Privacy Policy
Effective date: May 1, 2026. Last updated: May 1, 2026.
Who we are
Shiva In Motion Inc. is a nonprofit corporation formed in the State of Delaware and operated for charitable and educational purposes. In this policy, “Shiva In Motion,” “we,” “us,” and “our” mean Shiva In Motion Inc. We operate an adult-controlled service at www.shivainmotion.org, including a private, sign-in family portal. The service lets parents and other authorized adults create private family and child profiles and request treatment, travel, equipment, tools, and other support for children with medical and disability-related needs.
Our mailing address is 8 The Green, STE B, Dover, DE 19901.
If you have a question or request about privacy, contact our Data Privacy Officer, Shailin Dhar, at shailin@shivainmotion.org.
Scope of this policy
This policy explains how we collect, use, disclose, retain, and protect personal information across our family account, child profile, grant application, and case report services. It does not replace a separate authorization we present for a grant application, a case report, contacting a provider, publicity, fundraising, or research. Our donation service has its own notice, the Donor Privacy Notice.
Adults operate the service
Accounts are available only to adults who are 18 or older. Children may not create or operate accounts or submit information directly. The age requirement applies to the adult who operates the account, not to the child who may benefit from support. The children we serve are often infants and have no minimum age.
An adult who submits information about a child must be the child’s parent or legal guardian, or must otherwise be authorized to act for that child. We ask you to confirm your authority, and we may ask for more information when it is reasonably necessary to confirm it.
Email verification and any third-party sign-in confirm control of an account or a communication channel. They do not by themselves prove that you are an adult or establish legal identity or guardianship. We rely on your attestations for those facts unless we tell you otherwise.
Information we collect
Depending on how you use the service, we may collect the following categories of information.
- Account and contact information: your name, email address, the country you are in, and an authentication identifier for your sign-in.
- Adult eligibility and relationship information: your confirmation that you are at least 18, and your relationship to, or authority over, a child.
- Basic child profile information: the child’s name, date of birth, gender, general location, diagnosis or disability category, and connection to your account. You may also add birth details and a medical history summary.
- Grant application information: the support you request (such as treatment, equipment, travel, or tools); health and treatment history; provider information; financial or insurance information; cost and amount requested; and documents you upload.
- Case report information that you choose to provide under a separate authorization, which may include clinical history, observations, assessment scores, treatment records, quotations, photographs, and video. Photographs and video can carry embedded technical details such as camera information and the location where they were captured.
- Communications and requests: your questions, support messages, application correspondence, and privacy requests. When you contact us, ask for support, or request a physical toolkit, we collect the information you provide, which can include a phone number, a child’s name and date of birth, a diagnosis, and, for a physical toolkit, a shipping address.
- Technical and security information: sign-in events and limited operational records used to secure and operate the service. We use a product-analytics provider on our public pages to understand how the website is used. We do not run behavioral analytics on the signed-in family, child profile, grant, or case-report pages.
We collect only what we need for the purpose at hand. We keep detailed medical, financial, photographic, video, and provider information inside the grant application or case report workflow, each of which has its own notice and consent. Your basic child profile is private and is not required to contain those details.
Sources of information
We collect information directly from you; from another adult you authorize to act for the child; from a provider or other person you specifically authorize; and automatically from your device for the security and operation of the service. We do not import records directly from clinicians, hospitals, or record systems. You upload records to us yourself.
How we use information
We use information to create and secure accounts; maintain private family and child profiles; confirm eligibility and authority; evaluate and administer requests for support; communicate with you; contact a provider when you specifically authorize it; prevent fraud, duplicate awards, misuse, and security threats; keep the nonprofit accounting and governance records we are required to keep; respond to your privacy requests; comply with law; and protect children, families, and users.
We use artificial intelligence software to help read, summarize, organize, and de-identify the documents and case information you provide, so that we can process grant applications and prepare case materials. Our contract with the provider prohibits using your family’s information to train models, to advertise, or to build unrelated profiles. We are moving this document processing onto a dedicated server that we control on our own premises, so that the reading and summarizing of your documents happens on infrastructure we operate.
We use case report, research, publicity, fundraising, photograph, and video information only as described in the separate authorization for that use. Declining an optional use does not prevent you from applying for or receiving support.
How we disclose information
We disclose information to our own authorized staff, reviewers, directors, advisers, contractors, and volunteers who need it for an approved purpose and are bound by confidentiality requirements. Access is limited by role, and we log administrative access to sensitive information.
We also use service providers that process information so we can run the service. They act on our instructions for the functions below and are not permitted to use your information for their own advertising, sale, independent profiling, or model training. We use the following categories of service providers.
| Function | Information they process |
|---|---|
| Website and application hosting | All service traffic, including technical connection data |
| Database and data storage | The information you and we store in the service, including account, child profile, and application data |
| Sign-in and account security | Your email, sign-in credentials, and session identity |
| File and document storage | The documents and photographs you upload |
| Email delivery | The email addresses and the content of the messages we send |
| Donation processing | The donation amount and the payment details you enter to donate |
| Document reading and summarizing | Copies of the documents and case text we process on your behalf, to extract and summarize them, under a contract that prohibits using your information to train models |
| Product analytics, public pages only | Usage and error events on our public website, not on signed-in or sensitive pages |
Our video analysis feature is a separate, internal capability. When it becomes available to families, it will have its own notice and consent describing the video processing involved. It is not covered by this policy.
