Privacy Policy
What’s in this policy
1. Who we are
Learn and Excel is an Indian digital-product publisher operating the website learnandexcel.in. When this policy says “we”, “us” or “our”, we mean Learn and Excel. When it says “you” or “your”, we mean the person visiting the site or buying a product.
2. What information we collect
We only collect information that is necessary to deliver our products, take payments, and improve our service. Specifically:
Information you give us
- Email address — for delivering downloads, receipts, and (occasional) product updates.
- Mobile number — required by our payment gateway (Razorpay) for OTPs, refund processing, and order receipts.
- Name — optional, for personalising delivery emails and invoices.
- Payment details — card numbers, UPI IDs, net-banking credentials are entered directly on Razorpay’s secure checkout page. We never see or store these.
Information collected automatically
- Browser & device info — user-agent, IP address (anonymised before storage), referring URL. Used to debug issues and prevent fraud.
- Marketing attribution — if you click an ad on Meta (Facebook/Instagram) or Google, we receive a click identifier (such as
fbclidorgclid) and any UTM tags. This lets us measure which campaigns work. - Page-view analytics — anonymous counts of which pages were visited, which CTAs were clicked. See cookies & analytics below.
3. Why we collect it
We have a lawful basis for each piece of data we collect:
- Contract — we need your email and phone to deliver the product you paid for and to send the invoice.
- Legal obligation — tax authorities require us to keep transaction records for several years.
- Legitimate interest — we measure which marketing channels work so we can spend our advertising budget wisely.
- Consent — we only send marketing emails (e.g. new product launches) if you bought from us or explicitly opted in. Every email has a one-click unsubscribe.
4. Who we share it with
We share the minimum data needed with a small, vetted set of vendors. We do not sell, rent, or trade your information. Our vendors are:
- Razorpay — processes payments. They receive your email, phone, name, and the amount. Razorpay’s privacy policy.
- Resend (or another email delivery vendor) — delivers transactional emails (download links, receipts). They receive your email + the email content.
- Digital Ocean — hosts our database and website. Our database is encrypted at rest.
- Meta (Facebook) & Google — if you arrived from an ad, we may send a hashed copy of your email back to them so they can measure conversions (Conversions API). Hashed means they can’t read the email, only match if you already have an account.
We will share data with law enforcement only when legally compelled (e.g. a court order or RBI investigation).
5. How long we keep it
- Order & invoice records — 7 years (Indian tax law minimum).
- Customer email/phone — until you ask us to delete it.
- Marketing attribution data — 24 months, then anonymised.
- Analytics logs — 12 months at most.
6. Your rights
Under India’s Digital Personal Data Protection Act (DPDP Act, 2023) you have the right to:
- Access — ask us what data we hold about you. We’ll respond within 30 days.
- Correction — ask us to fix any wrong information.
- Erasure — ask us to delete your data (subject to legal record-keeping obligations).
- Withdraw consent — unsubscribe from marketing emails any time, with one click.
- Grievance — if you’re unhappy with how we handled a request, you can complain to the Data Protection Board of India.
To exercise any of these rights, email hello@learnandexcel.in with the word “data request” in the subject line.
7. Cookies & analytics
We use the minimum set of cookies we can get away with:
- Essential cookies — remember your checkout email and phone so you don’t retype them. Stored only in your browser’s localStorage; never sent to our servers.
- Analytics cookies — we may use privacy-respecting analytics tools like Plausible or self-hosted Umami to count anonymous page views. No third-party tracking cookies.
- Marketing pixels — if you visited from a Meta or Google ad, a pixel from those platforms may load to measure conversions. You can block these via your browser’s tracking-protection settings.
8. Security
Our website runs over HTTPS only (TLS 1.3). Our database is encrypted at rest. Passwords are never stored in plaintext. Payment data never touches our servers — Razorpay handles all card/UPI/net-banking input directly. We patch our infrastructure regularly and use server-side rate-limiting to prevent abuse.
If we ever discover a data breach affecting your information, we’ll notify you and the Data Protection Board within 72 hours, as required by the DPDP Act.
9. Changes to this policy
We’ll update this policy when we add new vendors or our practices change. The Last updated date at the top will reflect the most recent change. If the change is material (e.g. a new use of your data), we’ll email you.
10. Contact us
Privacy questions, data requests, or complaints — email hello@learnandexcel.in. We respond to every email; we don’t use bots.