Privacy Policy

Last updated 18 August 2026

What we collect

When you register we collect your name, email address, mobile number, college, city/state, course details, year and semester of study, and any optional information you provide (skills, GitHub/LinkedIn links, t-shirt size).

We also automatically record technical and marketing data: your IP address, browser user agent, the page you arrived on, and campaign parameters (UTM tags and Facebook click identifiers) so we understand which of our advertisements brought you here.

How we use it

  • Running the event: registration, team formation, submissions, judging, results
  • Communicating with you by email and WhatsApp about the event
  • Processing your registration payment
  • Measuring which marketing channels work, so we spend our budget sensibly
  • Issuing certificates and prizes

Payment data

Payments are processed by Razorpay. We never see or store your card number, CVV, UPI PIN or banking credentials — those go directly to Razorpay, who are PCI-DSS compliant. We store only the transaction reference, amount, and status.

Advertising & Meta (Facebook)

We advertise this event on Facebook and Instagram. To measure whether those ads work, we use the Meta Pixel and Meta's Conversions API. When you register or pay, we send Meta a signal that a conversion happened.

Personal identifiers sent to Meta are cryptographically hashed (SHA-256) before transmission — Meta receives an irreversible hash, not your plain email address or phone number. This is standard advertising measurement practice and lets Meta match the conversion to an ad click without us handing over your raw details.

You can control ad tracking through your Facebook ad preferences and your browser's cookie settings.

Cookies

We use a session cookie to keep you logged in (essential — the site cannot work without it), and Meta advertising cookies (_fbp, _fbc) for the measurement described above.

Who we share it with

We share data only with: Razorpay (payments), our email service provider (event communications), Meta (hashed conversion signals), and event sponsors — the last only where you have explicitly opted in. We do not sell your personal data.

How long we keep it

Registration and submission data is retained for up to 3 years so we can verify certificates and results. Payment records are retained as long as required by Indian tax law. You can ask us to delete your data sooner, subject to those obligations.

Your rights

You may request access to, correction of, or deletion of your personal data at any time by emailing team@inithack.com. You may also unsubscribe from non-essential emails; we will still send you operational messages about an event you have paid for.

Security

Passwords are stored using bcrypt hashing — we cannot read them. The site is served over HTTPS and access to participant data is restricted to authorised organisers. No system is perfectly secure, but we take reasonable measures to protect your data.

Contact

Privacy questions: team@inithack.com

Note: this is a general template. Have it reviewed by a legal professional before going live, and confirm it satisfies India's Digital Personal Data Protection Act obligations for your specific setup.