Privacy Policy — IIBS EduCoin

Effective date: [INSERT DATE OF PUBLICATION] · Version 1.0
Before publishing: this policy is drafted diligently and specifically for this app's actual data flows, based on Indian law (the Digital Personal Data Protection Act, 2023; the Information Technology Act, 2000 and the SPDI Rules, 2011). It is not a substitute for review by a licensed Indian lawyer before publication. Every field marked [INSERT ...] must be filled in with real information before this is published or submitted to Google Play — a policy with placeholder text will be rejected by Play's review, and an inaccurate policy creates real legal exposure.

1. Who this policy covers and who we are

This Privacy Policy explains how the IIBS EduCoin campus wallet application ("EduCoin," "the App," "we," "us") collects, uses, stores, shares, and protects personal data belonging to its users — students, staff acting as counter receivers, and administrators (together, "you," "Data Principal").

The App is operated by:

Data Fiduciary (operating entity)IIBS [CONFIRM: full registered legal name, e.g., "Indian Institute of Business Studies" or the exact registered trust/society/company name — "IIBS" is the common name, not necessarily the registered one]
Registered address75, Bangalore North, Jala Hobli, Begur, Muthugadahalli, Bengaluru, Karnataka [CONFIRM PIN code], India
Grievance Officer[INSERT full name]
Grievance Officer contact[INSERT email address] · [INSERT phone number, if any]

Under the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 ("SPDI Rules") and the Digital Personal Data Protection Act, 2023 ("DPDPA"), the person named above is responsible for handling complaints and requests relating to your personal data under this policy.

2. Scope

This policy applies to the EduCoin mobile application (Android/iOS) and the EduCoin website, both of which connect to the same backend service. It does not apply to any third-party website or service you may reach through a link inside the App.

3. Personal data we collect

We collect only the data needed to operate a campus wallet — we do not collect data for advertising, and the App has no advertising or third-party tracking SDK embedded in it.

CategoryWhat we collectWhen
Account & identity data Login ID, display name, role (student/receiver/admin), a securely hashed password, and — for students — a securely hashed 4-digit transaction PIN Account creation (by an administrator, or by you via Google Sign-In)
Contact data Email address (if you link a Google account or an administrator adds a recovery email), mobile number (optional, self-entered in your profile) When you provide it
Profile data Date of birth (optional), profile photo/avatar (optional, self-uploaded) When you provide it, via your Profile screen
Government/institutional ID document A photo of your college ID card or a government-issued ID, uploaded by you for identity verification When you use the "ID Verification" feature
Financial/transaction data Your EduCoin balance, and a record of every payment, credit, and balance adjustment on your account (amount, department/counter, time, and — for adjustments — a stated reason) Every time your balance changes
Support communications The subject, message, and category of any support ticket you submit to the administrator, plus an optional screenshot attachment When you use "Help & Support"
Authentication data (Google Sign-In) Your Google account's verified email address and display name — provided to us by Google only after you choose to sign in with Google Only if you choose to use "Continue with Google"
Session & security data A session token issued at login, its creation and expiry time; failed-login and support-ticket-submission counts, held briefly to prevent abuse Automatically, at login / on each request
We do not collect: precise or coarse device location, contacts, call/SMS logs, browsing history outside the App, biometric identifiers, or advertising identifiers. The App requests camera access solely to scan a payment QR code and to let you photograph a document for upload — we do not access the camera roll except to let you pick a file you choose.

4. How we use your data

PurposeData used
Operating your wallet — recording and displaying balances and transaction historyAccount, financial/transaction data
Authenticating you and keeping your account securePassword/PIN hashes, session data, Google Sign-In email
Verifying your identity as a member of the institutionGovernment/institutional ID document, name
Letting you recover access if you forget your passwordRecovery email, security question (if set)
Responding to support requestsSupport communications, contact data
Preventing fraud and abuse (e.g., brute-force login attempts, spam ticket submissions)Session & security data
Administering the campus wallet programme (e.g., an administrator crediting or correcting a balance)Account and financial/transaction data, visible to administrators only

We do not use your data for advertising, and we do not build behavioural or advertising profiles of you.

