro may upload encrypted backup files to infrastructure hosted through Hostinger.

The school database is encrypted locally before it is uploaded. ShalaPro does not possess the school’s decryption key and cannot ordinarily open, read or analyse the student records contained inside an encrypted backup.

ShalaPro servers therefore store the encrypted backup file, not a readable server-side copy of the school’s student database.

Encrypted backups are used only for backup and restoration purposes. Schools may manage or delete available backups through ShalaPro where that functionality is provided.

5. ShalaPro Browser Assistant

The ShalaPro Browser Assistant is intended for authorized school staff using the locally installed ShalaPro desktop application.

Its single purpose is to connect ShalaPro with supported education portals and provide user-initiated school administration assistance, including session maintenance, local data capture and form-filling workflows.

5.1 Connection to the ShalaPro desktop application

The extension uses Chrome Native Messaging to communicate with the locally installed ShalaPro desktop application.

The extension may receive:

  • Whether ShalaPro is currently running
  • Whether the user is signed in
  • School ID, school name and UDISE code
  • Desktop application and bridge versions
  • Available features and modules
  • Subscription, entitlement and access-control status
  • Minimum supported extension version
  • Module labels, descriptions, order and visibility

The extension does not receive the user’s ShalaPro password or main ShalaPro authentication token.

School access can be enabled, restricted or revoked through ShalaPro’s access-control service. Subscription requirements may also be applied according to the access policy shown to the school.

5.2 Rajasthan PSP Student Capture

When the user clicks Scan Current Class, the extension reads the student table currently visible to that authorized user on the Rajasthan PSP portal.

Depending on what the PSP table displays, captured rows may include:

  • Student name
  • Student NIC or other identification number
  • Class and section
  • Parent or guardian information
  • Gender, date of birth or other student details
  • Other columns visible in the selected PSP student table

The captured rows are stored in the Rajasthan PSP website’s local browser storage on that computer. They are used only to combine the selected class pages and create a CSV file when the user clicks Download CSV.

Student Capture data:

  • Is not transmitted to or stored by ShalaPro servers
  • Is not used for advertising, analytics or profiling
  • Remains on the user’s computer
  • Can be removed using Clear captured data
  • Can also be removed by clearing stored site data for the Rajasthan PSP website

Removing the extension may remove the extension’s own Chrome storage, but it may not remove information stored under the PSP website’s local storage. Users should use Clear captured data or clear the PSP website’s stored site data.

A downloaded CSV file is controlled by the user and remains on the computer until the user moves or deletes it.

5.3 Rajasthan PSP प्रपत्र 7

For the user-initiated प्रपत्र 7 workflow, the extension reads the following information visible on the current PSP page:

  • Academic session
  • Selected class
  • Student NIC IDs shown in the form

This information is sent only through the local Native Messaging connection to the installed ShalaPro desktop application.

The desktop application compares the NIC IDs with the school’s local ShalaPro database and returns the applicable:

  • Third Language for Classes 6–10
  • Stream for Classes 11–12
  • Optional Subjects for Classes 11–12
  • Vocational subject, where applicable

This local exchange does not include student names, marks, PSP passwords or ShalaPro passwords.

The student NIC IDs and subject selections used by this workflow are not uploaded to ShalaPro servers. Separate school, device and entitlement information may be processed by ShalaPro servers to verify that the school is authorized to use the feature.

The extension fills matching fields on the PSP page but does not click the PSP Save or final submission button. The authorized user must review the completed rows and save them manually.

5.4 PSP Session Keeper

Session Keeper is disabled by default and operates only after the user enables it.

While enabled, it periodically sends a request to the Rajasthan PSP portal to keep an already authenticated session active. The request is made only to:

https://rajpsp.rajasthan.gov.in

Chrome may automatically attach the existing PSP authentication cookie to this request. The extension does not read, copy, display, store or transmit the user’s PSP password or authentication cookie to ShalaPro.

Session Keeper locally stores its enabled status, selected interval, most recent check time, success time and limited status or error information.

5.5 Portal and browsing information

The extension checks whether an eligible Rajasthan PSP tab is open so that a user-requested feature can operate on that tab.

