Skip to content

Privacy Policy

This policy explains what personal data PipelinePrep collects, why we collect it, how long we keep it, and the rights you have over it.

Last updated: 1 October 2026

1. Who we are and scope

PipelinePrep (“we”, “us”) operates the PipelinePrep website at https://pipelineprep.in. This policy covers the Platform, including accounts, purchases, quizzes, and scenarios.

We process personal data in accordance with the Digital Personal Data Protection Act, 2023 (the “DPDP Act”) and applicable rules made under it. Where this policy is inconsistent with the DPDP Act, the Act prevails.

2. What we collect

We do not collect payment credentials

Card numbers, UPI handles, and banking credentials are entered directly into our payment gateway (Razorpay) and are never received, stored, or transmitted through our servers. We store only the payment identifiers, amount, and status needed to grant and record access, and we receive a limited transaction report from the gateway. Razorpay handles your payment data under its own privacy policy and its PCI DSS obligations.

We collect the following categories of data:

Account data

Your email address, hashed password, display name, and account creation date. If you choose to provide them: your target role, experience level, and leaderboard display preference.

Practice activity

Quiz attempts and your answers, scores, time taken, scenario progress and completion, and bookmarks. This is what powers your dashboard, history, and score tracking. If you do not want us to retain this history, you can delete your account.

Purchase and billing records

Your plan, the amount paid, any coupon applied, order and invoice numbers, payment and order identifiers from the gateway, and subscription start and expiry dates. We retain these because tax and accounting law requires it.

Messages

If you contact us, we collect the name, email address, and content of your message so we can respond.

Technical data

Our servers may process your IP address, user agent, and request logs for security, rate limiting, and diagnosing errors. We keep these briefly and do not use them to build advertising profiles.

We also record aggregated, non-identifying usage statistics (for example, how many people attempted a given quiz) to decide what content to write next. These statistics are not linked to an individual.

3. How we use your data, and on what basis

We process data only for the purposes listed here:

  • To provide the service. Authenticating you, delivering quizzes and scenarios, grading your answers, and showing your progress and history.
  • To process payments and meet legal obligations. Granting Premium access, issuing tax invoices, and retaining records required by tax and accounting law.
  • To secure the service. Preventing abuse, enforcing rate limits, detecting fraud, and investigating account compromise.
  • To communicate with you. Password reset links, receipts, subscription expiry reminders, and replies to your messages.
  • To improve the service. Understanding which content is useful through aggregated statistics.

Our lawful bases, as recognised by the DPDP Act, are performance of a contract (for accounts, content, and payments), compliance with a legal obligation (tax and accounting records), and legitimate interests (security, fraud prevention, and service improvement). We do not use your data for cross-context behavioural advertising, and we do not sell or share your personal data with third parties for their own marketing.

Where consent is the appropriate basis (for example, optional marketing emails), you may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal. Service and transactional emails are not marketing and cannot be opted out of while you hold an account.

4. Cookies and local storage

We use a small number of cookies, all necessary rather than optional:

  • pp_session — a signed, HTTP-only session cookie that keeps you signed in. It contains only an identifier and a signature; it does not contain your personal data in readable form.
  • Rate limiting — short-lived server-side records keyed by IP address used to prevent automated abuse of sign-in and checkout.

We do not use advertising cookies or third-party tracking pixels. If privacy-respecting analytics are enabled, they are configured to set no cookies and to record no cross-site identifiers.

5. Who we share data with

We share the minimum necessary data with the following categories of processors, each bound to use the data only to provide services to us:

Payment gateway

Razorpay, for processing payments, verifying them, and issuing refunds. Your payment credentials go directly to them and are not held by us.

Cloud hosting

Amazon Web Services, which hosts our servers and database. Data is stored in an AWS region in India wherever practicable.

Email delivery

An email delivery provider (Amazon SES or equivalent) that sends transactional emails on our behalf, such as password resets and invoices.

Professional advisers

Accountants, auditors, and legal advisers, where required to comply with our legal and tax obligations.

We do not sell personal data, rent mailing lists, or disclose personal data to third parties for their own commercial purposes. We may disclose data where required by law, a valid court order, or to establish or defend legal claims.

6. How long we keep data

Account data

For as long as your account is active, and for 12 months afterwards unless you ask us to delete it sooner.

Practice history

Until you delete your account, or 12 months after your last activity.

Billing records

Retained for 8 years from the date of transaction, as required by Indian tax and accounting law, even if you delete your account.

Security logs

Typically 90 days, or longer where needed to investigate an incident.

Data is deleted or anonymised when the applicable period ends. Anonymised aggregate statistics may be retained indefinitely because they cannot be linked back to you.

7. Your rights

Under the DPDP Act, you have the following rights. To exercise any of them, email support@pipelineprep.in or use the contact page. We respond within 30 days and may ask you to verify your identity first.

  • Access. A copy of the personal data we hold about you, and information about how we use it.
  • Correction. Have inaccurate or incomplete data corrected. You can edit most profile fields yourself from your dashboard.
  • Erasure. Have your data erased, where there is no overriding legal reason to keep it. Note that billing records must be retained for tax purposes, and that deleting your account removes your progress and history permanently.
  • Data portability / export. Receive your data in a structured, commonly used, machine-readable format. Ask us and we will provide a JSON export of your account, attempts, and orders.
  • Withdraw consent. Where we rely on consent, withdraw it at any time.
  • Nominate someone. Where you are unable to exercise these rights yourself, you may nominate another person to do so on your behalf.
  • Grievance redressal. Raise a complaint and receive a response. See section 10.

8. Security practices

We apply technical and organisational measures proportionate to the risk, including:

  • Encryption of data in transit using TLS, with HTTPS enforced across the whole Platform.
  • Passwords hashed with bcrypt using a per-password salt. We never store or log plaintext passwords, and we cannot see your password.
  • Premium content access checked on the server for every request. Correct answers and premium scenario content are not sent to clients that are not entitled to see them.
  • Rate limiting on sign-in, sign-up, password reset, contact, and checkout endpoints to prevent abuse and credential stuffing.
  • Webhook signature verification on payment notifications, so subscription state cannot be altered by forged requests.
  • Regular database backups, and access controls limiting who can reach production data.

No system is perfectly secure. If we become aware of a personal data breach that is likely to harm you, we will notify the Data Protection Board and notify you without delay as required by the DPDP Act, including a description of the breach, the likely consequences, and the remedial measures taken.

9. Children's data

The Platform is not directed at children, and we do not knowingly collect personal data from anyone under 18. If you are under 18, do not create an account. If you believe a child has created one, contact us and we will delete it.

10. Grievance officer and contact

In line with the DPDP Act, we have designated a grievance officer who is responsible for ensuring compliance and addressing complaints about the processing of personal data.

Grievance Officer: [Name, to be published]

Email: support@pipelineprep.in

If you are not satisfied with our response, you may approach the Data Protection Board of India. We would rather you raise it with us first, and we will treat that as a priority.

11. International transfers and hosting

Our servers and database are hosted on Amazon Web Services. We use an AWS region in India as our primary location. Some service providers (for example, email delivery or support tooling) may process data outside India. Where personal data is transferred outside India, we rely on contractual safeguards and, where required, obtain any certification or consent mandated by the DPDP Act.

12. Changes to this policy

We may update this policy from time to time. Material changes will be announced on the Platform or by email before they take effect. Your rights under the DPDP Act apply regardless of the version of this policy in force when your data was collected.

13. Related documents