1. Introduction
Welcome to WinQuest Online ("WinQuest Online," "we," "us," or "our"). We are committed to protecting your privacy and handling your personal data in a transparent and secure manner. This Privacy Policy explains how WinQuest Online collects, uses, processes, discloses, and protects your personal data when you use our website (winquestonline.com), mobile applications, learning platforms, and all related services, content, tools, and features (collectively, the "Services").
By using our Services, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree with the terms of this policy, please do not use our Services.
We comply with applicable data-protection regulations including the EU General Data Protection Regulation (GDPR), the UK GDPR, the US Children's Online Privacy Protection Act (COPPA), the California Consumer Privacy Act (CCPA) / California Privacy Rights Act (CPRA), Canada's PIPEDA, Singapore's PDPA, and India's Digital Personal Data Protection Act 2023 (DPDP Act).
2. Definitions
- Account
- A unique account created for you to access our Service or parts of our Service.
- Company / We / Us / Our
- WinQuest Online, operated by Winquest Advisory Services LLP, Kolkata, West Bengal, India.
- Cookies
- Small files placed on your device containing details of your browsing history and preferences.
- Device
- Any device that can access the Service such as a computer, mobile phone, or digital tablet.
- Personal Data
- Any information that relates to an identified or identifiable natural person.
- Service
- Refers to the online educational platform provided by WinQuest Online.
- Service Provider
- Any natural or legal person who processes data on behalf of WinQuest Online.
- Usage Data
- Data collected automatically from use of the Service (e.g., page visit duration, browser type).
- Website
- WinQuest Online, accessible at winquestonline.com.
- You / User
- The individual accessing the Service, or the company on whose behalf such individual is acting.
- Child (COPPA purposes)
- An individual under the age of 13 years.
- Parent / Guardian
- The parent or legal guardian of a Child.
3. Information We Collect
3.1 Personal Data You Provide Directly to Us
- Identity Data: Name, date of birth, gender, educational background.
- Contact Data: Email address, postal address, telephone and WhatsApp numbers.
- Account Data: Username, password, preferences, and feedback.
- Payment Data: Billing address and payment details — processed securely by third parties; we do not store full card numbers.
- Educational Data: Current grade/class, subjects, learning goals, curriculum type (CBSE, IGCSE, IB, US Common Core, etc.), assessment results.
- Communications: Content of emails, support queries, surveys, and feedback you send us.
3.2 Data We Collect Automatically
- Usage Data: IP address, browser type, pages visited, time spent, referring URLs.
- Device Data: Device type, operating system, unique identifiers.
- Cookie Data: Session cookies, preference cookies, analytics cookies.
- Session Recordings: With your consent, we may record live tutoring sessions for quality and review purposes.
3.3 Data We Receive from Third Parties
- Authentication data from Google Sign-In or other OAuth providers.
- Payment confirmation data from Razorpay or Stripe.
- Behavioural and analytics data from Google Analytics and Meta Pixel.
4. How We Collect Your Information
- Direct interaction — when you register an account, book a session, fill in forms, or contact us.
- Automated technologies — cookies, web beacons, and similar tracking technologies as you navigate our Website.
- Third-party sources — analytics providers, payment processors, and social media platforms you connect to our Service.
- Parental / guardian submission — when a parent or guardian registers on behalf of a child.
5. How We Use Your Information
We use your personal data for the following purposes:
- To create and manage your account and deliver the Services you request.
- To match students with suitable tutors and schedule sessions.
- To process payments and send transaction receipts.
- To personalise the learning experience and track educational progress.
- To send service notifications, booking confirmations, and reminders.
- To respond to your enquiries and provide customer support.
- To send marketing communications (only with your explicit consent; you can opt out at any time).
- To conduct analytics, improve our Services, and develop new features.
- To comply with legal obligations and enforce our Terms of Service.
- To ensure platform safety and prevent fraud or abuse.
