Privacy Policy

Privacy Policy

Effective Date: September 28, 2025

DoubtBin is a platform operated by Spearhead Eduventures LLP (“we”, “us”, “our”). We are committed to protecting the privacy of learners, instructors, and visitors who use our online training platform and related services. This Privacy Policy explains how we collect, use, disclose, retain, secure, and otherwise process personal information across our website and services available globally, with primary operations in India.


1) Overview, Scope & Who We Are

This Policy applies to all interactions with our platform at https://doubtbin.com, including account creation, course purchases and enrollments, instructor onboarding and payouts, community features, communications, support, and use of mobile or desktop browsers. By accessing or using our services, you consent to the practices described here, subject to applicable law. Our services are offered worldwide from India; region-specific rights are described below.

Operator: Spearhead Eduventures LLP

2) Roles, Responsibility, and Definitions

Data Controller. For most processing activities described in this Policy, Spearhead Eduventures LLP acts as the data controller.

Instructors and Institutional Clients. Instructors who upload courses provide educational content on our platform. If an instructor independently collects/uses learner data outside the platform (e.g., their own mailing list), they act as an independent controller for those external activities. Where an educational institution engages us and directs our processing, we may act as a data processor under that institution’s direction and our agreement.

Students and Minors. The platform is available to users aged 15 and above. Where required by local law (including in India), the consent of a parent or lawful guardian is necessary for minors.

3) Information We Collect and Sources

We collect only what we need to operate our services, fulfill legal obligations, and improve user experience. Categories include:

  • Personal Identification Data. Name, email address, phone number, postal address; for instructors and payout verification, government-issued identification where required by law or payment partners.
  • Account and Learning Data. Username, password (hashed), profile details, enrollments, course progress, quiz results, certifications issued, notes, reviews/ratings, direct/private messages exchanged within the platform (see “Community Features”), and preferences.
  • Payment and Financial Data. Transaction records and limited billing details necessary to process payments and refunds. We do not store full card or UPI credentials. Payments are processed primarily by PayU and PhonePe. During service issues or downtime, we may use Paytm or Cashfree. Instructor payouts are made via Bank Transfer, UPI, or PayPal.
  • Technical and Usage Data. IP address, device and browser type, operating system, time zone, language, referring and exit pages, device identifiers, session activity, pages viewed, time spent, and diagnostic logs.
  • Communications. Support requests, email and WhatsApp exchanges, notification delivery records, survey responses, and platform announcements.
  • Sources. Data is collected (i) directly from you (e.g., registration, purchases, submissions), (ii) automatically through cookies and similar technologies, and (iii) from service providers (e.g., payment processors, analytics) strictly as needed to operate our services.

Comments (incl. Gravatar)

When visitors leave comments, we collect the data shown in the comments form, and also the visitor’s IP address and browser user-agent string to help spam detection. An anonymized string created from your email address (a hash) may be provided to the Gravatar service to check if you use it. The Gravatar privacy policy is available at https://automattic.com/privacy/. After approval of your comment, your profile picture may be visible to the public next to your comment.

Media

If you upload images, avoid uploading images with embedded location data (EXIF GPS). Visitors to the website can download and extract any location data from images on the website.

Embedded content

Articles on this site may include embedded content (e.g., videos, images, articles). Embedded content from other websites behaves as if you visited the other website. Those websites may collect data about you, use cookies, embed additional third-party tracking, and monitor your interaction with that embedded content (including if you are logged in to that website).

Community Features

  • Profile Data: Your display name is public. Other fields may be required or optional. You can modify or remove profile fields in your account settings. Administrators can read and edit profile data as needed to operate the service.
  • Activity: Posts, comments, group joins, and profile updates may be recorded. Visibility follows the context (public areas vs. private groups). You can delete your own items; administrators can edit items to enforce policies or comply with law.
  • Direct/Private Messages: Private messages are visible only to senders/recipients. For safety, compliance, and abuse-prevention, access to message content is strictly limited to a highly restricted set of authorized administrators and is only used when necessary (e.g., to investigate violations or meet legal obligations). No one on the public frontend can access your private messages.

Interactive Content (H5P)

When you interact with H5P content, we may store attempts/scores to show results and progress. Technical logs (e.g., IP, user-agent) may be recorded for performance and abuse prevention.

4) Purposes of Processing and Legal Bases

  • Service Delivery and Operations. Creating/managing accounts; enrollments; course access; progress tracking; issuing certificates under Spearhead Eduventures LLP; instructor tools; payments/refunds/payouts; support; uptime/performance.
  • Security and Fraud Prevention. Detecting/preventing unauthorized access, misuse, spam, and fraud; protecting platform, users, and intellectual property; ensuring reliability.
  • Improvements and Analytics. Measuring engagement, content effectiveness, and performance; developing features; A/B testing; troubleshooting.
  • Communications. Essential service messages (account alerts, receipts, password resets, course notifications, policy updates). Marketing (email or WhatsApp) is sent only where permitted with opt-out options.
  • Push Notifications. If you opt in to browser push notifications, we store a push subscription ID tied to your device/browser to deliver course updates, announcements, and offers. You can opt out at any time via your browser/site notification settings.
  • Compliance and Legal Obligations. Tax/accounting; responding to lawful requests; enforcing terms; protecting legal rights.
  • Legal Bases. Contractual necessity; legitimate interests (e.g., security, improvements); consent (e.g., certain cookies/marketing/push notifications); and legal obligations (e.g., financial record retention). We align our practices with India’s Digital Personal Data Protection Act, 2023 (DPDP) (primary), and with GDPR (EU/UK) and CCPA/CPRA (California) as applicable.

