St. Jude India ChildCare Centre is a not-for-profit Section 8 Company established in Mumbai in 2006. We provide free, hygienic accommodation and holistic support for underprivileged children up to the ages of 15 years, and their families, who travel to hospitals in metro cities for pediatric cancer treatment, thereby improving their chances of surviving the disease and leading a full, healthy, happy life.
As an organisation, St. Judes is committed to conducting and governing ourselves with ethics, transparency and accountability, and to this end, we have developed governance structures, practices and procedures that ensure ethical conduct at all levels is promoted across our value chain.
St. Judes believes that every child, irrespective of their economical background, has the right to lead a healthy happy life. Equality across the organisation is one of our core values, and we do not distinguish among our children, families, and staff based on region, caste, or religion. Since children staying at our centres are minors (up to 15 years of age), it is mandatory for them to be accompanied by their parents.
Our Child Protection Policy ensures that children are safeguarded from all kinds of harm, keeping their best interests in perspective. The policy makes it clear that violation of the policy is unacceptable and nonnegotiable, and will lead to appropriate disciplinary action.
The protection of our children and families is paramount. Our centres are a safe haven for these families who come from smaller towns and villages to live in metro cities during their child’s treatment. Our housekeeping and security staff along with CCTV cameras everywhere in the centres ensure they are well taken care of even when the staff is not around.
While photography in the centres is strictly prohibited, consent is taken by our staff personally from all parents before using their and their child’s images, names, and other details on our website, social media platforms, brochures, AV films, or any other form of media.
Discretion is used before sharing these images with anyone outside the organisation. Volunteer Policy ensures all vistors and volunteers follow the correct protocol inside the centres.
In addition to providing a safe space, we strive to create a physical and emotional environment that is conducive for the recovery of children. Treatment for cancer can be extremely taxing and it is very often accompanied by side effects in the form of secondary infection which can be more life-threatening than the disease itself. While many of the side effects, such as hair loss, cannot be helped, some can be either treated or prevented. Prevention of infection during treatment makes a significant difference in the survival rate of children. Our efforts are focused on providing surroundings that are infection free at all times. Our Infection Control Policy has been established to ensure that our SOPs and training are put into practice at all levels and to prevent patients from catching or transmitting infection between patients during their stay at the Centres.
The staff is an integral part of St. Judes and we aim to provide a safe working environment that prohibits any form of sexual harassment through the implementation of the POSH Policy. Any act of sexual harassment or related retaliation against or by any employee is unacceptable. The policy intends to prohibit such occurrences and also details procedures to follow when an employee believes that a violation of the policy has occurred within the ambit of all applicable regulations regarding Sexual Harassment.
Our strict implementation of procedures and policies led to CRISIL awarding us Voluntary Organisation (VO) Grading ‘VO 1A’ for the fourth year in a row in 2022. The grading indicates our organisation’s ‘very strong delivery capability and high proficiency’.
App display name: St. Judes For Life (Founded in the memory of Mrs. Rani Vicaji) Last updated: 21 July 2026
St Jude India ChildCare Centres, the developer of the App (“St. Judes India”, “we”, “us” or “our”), respects the privacy and confidentiality of personal data processed through the St Judes For Life (Founded in the memory of Mrs. Rani Vicaji) Aid Request App, displayed on a user’s device as St. Judes For Life (Founded in the memory of Mrs. Rani Vicaji) (the “App”).
This policy explains how the App accesses and processes personal data, why the data is used, when it may be shared, how it is protected and retained, and the choices available to users.
The Android application ID and iOS bundle identifier are org.stjude.sjfl.
The App is an authenticated mobile front end to the existing St. Judes For Life (Founded in the memory of Mrs. Rani Vicaji) Aid Management System (the “CRM”). The App is not a separate system of record and does not maintain a separate backend database.
The App is intended for users who already have an authorised record in the CRM. A member of the public cannot register or create a new account through the App.
Information displayed in the App is retrieved from the CRM. Information entered or uploaded through the App is submitted to the CRM and becomes part of the relevant CRM record. References in this policy to information processed through the App include these interactions with the CRM.
2.1 Account and authentication information
When a user signs in, the App processes:
The App uses UID-and-OTP authentication. It does not ask users to create or submit a password.
2.2 Aid requests and service information
When a user views or submits an aid request, the App may retrieve from or submit to the CRM:
2.3 Counselling information
The App may retrieve and display counselling information from the CRM, including:
2.4 Documents, photographs and sensitive information
When a user chooses to take a photograph, select an image or choose a PDF, the App accesses the selected file and uploads it to the CRM for the relevant aid request.
Uploaded documents may contain:
An image selected from the camera or photo library is converted to PDF before upload. Temporary files may be created on the device while preparing and transmitting the document.
Users should upload only the information necessary for the relevant request. A user uploading personal data about another person must be authorised to provide it to St. Judes.
