Privacy Policy

Last Updated: 7/24/2026

Privacy Policy for sastranet

Effective Date: March 2026

Welcome to sastranet.

sastranet is an integrated digital platform designed for the student community, providing administrative, academic, and club utilities under a unified domain (sastranet.sastra.edu).

This Privacy Policy explains how sastranet collects, uses, stores, and protects user data across all platform modules, including sastranet Core, RayID (/rayid), Material Hub (/materialhub), Club Tools (/clubtools), Feedback Portal (/feedbackportal), and sastranet Studio (/studio).

1. Information We Collect

sastranet collects minimal information to operate its modules effectively:

Account Information: Name, institutional email address, and authentication identifiers obtained through Google OAuth sign-in.

Application Data: Attendance logs, academic resource submissions, feedback responses, and club management records created within specific platform modules.

Technical Log Data: Security logs, IP addresses, and standard session state required to maintain platform security and performance.

2. Module-Specific Use of Google APIs

sastranet integrates with Google APIs to enable specific features within sub-modules. We only request permissions necessary for core user-facing functionality (following the Principle of Least Privilege):

RayID (/rayid): Requests access to Google Drive and Google Sheets APIs to read, process, and update student attendance rosters, access authorized spreadsheets, and export attendance analytics.

sastranet Club Tools (/clubtools): Requests access to Google Sheets APIs to sync club membership lists, manage event registration spreadsheets, and track participant rosters.

Material Hub (/materialhub): Requests access to Google Drive APIs (drive.file) to permit users to upload, store, organize, and download user-contributed academic materials.

sastranet Core, Studio, and Feedback Portal: Use basic Google OAuth solely for user authentication (Name and Email address) and do not access Google Drive or Sheets APIs.

3. Google API Services User Data Policy & Limited Use Disclosure

sastranet’s use and transfer of information received from Google APIs to any other application strictly adheres to the Google API Services User Data Policy, including the Limited Use requirements:

Prominent Feature Provision: Data obtained through Google APIs is used strictly to provide or improve visible, user-facing features within the requesting sastranet module.

No Unrelated Transfers: We do not sell, rent, or transfer Google user data to third parties, except as required for platform operations, legal compliance, or explicit user authorization.

No Advertising or Profiling: Data accessed via Google APIs is never used for personalized advertising, retargeting, commercial profiling, or marketing purposes.

No AI/ML Model Training: User data obtained from Google APIs is never utilized to train, fine-tune, or refine artificial intelligence, machine learning, or large language models.

Human Data Access: Human staff cannot read user data obtained via Google APIs unless explicit consent is provided for technical support, or where required for security investigation or legal compliance.

4. Data Storage, Security, and Retention

sastranet employs industry-standard safeguards to ensure your data remains secure:

Encryption in Transit: All interactions across sastranet.sastra.edu and Google API communications are secured using mandatory TLS (HTTPS) encryption.

Data Retention: We retain Google API user data (such as temporary spreadsheet tokens or uploaded document metadata) only for as long as necessary to fulfill the requested feature action. Once an operation is completed or an account connection is revoked, access keys are purged.

5. User Rights and Revocation

Users retain full control over their data and Google permissions at all times:

Revoking Access: You can revoke sastranet’s access to your Google Account at any time via the Google Security Settings page.

Data Erasure: To request the deletion of account records or module data stored on sastranet servers, submit a request to the sastranet admin team.

6. Contact Information

For questions regarding this Privacy Policy or data handling across sastranet modules, please contact:

Platform Developers : Team sastranet

Domain: https://sastranet.sastra.edu

Contact Email: sastranet@sastra.edu