Privacy policy
Last updated 29 August 2026
kaal (www.kaal.info) is an invitation and RSVP site operated by Singam Tech Inc. This page describes what it collects when you respond to an invitation, why each item is collected, and who can see it.
Questions, or a request to see or delete your data: support@singamtech.com.
What kaal does
Someone hosting an event sends you a link. That link is the invitation — events are not listed or searchable anywhere on this site. To respond you sign in with an existing Microsoft or Google account, and your answer is recorded so the host knows who is coming and so you can change it later.
Why kaal asks you to sign in
Signing in exists to attach your response to an address you have proved you control. That is what lets you come back and change your answer instead of creating a second response, and it stops anyone else from answering, viewing or altering your response by guessing your name.
Only your email address is taken from the sign-in. Microsoft and Google return a signed token that also contains your name, and in Google’s case a profile picture. Neither library allows an application to ask for less. kaal reads the email address from that token and discards the rest — it is never stored, logged, or shown to anyone. kaal never receives your password.
What is stored
Your response
- Your email address, and which provider you signed in with (Microsoft or Google).
- Whether you are coming, and the number of people in your party if you gave one.
- When you first responded, when you last changed your answer, and how many times you have answered.
Technical information recorded with a response
- Your IP address, your browser’s user-agent string, and the site the request came from.
- A running count of accepted and rejected requests from your IP address, with the first and last time it was seen.
This second group exists for one purpose: detecting and limiting abuse of the service. It is never shown to event hosts, never returned by the site, and never used to profile you or to advertise.
A note on how responses are filed
Each response is stored in a file named after a SHA-256 hash of your lower-cased email address, so that addresses do not appear in file names, listings or operational logs. This is a storage key, not anonymisation. Your address is stored in plain text inside the record itself, because the host has to know who is coming — that is the purpose of the product. Treat the hashing as tidiness, not as protection.
Who can see it
- You — your own response, when signed in with the same address.
- The host of that event — your email address, sign-in provider, answer, party size and timestamps. Hosts do not see IP addresses or user-agent strings.
- Singam Tech Inc, as the operator, for running and supporting the service.
Nothing is sold or rented, and no advertising trackers of any kind run anywhere on kaal. This page (privacy), the terms page, and the homepage carry Google Analytics, described below; the invitation and RSVP flow — every page under an event link — does not, and never gains a third-party data recipient it did not already have.
Sign-in providers and other services
- Microsoft — signing in sends you to Microsoft to authenticate, under Microsoft’s own privacy policy.
- Google — when Google sign-in is offered, this site loads Google’s sign-in library from
accounts.google.com, and signing in is handled by Google under its own privacy policy. - Google Analytics — this page, the terms page, and the homepage load Google’s
gtag.jsto measure visits (page views, referrers, general device/browser signals), under Google’s own privacy policy. It runs only on those three pages. It does not run on an event page, on the RSVP flow, or anywhere in admin.kaal.info, and never sees your email address or RSVP response — kaal’s own storage and Google Analytics are entirely separate. - Microsoft Azure — responses are stored in Azure Blob Storage in the United States (West US 2).
- Cloudflare — requests to the kaal API pass through Cloudflare, which processes IP addresses in order to route and filter traffic.
Cookies and browser storage
kaal itself sets no cookies. Your sign-in token is held in your browser’s sessionStorage, which is scoped to that tab and erased when you close it — so signing in does not persist across browser sessions. Microsoft and Google set their own cookies on their own domains when you sign in with them. On the homepage, this page, and the terms page only, Google Analytics also sets its own cookies to distinguish visits — an event page never loads Google Analytics, so no analytics cookie is ever set there.
How long it is kept
A response is kept for as long as the event needs it and is not deleted automatically. If you want your response removed, email support@singamtech.com from the address you signed in with and it will be deleted. Deleting it removes the record entirely; the host will no longer see your answer.
Your choices
You can ask for a copy of what is stored about you, ask for it to be corrected, or ask for it to be deleted, at support@singamtech.com. You can also simply not sign in — nothing is collected from someone who only reads an invitation.
Children
kaal is not directed at children under 13 and no account may be created for one. Where a child is attending, the responding adult answers on their behalf, and kaal stores no information about the child beyond the number of people in the party.
Security, stated plainly
Traffic is encrypted in transit, sign-in tokens are verified cryptographically before any response is read or written, and access to a guest list is restricted to the event’s host. No service can promise more than that, and this page will not pretend otherwise.
Changes to this policy
If what kaal collects changes, this page changes with it and the date at the top is updated.