6. Legal Basis for Processing (GDPR / UK GDPR)
For users in the European Economic Area or the United Kingdom, we process your personal data on the following legal bases:
- Contract performance — to deliver the tutoring services you have enrolled in.
- Legitimate interests — analytics, fraud prevention, and platform improvement, where not overridden by your rights.
- Consent — for marketing communications, optional cookies, and session recording.
- Legal obligation — to comply with applicable laws and regulations.
- Vital interests — in rare circumstances involving the safety of a child.
For children under 16 in the EU/UK, we require verifiable parental or guardian consent before processing their personal data.
7. Sharing Your Personal Data
We do not sell your personal data. We may share data with:
- Tutors and Instructors — to deliver scheduled sessions (limited to name, subject, and session details).
- Payment processors — Razorpay (India), Stripe (international) — bound by their own privacy policies.
- Communication tools — Zoom, Google Meet, WhatsApp Business — for session delivery and support.
- Analytics providers — Google Analytics, Meta Pixel — in anonymised or aggregated form where possible.
- Legal authorities — where required by law, court order, or to protect our legal rights.
- Business successors — in the event of a merger, acquisition, or sale of assets, with notice to you.
All third-party service providers are bound by data-processing agreements and are permitted to use your data only for the specific purpose we engage them for.
8. International Data Transfers
WinQuest Online is based in India and operates internationally. Your data may be transferred to, and processed in, countries other than your country of residence. These countries may have data-protection laws that differ from your own.
When transferring personal data from the EEA or UK to a third country, we rely on appropriate safeguards such as Standard Contractual Clauses (SCCs) approved by the European Commission, or equivalent mechanisms recognised by UK law. By using our Services, you consent to such transfers.
9. Data Security
We implement industry-standard technical and organisational security measures to protect your personal data, including:
- TLS/SSL encryption for all data in transit.
- Encrypted storage of passwords and sensitive credentials.
- Access controls limiting data access to authorised personnel only.
- Regular security assessments and penetration testing.
- Incident response procedures and breach notification protocols.
No method of transmission over the internet is 100% secure. While we strive to protect your data, we cannot guarantee its absolute security. In the event of a data breach that is likely to affect your rights, we will notify you and the relevant supervisory authority within the legally required timeframe.
10. Data Retention
We retain your personal data only for as long as is necessary for the purposes set out in this policy, or as required by applicable law. Typical retention periods include:
- Account data: For the duration of your active account plus 3 years after closure.
- Session recordings: Up to 90 days unless you request earlier deletion.
- Payment records: 7 years (for financial and tax compliance).
- Marketing consent records: Until you withdraw consent, then archived for 3 years.
You may request deletion of your data at any time — see Your Rights below.
11. Your Data Protection Rights
Depending on your location, you may have the following rights regarding your personal data:
- Right of Access — request a copy of the personal data we hold about you.
- Right to Rectification — ask us to correct inaccurate or incomplete data.
- Right to Erasure ("Right to be Forgotten") — request deletion of your data, subject to legal retention requirements.
- Right to Restriction — ask us to pause processing of your data.
- Right to Data Portability — receive your data in a machine-readable format.
- Right to Object — object to processing based on legitimate interests or for direct marketing.
- Rights related to Automated Decision-Making — not to be subject to solely automated decisions that significantly affect you.
- Right to Withdraw Consent — at any time where processing is based on consent.
To exercise any of these rights, contact us at privacy@winquestonline.com. We will respond within 30 days. You also have the right to lodge a complaint with your local supervisory authority (e.g., ICO in the UK, Data Protection Commissioner in your EU member state, or the Data Protection Board of India).
12. CalOPPA Compliance (California Online Privacy Protection Act)
In accordance with CalOPPA, we agree to the following:
- Users may visit our Website anonymously.
- Our Privacy Policy link is clearly visible on our homepage.
- Our Privacy Policy link includes the word "Privacy" and is easily findable from every page.
- You will be notified of any Privacy Policy changes on this page.
- You can change your personal information by logging into your account or emailing us.