The extension does not collect or store the user’s general browsing history. It does not monitor websites outside the specifically permitted education portals, and it does not record keystrokes, mouse movement or unrelated browsing behaviour.

Current PSP page content is accessed only when required for Session Keeper, Student Capture or प्रपत्र 7 functionality.

5.6 UDISE functionality

The current Browser Assistant may provide UDISE navigation, school readiness and feature-access information.

Unless a future extension version clearly introduces and discloses an assisted UDISE workflow, the extension does not read UDISE page content.

If a future feature requires additional website access or a new category of data, ShalaPro will update the extension, its permission declarations, its user disclosures and this Privacy Policy before using that access.

6. Browser extension permissions

The Browser Assistant uses the following Chrome permissions:

nativeMessaging

Connects the extension to the locally installed ShalaPro desktop application to verify the signed-in school, check feature access and obtain locally stored information needed for user-requested workflows.

sidePanel

Displays the Browser Assistant beside the supported portal so users can view connection status and operate available tools.

storage

Stores extension interface preferences, the selected module, Session Keeper settings and temporary connection status locally in Chrome.

PSP Student Capture rows are stored separately within the PSP website’s local browser storage.

alarms

Schedules Session Keeper checks only while Session Keeper is enabled.

scripting

Loads the packaged ShalaPro content script into an eligible PSP tab when necessary, including when the tab was already open during extension installation or an extension update.

Rajasthan PSP host permission

Access to https://rajpsp.rajasthan.gov.in/* is required only for the user-enabled Session Keeper and the user-initiated Student Capture and प्रपत्र 7 features. The school staff member must already have valid PSP credentials and must sign in directly on the Rajasthan PSP website.

The extension does not provide PSP access, bypass authentication or access information the user cannot already view. It works only inside the user’s existing authorized PSP session to reduce repetitive manual work on the portal’s legacy ASP.NET Web Forms interface. It does not request permission to access all websites.

7. Remote configuration and executable code

ShalaPro may provide configuration information that controls:

  • Module labels and descriptions
  • Module order and visibility
  • School-specific feature access
  • Subscription or entitlement requirements
  • Minimum extension version
  • Emergency disabling or revocation of a feature

This remote configuration is data only. It is not executable JavaScript or WebAssembly code.

The Browser Assistant does not download or execute remotely hosted code. All executable extension code is included in the extension package distributed through the Chrome Web Store.

New automation code is delivered through an extension update. If a new feature materially changes how user information is handled, this Privacy Policy and the applicable user disclosures will be updated.

8. How information is used

ShalaPro uses information only as necessary to:

  • Create and maintain ShalaPro accounts
  • Register and identify schools
  • Authenticate users and devices
  • Process payments and activate plans
  • Provide desktop and Browser Assistant features
  • Verify school-specific feature access
  • Enable or revoke modules
  • Maintain compatibility and security
  • Provide encrypted cloud backups
  • Diagnose failures and improve service reliability
  • Respond to support requests
  • Prevent fraud, misuse and security incidents
  • Meet applicable legal, accounting and regulatory requirements

We do not use student information or extension-derived page content for advertising, unrelated profiling, creditworthiness or lending decisions.

9. Sharing and disclosure

ShalaPro does not sell, rent or trade student information, school information or extension-derived user data to advertising companies, data brokers or information resellers.

Information may be disclosed only:

  • To service providers necessary to operate ShalaPro, such as hosting and payment-processing providers
  • To the education portal being used by the authorized school user
  • When the user or school explicitly directs or consents to the disclosure
  • When necessary to investigate fraud, abuse or a security incident
  • When required by applicable law, regulation, court order or lawful government request
  • As part of a merger, acquisition or sale of assets, subject to applicable notice and consent requirements

Service providers are permitted to process information only for the services they provide to ShalaPro and subject to applicable contractual and security requirements.

10. Human access

ShalaPro personnel do not receive or access student page content processed locally by Student Capture or प्रपत्र 7.

