Last updated 9 October 2026
Pandalers is a guide to Durga Puja pandals in Kolkata, operated by IndoGeek. You can read all of it without an account: an account exists so a photograph you contribute can be credited to you and so your visit progress can follow you to another device. The site also shows advertising, which is supplied by third-party networks and is described in full below.
In short: your visit progress and your location preference stay in your own browser unless you sign in. Your position is sent to the server only when a feature you asked for needs it, and it is never stored. If you create an account we keep your address and a hashed password, and nothing else you did not type. Advertising is served by third parties who set their own cookies, and you can turn personalised advertising off.
Four things, in your browser's local storage. None of them is sent to us unless you sign in, and then only the visit progress.
Your visit progress records which pandals you have visited, kept separately for each Puja year, with the time you marked each one. This is what the Progress page reads. It stays in the browser; if you use another device, or another browser, it starts empty — unless you sign in, which copies it to your account so the next device can pick it up. A Puja year runs to 31 December: at midnight on New Year's Eve the year that ended becomes history, kept on the device under Previous years on the Progress page, and the new year starts from zero.
Your location preference is a single flag recording that you turned location on, so the site does not ask again on every page. It contains no coordinates and no history. Turning location off in the site forgets it.
Automatic visit detection is a second flag, off by default, recording whether you asked the site to mark a pandal for you when you spend long enough at it. It is a preference, not a position.
Your theme choice is light or dark, so the site does not flash the other one while loading.
Loading any page sends the usual request information: your IP address, the address of the page or API endpoint requested, the time, and your browser's user agent. Our web server and API keep access logs for a short period for debugging and for rate limiting.
Your browser gives us a position only after you allow it, and only while the site is open. It is used to answer the question you just asked: which pandals are near you, how far each one is, and whether you have arrived at one. To compute those distances the coordinates are sent to our API, which measures them and returns the answer.
Those coordinates are not stored: they are not written to our database, are not attached to your progress, and are not used to build a history. Because they travel in the request address, a coordinate can appear in the web server's access log in the same way any requested URL does; those logs are short-lived and are not used for any other purpose.
When you plan a walking or driving route, the coordinates of the stops in that route are sent from our server to OpenRouteService to measure the streets between them. Only the stops are sent. Nothing about you is sent with them. Routes are cached so that the same journey is not requested twice.
A photograph you contribute is stored on our server and shown publicly in that pandal's gallery, together with the date it was uploaded and the display name on your account. It is not private and it may be seen by anyone. Please do not upload pictures of people who have not agreed to it.
Photographs are stored exactly as you upload them. Cameras and phones very often embed metadata in a JPEG, frequently including the place the picture was taken. If that matters to you, remove the metadata before uploading, or share the photograph without it.
An account needs an email address and a password. The address has to be one that can receive mail — a mistyped address is refused when you sign up, because an account nobody can write to is an account nobody can recover — and the password is stored only as a salted hash, never as text. You may also add a display name and a profile picture, and both are optional: without a name, your uploads are credited to the part of your email address before the @.
While you are signed in we keep your visit progress on the server, so it can follow you to another device, and we record which account contributed a photograph so the picture stays credited to you. If you sign in with Google, we receive your address and the fact that Google verified it, and nothing else; we never see your Google password. Signing in sets one cookie, which is required for the account to work at all: it is marked HttpOnly so scripts cannot read it, SameSite=Lax, Secure on the public site, and it expires after thirty days of being unused.
When we count that an advertisement was displayed or clicked, we store which position on the page it was, which network supplied it, which page it appeared on, how large the box actually was, and the ordinary request details above. There is no identifier of any kind in that record and no cookie is set or read by our own code in order to make it — the same rule our page-view counter follows. It is what the Ads figures in the operator's console are counted from, and it is deleted with the rest of the log.
Advertising on this site is served by third-party networks, configured by the operator in the site's own admin panel. Google AdSense is the network that is set up by default; the disclosure below applies to it, and the same rules apply to any other network configured in its place.
Those cookies belong to the networks, not to us: we cannot read them and we do not decide what goes in them. If you would rather not have them at all, your browser and any content blocker can refuse third-party cookies — the site keeps working, and the ads simply stop being chosen for you. Where the law requires consent for personalised advertising, that choice is the network's to request and yours to give or refuse; refusing it never costs you access to anything here.
Google describes what its advertising products collect and how they use it in How Google uses data when you use our partners' sites or apps, which is the explanation its own publisher policies point to.
Every ad is labelled Advertisement so it cannot be mistaken for something this project published, and no ad is placed on the sign-in, account, error or maintenance pages.
Fonts and images the site ships are served from our own server, so loading a page does not contact a font or asset network.
Progress is yours to clear at any time on the Progress page. Location can be turned off there or in your browser's site settings. To have a photograph you uploaded taken down, whether it is yours or one of you, open an issue on the project's issue tracker with the pandal and, if you have it, the link to the picture. Removal is manual, so please allow a little time.
Closing your account deletes the account, its sessions and the visit progress stored with it. Photographs you contributed stay in the gallery, because they are part of the festival record rather than of the account — but you can ask for any of them to be taken down by the route above. You can also ask us for a copy of what is held about you, or ask for it to be deleted.
This site is not directed at children. It asks nobody for personal details, it does not run interest-based advertising aimed at children, and an account is not required to use anything here. If a child has created an account or uploaded a photograph that you would like removed, use the route above and we will remove it.
If this policy changes, for instance if a new service is added or a feature that stores something new, the date at the top of this page changes with it. The history of every change is public in the project's repository.
The policy above is about the two things you give this site: a location, and a photograph. The other direction, what this site gives you and on what terms, is settled by the licence. Pandalers is not open source. Copyright in the code, the design, the written content, the pandal records and the photographs published here belongs to Tanumoy Maity, and the name Pandalers is a mark of the same owner.
You may read the site and use it as a visitor. Copying it, reusing its data, or running any of it under this name or one close to it needs written permission first. The terms, and the signed notice of ownership behind them, are here: download the licence or read it in the browser.
Questions about any of this, or a request about something you have contributed, are best raised on the issue tracker. See also what Pandalers is and where its data comes from.