Legal
Privacy Policy
This Privacy Policy explains how iTestSeries collects, uses, shares, stores, and protects your personal data. It applies to students, educators, and all users.
Last updated: July 21, 2026. We may update this; continued use means acceptance.
Direct from you: Name, email, mobile, username, password (hashed), role (student/educator/etc.), profile picture, bio, referral code, test submissions, answers, scores, uploaded questions/content, support tickets, payment details (processed securely, we don't store full card data).
Automatically: IP, browser/device, session data, timestamps, quiz attempt events (timing, navigation, changes, flags - for anti-cheat and analytics), cookies for session/CSRF.
For educators: Created test series, quizzes, questions (with BBCode), enrollment data, analytics usage.
For students: Attempt history, scores, time spent, device fingerprints for integrity.
- Provide and personalize tests, results, dashboards, and analytics (premium for educators/students with subscription).
- Process enrollments, payments, and refunds (see dynamic Refund Policy in Terms).
- Detect cheating/fraud (event logging, rate limits, fingerprinting).
- Improve the platform, send important notices, moderate content.
- Comply with law and protect rights/safety.
Consent (for marketing/analytics where applicable), contract (to deliver the service), legitimate interests (security, improvement, fraud prevention), legal obligations.
You can withdraw consent for non-essential processing via profile settings or support.
We do not sell your data. We share with:
- Hosting, analytics, email, and payment processors (under contracts).
- Legal authorities when required.
- In case of merger/acquisition (with notice).
- Educators or institutions when necessary to deliver tests or enrollment features.
Educator-created content may be visible to enrolled students as intended. Attempt data is shared with the educator who created the test.
We use session cookies and similar technologies to keep you signed in, remember preferences, maintain security, and analyze usage. You can control cookies through your browser settings, but some features may not work correctly if cookies are disabled.
We retain data as long as needed for the service + legal (e.g. 3-7 years for financial/audit). You can request access, correction, deletion (subject to legal holds and active enrollments) via support.
We use industry-standard security measures including strong hashing, encrypted transport where configured, access controls, and monitoring. No method is 100% secure; report incidents immediately.
Analytics may use aggregated data. Essential cookies for session and CSRF are described above.
We do not knowingly collect data from children under 13 without consent. Student attempt data is educational and handled per role.
Data may be processed in India or with service providers under adequate safeguards.
Changes to this Policy will be posted here with date. For material changes, we may notify via email or site notice.
Use our Contact Us form or the support center. For India DPDP grievances, use the designated officer listed on the site. We aim to respond within 30 days.
Refund requests: See the dynamic Refund Policy in our Terms.