This Privacy Policy explains how the IIBS EduCoin campus wallet application ("EduCoin," "the App," "we," "us") collects, uses, stores, shares, and protects personal data belonging to its users — students, staff acting as counter receivers, and administrators (together, "you," "Data Principal").
The App is operated by:
| Data Fiduciary (operating entity) | IIBS [CONFIRM: full registered legal name, e.g., "Indian Institute of Business Studies" or the exact registered trust/society/company name — "IIBS" is the common name, not necessarily the registered one] |
|---|---|
| Registered address | 75, Bangalore North, Jala Hobli, Begur, Muthugadahalli, Bengaluru, Karnataka [CONFIRM PIN code], India |
| Grievance Officer | [INSERT full name] |
| Grievance Officer contact | [INSERT email address] · [INSERT phone number, if any] |
Under the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 ("SPDI Rules") and the Digital Personal Data Protection Act, 2023 ("DPDPA"), the person named above is responsible for handling complaints and requests relating to your personal data under this policy.
This policy applies to the EduCoin mobile application (Android/iOS) and the EduCoin website, both of which connect to the same backend service. It does not apply to any third-party website or service you may reach through a link inside the App.
We collect only the data needed to operate a campus wallet — we do not collect data for advertising, and the App has no advertising or third-party tracking SDK embedded in it.
| Category | What we collect | When |
|---|---|---|
| Account & identity data | Login ID, display name, role (student/receiver/admin), a securely hashed password, and — for students — a securely hashed 4-digit transaction PIN | Account creation (by an administrator, or by you via Google Sign-In) |
| Contact data | Email address (if you link a Google account or an administrator adds a recovery email), mobile number (optional, self-entered in your profile) | When you provide it |
| Profile data | Date of birth (optional), profile photo/avatar (optional, self-uploaded) | When you provide it, via your Profile screen |
| Government/institutional ID document | A photo of your college ID card or a government-issued ID, uploaded by you for identity verification | When you use the "ID Verification" feature |
| Financial/transaction data | Your EduCoin balance, and a record of every payment, credit, and balance adjustment on your account (amount, department/counter, time, and — for adjustments — a stated reason) | Every time your balance changes |
| Support communications | The subject, message, and category of any support ticket you submit to the administrator, plus an optional screenshot attachment | When you use "Help & Support" |
| Authentication data (Google Sign-In) | Your Google account's verified email address and display name — provided to us by Google only after you choose to sign in with Google | Only if you choose to use "Continue with Google" |
| Session & security data | A session token issued at login, its creation and expiry time; failed-login and support-ticket-submission counts, held briefly to prevent abuse | Automatically, at login / on each request |
| Purpose | Data used |
|---|---|
| Operating your wallet — recording and displaying balances and transaction history | Account, financial/transaction data |
| Authenticating you and keeping your account secure | Password/PIN hashes, session data, Google Sign-In email |
| Verifying your identity as a member of the institution | Government/institutional ID document, name |
| Letting you recover access if you forget your password | Recovery email, security question (if set) |
| Responding to support requests | Support communications, contact data |
| Preventing fraud and abuse (e.g., brute-force login attempts, spam ticket submissions) | Session & security data |
| Administering the campus wallet programme (e.g., an administrator crediting or correcting a balance) | Account and financial/transaction data, visible to administrators only |
We do not use your data for advertising, and we do not build behavioural or advertising profiles of you.
We do not sell your personal data. We share it only in these limited circumstances:
We do not use any third-party analytics, advertising, or crash-reporting service that receives your personal data.
The App's database and file storage are hosted on infrastructure located in India (AWS's Mumbai (ap-south-1) region). We do not routinely transfer your personal data outside India, other than the limited Google Sign-In verification described in §5, which is inherent to using that sign-in method.
| Data | Retention |
|---|---|
| Account and transaction data | For as long as your account is active, and thereafter as required for the institution's financial/audit record-keeping obligations, or until deletion is requested and permitted under §8 |
| ID document / avatar uploads | Until you replace them, or your account is deleted |
| Support tickets | Retained as a service record; you may request deletion subject to §8 |
| Session tokens | Expire automatically 30 days from issue, or immediately on logout — whichever is sooner |
| Automated database backups | Retained on a rolling 14-day basis and then automatically deleted |
Subject to applicable law, you have the right to:
To exercise any of these rights, contact the Grievance Officer at the details in §1, or use the "Help & Support" feature inside the App.
EduCoin is a reward-only balance. Administrators award it to students at their discretion (for example, for good attendance or achievement) — students never pay money, through the App or otherwise, to acquire EduCoin balance, and EduCoin can never be redeemed by a student for cash. It is a closed-loop credit usable only at participating campus counters, and has no value outside that closed system. Where a payment exceeds a student's EduCoin balance, the shortfall is paid directly to the counter in cash, in person — that cash payment is not processed, held, or routed through the App in any way.
EduCoin is intended for use by enrolled students, staff, and administrators of the institution, who are expected to be 18 years of age or older [CONFIRM this matches IIBS's actual enrolment policy — if any programme enrols under-18 students, this section and the account-creation flow need review with counsel before launch, since the DPDPA imposes specific verifiable-parental-consent obligations for under-18 users]. We do not knowingly direct the App at children, and we do not use children's data for behavioural monitoring, tracking, or targeted advertising. If you believe a child's personal data has been provided to us without appropriate consent, contact the Grievance Officer and we will address it under Section 9 of the DPDPA.
We apply reasonable security practices and procedures as required under Section 43A of the Information Technology Act, 2000 and the SPDI Rules, including:
No method of transmission or storage is 100% secure. In the event of a personal data breach that is likely to affect you, we will notify the Data Protection Board of India and affected users as required under Section 8(6) of the DPDPA.
We may update this policy from time to time. If we make a material change, we will update the "Effective date" above and, where required by law, seek fresh consent or provide notice within the App before the change takes effect.
For any question, request, or complaint about this policy or your personal data, contact:
| Grievance Officer | [INSERT NAME] |
|---|---|
| [INSERT EMAIL] | |
| Address | 75, Bangalore North, Jala Hobli, Begur, Muthugadahalli, Bengaluru, Karnataka [CONFIRM PIN code], India |