Who handles your data
[company legal name] (“LearnKit”) decides how and why your personal data is handled on this platform. Under the Digital Personal Data Protection Act, 2023, that makes us the data fiduciary and you the data principal.
One thing worth saying plainly: we do not sell your data, and we never will. We make money from platform fees and plan fees. Your data is not the product.
What we collect
When you open an account
- Name, email address and password (stored only as a hash, never as text).
- The role you chose, and for creators, the store handle you claimed.
- Anything you add later: bio, photograph, phone number.
When you buy something
- Name, email, phone number, and what you bought.
- The order amount, method and status. We never see or store your card number, CVV, UPI PIN or netbanking password — those go straight to the payment gateway.
When you sell something
- Bank account details and IFSC, if you add them on the payouts screen. For now they stay in your own browser and are not sent to us; they will be needed once automatic payouts open.
- PAN, and GSTIN if you have one, once payouts open, because tax law requires them.
Automatically
- Basic technical data: IP address, browser, device type, pages opened, errors hit.
- Progress data if you are studying: which lessons you finished, notes you wrote.
Why we collect it
- To run your account and deliver what you bought. Without this the service cannot work, so it is not optional.
- To pay creators and to meet tax law. Bank details, PAN and GST records are required by law, not by preference.
- To keep the place safe: spotting fraud, piracy and account takeovers.
- To support you when you write to us.
- To send marketing — only if you ticked the box. Nothing is pre-ticked, no email is sent yet, and once it is, every marketing email will carry an unsubscribe link that works.
Who else sees it
Only the people who have to, and only what they need:
- The creator you bought from gets your name, email, phone number and what you bought — they need it to deliver and to support you. They may only use it for that, unless you separately agreed to hear from them. For their own marketing they are an independent fiduciary and answerable for it.
- The payment gateway ([Razorpay]) processes the payment and holds the card or UPI details we never see.
- Infrastructure providers — Google Firebase for accounts and the database, the file storage that holds what creators upload, and Amazon Web Services (Amazon SES), which sends our emails, such as the welcome email, order confirmations with access links, sale notices to creators and reminders before a live session — process data on our instructions only. No WhatsApp provider is connected yet.
- Tax and law enforcement authorities, where a law or a valid order requires it.
- A buyer of the business, if the company is ever sold, on the same terms as this policy. You would be told before anything moved.
What is stored on your device
We use your browser’s local storage for things that only make sense on your device: your light or dark theme choice, your session, your progress through a lesson, drafts you have not saved, a working copy of your store and orders, and, for creators, any bank details saved on the payouts screen. This stays in your browser and is cleared when you clear site data.
We do not run third-party advertising or cross-site tracking on this platform.
How long we keep it
- Account data — while your account is open, then up to [90] days after you close it, so that a mistaken deletion can be undone.
- Order, invoice and payout records — [8] years, because tax and companies law requires it. Closing your account does not delete these.
- Support messages — [3] years.
- Technical logs — [180] days.
Your rights
Under the DPDP Act you can:
- See what we hold about you, and who we shared it with. Students can export it themselves from Profile.
- Correct anything wrong or out of date.
- Have it erased, except records we are legally required to keep.
- Withdraw consent for anything you consented to, such as marketing, as easily as you gave it.
- Nominate someone to exercise these rights if you die or become incapable.
- Complain — to our Grievance Officer first, and then to the Data Protection Board of India if we do not resolve it.
Write to [email protected] and we will answer within [30] days.
How we protect it
- Everything travels over HTTPS.
- Passwords are hashed by Google Firebase Authentication. Nobody here can read yours.
- Database rules let a signed-in user read and write only their own records, and only the account that claimed a store link can change that store and its products.
- Each download goes through a link issued to one buyer that expires on its own, never an open web address.
- Card and UPI credentials never touch our servers.
No system is perfectly safe. If a breach ever affects you, we will tell you and the Data Protection Board without undue delay, and say plainly what happened and what to do.
Children
This platform is not intended for children under 18. Where we know a user is a child, we will not process their data without verifiable parental consent, and we will not track them or show them targeted advertising. If you believe a child has given us data, write to us and we will remove it.
Data outside India
Some providers we rely on, including Google Firebase, may process data on servers outside India. We keep the primary database in the [asia-south1] region and only use providers who commit to protections comparable to those in this policy and to the restrictions the Central Government sets.
Grievance Officer
As required by Indian law:
[Officer name]
[company legal name]
[registered address]
[email protected]
We acknowledge complaints within [48 hours] and resolve them within [30] days.
Changes to this policy
If we change how we handle your data in a way that matters, we will email you before it takes effect. The date at the top of this page tells you which version you are reading.
The rules for using the platform are in the terms of service.