2.5 Technical information
When the App communicates with St. Judes systems, the CRM and supporting infrastructure may receive standard technical information, such as:
The App also uses the device language setting to select a supported language and stores the user’s selected language preference on the device.
The App does not intentionally collect persistent device identifiers such as IMEI, IMSI, SIM serial number, Android Advertising ID or App Set ID. It does not use technical information for advertising or cross-app tracking.
2.6 Data-handling summary
The following table summarises data handling in the current App. “Required” means the information is necessary to sign in or use the stated feature. An optional feature may still require particular fields after the user chooses to use it.
| Data category | How obtained | Required or optional | Main purpose | Destination or recipient |
|---|---|---|---|---|
| UID | Entered by the user | Required to sign in | Authentication and account management | St. Judes CRM/API |
| OTP | Entered by the user | Required to sign in | Authentication and fraud prevention | St. Judes CRM/API; processed transiently by the App and not intentionally retained on the device |
| Name and email address | Retrieved from the CRM | Required for the authenticated profile | Account and service functionality | St. Judes CRM; cached in private App storage |
| Registered mobile number | Already held in the CRM; not read from the device | Required by St. Judes systems for SMS OTP delivery | Authentication and communication | St. Judes CRM and its SMS service provider |
| Aid-request fields | Entered by the user or retrieved from the CRM | Optional until the user chooses the aid-request feature; fields may then be required | Aid-request processing and beneficiary support | St. Judes CRM and authorised service personnel |
| Identity, financial, education and health documents | Selected or captured by the user | Optional until the user chooses or is required to support an aid request | Evidence review and aid-request processing | Uploaded to the St. Judes CRM; accessible to authorised recipients described in Section 8 |
| Counselling information | Retrieved from the CRM | Optional feature | Display counselling and follow-up information | St. Judes CRM; may be cached in private App storage |
| Device language and selected App language | Read from device settings or selected by the user | Optional; a default language is used if unsupported | Localisation | Processed on the device; selected preference stored in private App storage |
| IP address, timestamps, request status and security/error information | Generated when the App connects to the API | Automatic and required for network operation | App operation, security, fraud prevention and troubleshooting | St. Judes API, CRM and infrastructure providers |
The current App does not use or collect:
It also does not:
The current App does not display third-party advertising or use personal data for advertising. It does not include Firebase Analytics, Firebase Crashlytics, Firebase Cloud Messaging, Google Analytics, Google Maps, a payment SDK, an advertising SDK or an attribution SDK. Libraries used to provide the camera, photo picker, document picker, PDF display and other App interfaces operate as part of those user-selected features; selected information is transmitted to the St. Judes CRM, not to those libraries for independent advertising or analytics purposes.
If a future version introduces a feature that processes additional personal data, St. Judes will update this policy and provide any required disclosure, permission request or consent before the processing begins.
St. Judes uses personal data processed through the App to:
St. Judes does not sell or rent personal data processed through the App.
The App uses the following device capabilities for user-selected features:
| Device access | Purpose |
|---|---|
| Internet/network | Authenticate with the CRM, retrieve CRM information, submit aid requests, and upload or download documents. |
| Camera | Photograph a document selected by the user for upload. Camera access is requested when the user selects this option. |
| Photos/media | Select an existing image for upload using the device permission or system picker. |
| Files/documents | Select a PDF for upload and save an aid-request letter to the Downloads folder when requested by the user. |
Users can manage permissions through their device settings. Refusing camera, photo or file access prevents only the associated capture, selection or download feature.
The current App does not require location, contacts or microphone access for its features.
Camera, photo and document access occurs only after the user chooses the corresponding upload option. The App does not intentionally extract or use location metadata from a selected image. Images are compressed and converted into a temporary PDF before being uploaded to the CRM.
The CRM is the system of record for profiles, aid requests, counselling information and uploaded supporting documents. The App does not create a separate server-side database or independently retain another permanent copy of those business records.
For the App to operate on a user’s device, its private application storage may contain:
Signing out removes the locally stored authentication token and basic profile record. Technical cache data may remain in the App’s private storage until it is cleared by the App or operating system, the user clears the App’s storage, or the App is uninstalled.
A file that a user deliberately downloads to the public Downloads folder remains on the device until the user deletes it. A device operating system or backup service may handle local App data according to the user’s device and backup settings.
The App transmits personal data to the St. Judes CRM or supporting systems as described in this policy. Data retrieved from the CRM may be displayed or cached by the App. Processing required to prepare a selected document occurs locally on the device until the document is uploaded.
St. Judes does not sell personal or sensitive data. The App does not share personal data with advertising companies, data brokers or analytics providers.
Personal data may be made available only where reasonably necessary to:
Service providers acting on St. Judes’ instructions are expected to process personal data only for authorised purposes and under appropriate contractual, confidentiality and security obligations.
