Your data
Privacy Policy
This policy describes the personal data TNPSCLab uses to provide secure bilingual learning and payment access.
Effective date: 11 August 2026 · Last updated: 29 August 2026
1. Scope and data controller
This Privacy Policy explains how TNPSCLab collects, uses, stores, shares and protects personal data when you use our public website, account features and paid digital learning services. TNPSCLab is responsible for the personal data described here. Contact details for privacy questions and grievances appear on our Contact Us page.
2. Data we collect
- Account data: name, email address, password hash, preferred language, target exam group, role and account status.
- Learning data: viewed lessons, answers, scores, attempts, time spent, progress, bookmarks, notes and plan entitlements.
- Transaction data: Annual All Access order details, amount, currency, payment status, payment-provider transaction identifiers, timestamps and refund status. We do not store full card numbers, CVV, UPI PINs or banking passwords.
- Technical and session data: IP address, browser and device information, login timestamps, active session identifier, security logs, cookies and local-storage preferences needed for language, theme, authentication and fraud prevention.
- Support data: messages, attachments and information you provide when requesting assistance, a refund or reporting a problem.
3. How and why we use data
- Create and secure your account, authenticate you and enforce the one-active-device rule.
- Deliver free and paid content, remember preferences, save progress and personalize the learning experience.
- Process and reconcile payments, activate entitlements, prevent duplicate or fraudulent transactions and handle refunds.
- Answer support requests, send service and security communications, diagnose errors and improve performance and content quality.
- Comply with legal, tax, accounting, payment-network, fraud-prevention and dispute-resolution obligations.
4. Consent and choices
We process data to provide services you request, meet legal obligations, protect legitimate security and operational interests, and where necessary based on your consent. You may change language and theme preferences, decline non-essential browser storage where offered, and withdraw consent for optional processing. Withdrawal does not affect prior lawful processing and may limit features that require the relevant data.
5. Cookies, analytics and advertising choices
TNPSCLab uses strictly necessary session cookies and browser storage for authentication, security, language, theme and your privacy preference. Optional analytics, Google and YouTube advertising measurement, personalisation and remarketing remain disabled until you choose them in Privacy settings. When enabled, Google Tag Manager operates through Google Consent Mode and receives only the events allowed by your choices. You may reopen Privacy settings and withdraw optional consent at any time.
With relevant consent, successful sign-up, login, free-trial start, content search, plan views and checkout starts may be measured. Search events contain result totals, the search surface and broad writing system—not the words entered. For a verified paid purchase, advertising measurement may receive the order identifier, value, currency and plan name. If you consent to advertising measurement, normalized email and phone values may be one-way SHA-256 hashed on our server before being made available to the conversion event; raw contact details, Cashfree credentials, learning answers and protected content are not included in tracking events.
6. Sharing and service providers
We do not sell or rent personal data. We may share the minimum necessary data with contracted hosting, database, email, support, security and payment providers acting for us; and, only with the relevant optional consent, analytics and advertising measurement providers. We may also share data with professional advisers, authorities where lawfully required, or during a genuine business reorganization subject to appropriate protection. Payment providers process payment credentials under their own privacy policies. Providers are expected to use data only for the contracted purpose and apply appropriate safeguards.
7. Retention
Account and learning data are kept while the account is active and afterward only while reasonably needed for reactivation, support, disputes, fraud prevention or a legal obligation. When an account is closed or data is no longer needed for those purposes, it is deleted or anonymized through our normal operational and backup cycles, unless lawful preservation is required.
Payment, invoice, tax, fraud, consent and refund records are retained for the periods required by applicable law, accounting needs and payment-network rules. Security and support records are kept only for as long as reasonably required to investigate incidents, resolve requests and protect the service.
8. Security and data location
We use reasonable administrative and technical safeguards such as password hashing, access control, session revocation, validation and restricted staff roles. No internet system can be guaranteed completely secure. If a breach creates a legally reportable risk, we will take required response and notification steps. Providers may process data in other locations subject to applicable law and contractual safeguards.
9. Your rights and grievances
Subject to applicable law, you may ask to access or correct your personal data, request erasure of data no longer needed, withdraw consent, obtain information about processing, nominate another individual to exercise applicable rights in the event of death or incapacity, or raise a grievance. We may verify identity before acting and may retain data that lawfully must be preserved.
Use the privacy/grievance contact on our Contact Us page and include your registered email and a clear description of the request. We will provide a reasonable opportunity for grievance redressal. Where applicable law provides a further remedy, you may approach the competent authority after first using our grievance process.
10. Children and policy changes
TNPSCLab is intended for exam candidates and is not directed to children. A person under 18 years of age must use the service only with verifiable consent and supervision of a parent or lawful guardian where required by applicable law. We do not knowingly use a child's personal data for targeted advertising or behavioural monitoring. Contact us if you believe a child supplied data without appropriate authorization.
We may update this policy for legal, security or service changes. Material changes will be posted with a revised date and notified where required by law.