Do Not Track: We honour Do Not Track signals. When a Do Not Track browser mechanism is in place, we do not track, plant cookies, or use advertising.
13. CCPA / CPRA — California Residents
Under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA), California residents have specific rights regarding their personal information:
- Right to Know — what personal information we collect, use, disclose, or sell.
- Right to Delete — request deletion of personal information we collected.
- Right to Correct — request correction of inaccurate personal information.
- Right to Opt-Out — opt out of the sale or sharing of personal information. We do not sell personal information.
- Right to Limit Use — limit the use and disclosure of Sensitive Personal Information.
- Right to Non-Discrimination — we will not discriminate against you for exercising your privacy rights.
To submit a verifiable consumer request, contact privacy@winquestonline.com. We will respond within 45 days. Authorised agents may submit requests on behalf of California consumers with written proof of authorisation.
14. Service Providers
We employ third-party companies and individuals ("Service Providers") to facilitate our Services. These third parties have access to your personal data only to perform specific tasks on our behalf and are obligated not to disclose or use it for any other purpose. Key Service Providers include:
- Zoom / Google Meet — live video session delivery.
- Razorpay — payment processing (India).
- Stripe — payment processing (international).
- WhatsApp Business — customer communications.
- Google Workspace — email, calendar, and document management.
- Hostinger — web hosting and server infrastructure.
15. Analytics
We use Google Analytics to monitor and analyse traffic to our Website. Google Analytics collects data such as the frequency with which users visit our Website, pages visited, and other websites users visited before coming to our Website. We use this data only to improve our Website and Services.
Google Analytics' ability to use and share information about your visits is restricted by the Google Analytics Terms of Service and Google Privacy Policy. You can opt out of Google Analytics by installing the Google Analytics opt-out browser add-on.
16. Behavioural Remarketing
WinQuest Online uses remarketing services to advertise our Services after you have visited our Website. We and our third-party vendors use cookies to inform, optimise, and serve ads based on your past visits.
- Google Ads Remarketing — governed by Google's Privacy Policy. You can opt out via Google Ad Settings.
- Meta (Facebook) Pixel — governed by Meta's Data Policy. You can manage preferences in your Facebook/Instagram settings.
You can opt out of interest-based advertising from participating companies via www.aboutads.info/choices or www.youronlinechoices.eu (EU).
17. Payments
We provide paid products and services. Payment information is processed by our third-party payment processors — Razorpay (India) and Stripe (international). We do not store your payment card details on our servers.
These payment processors adhere to the standards set by PCI-DSS (Payment Card Industry Data Security Standard). Their Privacy Policies govern their use of your financial information.
18. Links to Other Sites
Our Service may contain links to other websites not operated by WinQuest Online. If you click on a third-party link, you will be directed to that site. We strongly advise you to review the Privacy Policy of every site you visit. We have no control over and assume no responsibility for the content, privacy policies, or practices of any third-party sites or services.
19. Children's Privacy
We take the privacy of children very seriously. WinQuest Online is primarily an educational platform that serves learners of all ages, including children. We adhere to the following safeguards:
- COPPA (USA): We do not knowingly collect personal information from children under 13 without verifiable parental consent. Parents/guardians must create the account and provide consent before a child under 13 can access the Services.
- GDPR / UK GDPR (EU/UK): Children under 16 require parental consent for data processing.
- DPDP Act (India): Children under 18 require parental consent.
If you are a parent or guardian and believe your child has provided us with personal information without consent, please contact us at privacy@winquestonline.com and we will take prompt action to delete that information.
We do not subject children to behavioural advertising and maintain strict data minimisation for child user accounts.
20. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will:
- Update the "Last updated" date at the top of this page.
- Send an email notification to registered users for material changes.
- Where required by law, obtain fresh consent before changes take effect.
We encourage you to review this Policy periodically. Your continued use of the Service after changes are posted constitutes your acceptance of the updated Policy.
21. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact our Privacy team:
Kolkata, West Bengal, India