Privacy Policy
Effective Date: 15 March 2026
This Privacy Policy explains how Expert Root ("we", "our", "us") collects, uses, discloses, and safeguards your information when you use our platform at https://www.expertroot.in. Please read it carefully before using our services.
1. Who We Are
Expert Root is an online examination and learning platform incorporated in India. Our registered office is located at:
Land Mark Towers, Bypass Junction, Thadathilkulam, Kanjiramkulam, Kerala 695524, India
If you have any questions about this Policy, please contact us at expertrootofficial@gmail.com.
2. Information We Collect
We collect information in the following categories:
- Account Data: name, email address, and password hash when you register.
- Profile Data: phone number, institution, and other optional information you provide in your profile.
- Transaction Data: payment details processed securely through our payment gateway (Stripe/Razorpay). We do not store card numbers.
- Usage Data: exam attempts, scores, time-on-screen, answers selected, and navigation patterns — used to provide analytics to you.
- Technical Data: IP address, browser type, device identifiers, and cookies for session management and security.
- Communications: messages sent through the contact form, including name, email, phone, and message content.
We do not knowingly collect data from individuals under 13 years of age. If you believe a minor has provided us with personal data, contact us immediately.
3. How We Use Your Information
We use the data collected for the following purposes:
- To create and manage your account and provide access to purchased exams.
- To process payments and issue receipts.
- To display performance analytics and progress reports in your dashboard.
- To send transactional emails (e.g., receipts, account alerts). Marketing emails are sent only with your consent.
- To respond to support queries submitted via the contact form.
- To detect and prevent fraud, cheating, and unauthorised access.
- To improve platform quality through aggregate, anonymised analytics.
- To comply with applicable law and legal process.
4. Legal Basis for Processing (GDPR / IT Act)
Where applicable, we process your data under one or more of the following legal bases:
- Contract performance: necessary to provide the services you have purchased.
- Legitimate interests: security monitoring, fraud prevention, and platform improvement.
- Consent: for marketing communications, which you may withdraw at any time.
- Legal obligation: compliance with Indian law including the Information Technology Act, 2000 and the IT (Amendment) Act, 2008.
5. Data Sharing and Disclosure
We do not sell your personal data. We may share data with:
- Payment processors (e.g., Stripe, Razorpay) solely to handle transactions — governed by their own privacy policies.
- Cloud infrastructure providers (e.g., Supabase, Vercel) operating under data processing agreements.
- Law enforcement or courts when required by applicable law, court order, or to protect our legal rights.
- Business successors in the event of a merger, acquisition, or sale of assets, subject to the same privacy obligations.
6. Data Retention
We retain your personal data for as long as your account is active or as required to provide our services. You may request deletion of your account and associated data by emailing us at expertrootofficial@gmail.com. Certain data may be retained longer if required by law (e.g., financial records for 7 years under Indian accounting law).
7. Cookies and Tracking
We use strictly necessary cookies for authentication (session tokens) and security (CSRF protection). We do not use advertising or third-party tracking cookies. You may disable cookies in your browser settings, but this will prevent you from logging in.
8. Data Security
We implement industry-standard safeguards including TLS/HTTPS encryption for data in transit, bcrypt hashing for passwords, row-level security on our database, and access controls that restrict data access to authorised personnel only. No method of transmission over the internet is 100% secure; we cannot guarantee absolute security but we continuously audit and improve our practices.
9. Your Rights
Subject to applicable law, you have the right to:
- Access — request a copy of the personal data we hold about you.
- Rectification — update or correct inaccurate data via your profile settings.
- Erasure — request deletion of your account and personal data.
- Portability — receive your data in a machine-readable format.
- Objection — object to processing of your data for direct marketing at any time.
To exercise any of these rights, email us at expertrootofficial@gmail.com. We will respond within 30 days.
10. Third-Party Links
Our platform may contain links to third-party websites. We are not responsible for the privacy practices of those sites and encourage you to read their privacy policies independently.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be notified via email or a prominent notice on our website at least 14 days before taking effect. Continued use of the platform after the effective date constitutes acceptance of the revised Policy.
12. Contact Us
If you have any questions, concerns, or complaints regarding this Privacy Policy, please contact:
Expert Root
Land Mark Towers, Bypass Junction, Thadathilkulam, Kanjiramkulam, Kerala 695524, India
Email: expertrootofficial@gmail.com