Privacy · Last updated 2 October 2026
What we collect, and (mostly) what we don't.
01
The short version
Discover Manipur is an open-source public platform, run by volunteers, that helps visitors and local people find places to see in Manipur. It is not a commercial travel business and not an official government service. It does not take payments, and it collects as little about you as it can.
- You can browse the whole site without an account. If you create one, we store your name, email address and the optional profile details you add.
- If you are signed in, your booking requests, saved trip plans, saved places and host application are stored with your account. Signed out, they stay in your own browser.
- We count page views with Vercel's cookieless analytics, and use Microsoft Clarity to see how pages are used (heatmaps and session recordings). We do not sell personal data, and we do not run advertising trackers.
- We do not knowingly collect anything from children under 13.
- You can ask us what we hold, ask for it to be corrected, or ask for it to be deleted.
The rest of this notice is the detail.
02
Who we are
Discover Manipur is a community project about tourism in Manipur, India. It began as a student and volunteer project around World Tourism Day 2026 and is now developed in the open: the source code is public on GitHub, so anyone can check how the site handles data. The maintainers work remotely and there is no company or public office behind it.
For a question about this notice or about data we may hold, ask the maintainers on our community Discord or open an issue on GitHub. Please do not post personal details in a public channel or issue. Say what you need and a maintainer will contact you privately.
03
What we collect
Information you give us
- Account details: if you create an account, your email address, your name and your password. Sign-in is handled by our authentication provider, which stores the password in hashed form; we never see or store it in readable form. Your profile also holds any phone number or profile-photo link you choose to add, your account role (traveller, host or admin) and when the account was created and last updated.
- Email verification: when you sign up, your email address is passed to our email provider so it can send you a one-time verification code.
- Contact form: your name, email address, enquiry type, subject and message. At the moment the form checks these on the server and then discards them: nothing is stored and nothing is forwarded to an inbox, because no mail provider is connected to it yet.
- Booking requests: when you are signed in, the listing, dates, number of guests, price shown and any note you add are stored with your account. Our admins can see them, and the host of that listing sees your first name, the dates and the number of guests and the price on their dashboard. A booking is a request, not a reservation: no payment is taken and the property is not notified automatically.
- Saved trip plans and saved places: when you are signed in, they are stored with your account so they follow you across devices. When you are signed out, they are kept in your browser's local storage instead. Places you saved while signed out are moved into your account the next time you sign in.
- Places you list: when you add a place, its details, any links and coordinates you give, how you are connected to it, and the photos you upload with their credit are stored with your account. While it is collecting votes it is visible to signed-in users with a verified email address; once published it is public, shown with your first name. Our admins see your name and email address next to it.
- Photos you upload: each photo is resized and re-encoded on our server before it is stored, which removes its location data and all other embedded metadata. Photos of a place that is not published are only shown to the people allowed to see that place.
- Votes: which community places you upvoted is stored with your account, so each account votes once. Only the number of votes is shown, never who cast them.
Information collected automatically
- Standard server and hosting logs, which typically include an IP address, a timestamp, the page requested and a user-agent string. These are generated by our hosting provider.
- Aggregate usage and performance data from Vercel Web Analytics and Speed Insights: the pages visited, the referring site, approximate country, browser, operating system and device type, and page-load measurements. These tools do not use cookies and do not follow you across other sites.
- Interaction data from Microsoft Clarity: clicks, taps, scrolling and mouse movement, the pages you visit, and your browser, device and approximate location. Clarity uses this to build heatmaps and session recordings that show us where pages confuse people. Text you type into form fields is masked before a recording leaves your browser, and so is everything shown in your account, the host dashboard, the admin area and your conversations with the concierge. Recordings are made only on the live site, never on preview or test copies of it. Clarity sets first-party cookies (described below). Microsoft processes this data under its privacy statement.
- Some photographs and the 3D map of Kangla are loaded from Google Maps Platform, so Google receives your IP address and browser details when they load, under Google's own privacy policy.
What we do not collect
We do not take payment card details, we do not ask for identity documents, permits or passport numbers, and we do not track your location.
04
Why we use it
- To run your account. We need your email address to sign you in and to verify that the address is yours, and your role to decide which pages you can open.
- To keep the site working and safe. Logs help us find errors and abuse.
- To improve the platform. Aggregate usage tells us which pages are worth writing more of and which are slow.
Where a legal basis is required, we rely on your consent for optional features such as an account, on legitimate interests for security and for improving the service, and on the steps necessary to respond to a request you have made.
05
AI features
The site includes an AI concierge that drafts itineraries from the prompt you give it together with our own catalogue of places, stays and experiences. It is switched off on the live site at the moment: the planner page shows a sample conversation instead, and nothing you type is sent to an AI provider.
If the concierge is switched on in future:
- Your messages will be sent to a third-party model provider (Google Gemini, or Anthropic as a fallback) to generate the response.
- Do not put anything sensitive into the planner. Treat it as a public message.
- Generated itineraries are suggestions. They can be wrong about timings, prices, opening hours and access, and they must never be used as a substitute for checking permits, advisories or road conditions with official sources.
- We do not use your prompts to train models ourselves. The provider processes them under its own terms.
08
How long we keep it
- Accounts and profiles: until you ask us to delete them, or until we remove an account that breaks the terms of use.
- Booking requests, saved trip plans and saved places held with your account: until you remove them (you can delete saved plans and places yourself, and cancel a booking request) or ask us to delete your account. Anything kept only in your browser stays there until you remove it or clear your browser storage.
- Places you list and their photos: kept as the record of the listing, whether or not it is published, until you ask us to delete them. An admin may remove a photo that breaks the terms; its image is then deleted. If you delete your account, places you listed stay on the site without your name, and your votes are removed.
- Contact messages: not kept at all while the form has no mail provider.
- Server logs and analytics: for the retention period set by our hosting provider.
- Microsoft Clarity: session recordings for 30 days, and aggregated heatmaps and statistics for up to 13 months, under Microsoft's retention policy.
09
Your rights
Depending on where you live, you may have the right to access a copy of your data, to have it corrected, to have it erased, to restrict or object to how we use it, to withdraw consent, and to complain to a data protection authority. Indian users have comparable rights under the Digital Personal Data Protection framework.
You can correct your name, phone number and profile photo yourself on your account's profile page. For anything else (a copy of your data, or deleting your account), ask the maintainers on Discord or through a GitHub issue, without posting personal details publicly. The maintainers are volunteers; we aim to respond within 30 days. We will ask you to confirm your identity (usually by writing from the email address on the account) before acting on a request, so that nobody can use this route to access someone else's data.
10
Security
The site is served over HTTPS, secrets are held in environment variables rather than in the codebase, access to the database is restricted to the maintainers, and pages for hosts and admins check your role on the server. Passwords are handled by our authentication provider and are never stored by us in readable form.
That said: this is a community-run project that has not had an independent security audit. Please do not enter anything into it that you would be unhappy to see disclosed. If you find a security problem, report it privately to a maintainer rather than in a public issue.
11
Children
The site is not directed at children under 13 and we do not knowingly collect their personal data. If you believe a child has created an account, contact us and we will delete it.
12
Changes to this notice
If this notice changes materially, we will update the date at the top of the page and, where the change is significant, note it on the site. Because the site is open source, every change to this page is also visible in the repository's history. Continuing to use Discover Manipur after a change means you accept the updated notice.