5) Payments, Payouts, and Financial Handling

Payments by learners are processed primarily through PayU and PhonePe; we may switch to Paytm or Cashfree if needed. We receive transaction confirmations and limited metadata to reconcile payments, handle refunds/chargebacks, and comply with audits. We do not collect/store full card numbers or UPI PINs. Instructors receive payouts via Bank Transfer, UPI, or PayPal. Payment partners act as our processors and handle data only as necessary to provide their services.

6) Cookies & Similar Technologies

We use strictly necessary cookies to run the site (e.g., authentication, security, load balancing) and optional analytics/marketing cookies that require your consent. Non-essential cookies are blocked until you enable them via the banner or your preferences.

  • Essential cookies: required for login, core functionality, and security; typically expire at session end or within a short period.
  • Preference cookies: remember settings (e.g., language, display options); typical duration up to 1 year.
  • Analytics & marketing cookies: help us understand usage and measure campaigns (e.g., Google Analytics, Meta Pixel); set only with consent and can be changed any time.

You can manage cookie choices via our banner/links (where available) or your browser settings. Blocking some cookies may affect certain features.

7) Disclosures to Service Providers & International Transfers

We share data only as necessary with trusted service providers bound by confidentiality and data-protection obligations: payment processors (PayU, PhonePe; backups Paytm, Cashfree), hosting/cloud and content delivery (BunnyCDN), DNS and security (e.g., Cloudflare), analytics and advertising measurement (Google Analytics, Meta Pixel), email/push/communications, security and anti-spam tools, and customer support systems. Limited profile details may be visible to other users for core functionality (e.g., instructor name, learner name on certificates). We may disclose information to authorities where legally required, and in connection with mergers, acquisitions, or asset transfers, subject to continued protection.

Lead referrals and sale/share of leads. If you submit contact/enquiry forms, we may—with your explicit consent at the time of submission—share or sell those leads to vetted third parties to help fulfill services (e.g., career services, financing, placement support). You can withdraw consent at any time (see “Your Rights and Choices”). For California residents, this may be considered “selling” or “sharing” personal information; you can opt out by emailing us with the subject line “Do Not Sell/Share”.

Because we serve users globally, personal information may be processed in or transferred to countries outside your own. We apply safeguards for international transfers (contracts, access controls, encryption) consistent with applicable laws.

8) Store & Checkout

While you browse, we may track products viewed to show “recently viewed” items; collect IP/location/device data for tax/shipping estimates and fraud prevention; and use cart/session cookies to keep your cart updated. At checkout, we ask for name, billing/shipping addresses, email, phone, and payment details (processed by gateways). Purposes include: sending order/account info, responding to requests (refunds/complaints), processing payments, preventing fraud, setting up your account, complying with legal obligations, improving offerings, and sending marketing if you opt in.

9) Affiliate Tracking & Partner Disclosures

When you visit our site via an affiliate link, we process limited data to attribute referrals and pay partners. This may include: a referral ID or coupon code, timestamp, landing URL, pages visited for attribution, approximate location (derived from IP), device/browser information, and order metadata (non-card). We use cookies, local storage, and/or server-side methods to remember attribution during the [up to 30-day] window.

  • Coupon-less tracking via URL: If you arrive via a referral link and complete a purchase without entering a coupon, our system may still attribute the order to that affiliate.
  • Data sharing: We share necessary aggregated performance metrics with affiliates (clicks, orders, approved commissions). Affiliates do not receive your full payment data.
  • Retention: Affiliate attribution cookies typically expire within [30] days; related logs are retained per our retention policy for accounting, fraud prevention, and audit.
  • Opt-out: You can clear cookies, use a private window, or adjust browser settings to limit tracking. Some site features (e.g., automatic discounts) may not function without attribution cookies.

Affiliate Account Data

For affiliates, we process registration details (name, email, profile), payout details (UPI/Bank/PayPal as provided), tax/KYC information where required, performance statistics, and communications. This information is used to operate the program, calculate payouts, comply with legal/ tax obligations, and prevent fraud. We may request additional verification before releasing payouts.

10) Content Delivery, Caching & Infrastructure

To provide fast and reliable access worldwide, we use BunnyCDN for content delivery and may use caching at the edge and/or on our servers. DNS is provided via Cloudflare (we may enable additional Cloudflare security/caching features as needed). On our servers, we use performance caching and Redis object caching, and employ LiteSpeed server-level caching for efficiency. Cached copies are temporary and are purged on schedules or earlier if necessary.