Access to server-side account, school, payment and diagnostic information is restricted to authorized personnel and may occur only when necessary for:

  • Providing support requested by the user
  • Maintaining and securing the service
  • Investigating fraud or abuse
  • Meeting legal obligations
  • Using aggregated and anonymized information for internal operations

11. Data retention and deletion

Different information is retained for different periods:

  • Account and school profile information is retained while the account is active and for as long as reasonably necessary for support, security and legal obligations.
  • Payment records may be retained for accounting, taxation, fraud prevention and legal requirements.
  • Device registrations and Browser Assistant authorization records are retained while necessary to provide and secure access.
  • Operational logs are retained only for as long as reasonably necessary for reliability, troubleshooting, fraud prevention and security.
  • Encrypted cloud backups remain available according to the school’s backup lifecycle or until deleted through available ShalaPro controls.
  • Extension preferences remain in Chrome until changed, cleared or the extension is removed.
  • PSP Student Capture rows remain in PSP website local storage until the user selects Clear captured data or clears the PSP website’s stored site data.
  • Downloaded CSV files remain under the user’s control until manually deleted.

Users may request deletion of eligible account and school profile information by contacting ShalaPro. Some records may need to be retained where required by law or necessary to resolve disputes, prevent fraud or protect the service.

12. Security

ShalaPro uses reasonable technical and organizational measures intended to protect information, including:

  • HTTPS encryption for information transmitted to ShalaPro servers
  • Locally encrypted cloud backup files
  • Restricted server and administrative access
  • Protected authentication credentials and session tokens
  • School- and device-scoped Browser Assistant authorization
  • A local Native Messaging connection between the extension and desktop application
  • Narrow website permissions
  • Packaged extension code instead of remotely executed code
  • Feature revocation and emergency access controls

No electronic system can be guaranteed to be completely secure. Users and schools are responsible for protecting their devices, email accounts, ShalaPro credentials, PSP credentials and downloaded files.

13. Student privacy and authorized use

The Browser Assistant and ShalaPro desktop application are intended for authorized school administrators and staff, not for direct use by children.

The school remains responsible for:

  • Ensuring it has lawful authority to process student information
  • Limiting access to authorized staff
  • Reviewing information before submission to government portals
  • Protecting locally stored databases and downloaded files
  • Following applicable education, child-protection and data-protection requirements

ShalaPro processes school and student information only to provide functionality requested by the school and does not use that information for independent advertising or profiling purposes.

14. Chrome Web Store Limited Use disclosure

ShalaPro Browser Assistant’s use and transfer of information received from Chrome APIs complies with the Chrome Web Store User Data Policy, including the Limited Use requirements.

In particular:

  • Information is used only to provide or improve the extension’s disclosed, user-facing purpose.
  • Information is not sold or transferred to advertising platforms, data brokers or information resellers.
  • Information is not used for personalized, retargeted or interest-based advertising.
  • Information is not used for purposes unrelated to the Browser Assistant’s single purpose.
  • Information is not used to determine creditworthiness or for lending purposes.
  • Human access is prohibited except with explicit user consent for specific support, for security purposes, to comply with applicable law, or after aggregation and anonymization for lawful internal operations.

15. Your choices and rights

Subject to applicable law, users may request:

  • Access to eligible personal information held by ShalaPro
  • Correction of inaccurate account or school profile information
  • Deletion of eligible account or school profile information
  • Information about how their data is used
  • Withdrawal of optional analytics consent where available

Schools retain control over student information stored in the local ShalaPro database.

Because encrypted cloud backups use a zero-knowledge design, ShalaPro cannot read, modify or extract individual student records from those encrypted files on the school’s behalf.

16. Third-party services and websites

ShalaPro services may interact with third-party services, including:

  • Razorpay
  • Hostinger
  • Google Chrome and the Chrome Web Store
  • Rajasthan PSP
  • UDISE and other supported education portals

Those services operate under their own terms and privacy policies. ShalaPro is not responsible for the independent privacy practices of external government portals or other third-party services.

17. Changes to this policy

We may update this Privacy Policy when ShalaPro features, legal requirements or data-handling practices change.

When we make a material change, we will update the “Last Updated” date and provide additional notice where required. We will update the policy and obtain any required consent before using previously collected information for a materially different purpose.

18. Contact us

For privacy questions, requests or complaints, contact:

Email: info@shalapro.com
Website: https://shalapro.com
Privacy Policy: https://shalapro.com/privacy-policy/