Privacy Policy
How Parivartan Sutra collects, uses, and protects the information of parents and children who use this platform.
⚠️ मसौदा सूचना: यह दस्तावेज़ एक मसौदा (draft) है और अनुपालन (compliance) के उद्देश्य से भरोसा करने से पहले इसे किसी कानूनी विशेषज्ञ (legal professional) से समीक्षा करवाना ज़रूरी है।
Last updated: August 4, 2026
1. Who we are
Parivartan Sutra ("we", "us", "our") operates an online assessment-and-strategy platform for students, built around a combined parent-and-child questionnaire (the "Parivartan Score" audit) that produces a personalised persona, score report, and improvement strategy. This policy explains what personal data we collect from Parents, Children (Students), and Admins who use the platform, and how that data is used, stored, shared, and protected.
2. What data we collect
We collect only the data needed to create accounts, run the assessment, compute a score, match a strategy, and process payments. Specifically:
| Category | What we collect |
|---|---|
| Parent account details | Name, email address, mobile number, city/state/country, and a securely hashed password. Mobile number is mandatory for a parent account and is also used for login and OTP-based password reset. |
| Child (student) details | Name, class/grade, date of birth, and — only when a login is created for the child — either a mobile number or a username (never both), plus a securely hashed password. |
| Assessment (audit) data | The parent's and child's answers to the Parivartan Score questionnaire, the option each of you selected, and the resulting pillar scores (Hunger/Desire, Blueprint/Plan, Competence/Strategy, Resistance), combined score (0–50), and Persona. |
| Strategy & progress data | Which strategy was matched or purchased for a child, and follow-up progress recorded against that strategy over time. |
| Payment data | Order and payment records — item purchased, amount, currency, status, and a payment-gateway reference id. We do not collect or store card, UPI, or net-banking credentials ourselves — all payment collection happens on Razorpay's own secure, PCI-DSS-compliant checkout; we only receive a confirmation and reference id back from Razorpay once a payment succeeds or fails. |
| Technical / session data | Login session state (to keep you signed in), and standard request metadata (IP address, timestamp) used only for security purposes such as rate-limiting repeated failed login attempts. |
3. Why we collect it
- To deliver the core service — running the parent-side and child-side halves of the assessment, computing the combined Parivartan Score and Persona, and matching an appropriate improvement strategy.
- To manage accounts — parent registration and login, creating and managing child logins (which only a parent can do — a child cannot self-register), and password resets.
- To process payments — creating orders for the ₹499 detailed report or a strategy, and confirming payment status via our payment gateway partner.
- To communicate with you — sending a one-time password (OTP) by SMS for the parent password-reset flow.
- To keep the platform secure — detecting and slowing down repeated failed login attempts, and protecting session data.
We do not use assessment answers, scores, or personal details for advertising, and we do not sell personal data to any third party.
4. Children's data & parental consent
A core design principle of this platform is that a child cannot create their own account. Every child profile is created by a parent from the parent's own logged-in account, and a child's login credentials (if any) are also created by the parent. This means all data we hold about a child — their name, class, date of birth, assessment answers, scores, and strategy — is collected with the parent's knowledge and direct action, since the parent is the one entering it on the child's behalf or authorising the child's own half of the assessment.
Under India's Digital Personal Data Protection Act, 2023 (DPDP Act), a child is defined as an individual under 18 years of age, and the Act requires verifiable parental/guardian consent before processing a child's personal data, along with a general prohibition on processing that could cause harm to a child and on behavioural tracking or targeted advertising directed at children. Our platform's "parent adds and manages the child" model is intended to align with this consent requirement — the parent's own account action (adding a child, creating a child login) is the mechanism by which that consent is given. We do not run behavioural tracking or targeted advertising of any kind, for children or adults.
If a parent wishes to withdraw consent for a child's data to be processed — for example, to have a child's assessment data deleted — they can do so by contacting us (see "Your rights" below).
5. Data sharing with third parties
We do not sell personal data. We share the minimum data necessary with the following categories of service providers, solely so they can perform the specific function we use them for:
- Razorpay (payment processing) — when you purchase the detailed report or a strategy, the payment itself (card/UPI/net-banking details) is collected and processed directly by Razorpay, not by us. We only send Razorpay the order amount and receive back an order/payment status and reference id.
- MSG91 (SMS delivery) — used to deliver the one-time password (OTP) for the parent forgot-password flow. Only the parent's mobile number and the OTP value are sent to MSG91 for the purpose of delivering that single SMS; MSG91 does not receive any other account or assessment data.
We do not share data with advertising networks, data brokers, or any other party for marketing purposes. We may disclose data if required to do so by law or a valid legal request from a competent authority.
6. Data retention
We retain account, assessment, and strategy/progress data for as long as the parent's account remains active, since progress tracking (the "Followup" feature) is designed to show a child's improvement over time and depends on historical data being available. Payment records are retained for as long as needed to meet our accounting and tax obligations. If a parent requests deletion of their account or a child's data (see below), we will delete or anonymise the data within a reasonable timeframe, except where we are required to retain certain records (e.g. payment records) for legal or regulatory reasons.
7. Security measures
We apply the following safeguards to protect the data described above:
- Passwords are never stored in plain text — they are one-way hashed before being saved.
- An application-level encryption key is used for other sensitive stored values.
- Login, OTP-request, and OTP-verification endpoints are rate-limited to slow down automated guessing attempts.
- One-time passwords (OTPs) are randomly generated using a cryptographically secure method, expire after a short window, and are limited to a small number of verification attempts.
- Cross-Site Request Forgery (CSRF) protection is enforced across the platform's forms and AJAX requests.
- Payment card/UPI/net-banking data is never handled or stored by our own servers — it is collected directly by Razorpay's PCI-DSS-compliant checkout.
No method of storage or transmission is 100% secure, but we work to apply reasonable, industry-standard safeguards appropriate to the sensitivity of the data we hold.
8. Cookies & session data
We use a functional session cookie to keep you logged in while you use the parent, student, or admin portal, and a CSRF token (stored in your session) to protect forms and AJAX requests from cross-site request forgery. We do not currently use any third-party analytics, advertising, or tracking cookies on this platform.
9. Your rights
You (or, for a child's data, the parent acting on the child's behalf) may contact us to:
- Request a copy of the personal data we hold about you or your child.
- Ask us to correct inaccurate or outdated data.
- Ask us to delete your account or your child's data (subject to the retention exceptions noted above).
- Withdraw consent for a child's data to be processed going forward.
- Raise a grievance about how your data has been handled.
To exercise any of these rights, please email us at parivartansutra@gmail.com from the email address associated with your account, describing your request. We will respond within a reasonable timeframe.
10. Changes to this policy
We may update this Privacy Policy from time to time as the platform evolves. The "Last updated" date at the top of this page will reflect the most recent revision. Continued use of the platform after a change constitutes acceptance of the updated policy.
11. Contact us
If you have any questions about this Privacy Policy or how your data is handled, reach us at:
- Email: parivartansutra@gmail.com
- Phone / WhatsApp: +91 92854 05665