PRIVACY & DATA USE
Student information deserves
careful handling.
Effective 19 August 2026 · Review before production launch whenever services change.
What this notice covers
This notice explains the information used by the Mathav public website, student portal, test series, authentication system, and payment workflow. Mathav does not sell student information or use advertising trackers in the supplied website.
Information used
- Account information: name and email address supplied during registration. Passwords are handled by the authentication provider and are not visible to Mathav.
- Learning information: test attempts, answers, scores, accuracy, timestamps, and progress signals required to provide the test series.
- Payment records: plan, amount, order ID, payment ID, status, and time. Card, UPI PIN, CVV, OTP, and banking credentials are entered only in Razorpay’s checkout and are not stored by Mathav.
- Security information: limited account, action, and timestamp records used to detect automated extraction, excessive requests, and suspicious access.
- Public enquiry form: the current preview form does not transmit or store the entered name or phone number. Update this notice before connecting a form backend.
Why information is used
Information is used to create and protect accounts, provide purchased or preview content, score attempts, display progress, verify payments, prevent fraud and abuse, provide support, and meet legitimate accounting or legal record requirements.
Service providers
Production deployment may use Supabase for authentication and database services, Razorpay for payment processing, an HTTPS hosting provider, an email provider for account messages, and Cloudflare Turnstile for bot protection. Each provider processes only the information needed for its service and is governed by its own terms and privacy practices.
Retention and deletion
Keep account and learning data only while it is needed to provide the service or resolve a legitimate operational issue. Payment and accounting records may need a longer retention period. Students should be given a working channel to request access, correction, export, or deletion before the portal launches publicly. Some records may be retained where required for fraud prevention, disputes, accounting, or law.
Security
The supplied system uses HTTPS deployment headers, verified accounts, least-privilege database access, row-level security, server-side payment confirmation, protected answer keys, per-question content delivery, rate limiting, security event records, and account watermarks. No internet service can promise absolute security, so access and provider logs must be monitored and dependencies, keys, and policies kept current.
Student responsibilities
Students should use a unique password, protect verification links and OTPs, sign out on shared devices, avoid sharing accounts, and report unexpected account or payment activity. Paid questions and solutions are licensed for the enrolled student’s personal preparation and must not be redistributed.
Children and contact
If a student is below the applicable age for independent consent, obtain consent from a parent or guardian before collecting personal information or accepting payment. Privacy, correction, export, deletion, and security requests can be made through the Contact & Grievance page. A monitored email and telephone number must be added there before live payments begin.