Privacy Policy

BacktestIndia Educational Platform

Last Updated: January 17, 2025

Compliant with Digital Personal Data Protection Act, 2023

1. Introduction & Commitment to Privacy

BacktestIndia ("we," "us," or "our") is committed to protecting your privacy and complying with India's Digital Personal Data Protection Act, 2023 (DPDP Act).

This Privacy Policy explains:

  • What personal data we collect and why
  • How we use, store, and protect your data
  • Your rights under the DPDP Act 2023
  • How to exercise those rights

🔒 Our Privacy Commitment

We collect the minimum data necessary to provide our educational backtesting service. We do NOT sell your data. We do NOT use it for advertising. We store it securely and give you full control.

2. Data Controller & Contact Information

Data Controller Details

Platform Name: BacktestIndia
Operated By: T. Desai
Data Protection Email: backtestindia@gmail.com
Website: backtestindia.com
Jurisdiction: India (Mumbai, Maharashtra)

3. Personal Data We Collect

3.1 Data You Provide Directly

We collect the following information when you create an account:

Data TypePurposeLegal Basis
Email AddressAccount authentication, password reset, service updatesContractual necessity
Payment InformationSubscription billing (processed by Razorpay)Contractual necessity
Name (Optional)Personalization, support communicationYour consent

3.2 Data Generated Through Platform Use

  • Backtest Parameters & Results: Saved strategies, historical query logs (stored to improve service and provide your history)
  • Usage Analytics: Features used, time on platform, navigation patterns (via Firebase Analytics)
  • Technical Data: IP address, browser type, device type, operating system (for security and troubleshooting)
  • Cookies & Session Data: Authentication tokens, preference settings (see Section 8)

3.3 Data We Do NOT Collect

We do NOT collect:

  • Your actual investment portfolio or holdings
  • Bank account details (Razorpay handles this securely)
  • Sensitive personal data (health, religion, biometrics, etc.)
  • Location data beyond general IP geolocation
  • Social media profile information

4. Purpose of Data Collection & Processing

We process your personal data for the following specific, lawful purposes:

🔐 Account Authentication & Service Delivery

Create and manage your account, enable login via Firebase Authentication, provide access to backtesting features, save your custom strategies and backtest history.

💳 Payment Processing & Subscription Management

Process subscription payments securely via Razorpay, manage billing cycles, send payment receipts, handle refund requests (within 7-day guarantee period).

🛠️ Customer Support & Communication

Respond to your questions, resolve technical issues, send critical service updates (e.g., maintenance, security alerts, Terms changes).

📊 Platform Improvement & Analytics

Analyze aggregate usage patterns to improve features, fix bugs, optimize performance, understand which educational content is most helpful. All analytics are anonymized where possible.

🔒 Security & Fraud Prevention

Detect and prevent unauthorized access, abuse of free tier limits, payment fraud, account takeovers, and other security threats.

⚖️ Legal Compliance

Comply with applicable laws, regulations, court orders, or government requests. Maintain records as required by Indian law.

5. Data Storage, Security & Retention

5.1 Where We Store Your Data

Primary Storage Locations:

  • Firebase (Google Cloud): Email authentication, user profiles, saved strategies
  • Razorpay (India): Payment processing data (we do not store card details)
  • Vercel: Application hosting, session data

5.2 Security Measures

We implement industry-standard security measures to protect your data:

  • Encryption in Transit: All data transmitted via HTTPS/TLS encryption
  • Encryption at Rest: Firebase and Razorpay encrypt stored data
  • Access Controls: Role-based access, multi-factor authentication for admin accounts
  • Regular Audits: Periodic security reviews and vulnerability assessments
  • Secure Authentication: Firebase Authentication with industry-standard OAuth protocols

Important: No security system is 100% impenetrable. While we use best practices, we cannot guarantee absolute security. You are responsible for maintaining the confidentiality of your login credentials.

5.3 Data Retention Period

Data TypeRetention Period
Active Account DataRetained while your account is active
Deleted Account DataDeleted within 90 days (except as legally required)
Payment Records7 years (Indian tax law requirement)
Support Correspondence3 years from last contact
Anonymized AnalyticsIndefinitely (contains no personal identifiers)

6. Third-Party Data Sharing & Processors

We do NOT sell your personal data. We do NOT share it for advertising.

We share your data ONLY with essential service providers who help us operate the Platform:

Service ProviderData SharedPurpose
Firebase (Google)Email, user ID, auth tokensAuthentication, data storage
RazorpayEmail, payment detailsPayment processing
VercelSession data, usage logsApplication hosting
EODHDNone (no personal data)Market data provider

Data Processor Agreements

All third-party processors are contractually required to:

  • Process data only for the specified purpose
  • Implement appropriate security measures
  • Comply with applicable data protection laws
  • Delete or return data upon request

Legal Disclosures

We may disclose your data if required by:

  • Court orders or legal proceedings
  • Law enforcement agencies (with valid legal request)
  • Regulatory authorities (SEBI, tax authorities, etc.)
  • Protection of our legal rights or prevention of fraud

7. Your Rights Under DPDP Act 2023

✅ You Have Full Control Over Your Data

The Digital Personal Data Protection Act, 2023 grants you specific rights. We are committed to honoring these rights promptly and transparently.

