Privacy Policy
Last updated: October 7, 2026
Pareeksha (“Pareeksha”, “we”, “us”) operates the website pareeksha.in and the mock-test and study services offered on it. This policy explains what personal data we collect, why we collect it, and the rights you have over it. We follow India’s Digital Personal Data Protection Act, 2023 (DPDP Act) and its Rules. For the DPDP Act we are the “Data Fiduciary” and you are the “Data Principal”. This notice is also available in Hindi (हिन्दी में पढ़ें).
1. Data we collect
- Account data. When you sign in with Google, we receive and store your name, email address and profile photo. We never receive or store your Google password.
- Phone number. When you sign in with WhatsApp (on the website or in our Android app), we store your mobile number and send one-time login codes to it on WhatsApp. If you opt in, we also send exam and account updates there; you can opt out at any time from Settings, and we keep a record of when and how you opted in or out. Your number is stored encrypted.
- Learning data. Your test attempts, answers, scores, saved questions, referrals and progress, which is what powers your dashboard and percentile.
- Payment data. When you purchase access, payments are processed by Razorpay. We store the order reference, amount, status and plan. We do not store your card, UPI or bank details. Those are handled entirely by Razorpay under PCI-DSS. In the Android app you can also pay through Google Play; Google processes that payment, and we receive only the purchase reference needed to unlock your access.
- Android app. The app uses the same account and learning data as the website. It does not access your location, contacts, camera, microphone or files, and contains no advertising SDKs.
- Technical data. IP address, device/browser type and pages viewed, used for security, rate-limiting and to improve the product.
- Analytics & cookies (optional). Only if you press Accept on the cookie banner, we load Google Analytics and Google Tag Manager (aggregate usage), the Meta pixel (measuring whether our Meta campaigns work), Zoho PageSense (heatmaps and session recordings of how pages are used; typed text and payment details are not recorded) and the Zoho SalesIQ chat widget. If you decline, none of these load. Essential cookies that keep you signed in are always used. You can change your choice any time via .
2. Why we use it, and on what basis
We use personal data only for the purposes below. We do not sell it and we do not use it for anything else without asking you first.
| Purpose | Data | Basis |
|---|---|---|
| Create your account, sign you in, run tests, show scores, ranks and percentile | Name, email, phone, learning data | You asked for the service (consent given by signing up) |
| Take payment, unlock access, send receipts and payment-failure notices, keep tax records | Order reference, amount, plan, email/phone | Performing your purchase; legal duty to keep accounts |
| Security, fraud and abuse prevention, rate limiting | IP address, device/browser type | Protecting you and the service |
| Reply to your messages and complaints | Name, email, message | You contacted us |
| WhatsApp and email updates, exam alerts, offers | Phone / email | Your separate, optional consent (see below) |
| Measure aggregate usage, heatmaps, session recordings, chat widget | Cookies, pages viewed, device data | Your cookie consent (optional) |
What you can refuse. Updates on WhatsApp/email and analytics cookies are optional: refusing them never limits your tests, scores or payments. Login codes, receipts and payment notices are service messages and are not marketing. You can withdraw any consent at any time, as easily as you gave it, from Settings, the unsubscribe link in an email, or . Withdrawing does not affect what we did before you withdrew.
3. Sharing
We share data only with processors who help us run the service: Google (sign-in and Google Play payments), Razorpay (payments), our WhatsApp messaging provider (login codes and opted-in updates), Zoho (invoicing, support tickets and, if you subscribe, email updates), our hosting and database providers, and analytics providers you have consented to. We do not share your phone number with Zoho. Each processes data on our instructions. Our servers and some providers are located outside India (for example hosting, analytics and Google services); where that happens we use providers with published security commitments, and the DPDP Act allows such transfers unless the Government restricts a country. We may disclose data if required by law or to a court or authority.
4. Retention
We keep account and learning data for as long as your account is active. Payment records are kept as long as required by Indian tax and accounting law. Contact details we copy for operational reasons are kept only as long as needed: login-code records keep your number for 7 days and are deleted after 30; WhatsApp delivery logs keep your number for 90 days; email delivery logs keep your address for 180 days. You can delete your account at any time from Settings in the app or on the website, or by email — see how to delete your account. Deletion removes your contact details from our systems and from our invoicing and email providers; we keep a record that the deletion happened.
5. Your rights
Under the DPDP Act you may:
- Access a summary of your data and who we share it with: download a copy when signed in.
- Correct or complete your details in Settings, or ask us.
- Erase your data: delete your account.
- Withdraw consent for optional processing at any time.
- Nominate another person to exercise these rights if you die or cannot act for yourself.
- Complain to us first; if unresolved, to the Data Protection Board of India.
Make any request at pareeksha.in/privacy/rights or email privacy@pareeksha.in. We confirm receipt within 48 hours and resolve within 30 days.
Grievance Officer: Shiv, Founder and Grievance Officer, privacy@pareeksha.in.
6. Security
Sessions use secure, HTTP-only cookies. Traffic is served over HTTPS. Phone numbers are encrypted at rest (AES-256) with keys held separately from the database, and are looked up by a keyed hash rather than in readable form. Login codes are never stored, only a hash of them. Access to production data is restricted, and staff without an administrator role see only the last four digits of a number. No system is perfectly secure, but we take reasonable technical and organisational measures to protect your data. If a breach affects your personal data we will tell you and the Data Protection Board of India, as the law requires, describing what happened, what it may mean for you and what you can do.
7. Children
Pareeksha is meant for people who are 18 or older. If you are under 18, you may use it only with the knowledge and consent of a parent or legal guardian, who is responsible for your account. For a person who tells us they are under 18 we switch off analytics and recording on their sessions, do not send them marketing messages, and do not track or profile them for advertising. A parent or guardian can ask us to access or delete a child’s data at /privacy/rights; we may ask for proof of the relationship.
8. Changes & contact
We may update this policy; the “last updated” date will change accordingly, and for material changes we will ask for your consent again where the law requires it. Questions or requests? Email info@pareeksha.in. Cookie choices: .