Government identification, financial information, health information and uploaded documents are not made publicly available through the App.
St. Judes provides services involving children, former child beneficiaries and their families. Information about a child must be submitted only by a parent, legal guardian, authorised representative or authorised St. Judes personnel.
Where required, St. Judes will obtain appropriate parental or guardian consent and apply safeguards required for children’s personal data.
The App is restricted to pre-registered St. Judes users. It does not allow a member of the public or a child to create an independent account, and it is not intended to enable a child to submit personal data without appropriate authorisation.
Health and beneficiary information is used only for the aid, counselling, care-coordination, safeguarding, administration and legal purposes described in this policy. It is not used for advertising or analytics.
St. Judes uses reasonable technical and organisational safeguards appropriate to the nature and sensitivity of the information processed. These may include:
No electronic transmission or storage system can be guaranteed to be completely secure. Users should protect their devices and OTPs, avoid uploading unnecessary information, sign out when appropriate and promptly report suspected misuse.
St. Judes retains personal data in the CRM only for as long as reasonably necessary to provide and administer its services and to satisfy applicable operational, legal, accounting, audit, medical-record, safeguarding, security and record-keeping requirements.
Retention is determined using the following criteria:
| Data category | Retention criterion |
|---|---|
| CRM profile and beneficiary record | For the duration of the service relationship and the additional period required by the applicable beneficiary, safeguarding, audit and legal retention schedule. |
| Aid requests and supporting documents | Until the request and related support, payment, review or dispute are complete, followed by the period required by the applicable financial, audit, safeguarding and legal retention schedule. |
| Counselling and health-related records | For the period required to provide and document the service and satisfy applicable medical-record, safeguarding and legal obligations. |
| Authentication and security records | For the period needed to protect accounts, investigate misuse, meet audit requirements and resolve security incidents under the applicable security-log schedule. |
| Authentication token on the device | Until logout, token expiry, App-storage clearance or uninstall, whichever removes or invalidates it first. |
| Basic local profile | Until logout, App-storage clearance or uninstall. |
| Local CRM response cache | Until cleared by the App or operating system, the user clears App storage, or the App is uninstalled; the current implementation may retain this cache after logout. |
| Temporary upload files | Until removed through App or operating-system cache management or the App is uninstalled. |
| User-downloaded files | Until the user deletes the file from the Downloads folder. |
| Backups | Until overwritten or deleted under the applicable backup-rotation and legal-hold schedule. |
When personal data is no longer required under these criteria, it will be deleted, anonymised or securely disposed of in accordance with St. Judes’ applicable retention procedures.
The App does not permit account creation and does not maintain an independent App account. A user may request deactivation of mobile access, closure of the relevant CRM account where applicable, or deletion of personal data associated with the App and CRM by contacting St. Judes using the details in Section 16. Include enough information to identify the record, such as the user’s name and UID. Do not send an OTP or unnecessary identity documents in the initial request.
St. Judes may verify the requester’s identity and authority before acting. Some information may need to be retained for legal, regulatory, accounting, audit, medical-record, fraud-prevention, safeguarding, security or other permitted purposes.
Signing out or uninstalling the App does not delete the underlying CRM record. Users can remove local App data by clearing the App’s storage in device settings or uninstalling the App. Downloaded files must be deleted separately from the Downloads folder.
Subject to applicable law, a user may ask St. Judes to:
These rights may be limited where processing or retention is required or permitted for legal, medical-record, safeguarding, fraud-prevention, security or other purposes. St. Judes may verify the identity and authority of the person making a request.
Some technology or support providers may process or store information outside India. Where an international transfer occurs, St. Judes will take measures required by applicable law and use appropriate contractual, organisational and technical safeguards.
St. Judes maintains procedures to identify, investigate and respond to suspected personal-data breaches and security incidents. Where required by applicable law, St. Judes will notify affected individuals and the relevant authority.
Users may report a suspected privacy or security incident using the contact details below.
St. Judes may update this policy to reflect changes to the App, CRM, data-handling practices, applicable law or platform requirements. The updated policy will be published with a revised “Last updated” date. Where required, St. Judes will provide additional notice or obtain additional consent.
Questions, complaints, deletion requests, other privacy requests and suspected security incidents may be submitted to Grievance Cell:
St Jude India Child Care Centres
Cotton Green Campus
Ground Floor, Mumbai Port Trust Colony
ABC Colony (Rajas Nagar)
Zakaria Bunder Road, Sewri
Mumbai – 400015, Maharashtra, India
Email: grievance@stjudechild.org
Mobile: +91 022 45452600
Website: https://stjudechild.org/
For privacy or data-deletion requests, use the subject line: St. Judes For Life (Founded in the memory of Mrs. Rani Vicaji) Aid Request App – Privacy Request. This email address is the App’s privacy and grievance contact mechanism.