5. Who we share your data with

We do not sell your personal data. We share it only in these limited circumstances:

We do not use any third-party analytics, advertising, or crash-reporting service that receives your personal data.

6. Where your data is stored

The App's database and file storage are hosted on infrastructure located in India (AWS's Mumbai (ap-south-1) region). We do not routinely transfer your personal data outside India, other than the limited Google Sign-In verification described in §5, which is inherent to using that sign-in method.

7. How long we keep your data

DataRetention
Account and transaction dataFor as long as your account is active, and thereafter as required for the institution's financial/audit record-keeping obligations, or until deletion is requested and permitted under §8
ID document / avatar uploadsUntil you replace them, or your account is deleted
Support ticketsRetained as a service record; you may request deletion subject to §8
Session tokensExpire automatically 30 days from issue, or immediately on logout — whichever is sooner
Automated database backupsRetained on a rolling 14-day basis and then automatically deleted

8. Your rights (Data Principal rights under the DPDPA, 2023)

Subject to applicable law, you have the right to:

To exercise any of these rights, contact the Grievance Officer at the details in §1, or use the "Help & Support" feature inside the App.

9. About the EduCoin balance

EduCoin is a reward-only balance. Administrators award it to students at their discretion (for example, for good attendance or achievement) — students never pay money, through the App or otherwise, to acquire EduCoin balance, and EduCoin can never be redeemed by a student for cash. It is a closed-loop credit usable only at participating campus counters, and has no value outside that closed system. Where a payment exceeds a student's EduCoin balance, the shortfall is paid directly to the counter in cash, in person — that cash payment is not processed, held, or routed through the App in any way.

For the operating institution: because no money is ever paid by a student to obtain EduCoin — it is only ever awarded — this does not fit the Reserve Bank of India's definition of a Prepaid Payment Instrument (PPI) under the Payment and Settlement Systems Act, 2007 and RBI's Master Directions on PPIs, which centres on instruments a holder pays to load with value. It functions more like an internal rewards/loyalty-points programme than a payment instrument. This is a reasonable reading of the facts as they currently stand, not a substitute for confirmation from qualified legal counsel — and it would need re-examining immediately if the design ever changes to let students purchase, top up, or cash out EduCoin balance.

10. Children's data

EduCoin is intended for use by enrolled students, staff, and administrators of the institution, who are expected to be 18 years of age or older [CONFIRM this matches IIBS's actual enrolment policy — if any programme enrols under-18 students, this section and the account-creation flow need review with counsel before launch, since the DPDPA imposes specific verifiable-parental-consent obligations for under-18 users]. We do not knowingly direct the App at children, and we do not use children's data for behavioural monitoring, tracking, or targeted advertising. If you believe a child's personal data has been provided to us without appropriate consent, contact the Grievance Officer and we will address it under Section 9 of the DPDPA.

11. Security

We apply reasonable security practices and procedures as required under Section 43A of the Information Technology Act, 2000 and the SPDI Rules, including:

No method of transmission or storage is 100% secure. In the event of a personal data breach that is likely to affect you, we will notify the Data Protection Board of India and affected users as required under Section 8(6) of the DPDPA.

12. Changes to this policy

We may update this policy from time to time. If we make a material change, we will update the "Effective date" above and, where required by law, seek fresh consent or provide notice within the App before the change takes effect.

13. Contact us

For any question, request, or complaint about this policy or your personal data, contact:

Grievance Officer[INSERT NAME]
Email[INSERT EMAIL]
Address75, Bangalore North, Jala Hobli, Begur, Muthugadahalli, Bengaluru, Karnataka [CONFIRM PIN code], India