निजता नीति
Privacy Policy
This policy covers this website — what happens when you browse it and when you buy a plan. The Tales of Amritpur app has its own, fuller policy covering children's profiles; it ships with the app.
Last updated: 27 August 2026 · Governed by India's Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025.
The short version
- We collect order details and anonymous site-usage signals, and nothing else.
- No child ever gives us data through this website. The account holder is a parent or guardian.
- No advertising trackers or analytics cookies in your browser — ad results are measured server-side only (see advertising measurement), and children are never tracked, anywhere, ever.
- We never sell, rent or share your data with anyone for marketing.
What we collect, and why
| Data | Why we need it | How long we keep it |
|---|---|---|
| Name, mobile number, email | Name — for your order and the books; email — to confirm your order and sign you in; mobile — for delivery updates and support (never for sign-in) | While your plan is active, then 8 years (tax and audit law) |
| Delivery address (full admission only) | To post you twelve activity books | Same as above |
| Payment status and reference ids | To confirm payment, issue invoices and process refunds | 8 years (tax law) |
| How you found us — the campaign label from our own advertising link (if you arrived through one), the website that referred you, and, if you choose to answer the one optional question after payment, where you first heard about Amritpur | To know which of our own efforts actually reach families, so we spend less on advertising and more on the programme. It is never used to profile you, never shared, and never linked to anything your child does | With your order |
| Login codes (OTP) | To verify it is really you signing in | 5 minutes, stored hashed, deleted on use |
| Security logs (IP address, request counts) | To stop abuse and fraud — a legitimate-use basis | 90 days |
| Site usage signals — pages viewed, buttons tapped, scroll depth and timings, your approximate location (city, state, country — worked out from your network address, which itself is never stored) and coarse device and browser type (for example “Android · Chrome”), tied to a random session number that disappears when you close the tab (never your name, number or email) | To improve this website and see which of our ads bring families here — measured by us alone, on our own servers, never shared with anyone | 180 days |
We never collect card or UPI details. Payment happens inside Razorpay's own secure checkout. We receive only a payment reference and a success or failure result.
Children's data
Under the DPDP Act, a child is anyone under 18 — the highest threshold in the world, and we build to it. This website is for parents and guardians. It has no child sign-up, no child profile, and no place for a child to enter anything.
Inside the app, where children do appear, we never track them, never monitor their behaviour, and never show them advertising — as required by DPDP s.9(3), and as a design principle we would hold to regardless. The app requests no camera, microphone, location or contacts permission at all.
Cookies
We set exactly one cookie, and only if you sign in to your account: a session cookie that keeps you signed in. It is HttpOnly, Secure, SameSite=Lax, and carries no advertising identifier. There are no analytics cookies and no third-party cookies, which is why you are not being asked to dismiss a cookie banner. Our own usage measurement is cookie-less — it sets no cookie and stores nothing on your device that outlives your visit.
Who we share data with
- Razorpay — to take the payment. They receive your name, email and mobile number as required for the transaction.
- Our courier partner — receives your name, address and mobile number, solely to deliver the books.
- Our email provider — receives the address needed to deliver each message we send you (order confirmations, the free kit, login codes).
That is the complete list. Each of these is a data processor acting on our instructions, not a party free to use your details for its own purposes.
Advertising measurement
When we advertise (for example on Meta), we measure whether our own ads worked by reporting conversion events — “a purchase happened”, with contact details hashed — to the ad platform. That measurement covers this website's visitors only: it never includes anything a child does, we never sell or rent your data, and we do not run third-party behavioural profiling of you across other sites. Separately, we keep first-party, anonymous usage statistics on our own servers — the site-usage signals in the table above; nothing is sent to any ad platform from your browser.
Where the data lives
Order data is stored in a managed Postgres database with row-level security enabled and access restricted to our servers. Transport is TLS-encrypted throughout. Sensitive values — login codes, and the index we use to look your orders up by email — are stored hashed, never in plain text.
Your rights
Under the DPDP Act you may ask us to:
- tell you what data of yours we hold and who we shared it with;
- correct anything inaccurate or incomplete;
- erase your data — subject to the records tax law requires us to retain;
- nominate someone to exercise these rights if you cannot;
- withdraw consent, at which point we stop the related processing.
Write to support@leocaster.com. We acknowledge within 48 hours and resolve within 30 days.
If something goes wrong
If a breach affects your data we will notify you and the Data Protection Board without delay, and file the detailed report the law requires within 72 hours. Our playbook for this is written in advance rather than improvised on the day.
Grievance Officer
Mayank Patel, Designated Partner — Grievance Officer
mayank@leocaster.com
Leocaster Systems LLP, Ward 19, Ahead of Vallabh Das Bhawan, Talaiya, Vidisha 464001, India
