1. Who ROAS EdTech is
ROAS EdTech ("we", "us", "our") operates the ROAS EdTech website and learning platform. ROAS stands for Return on Applied Studies — a learning philosophy focused on practical, outcome-oriented performance marketing education.
For privacy-related questions, contact us at [LEGAL CONTACT EMAIL].
2. What personal information we collect
We only collect information we need to provide, improve, and secure the Platform. The categories are described in the sections that follow.
3. Account information
When you create an account we collect:
- Name
- Email address
- Password (stored in a hashed form — we cannot see your plain password)
- Profile information you choose to add
4. Contact and communication information
When you contact us, sign up for a webinar, or submit a form, we may collect:
- Your email and phone number (including WhatsApp number where you provide it)
- The contents of your message or enquiry
- Your communication preferences
5. Payment and order information
When you purchase a plan we collect:
- Plan, amount, and currency
- Order and transaction references
- Billing email
We do not store your full card number, CVV, or bank credentials. Payment details are handled by our payment provider (see section 18).
6. Learning and platform activity
To deliver the learning experience we record:
- Lessons viewed, progress, and completion status
- Quiz and checkpoint responses
- Enrollments, plan entitlements, and access history
7. Simulation activity and performance data
Inside the simulator we record:
- Scenarios started and completed
- Decisions made (budgets, audiences, bids, creatives, and similar)
- Simulated outcomes (virtual spend, virtual revenue, ROAS, etc.)
- Day-by-day run history and scoring
This data is used to show you your own progress, to score your decisions, and to improve the simulator.
8. Portfolio and proof-of-work information
If you use portfolio features we store the case studies, submissions, and feedback you create. You control which items you make public or keep private. Public items are visible to anyone with the link.
9. Technical, device and log information
When you use the Platform we automatically receive:
- IP address (anonymised where feasible)
- Browser type, operating system, and device type
- Pages visited, features used, and time spent on pages
- Referring URL and UTM parameters where present
- Basic error and performance logs
10. How information is used
We use personal information only for the purposes described in sections 11–15 and where we have a lawful basis to do so (for example: performing our contract with you, legitimate interests, your consent, or legal obligations).
11. Account and service delivery
To create your account, authenticate you, deliver the plan you purchased, record progress, and support you when you reach out.
12. Payments and transactions
To process payments, issue entitlements, handle refunds, and keep transaction records for accounting and legal purposes.
13. Product communication
To send you service-related messages such as login alerts, password resets, plan receipts, important Platform updates, and changes to these policies.
14. Marketing communication
Where you have consented (for example by ticking the consent box at signup or checkout), we may send you emails or WhatsApp messages about upcoming cohorts, new features, webinars, or offers. You can unsubscribe at any time using the link in the message or by contacting us.
15. Analytics and security
To understand how the Platform is used, to improve features and content, and to detect abuse, fraud, and security incidents.
16. Cookies and local storage
The Platform uses:
- Essential storage — to keep you signed in and remember your session (stored by our authentication provider).
- Local storage — for small non-personal preferences such as UI state.
We do not run invasive third-party advertising tracking cookies. If we add analytics tools in future we will disclose them here.
17. Third-party service providers
We share data only with providers who help us run the Platform. They are contractually bound to use the data only for the service they provide. The current categories are described in sections 18–20.
18. Payment providers
Payments are processed by Razorpay (or another provider we disclose here if changed). Razorpay receives the billing details needed to complete the transaction and is subject to its own privacy policy and PCI-DSS obligations.
19. Email and WhatsApp providers
Transactional and (where consented) marketing emails may be delivered through an email service provider. Where WhatsApp messaging is configured, messages are delivered through a WhatsApp/messaging provider. We share only the recipient address/phone and the message content needed to deliver the message.
20. Infrastructure providers (Supabase)
The Platform's database, authentication, and server-side functions are hosted on Supabase. Supabase acts as a data processor under our instructions. Data is stored in the Supabase region configured for our project.
21. Data retention
We keep personal information only as long as needed for the purposes above, or as required by law:
- Account data: while your account is active, plus a reasonable period after closure.
- Payment/transaction records: as required by Indian tax and accounting law.
- Logs: for a limited period for security and debugging.
- Marketing consent records: to demonstrate consent while it is active and for a short period after withdrawal.
22. Data security
We use reasonable technical and organisational measures including:
- Encrypted connections (HTTPS) for all traffic.
- Row-level security and service-role restrictions on the database.
- Hashed passwords via the authentication provider.
- Secrets stored in the infrastructure provider's secret store, not in code.
- Access limited to people who need it.
No system is perfectly secure. If we become aware of a security incident that affects your data, we will notify you where required.
23. Your rights and consent withdrawal
Depending on where you are located, applicable law may give you rights such as:
- Accessing the personal data we hold about you.
- Correcting inaccurate data.
- Requesting deletion of your data, subject to legal and contractual retention.
- Withdrawing marketing consent at any time.
- Objecting to or restricting certain processing.
To withdraw marketing consent, use the unsubscribe link in any message or contact us directly.
24. How to request correction, deletion, or access
Write to [LEGAL CONTACT EMAIL] with:
- The email address associated with your account.
- What you are requesting (access, correction, or deletion).
- Any details that help us locate your record.
We will respond within a reasonable period (typically within [e.g. 30 days]) and may ask for reasonable verification of your identity.
25. Children's and minors' data
The Platform is intended for users aged 18 or older, or minors using it with a parent or guardian's involvement. We do not knowingly collect personal data from children under 13. If you believe we have inadvertently done so, please contact us and we will take appropriate steps.
26. International data processing and transfers
ROAS EdTech is based in India. If you access the Platform from outside India, your data may be transferred to, stored in, and processed in India and in the regions where our infrastructure providers operate. By using the Platform you acknowledge this.
27. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. Material changes will be reflected by updating the "Last Updated" date at the top of this page and, where appropriate, by email or in-platform notice. Continued use of the Platform after changes take effect means you accept them.
28. Contact and grievance information
For privacy questions, requests, or complaints:
- Email: [LEGAL CONTACT EMAIL]
- Entity: [LEGAL ENTITY NAME]
- Address: [REGISTERED ADDRESS]
Grievance process:
- Contact us at the email above with a clear description of your concern.
- We will acknowledge receipt within [e.g. 3 working days].
- We aim to resolve grievances within [e.g. 30 days].
- If unresolved, escalate in writing to the same address, marked "Privacy Grievance Escalation".