Grant funds are paid to the treatment provider, clinic, or vendor that delivers the support. We do not pay grant funds directly to families. When we make a payment, we share only the information the provider or vendor needs to receive it.
When you specifically authorize it, we may disclose information to a named provider, vendor, travel provider, case report collaborator, or other recipient. We may also preserve or disclose information when reasonably necessary to comply with law, respond to lawful process, protect a child or another person, investigate misuse or a security incident, or establish or defend legal rights.
Shiva In Motion does not sell personal information. We do not use your family account, child profile, grant application, or case report information for third-party advertising, behavioral targeting, data brokerage, or unrelated commercial profiling.
Sign-in and authentication
You can sign in using an email address and password, or through an external sign-in provider. If you use an external sign-in provider, that provider confirms your account and shares a limited set of information with us, such as your name and email address, so we can create or authenticate your Shiva In Motion account. We do not send the sign-in provider your child profile, grant application, medical documents, or case report materials through the sign-in process.
How we protect information
We use administrative, technical, and organizational safeguards appropriate to the sensitivity of the information we hold. These include encryption in transit and at rest; role-based access on a least-privilege basis; multi-factor authentication for staff who can reach sensitive information; sign-in security; logging of administrative access to sensitive information; and short-lived, authenticated links for the files you upload, so that they are not exposed through public web addresses. No method of storage or transmission is completely secure, and we cannot guarantee absolute security.
Children and family information
Our service is directed to adults, not children. If we learn that a child created an account or submitted information without appropriate adult involvement, we may suspend the account and delete or restrict the information as appropriate. Parents and authorized adults may contact us to review, correct, or request deletion of information about a child, subject to verification and to the retention requirements described below.
How long we keep information
We keep information only as long as reasonably necessary for the purposes in this policy and any applicable authorization, including account operation, grant administration, nonprofit accounting, security, fraud prevention, safeguarding, dispute resolution, and legal compliance. Retention varies by record type. Information under an active legal, audit, security, fraud, or safeguarding hold may be kept until the matter is resolved. Backup copies are removed on our normal backup cycle.
Our current retention targets are below. We will review them as regulations change.
| Record type | Kept for |
|---|---|
| Unverified or inactive account | 90 days |
| Abandoned child profile or unsubmitted draft | 12 months after last activity |
| Declined or withdrawn application | 24 months |
| Awarded grant core record | 7 years, for tax and audit purposes |
| Medical documents not needed for accounting | Deleted after review, or within 24 months, whichever is sooner |
| Case report source material | As stated in the case report authorization |
| Consent and authorization records | Kept as long as the record they relate to, to prove consent |
| Security and administrative logs | 12 months |
| Backups | Removed on our normal backup cycle, within 30 days |
Your privacy choices and rights
Subject to verification and applicable law, you may ask us to give you access to your personal information, correct it, provide a copy, or delete it. You may close your account, withdraw an unsubmitted application, withdraw an optional consent, or appeal a decision we make about your request. Withdrawing an optional consent does not affect processing we already carried out under it, and it does not prevent you from applying for or receiving support.
Depending on where you live, you may have additional rights, such as the right to object to or restrict certain processing, the right to data portability, and the right to lodge a complaint with your local data protection authority. We do not charge you for making a request, and we will not deny you support for exercising a right.
To make a request, contact our Data Privacy Officer, Shailin Dhar, at shailin@shivainmotion.org, or use the request feature in your account. We will verify your identity in a way proportionate to the request and confirm your authority over the relevant child profile. We aim to respond within 45 days, or within the period required by the law that applies to you. If we cannot fully grant a request, for example because we must keep certain records for grants, accounting, safeguarding, security, or legal reasons, we will explain why to the extent the law allows.
If you disagree with our decision, you may appeal by replying to our response to the Data Privacy Officer, Shailin Dhar. An officer of the organization who did not make the original decision will review your appeal.
International data transfers
Shiva In Motion is based in the United States, and our service providers process information in the United States and, in some cases, other countries. If you use the service from outside the United States, your information will be transferred to and processed in the United States and other locations that may not provide the same level of data protection as your home country. Where required, we use appropriate safeguards for these transfers. We are finalizing the specific transfer mechanisms for the United Kingdom, the European Union, and other regions during the fourth quarter of 2026, in coordination with the relevant government departments, and we will update this section when that work is complete.
Legal bases for processing
For families in the United Kingdom, the European Union, and other jurisdictions that require a stated lawful basis, we rely on your consent for optional and sensitive uses, such as case reports, publicity, and media; on contract and our legitimate interests for account operation and grant administration; and on legal obligation for accounting, tax, and safeguarding records. The detailed lawful-basis mapping for each non-US jurisdiction, including for health data about children, is being finalized alongside the transfer work described above during the fourth quarter of 2026.
Changes to this policy
We may update this policy to reflect changes in the service, the law, or our practices. We will post the updated policy with a new effective date and give you additional notice, or ask for your consent, when the law requires it for a material new use of sensitive information.
Contact us
Data Privacy Officer: Shailin Dhar
Email: shailin@shivainmotion.org
Mailing address: Shiva In Motion Inc., 8 The Green, STE B, Dover, DE 19901
Appeals: reply to our response, addressed to the Data Privacy Officer above.