GamifyTL legal
Privacy Policy
This policy explains what information GamifyTL collects, why it is used, how single active device security is managed, and the privacy safeguards provided to authors and participants.
Effective 21 August 2026
1. Information We Collect
1.1 Author Accounts: For educators and hosts who create accounts, we process name, email address, password hash (managed via Supabase Auth), billing profile details, subscription plan tier, payment identifiers (Razorpay customer and subscription IDs), support inquiries, and usage counters.
1.2 Single-Device Session & Security Telemetry: To enforce our single active device policy, prevent credential sharing, and safeguard against account compromise, we collect and process limited device metadata, including: client device name, browser/OS user agent, client IP address, ephemeral device session tokens, and last active timestamps. This data is used solely for session management, takeover broadcast authorization, and fraud prevention.
1.3 Session & Gameplay Data: For live sessions, we store room configuration, uploaded questions, temporary participant display names, answers, points, timestamps, and educational files shared via Resource Drop.
1.4 Diagnostic Logs: We collect standard server logs, request IDs, rate-limit counters, and application error traces to ensure platform stability.
2. How We Use Information
We use collected information strictly to: (a) authenticate educators and verify active device sessions; (b) power real-time classroom interactions, leaderboards, and scoring; (c) process secure subscriptions and generate tax receipts through Razorpay; (d) enforce plan limits and fair-use guidelines; (e) prevent abusive traffic and unauthorized account pooling; (f) comply with accounting and statutory requirements under Indian law; and (g) deliver customer support.
3. Third-Party Service Providers
GamifyTL relies on trusted, industry-standard infrastructure providers who process data strictly pursuant to confidentiality obligations:
- Supabase: Managed database, authentication, storage, and real-time WebSocket message brokering.
- Razorpay: PCI-DSS certified payment gateway handling checkout, UPI, cards, and billing mandates.
- AI Providers (Google Gemini, OpenRouter, NVIDIA): Assistive generation requested by authors. No student personal data is transmitted to AI providers.
- Render / Cloud Hosting: Stateless backend API hosting and edge delivery.
4. Student & Participant Privacy (COPPA, FERPA, DPDP Act)
4.1 No Student Accounts Required: Learners, students, and attendees do not create accounts, supply emails, or provide passwords. They join live games anonymously using only a room code and a temporary screen nickname.
4.2 No Tracking or Profiling: We do not track participants across websites, build behavioral advertising profiles, or monetize student information.
4.3 Institutional Consent: Educators hosting classroom sessions are responsible for ensuring that their use complies with their school district's parental notice and consent policies.
5. Data Retention & Deletion
5.1 Room Data: Free-plan room results and participant answers expire after seven (7) days. Paid Pro room histories remain accessible in the author's dashboard until deleted by the host.
5.2 Resource Drop Files: Files uploaded to Resource Drop automatically expire and are permanently erased after 7 days (Free) or 28 days (Pro).
5.3 Active Session Records: Device session tracking records are overwritten whenever an author signs in from a new device, and obsolete session records are pruned.
5.4 Financial Records: Invoices, payment records, and fraud-prevention logs are retained for the statutory period required by Indian tax and commercial regulations.
6. Security Measures
We implement strong technical and organizational safeguards: end-to-end HTTPS encryption, Postgres Row Level Security (RLS) on all database tables, encrypted server environment secrets, cryptographically signed game tokens, and single-device session invalidation. However, no internet transmission is 100% immune, and authors should protect their login credentials.
7. Your Privacy Rights
You may request access to, correction of, or permanent deletion of your personal author account data by contacting us at support@northnode.live. We promptly fulfill verified requests in accordance with applicable data protection laws.
Business details
NorthNode Technologies, trading as NorthNode/GamifyTL, is an individual business registered in India.
Registered address: NorthNode Technologies, Garden City University, Battarahalli, Bengaluru, Karnataka 560049
Email: support@northnode.live · Phone: +91 63033 92391