Privacy Policy

Effective date: 13 July 2026

1. Who We Are

VetriPath is a partnership firm registered in Coimbatore, Tamil Nadu, India. We operate vetripath.in, an e-learning platform for government exam preparation. VetriPath determines why and how personal data is processed for this service.

Address: 6/517, First Floor, Rayon Nagar, Sirumugai, Coimbatore - 641302, Tamil Nadu, India

Email: [email protected]

Phone: +91 9344175851

2. Information We Process

  • Account and profile data: email address, name, phone number, email-verification state, marketing preference, and, when Google sign-in is used, the Google account identifier and verified email returned by Google.
  • Authentication and security data: one-time-code records, session records, CSRF state, timestamps, and request metadata used for security and abuse prevention. The application uses an IP address in short-lived, in-memory rate limits; our hosting, Cloudflare, and application logs may also record request metadata such as IP address and user agent.
  • Payment and entitlement data: Razorpay order and payment identifiers, amount, currency, status, signature or webhook processing state, receipt details, purchased course, and access period. Razorpay handles card, bank, UPI, and other payment credentials; VetriPath does not receive or store complete payment-instrument details.
  • Learning data: course purchases, completed lessons, and playback events containing course/video identifiers, playback position, reported duration, a session identifier, and timestamps. Playback events are advisory engagement telemetry and are not the sole automatic basis for a refund decision.
  • Contact data: the name, email address, phone number, and message submitted through the contact form.

We do not currently run advertising trackers or a product-analytics script in this version of the site.

3. Why We Process Data

We process data to:

  • create and secure accounts, authenticate users, and prevent abuse;
  • provide purchased or free course access and remember learning progress;
  • create orders, confirm payments, grant entitlements, and issue receipts;
  • respond to contact and support requests;
  • send service messages such as login codes and payment-related communication;
  • send marketing messages only when the account holder has opted in; and
  • meet applicable accounting, tax, fraud-prevention, dispute, and legal obligations.

Where consent is the applicable basis, it may be withdrawn by contacting us. Marketing consent can be withdrawn without closing the account. Data needed to provide purchased access, secure the service, resolve a dispute, or meet a legal obligation may still need to be retained or processed.

4. Marketing Choices

Marketing is off by default. If you opt in, we may use the contact channels you supplied for course, offer, and platform updates. You can opt out through your profile settings or by contacting us. Transactional and security messages are separate from marketing and may still be sent when needed to operate your account.

5. Cookies and Browser Storage

  • Session cookie: a secure, HTTP-only cookie keeps you signed in and expires according to the configured session limits.
  • CSRF cookie/token: a security cookie and token protect state-changing requests from cross-site request forgery.
  • OAuth state: temporary sign-in state is stored during a Google login flow.
  • Cloudflare: Cloudflare may set functional security cookies, such as bot-management cookies, when its protection features are enabled.

We do not currently use advertising cookies. If analytics is added later, this policy and the site's consent controls must be updated before it is enabled.

6. Service Providers

We use service providers only for defined operational purposes:

  • Google: optional account sign-in and verified account information.
  • Resend: delivery of email login codes and service email.
  • Razorpay: checkout, payment processing, refunds, and payment-status webhooks.
  • Cloudflare: CDN/security, Stream video delivery, and R2 content-file storage.
  • Pushover: data-minimized operational alerts. VetriPath sends only an event type, sign-in method, or course title; names, email addresses, order IDs, and payment IDs are not included.
  • Hosting and deployment providers: application containers, Postgres application data, PocketBase CMS data, logs, and backups.

PocketBase stores editorial course content. End-user accounts, payments, purchases, and progress are stored in Postgres, not PocketBase.

Some providers operate global infrastructure and may process request or account data outside India. We do not promise that all data remains exclusively in India. Production deployment must verify each provider's configured region, contractual terms, and transfer safeguards.

7. Security

The application uses HTTPS in production, HTTP-only secure session cookies, CSRF protection, access controls, bounded request sizes, rate limits, signed payment verification, and restricted administrative credentials. No internet service can guarantee absolute security. Production operations also require encrypted secret storage, restricted origin access, monitored backups, and a tested restore procedure.

8. Retention

  • One-time codes stop being valid after 10 minutes. Related security records may be retained for abuse prevention and operational review.
  • Session records expire according to the configured absolute and idle limits.
  • Account, profile, entitlement, and progress data is generally retained while the account or purchased access remains active.
  • Contact submissions are retained while needed to answer the request and for a reasonable follow-up period.
  • Payment and receipt records are retained for accounting, tax, fraud, chargeback, and other applicable legal requirements.
  • Security logs and backups are retained according to the production retention schedule and may remain for a limited period after primary data is deleted.

Before production launch, VetriPath must approve concrete retention and backup-deletion periods with its legal/accounting advisers and configure operations to match them.

9. Your Requests

Subject to applicable law, you may ask us for information about your personal data, request correction or erasure, withdraw consent, nominate another person where the law provides, or raise a grievance. Email [email protected] from your registered address. We may need to verify your identity and may retain data that the law or an unresolved transaction requires us to keep.

10. Users Under 18

You must be at least 18 years old to create a VetriPath account. A learner under 18 may use the service only through an account created and controlled by a parent or lawful guardian. Contact us if you believe a person under 18 created an account without appropriate involvement; we will review and take appropriate action.

11. Breaches and Policy Changes

We will investigate personal-data incidents and make notifications required by applicable law. We may update this policy when the service, providers, or legal requirements change. Material changes will be communicated through an appropriate channel, and the effective date displayed on this page will be updated.

12. Grievances and Contact

For a privacy request or grievance:

Email: [email protected]

Phone: +91 9344175851

Address: 6/517, First Floor, Rayon Nagar, Sirumugai, Coimbatore - 641302, Tamil Nadu, India