Privacy policy
How ARCH GATE collects, uses, stores and protects your personal data, and the rights you have over it under the Digital Personal Data Protection Act, 2023 and the Information Technology Act, 2000.
In effect from 24 August 2026. This page supersedes any earlier version.
1. Who is responsible for your data
ARCH GATE, operating the website archgate.online, is the Data Fiduciary for the personal data described here — that is, we decide why and how it is processed. Our address of record is [registered address — to be published before live payments]. You, as the person the data is about, are the Data Principal.
This policy is published under Section 5 of the Digital Personal Data Protection Act, 2023 (“DPDP Act”), and under Rule 4 of the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (“SPDI Rules”) framed under Section 43A of the Information Technology Act, 2000.
2. What we collect, and why
| Data | Why we need it | Basis |
|---|---|---|
| Name and email address | To create and identify your account, sign you in, and write to you about your account or a payment. | Your consent, given at sign-up |
| Password | To authenticate you. It is stored only as a bcrypt hash and is never stored, logged or transmitted in a form we or anyone else could read. | Your consent |
| Test attempts — your responses, timings, marks, bookmarks and target score | To mark your paper, produce your analysis, and let you return to past attempts. This is the service you came for. | Performance of the service you asked for |
| Payment records — the amount, the tier bought, and the payment gateway’s own order and payment identifiers | To credit your purchase, to trace any credit back to a real charge, and to meet our tax and accounting obligations. | Contract, and legal obligation |
| Technical logs — IP address, browser type, timestamps of requests | To keep the service running, and to detect and investigate abuse. | Legitimate use under Section 7 of the DPDP Act |
We do not collect, and have no way to see, your card number, UPI PIN, bank credentials or any other payment instrument details. Those are entered on the payment gateway’s own secure screen and never reach our servers.
We do not buy personal data from anyone, we do not run advertising, and we do not build profiles of you for any purpose other than showing you your own results.
3. Cookies
One cookie is set: a session cookie that keeps you signed in. It is httpOnly, so no script on the page can read it; it is marked SameSite=Lax, so it is not sent from other sites; and in production it is sent only over HTTPS. It expires after 30 days, or immediately when you sign out.
There are no advertising cookies, no third-party analytics trackers and no social media pixels on this site. The payment gateway sets its own cookies while its checkout window is open; those are governed by its policy, not ours.
4. Who else sees your data
We share personal data only with the following, and only so far as each needs it:
- Our payment gateway (Razorpay Software Private Limited), which processes payments and receives your name, email address and the amount payable in order to do so. It is regulated by the Reserve Bank of India and is PCI-DSS compliant.
- Our hosting and backup providers, on whose infrastructure the database runs and is backed up. They act on our instructions as Data Processors and do not use your data for their own purposes.
- A court, regulator or law-enforcement authority, where we are required by Indian law to disclose. We disclose only what is demanded, and no more.
We do not sell, rent or trade personal data. Ever. Our data is held on servers located in India; encrypted backups may be stored with a provider outside India in a country not restricted by the Central Government under Section 16 of the DPDP Act.
5. How long we keep it
- Account and attempt data — for as long as your account exists. The point of the analysis is that it reads across every attempt, so deleting an attempt would silently change the charts you rely on.
- After you ask us to delete your account — personal data is erased within 30 days, and the account, its attempts, answers and bookmarks go with it.
- Payment records — retained for eight years after the financial year of the transaction, because tax and companies law requires it. These are kept even after account deletion, and are reduced to the transaction identifiers and amount.
- Technical logs — 90 days.
6. How we protect it
- All traffic is served over HTTPS with certificates renewed automatically.
- Passwords are stored as bcrypt hashes with a per-password salt, never in plain text.
- Session identifiers are 256 bits of cryptographic randomness, stored server-side and revocable.
- Payments are verified by cryptographic signature against the gateway’s secret before any purchase is credited, so a callback cannot be forged or replayed.
- The database runs as an unprivileged service user with continuous encrypted off-site backup, and access to the server is by SSH key only.
- Security updates are applied automatically.
These are our reasonable security practices for the purposes of Section 43A of the Information Technology Act, 2000 and Rule 8 of the SPDI Rules. No system is perfect; if we become aware of a personal data breach we will notify the Data Protection Board of India and every affected person, as Section 8(6) of the DPDP Act requires.
7. Your rights
Under Sections 11 to 14 of the DPDP Act you have the right to:
- Access — a summary of the personal data we hold about you and what we have done with it.
- Correction, completion and updating — of anything inaccurate or out of date.
- Erasure — of your personal data, subject only to what we must keep by law.
- Withdraw consent — as easily as you gave it. Withdrawing consent closes your account, because the service cannot be provided without it.
- Nominate — another person to exercise these rights on your behalf in the event of your death or incapacity.
- Grievance redressal — the route in Section 8 below, which you must use before approaching the Data Protection Board of India.
To exercise any of these, write to admin@archgate.online from the email address on your account. There is no charge.
The DPDP Act also places duties on you: not to impersonate anyone else when registering, not to suppress material information, and not to file a false or frivolous grievance.
8. Grievance officer
The Grievance Officer, ARCH GATE
Email: admin@archgate.online
Postal address: [registered address — to be published before live payments]
We acknowledge every complaint within 48 hours and resolve it within 15 days, as Rule 5(9) of the SPDI Rules requires.
If you are not satisfied with how we have handled your complaint, you may take it to the Data Protection Board of India under Section 13(3) of the DPDP Act.
9. Children
This service is intended for candidates preparing for a postgraduate entrance examination and is offered to persons aged 18 and over. We do not knowingly collect personal data from anyone under 18. If you believe a child has registered, write to admin@archgate.online and the account will be removed.
10. Changes to this policy
If this policy changes materially we will say so on this page and, where the change affects how your data is used, by email. Continuing to use the site after a change means you accept the revised policy.
See also: Terms of use · Refunds and cancellation · Contact and grievances