Security & Privacy

How Temple Hub protects temple and devotee data: OTP sign-in, role-based access, per-temple data isolation, audit logging, and what is stored.

How is devotee data protected?

All data is encrypted in transit (TLS 1.3) and at rest using AES-256 encryption. Each temple's data is strictly isolated — admins of one temple cannot access another temple's records. We do not share, sell, or use devotee data for advertising.

What is OTP login and why is it more secure than passwords?

OTP (one-time passcode) login sends a 6-digit code to a verified email address or mobile number each time someone signs in, and the code expires in 15 minutes. Because there is no stored password, there is nothing for attackers to steal or brute-force. Once verified, your session is carried by a cryptographically signed, tamper-proof JWT, and every request travels over TLS (HTTPS) so your data is never sent in the clear.

How does role-based access work in Temple Hub?

Temple Hub uses role-based access combined with the Tile Access configuration. There are seven roles: Admin, SuperAdmin, Priest, Volunteer, Devotee, Finance, and Facility. Admins control exactly which tiles each role sees — a Priest sees their schedule and puja calendar; a Finance user sees orders and billing; a Facility user manages space reservations; Devotees see booking and gallery tiles. No role can view data outside its configured scope.

Is Temple Hub compliant with data privacy regulations?

Yes. Temple Hub is built around U.S. state privacy laws — the California Consumer Privacy Act (as amended by the CPRA) and the comprehensive laws of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, and other states as they take effect. Each temple is the controller of its devotee data and Temple Hub acts as a service provider that processes it only on the temple's instructions under contract. We follow data minimization, do not sell personal information or share it for targeted advertising, honor the Global Privacy Control signal, and support consumer rights (access, correct, delete, portability, opt-out, and appeal). Temple administrators can export or delete devotee records at any time. See our Privacy Policy and Cookie Policy for full details.

How does Temple Hub use cookies, and can I control them?

There is no cookie banner, because there is nothing to consent to. Temple Hub sets no advertising or cross-site tracking cookies and shares no data with advertising networks. The only cookies are strictly necessary ones — they keep your sign-in session secure and guard against abuse — and those do not require consent under privacy law. Your selected temple and light/dark theme are kept in your browser's local storage, on your device only. Usage analytics run in a cookieless mode with no persistent identifier, so we cannot recognise you across visits, and if your browser sends the Global Privacy Control signal, analytics is not loaded at all. Full details are in our Cookie Policy, linked in the footer.

Still have questions?

Our team is happy to walk you through anything — from a live demo to a custom onboarding session for your temple.