Privacy Policy
1) Overview
We respect your privacy. This Policy explains what data we collect, how we use it, how we protect it, and the choices you have. By using our Services, you agree to this Policy.
2) Scope
This Policy applies to our website, mobile apps, products, customer support, and any related integrations (e.g., payments, analytics, messaging).
3) Information We Collect
- Identity & Contact: name, email, phone, address, organization/school, role.
- Account & Auth: username, hashed passwords, OTP/2FA details, profile photo (if provided).
- Usage & Device: IP address, device/browser type, OS, pages/screens viewed, clicks, session duration, crash/diagnostic logs.
- Transaction & Payment: order IDs, invoices, payment status, limited payment metadata (actual card/bank details handled by our payment processor).
- Location (optional): approximate or precise location if you grant permission.
- Content You Provide: messages, forms, uploads (e.g., documents/photos), feedback.
- Third-Party/SSO: basic profile data (name, email) when you sign in with Google/Apple/etc., per your consent.
4) How We Use Information
- Provide, operate, and improve our Services.
- Create and manage user accounts; authenticate and secure access.
- Process transactions, invoices, notifications, and customer support.
- Personalize content, features, and recommendations.
- Monitor performance, debug, and prevent fraud/abuse.
- Comply with legal obligations and enforce our Terms.
Legal bases (if you’re in the EEA/UK): performance of a contract, legitimate interests (e.g., security, product improvement), consent (where required), and legal obligation.
5) Cookies & Tracking
We use cookies, local storage, and similar tech to:
- Keep you signed in and remember preferences,
- Measure traffic and performance,
- Improve features and fix issues.
You can manage cookies in your browser settings. If you block cookies, some features may not work.
6) Sharing & Disclosure
We do not sell personal data. We share information only with:
- Service Providers/Processors: hosting, analytics, email/SMS, customer support, payment processing, cloud storage—bound by confidentiality and data-processing terms.
- Business Transfers: merger, acquisition, or asset sale (we’ll notify you of changes).
- Legal: to comply with law, lawful requests, or protect rights, safety, and security.
- With Your Consent: when you explicitly ask us to share.
7) Payments
We use [Payment Processor Name] to handle payments. Your card/bank details are processed directly by them under their own security and privacy certifications (e.g., PCI-DSS). We only receive limited transaction metadata.
8) Data Retention
We keep personal data only as long as necessary for the purposes described above, to comply with legal/accounting requirements, or to resolve disputes. When no longer needed, we securely delete or anonymize it.
9) Security
We use industry-standard safeguards (encryption in transit, access controls, logging, backups). However, no method of transmission or storage is 100% secure.
10) Your Rights & Choices
Depending on your location, you may have the right to:
- Access, correct, or delete your data,
- Object to or restrict certain processing,
- Port your data,
- Withdraw consent where processing is based on consent,
- Opt out of marketing communications (use the “unsubscribe” link or contact us).
Make requests via [support email]. We may verify your identity before acting.
CCPA/CPRA (California)
California residents can request access/deletion and opt out of “sharing” for cross-context behavioral advertising. We do not sell personal information. Submit requests at [support email/link].
GDPR/UK GDPR (EEA/UK)
- Controller: [Company Name], [address].
- DPO/Contact: [DPO or privacy contact email].
- You may lodge a complaint with your local supervisory authority.
India (DPDP Act, 2023)
You can access, correct, delete, and withdraw consent for your personal data. Contact our Grievance Officer at [name + email].
11) Children’s Privacy
Our Services are not intended for children under [13/16]. We do not knowingly collect data from children. If you believe a child provided data, contact us to remove it.
12) International Transfers
We may process data in countries other than yours. Where required, we use safeguards such as Standard Contractual Clauses or comparable transfer mechanisms.
13) Third-Party Links & Integrations
Our Services may link to third-party sites or include integrations (e.g., maps, SSO). Their privacy practices are governed by their policies, not ours.
14) Do Not Track
Browsers may send “Do Not Track” signals. Our Services currently do not respond to DNT due to industry standards not being finalized.
15) Changes to This Policy
We may update this Policy from time to time. We’ll post the new version with an updated “Effective Date.” Material changes may be notified via email or in-app notice.