11) Data Retention and Deletion

  • Comments & metadata: retained indefinitely to auto-approve follow-ups and preserve discussions.
  • Orders & invoices: retained for 8 years (India tax/accounting and legal defense).
  • Accounts: retained while active; deleted/anonymized upon verified request unless law requires retention. Accounts inactive for 5 years are deleted.
  • Messages & activity: retained while your account exists or until you delete; admins may retain copies if legally required.
  • Cookies: per durations above or until cleared by you.
  • Backups & cache: temporary and purged on rolling schedules; not used to restore deleted personal data except as required by law or to investigate security incidents.

12) Your Rights and Choices

Depending on the laws that apply to you, you have a number of rights regarding your personal data. These include the right to access the data we hold about you, the right to request corrections or updates, the right to request deletion of your data, and the right to restrict or object to the way we process it. You may also request a copy of your information in a portable format. If we rely on your consent to process your data, you may withdraw that consent at any time; this will not affect the lawfulness of processing carried out before your withdrawal.

We will never treat you unfairly or deny you services simply because you exercised any of your privacy rights.

  • Under India’s Digital Personal Data Protection Act (DPDP 2023): you have rights to provide or withdraw consent, to access your data, to request corrections, to request erasure, and to seek grievance redressal.
  • Under the GDPR (EU/UK): you have additional rights including the right to object when we rely on “legitimate interests” as our legal basis, as well as the right to lodge a complaint with a supervisory authority.
  • Under the CCPA/CPRA (California): you have rights to know what personal information we collect, to request deletion, and to opt out of the “selling” or “sharing” of personal information for cross-context behavioral advertising. To exercise the “Do Not Sell/Share” right, you may email us with the subject line “Do Not Sell/Share.” We do not sell your personal information, except in limited cases where you have explicitly consented to share your details for lead referral purposes (see Section 7).

Regarding marketing and notifications: you can manage your marketing email preferences using the unsubscribe link provided in each message. You can also adjust in-platform notification settings, reply with STOP to WhatsApp messages where supported, and disable push notifications through your browser or by using the on-site toggle. Please note that certain essential service communications, such as security alerts, payment receipts, or updates related to course progress will continue to be sent, as they are necessary to provide you with our services.

13) Security and Incident Response

We employ layered administrative, technical, and physical safeguards, including:

  • Network & application security: web application firewall (WAF), bot/spam protection, IP reputation checks, rate limiting, security headers, TLS encryption in transit and encryption at rest for sensitive data, environment segregation, and least-privilege access.
  • Account & data protection: multi-factor authentication for internal systems, role-based access controls, periodic access reviews, and activity logging/monitoring.
  • Operations: vulnerability management and patching, regular backups with secure storage and tested restores, vendor due diligence, and incident runbooks.

While no system is perfectly secure, we continually improve our controls and monitor for emerging threats. If we become aware of a data breach affecting personal information, we will act promptly to contain and remediate, and will notify affected users and, where required, authorities without undue delay and, where feasible, within 72 hours.

14) Where Your Data Is Sent (Spam/Abuse & Password Resets)

Visitor comments and certain submissions may be checked through automated spam detection and abuse-prevention services. If you request a password reset, your IP address may be included in the reset email for security.

15) Third-Party Sites, Integrations & Public Content

Our platform may link to, embed, or integrate third-party services (for example, payment gateways, analytics/advertising measurement, content delivery, social media embeds, survey tools, or single-sign-on providers). These third parties process data under their own privacy policies and terms, which we do not control. When you interact with third-party content or features, those providers may collect information about you (including via cookies, SDKs, pixels, or APIs), and your use of such third-party services is subject to their policies.

Where the platform allows public content (e.g., reviews or forum-style posts), information you choose to share publicly may be visible to others and may be indexed by search engines. Please use discretion when posting content that may identify you or others. If you link or connect your account with any third-party service, you authorize us to receive and process information from that service consistent with this Policy. Disconnecting or revoking access at the third-party service may limit certain features on our platform.

16) Changes to This Policy

We may update this Policy to reflect changes in services, technologies, or legal obligations. Updates will be posted here with a new effective date. Continued use after the effective date constitutes acceptance.

17) Contact and Grievance Redressal

Data Controller: Spearhead Eduventures LLP
Registered Address: Spearhead Eduventures LLP, Kanchan Bhavan, Road No. 4, Bagunhatu, Baridih, Jamshedpur, Jharkhand, India 831017

Privacy & Grievance Contact:[email protected]
Support:[email protected]

We will review and respond to privacy and grievance requests in accordance with applicable law and within required timelines. If you are not satisfied with our response, you may have the right to lodge a complaint with the data protection authority in your jurisdiction.

Select the fields to be shown. Others will be hidden. Drag and drop to rearrange the order.
  • Image
  • SKU
  • Rating
  • Price
  • Add to cart
  • Description
  • Content
  • Additional information
Click outside to hide the comparison bar
Compare