1️⃣ Right to Access

What it means: You can request a copy of all personal data we hold about you.

How to exercise: Email backtestindia@gmail.com with subject "Data Access Request"

Response time: Within 30 days

2️⃣ Right to Correction

What it means: You can request correction of inaccurate or incomplete data.

How to exercise: Update directly in account settings, or email us with corrections

Response time: Immediate (self-service) or within 15 days

3️⃣ Right to Deletion ("Right to be Forgotten")

What it means: You can request deletion of your account and personal data.

How to exercise: Email backtestindia@gmail.com with subject "Account Deletion Request"

Note: We may retain payment records for 7 years (tax law requirement) and anonymized analytics.

Response time: Within 90 days

4️⃣ Right to Data Portability

What it means: You can request your data in a machine-readable format (JSON, CSV).

How to exercise: Email us requesting data export

Response time: Within 30 days

5️⃣ Right to Withdraw Consent

What it means: For processing based on consent (e.g., marketing emails), you can withdraw consent anytime.

How to exercise: Click "unsubscribe" in emails, or adjust settings in your account

Effect: Immediate upon withdrawal

6️⃣ Right to Grievance Redressal

What it means: You can file a complaint if you believe we've violated your data rights.

How to exercise: Contact our Grievance Officer (see Section 11 below)

Response time: Acknowledgment within 48 hours, resolution within 30 days

7️⃣ Right to Nominate

What it means: You can nominate someone to exercise your data rights in case of death or incapacity.

How to exercise: Email us with nominee details and consent documentation

Note: This right is as per DPDP Act 2023 provisions

8. Cookie Policy

8.1 What Are Cookies?

Cookies are small text files stored on your device that help us recognize you and remember your preferences.

8.2 Cookies We Use

Cookie TypePurposeDuration
Essential CookiesAuthentication, session management (required for platform to function)Session / 30 days
Analytics CookiesFirebase Analytics - understand usage patterns (anonymized)2 years
Preference CookiesRemember your settings (e.g., saved strategies, UI preferences)1 year

8.3 Managing Cookies

You can control cookies through your browser settings. Note that disabling essential cookies may prevent the Platform from functioning properly.

  • Chrome: Settings → Privacy and Security → Cookies
  • Firefox: Settings → Privacy & Security → Cookies
  • Safari: Preferences → Privacy → Cookies

9. Children's Privacy

Age Restriction: Our Platform is NOT intended for individuals under 18 years of age. We do not knowingly collect data from children. If you are under 18, please do not use this Platform.

If we discover that we have inadvertently collected data from a child under 18, we will delete it immediately. Parents/guardians who believe their child's data was collected should contact us at backtestindia@gmail.com.

10. International Data Transfers

While we primarily serve Indian users, some of our service providers (Firebase, Vercel) may process data on servers located outside India, including in the United States and European Union.

Cross-Border Transfer Safeguards: We ensure that all international data transfers comply with DPDP Act 2023 requirements, including standard contractual clauses and adequacy assessments. Your data is protected regardless of where it's processed.

11. Grievance Redressal Officer

As required under the DPDP Act 2023, we have appointed a Grievance Officer to address your data protection concerns.

📧 Contact Grievance Officer

Name: T. Desai

Designation: Data Protection & Grievance Officer

Email: backtestindia@gmail.com

Subject Line Format: "Privacy Grievance - [Your Issue]"

Response Timeline:

  • Acknowledgment: Within 48 hours
  • Investigation & Response: Within 30 days

What to Include: Detailed description of your concern, relevant dates, supporting documentation (if any), and your preferred resolution.

Escalation to Data Protection Board

If you are not satisfied with our response, you have the right to file a complaint with the Data Protection Board of India as established under the DPDP Act 2023. Contact details will be published by the Board once operational.

12. Changes to This Privacy Policy

We may update this Privacy Policy to reflect:

  • Changes in data protection laws (DPDP Act updates)
  • New features or services we offer
  • Changes to our data processing practices
  • Feedback from users or regulators

How We Notify You: Material changes will be communicated via email (to your registered address) at least 30 days before taking effect. We will also update the "Last Updated" date at the top of this page. Your continued use after changes constitutes acceptance.

13. Contact Us

For any privacy-related questions, concerns, or requests:

Email: backtestindia@gmail.com
Subject Line: "Privacy Inquiry" or "Data Rights Request"
Website: backtestindia.com
Response Time: We aim to respond within 48 hours

🔐 Your Privacy Matters to Us

We collect minimal data, protect it rigorously, and give you full control.
Your data is NEVER sold. Your rights under DPDP Act 2023 are fully respected.
Questions? Contact us anytime at backtestindia@gmail.com