Institute

Privacy Policy

Last updated: 18 August 2026

1. Who we are

Institute is a multi-tenant software service for managing classes, attendance, students, and fees. It is operated at samarpan.app (the “Service”). This policy explains how we handle personal information when you visit the Service or an institute uses it.

Each institute (a “tenant”) is responsible for the student, guardian, and class records it enters. We process that information to provide the Service to the institute. We are responsible for staff account information used to sign in to the Service.

2. Information we collect

Account and staff data. Phone number (used to sign in with a one-time code), name, optional email, institute membership and role, and session information.

Business interest. If you ask to be contacted from the public home page, we store the email and mobile number you submit so we can follow up. This is for India-based businesses considering the Service, not student or guardian records.

Institute records. Data an institute chooses to store, which may include student name, gender, date of birth, course and center, attendance, schedules, fee charges and payment records, and guardian or billing contact name and phone.

Communications. One-time passwords sent by SMS, and class or fee notices sent by WhatsApp or similar channels to numbers the institute provides.

Technical data. Device and browser details, IP address, request identifiers, and diagnostic logs. We use error monitoring to keep the Service reliable.

We do not require payment card numbers to use the Service. Fee amounts recorded in the Service are institute bookkeeping, not card processing by us.

3. Students and children

Institutes may store records about students, including people under 18. Guardian name and phone are required when the institute records a student as under 18. The institute must have a lawful basis and any required consent or parental authorization before entering that information or sending notices to those contacts.

The Service is not directed at children as end users. Students and guardians do not create staff accounts.

4. How we use information

We use personal information to:

  • Create and authenticate staff sessions (phone OTP and signed-in sessions)
  • Respond to businesses that leave contact details on the public home page
  • Provide class, attendance, student, and fee features the institute configures
  • Send OTPs and, on the institute’s instruction, notices to student or guardian contacts
  • Secure, operate, troubleshoot, and improve the Service
  • Comply with law and enforce our terms

We do not sell personal information or use it for advertising.

5. How we share information

We share information only as needed to run the Service:

  • Hosting, database, file storage, and application infrastructure providers
  • SMS providers for one-time sign-in codes
  • WhatsApp / Meta (or similar messaging providers) when an institute sends a notice
  • Error monitoring and logging providers
  • Professional advisers, or authorities, when required by law or to protect rights and safety

Institute staff with access to that tenant can see the records stored for it. We do not share one institute’s operational records with another institute.

6. Cookies and similar technologies

We use essential cookies and similar storage for sign-in sessions and basic site preferences. We do not use advertising cookies. You can block cookies in your browser; doing so may prevent sign-in from working.

7. Retention

We keep account and institute data for as long as the institute’s account is active and as needed to provide the Service, resolve disputes, and meet legal duties. OTP codes and sign-in tickets expire quickly and are not reused. If an institute account is closed, we delete or de-identify personal data within a reasonable period, unless we must retain it longer (for example, security logs or legal claims). Business interest email and phone numbers from the public home page are kept until we have followed up and no longer need them, or you ask us to delete them.

8. Security and international processing

We use administrative and technical measures appropriate to the Service, including tenant isolation of operational records and access limited to authenticated members. No method of transmission or storage is completely secure.

Providers may process data in India and in other countries. Where we transfer personal information, we do so to operate the Service and with safeguards our providers offer.

9. Your rights

Depending on applicable law (including India’s Digital Personal Data Protection Act), you may have rights to access, correct, or erase personal information, withdraw consent where processing is consent-based, and nominate someone to act for you in certain cases.

Staff can update some profile details in the Service. For student or guardian records, contact the institute that entered them — that institute decides what to keep. For account or platform requests, email privacy@samarpan.app.

10. Changes

We may update this policy. The “Last updated” date at the top will change when we do. Continued use of the Service after an update means you accept the revised policy.

11. Contact

Privacy questions: privacy@samarpan.app.