Effective: 12 August 2026
Our service
DinSutra is a Nepal-focused calendar, news, and market-information service. Public calendar, news, market, and company-calendar pages can be used without an account. A Google account is optional and is used only for the personal Google Calendar features described below.
Information we collect
When you browse DinSutra, we may process basic technical information supplied by your browser, such as IP-derived approximate region, device/browser information, and pages viewed through Vercel Analytics. We do not use advertising cookies or sell personal information.
Google sign-in and Google Calendar data
If you choose to sign in with Google, DinSutra receives your Google account identifier, verified email address, display name, and, when available, profile image. We request the calendar.events.owned permission only to create, display, and delete Google Calendar events that you explicitly create through DinSutra. DinSutra does not request access to calendars you do not choose to connect or use Google Calendar data for any other purpose.
For the personal calendar experience, DinSutra may process the title, date, time, description, location, links, reminder settings, Google event ID, and Google Calendar event link for events created through DinSutra. We store only the Google event ID, title, Bikram Sambat and Gregorian dates, and event time in our local event record so that your events can be shown and deleted from DinSutra. Event descriptions, locations, links, and reminder settings are sent to Google Calendar to create the event and may be read from Google Calendar to display the event detail to you; DinSutra does not retain those fields in its local event record.
How we protect sensitive Google data
DinSutra applies the following safeguards to Google user data and other sensitive account information:
- Encryption in transit: DinSutra, Google, Vercel, and Neon connections use HTTPS/TLS. Google OAuth tokens are exchanged only server-side; they are never exposed in browser code or URLs.
- Encryption at rest: Google refresh tokens are encrypted before storage using AES-256-GCM with a unique random initialization vector. The encryption secret is kept in server-only environment configuration and is not delivered to the browser.
- Access controls: Google Calendar requests are made only from DinSutra's server after a valid, signed, HttpOnly session has been verified. Every stored personal event is scoped to its account, so one signed-in user cannot access another user's event records.
- Least-privilege use: DinSutra uses the limited
calendar.events.ownedscope and performs calendar actions only when you explicitly create, view, or delete an event through the service. - Operational access: Access to production credentials and stored data is restricted to the service infrastructure and authorised operators when necessary to maintain security, investigate an incident, or provide support. We do not use Google Calendar data for advertising, profiling, or training artificial-intelligence models.
How Google user data is used and shared
Google user data is used only to authenticate your DinSutra account and provide the Google Calendar features you request. We do not sell Google user data, use it for advertising, permit humans to read it for advertising purposes, or transfer it to third parties for unrelated purposes. Data is shared only with Google to operate Google Calendar and with DinSutra's service providers, including Vercel for hosting and Neon for database storage, solely as necessary to operate, secure, and support DinSutra.
DinSutra's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Retention, disconnection, and deletion
We retain your DinSutra account and locally stored event records while your account remains active. You can disconnect Google Calendar from your account settings at any time. DinSutra will attempt to revoke the Google token and immediately removes the stored encrypted token. You can also permanently delete your DinSutra account from account settings; this removes your account, stored encrypted token, and locally stored event records from DinSutra. Events already stored in Google Calendar remain in your Google account until you delete them there or through DinSutra.
Local browser data and location
Your language choice, cookie-notice acknowledgement, and similar preferences may be stored in your browser. Weather location is requested only after you choose to share it and is used in your browser to request weather data. You can clear browser data or withdraw location permission through your browser settings.
Company calendars and contact inquiries
Company calendar administrators provide credentials, branding, and company event information to operate their company calendar. If you submit a contact form, DinSutra stores the name, company name, selected plan, contact number, and email address you provide to respond to and manage your inquiry. We retain contact inquiries only for as long as reasonably necessary for those purposes.
Contact us
For privacy questions, a data-deletion request, or a concern about Google Calendar access, please use our contact page. We will verify the request against the relevant account before taking action.