Legal

Privacy Policy

Last Updated: 15 September 2026

CPLGrid ("we", "us", "our") operates an online exam-preparation platform for DGCA Commercial Pilot Licence (CPL) candidates at cplgrid.in. This Privacy Policy explains what information we collect when you create an account, practise, take mock tests, subscribe or contact us — and how that information is used, protected and retained. We keep this policy deliberately specific to what CPLGrid actually does; we do not sell your data and we do not run advertising trackers.

1. Information We Collect

We collect only the information needed to run your study account and process your subscription:

Account & authenticationYour email address and a securely hashed password. If you sign in with email verification or a password-reset link, we process the verification or recovery token associated with that request.
Profile detailsYour full name, phone number and country, which you provide during onboarding. This appears inside your account and is used to personalise the workspace and reach you about your account.
Practice & exam activityThe subjects and chapters you choose, the questions served to you, your selected answers, session scores, time spent, and the questions you bookmark or flag for review. This is what powers your analytics, mistake review and revision tools.
Subscription & payment recordsWhen you purchase a plan or claim a free trial, we record the package, amount, currency, payment status, order identifiers and the start and end dates of your access.
Support & issue reportsIf you report a snag or contact us for help, we keep the details of your request so we can resolve it.
Technical dataStandard request information such as IP address, browser type and device characteristics, processed by our hosting and authentication infrastructure to deliver and secure the service.

2. How We Use Your Information

  • To create and maintain your account and authenticate you securely.
  • To deliver practice sessions, mock tests, bookmarks, flags, mistake review and analytics.
  • To process subscriptions and free trials, and to determine what content your access level allows.
  • To send essential service emails — email address verification, password resets, and payment or access confirmations.
  • To detect abuse, prevent duplicate or unauthorised access, and keep the platform secure.
  • To fix problems you report and improve the question bank and study experience.

We do not use your information to build advertising profiles, and we do not sell or rent personal data to anyone.

3. Authentication & Account Data

Accounts are managed by our authentication provider. Your password is stored only as a cryptographic hash — never in readable form, and never by us in plain text. If you use the "Remember me" option on the login page, only your email address is stored in your own browser's local storage so the field can be prefilled on your next visit; your password is never stored by CPLGrid. Your login session is kept in your browser so you stay signed in, and signing out removes it.

If you request a password reset, we send a time-limited, single-use link to your registered email address. For security reasons, our responses do not reveal whether an email address is registered.

4. Practice & Exam Activity

To make the platform work, we necessarily record what you study: the questions you were shown, the answers you picked, whether sessions were completed, your scores, and the questions you saved or flagged. During a practice or mock attempt we do not share this anywhere — it is stored against your account and shown only to you. Aggregate, de-identified patterns (for example, which questions are commonly missed across all students) may be used to improve question quality, but individual answer histories are not disclosed to other users.

5. Payment & Subscription Information

Subscriptions are processed through our payment gateway, Razorpay. When you pay, your card, UPI or net-banking details are collected and processed by Razorpay on its own secure infrastructure — CPLGrid never sees or stores your full card or payment credentials. We receive and retain only the records needed to grant and verify your access: your plan, amount, currency, payment identifier, status and validity period. If a payment fails or is disputed, we may retain related correspondence and status records to resolve it.

6. Cookies & Local Storage

CPLGrid does not use advertising cookies and does not run third-party analytics trackers. We use only essential browser storage, which is required for the site to function:

  • Session storage — keeps you signed in between pages and visits.
  • Theme preference — remembers whether you chose dark or light mode.
  • Remembered email — stores your email address on the login page only if you tick "Remember me".

You can clear or block this storage in your browser settings; doing so may sign you out or reset preferences, but the platform will otherwise keep working.

7. Data Sharing

We do not sell your personal data. We share it only with:

  • Infrastructure providers — our hosting, authentication and database platform (Supabase) and payment gateway (Razorpay), which process data on our behalf to run the service.
  • Authorities — where we are legally required to disclose information, or to protect the rights, property or safety of CPLGrid, our users or the public.

These providers process data under their own security and privacy obligations; we do not permit them to use your data for their own marketing.

8. Data Retention

We keep your account, profile and practice history for as long as your account is active so your analytics and revision tools keep working. Subscription and payment records are kept for the period required for accounting and tax purposes under Indian law. If you ask us to delete your account, we delete or de-identify your profile and personal data; we may retain minimal records where retention is legally required or necessary for fraud prevention.

9. Security

Access to the platform is encrypted in transit (HTTPS), passwords are stored only as hashes, and database access is restricted by row-level security rules so your records are readable only by you (and, where strictly necessary, by authorised administrators for support). Payment secrets are held only in the server environment and are never exposed to the browser. No system is perfectly secure, and we cannot guarantee absolute security, but we review and limit access to personal data as a matter of practice.

10. Your Rights & Requests

Subject to applicable Indian law, you may ask us to:

  • Confirm what personal data we hold about you and receive a copy of it.
  • Correct inaccurate profile details (you can also edit some details yourself in Settings).
  • Delete your account and associated personal data.
  • Withdraw consent to optional features such as the remembered email.

To make a request, write to us at the address in the Contact section. We may ask you to verify your identity before acting on a request, and we will respond within a reasonable timeframe.

11. Children's Privacy

CPLGrid is intended for CPL candidates preparing for DGCA examinations, which are generally undertaken from the age of 16 and above. The service is not directed at children under 13, and we do not knowingly collect personal data from them. If you believe a child under 13 has created an account, contact us and we will remove it.

12. Changes to This Policy

We may update this policy as the platform evolves — for example, if we add new study features, payment options or support channels. Material changes will be highlighted on the site or communicated to active account holders. The "Last Updated" date at the top of this page always reflects the current version, and continuing to use CPLGrid after an update means you accept the revised policy.

13. Contact Us

Questions, access requests or privacy concerns can be sent to support@cplgrid.in. We aim to respond to privacy requests within 30 days.